Privacy Policy

v1.0First published: 15 October 2025Last updated: 14 January 2026Effective: 1 February 2026

This policy explains how docDule, a product of Narra Technologies, collects, uses, and protects your personal and health data under applicable data protection law.

Introduction

Welcome to docDule, a product of Narra Technologies. We are committed to protecting your privacy and being transparent about how we collect, use, and protect your personal and health data.

This Privacy Policy applies to:

  • Our website (docdule.com)
  • Our web-based SaaS platform
  • Our mobile applications (iOS and Android)
  • Our APIs and integrations
  • Our email communications

This policy is designed to comply with applicable data protection law. Concerns can be raised with the relevant data protection authority. If you do not agree with this Privacy Policy, please do not use our services.

Definitions

Key terms used throughout this policy:

Personal Data
Any information that can be used to identify you directly or indirectly (e.g., name, email, phone number, IP address).
Health Data / PHI
Sensitive personal health information, including medical records, diagnostic results, prescriptions, vitals, allergies, and treatment history. Treated as "Sensitive Personal Data" under the DPDP Act.
Data Principal
You: the person whose data we collect. Also called "Data Subject" under GDPR.
Data Fiduciary
Us: the organisation that determines how and why your data is processed. Also called "Controller" under GDPR.
Data Processor
A third party that processes data on our behalf (e.g., cloud provider, payment processor). All processors are bound by contract to meet our security standards.
ABHA
Ayushman Bharat Health Account: a unique 14-digit health identifier issued by India's National Digital Health Mission (ABDM).
ABDM
Ayushman Bharat Digital Mission: India's national digital health ecosystem.
EMR / EHR
Electronic Medical Record / Electronic Health Record: digital health records maintained by healthcare providers.
Processing
Any activity we perform with your data (collecting, storing, analysing, sharing, deleting, etc.).
Breach
Unauthorised access, disclosure, or loss of your personal or health data.

Who We Are

Organisation Name
Narra Technologies
Website
docdule.com
Data Protection Officer
admin@narrahealthcare.com
General Support
support@narrahealthcare.com
Registered Address
Available on request from admin@narrahealthcare.com.
DPDP Act Registration
To be filed once the Act requires it of an entity of our size. We will publish the reference here when it is.

We are a healthcare technology company building an integrated digital health platform that connects diagnostic centres, clinics, hospitals, and patients across India.

What Data We Collect

We collect different types of data depending on how you interact with docDule.

1. Identity Data

Full name, date of birth, gender, and unique identifiers including ABHA ID, a docDule patient ID, and Aadhaar (with explicit consent, only if required by law). Collected when you sign up or when your healthcare provider creates your patient record. Name, date of birth, and gender are mandatory to create an account.

2. Contact Data

Mobile phone number, email address, postal address, and emergency contact information. Phone number and email are required for account recovery and notifications.

3. Health & Clinical Data (Sensitive Personal Data)

Laboratory test results, diagnostic images, vital signs, medical diagnoses, allergies, medications, prescriptions, treatment history, discharge summaries, procedure records, immunisation records, and family health history (if provided).

Health data is only collected with your explicit, informed consent. You have full control over which data is shared and with whom. Under the DPDP Act 2023, health data is classified as sensitive because unauthorised disclosure could harm your privacy, medical autonomy, or insurance eligibility.

4. Usage & Device Data

IP address, browser type and version, operating system, device type, pages visited and time spent, clicks and interactions, and error logs. Collected automatically through cookies and server logs. We do not store raw IP addresses longer than necessary.

5. Transactional & Financial Data

Payment method information (card type, last 4 digits), transaction IDs, invoice records, insurance policy numbers, and billing address. Collected only if you purchase paid services. docDule does not store full credit card numbers. Our payment processor handles all sensitive payment data.

6. Support & Communications Data

Support tickets, email communications, call recordings (only with consent), feedback and survey responses, and chat transcripts. Collected only when you contact us.

7. Special Categories

Data about minors (if a parent or guardian creates an account for a child), mental health data (if disclosed in clinical records), and genetic or biometric data (only if explicitly shared). None of these categories are mandatory and are collected only with explicit consent.

How We Use Your Data

Essential uses (required to provide the service)

  • Creating and managing your health records: maintaining your EHR, integrating records from multiple providers, and enabling you to access your own health data at any time.
  • Enabling provider collaboration: sharing health records with your treating doctors and healthcare providers. You control which providers can access which records and can revoke access at any time.
  • ABDM / ABHA integration: linking your docDule account to your ABHA and syncing health records to the national digital health ecosystem. Optional; you can revoke access through the ABDM consent manager.
  • Patient notifications & reminders: test result notifications, appointment reminders, and alerts for abnormal results.

Secondary uses (improving service & compliance)

  • Analytics & product improvement: anonymised usage trends to improve the platform. You can opt out of non-essential analytics in account settings.
  • Fraud prevention & platform security: monitoring for unauthorised access, maintaining audit logs. Non-optional for security reasons; we use the minimum data necessary.
  • Billing & account management: processing payments, generating invoices.
  • Legal compliance & audit: complying with court orders, regulatory investigations, and maintaining audit records.

Tertiary uses (with explicit consent)

  • Marketing & communications: emails about new features, events, and health tips. Entirely optional; you can unsubscribe at any time.
  • Research & clinical insights: de-identified research on health trends. You can opt out during sign-up; opting out does not affect your use of docDule.

Who We Share Your Data With

Your health data is private by default. We only share it when necessary and with your permission.

Healthcare providers (with your authorisation)

Doctors, hospitals, diagnostic centres, and other providers in our network. You explicitly authorise each provider, can limit what they see, and can revoke access at any time. All providers sign a Data Processing Agreement (DPA) or Business Associate Agreement (BAA).

ABDM ecosystem (with your consent)

Other healthcare providers, PHR apps, and government health programmes connected to ABDM, if you link your ABHA account. Linking is optional and you can revoke consent through the ABDM consent manager. Once data is shared via ABDM, other ABDM-registered providers may access it. This is the intended purpose of the national health network.

Cloud & technology service providers

Encrypted health data is processed by cloud infrastructure (India-region), payment processors, SMS gateways, email services, and analytics tools. Raw health data is never shared unencrypted. All vendors sign DPAs with strict security requirements including AES-256 encryption, access controls, and breach notification within 24 hours.

Our employees & support team

Staff with a legitimate need (support, compliance), governed by strict Role-Based Access Control (RBAC), mandatory MFA, and comprehensive audit logging. Access is granted only to resolve support issues or technical problems.

Law enforcement & regulatory bodies (when legally required)

Government agencies, courts, and tax authorities, only in response to valid legal process. We object to overly broad requests, share only what is legally required, and notify you when legally permitted to do so. We do not voluntarily share your data with law enforcement.

Researchers & academic institutions (with consent)

De-identified and anonymised health data only, with your explicit opt-in consent.

What we do NOT do

  • Sell your personal or health data to third parties
  • Share data with insurance companies for underwriting without explicit consent
  • Share data with employers
  • Share data with pharmaceutical companies without anonymisation and explicit consent
  • Rent or lease your data
  • Combine your data with data from other companies for marketing purposes

Data Retention

We keep your data only as long as necessary for the purpose it was collected.

Health records
Retained for the lifetime of your account. Upon account deletion, data is irreversibly destroyed within 30 days.
Support & operational data
1–3 years after your last interaction (support tickets: 2 years; chat transcripts: 1 year; call recordings: 90 days).
Analytics & usage data
1–2 years, aggregated and anonymised.
Billing & financial records
7 years, as required by India's Income Tax Act.
Cookies & tracking data
Session cookies: until you close the browser. Persistent cookies: up to 12 months.
ABDM / ABHA data
As long as your ABHA account exists or until you revoke consent through the ABDM consent manager.
Breach notification records
5 years, as required by the DPDP Act.

Your Rights

Under the DPDP Act 2023 (and where applicable, GDPR), you have the following rights:

Right to Access

You may request a copy of all personal data we hold about you. Email admin@narrahealthcare.com with the subject "Data Access Request" or use Account Settings → Privacy → Download My Data. We will respond within 30 days at no cost.

Right to Correction

You may correct inaccurate or incomplete data. Update contact data directly in Account Settings → Profile. For health data, contact your healthcare provider or email our DPO. Timeline: 30 days.

Right to Erasure

You may request permanent deletion of your data via Account Settings → Delete Account. Data will be irreversibly deleted within 30 days. We may retain de-identified data for research and must retain records required by law. Deleted health records cannot be recovered.

Right to Restrict Processing

You may ask us to limit how we use your data while investigating an issue. Email admin@narrahealthcare.com with the subject "Request to Restrict Processing". Timeline: 30 days.

Right to Data Portability (GDPR)

You may request your data in a portable format (CSV, JSON, PDF) via Account Settings → Privacy → Download My Data. Timeline: 30 days.

Right to Object (GDPR)

You may object to processing of your data for marketing or research by unsubscribing or emailing our DPO. Marketing objections take effect immediately; other processing within 30 days.

Right to Lodge a Complaint

  • India (DPDP Act): Data Protection Board of India
  • EU (GDPR): Your country's Data Protection Authority (DPA)
  • To us first (recommended): Email admin@narrahealthcare.com with the subject "Privacy Complaint". We will investigate and respond within 45 days.

International Data Transfers

Your health data is stored and processed primarily in India, in compliance with the DPDP Act's data residency requirements.

Data centres: India-region cloud infrastructure. Backups are replicated within India for disaster recovery.

Exceptions (rare)

  • GDPR users (EU/EEA): If you are in the EU, data may be transferred to EU-certified cloud providers under Standard Contractual Clauses (SCCs). You can request data remain in India (functional limitations may apply).
  • ABDM / regulatory requirement: If India's government requires data sharing for national health infrastructure.
  • Legal obligation: If a court or regulator orders data transfer.

All international transfers are protected by Standard Contractual Clauses, encryption, pseudonymisation, and access controls. We notify you before any such transfer.

Children's Data

docDule is not intended for children under 18 years of age except in specific healthcare scenarios.

A parent or legal guardian may create an account on behalf of a child. The guardian is the Data Principal and manages all access and consent. This is the recommended approach for accessing a child's healthcare (test results, appointments, etc.).

Safeguards for children's data

  • Sensitive health data for minors (mental health, reproductive health) is treated with additional privacy protections
  • Guardian consent is required for any data sharing
  • No marketing to minors
  • No data sharing with third parties (other than healthcare providers) without explicit guardian consent

Security & Safeguards

Encryption

  • In transit: TLS 1.3. All connections to docDule are encrypted; no data is transmitted unencrypted.
  • At rest: AES-256 encryption with keys managed by a dedicated KMS. Regular key rotation.

Access control

  • Strict Role-Based Access Control (RBAC): staff see only what they need
  • Multi-Factor Authentication (MFA) required for all staff accessing production systems
  • Comprehensive audit logging of all data access

Monitoring & incident response

24/7 automated monitoring with immediate alerts. Potential breaches are investigated within 1 hour. If a breach occurs, affected systems are isolated within 2 hours, users notified within 72 hours (as required by the DPDP Act), and preventive measures implemented immediately.

Certifications & compliance

  • ISO 27001: Information Security Management (certified or in progress)
  • SOC 2 Type II: Security, availability, and integrity controls
  • OWASP Compliance: Security best practices for web applications
  • Regular penetration testing by independent external security experts

Cookies & Tracking

Full details are provided in our separate Cookie Policy. Here is a summary:

Essential cookies (always on)
Session cookies (keep you logged in), CSRF protection, and preference cookies (language, theme). Cannot be disabled: required for security and functionality.
Analytics cookies (opt-in)
Track page views, user flow, and popular features. Data is anonymised and aggregated. You can disable these in Settings → Privacy → Analytics.
Marketing cookies (disabled by default)
Social media pixels and remarketing. Disabled by default; you can enable them if interested.

If your browser sends a "Do Not Track" signal, we honour it and disable non-essential tracking.

Changes to This Policy

We may update this Privacy Policy to reflect changes in Indian law (DPDP Act updates), new ABDM requirements, changes to how docDule processes data, or user feedback.

How we notify you

  • Material changes (new uses of data, new sharing): Email notification to all users at least 30 days before the change takes effect, plus an in-app notification with an option to accept or reject.
  • Minor changes (e.g., contact information updates): Posted on this page with an updated "Last Updated" date; no advance notification required.

If you don't agree with updated terms, you can opt out before the change takes effect, request deletion of your account, or withdraw consent.

Contact & Complaints

Data Protection Officer (DPO)
admin@narrahealthcare.com: response within 5 business days
General Support
support@narrahealthcare.com: response within 24 hours
Phone
+91 90329 31217
Postal address
Available on request from admin@narrahealthcare.com.

How to file a complaint

  1. Contact us: Email admin@narrahealthcare.com with your name, ABHA/Patient ID, a description of the issue, the specific right you believe was violated, and the remedy you seek.
  2. Investigation: We investigate within 30 days and keep you updated on progress.
  3. Resolution: We provide a written response within 45 days. If you disagree, you may escalate.

Regulatory escalation

  • India (DPDP Act): Data Protection Board of India
  • EU (GDPR): Your country's Data Protection Authority: list available at edpb.eu

You also retain the right to seek legal remedy through the courts.