Last updated: July 2026
CuraAi_HOS ("we", "us") respects your privacy. This policy explains how we collect, use, store, and protect your personal and health data. We comply with the Digital Personal Data Protection Act (DPDP) 2023 of India.
Patient Data: Name, age, gender, phone, email, blood group, height, weight, allergies, chronic conditions, symptoms, prescriptions, lab reports, health records.
Partner Data: Business name, licenses, qualifications, bank details, performance metrics, compliance scores, feedback.
Usage Data: IP address, browser type, pages visited, timestamps, interaction logs.
Data Residency: All data is stored in India (Mumbai region — AWS ap-south-1 / Neon ap-south-1).
Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
Access Control: Only authorized personnel can access personal data. All access is logged in our audit system.
Backups: Encrypted weekly backups. Backups are stored separately and can be destroyed via self-destruct if compromised.
We do NOT sell your data. We share data only:
To exercise these rights, email: privacy@curaai.in
Patient health records: 7 years (per Indian medical record retention law). Account data: until account deletion requested. Audit logs: indefinitely (for security). Backup data: 90 days rolling.
In case of a data breach, we will notify affected users and the Data Protection Board of India within 72 hours, as required by DPDP Act 2023.
We use essential cookies for authentication and session management. We do not use third-party advertising cookies.
Data Protection Officer: privacy@curaai.in
© 2026 CuraAi_HOS. All rights reserved.