Privacy Policy
Last updated: 21 Jul 2026
The following is drawn from the ZAYUSH Healthcare Services Official Policy & Governance Handbook.
3.1 Scope and Acceptance
This Policy applies to all persons who access or use the Platform, including patients, caregivers, empanelled healthcare professionals, and visitors. By using the Platform, providing information through any channel (including WhatsApp, telephone, or email), or booking a service, the user consents to the practices described in this Policy. Users who do not agree with this Policy should refrain from using the Platform.
3.2 Information Collected
3.2.1 Personal Information
- Name, age, date of birth, and gender;
- Contact details: mobile number, alternate contact number, email address;
- Residential or service address, including landmarks provided for locating the premises;
- Government-issued identity information where provided for verification purposes;
- Caregiver or emergency-contact details provided by the patient or family;
- For professionals: qualification certificates, professional registration details, KYC documents,
bank account details for settlements, and background-verification records.
3.2.2 Medical Information
- The nature of the service requested and relevant medical context provided by the patient or
caregiver;
- Prescriptions, treating practitioner’s advice, and referral notes uploaded or shared for
prescription-dependent services;
- Service records created during or after a visit, such as visit confirmations, procedure notes,
and observations recorded by the assigned professional;
- Feedback and complaint records that may contain health-related content.
IMPORTANT NOTE Medical information is treated as sensitive personal data. It is collected only to the extent necessary to verify, assign, deliver, and document the requested service, and is handled under the heightened safeguards described in this Policy.
3.2.3 Location Data
- Service address entered by the user;
- Device location, where the user grants permission through the Android application, used to
assist address accuracy and professional assignment;
- Professional location during active assignments, where permission is granted, used for dispatch
coordination and safety.
3.2.4 Device Information
- Device model, operating system and version, application version, device identifiers, and
language settings;
- IP address, access timestamps, and usage logs;
- Crash reports and diagnostic data used to maintain Platform stability.
3.2.5 Payment Information
- Transaction amount, payment method, transaction reference, and settlement status;
- Payments are processed through authorised third-party payment gateways and payment
methods. The Company does not store complete card numbers, CVV, UPI PINs, or banking passwords on its own systems.
3.3 How Information Is Used
Information is used for the following purposes:
- verifying service requests, patient identity, and service addresses;
- verifying, empanelling, and managing healthcare professionals;
- assigning appropriate professionals to verified requests;
- facilitating and documenting service delivery, including prescription verification for
prescription-dependent services;
- processing payments, issuing receipts, and managing settlements and refunds;
- communicating booking confirmations, schedule changes, service updates, and support
responses through the user’s chosen channels, including WhatsApp, SMS, telephone, and email;
- operating quality assurance, grievance redressal, incident management, and fraud prevention;
- complying with legal obligations and responding to lawful requests from authorities;
- improving Platform functionality, safety, and user experience through aggregated and, where
feasible, anonymised analysis; and
- sending service-related notices and, subject to consent and opt-out rights, informational
updates about Platform services.
The Company does not sell personal information. The Company does not use medical information for advertising.
3.4 Data Storage
- Data is stored on secured servers and reputable cloud infrastructure engaged by the Company,
with storage practices aligned to applicable Indian data-protection requirements, including any data-localisation requirements in force.
- Physical documents received during onboarding or operations are stored securely with
restricted access and are digitised where practicable.
- Access to stored data is role-based and limited to personnel who require it for the purposes
stated in this Policy.
3.5 Data Protection and Security Measures
The Company implements reasonable security practices and procedures, including:
- encryption of data in transit and, where supported by the infrastructure employed, at rest;
- role-based access controls, unique credentials, and least-privilege administration;
- secured payment processing exclusively through authorised gateways;
- audit logging of access to sensitive records;
- confidentiality obligations binding all employees and empanelled professionals;
- periodic review of security practices, vendors, and access rights; and
- a documented incident-response process for suspected data breaches, including notification
to affected users and authorities where required by law.
3.6 Data Sharing
Personal information is shared only as follows:
- With the assigned professional: the patient’s name, contact details, service address, service
requirements, and relevant medical context necessary to deliver the booked service safely.
- With the patient: the assigned professional’s name, photograph, professional category, and
verification status.
- With diagnostic laboratories: for blood sample collection services, the information necessary
to register and process the sample with the laboratory selected by the patient or directed by the prescribing practitioner.
- With service providers: payment gateways, cloud hosting, communication services (includ-
ing WhatsApp Business infrastructure), and verification agencies, in each case limited to the data required for their function and bound by contractual confidentiality obligations.
- With authorities: where required by law, court order, or lawful request of a governmental or
regulatory authority.
- In a business transaction: in connection with a merger, acquisition, financing, or restructur-
ing, subject to confidentiality and continuity of this Policy’s protections.
Empanelled professionals receive patient information solely for delivering the assigned service. Any use of patient information beyond the assignment — including private solicita- tion, disclosure to third parties, or retention after service completion — is prohibited and constitutes grounds for termination and legal action.
3.7 Third-Party Services
The Platform relies on third-party services, including payment gateways, mapping and location services, cloud infrastructure, analytics, and WhatsApp Business messaging. These providers process data under their own privacy policies in addition to contractual obligations to the Company. Users are encouraged to review the privacy policies of third-party services they interact with. The Company is not responsible for the independent practices of third-party platforms beyond the safeguards it contractually imposes.
3.8 Cookies and Similar Technologies
The website uses cookies and similar technologies to maintain sessions, remember preferences, measure usage, and improve functionality. Users may control cookies through browser set- tings; disabling cookies may limit certain Platform features. The Android application may use comparable identifiers and local storage for equivalent purposes.
3.9 Patient Rights
Subject to applicable law, patients and other users have the right to:
- access the personal information the Company holds about them;
- request correction of inaccurate or incomplete information;
- withdraw consent for processing, subject to the consequence that certain services may no
longer be deliverable;
- request deletion of personal information, subject to legal and operational retention require-
ments;
- obtain information about the categories of data shared and the purposes of sharing;
- register grievances with the Company’s designated grievance contact and receive a time-bound
response; and
- exercise any additional rights conferred by the Digital Personal Data Protection Act, 2023,
and rules thereunder, as and when in force.
3.10 Professional Rights
Empanelled professionals have the right to access and correct their onboarding and profile data, to receive statements of settlements, and to request deletion of their data upon exit from the Platform, subject to retention required for legal, tax, dispute-resolution, and audit purposes. Verification records may be retained as required to evidence the Company’s due diligence.
3.11 Data Retention
- Service and booking records are retained for the period necessary for operational continuity,
dispute resolution, and compliance with applicable legal and tax requirements.
- Medical information linked to a service is retained no longer than necessary for those purposes,
after which it is deleted or anonymised.
- Payment and financial records are retained as mandated by applicable tax and accounting
law.
- Records relating to complaints, incidents, and legal disputes are retained until the matter is
conclusively resolved and applicable limitation periods have expired.
3.12 Deletion Requests
Users may request deletion of their account and associated personal information through any official support channel. Upon a verified request, the Company will delete or anonymise the user’s personal information within a reasonable period, except where retention is required by law, for the completion of pending transactions, for the resolution of pending disputes, or for the establishment or defence of legal claims. The Company will confirm the action taken to the requester.
3.13 Children’s Data
The Platform is intended for use by adults. Services for minors must be requested and managed by a parent or lawful guardian, who provides consent and information on the minor’s behalf. The Company does not knowingly permit minors to operate accounts independently.
3.14 Legal Compliance
This Policy is intended to operate in compliance with applicable Indian law, including the Information Technology Act, 2000, the SPDI Rules, 2011, the Digital Personal Data Protection Act, 2023 (as and when its provisions are brought into force), and the Consumer Protection Act, 2019, together with rules made thereunder. In the event of conflict between this Policy and applicable
law, the law prevails. Subject to applicable Indian laws and professional legal review.
3.15 Changes to This Policy
The Company may update this Policy from time to time. Material changes will be notified through the Platform. Continued use of the Platform after notification constitutes acceptance of the updated Policy.