Privacy Policy
Effective date: 1 April 2025 · Vyasa Integrated Healthcare Pvt. Ltd.
1. Who we are
HealthForIndia is operated by Vyasa Integrated Healthcare Private Limited, a company registered in India. We build tools that make public health data accessible to citizens, policymakers and researchers. This policy explains how we handle personal information when you use our platform at healthforindia.vyasa.health (the "Platform").
2. Data we collect
We collect the minimum data needed to provide our services:
- Account data — name, email address and hashed password when you register as a citizen user.
- Profile data — phone number, location (city/district), age — only if you choose to add them.
- Health Locker files — documents you upload (reports, prescriptions) are stored encrypted and accessible only by you.
- Submissions — health data documents you contribute are stored with your email to allow status tracking.
- Usage data — standard server logs (IP address, browser type, pages visited) for security and debugging. These are not sold or shared.
- Cookies — session cookies for authentication and analytics cookies (Google Analytics / Vercel Analytics) to understand usage. See our Cookie Policy.
3. How we use your data
- To provide and personalise the Platform (state health stats, facility finder, health locker).
- To verify your identity and secure your account.
- To process data submissions and notify you of their review status.
- To improve the Platform based on aggregated, anonymised usage patterns.
- To respond to your support or feedback requests.
We do not sell your personal data to third parties. We do not use your health locker data for advertising or model training.
4. Data storage and security
All data is stored in Google Cloud (Firebase / Firestore) with servers located in Asia (Mumbai region). Passwords are hashed using scrypt with a random salt — we cannot recover your password. Health locker files are stored as encrypted blobs accessible only via authenticated API calls. We use HTTPS for all data in transit.
5. Data retention
Account data is retained for as long as your account is active. If you delete your account, personal data is permanently removed within 30 days. Health locker files are deleted immediately upon your request. Anonymised aggregate statistics derived from submissions may be retained indefinitely.
6. Your rights
Under applicable Indian data protection law (DPDPA 2023) and, where applicable, GDPR, you have the right to:
- Access — request a copy of personal data we hold about you.
- Correction — update inaccurate data via your profile settings.
- Deletion — request account and data deletion by emailing us.
- Portability — receive your data in a machine-readable format.
- Objection — opt out of analytics cookies via Cookie Settings in the footer.
To exercise any right, email support@vyasaa.com. We will respond within 30 days.
7. Third-party services
- Google Maps / Places API — used for nearby facility search. Google's privacy policy applies to location data passed in API requests.
- Nominatim (OpenStreetMap) — used for reverse geocoding GPS coordinates. No personal data is stored by Nominatim.
- Vercel — hosting provider. Edge logs are subject to Vercel's privacy policy.
- Firebase / Google Cloud — database and authentication infrastructure.
8. Children
HealthForIndia is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it promptly.
9. Changes to this policy
We may update this policy as the Platform evolves. Material changes will be flagged with an updated effective date. Continued use of the Platform after changes constitutes acceptance of the updated policy.
10. Contact
Questions about this policy? Email support@vyasaa.com or visit our Contact page.