Legal

Privacy Policy.

Version 2.0. Last updated 2 September 2026. What we collect, why, who sees it and what you can ask us to do with it.

Ramya · Version 2.0 (draft for review) · Last updated: 2 September 2026

This policy explains what we collect about you, why we collect it, who else sees it, how long we keep it, and what you can ask us to do with it.

Your health information is the most sensitive thing you will ever give a business. We treat it that way. We do not sell it, we do not share it with advertisers, and we do not use it to target you with anything.

1. Who is responsible for your data

RAMYA HEALTHCARE (OPC) PRIVATE LIMITED
Eldeco Estate One, 46 Ground Floor, GT Road, Ludhiana, Punjab 141008, India
CIN: [to be inserted on incorporation]

We are the data fiduciary for your personal data under the Digital Personal Data Protection Act, 2023.

Questions about this policy: members@ramyacare.in

2. What we collect

When you visit the website
Pages you view, how long you stay, the device and browser you use, your approximate location from your IP address, and where you arrived from. Cookies and similar technology are covered in clause 8.

When you join
Your name, email address, phone number, password (stored only as an encrypted hash, never in readable form), and delivery address.

When you become a member
Your date of birth, sex, height and weight, existing medical conditions, current medicines and supplements, allergies, past treatments, surgeries, family health history, and details about your sleep, diet, exercise, work and stress.

During your membership
Notes your doctor writes during and after consultations, your health plan and its revisions, messages you send us on WhatsApp or email, your consultation schedule and attendance, documents you upload, and delivery and tracking details for medicine sent to you.

When you pay
The amount, the date, the plan you bought, and a payment reference. We never see or store your full card number, your UPI PIN, your CVV or your bank login. Those go directly to our payment provider.

3. Why we collect it

What forWhy we are allowed to
Providing your care and writing your planPerforming our contract with you, and your consent
Dispensing and delivering medicinePerforming our contract with you, and your consent
Taking payment and issuing invoicesPerforming our contract with you
Sending consultation reminders and account emailsPerforming our contract with you
Keeping medical recordsLegal obligation and legitimate use
Keeping accounting and tax recordsLegal obligation
Improving the website and fixing faultsLegitimate use
Marketing emails and promotionsYour consent, which you can withdraw at any time

We do not use your health information for marketing. Ever. Marketing emails go to a separate list you opt into, and unsubscribing from them does not affect your care.

4. Who sees your data

Inside Ramya. Your treating doctor sees your full record. A small number of administrative staff can see your name, contact details, plan status and delivery information so that they can run the service. They do not have access to your clinical notes.

Inside your household. The payer of a household sees billing for the household. The payer does not see another adult member's health plan, notes or records. A recorded guardian of a person under 18 sees that minor's records.

Service providers. We use outside companies to run parts of the service. Each one only receives what it needs.

ProviderWhat it handlesWhere data sits
SupabaseDatabase, accounts, filesCloud infrastructure
RazorpayPayments and subscriptionsIndia
ResendTransactional emailCloud infrastructure
Google (Calendar and Meet)Scheduling and video consultationsCloud infrastructure
Google WorkspaceOur staff emailCloud infrastructure
CloudflareBot protection on our formsCloud infrastructure
NetlifyWebsite hostingCloud infrastructure
DTDCCourier delivery of medicineIndia
WhatsApp (Meta)Member support messagingCloud infrastructure

Some of these providers store or process data outside India. Where that happens, it is under contractual protections and only to the extent permitted by Indian law.

Legal. We will disclose information where the law requires it, for example to a court, a regulator or the police acting under proper authority. We will tell you when that happens unless we are forbidden from doing so.

Business transfer. If the business is sold or restructured, records may transfer to the new owner, who will be bound by this policy.

We never sell your data. We never share it with advertisers or data brokers. We do not send your health data to advertising platforms, and our advertising pixels do not receive it.

5. How long we keep it

Medical records: retained for the period required under Indian medical record keeping practice and applicable law, counted from your last consultation. Medical records cannot be deleted on request, because a doctor is obliged to keep them.

Financial records: eight years, as required for tax and company law.

Account and contact details: for as long as you hold a membership, and afterwards for as long as we hold your medical records.

Consent records: kept permanently as an append only log, so that we can always show what you agreed to and when.

Website analytics: up to 26 months.

Marketing list: until you unsubscribe.

6. Your rights

Under the Digital Personal Data Protection Act, 2023, you can:

  • Access the personal data we hold about you, and get a summary of how it is processed
  • Correct anything inaccurate, incomplete or out of date
  • Erase personal data that is no longer needed for the purpose it was collected for, subject to the medical and financial record retention above
  • Nominate someone to exercise your rights if you die or become incapable
  • Complain to us and then to the Data Protection Board of India

You can download your own health plan and consultation history from your member portal at any time, without asking us.

To make a request, email members@ramyacare.in. We will respond within 30 days. We may ask you to confirm your identity first, so that nobody else can get your records by pretending to be you.

Withdrawing consent. You may withdraw consent for anything based on consent. Withdrawing consent for clinical processing means we can no longer treat you, so it ends your membership. Refunds are then handled under our Refund Policy.

7. How we protect your data

  • Traffic to and from our site is encrypted in transit
  • Passwords are stored as one way hashes and are never readable by us or by anyone
  • Access to member records is enforced at the database level, so one member's account structurally cannot read another's
  • Administrative accounts require two factor authentication
  • Consent records are append only and cannot be edited or deleted, including by us
  • Access is limited to staff who need it to do their job

No system is perfectly secure. If a breach happens that is likely to affect you, we will tell you and the Data Protection Board of India as required by law.

8. Cookies

We use:

  • Necessary cookies, to keep you signed in and to keep the site secure. These cannot be switched off.
  • Analytics cookies, to understand how the site is used, so we can improve it.
  • Advertising cookies, where you allow them, so that we can measure whether our advertising works.

You choose on your first visit and can change your mind at any time from the cookie settings link in our footer, or in your browser settings.

Advertising and analytics tools receive information about your visit to our public website. They never receive health information, and they are not present inside the member portal.

9. Children

Our website and membership signup are for adults. A person under 18 can receive care only through a household where a parent or legal guardian is the payer and has consented for them.

We do not knowingly collect data from a person under 18 without that consent. If you believe we have, email members@ramyacare.in and we will remove it.

10. Consultations and messages

Video consultations are not recorded unless we tell you in advance and you agree.

Your doctor writes clinical notes during and after each consultation. Those notes are part of your medical record.

WhatsApp messages are stored so that we have a record of what you asked and what we answered. WhatsApp itself is operated by Meta and messages pass through their infrastructure. Do not send anything over WhatsApp that you would not want held there. Anything clinically sensitive belongs in a consultation, not in a chat.

11. Software and AI tools

We use software tools, including artificial intelligence tools, to help draft, organise and review plan documents and internal notes.

Every plan and every clinical decision is made and approved by your doctor. Software does not diagnose you, does not prescribe for you and does not decide anything about your care.

Where such a tool is used on information that could identify you, it is used under a contract that forbids the provider from training its models on your data.

12. Changes to this policy

We may update this policy. The current version always lives at ramyacare.in/privacy with a version number and date.

If a change materially affects your rights, we will tell you and ask you to consent again before it applies to you.

13. Complaints and grievance officer

Email members@ramyacare.in first. We acknowledge within 48 hours and aim to resolve within 15 days.

If you are not satisfied, escalate to our Grievance Officer:

Grievance Officer: Dr. Rahul Garg
Email: members@ramyacare.in
Address: Eldeco Estate One, 46 Ground Floor, GT Road, Ludhiana, Punjab 141008, India

You may also complain to the Data Protection Board of India.

Contact

RAMYA HEALTHCARE (OPC) PRIVATE LIMITED
Eldeco Estate One, 46 Ground Floor, GT Road, Ludhiana, Punjab 141008, India

Member support: members@ramyacare.in
Website: ramyacare.in