This policy explains how docDule, a product of Narra Technologies, collects, uses, and protects your personal and health data under applicable data protection law.
Welcome to docDule, a product of Narra Technologies. We are committed to protecting your privacy and being transparent about how we collect, use, and protect your personal and health data.
This Privacy Policy applies to:
docdule.com)This policy is designed to comply with applicable data protection law. Concerns can be raised with the relevant data protection authority. If you do not agree with this Privacy Policy, please do not use our services.
Key terms used throughout this policy:
docdule.comWe are a healthcare technology company building an integrated digital health platform that connects diagnostic centres, clinics, hospitals, and patients across India.
We collect different types of data depending on how you interact with docDule.
Full name, date of birth, gender, and unique identifiers including ABHA ID, a docDule patient ID, and Aadhaar (with explicit consent, only if required by law). Collected when you sign up or when your healthcare provider creates your patient record. Name, date of birth, and gender are mandatory to create an account.
Mobile phone number, email address, postal address, and emergency contact information. Phone number and email are required for account recovery and notifications.
Laboratory test results, diagnostic images, vital signs, medical diagnoses, allergies, medications, prescriptions, treatment history, discharge summaries, procedure records, immunisation records, and family health history (if provided).
Health data is only collected with your explicit, informed consent. You have full control over which data is shared and with whom. Under the DPDP Act 2023, health data is classified as sensitive because unauthorised disclosure could harm your privacy, medical autonomy, or insurance eligibility.
IP address, browser type and version, operating system, device type, pages visited and time spent, clicks and interactions, and error logs. Collected automatically through cookies and server logs. We do not store raw IP addresses longer than necessary.
Payment method information (card type, last 4 digits), transaction IDs, invoice records, insurance policy numbers, and billing address. Collected only if you purchase paid services. docDule does not store full credit card numbers. Our payment processor handles all sensitive payment data.
Support tickets, email communications, call recordings (only with consent), feedback and survey responses, and chat transcripts. Collected only when you contact us.
Data about minors (if a parent or guardian creates an account for a child), mental health data (if disclosed in clinical records), and genetic or biometric data (only if explicitly shared). None of these categories are mandatory and are collected only with explicit consent.
Under the DPDP Act 2023, every use of your data must have a clear legal basis:
For GDPR users (EU/EEA): We also comply with GDPR lawful bases: consent, contract, legal obligation, legitimate interest, and vital interest.
Consent is central to our approach. You should have control over your data.
When you authorise a healthcare provider to access your records, you choose what they can see (all data, only test results, only clinical notes, specific date ranges) and set an expiry. You can revoke access at any time.
Withdrawing consent may limit your ability to use docDule's features. Withdrawing consent to store health data means we cannot maintain your patient record.
Your health data is private by default. We only share it when necessary and with your permission.
Doctors, hospitals, diagnostic centres, and other providers in our network. You explicitly authorise each provider, can limit what they see, and can revoke access at any time. All providers sign a Data Processing Agreement (DPA) or Business Associate Agreement (BAA).
Other healthcare providers, PHR apps, and government health programmes connected to ABDM, if you link your ABHA account. Linking is optional and you can revoke consent through the ABDM consent manager. Once data is shared via ABDM, other ABDM-registered providers may access it. This is the intended purpose of the national health network.
Encrypted health data is processed by cloud infrastructure (India-region), payment processors, SMS gateways, email services, and analytics tools. Raw health data is never shared unencrypted. All vendors sign DPAs with strict security requirements including AES-256 encryption, access controls, and breach notification within 24 hours.
Staff with a legitimate need (support, compliance), governed by strict Role-Based Access Control (RBAC), mandatory MFA, and comprehensive audit logging. Access is granted only to resolve support issues or technical problems.
Government agencies, courts, and tax authorities, only in response to valid legal process. We object to overly broad requests, share only what is legally required, and notify you when legally permitted to do so. We do not voluntarily share your data with law enforcement.
De-identified and anonymised health data only, with your explicit opt-in consent.
We keep your data only as long as necessary for the purpose it was collected.
Under the DPDP Act 2023 (and where applicable, GDPR), you have the following rights:
You may request a copy of all personal data we hold about you. Email admin@narrahealthcare.com with the subject "Data Access Request" or use Account Settings → Privacy → Download My Data. We will respond within 30 days at no cost.
You may correct inaccurate or incomplete data. Update contact data directly in Account Settings → Profile. For health data, contact your healthcare provider or email our DPO. Timeline: 30 days.
You may request permanent deletion of your data via Account Settings → Delete Account. Data will be irreversibly deleted within 30 days. We may retain de-identified data for research and must retain records required by law. Deleted health records cannot be recovered.
You may ask us to limit how we use your data while investigating an issue. Email admin@narrahealthcare.com with the subject "Request to Restrict Processing". Timeline: 30 days.
You may request your data in a portable format (CSV, JSON, PDF) via Account Settings → Privacy → Download My Data. Timeline: 30 days.
You may object to processing of your data for marketing or research by unsubscribing or emailing our DPO. Marketing objections take effect immediately; other processing within 30 days.
Your health data is stored and processed primarily in India, in compliance with the DPDP Act's data residency requirements.
Data centres: India-region cloud infrastructure. Backups are replicated within India for disaster recovery.
All international transfers are protected by Standard Contractual Clauses, encryption, pseudonymisation, and access controls. We notify you before any such transfer.
docDule is not intended for children under 18 years of age except in specific healthcare scenarios.
A parent or legal guardian may create an account on behalf of a child. The guardian is the Data Principal and manages all access and consent. This is the recommended approach for accessing a child's healthcare (test results, appointments, etc.).
24/7 automated monitoring with immediate alerts. Potential breaches are investigated within 1 hour. If a breach occurs, affected systems are isolated within 2 hours, users notified within 72 hours (as required by the DPDP Act), and preventive measures implemented immediately.
Full details are provided in our separate Cookie Policy. Here is a summary:
If your browser sends a "Do Not Track" signal, we honour it and disable non-essential tracking.
Our website and apps may contain links to third-party websites. We are not responsible for their privacy practices. Before clicking external links, review their privacy policy. We do not share your data when you click external links.
We may update this Privacy Policy to reflect changes in Indian law (DPDP Act updates), new ABDM requirements, changes to how docDule processes data, or user feedback.
If you don't agree with updated terms, you can opt out before the change takes effect, request deletion of your account, or withdraw consent.
You also retain the right to seek legal remedy through the courts.