Privacy Policy

Last updated: July 2026

1. Overview

CuraAi_HOS ("we", "us") respects your privacy. This policy explains how we collect, use, store, and protect your personal and health data. We comply with the Digital Personal Data Protection Act (DPDP) 2023 of India.

2. Data We Collect

Patient Data: Name, age, gender, phone, email, blood group, height, weight, allergies, chronic conditions, symptoms, prescriptions, lab reports, health records.

Partner Data: Business name, licenses, qualifications, bank details, performance metrics, compliance scores, feedback.

Usage Data: IP address, browser type, pages visited, timestamps, interaction logs.

3. How We Use Your Data

  • Provide AI symptom triage and healthcare navigation
  • Connect patients with appropriate healthcare providers
  • Process bookings, orders, and payments
  • Detect fraud and ensure partner compliance
  • Maintain audit logs for security
  • Generate anonymous analytics for platform improvement

4. Data Storage & Security

Data Residency: All data is stored in India (Mumbai region — AWS ap-south-1 / Neon ap-south-1).

Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256).

Access Control: Only authorized personnel can access personal data. All access is logged in our audit system.

Backups: Encrypted weekly backups. Backups are stored separately and can be destroyed via self-destruct if compromised.

5. Data Sharing

We do NOT sell your data. We share data only:

  • With your assigned doctor (for consultation purposes)
  • With pharmacies/labs you choose to order from
  • With payment processors (Razorpay) for transactions
  • With law enforcement if legally required

6. Your Rights (DPDP Act 2023)

  • Right to Access: Request a copy of your data
  • Right to Correction: Update inaccurate data
  • Right to Erasure: Request deletion of your data
  • Right to Grievance: File complaints with our Data Protection Officer

To exercise these rights, email: privacy@curaai.in

7. Data Retention

Patient health records: 7 years (per Indian medical record retention law). Account data: until account deletion requested. Audit logs: indefinitely (for security). Backup data: 90 days rolling.

8. Breach Notification

In case of a data breach, we will notify affected users and the Data Protection Board of India within 72 hours, as required by DPDP Act 2023.

9. Cookies

We use essential cookies for authentication and session management. We do not use third-party advertising cookies.

10. Contact

Data Protection Officer: privacy@curaai.in

© 2026 CuraAi_HOS. All rights reserved.