MedCord AI Product Suite (MAIPS)
Privacy Policy
CREATED ON: [13 August 2024]
LAST UPDATED: [17 August 2024]
This Privacy Policy (�Policy�) outlines
Tech Applied Well Technologies�s (�TAW;�, �TAW�,
�Taw�,�taw�, �taw;�, �we� or �us�)
practice in relation to the storage, use, processing, and disclosure
of personal data that you have chosen to share with us when you access
our website https://www.medcord.in and mobile application �MedCord�
(collectively, the MedCord AI Product Suite (�MAIPS") or
�Platform� , or personal data that we may have access to in
relation to your use of the Services.
At taw, we are committed to protecting your personal data and respecting your privacy. Please read the following terms of the Policy carefully to understand our practices regarding your personal data and how we will treat it. Your privacy is important to us. Maintaining your trust and confidence is one of our highest priorities. We ensure secure transactions and strive to take reasonable care in the protection of information we receive during the course of us rendering services.
This policy sets out the basis on which any personal data we collect from you, we collect about you, or that you provide to us, will be processed by us. If You provide us with personal information about someone else, you confirm that they are aware that You have provided their information and that they consent to our use of their information according to our Privacy Policy.
This Privacy Policy may be subject to further changes including as may be warranted by change in law. Upon updating the Policy, we may revise the "Updated" date at the top of this Policy. We therefore request you to go through our Privacy Policy frequently to be updated with changes incorporated from time to time. Your continued engagement with us will imply your acceptance of such updates to this Policy.
If you do not agree to the terms of this Privacy Policy, please do not (i) access or use our Platform, (ii) avail of services from us, and do not disclose your information to us.
By providing us your and/or your family members and/or your dependents information, you hereby (i) consent to the collection, storage, disclosure, use for manual, machine learning or other AI based processing and research, processing and transfer of such information for the purposes as disclosed in this Policy and (ii) represent that you have taken the necessary consents from such persons to provide us with such information. You are providing the information out of your free will. You have the option not to provide the data or Personal Information / Sensitive Personal Data or Information (as defined below) sought to be collected if you do not agree with this Policy.
The terms of this Privacy Policy are applicable to all individuals and entities that visit, access and / or avail of our services via the Platform from whom we collect information, including insurers, healthcare providers, corporate clients and employees of corporate clients. Capitalised words in the Policy shall have the same meaning ascribed to them in the Terms and Conditions (�Terms�), available at Terms & Conditions. Please read this Policy in consonance with the Terms.
1. THE DATA WE COLLECT ABOUT YOU
a. Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed � for example, anonymous data.
b. Taw may supplement the information provided by You with information from third parties and add it to the information provided by You.
c. We may collect, use, store and transfer different kinds of personal data including sensitive personal data or information about you to provide you with or in connection with the Services. Such personal data includes:
� data pertaining to your identity and profile-related data, such as your first and last name, profile image, username or similar identifiers, gender, title, passwords, purchases or orders, feedback, survey responses, etc.;
� data pertaining to your health, diagnosis, disease, condition, prognosis, treatment, medication, laboratory reports, scans and doctor�s comments and notes on this data, etc.;
� contact details, including email addresses, phone numbers, delivery addresses, business addresses, etc.;
� transaction data, including details about payments to and from you and details of products and services you have purchased or sold;
� technical data includes IP addresses, browser types and versions, time zone settings and locations, operating systems, and other technology on the devices you use to access the platform;
� usage data including information about how you use our Services; and
� marketing and communications data includes your preferences in receiving marketing from us and our third parties and your communication preferences.
� KYC Data - We may retrieve from Your records available with third party including from Know Your Customer (KYC) Registration Agency (KRA) such as name, KYC details, KYC status, father�s/spouse�s name, occupation, address details and other related documents, for completion of Your KYC, which is required by the financial institutions for processing of Your application for availing a financial product.
� Other Information - We may also request You to provide other information as and when necessary, subject to your consent.
d. We may also collect, use, and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data under applicable laws. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific feature of the Services.
e. Taw may use the personal information and transaction data collected to provide, maintain, improve, analyze and personalize the Services to its Users, partners and third-party providers. More specifically, Taw may use such information to:
� Categorise customers into different risk profiles, and create insights and summaries, the logic of which can be solely decided by Taw.
� We can distribute these insights and summaries via taw app, web portal, telephonic calls, text messages, WhatsApp, email, or other electronic mediums
f. Where we need to collect personal data by law, or under the terms of the arrangement we have with you, and you fail to provide that data when requested, we may not be able to perform our obligations under the arrangement we have with you or are trying to enter into with you (for example, to provide you with features of the Services). In this case, we may have to cancel or limit your access to the Services, but we will notify you if this is the case at the time.
g. We may collect certain Personal Information including Sensitive Personal Data or Information (as defined below) from you and/or your family members and/or your dependents while using our Platform or directly from the concerned insurer and / or your employer, if applicable.
h. Personal Information means any information that relates to or identifies you and/or your family members and/or your dependents and may include name, identity card number, date of birth, employee code, email address, residential address, mobile number, alternate telephone number, etc.
i. Further, you would be required to give us certain Sensitive Personal Data or Information about you and/or your family members and/or your dependents. Sensitive Personal Data or Information shall mean such Personal Information which consists of information relating to
� Financial information such as bank account or any other payment instrument details;
� Physical, physiological and mental health condition;
� Medical records and history; and
� Any detail relating to the above
j. We inform you that our Platform may collect certain Personal Information and/or Sensitive Personal Data or Information about you and/or your family members and/or your dependents such as medical and health records including but not limited to your prescription, test reports, past medical history, etc.
k. We understand that the Personal Information and/or Sensitive Personal Data or Information is extremely private to you and/or your family members and/or your dependents and assure you that it will be used only for providing required healthcare services as mutually agreed to be rendered by us, and as stated under this Policy.
l. While using our Platform and for availing of any of our services, you would be required to give us your and/or your family members and/or your dependents Personal Information and/or Sensitive Personal Data or Information. This could be done post login on our Platform using the OTP given by us, which will be shared with you by email, which is unique to you.
m. When you visit our Platform, we may use GPS technology (or other similar technology) to determine your current location in order to determine the city or area you are located within for helping you in selection of right provider for the services you wish to avail. While using our Platform, you may also be required to give us access to few files available on your device. In case you do not want us to use your location for the purposes set forth above, you should turn off the location services. We may use your photo gallery or camera only to facilitate the uploading of documents or files in certain flow but we will not access information without your explicit consent. You have the option not to provide us with consent or to subsequently revoke consent, for our use of your device's camera / file and folders.
n. On receipt of express consent from the user, we collect certain information limited to user's name, email id and phone number provided by the user while installing and using the MedCord mobile app, we may also collect certain non-identifiable aggregated health-related information of the user from Apple Health Kit to create user profile which enable the user to automatically track their step count, water consumption, weight, calorie count and blood pressure. We do not store any payment details including but not limited to net banking, Credit card or Debit card details.
o. The eSPI Rules 2011 further define �Sensitive Personal Data or Information� of a person to mean personal information about that person relating to:
� Passwords
� financial information such as bank accounts, credit and debit card details or other payment instrument details
� physical, physiological, and mental health condition
� sexual orientation
� medical records and history
� biometric information
� information received by body corporate under lawful contract or otherwise
� visitor details as provided at the time of registration or thereafter; and call data records
2. HOW DO WE COLLECT DATA ABOUT YOU?
a. We use different methods to collect and process data about you.
i.Information you give us � This is the information (including identity, contact, health and marketing and communications data) you consent to giving us about you when you create a Profile or by corresponding with us (for example, by email or chat). It includes information you provide when you register to use the Services, use an in-Platform feature, or share data through the Services, through other activities commonly carried out in connection with the Services, and when you report a problem with the Platform and our Services. If you contact us, we will keep a record of the information shared during the correspondence.
ii.Information that you authorise a user of the Services to share with us � We may collect data and information about you that you authorise a healthcare institution, organization, doctor, advisor or counsellor who you have chosen to provide you with advice, counselling or treatment to share, edit, post or create.
iii.Information we collect about you and your device � Each time you visit our Platform or use one of our Services, we will automatically collect personal data including device and usage data. We collect this data using cookies and other similar technologies.
iv.Information we receive from other sources including third parties and publicly available sources - We will receive personal data about you from various third parties and public sources as set out below:
A. Analytics providers such as Google and Facebook;
B. Advertising networks;
C. Search information providers;
D. Contact, financial and transaction data from providers of technical, payment, and delivery services;
E. Identity and contact data from data brokers or aggregators; and
F. Identity and contact data from publicly available sources.
3. HOW DO WE USE AND DISCLOSE DATA WE COLLECT?
a. We will only use your personal data when the law allows us to. Most commonly, we will use your personal data to provide you with the Services, or where we need to comply with a legal obligation.
b. You understand that when you consent to providing us with your personal data, you also consent to us sharing the same with third parties. You are aware that by using our Services or creating an account on the Platform, you authorise us, our associate partners, and affiliates to contact you via email, phone, or otherwise. This is to ensure that you are aware of all the features of the Services.
c. You are aware that any and all information pertaining to you, whether or not you directly provide it to us (via the Services or otherwise), including but not limited to personal correspondence such as emails, instructions from you etc., may be collected, compiled and shared by us in order to render Services to you and you expressly authorise us to do so. This may include but not be limited to storage providers, all types of clinics, hospitals, labs, doctors, clinicians, attenders, counsellors, advisors, payments systems providers, marketing partners, data analytics providers, and consultants, lawyers, and auditors. We may also share this information with our parent company, subsidiaries, affiliates or any of their holding companies.
d. You agree and acknowledge that we may share data without your consent, when it is required by law or by any court or government agency or authority to disclose such information. Such disclosures are made in good faith and belief that it is reasonably necessary to do so for enforcing this Policy or the Terms, or in order to comply with any applicable laws and regulations.
e. In general, we will not disclose personal data except in accordance with the following purpose/activity:
i.To install the Platform and register you as a user;
ii.To deliver Services;
iii.To manage our relationship with you including notifying you of changes to any Services;
iv.To administer and protect our business and the Services including troubleshooting, data analysis and system testing;
v.To deliver content and advertisements to you;
vi.To make recommendations to you about goods or services which may interest you;
vii.To measure and analyse the effectiveness of the advertising we serve you;
viii.To monitor trends so we can improve the Services;
ix.To perform our obligations that arise out of the arrangement we are about to enter or have entered with you;
x.To enforce our Terms;
xi.Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests;
xii.To comply with a legal or regulatory obligation.
f. You authorise us to send you electronic alerts and messages for details pertaining to registration on the Platform, requirements arising out of the provision of Services, and advertising in any messaging, email, SMS or social media platforms that you register with us.
g. Further, you agree to receive promotional and other emails and other forms of communication from us. Through such communication you will receive information about the latest developments on the Services. You may unsubscribe from our mailing list at any time, via the unsubscribe option we offer.
4. TRANSFER OF PERSONAL DATA
a. As a part of your use of the Services, the information and personal data you provide to us may be transferred to and stored at countries other than India. This may happen if any of our servers are from time to time located in a country other than India, or one of our service providers is located in a country other than India. We may also share information with entities of countries other than India. These countries shall be subject to data laws of their respective countries.
b. If you use the Services while you are outside India, your information may be transferred to a country other than India in order to provide you with the Services.
c. By submitting your information and personal data to us, you agree to the transfer, storage, and/or processing of such information and personal data outside India in the manner described above.
5. THIRD PARTY LINKS AND USER EXPERIENCE IMPROVEMENT SERVICES
a. Our Services may, from time to time, contain services provided by or links to and from the websites of our partner networks, advertisers and affiliates (�Third Party Services�). Please note that the Third-Party Services, that may be accessible through our Services have their own privacy policies. We do not accept any responsibility or liability for the policies or for any personal data that may be collected through the Third-Party Services. Please check their policies before you submit any personal data to such websites or use their services.
b. We may use third-party user experience improvement services (including but not limited to those provided by Google Inc and/or its affiliates) and applications to better understand your behaviour on the Services.
c. The information collected includes (but is not limited to):
A. age;
B. gender;
C. preferences; and
D. interests.
d. Your relationship with these third parties and their services and tools is independent of your relationship with us. These third parties may allow you to permit/restrict the information that is collected. It may be in your interest to individually restrict or enable such data collections.
e. The place of processing information depends on each third-party service provider and you may wish to check the privacy policy of each of the service providers to identify the data shared and its purpose. You will be subject to a third party�s privacy policy if you opt in to receive communications from third parties. We will not be responsible for the privacy standards and practices of third parties.
6. COOKIES
a. We use cookies and/or other tracking technologies to distinguish you from other users of the Services and to remember your preferences. This helps us to provide you with a good experience when you use our Services and also allows us to improve the Services.
b. We collect data by way of �cookies�. Cookies are small data files which are sent to your browser from the Platform and are stored on your computer or device (hard drive). The cookies shall not provide access to data in your computer or device such as email addresses or any other data that can be traced to you personally. The data collected by way of cookies will allow us to administer the Services and provide you with a tailored and user-friendly service. The cookies shall enable you to access certain features of the Services. Most web browsers and devices can be set to notify when you receive a cookie or prevent cookies from being sent. If you do prevent cookies from being sent, it may limit the functionality that we can provide when you visit the Platform or try to access some of the Services.
c. Additionally, you may encounter cookies or other similar devices on certain pages of the Services that are placed by third parties. We do not control the use of cookies by third parties. If you send us personal correspondence, such as emails or letters, or if other users or third parties send us correspondence about your activities in relation to the Services, we may collect such information into a file specific to you.
d. We may use cookies on certain pages of the Platform to help analyse our web page flow and promote trust and safety.
e. We may also use "Cookies" to allow you to enter your password less frequently during a session. Most "Cookies" are "Session Cookies", meaning that they are automatically deleted from your hard drive at the end of a session. You are free to decline our "Cookies" if your browser permits you to do so, although we strongly recommend that you allow them to ensure you have access to all of our services.
7. DATA SECURITY
a. We implement certain security measures including encryption, firewalls, and socket layer technology to protect your personal information from unauthorised access and such security measures are in compliance with the security practices and procedures as prescribed under the Information Technology Act, 2000 and the applicable rules (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011). However, you agree and acknowledge that the above-mentioned measures do not guarantee absolute protection to the personal information and by accessing the Services, you agree to assume all risks associated with disclosure of personal information arising due to breach of firewalls and secure server software.
b. Where we have given you (or where you have chosen) a password and/or OTP that enables you to access certain parts of the Services, you are responsible for keeping this password confidential. We ask you not to share the password with anyone.
c. We will comply with the requirements under the Information Technology Act, 2000 and the rules made thereunder in the event of a data or security risk.
8. DATA RETENTION
You are aware that your personal data will continue to be stored and retained by us for a reasonable period after termination of your account on the Platform.
9. BUSINESS TRANSITIONS
You are aware that in the event we go through a business transition, such as a merger, acquisition by another organisation, or sale of all or a portion of our assets, your personal data might be among the assets transferred.
10. CHANGE IN PRIVACY POLICY
a. We keep our Policy under regular review and may amend this Policy from time to time, at our sole discretion.
b. The terms of this Policy may change and if it does, these changes will be posted on this page and, where appropriate, notified to you by email. The new Policy may be displayed on-screen and you may be required to read and accept the changes to continue your use of the Services.
c. Your continued use of the Services shall constitute consent to the latest policy.
11. ACCESS
You may be given the privilege to upload and store your and/or your family members and/or your dependents medical and health records on our Platform to which only you shall have access to by using your unique login credentials. This will help you have access to all your and/or your family members and/or your dependents medical and health records. We would like to reiterate that barring you, no one shall have access to these records except to the parties as mentioned in this Privacy Policy and such information shall be transmitted by us in encrypted form to avoid being hacked and decoded.
If you need to access your Sensitive Personal Data or Information, update or correct such information for any reason, you may do so by logging into the Platform and / or writing to us at grievance@medcord.in, and your Sensitive Personal Data or Information will accordingly be updated / corrected.
In the event you wish to know the names and addresses of the third parties your Personal Information has been disclosed to, you may request us for such information by writing to us at grievance@medcord.in. We will make all reasonable efforts to revert to you within a reasonable period of time, with the information that you require.
12. �Purpose for which Personal Information and/or Sensitive Personal Data or Information is collected and processed
We would like to state that we collect Personal Information and/or Sensitive Personal Data or Information that is absolutely necessary and relevant for us to make your experience hassle-free, convenient, smooth and most importantly, safe. This will also help us in providing you with customized services, assist you with all your queries, resolve the issues faced by you, to follow up with you in order to ensure a long, sustained relationship and most importantly to safeguard you from any kind of fraudulent and unlawful usage.
Personal Information and/or Sensitive Personal Data or Information may be collected by us directly from you and/or your family members and/or your dependents for the purpose of providing healthcare services including inpatient & outpatient services, administration of health screening and wellness benefits.
We may collect PSI in the following manner in order to facilitate the services seamlessly through our empanelled service providers. User hereby consent to the collection of such information by MedCord.
A. GPS Location Permission
� Location is utilised to deliver labs and Medicine delivery at their home.
� It is recommended that the User sets their location sharing �Always� as it will help MedCord to show you location specific data like availability of medicines, Lab tests.
� Connects the User to doctors available in their region for better facilitation of Services
B. Images / PDF / Files Access Permission
� To upload and store the medical prescription during a doctor consultation (or) to upload and store lab reports. These are actions performed by the User.
� To download and store the prescription / lab reports of the User
C. Camera Permission
� To capture a picture of medical records during a doctor consultation (or) a picture of the lab reports arising out of any medical test, examination, or scans taken in a lab, clinic, hospital or home (or) upload such records and store it under Users MedCord profile.
D. Consultation Recording Permission
� Required to record consultation in all forms of communication including but not limited to audio calls, video calls, and chat history of doctor consultations.
E. Storage Permission
� To show/access Users files uploaded by the User/ lab test records/ prescriptions in Users phone.
F. SMS Permission
� To support automatic OTP confirmation, so that you don't have to enter the authentication code manually.
G. Receive SMS Permission
� This helps MedCord to send the User reminders, order status, booking reminders related SMS.
H. Access Wifi State Permission
� This helps MedCord to optimize Users experience based on the Wifi's strength and signals, especially for optimizing video consultations.
I. Phone, Microphone Permission
� This will allow Users to call MedCord�s health expert and connect with our expert doctors.
J. Activity Recognition Permission
� To help you track/view/access Users fitness information like step count, sleep via wearable devices or using capability available in Users mobile.
K. Bluetooth and related Permissions
� This will enable us to provide a seamless experience while the user is taking an online video consultation by redirecting them to a Bluetooth headset if the user has already paired or auto-connected with their mobile.
L. Notification Permission
� This will enable us to send you alerts about your order status, notify you about the doctor's response, and send video call notifications during an online consultation.
13. Use of Personal Information
We collect Personal Information for various purposes including but not limited to the following:
14. Data Storage
All your Personal Information and/or Sensitive Personal Data or Information or medical records is hosted and/or processed by us at Amazon Web Services (AWS) Secure data servers located in India.
Your and/or your family members and/or your dependents' Personal Information and/or Sensitive Personal Data or Information or medical records is retained by us only for the purpose of providing the required services or for historical or statistical or legal purposes and such retention shall be for a period required to fulfil such purposes and / or as required under applicable law.
15. Transfer / Sharing of Information
We respect your privacy and hereby declare that we do not transfer and / or disclose your and/or your family members and/or your dependents' Personal Information and/or Sensitive Personal Data or Information except as under:
16. Advertisements and links to third-party websites
Our Platform may contain certain advertisements and links to third-party websites. We would like to clarify that we do not control or guarantee the accuracy, safety and integrity of the Personal Information and/or Sensitive Personal Data or Information you provide, if you choose to, share your information with these advertisers and third-party websites. It is, therefore, advised that you go through their terms and conditions and privacy policy before providing any Personal Information and/or Sensitive Personal Data or Information about yourself and/or your family members and/or your dependents on these websites.
17. Safety Precautions
We have stringent, strong, security measures undertaken to ensure against the loss, misuse or alteration of Personal Information and/or Sensitive Personal Data or Information about you and/or your family members and/or your dependents with us. We shall take all necessary precautions to safeguard your information and protect it from any unauthorized use. We have SSL Certificate issued by trusted certification authority and other safety measures in place to guard your information with us against any theft or unlawful usage or modification thereof. You are advised, however, that internet technology is not 100% safe and you should exercise discretion on using the same.
18. Consent
By using our Platform and providing your and/or your family members and/or your dependents' Personal Information and/or Sensitive Personal Data or Information, you hereby consent to the collection, storage, disclosure, transfer, processing and usage of your and/or your family members and/or your dependents' Personal Information and/or Sensitive Personal Data or Information by us as per the terms of this Privacy Policy. Kindly frequent this section to keep yourself updated of any changes made by us in the Privacy Policy.
You hereby confirm to the Company that you have taken necessary consent from your family members and/or your dependents for submission of their Personal Information and/or Sensitive Personal Data or Information with us.
The Company respects your privacy considerations and hence provides an option to you, to not provide the Personal Information and/or Sensitive Personal Data or Information sought to be collected. Further, you can also withdraw your consent which was earlier given to the Company, and the same must be communicated to the Company in writing. However, we inform you that on your electing to opt out (as envisaged in this section) or on withdrawal of your consent, the Company may not be in a position to provide you necessary services / benefits for which the Personal Information and/or Sensitive Personal Data or Information was sought to be collected.
You can stop all collection of information by the mobile application easily by uninstalling the mobile application from your device. You may use the standard uninstall processes as may be available as part of your mobile device or via the mobile application.
Further, you will have the option to not provide your consent, or withdraw any consent given earlier, provided that the decision to not provide consent / withdrawal of the consent is communicated to us at grievance@medcord.in
19. Grievance Officer
The name and contact details of the Grievance Officer is provided hereunder to address all your queries and grievances in accordance with the Information Technology Act, 2000, and Rules made thereunder.
Grievance Officer: Ms. Kavita
Email address: grievance@medcord.in
Contact No.: 917347489331
Address: Tech Applied Well Technologies,
371 Phase 3B1, Mohali, Punjab - 160059
If you have any reason to believe that we or any company associated with us has misused any of your and/or your family members and/or your dependents Personal Information and/or Sensitive Personal Data or Information please contact us immediately and report such misuse.
We can address any questions, comments and concerns about our online privacy practices and policy. Please write to our Grievance Officer at the above-mentioned email address.
20. Governing rules and law
If you choose to visit our Platform, your visit/use and any dispute over privacy is subject to this Privacy Policy and the Platform's terms of use. In addition to the foregoing, any disputes arising under this Privacy Policy shall be governed by the laws of India.
This Privacy Policy is compliant with the provisions of all applicable Indian laws including but not limited to the Information Technology Act, 2000 and Rules made thereunder including any modifications or amendments made thereto. MedCord may make necessary changes to this Privacy Policy consequent upon any changes or modification in the law. It is hence imperative that you frequently read this Privacy Policy to keep yourself updated of any changes made by us.
21. Miscellaneous
- End of the Document �