1Who we are and what this policy covers
Nabhaya is a healthcare software platform operated by ImproveFX Technologies Pvt. Ltd. ("ImproveFX", "Nabhaya", "we", "us" or "our"), a company incorporated in India with its office at First Floor, E-49/5, Pocket D, Okhla Phase II, Okhla Industrial Estate, New Delhi, Delhi 110020 (CIN: [company CIN]).
This Privacy Policy explains how we collect, use, share, store and protect personal data when you:
- visit nabhaya.com or any page that links to this policy (the "Website");
- ask for a demo, a callback or information, or contact us by phone, email or WhatsApp;
- use Nabhaya Clinic, Nabhaya Hospital, Nabhaya Pharmacy or any related app, API or service (together, the "Services");
- take part in our referral or partner programmes, events or surveys.
We process personal data in line with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the "DPDP Act"), the Information Technology Act, 2000 and the rules made under it, and other laws of India that apply to us.
2Our two roles: data fiduciary and data processor
How we handle personal data depends on whose data it is and why we have it.
Your data as our visitor or customer
For website visitors, people who enquire or book demos, clinic owners, and the doctors, receptionists, pharmacists and admins who log in to Nabhaya, we decide why and how the data is used. This policy applies in full.
Patient data inside a clinic's account
When a clinic, hospital or pharmacy (our "Customer") uses Nabhaya to record patients, appointments, prescriptions, bills and documents, the Customer is the data fiduciary. We process that data only on the Customer's instructions and under our agreement with them.
3Personal data we collect
| Who | What we collect | How we get it |
|---|---|---|
| Website visitors | IP address, device and browser type, pages viewed, referring page, approximate location from IP, cookie identifiers | Automatically, through cookies and server logs |
| Enquiries and demo requests | Name, mobile number, email, clinic or hospital name, city, number of doctors, product interest, preferred call time, your message | Forms on the Website, phone calls, email and WhatsApp |
| Customer account users | Name, role, mobile number, email, login credentials, medical registration number where a doctor provides it, signature image for prescriptions if uploaded, activity and audit logs | From you or your clinic's admin when accounts are created |
| Billing contacts | Billing name, business name, GSTIN, billing address, invoices, payment status and transaction references | From you, and from our payment partners. We do not store full card or bank account numbers. |
| Support | Messages, call notes, screenshots and files you share with our support team | From you |
| Referral and partner applicants | Name, contact details, company, city, role, bank or UPI details for payouts | From you |
| Patients of our Customers (processed on the Customer's behalf) | Name, age, gender, contact details, appointment history, vitals, clinical notes, diagnoses, prescriptions, lab reports, images and documents, bills and payments, messages sent to the patient | Entered or uploaded by the Customer's staff, or submitted by patients through the Customer's booking link |
Health information is sensitive. We treat all patient data with the highest level of protection we apply to any data.
4How and why we use personal data
We use personal data only for clear, specific purposes:
- To provide the Services: create and manage accounts, run appointments, queues, prescriptions, billing, pharmacy, documents and messages, and keep the Services working.
- To respond to you: answer enquiries, arrange and run demos, provide onboarding, training and support.
- To bill and collect payment: issue invoices and tax documents, process payments and manage renewals.
- To keep the Services secure: authenticate users, keep audit logs, detect and prevent fraud, misuse and security incidents.
- To improve the Services: understand how features are used, fix bugs and plan improvements, using account-level usage information that does not identify patients.
- To send updates: service notices, security alerts, product updates and, where you have agreed, marketing messages. You can opt out of marketing at any time.
- To meet legal duties: tax and accounting records, responding to lawful requests from authorities, and enforcing our agreements.
Legal grounds. We rely on your consent, which you can withdraw at any time; on the legitimate uses permitted under Section 7 of the DPDP Act, such as when you voluntarily give us data for a specific purpose; and on compliance with law. Patient data is processed on the grounds the Customer relies on, and on the Customer's instructions.
5Patient data we process for clinics
When we act as a data processor for a Customer, we commit that we will:
- process patient data only to provide the Services to that Customer and on their documented instructions;
- never sell patient data or use it to advertise to patients;
- never share patient data with another clinic or customer;
- limit staff access to people who need it to provide support, and only with the Customer's permission or where needed for security or legal reasons;
- help the Customer respond to patient requests to access, correct or erase their data;
- tell the Customer without undue delay if we become aware of a personal data breach affecting their data;
- return or delete patient data at the end of the Customer's subscription, as described in the Retention section.
Customers are responsible for giving patients the notices and obtaining the consents that the law requires, including consent to receive WhatsApp, SMS and email messages, and for meeting the medical record keeping rules that apply to them.
6WhatsApp, SMS and email messages
Nabhaya can send appointment confirmations, queue updates, prescriptions, reminders and feedback requests to patients on WhatsApp, and emails to users and patients.
- WhatsApp messages are delivered through the WhatsApp Business Platform operated by Meta. Meta processes message content and phone numbers under its own terms and privacy policy.
- On the Multi-Speciality plan, a Customer may connect its own WhatsApp Business account and its own email (SMTP) server. Messages then go out under the Customer's accounts and the Customer's agreements with those providers.
- Customers must send messages only to patients who have agreed to receive them, and must stop when a patient opts out.
- Marketing messages from Nabhaya to you are sent only where you have agreed. Reply STOP, use the unsubscribe link, or write to [[email protected]] to opt out.
9Where data is stored and cross-border transfers
We store Customer data, including patient data, on servers located in [India]. Some service providers, such as messaging or email providers, may process limited data outside India. We transfer personal data outside India only as permitted under the DPDP Act, and never to a country or territory that the Government of India has restricted.
10How we protect personal data
We use reasonable security safeguards appropriate to health data, including:
- encryption of data in transit (HTTPS/TLS) and at rest [confirm with engineering];
- role-based access, so each admin, doctor, receptionist and pharmacist sees only what their role needs;
- audit logs of sign-ins and important actions, retained for at least one year;
- regular backups and tested restore processes;
- access to production systems limited to authorised staff, with confidentiality obligations and security training;
- monitoring, vulnerability management and prompt patching.
If a breach happens, we will contain it, investigate it and notify the Data Protection Board of India and affected people (or, for patient data, the affected Customer) as the DPDP Act requires, and report cyber security incidents to CERT-In within the time its directions set.
No system is completely secure. Please keep your password private, use a strong password, and tell us at once at [[email protected]] if you think your account has been compromised.
11How long we keep personal data
- Enquiries and demo requests: for up to [24 months] after our last contact, unless you become a customer.
- Customer account and billing data: for the length of the subscription, and afterwards for as long as tax and accounting laws require.
- Logs: at least one year, as the DPDP Rules require, and longer only where needed for security or legal reasons.
- Patient data held for a Customer: for as long as the Customer's subscription is active. After the subscription ends, the Customer has [30 days] to export its data. We then delete it from live systems within [90 days], and from backups as they roll off, unless the law requires us to keep it longer.
Customers decide how long patient records must be kept under the medical record rules that apply to them, and should export their records before closing an account.
12Your rights
Under the DPDP Act, you have the right to:
- access a summary of the personal data we process about you and how we process it;
- correct, complete or update your personal data;
- erase your personal data, where we no longer need it for the purpose it was collected or to meet a legal duty;
- withdraw consent at any time, as easily as you gave it. This does not affect processing before you withdrew it;
- nominate another person to exercise your rights if you die or are unable to do so;
- grievance redressal through our Grievance Officer, and, if you are not satisfied, to complain to the Data Protection Board of India.
To use these rights, write to [[email protected]] or call +91 70428 88631. We may need to verify your identity first. We will respond as soon as possible and in any case within the time the law allows, which is no more than 90 days. Patients should contact their clinic first, as explained in section 2.
13Children
The Website and Nabhaya accounts are meant for adults acting for a clinic or business. We do not knowingly collect personal data directly from children.
Clinics may record data about patients who are children. In that case, the clinic is responsible for obtaining verifiable consent from the child's parent or lawful guardian as the DPDP Act requires. We process children's data only for the clinic's care and administration, and never for tracking, behavioural monitoring or targeted advertising.
14Third-party websites and services
The Website and the Services may link to or work with third-party services, such as Google Business Profile, WhatsApp and YouTube. Their own privacy policies apply when you use them. We are not responsible for how they handle personal data.
15Changes to this policy
We may update this policy as our Services or the law change. We will post the new version on this page with a new "Last updated" date. If the changes are significant, we will tell Customers by email or in the product at least [15 days] before they take effect.
16Grievance Officer and contact
If you have a question, request or complaint about personal data, please contact our Grievance Officer:
We will acknowledge your message within [48 hours] and aim to resolve it within [30 days], and in any case within 90 days.