Privacy Policy

v1.1First published: 15 October 2025Last updated: 1 September 2026Effective: 1 October 2026

This policy explains how hospiDule, a product of Narra Technologies Private Limited, collects, uses, and protects your personal and health data under applicable data protection law.

Introduction

Welcome to hospiDule, a product of Narra Technologies Private Limited ("Narra"). We are committed to protecting your privacy and being transparent about how we collect, use, and protect your personal and health data.

This Privacy Policy applies to:

  • Our website (hospidule.com)
  • Our web-based SaaS platform
  • Our mobile applications (iOS and Android)
  • Our APIs and integrations
  • Our email communications

This policy is designed to comply with applicable data protection law. Concerns can be raised with the relevant data protection authority. If you do not agree with this Privacy Policy, please do not use our services.

Healthcare and commerce deployments

Narra is sold in two configurations, and this policy covers both.

  • Healthcare deployments process health data. Every section of this policy applies.
  • Commerce deployments (for example grossDule, storeDule, and webDule) process customer, order, and business data. They do not process Protected Health Information. The health-data, clinical, and national-health-network sections of this policy have no subject matter in a commerce deployment; everything else applies unchanged.

Definitions

Key terms used throughout this policy:

Personal Data
Any information that can be used to identify you directly or indirectly (for example name, email, phone number, IP address).
Health Data / PHI
Sensitive personal health information, including medical records, diagnostic results, prescriptions, vitals, allergies, and treatment history. Treated as a special category of personal data under GDPR Article 9 and as sensitive personal data under India's DPDP Act 2023.
Data Principal
You: the person whose data we collect. Also called "Data Subject" under GDPR.
Data Fiduciary
The organisation that determines how and why your data is processed. Also called "Controller" under GDPR. Which party holds this role depends on how you use Narra: see "Who is the Controller" below.
Data Processor
A party that processes data on behalf of a Controller (for example a cloud provider or a payment processor). All processors are bound by contract to meet our security standards.
EMR / EHR
Electronic Medical Record / Electronic Health Record: digital health records maintained by healthcare providers.
Processing
Any activity we perform with your data (collecting, storing, analysing, sharing, deleting, and so on).
Breach
Unauthorized access, disclosure, alteration, or loss of personal data. This definition is used consistently across this policy, our Terms of Service, our Data Processing Agreement, and our Business Associate Agreement.

National health network terms

These terms apply to customers using India's national health network.

ABHA
Ayushman Bharat Health Account: a unique 14-digit health identifier issued under India's Ayushman Bharat Digital Mission.
ABDM
Ayushman Bharat Digital Mission: India's national digital health network.

Who We Are

Legal entity
Narra Technologies Private Limited
Website
hospidule.com
Data Protection Officer
dpo@narrahealthcare.com
Privacy requests
privacy@narrahealthcare.com
General Support
support@narrahealthcare.com
Registered office
Hyderabad, Telangana, India. The full registered address is provided on request from legal@narrahealthcare.com and appears on any invoice or Order Form.

We build software for healthcare and commerce organisations and the people they serve.

Who is the Controller

Which role we hold depends on how you reached us.

  • You signed up with us directly (for example an individual account, or a business buying a subscription): we are the Controller, and this policy governs.
  • Your healthcare provider or your employer gave you access: that organisation is the Controller and decides why your data is processed. We act as their Processor under our Data Processing Agreement, and you should read their privacy notice alongside this one. We will still help you exercise your rights, but we may need to route your request to them.

For our own website analytics, marketing, and billing, we are always the Controller.

Registration status

We are not currently registered as a Significant Data Fiduciary under India's DPDP Act 2023. If the Act's thresholds come to apply to an entity of our size, we will register and publish the reference here.

What Data We Collect

We collect different types of data depending on how you interact with hospiDule.

1. Identity Data

Full name, date of birth, gender, and unique identifiers including your hospiDule account ID. In a healthcare deployment this may also include a national health identifier such as an ABHA ID, and, only where required by law and with explicit consent, a government identity number. Collected when you sign up or when your healthcare provider creates your record. Name, date of birth, and gender are mandatory to create an account.

2. Contact Data

Mobile phone number, email address, postal address, and emergency contact information. Phone number and email are required for account recovery and notifications.

3. Health & Clinical Data (special category data)

Applies to healthcare deployments. Laboratory test results, diagnostic images, vital signs, medical diagnoses, allergies, medications, prescriptions, treatment history, discharge summaries, procedure records, immunisation records, and family health history (if provided).

Health data is only collected with your explicit, informed consent, or on the instruction of the healthcare provider who is the Controller for it. You have control over which data is shared and with whom. Health data is treated as a special category under GDPR Article 9 and as sensitive personal data under India's DPDP Act 2023, because unauthorised disclosure could harm your privacy, medical autonomy, or insurance eligibility.

4. Usage & Device Data

IP address, browser type and version, operating system, device type, pages visited and time spent, clicks and interactions, and error logs. Collected automatically through cookies and server logs. We do not store raw IP addresses longer than necessary.

5. Transactional & Financial Data

Payment method information (card type, last 4 digits), transaction IDs, invoice records, insurance policy numbers, and billing address. Collected only if you purchase paid services. hospiDule does not store full card numbers. Our payment processor handles all sensitive payment data.

6. Support & Communications Data

Support tickets, email communications, call recordings (only with consent), feedback and survey responses, and chat transcripts. Collected only when you contact us.

7. Special Categories

Data about minors (if a parent or guardian creates an account for a child), mental health data (if disclosed in clinical records), and genetic or biometric data (only if explicitly shared). None of these categories are mandatory and are collected only with explicit consent.

How We Use Your Data

Essential uses (required to provide the service)

  • Creating and managing your records: maintaining your health or business record, integrating records from multiple sources, and enabling you to access your own data at any time.
  • Enabling collaboration: in a healthcare deployment, sharing health records with your treating doctors and healthcare providers. You control which providers can access which records and can revoke access at any time.
  • National health network integration: where such a network is available in your country, linking your hospiDule account to it and syncing records. In India this is ABHA and ABDM. Optional; you can revoke access through that network's consent manager.
  • Notifications & reminders: test result notifications, appointment reminders, order updates, and alerts.

Secondary uses (improving service & compliance)

  • Analytics & product improvement: anonymised usage trends to improve the platform. You can opt out of non-essential analytics in account settings.
  • Fraud prevention & platform security: monitoring for unauthorised access, maintaining audit logs. Non-optional for security reasons; we use the minimum data necessary.
  • Billing & account management: processing payments, generating invoices.
  • Legal compliance & audit: complying with court orders, regulatory investigations, and maintaining audit records.

Tertiary uses (with explicit consent)

  • Marketing & communications: emails about new features, events, and health tips. Entirely optional; you can unsubscribe at any time.
  • Research & clinical insights: de-identified research on health trends. You can opt out during sign-up; opting out does not affect your use of hospiDule.

What we do not do with your data

We do not use identifiable personal or health data to train, fine-tune, or evaluate machine-learning models without your separate, explicit, opt-in consent. We do not sell your data, and we do not use it for advertising. These limits are also written into our Terms of Service and our Business Associate Agreement.

Who We Share Your Data With

Your health data is private by default. We only share it when necessary and with your permission.

Healthcare providers (with your authorisation)

Doctors, hospitals, diagnostic centres, and other providers in our network. You explicitly authorise each provider, can limit what they see, and can revoke access at any time. All providers sign a Data Processing Agreement (DPA) or Business Associate Agreement (BAA).

National health networks (with your consent)

Where you link a national health account, other providers, personal health record apps, and government health programmes connected to that network may access what you share. In India this is the ABDM ecosystem, linked through your ABHA. Linking is optional and you can revoke consent through that network's consent manager. Once data is shared into such a network, other registered participants may access it. This is the intended purpose of a national health network.

Cloud & technology service providers

Encrypted data is processed by our cloud infrastructure, payment processors, SMS gateways, and email services. Raw health data is never shared unencrypted. The complete, current list of these sub-processors, with purpose and location, is published in our Data Processing Agreement, and we give 30 days notice before adding a new one. All vendors sign data processing agreements with strict security requirements including AES-256 encryption, access controls, and breach notification within 24 hours.

Our employees & support team

Staff with a legitimate need (support, compliance), governed by strict Role-Based Access Control (RBAC), mandatory MFA, and comprehensive audit logging. Access is granted only to resolve support issues or technical problems.

Law enforcement & regulatory bodies (when legally required)

Government agencies, courts, and tax authorities, only in response to valid legal process. We object to overly broad requests, share only what is legally required, and notify you when legally permitted to do so. We do not voluntarily share your data with law enforcement.

Researchers & academic institutions (with consent)

De-identified and anonymised health data only, with your explicit opt-in consent, and under a written agreement that prohibits re-identification.

What we do NOT do

  • Sell your personal or health data to third parties
  • Share data with insurance companies for underwriting without explicit consent
  • Share data with employers
  • Share data with pharmaceutical companies without anonymisation and explicit consent
  • Rent or lease your data
  • Combine your data with data from other companies for marketing purposes

Data Retention

We keep your data only as long as necessary for the purpose it was collected. These periods are the same in our Terms of Service, Data Processing Agreement, Business Associate Agreement, and Data Security Statement.

Health and business records
Retained for the life of your account. On account deletion, data is irreversibly destroyed within 30 days, except where a longer period is required by law.
After termination of a business subscription
Retained for 30 days so the account holder can export it, then deleted. A certificate of deletion is available on request.
Support & operational data
1–3 years after your last interaction (support tickets: 2 years; chat transcripts: 1 year; call recordings: 90 days).
Analytics & usage data
1–2 years, aggregated and anonymised.
Billing & financial records
Up to 7 years, or the period required by the tax law of your billing jurisdiction. In India this is 7 years.
Audit logs
5 years, or the longer period required by applicable law.
Cookies & tracking data
Session cookies: until you close the browser. Persistent cookies: up to 24 months.
National health network data
As long as your account on that network exists, or until you revoke consent through its consent manager. Data already synced into the network is governed by that network, not by us.
Breach notification records
5 years, or the period required by applicable law.

Your Rights

Under applicable data protection law, and under GDPR where it applies to you, you have the following rights. Exercising them is free, and we respond within 30 days.

Right to Access

You may request a copy of all personal data we hold about you. Email dpo@narrahealthcare.com with the subject "Data Access Request" or use Account Settings → Privacy → Download My Data. We will respond within 30 days at no cost.

Right to Correction

You may correct inaccurate or incomplete data. Update contact data directly in Account Settings → Profile. For health data, contact your healthcare provider or email our DPO. Timeline: 30 days.

Right to Erasure

You may request permanent deletion of your data via Account Settings → Delete Account. Data will be irreversibly deleted within 30 days. We may retain de-identified data where you have consented, and must retain records required by law. Deleted health records cannot be recovered.

Right to Restrict Processing

You may ask us to limit how we use your data while investigating an issue. Email dpo@narrahealthcare.com with the subject "Request to Restrict Processing". Timeline: 30 days.

Right to Data Portability

You may request your data in a portable format (CSV, JSON, PDF) via Account Settings → Privacy → Download My Data. Timeline: 30 days.

Right to Object

You may object to processing of your data for marketing or research by unsubscribing or emailing our DPO. Marketing objections take effect immediately; other processing within 30 days.

Rights relating to automated decisions

We do not make decisions that produce legal or similarly significant effects about you by automated means alone. If that ever changes, we will tell you, explain the logic involved, and give you the right to obtain human review.

Right to Nominate

Where India's DPDP Act 2023 applies to you, you may nominate another individual to exercise your rights in the event of your death or incapacity. Contact our DPO to record a nomination.

Right to Lodge a Complaint

  • To us first (recommended): Email dpo@narrahealthcare.com with the subject "Privacy Complaint". We will investigate and respond within 30 days, and in any event within the period required by applicable law.
  • To your regulator: You may complain to the relevant data protection authority at any time, whether or not you contact us first.

United States Privacy Rights (CCPA / CPRA)

This section applies to California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act, and we extend the same rights to residents of other US states with comparable privacy laws. It supplements, and does not replace, the rest of this policy.

Notice at collection

The categories of personal information we collect, the purposes we collect them for, and how long we keep them are set out in "What Data We Collect", "How We Use Your Data", and "Data Retention" above. In CCPA terms we collect identifiers, personal records, commercial information, internet activity, geolocation inferred from IP address, and, in a healthcare deployment, sensitive personal information in the form of health data.

We do not sell or share your personal information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding 12 months, including for consumers we knew to be under 16. Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" opt-out to operate. If that ever changes, we will update this section and provide the required opt-out before any such disclosure begins.

Limiting the use of sensitive personal information

We use sensitive personal information only to provide the service you asked for, to secure it, and to comply with law. We do not use it to infer characteristics about you. This is within the exemptions in the CCPA regulations, so the "Limit the Use of My Sensitive Personal Information" right does not change how we handle it. You may still ask us to restrict processing under the Right to Restrict Processing above.

Your rights

  • Right to know the categories and specific pieces of personal information we have collected, the sources, the business purpose, and the categories of third parties we disclosed it to, covering at least the preceding 12 months and, on request, the period since 1 January 2022.
  • Right to delete personal information we collected from you, subject to the statutory exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of sale or sharing. See above: we do neither.
  • Right to limit use of sensitive personal information. See above.
  • Right to non-discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right. We do not operate financial incentive programmes for personal information.

How to exercise these rights

Email dpo@narrahealthcare.com with the subject "US Privacy Request", or use Account Settings → Privacy. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days if we tell you why. We verify your identity against information already in your account before acting.

Authorised agents

An authorised agent may submit a request on your behalf. We will ask for written permission signed by you, and we may ask you to verify your own identity directly with us.

Health data

Protected Health Information handled under our Business Associate Agreement is exempt from the CCPA. Requests about that data are handled under HIPAA and the relevant health data law, and we will route them to the healthcare provider who is the covered entity.

Global Privacy Control

We honour the Global Privacy Control (GPC) signal. Because we do not sell or share personal information, GPC has no sale to stop, but we treat it as an opt-out of all non-essential analytics and tracking.

Data Residency & International Transfers

Where your data is today

Our production platform runs on Google Cloud Platform in the asia-south1 (Mumbai, India) region, which is our primary hosting region for all customers. Backups are replicated within India. Our managed database and application hosting services run in the same region.

This is a statement of current fact, not a promise about the future. We will update this section before we change region, and material changes are notified under the Changes to This Policy section.

Regional residency options

Additional residency regions, including the EU, the UK, and the United States, are on our roadmap and are not available today. We do not currently offer a contractual data-residency commitment outside India. If regional residency is a requirement for you, raise it before you sign: we will tell you honestly whether we can meet it, and any commitment we can make will be recorded in your Order Form rather than implied here.

What this means if you are outside India

If you are in the EU, the EEA, the UK, or another country whose law restricts international transfers, using our service today means your personal data is transferred to and stored in India. India has not received an adequacy decision from the European Commission or the UK government. We rely on the following safeguards for that transfer:

  • EU Standard Contractual Clauses: the Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor) where you are our customer and we process on your behalf, and Module Three (processor to processor) for onward transfers to our sub-processors. These are incorporated into our Data Processing Agreement.
  • UK transfers: the UK International Data Transfer Addendum to the EU SCCs, issued under section 119A of the Data Protection Act 2018.
  • Swiss transfers: the EU SCCs as amended by the Swiss Federal Data Protection and Information Commissioner's addendum.
  • Transfer impact assessment: we maintain a transfer impact assessment covering Indian government access law, and will provide it under NDA on request.
  • Technical measures: encryption in transit and at rest, access control, and audit logging, as described in our Data Security Statement.

Onward transfers to a sub-processor are made only under the same or equivalent safeguards, and only to the sub-processors listed in our Data Processing Agreement.

EU and UK representative

Appointment of an EU representative under GDPR Article 27 and a UK representative under UK GDPR Article 27 is in progress and is not yet complete. Until a representative is appointed and named here, EU and UK data subjects should contact our Data Protection Officer directly at dpo@narrahealthcare.com. We will publish the representative's name and address in this section as soon as the appointment is made. This does not limit your right to complain to your own supervisory authority.

Other transfers

  • National health network: where a government requires data sharing for national health infrastructure in your jurisdiction.
  • Legal obligation: where a court or regulator with valid jurisdiction orders a transfer. We challenge requests that are overly broad, and notify you where we are legally permitted to.

Children's Data

hospiDule is not intended for children under 18 years of age except in specific healthcare scenarios.

A parent or legal guardian may create an account on behalf of a child. The guardian is the Data Principal and manages all access and consent. This is the recommended approach for accessing a child's healthcare (test results, appointments, and so on).

Safeguards for children's data

  • Sensitive health data for minors (mental health, reproductive health) is treated with additional privacy protections
  • Verifiable guardian consent is required for any data sharing
  • No marketing to minors, and no behavioural tracking or profiling of a child
  • No data sharing with third parties (other than healthcare providers) without explicit guardian consent

Security & Safeguards

Encryption

  • In transit: TLS 1.3. All connections to hospiDule are encrypted; no data is transmitted unencrypted.
  • At rest: AES-256 encryption with keys managed in Google Cloud KMS. Regular key rotation.

Access control

  • Strict Role-Based Access Control (RBAC): staff see only what they need
  • Multi-Factor Authentication (MFA) required for all staff accessing production systems
  • Comprehensive audit logging of all data access

Monitoring & incident response

24/7 automated monitoring with immediate alerts. Potential breaches are investigated on detection. If a breach occurs, affected systems are isolated without undue delay and in any event within 1 hour, and notification follows the timelines below. These are the same timelines as in our Data Processing Agreement, Business Associate Agreement, and Data Security Statement.

  • To you and to your Controller: without undue delay after we become aware.
  • To a supervisory authority under GDPR Article 33: without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to your rights and freedoms.
  • To affected individuals under GDPR Article 34 and India's DPDP Act: without undue delay where the breach is likely to result in a high risk to your rights, and in any event within 72 hours.
  • Where HIPAA applies: we notify the covered entity so that individual notice can be given without unreasonable delay and no later than 60 calendar days from discovery, with notice to the US Department of Health and Human Services, and to prominent media where a breach affects 500 or more residents of a state or jurisdiction.

Certifications & compliance

We state our certification status plainly. Nothing below is claimed as achieved unless it says so.

  • ISO/IEC 27001:2022: implementation in progress. Not yet certified. No certificate has been issued to us.
  • SOC 2 Type II: readiness work in progress. No report has been issued. We will make the report available under NDA once one exists.
  • OWASP Top 10: our application security controls are mapped to the OWASP Top 10. The OWASP Top 10 is an awareness document and is not a certifiable standard, so no compliance can be claimed against it.
  • Penetration testing: conducted by an independent external firm. The most recent summary report is available under NDA.

Cookies & Tracking

Full details are provided in our separate Cookie Policy. Here is a summary:

Essential cookies (always on)
Session cookies (keep you logged in), CSRF protection, and preference cookies (language, theme). Cannot be disabled: required for security and functionality.
Functional cookies (opt-in)
Language, theme, last-viewed records, and form autofill. Disabling them reduces convenience only.
Analytics cookies (opt-in)
Aggregated, anonymised page views and user flow. You can disable these in Account Settings → Privacy → Data Usage, or decline them in the cookie banner.
Marketing cookies
We do not use advertising, retargeting, or social-media tracking cookies.

Withdrawing cookie consent is as easy as giving it, through the same control. If your browser sends a "Do Not Track" signal or a Global Privacy Control signal, we honour it and disable non-essential tracking.

Changes to This Policy

We may update this Privacy Policy to reflect changes in applicable law, new requirements from a national health network, changes to how hospiDule processes data, or user feedback.

How we notify you

  • Material changes (new uses of data, new sharing, a change of hosting region): email notification to all users at least 30 days before the change takes effect, plus an in-app notification with an option to accept or reject.
  • Minor changes (for example contact information updates): posted on this page with an updated "Last Updated" date; no advance notification required.

If you don't agree with updated terms, you can opt out before the change takes effect, request deletion of your account, or withdraw consent.

Contact & Complaints

Legal entity
Narra Technologies Private Limited
Data Protection Officer (DPO)
dpo@narrahealthcare.com: response within 5 business days
Privacy requests
privacy@narrahealthcare.com
General Support
support@narrahealthcare.com: response within 24 hours
Phone
+91 90329 31217
Registered office
Hyderabad, Telangana, India. Full registered address on request from legal@narrahealthcare.com.
EU / UK representative
Appointment in progress. Until it is complete, contact the DPO above.

How to file a complaint

  1. Contact us: Email dpo@narrahealthcare.com with your name, account ID, a description of the issue, the specific right you believe was violated, and the remedy you seek.
  2. Investigation: We investigate within 30 days and keep you updated on progress.
  3. Resolution: We provide a written response within 30 days, and in any event within the period required by applicable law. If you disagree, you may escalate.

Regulatory escalation

You may complain to the relevant data protection authority at any time. You do not have to contact us first, and you also retain the right to seek a legal remedy through the courts.