Aroverse Protech Legal Privacy Policy
Effective date: June 11, 2026 · Last reviewed: June 11, 2026
This Privacy Policy explains how Aroverse ProTech collects, uses, discloses, stores, and protects personal data and health-related data when you use our digital healthcare data management platform, website, mobile experiences, and related services (collectively, the “Services”).
We designed this policy to align with major mobile platform expectations, including Google Play User Data and Data Safety requirements, Apple App Store privacy requirements, and common healthcare privacy standards used by digital health companies.
1. Scope and Roles
Aroverse ProTech may act as a Data Fiduciary, joint Data Fiduciary, or data processor on behalf of healthcare providers depending on contracts, jurisdiction, and service configuration. This policy applies to various Data Principals (Data Subjects), including:
- Patients: Individuals seeking or receiving healthcare services, consultations, or medical documentation.
- Healthcare Professionals (HCPs): Clinicians, doctors, and nursing staff providing services via the platform.
- Employees: Internal staff, contractors, interns, and job applicants.
- Website Visitors & Administrators: Individuals accessing digital assets or managing platform backends.
1.1 Multi-Tenant Service Model
Aroverse ProTech operates as a multi-tenant Software-as-a-Service (SaaS) platform. Each subscribing healthcare organization (clinic, hospital, diagnostic center, or medical practice) is provided with a logically segregated environment. Data belonging to one healthcare organization is not visible or accessible to another healthcare organization unless explicitly authorized by the patient, healthcare provider, or applicable law.
1.2 Ownership of Healthcare Data
Patient records, consultation notes, prescriptions, diagnostic reports, and other clinical information entered by a healthcare organization remain the property and responsibility of that healthcare organization and its authorized healthcare professionals.
Aroverse ProTech acts as a technology platform provider and processes such data according to customer instructions and applicable law.
1.3 Doctors working across multiple clinics
A healthcare professional may be associated with multiple healthcare organizations. Access to records is controlled through organization-specific permissions and role-based access controls. Healthcare professionals may only access information for organizations that have granted authorization.
1.4 Patients appearing across multiple hospitals/clinics
Patients may receive care from multiple healthcare organizations using the Services. Records remain logically associated with the healthcare organization that created or maintains them unless legally permitted or explicitly authorized for sharing.
2. Data We Collect
2.1 Data you provide directly
- Identity data: name, age/date of birth, profile details, organization and role.
- Contact data: phone number, email address, postal address (if provided).
- Account data: login credentials, authentication events, account preferences.
- Consultation data: audio recordings, transcript content, prescriptions, notes, attachments.
- Health data: symptoms, diagnoses, medications, lab recommendations, follow-up plans.
- Support data: inquiries, tickets, and communication records.
- Subscription plan details, invoices, payment status, billing contacts, tax identifiers, GST information, transaction references, and payment processor records.
2.2 Data collected automatically
- Device and technical data: IP address, device model, OS version, browser/app version.
- Usage data: feature interactions, timestamps, session metadata, crash and performance logs.
- Security data: risk signals, suspicious login attempts, abuse prevention telemetry.
2.3 Data from third parties
- Healthcare providers, laboratories, insurers, or authorized integration partners.
- Identity verification, analytics, security, hosting, and communication service providers.
3. Why We Process Data
- Providing core healthcare workflows, consultations, and digital prescription operations.
- Delivering clinical documentation tools such as speech-to-structured extraction.
- Facilitating medical consultations between preferred HCPs and Patients via WhatsApp for Business.
- Processing employee payroll, benefits, and statutory HR compliance. Authenticating users and securing access to protected health information (PHI).
- Complying with legal, regulatory, and contractual obligations. Providing customer support and responding to incidents or legal requests.
- Operate, maintain, and improve service quality, reliability, and safety.
4. Legal Bases for Processing
- Depending on region and use case, we rely on one or more of the following: User consent (for example, optional features, marketing, or specific processing flows).
- Performance of a contract (for service delivery and account operation). Legitimate interests (security, fraud prevention, service reliability). Compliance with legal obligations (records, safety, and law enforcement requests).
- Provision of healthcare or health system management as permitted by applicable law.
4A. India-Specific Privacy Notice (Applicable to Users in India)
This section supplements this Privacy Policy to support compliance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
If there is any inconsistency between this Section 4A and the rest of this Privacy Policy for users in India, Section 4A will apply to the extent of that inconsistency.
A. WhatsApp Business Account: Clinical Usage
Registered patients may be contacted via an authorized WhatsApp Business Account specifically for taking consent and medical consultation purposes. This channel is used for real-time consent capture, symptom discussion, digital prescription delivery, and care coordination. Messages are encrypted in transit, but users must manage device-level security and cloud backups.
B. Choice: Opt-In and Opt-Out Features
Users must provide explicit, affirmative opt-in to enable clinical WhatsApp messaging.
- Opt-Out: Available anytime using the "STOP" keyword within WhatsApp or via app settings.
- Withdrawal: Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
C. Third-Party Platform Disclaimer
The User understands that WhatsApp is a third-party platform not controlled by the Application. While reasonable security safeguards are implemented, the Application shall not be responsible for any data breaches, delays, or unauthorized access occurring due to vulnerabilities in third party platforms.
D. Data Sharing and Transfer Protocols
Data is shared on a ‘need-to-know’ basis with verified third-party processors. International transfers are protected by safeguards like Standard Contractual Clauses (SCCs) to ensure equivalent protection.
E. Employee and HCP-Specific Processing
Employee and HCP data is processed strictly for employment management and professional verification. This data is segregated from patient health records to prevent unauthorized cross access.
F. Role as Data Fiduciary
For platform administration, account management, subscription billing, security monitoring, and customer support activities, Aroverse ProTech acts as a Data Fiduciary.
For healthcare records and clinical information processed on behalf of healthcare organizations, Aroverse ProTech may act as a Data Processor or service provider depending on applicable law and contractual arrangements.
Healthcare organizations may independently act as Data Fiduciaries with respect to patient information collected through their use of the Services for personal data processed through the Services. In some deployments, healthcare providers or partner institutions may act as independent Data Fiduciaries or Data Processors based on contractual arrangements and service design.
| Scenario | Aroverse ProTech Role |
|---|---|
| Platform account management | Data Fiduciary |
| SaaS subscription billing | Data Fiduciary |
| Clinic patient records | Data Processor |
| Hospital EMR data | Data Processor |
| Marketing communications | Data Fiduciary |
G. Notice at the Time of Collection
At or before collection, you are informed that we process the following:
- Personal data categories: identity data, contact data, account data, consultation records, and health-related data, including medical history, symptoms, prescriptions, and clinical notes.
- Processing purposes: healthcare service delivery (consultation, diagnosis support, documentation), account and authentication management, care coordination and communication, legal and regulatory compliance, platform safety, fraud prevention, and service improvement.
- Sensitive data: health-related information processed through the Services is treated as Sensitive Personal Data or Information under applicable Indian rules.
- Consent basis: where required, processing is based on your free, specific, informed, and unambiguous consent, except where otherwise permitted by law (including medical and legal obligations).
H. Withdrawal of Consent
You may withdraw consent at any time through in-app privacy controls (where available) or through whatsapp or by contacting the Grievance Officer. On withdrawal, we stop future processing unless retention or continued processing is required by legal, medical, or regulatory obligations.
I. Rights of Data Principals
Subject to law, you are entitled to exercise the following rights:
- Right to Access Information: To obtain from the Data Fiduciary confirmation as to whether personal data is being processed, and to access such personal data along with information relating to its processing.
- Right to Correction and Erasure: To request correction, completion, updating, or erasure of personal data that is inaccurate, misleading, or no longer necessary for the purpose for which it was processed, subject to applicable legal obligations.
- Right to Withdraw Consent: To withdraw previously given consent for the processing of personal data at any time, with such withdrawal not affecting the lawfulness of processing based on consent before its withdrawal.
- Right to Grievance Redressal: To have readily available means to register a grievance with the Data Fiduciary and to seek timely redressal of such grievance.
- Right to Nominate: To nominate another individual who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with applicable law.
You may exercise the above rights by submitting a request to the designated Grievance Officer or through such other mechanism as may be provided by the Data Fiduciary. Requests shall be addressed in accordance with timelines and procedures prescribed under applicable law.
J. Data Breach Notification
If a personal data breach is likely to affect your rights, Aroverse ProTech will notify affected users in a reasonable and timely manner and notify applicable authorities, including the Data Protection Board of India, where legally required. In the event of high-risk data breaches, we maintain a 72-hour notification protocol for authorities and affected users.
K. Cross-Border Data Transfers
Personal data may be transferred outside India for processing in accordance with applicable Indian law. We do not knowingly transfer personal data to jurisdictions restricted by the Government of India.
L. Children’s Data (Users Under 18 Years)
For users under 18 years of age, processing is based on verifiable consent of a parent or legal guardian, where required by law. Aroverse ProTech does not engage in tracking, behavioural monitoring, or targeted advertising directed at children.
M. Security Practices and Procedures
Aroverse ProTech applies reasonable administrative, technical, and physical safeguards to protect personal data and sensitive personal data, consistent with applicable Indian legal requirements.
5. Consent, Permissions, and In-App Disclosures
- We provide clear in-product disclosures for sensitive processing that may not be obvious from the immediate feature context.
- We request runtime permissions only where required and only for functionality relevant to the feature being used.
- We seek affirmative action for consent where legally required and provide mechanisms to withdraw consent.
- Withdrawing consent does not affect processing already completed lawfully before withdrawal.
7. Health Data Safeguards
- Health data is classified as sensitive data and handled with elevated controls.
- Access is role-based and limited to authorized users with a legitimate need.
- Data is encrypted in transit using HTTPS/TLS and encrypted at rest where supported.
- We apply retention controls, secure archival, and secure deletion where feasible.
- Aroverse ProTech maintains audit trails and records for authentication events, patient record access, record modifications, prescription generation, user administration activities, permission changes, and security-related events.
8. Retention and Deletion
We retain personal data only for as long as needed for service delivery, safety, legal compliance, and dispute resolution.
- Account data: retained while account is active and for required compliance periods after closure.
- Clinical records: Retained according to National Medical Commission (NMC) and jurisdiction specific legal requirements.
- Employee records: Retained for the duration of employment plus statutory tax and labor law retention periods.
- Logs and telemetry: retained for operational security and performance analysis for limited durations.
- Authorized healthcare organizations may request export of their data in a commercially reasonable format before termination of services, subject to legal and regulatory obligations.
- Upon termination of a subscription, customer data may be retained for a limited period to support data export, legal obligations, dispute resolution, security investigations, and backup recovery before secure deletion or anonymization.
Where permitted, data may be anonymized and retained for research, service quality, or analytics.
9. Your Privacy Rights
Subject to local law, you may have rights to:
- Access and receive a copy of your personal data.
- Correct inaccurate or incomplete data.
- Delete account and associated data (subject to legal retention obligations).
- Restrict or object to certain processing.
- Withdraw consent where processing is based on consent.
- Data portability where legally applicable.
- Opt out of non-essential marketing communications.
To submit a privacy or deletion request, email the Grievance Officer.
We may require identity verification before processing requests. We target response within 30 days unless local law permits a different timeline.
For users in India, additional and specific notices, rights, and grievance provisions are described in Section 4A above.
10. Account Deletion
Users can request deletion of their account through in-product settings (when available) or by emailing the Grievance Officer with the subject line “Account Deletion Request”. We will delete or de-identify eligible data, except where retention is required for legal, safety, audit, anti-fraud, clinical integrity, or regulatory reasons.
11. International Data Transfers
If data is processed outside your jurisdiction, we apply legally recognized safeguards (such as contractual clauses and equivalent protective controls) where required.
13. Security Practices
- Encryption in transit and at rest (where applicable).
- Role-based access controls and least-privilege design.
- Logging, monitoring, and incident response workflows. Periodic security testing and vulnerability management.
- Vendor due diligence for sub processors handling protected data.
- Aroverse ProTech maintains audit records for authentication events, patient record access, record modifications, prescription generation, user administration activities, permission changes, and security-related events.
- Aroverse ProTech maintains backup, disaster recovery, and business continuity processes designed to protect availability and integrity of customer data.
- Logical tenant segregation
- Multi-factor authentication support
- Session management controls
- Periodic access reviews
- Security event monitoring
- Administrative audit logging
14. Google Play and Apple App Store Disclosures
We maintain app-store privacy disclosures consistent with this policy, including declarations for data collection, use, sharing, encryption-in-transit status, and account/data deletion pathways where required.
- Google Play: User Data policy and Data Safety form alignment.
- Apple: App Privacy disclosures and in-app policy accessibility requirements.
15. Policy Updates
We may update this Privacy Policy from time to time. Material changes will be communicated through the Services or other appropriate channels.
16. Contact: Data Protection Officer & Grievance Redressal
Renuka SV
Data Protection Officer & Grievance Officer
Email: Renuka.sv@aroverse.in
Address: No. 51/75, 20th Main, 22nd Cross, Vijayanagar, Bangalore - 560040