Platform Privacy Policy
Last Updated: Takes effect on the day the Zivyaa platform launches
This document covers the Zivyaa software platform — the patient app and the logins used by clinics, hospitals, labs and pharmacies. For the zivyaa.co.in website itself, see the Website Privacy Policy.
1. Who we are
Zivyaa is a software platform operated by ZIVYAA HEALTHTECH SOLUTIONS PRIVATE LIMITED (CIN U58201UP2026PTC245355) ("Zivyaa", "we", "us"), registered at C/O: Shashibala Singh, Bhradwajpuram, Rustampur, Shivpuri New Colony, Gorakhpur Sadar, Gorakhpur, Uttar Pradesh 273016, India. Clinics, hospitals, diagnostic labs and pharmacies ("Facilities") use it to run appointments, prescriptions, lab reports, billing and inventory. Patients use it to see and manage their own records.
2. Our role under the Digital Personal Data Protection Act, 2023
- For records a Facility creates (prescriptions, lab reports, bills, visit notes), the Facility decides why and how the data is used. We process that data on the Facility's behalf and on its instructions.
- For your Zivyaa account (your login and the patient app), we decide how the data is used, and this policy explains it.
3. What we collect
- Patients: name, mobile number, date of birth, sex, address, Zivyaa Health ID and, if you give them, ABHA number and Aadhaar details; clinical information recorded by the Facility you visit (vitals, diagnoses, allergies, prescriptions, lab results, documents).
- Facility staff and doctors: name, mobile, email, role, registration numbers, and the Facility you work at.
- Everyone: sign-in records, the device used for notifications, and records of which account opened which patient record and when.
We do not collect more than a Facility or you need for the service.
4. Why we use it
- To provide the service: booking, consultation, prescriptions, lab reports, pharmacy bills, payments and notifications.
- To keep patients safe: medicine warnings (allergy, interaction, dose, pregnancy, kidney function) shown to the prescribing doctor.
- To meet legal duties: tax invoices, statutory registers for controlled medicines, and record keeping required of healthcare providers.
- To keep the platform secure and to investigate misuse.
We do not sell personal data. We do not use it for advertising.
5. Your records at another Facility need your consent
A Facility can see the records it created. Another Facility can see your records from elsewhere only with your consent. You can see who is asking and why, and you can withdraw your consent at any time, as easily as you gave it.
In a medical emergency, your allergies, current conditions and ongoing treatments may be shown to the doctor treating you without this step, because a doctor who does not know them could put your life at risk.
6. Who we share data with
- The Facilities you visit, as described above.
- Service providers who help us run Zivyaa: hosting, SMS delivery through licensed operators, push notifications, licensed payment gateways or banks (we do not store your full card details) and, for optional AI features, an AI service run by us or by a provider. Each of them may use the data only to provide that service to us. We will name them here as they are finalised.
- ABDM, only if you or a Facility link your ABHA, and only as the ABDM consent framework allows.
- Authorities, when the law requires it.
7. Artificial intelligence
Some optional features use an AI model. When a doctor asks for diagnosis suggestions, the model never receives your name, phone number or any ID. The suggestion is shown as a suggestion; the doctor decides. These features are off unless the Facility turns them on.
8. Where data is stored
Your data is stored on servers located in India. A service provider listed in section 6 may process the limited data it needs for its service elsewhere; we will name any such provider here.
9. How long we keep it
We keep your data while you want us to, and you can ask us to erase it. Where a law requires a record to be kept — medical records, for example, are medico-legal documents that healthcare providers must keep for periods set by law — we keep that record for as long as that law requires, and no longer. Closing a patient account stops all access to it immediately.
10. How we protect it
Encrypted connections (HTTPS), role-based access so staff see only what their role allows, a record of who opened which patient record, a change history on clinical and financial records, and regular backups that we test by restoring them. If a personal data breach occurs, we will inform the Data Protection Board of India and the people affected, as the law requires.
11. Your rights
Under the DPDP Act you may:
- ask what data we hold about you and who it was shared with;
- have it corrected or completed;
- have it erased where the law does not require us to keep it;
- withdraw consent;
- nominate someone to act for you;
- complain to us, and then to the Data Protection Board of India.
For records a Facility created, you may also ask that Facility directly.
12. Children
A child's records are managed by a parent or guardian through the family section of the patient app. We process a child's data only with the verifiable consent of the parent or guardian, and we never track, profile or target advertising at children.
13. Grievance Officer
Arjun Singh, Grievance Officer
ZIVYAA HEALTHTECH SOLUTIONS PRIVATE LIMITED
Email: contact@zivyaa.co.in · Phone: +91 87562 85739
Gorakhpur, Uttar Pradesh 273016, India
We will acknowledge your complaint within 7 days and resolve it within 30 days.
14. Changes
We will post any change here and, if it is significant, tell you in the app before it applies.
