Last updated: August 2026
Privacy Policy
This policy explains what personal data NirogMed collects, why, how long it is kept, and how you can exercise your rights under the Digital Personal Data Protection Act, 2023.
1. Who this policy covers
This Privacy Policy applies to imaging centers, radiologists, doctors, patients, administrators, and any other registered account holder on the NirogMed platform, and to visitors to a public report-link or share-records page who are not yet registered.
It is issued as a notice under Section 5 of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and should be read alongside the Terms and Conditions.
2. What personal data we collect
Identity and contact data: full name, date of birth, gender, phone number, email address, and postal address, collected at registration.
Aadhaar-linked mobile verification: the Aadhaar number is used once to send a verification OTP and is never stored in full — only a one-way cryptographic hash (for detecting duplicate accounts) and the last 4 digits (for display) are retained. NirogMed is not a UIDAI-licensed AUA/KUA and does not validate the Aadhaar number itself against UIDAI.
Health data: radiology scans and images, clinical history, diagnostic reports, and related metadata, uploaded by an imaging center or by you directly.
Payment data: wallet balance and transaction history. Card and UPI details are handled by our payment gateway partners and are not stored on NirogMed servers.
Professional credentials: for radiologists, doctors, and centers — registration numbers, qualifications, licence and indemnity insurance details, and verification documents.
Usage data: device information, IP address, and interaction logs, collected automatically for security and service reliability.
3. Why we collect it, and on what basis
To create and administer your account, and to provide the imaging, reporting, storage, and payment services you have requested — this is the primary basis for processing under the DPDP Act.
To obtain and record your consent before a scan is transmitted to a radiologist for remote reporting, where you hold a NirogMed account (see the Terms, and Section 6 below).
To verify the professional credentials of radiologists, doctors, and imaging centers before they are approved to use the platform.
To detect and prevent fraud, duplicate accounts, and misuse of the referral programme.
To comply with applicable law, including retention obligations described in Section 7.
Where we rely on your consent for a specific purpose, you may withdraw it at any time by contacting us as set out in Section 11; withdrawal does not affect processing already carried out, or processing required by law.
4. How your data is shared
With the imaging center and radiologist assigned to your case, strictly for the purpose of preparing your report.
With a treating doctor you have explicitly authorised — either by approving an OTP-verified access request, or by scanning that doctor’s sharing QR code from your own signed-in account. Viewing is free; a doctor requesting a downloadable copy for their own records triggers a separate charge that you approve.
With payment gateway and cloud storage providers, solely to process payments and store data on our behalf, under contractual confidentiality obligations.
With a court, regulator, or law enforcement authority where required by law.
We do not sell personal data, and we do not share health data with advertisers or data brokers.
5. Where your data is stored
Scan images, reports, and account data are stored on cloud infrastructure located in the AWS ap-south-1 (Mumbai) region.
This is our current operational configuration, not a contractual data-localisation guarantee — if that changes, this policy will be updated first.
6. Consent before your scan is sent for reporting
If you already hold a NirogMed account at the time a scan is uploaded for you, we send an OTP to your registered mobile number and the scan is held until you confirm — it is not assigned to a radiologist for remote reporting until you do.
If you do not yet hold an account, this digital consent step does not apply, and the imaging center’s own point-of-care consent process governs the upload, as it did before you had an account.
7. How long we keep your data
Patient and scan records are kept for a minimum of 3 years from creation, reflecting retention norms under the National Medical Commission’s Code of Medical Ethics Regulations and applicable state Clinical Establishment rules. Records relating to an ultrasound examination, including any Form F declaration, are kept for a minimum of 2 years under the PC-PNDT Rules.
Within that minimum period, records cannot be permanently deleted, including by us on request — they can only be deactivated (soft-deleted) so they no longer appear in normal use, with every deactivation logged. After the minimum period has passed, deletion proceeds normally.
Aadhaar verification data is limited to a one-way hash and the last 4 digits, as described in Section 2, and is kept only for as long as your account is active plus the retention period above.
8. Your rights
You may request access to the personal data we hold about you, request correction of inaccurate data, and request erasure of your data — subject always to the retention obligations in Section 7, which take precedence over an erasure request during the applicable minimum period.
You may withdraw consent for a specific processing activity as described in Section 3.
To exercise any of these rights, contact us using the details in Section 11. We will acknowledge your request and respond within the time limits prescribed under the DPDP Act.
9. Security measures
Data is encrypted in transit. Sensitive identifiers such as Aadhaar numbers are never stored in full, only as a one-way hash plus a masked display value, as described in Section 2.
Access to patient records by imaging centers, radiologists, and doctors is role-restricted and, for treating doctors, time-boxed and logged.
No system is completely immune to compromise. If a breach affecting your personal data occurs, we will notify the Data Protection Board of India and affected users as required under the DPDP Act.
10. Children’s data
The platform is intended for use by adults registering and managing accounts on their own behalf, or on behalf of a minor family member added under a Family account by an adult account holder. We do not knowingly collect data directly from an unaccompanied minor.
11. Grievance Officer and contact
Grievance Officer: to be notified. This section will be updated with the name and direct contact details of our designated Grievance Officer under the DPDP Act and the Consumer Protection (E-Commerce) Rules, 2020.
Until then, all privacy, data protection, and grievance requests can be sent to [email protected].
12. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated "last updated" date at the top of this page, and, where required by law, notified to you directly.