Last updated: March 2026 · Effective: March 2026
SIDVIR PRIVATE LIMITED (“UBIQCURE”, “we”, “us”, “our”) is committed to protecting your privacy and the privacy of your children. This Privacy Policy describes how we collect, use, store, share, and protect personal data in connection with the UBIQCURE Platform (www.ubiqcure.com and associated apps and portals).
This Policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act); the Information Technology Act, 2000 and SPDI Rules, 2011; the EHR Standards for India, 2016; the NMC Telemedicine Practice Guidelines, 2020; and all other applicable Indian laws.
By using the Platform, you consent to the data practices described in this Policy.
4.1 Who we are (Data Fiduciary)
UBIQCURE (SIDVIR PRIVATE LIMITED) is the Data Fiduciary under the DPDP Act, 2023. This means we determine the purpose and means of processing your personal data. We have appointed a Data Protection Officer (DPO) responsible for overseeing data protection compliance. You may contact the DPO at: dpo@ubiqcure.com.
4.2 Information we collect
4.2.1 Information You Provide to Us
| Category | Specific Data Points | How Collected |
|---|---|---|
| Account Registration | Full name, phone number, email address, date of birth, gender | Registration form on app / website |
| Student Health Data (eHRC) | 46+ health parameters including height, weight, blood pressure, vision, hearing, dental, skin, nutritional status, immunisation records, and mental health screening score | Medical team during health screening camp |
| Uploaded Health Documents | Prescription images, lab reports, vaccination certificates, hospital records | Parent/user upload through portal |
| Payment Information | UPI ID (for refund purposes only), billing contact name. Card details are NOT collected — processed by Razorpay. | Payment gateway (Razorpay) |
| Communications | Support queries, call recordings (CS interactions), chat messages, feedback | Voluntarily provided by user |
| Parental Consent Records | Consent given/revoked, timestamp, OTP verification, IP address | Consent portal |
| Identity Documents (Partners) | Doctor/nurse: NMC/nursing council registration, degree certificates, Aadhaar/PAN. Diagnostic centres: NABL/NABH certificates. | Partner registration portal |
4.2.2 Information Collected Automatically
- Device information: device type, operating system, browser type, screen resolution.
- Log data: IP address, access timestamps, pages viewed, search queries.
- Location data: GPS location (for camp geo-attendance and for proximity-based search features). Location is collected only when you grant permission.
- Usage analytics: features used, time spent, clicks, navigation patterns — used only for product improvement.
- Cookies and similar technologies: session cookies (essential, cannot be disabled) and analytics cookies (you may opt out).
4.3 Legal basis for processing
| Purpose of Processing | Legal Basis | Data Involved |
|---|---|---|
| Providing healthcare services (appointment, consultation, test booking) | Consent + Contract | Name, contact, health history, appointment details |
| Child health screening (eHRC) | Explicit consent of parent/guardian (mandatory under DPDP Act for minor data) | Student health data (all 46+ parameters) |
| Processing payments | Contract + Legal obligation (GST) | Transaction details, invoice records |
| Verifying partner credentials (doctors, nurses, diagnostic centres) | Legitimate interest + Legal obligation (NMC compliance) | Registration numbers, qualifications, identity docs |
| Sending health reports, reminders, and alerts | Consent (expressed at registration) | Contact details, health data summaries |
| Improving the Platform and conducting analytics | Legitimate interest (anonymised, aggregate only) | Anonymised usage data; no personally identifiable data |
| Complying with legal requirements | Legal obligation | Any data required by court order, law, or regulatory authority |
| Resolving disputes and protecting legal interests | Legitimate interest | Transaction records, communication logs, audit logs |
4.4 How we use your information
- To create and manage your account and deliver the services you have subscribed to.
- To connect patients with doctors, nurses, clinics, hospitals, and diagnostic centres.
- To generate Electronic Health Report Cards (eHRC) for students and deliver them to parents and schools.
- To calculate health scores, generate AI-powered health insights, and create personalised health recommendations.
- To send appointment confirmations, reminders, health alerts, vaccination reminders, and service updates via SMS, email, WhatsApp, and push notifications.
- To process payments and issue GST-compliant invoices.
- To verify the identity and credentials of healthcare professionals listed on the Platform.
- To comply with legal obligations, including responding to government or regulatory requests and court orders.
- To investigate fraud, security incidents, or violations of our Terms.
We do NOT use your personal data to show advertisements. UBIQCURE is an ad-free platform.
We do NOT sell, rent, or trade your personal data to any third party for commercial or marketing purposes.
4.5 Sharing of information
With Healthcare Professionals (Your Consent Required)
When you book an appointment, a virtual consultation, or a health test, your relevant health information is shared with the treating doctor, nurse, or diagnostic centre. This sharing requires your explicit consent, which you grant when you make a booking. You may withdraw consent to share your health record with a specific professional at any time from your portal.
With Schools (eHRC)
Under the eHRC service, your child’s health data is shared with the school’s authorised staff (Principal, Class Incharge, Class Teacher) in an aggregated and appropriately anonymised format for school-wide analytics. Individually identifiable health records are accessible only to the Principal and, where applicable, the Class Teacher. The school does not have the right to share your child’s data with any third party.
With Third-Party Service Providers
We use trusted third-party service providers to operate the Platform (cloud hosting, payment processing, SMS, email delivery, video calling infrastructure). These providers are bound by data processing agreements and are not permitted to use your data for any purpose beyond performing the services they provide to UBIQCURE. Key providers include: AWS (cloud infrastructure — India region only), Razorpay (payments), MSG91 (SMS), AWS SES (email), Daily.co/Twilio (video).
For Legal Compliance
We may disclose your data when required by law, court order, or a request from a government authority in accordance with applicable law. We will, where legally permissible, notify you of such a request before disclosure.
We Will Never
- Sell your personal or health data to any third party.
- Share your data with insurance companies, pharmaceutical companies, or employers without your explicit written consent.
- Use children’s health data for advertising or profiling.
4.6 Children’s data — special protections
UBIQCURE takes the privacy of children extremely seriously. In compliance with the DPDP Act 2023 and the POCSO Act provisions regarding minors:
- No health data of a child (under 18) is collected without the prior, explicit, and verifiable consent of a parent or legal guardian.
- Children under 13 years of age do not have independent login accounts. All data is accessible only through the parent’s verified account.
- Children aged 13 to 17 may be issued a limited student login, but only with parental consent recorded on the Platform.
- Children’s health data is never used for advertising, profiling, or any commercial purpose.
- Schools do not have the right to access individually identifiable student health data for any purpose other than educational administration and analytical reports within the scope of the eHRC service.
4.7 Your rights (DPDP Act, 2023)
| Your Right | What It Means | How to Exercise It |
|---|---|---|
| Right to Information | Know what personal data we hold about you and how it is being used. | Log in to your portal under ‘Account & Privacy’ or email support@ubiqcure.com |
| Right to Correction | Request correction of inaccurate or incomplete personal data. | Submit a correction request from your portal or email support@ubiqcure.com. We will respond within 7 days. |
| Right to Erasure (Right to be Forgotten) | Request deletion of your personal data when it is no longer required for the purpose it was collected. | Email support@ubiqcure.com. Note: health records required for ongoing service delivery cannot be deleted while the service is active. Clinical records are anonymised after the retention period. |
| Right to Withdraw Consent | Withdraw your consent to the processing of your data at any time. | In-portal consent management under ‘Account & Privacy’. Withdrawal takes effect within 48 hours. |
| Right to Data Portability | Receive your personal data in a structured, machine-readable format. | Email support@ubiqcure.com. Data will be provided within 15 days. |
| Right to Grievance Redressal | Lodge a complaint with UBIQCURE’s Grievance Officer. | Email support@ubiqcure.com. Acknowledged within 48 hours; resolved within 7 days. |
4.8 Data retention
| Data Category | Retention Period | Action After Retention |
|---|---|---|
| Student eHRC health records | Minimum 7 years from last service interaction | Anonymised (names and contact details replaced with random tokens). Aggregate data retained for public health research. |
| Consultation records and e-prescriptions | Minimum 7 years (as per NMC guidelines) | Archived in anonymised form |
| Audit logs | 7 years | Permanent retention (tamper-evident chain) |
| Payment records and invoices | 8 years (GST compliance requirement) | Securely archived |
| Account data (inactive accounts) | 3 years from last login, then anonymised | Soft-deleted; personal identifiers removed |
| Support ticket records | 3 years | Archived |
| Call recordings (CS interactions) | 90 days (3 years for escalated cases) | Permanently deleted after retention period |
4.9 Data security
We implement industry-standard security measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. Our key security measures include:
- Encryption in transit: All data transmitted between your device and UBIQCURE’s servers is encrypted using TLS 1.3.
- Encryption at rest: All personal and health data stored in our databases is encrypted using AES-256 encryption.
- Access controls: Role-based access controls ensure that only authorised UBIQCURE staff can access personal data, and only to the extent necessary for their role.
- Audit logging: All access to personal data and all system actions are logged in a tamper-evident audit system.
- Payment security: We do not store card numbers or bank account details. All payment data is handled by Razorpay (PCI-DSS Level 1 certified).
- Penetration testing: We conduct annual security audits (VAPT) by CERT-In empanelled agencies.
Despite these measures, no data transmission over the internet can be guaranteed as 100% secure. If we discover a data breach likely to result in a risk to your rights, we will notify you and the relevant authorities (CERT-In) in accordance with the DPDP Act, 2023 and CERT-In Directions, 2022.
4.10 Data localisation
All personal data and health data collected by UBIQCURE is stored exclusively on servers located within India (AWS Mumbai region, ap-south-1). UBIQCURE does not transfer personal data outside India without meeting the conditions prescribed under applicable Indian law.
4.11 Changes to this policy
We may update this Privacy Policy periodically. Material changes will be notified to you via email or in-app notification at least 15 days before the change takes effect. Your continued use of the Platform after the effective date of the revised Policy constitutes your acceptance of the changes.
4.12 Privacy contact
For all privacy-related queries, rights requests, and data complaints, contact:
| Data Protection Officer (DPO) | SIDVIR PRIVATE LIMITED |
|---|---|
| dpo@ubiqcure.com | |
| Postal Address | 403, Skyline Plaza, Sushant Golf City, Lucknow, UP – 226030 |
Source: Website Content Document · Terms · Refund · Contact · Home