Privacy Policy & International Data Protection Notice
Nirogyam Healthplexes comprehensive privacy policy covering compliance frameworks under the Digital Personal Data Protection Act (India), GDPR (EU/EEA & UK), and CCPA/CPRA (USA).
1. Overview & Data Fiduciary Identity
Nirogyam Healthplexes Pvt. Ltd. ('Nirogyam', 'we', 'us', or 'our') operates an international patient facilitation and medical travel platform. We are committed to protecting the privacy, confidentiality, and security of individuals who access our services. Under applicable data protection legislation, including the Digital Personal Data Protection Act, 2023 (DPDP Act, India) and the General Data Protection Regulation (EU/UK GDPR), Nirogyam operates as a Data Fiduciary / Controller with respect to journey coordination data.
2. Collection of Health and Personal Data
We collect personal information necessary to facilitate your medical travel enquiry. This includes: contact identifiers (name, email, phone/WhatsApp number, nationality), logistical preferences (preferred treatment city, hospital preferences, travel dates), and non-clinical case summaries. Medical reports, diagnostic imaging, and physician notes are collected solely with your explicit consent and transmitted securely to accredited hospital clinical teams for pre-travel opinions.
3. Lawful Basis and Special Category Data Processing (GDPR Article 9)
For visitors from the European Union, European Economic Area, and United Kingdom, health data constitutes special category data. We process health data exclusively pursuant to GDPR Article 9(2)(a) upon obtaining your explicit, freely given, and documented consent, or Article 9(2)(h) for the facilitation of medical assessment by licensed healthcare professionals at our partner hospitals.
4. Prohibition of Health Data in URLs and Unencrypted Channels
In strict compliance with international security standards, Nirogyam enforces a rigid architectural rule: health data, diagnoses, scans, and reports are NEVER transmitted via URL query parameters, unencrypted browser history, or public links. WhatsApp communications initiated through our platform contain only safe, non-clinical greeting text.
5. International Data Transfers and Security Safeguards
As our coordination desk is based in Jaipur, Rajasthan, India, your information will be processed in India. We employ standard contractual clauses, encryption in transit (TLS 1.3), encryption at rest (AES-256), and strict role-based access control to ensure international data transfer integrity.
6. US State Privacy Disclosures (California CCPA/CPRA)
California residents have specific rights regarding personal information under the California Consumer Privacy Act (CCPA) as amended by the CPRA. Nirogyam does not sell or share personal information for cross-context behavioral advertising. You have the right to request deletion, correction, and access to your data without discrimination.