Privacy Policy

Last updated: 21 Jul 2026

The following is drawn from the ZAYUSH Healthcare Services Official Policy & Governance Handbook.

3.1 Scope and Acceptance

This Policy applies to all persons who access or use the Platform, including patients, caregivers, empanelled healthcare professionals, and visitors. By using the Platform, providing information through any channel (including WhatsApp, telephone, or email), or booking a service, the user consents to the practices described in this Policy. Users who do not agree with this Policy should refrain from using the Platform.

3.2 Information Collected

3.2.1 Personal Information

  • Name, age, date of birth, and gender;
  • Contact details: mobile number, alternate contact number, email address;
  • Residential or service address, including landmarks provided for locating the premises;
  • Government-issued identity information where provided for verification purposes;
  • Caregiver or emergency-contact details provided by the patient or family;
  • For professionals: qualification certificates, professional registration details, KYC documents,

bank account details for settlements, and background-verification records.

3.2.2 Medical Information

  • The nature of the service requested and relevant medical context provided by the patient or

caregiver;

  • Prescriptions, treating practitioner’s advice, and referral notes uploaded or shared for

prescription-dependent services;

  • Service records created during or after a visit, such as visit confirmations, procedure notes,

and observations recorded by the assigned professional;

  • Feedback and complaint records that may contain health-related content.

IMPORTANT NOTE Medical information is treated as sensitive personal data. It is collected only to the extent necessary to verify, assign, deliver, and document the requested service, and is handled under the heightened safeguards described in this Policy.

3.2.3 Location Data

  • Service address entered by the user;
  • Device location, where the user grants permission through the Android application, used to

assist address accuracy and professional assignment;

  • Professional location during active assignments, where permission is granted, used for dispatch

coordination and safety.

3.2.4 Device Information

  • Device model, operating system and version, application version, device identifiers, and

language settings;

  • IP address, access timestamps, and usage logs;
  • Crash reports and diagnostic data used to maintain Platform stability.

3.2.5 Payment Information

  • Transaction amount, payment method, transaction reference, and settlement status;
  • Payments are processed through authorised third-party payment gateways and payment

methods. The Company does not store complete card numbers, CVV, UPI PINs, or banking passwords on its own systems.

3.3 How Information Is Used

Information is used for the following purposes:

  • verifying service requests, patient identity, and service addresses;
  • verifying, empanelling, and managing healthcare professionals;
  • assigning appropriate professionals to verified requests;
  • facilitating and documenting service delivery, including prescription verification for

prescription-dependent services;

  • processing payments, issuing receipts, and managing settlements and refunds;
  • communicating booking confirmations, schedule changes, service updates, and support

responses through the user’s chosen channels, including WhatsApp, SMS, telephone, and email;

  • operating quality assurance, grievance redressal, incident management, and fraud prevention;
  • complying with legal obligations and responding to lawful requests from authorities;
  • improving Platform functionality, safety, and user experience through aggregated and, where

feasible, anonymised analysis; and

  • sending service-related notices and, subject to consent and opt-out rights, informational

updates about Platform services.

The Company does not sell personal information. The Company does not use medical information for advertising.

3.4 Data Storage
  • Data is stored on secured servers and reputable cloud infrastructure engaged by the Company,

with storage practices aligned to applicable Indian data-protection requirements, including any data-localisation requirements in force.

  • Physical documents received during onboarding or operations are stored securely with

restricted access and are digitised where practicable.

  • Access to stored data is role-based and limited to personnel who require it for the purposes

stated in this Policy.

3.5 Data Protection and Security Measures

The Company implements reasonable security practices and procedures, including:

  • encryption of data in transit and, where supported by the infrastructure employed, at rest;
  • role-based access controls, unique credentials, and least-privilege administration;
  • secured payment processing exclusively through authorised gateways;
  • audit logging of access to sensitive records;
  • confidentiality obligations binding all employees and empanelled professionals;
  • periodic review of security practices, vendors, and access rights; and
  • a documented incident-response process for suspected data breaches, including notification

to affected users and authorities where required by law.

3.6 Data Sharing

Personal information is shared only as follows:

  • With the assigned professional: the patient’s name, contact details, service address, service

requirements, and relevant medical context necessary to deliver the booked service safely.

  • With the patient: the assigned professional’s name, photograph, professional category, and

verification status.

  • With diagnostic laboratories: for blood sample collection services, the information necessary

to register and process the sample with the laboratory selected by the patient or directed by the prescribing practitioner.

  • With service providers: payment gateways, cloud hosting, communication services (includ-

ing WhatsApp Business infrastructure), and verification agencies, in each case limited to the data required for their function and bound by contractual confidentiality obligations.

  • With authorities: where required by law, court order, or lawful request of a governmental or

regulatory authority.

  • In a business transaction: in connection with a merger, acquisition, financing, or restructur-

ing, subject to confidentiality and continuity of this Policy’s protections.

Empanelled professionals receive patient information solely for delivering the assigned service. Any use of patient information beyond the assignment — including private solicita- tion, disclosure to third parties, or retention after service completion — is prohibited and constitutes grounds for termination and legal action.

3.7 Third-Party Services

The Platform relies on third-party services, including payment gateways, mapping and location services, cloud infrastructure, analytics, and WhatsApp Business messaging. These providers process data under their own privacy policies in addition to contractual obligations to the Company. Users are encouraged to review the privacy policies of third-party services they interact with. The Company is not responsible for the independent practices of third-party platforms beyond the safeguards it contractually imposes.

3.8 Cookies and Similar Technologies

The website uses cookies and similar technologies to maintain sessions, remember preferences, measure usage, and improve functionality. Users may control cookies through browser set- tings; disabling cookies may limit certain Platform features. The Android application may use comparable identifiers and local storage for equivalent purposes.

3.9 Patient Rights

Subject to applicable law, patients and other users have the right to:

  • access the personal information the Company holds about them;
  • request correction of inaccurate or incomplete information;
  • withdraw consent for processing, subject to the consequence that certain services may no

longer be deliverable;

  • request deletion of personal information, subject to legal and operational retention require-

ments;

  • obtain information about the categories of data shared and the purposes of sharing;
  • register grievances with the Company’s designated grievance contact and receive a time-bound

response; and

  • exercise any additional rights conferred by the Digital Personal Data Protection Act, 2023,

and rules thereunder, as and when in force.

3.10 Professional Rights

Empanelled professionals have the right to access and correct their onboarding and profile data, to receive statements of settlements, and to request deletion of their data upon exit from the Platform, subject to retention required for legal, tax, dispute-resolution, and audit purposes. Verification records may be retained as required to evidence the Company’s due diligence.

3.11 Data Retention
  • Service and booking records are retained for the period necessary for operational continuity,

dispute resolution, and compliance with applicable legal and tax requirements.

  • Medical information linked to a service is retained no longer than necessary for those purposes,

after which it is deleted or anonymised.

  • Payment and financial records are retained as mandated by applicable tax and accounting

law.

  • Records relating to complaints, incidents, and legal disputes are retained until the matter is

conclusively resolved and applicable limitation periods have expired.

3.12 Deletion Requests

Users may request deletion of their account and associated personal information through any official support channel. Upon a verified request, the Company will delete or anonymise the user’s personal information within a reasonable period, except where retention is required by law, for the completion of pending transactions, for the resolution of pending disputes, or for the establishment or defence of legal claims. The Company will confirm the action taken to the requester.

3.13 Children’s Data

The Platform is intended for use by adults. Services for minors must be requested and managed by a parent or lawful guardian, who provides consent and information on the minor’s behalf. The Company does not knowingly permit minors to operate accounts independently.

3.14 Legal Compliance

This Policy is intended to operate in compliance with applicable Indian law, including the Information Technology Act, 2000, the SPDI Rules, 2011, the Digital Personal Data Protection Act, 2023 (as and when its provisions are brought into force), and the Consumer Protection Act, 2019, together with rules made thereunder. In the event of conflict between this Policy and applicable

law, the law prevails. Subject to applicable Indian laws and professional legal review.

3.15 Changes to This Policy

The Company may update this Policy from time to time. Material changes will be notified through the Platform. Continued use of the Platform after notification constitutes acceptance of the updated Policy.

Chat with us