Medigrace Hospital

Legal & Compliance

Privacy Policy

Effective: 1 January 2024  |  Last Updated: 1 June 2025

Medigrace Hospital ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect information gathered through our website medigracehospital.in and related services, in compliance with the General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

By using our website or submitting an enquiry form you agree to the collection and use of your information as described in this policy. If you do not agree, please do not use our website.

1. Who We Are

Data Controller / Data Fiduciary:
Medigrace Hospital
Shree Radheya Health Heights, Ramdaspeth, Nagpur – 440 010, Maharashtra, India
Email: [email protected]
Phone: +91-8007993330

We are a multi-specialty women's healthcare hospital providing IVF, infertility treatment, gynecology, obstetrics, laparoscopic surgery and cancer care services.

2. Data We Collect

a) Information You Provide Directly

When you fill our enquiry, appointment, or contact forms we may collect:

  • Full name
  • Mobile / phone number
  • Email address
  • City / location
  • Medical concern or specialty of interest (free-text)
  • Preferred appointment date / time

b) Medical Information

If you choose to share details about your medical history, symptoms, or treatment queries via our forms or during consultations, this constitutes sensitive personal data (health data) and is subject to the heightened protections described in Section 5.

c) Automatically Collected Data

When you visit our website, we automatically collect:

  • IP address (anonymised where technically possible)
  • Browser type and version
  • Operating system
  • Referring / exit pages
  • Date and time of visit
  • Pages viewed and time spent on page
  • Device type (mobile / tablet / desktop)

d) Cookies and Tracking Technologies

See Section 7 (Cookies) for full details.

3. How We Use Your Information

We use your personal data for the following purposes and on the following legal bases:

Purpose Legal Basis (GDPR) Legal Basis (DPDP Act)
Respond to appointment requests and enquiries Contract performance / Legitimate interests Consent / Legitimate use
Schedule and manage consultations Contract performance Consent
Provide medical diagnosis and treatment Vital interests / Healthcare provision (Art. 9(2)(c)(h)) Medical necessity
Send appointment reminders and follow-up communications Legitimate interests / Consent Consent
Improve website functionality and user experience Legitimate interests Legitimate use
Comply with legal and regulatory obligations Legal obligation (Art. 6(1)(c)) Legal obligation
Analytics (aggregated, anonymised) Legitimate interests Legitimate use

We do not sell your personal data to any third party for marketing or commercial purposes, ever.

4. Medical Record Confidentiality

Medigrace Hospital treats all patient medical records as strictly confidential. Our approach is governed by:

  • The Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 which impose a duty of medical confidentiality
  • The Clinical Establishments Act, 2010 and applicable state rules
  • The DPDP Act 2023 provisions on sensitive personal data (health data)
  • GDPR Article 9 protections for special categories of personal data (health data)

Access to Medical Records

Your medical records are accessible only to:

  • The treating physician(s) and clinical team directly involved in your care
  • Administrative staff on a strict need-to-know basis for billing and scheduling
  • Other healthcare professionals to whom you have been referred, with your consent
  • Regulatory or legal authorities where disclosure is required by law

Retention of Medical Records

Medical records are retained for a minimum of 7 years from the date of the last consultation, as recommended by the Indian Medical Association and applicable law. Records of minors are retained until the patient reaches the age of 25 years or for 7 years after the last treatment, whichever is later.

We will never disclose your diagnosis, treatment, or medical history to family members, employers, or any other third party without your explicit written consent, except where legally mandated.

5. How We Share Your Information

We share personal data only in the following limited circumstances:

a) Service Providers (Data Processors)

We engage trusted third-party service providers who process data solely on our behalf, under strict data processing agreements:

  • Email delivery (SMTP2GO): Used to transmit your enquiry details to our team. SMTP2GO is GDPR-compliant and processes data on servers in the EU/US (subject to Standard Contractual Clauses).
  • Website hosting (Hostinger): Your data may be stored on Hostinger's servers. Hostinger is GDPR-compliant.
  • Analytics (Google Analytics): Anonymised, aggregated usage data to improve the website. No personally identifiable information is sent to Google Analytics.

b) Legal Requirements

We may disclose your data if required by law, court order, or government authority, including under the DPDP Act's provisions on disclosures to the Indian government for reasons of national security or law enforcement.

c) Healthcare Partners

With your explicit consent, we may share relevant medical information with referred specialists, diagnostic laboratories, or other healthcare providers involved in your care.

d) Business Transfers

In the event of a merger, acquisition, or sale of hospital assets, your data may be transferred to the successor entity, subject to the same privacy protections. You will be notified of any such change.

6. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:

  • SSL / TLS encryption for all data transmitted via our website
  • Access controls — data is accessible only to authorised personnel
  • Password protection and role-based access to internal systems
  • Secure email transmission via SMTP2GO with TLS encryption
  • Regular security reviews and staff training on data protection
  • Firewall and server-level protections on our hosting infrastructure

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. In the event of a data breach that affects your rights and freedoms, we will notify you and the relevant supervisory authority within the timeframes required by applicable law (72 hours under GDPR; as prescribed under the DPDP Act).

7. Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies. A cookie is a small text file placed on your device to help the website remember your preferences and improve your experience.

Types of Cookies We Use

  • Strictly Necessary Cookies: Required for the website to function (e.g. form security tokens, session cookies). These cannot be disabled.
  • Analytics Cookies (Google Analytics): Help us understand how visitors interact with our website. All data is anonymised — no personal identifiers are transmitted. You can opt out via Google Analytics Opt-out.
  • Preference Cookies: Remember your language or layout preferences.

Managing Cookies

You can control and delete cookies through your browser settings. Disabling certain cookies may affect the functionality of our website. For more information on how to manage cookies visit aboutcookies.org.

We do not use advertising or remarketing cookies, and we do not place cookies for the purpose of profiling users for third-party advertising networks.

8. Third-Party Services

Our website may contain links to or embed features from third-party services. We are not responsible for the privacy practices of these services.

  • Google Maps: Used to display our hospital location. Google's Privacy Policy applies.
  • Google Fonts: Fonts loaded from Google's CDN. Google may log your IP. We aim to serve fonts locally in future releases.
  • WhatsApp (Meta): The WhatsApp chat button links to WhatsApp's platform. Meta's Privacy Policy applies when you use it.
  • Facebook / Instagram / YouTube: Our social media profiles are hosted on these platforms. Their respective privacy policies apply when you visit our social pages.
  • SMTP2GO: Used for email delivery of enquiry forms. View their Privacy Policy.

We encourage you to read the privacy policies of any third-party services you interact with through our website.

9. Data Retention

We retain your personal data only for as long as necessary for the purposes for which it was collected:

  • Enquiry / contact form data: 3 years from date of submission, or for the duration of the patient relationship, whichever is longer.
  • Medical records: Minimum 7 years from date of last consultation (or as required by applicable law).
  • Website analytics data: 26 months (Google Analytics default, or shorter where configured).
  • Email communication records: 3 years.

At the end of the applicable retention period, personal data is securely deleted or anonymised.

10. Your Rights

Depending on your location, you have the following rights regarding your personal data. We honour these rights for all our patients and website users regardless of jurisdiction.

Under GDPR (EU / UK Users)

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Ask us to correct inaccurate or incomplete data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your data, subject to legal retention obligations.
  • Right to Restrict Processing (Art. 18): Ask us to limit how we use your data.
  • Right to Data Portability (Art. 20): Receive your data in a machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time.

Under DPDP Act 2023 (India Users)

  • Right to Information (Sec. 11): Know what personal data is being processed and the purpose.
  • Right to Correction and Erasure (Sec. 12): Correct inaccurate data and request erasure when no longer needed.
  • Right of Grievance Redressal (Sec. 13): Have grievances addressed within a reasonable time.
  • Right to Nominate (Sec. 14): Nominate another person to exercise rights on your behalf in the event of death or incapacity.

To exercise any of your rights, please contact our Data Protection Officer at [email protected] or call us at +91-8007993330. We will respond within 30 days. We may need to verify your identity before processing the request.

Filing a Complaint

If you believe we have not handled your data correctly you have the right to lodge a complaint with:

  • India: The Data Protection Board of India (once operational under the DPDP Act 2023)
  • EU: Your local EU Data Protection Authority (DPA)
  • UK: The Information Commissioner's Office (ICO) — ico.org.uk

11. Children's Privacy

Our website is not directed at children under the age of 18 years. We do not knowingly collect personal data from children through our website without verifiable parental or guardian consent.

As a hospital, we do provide medical services to patients of all ages; in such cases, the parent or legal guardian provides consent and their details are collected in accordance with applicable medical consent laws. Medical records of minors are subject to enhanced confidentiality protections.

If you believe we have inadvertently collected personal data from a child under 18 without proper consent, please contact us immediately at [email protected] and we will promptly delete such data.

12. International Data Transfers

Medigrace Hospital is based in India. If you are accessing our website from outside India, your data will be transferred to and processed in India. We take steps to ensure that such transfers comply with applicable data protection law.

Where we use third-party service providers based outside India (e.g., SMTP2GO, Hostinger, Google), such transfers are covered by standard contractual clauses or adequacy decisions as appropriate under GDPR, and by the provisions of the DPDP Act as they come into force.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes we will:

  • Update the "Last Updated" date at the top of this page
  • Post a prominent notice on our website homepage
  • Where required by law, notify affected individuals directly via email

We encourage you to review this policy periodically. Your continued use of our website after any changes constitutes your acceptance of the updated policy.

14. Contact Us & Data Requests

For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, please contact:

Data Protection Officer / Privacy Contact
Medigrace Hospital
Shree Radheya Health Heights, Ramdaspeth
Nagpur – 440 010, Maharashtra, India

Email: [email protected]
Phone: +91-8007993330
Hours: Monday – Saturday, 9:00 AM – 6:00 PM (IST)

We aim to respond to all data-related requests within 30 calendar days. For complex requests or where an extension is required, we will inform you within the initial 30-day period.

This Privacy Policy is governed by the laws of India. Any disputes shall be subject to the exclusive jurisdiction of the courts in Nagpur, Maharashtra, India. This policy was last reviewed and updated on 1 June 2025.

Call Now