Enterprise Security & DPDP Safeguards

Security & Data Protection

Our multi-layered technical, cryptographic, and operational defense architecture safeguarding personal and health information.

Effective Date: 22 August 2026 Last Updated: 22 August 2026 Sehat Graph Technologies Pvt. Ltd.
AES-256
Storage Encryption
TLS 1.3
In-Transit Transit
Zero-Trust RBAC
Least-Privilege Access
24/7 SIEM
Threat Monitoring

01 Our Commitment to Security

At Sehat Graph Technologies Private Limited (“SehatGraph”), protecting the security and confidentiality of personal data is a fundamental part of our technology and service design.

Because SehatGraph may process health, medical and other personal information, we take appropriate measures to protect data against unauthorised access, use, disclosure, alteration, loss or destruction.

Our security practices are designed to support the requirements of applicable Indian data-protection laws, including the Digital Personal Data Protection Act, 2023 and applicable rules.

02 Data Protection Principles

SehatGraph follows privacy and security principles including:

  • Data minimisation
  • Purpose limitation
  • Controlled access
  • Secure processing
  • Appropriate data retention
  • Privacy-aware product design
  • Responsible handling of health information
  • Continuous improvement of security practices

03 Technical Security Measures

Depending on the service and technology environment, SehatGraph may use appropriate technical safeguards including:

Encryption of data during transmission (TLS 1.3)
Encryption for stored data (AES-256)
Secure multi-factor authentication
Role-based access controls (RBAC)
Least-privilege access restrictions
Continuous security logging & SIEM
Automated backup & recovery systems
Vulnerability management & pen-testing
Threat & malware protection controls
Secure CI/CD software development

The specific security controls used may vary depending on the system, service and technical environment.

04 Access Control

Access to personal data is restricted to authorised personnel, systems and service providers who require access for legitimate business or service purposes.

Where appropriate, access is strictly governed through authentication, role-based permissions, least-privilege principles, administrative access controls, and comprehensive monitoring and audit logging.

We aim to limit access to personal data to what is reasonably necessary.

05 Protection of Health Information

Health-related information may include medical reports, symptoms, prescriptions, consultation information, diagnostic information and other health-related data provided through SehatGraph.

We apply appropriate safeguards to protect such information and seek to prevent unauthorised access or disclosure.

Users should ensure that their account credentials and devices are kept secure and should not knowingly share their account access with unauthorised persons.

06 AI and Data Security

SehatGraph may provide AI-powered healthcare and wellness features.

Where personal data is processed through AI-enabled services, appropriate security and access controls are intended to be applied to the relevant processing environment.

We seek to prevent unauthorised access to information submitted through AI-enabled features.

Personal data will not be used for unrelated purposes in a manner inconsistent with our privacy commitments and applicable law.

07 Third-Party Service Providers

SehatGraph may work with trusted third-party technology and service providers, including cloud infrastructure, payment, communication, security, analytics, AI and healthcare service providers.

Where third parties process personal data on our behalf, we seek to implement appropriate contractual, technical and organisational safeguards consistent with applicable requirements.

08 Data Storage

Personal data may be stored using secure infrastructure operated by SehatGraph or its authorised technology service providers.

We seek to use appropriate security controls for data storage, access and transmission. Data may be stored or processed in locations permitted under applicable law and our service requirements.

09 Data Retention and Secure Deletion

SehatGraph retains personal data only for as long as reasonably necessary for the relevant purpose or as required or permitted by applicable law.

When personal data is no longer required, we may delete, anonymise or securely dispose of it in accordance with applicable requirements and our retention procedures.

10 Security Monitoring

We may monitor systems, access activity and security events to:

  • Detect suspicious activity and unauthorized intrusions
  • Prevent unauthorised access
  • Protect platform availability and integrity
  • Investigate security incidents
  • Improve our overall security controls

Security logs and related information may be retained for appropriate periods for security, operational, legal or regulatory purposes.

11 Personal Data Breach Response

SehatGraph maintains procedures for identifying, assessing, containing and responding to suspected security incidents and personal data breaches.

Where a breach occurs, our response framework entails:

  1. Identifying and containing the incident
  2. Assessing affected systems and data
  3. Taking corrective security measures
  4. Investigating the root cause
  5. Documenting the incident
  6. Notifying relevant parties or authorities where required by applicable law
  7. Taking steps to reduce potential harm

12 Employee and Personnel Security

Access to personal data may be provided to authorised employees, contractors and service providers only where reasonably necessary.

Where appropriate, personnel are bound by rigorous confidentiality obligations and formal security/privacy compliance training.

13 User Responsibilities

Security is a shared responsibility. Users should:

  • Use strong, unique, and complex passwords
  • Keep login credentials and tokens strictly confidential
  • Avoid sharing account access with third parties
  • Keep devices, browsers, and mobile operating systems updated
  • Use trusted and secure networks when accessing sensitive health metrics
  • Log out of shared or public devices after use
  • Immediately report suspected unauthorised access to SehatGraph

14 Responsible Disclosure

If you discover a potential security vulnerability affecting a SehatGraph website, application or service, please report it responsibly to:

Security Team Email: Support@sehatgraph.com
Subject: Vulnerability Report / Security Alert

Please provide sufficient technical information to help our security team understand and investigate the issue. Do not attempt to access, modify, delete or disclose another person's data or system information.

15 No Absolute Security Guarantee

Although SehatGraph takes reasonable measures to protect personal data, no internet transmission, electronic storage system or digital service can be guaranteed to be completely secure.

We continuously review and improve our security practices to address evolving risks and threats.

16 Updates to Security Practices

Security threats and technologies evolve over time. SehatGraph may periodically update its security practices, controls and procedures to improve the protection of personal data and services.

This page may also be updated to reflect changes in our technology, services or applicable legal requirements.

17 Contact Us

Sehat Graph Technologies Private Limited

Website: https://www.sehatgraph.com

Security Team: Support@sehatgraph.com

Privacy & Data Protection: Support@sehatgraph.com

For security vulnerabilities, suspected unauthorised access or data-security concerns, please contact us through the appropriate email address above.

© 2026 Sehat Graph Technologies Private Limited. All Rights Reserved.