DPDP Act 2023 & DPDP Rules 2025

DPDP Compliance Policy

Comprehensive data protection architecture and Data Fiduciary obligations of Sehat Graph Technologies Private Limited.

Effective Date: 22 August 2026 Last Updated: 22 August 2026 Sehat Graph Technologies Pvt. Ltd.

Data Fiduciary Commitment

Under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025, SehatGraph operates as a Data Fiduciary. We process personal health parameters and diagnostic records strictly on the principles of consent, purpose limitation, data minimisation, and complete Data Principal empowerment.

01 Our Commitment

Sehat Graph Technologies Private Limited (“SehatGraph”, “we”, “us”, or “our”) is committed to protecting the privacy, security and lawful use of personal data entrusted to us.

SehatGraph operates digital healthcare services and technology solutions that may involve personal information, health-related information, medical reports, prescriptions, consultation information and other data required to provide and improve our services.

We are committed to designing our products, systems and processes with privacy and data protection principles in mind and to complying with applicable requirements under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025, to the extent applicable to our processing activities.

The DPDP Act establishes a framework for processing digital personal data while recognising individuals' rights to protect their personal data and the need for lawful processing.

02 Who We Are

Data Fiduciary: Sehat Graph Technologies Private Limited

For processing activities where SehatGraph determines the purpose and means of processing personal data, SehatGraph acts as the relevant Data Fiduciary under applicable data protection law.

Where SehatGraph processes personal data on behalf of another organisation, SehatGraph may act as a Data Processor, subject to the applicable contractual and legal requirements.

03 Personal Data We May Process

Depending on the services you use, SehatGraph may process information such as:

Name and contact information
Mobile number and email address
Account and login credentials
Date of birth & demographic info
Health and wellness information
Symptoms & health responses
Medical history provided by user
Laboratory reports & diagnostics
Prescriptions & medications
Doctor consultation logs
Fitness & wearable telemetry
Documents uploaded to platform
Device & technical identifiers
IP address & security audit logs
Service usage & interaction data
Support & grievance records

We seek to collect only information that is reasonably necessary for the relevant purpose.

04 Why We Process Personal Data

Personal data may be processed for specific and lawful purposes, including:

  • Creating and managing user accounts
  • Providing healthcare and wellness-related services
  • Maintaining digital health records
  • Enabling doctor, laboratory, pharmacy or healthcare service workflows
  • Analysing uploaded medical reports where the relevant service is requested
  • Providing AI-assisted healthcare and wellness features
  • Providing personalised health, fitness and wellness recommendations
  • Processing bookings, orders and payments
  • Communicating with users regarding requested services
  • Providing customer support
  • Preventing fraud, misuse and unauthorised access
  • Maintaining platform security and reliability
  • Meeting applicable legal and regulatory obligations
  • Improving our services and technology, where legally permitted and appropriately disclosed

Personal data will not be processed for a purpose incompatible with the purpose communicated to the Data Principal, except where otherwise permitted by applicable law.

05 Notice and Consent

Where consent is the applicable legal basis for processing, SehatGraph will seek consent through an appropriate notice and consent mechanism.

Our notices are intended to explain:

  • What personal data is being requested
  • The specific purpose for which it is being processed
  • How the data is used
  • Relevant sharing or processing arrangements
  • How consent can be withdrawn
  • How users can exercise applicable rights

Consent should be capable of being given or withdrawn through an accessible mechanism. The Digital Personal Data Protection Rules, 2025 provide requirements concerning clear notices and information about personal data and processing purposes.

06 Withdrawal of Consent

Where processing is based on consent, you may withdraw your consent through the available SehatGraph mechanisms or by contacting us.

Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal.

After withdrawal, SehatGraph may stop or restrict the relevant processing, subject to:

  • Applicable legal requirements
  • Legitimate operational requirements permitted by law
  • Retention obligations
  • Security, fraud-prevention or dispute-resolution requirements
  • Other lawful grounds for processing

07 Health and Medical Information

SehatGraph recognises that health-related information requires a high level of care and protection.

We apply appropriate organisational, technical and security measures to protect health-related information against unauthorised access, use, disclosure, alteration, loss or destruction.

Users should only upload or provide medical information that they are authorised to provide.

Healthcare information may be processed to provide requested healthcare, diagnostic, wellness, fitness or related services.

08 AI-Powered Features

SehatGraph may provide AI-enabled features such as:

  • AI Health Assistant
  • AI Symptom Analysis
  • AI Report Analysis
  • AI Health Prediction
  • AI Fitness and Wellness Assistance
  • Personalised health insights

AI features may process information supplied by the user or generated through use of the relevant service.

Clinical Disclaimer: AI-generated information is intended to assist users and should not automatically be treated as a diagnosis, prescription or substitute for qualified medical advice unless expressly stated otherwise.

Where personal data is used for AI-related processing, SehatGraph will process such data according to the applicable purpose, consent requirements and privacy commitments. Personal data will not be used for unrelated AI model training or other incompatible purposes without an appropriate lawful basis and, where required, user consent or other applicable authorisation.

09 Data Sharing and Third-Party Service Providers

SehatGraph may engage service providers and technology partners to support the operation of its services, including:

  • Cloud infrastructure providers
  • Technology and software providers
  • AI and analytics service providers
  • Payment service providers
  • Healthcare service providers, laboratories, and pharmacies
  • Doctors and healthcare professionals
  • Communication and customer-support providers
  • Security and fraud-prevention providers

Such sharing will be limited to what is reasonably necessary for the relevant purpose and will be subject to applicable contractual, security and legal requirements. We do not sell users' personal data as a commercial commodity.

10 Data Security

SehatGraph is committed to implementing reasonable technical and organisational safeguards appropriate to the nature and risks of the personal data processed.

Security controls include: Access controls, authentication mechanisms, encryption during transit and at rest, secure data transmission, role-based access, monitoring and logging, backup and recovery controls, security testing, vulnerability management, incident response procedures, and employee/contractor access controls.

No digital system can be guaranteed to be completely secure. Users should also maintain the confidentiality of their passwords, authentication credentials and devices.

11 Personal Data Breach

A personal data breach may include unauthorised access, disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data.

SehatGraph maintains processes for identifying, assessing, containing, investigating and responding to suspected security incidents.

Where notification is required under applicable law, SehatGraph will take the required steps within the applicable timelines. The DPDP Rules, 2025 establish requirements relating to reasonable security safeguards and personal data breach notifications.

12 Data Retention

SehatGraph retains personal data only for as long as reasonably necessary for the relevant purpose, unless a longer retention period is required or permitted by applicable law.

Retention periods depend on data type, service provided, user relationship, legal/regulatory obligations, accounting/financial requirements, dispute resolution, security/fraud prevention, and medical record requirements where applicable.

When personal data is no longer required for a lawful purpose, it may be deleted, anonymised or otherwise handled in accordance with applicable law and our data retention procedures.

13 Your Rights as a Data Principal

Subject to applicable law and its conditions, users may have rights relating to their personal data, including:

Access: You may request information regarding the personal data being processed and other information available to you under applicable law.
Correction and Updating: You may request correction or updating of inaccurate or incomplete personal data.
Erasure: You may request erasure of personal data where applicable, subject to lawful retention requirements.
Withdrawal of Consent: Where processing is based on consent, you may withdraw your consent.
Grievance Redressal: You may raise a grievance regarding our processing of your personal data.
Nomination: Where applicable under the DPDP framework, a Data Principal may exercise nomination-related rights.

14 Data Deletion

Users may request deletion of their personal data through the Data Deletion Request mechanism provided by SehatGraph.

Deletion may be subject to information that SehatGraph is legally required or otherwise lawfully permitted to retain.

Where deletion cannot immediately be completed because of a legal or other permitted requirement, SehatGraph may restrict or securely retain the relevant information for the required period.

15 Children's Data

SehatGraph takes additional care when processing personal data relating to children.

Where applicable, SehatGraph will implement mechanisms required by the DPDP Act and applicable rules concerning children's personal data, including applicable requirements regarding verifiable parental or lawful guardian consent.

We do not knowingly seek to process children's personal data in a manner prohibited by applicable law.

16 Cross-Border Processing

SehatGraph may use technology or service providers whose infrastructure or operations may involve processing outside India.

Any such processing will be subject to applicable Indian law, contractual safeguards, security requirements and any restrictions or requirements notified by the Government of India from time to time.

The DPDP Act applies, among other circumstances, to certain processing outside India connected with offering goods or services to Data Principals in India.

17 Data Protection by Design

SehatGraph aims to incorporate privacy and security considerations into product development and technology architecture. This includes:

  • Data minimisation & purpose limitation
  • Strict access control & secure-by-design development
  • Privacy-aware product design & appropriate retention controls
  • Continuous security monitoring & responsible AI practices

18 Grievance Redressal

If you have a privacy or personal-data-related concern, you may contact SehatGraph through our designated privacy/grievance channel.

Privacy & Grievance Contact:
Email: privacy@sehatgraph.com / support@sehatgraph.com
Website: https://www.sehatgraph.com

Please include sufficient information to help us understand and investigate your request. We may request reasonable information to verify your identity before processing certain requests.

19 Data Protection Requests

For requests concerning access to personal data, correction, erasure, consent withdrawal, data deletion, privacy concerns, or grievances, please use the relevant request mechanism available on the SehatGraph website/app or contact our privacy team.

20 Third-Party Links and Services

The SehatGraph website or application may contain links or integrations to third-party websites, applications or services. Their privacy practices may differ from those of SehatGraph. Users should review the privacy policies of third-party services before providing personal data to them.

21 Updates to this DPDP Compliance Policy

SehatGraph may update this policy from time to time to reflect changes in applicable law, regulatory requirements, technology, products and services, data processing practices, or security practices.

Material changes may be communicated through appropriate channels where required. The latest version will be published on the SehatGraph website.

22 Governing Framework

This policy is intended to describe SehatGraph's approach to personal-data protection in the context of applicable Indian data-protection requirements, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as applicable from time to time.

The DPDP Rules, 2025 were notified by the Ministry of Electronics and Information Technology in November 2025 and provide the implementation framework for the Act, with specified provisions coming into force on a phased timeline.

23 Contact Us

Sehat Graph Technologies Private Limited

Website: https://www.sehatgraph.com

Privacy & Data Protection: support@sehatgraph.com / privacy@sehatgraph.com

For privacy, data-protection, consent, deletion or grievance-related requests, please contact us through the above channel.

© 2026 Sehat Graph Technologies Private Limited. All Rights Reserved.