Privacy Policy

Privacy Policy

PRIVACY POLICY

Effective Date: 30/09/25

Last Updated: 30/09/25

SECTION A: GENERAL PROVISIONS

1. Introduction and Data Controller Information

This Privacy Policy explains how Fractal Vision LLP ("Company," "we," "us," or "our") collects, uses, processes, stores, shares, and protects your personal data when you use the NurseNow mobile application, website, and related services ("Platform"). This Policy applies to all Users, including patients ("Patients") and registered nursing professionals ("Nurses").

Data Controller:

Fractal Vision LLP

Registered Office: 001A, First Floor, Emaar Palm Square, Golf Course Extension Road, Gurgaon - 122102

Email: privacy@nursenow.co.in

Phone: 9667887142

Data Protection Officer:
  • Appointed to oversee compliance with data protection laws, advise on internal policies, and act as liaison with the Data Protection Board of India.
  • Not a mandatory role under Indian law but maintained voluntarily as a best practice.

Name: Rekha Jain

Email: dpo@nursenow.co.in

Grievance Officer:
  • Responsible for addressing and resolving user grievances under the IT Act 2000 and SPDI Rules 2011.

Name: Parul Sharma

Email: grievance@nursenow.co.in

Phone: 9667887142

3. Definitions and Key Terms

  • Personal Data: Data relating to an identifiable natural person.
  • Sensitive Personal Data: Health data, financial data, passwords, etc.
  • Processing: Any operation on personal data.
  • Consent: Freely given, specific, informed, and unambiguous indication of wishes.

4. Data Collection and Processing Overview

  • Care Members: Identification, health and medical data, contact, payment, location.
  • Nurses: Credentials, licensing, performance metrics, financial and tax data, background checks.
  • Platform Usage: Device and technical data, cookies, logs.

5. User Rights Under DPDP Act 2023

  • Right to information, access, correction, erasure, portability, grievance redressal.
  • Requests via in-app settings, email to privacy@nursenow.co.in
  • Acknowledgment within 72 hours; resolution within 30 days (60 days if complex).

6. Data Security and Technical Safeguards

  • Encryption (AES-256 for data at rest, TLS 1.3 in transit)
  • Role-based access control with multi-factor authentication
  • Regular security audits, vulnerability assessments, incident response procedures
  • HIPAA-equivalent controls for health data

7. International Data Transfers

  • Primary data storage in India
  • Transfers only with legal basis, adequate safeguards, or explicit consent
  • Standard contractual clauses, binding corporate rules, or consent

8. Data Breach Management

  • 24/7 monitoring and detection
  • Containment within 1 hour, notification to Data Protection Board within 72 hours
  • User notification without undue delay, remediation and root-cause analysis

9. Grievance Redressal and Contact Information

  • Internal: grievance@nursenow.co.in (acknowledgment within 24 hours; resolution within 15 days)
  • Escalation: Data Protection Board of India, Consumer Forums, Healthcare Regulators

SECTION B: CARE MEMBER-SPECIFIC PROVISIONS

10. Health Data Processing for Care Members

  • Explicit Consent required for health data.
  • Special categories (mental health, genetic data, reproductive health) need separate explicit consent.
  • Purpose: Service delivery, emergency care, quality improvement, public health reporting.

11. Medical Records Management

  • Compliance with Clinical Establishments Act and EHR Standards.
  • Care Member Access: Records provided within 72 hours in machine-readable format.
  • Retention: 7 years from last treatment (longer for minors or mental health).
  • Secure Disposal via cryptographic erasure or physical destruction.

12. Emergency Contact and Family Data

  • Processing of emergency contacts and caregiver information with explicit consent.
  • Special protections for minors and dependents.
  • Guardian or proxy consent for incapacitated care members.

13. Insurance and Payment Information

  • PCI DSS compliance for payment data.
  • Tokenization of credit card data, encrypted storage.
  • Insurance data sharing with explicit care member consent; minimum necessary principle.

SECTION C: NURSE-SPECIFIC PROVISIONS

16. Professional Credential Processing

  • Secure handling of nursing degrees, licenses, NUID, continuing education records.
  • Automated and manual verification with audit trails.
  • Periodic re-verification and compliance checks.

17. Performance and Quality Data

  • Collection of care member feedback, clinical outcome metrics, peer reviews.
  • Usage for coaching, quality improvement, platform recommendations.
  • Nurses' right to access, dispute, and correct performance data.

18. Financial and Tax Information

  • Encrypted storage of earnings, payouts, PAN, TDS certificates, GST details.
  • Automated tax calculations, TDS certificate generation, annual summaries.
  • Nurses control sharing of financial data; correction mechanisms.

19. Background Verification Data

  • Secure processing of identity, criminal checks, employment history.
  • Confidential handling, restricted access, dispute resolution for inaccuracies.
  • Periodic re-screening and ongoing monitoring.

20. Professional Indemnity Records

  • Storage of insurance policy details, claims history, settlements.
  • Real-time coverage verification, alerts for policy expiration.
  • Confidential handling and audit logging.

21. Employment-Related Data Processing

  • Processing under "legitimate use" for contractor management, scheduling, performance evaluations.
  • No employment relationship; compliance with labour codes.
  • Nurses' rights to review, correct, and limit employment data processing.

SECTION D: PLATFORM OPERATIONS

22. Children's Data

  • NurseNow does not knowingly collect personal data from children under the age of 18.
  • Care members under 18 must have a parent or legal guardian provide consent and book services on their behalf.
  • Parental/guardian consent must be verifiable under the DPDP Act, 2023.
  • In emergencies, data may be processed for immediate care, with post-event review and guardian notification.

22. Cookies and Tracking Technologies

  • Essential Cookies: Authentication, security, performance.
  • Analytics Cookies: Usage patterns, performance analytics.
  • Marketing Cookies: Personalized offers, remarketing.
  • Consent Management: Granular opt-in/opt-out dashboard, renewal prompts.

23. Marketing and Communications

  • Consent-Based: Explicit opt-in for promotional emails, SMS, push.
  • Preferences: Category, channel, and frequency controls; mandatory service alerts.
  • Compliance: TCPA, CAN-SPAM, GDPR for EU residents.

24. Third-Party Services and Integrations

  • Healthcare Partners: EHR, telehealth, remote monitoring, insurance systems.
  • Infrastructure Partners: AWS, Azure, GCP, CDN, messaging, analytics.
  • Vendor Management: Due diligence, DPAs, regular audits, breach notification clauses.

25. Data Retention and Deletion

  • Retention Periods: Medical records (7–10 years), financial/tax (7 years), background checks (as required), cookies (13 months).
  • Automated Deletion: Lifecycle policies, legal holds, audit logs.
  • User-Initiated Deletion: Verified deletion requests, confirmation within 30 days, legal exceptions.

26. Policy Updates and Modifications

  • Review Cadence: Annual legal review, quarterly security review.
  • Notification: 30 days for material changes, 15 days for significant changes, immediate for emergencies.
  • User Consent: Explicit for material changes; opt-out and account suspension options.

ACKNOWLEDGMENT AND ACCEPTANCE

By using the NurseNow Platform, you acknowledge that you have read, understood, and agree to this Privacy Policy and any updates. For questions or requests, contact our Data Protection Officer at dpo@nursenow.co.in.

This Privacy Policy is compliant with the DPDP Act 2023, IT Act 2000, Clinical Establishments Act 2010, Consumer Protection Act 2019, and all relevant Indian laws governing privacy, data protection, and healthcare.