← Back to MedKura

Privacy Policy

Last updated: 18 June 2026 · Effective: production launch

1. About This Policy

MedKura Health Private Limited ("MedKura", "we", "us") operates an AI-assisted healthcare second-opinion platform accessible at medkura.in. This Privacy Policy explains how we collect, use, store, and protect your personal data — including sensitive health information — in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable Indian healthcare regulations.

2. Data We Collect

  • Identity data: Name, age, gender, phone number, city, pincode.
  • Health data: Medical reports, lab results, consultation notes, surgical history.
  • Communication data: WhatsApp messages, in-app notifications sent to you.
  • Technical data: Device type, IP address, browser type, session identifiers.
  • Transaction data: Consultation fees, payment references (no card data stored).

3. How We Use Your Data

  • To provide second-opinion consultations and manage your healthcare journey.
  • To enable AI analysis of medical reports and suggest specialist doctors.
  • To communicate case updates via WhatsApp, SMS, and in-app notifications.
  • To process payments for consultations through Razorpay.
  • To comply with legal obligations including DPDP Act 2023 and telemedicine guidelines.

4. Data Storage & Security

All data is stored on AWS Mumbai (ap-south-1) — data never leaves India. Medical documents are encrypted at rest (AES-256) and in transit (TLS 1.3). Access to documents is controlled via time-limited presigned URLs valid for 15 minutes.

5. Your Rights Under DPDP Act 2023

  • Right of access (§11): Download all your personal data via Profile → Download My Data. We respond within 30 days.
  • Right to correction (§12): Update your profile at any time from the Profile page. Doctor / lab partners contact support@medkura.in; we action within 7 working days.
  • Right to erasure (§13): Email privacy@medkura.in. We execute within 30 days; backups are purged within 90 days. Statutory records (invoices, audit logs) are retained for the legally mandated 7-year window even on erasure.
  • Right to withdraw consent (§6(4)): Manage granular consent toggles at Profile → My Consents. Withdrawal takes effect immediately; in-flight workflows complete under the original consent and a new audit row is written.
  • Right to nominate (§14): You may nominate a person to exercise your rights in the event of your death or incapacity. Contact the Grievance Officer below to register a nominee.
  • Right to grievance redressal (§13): Contact our Grievance Officer (details in §9). We acknowledge within 72 hours and resolve within 30 days.
  • Right to complain to the Data Protection Board: If unsatisfied with our response, you may escalate to the Data Protection Board of India under DPDP §27.

5a. Children & Vulnerable Adults

Where a case is created for a minor (under 18) or for a person under guardianship, the account holder declares that they have lawful authority to consent on the data principal's behalf (DPDP §9). MedKura does not knowingly process children's data without verifiable guardian consent. If you believe we have done so inadvertently, contact the Grievance Officer immediately and we will erase the data within 7 days.

5b. AI-Assisted Decisions

MedKura uses AI agents (Anthropic Claude Sonnet/Haiku) to summarise medical reports for the assigned doctor and to rank specialists by clinical relevance. AI output never replaces a clinician's judgement — a verified doctor reviews every recommendation before it influences your case. You may withdraw yourAI_PROCESSING consent in Privacy settings to opt out of AI summarisation entirely; doctors will still receive your raw documents in that case.

6. Third-Party Sharing

We share your data only with: (a) doctors you have booked a consultation with; (b) NABL-accredited lab partners processing your test orders; (c) payment processor Razorpay (no health data shared); (d) AWS for storage; (e) Twilio for SMS/WhatsApp delivery; (f) Daily.co for video consultations. We do not sell your data.

6a. Cookies & Local Storage

MedKura uses browser cookies + localStorage for sign-in, role-based portal routing, and chat continuity. We do not use marketing or advertising trackers — no Google Analytics, no Facebook Pixel, no AdWords. Optional anonymous performance analytics (Web Vitals) are opt-in via the cookie banner shown on your first visit. See the full per-cookie disclosure →

7. Retention

Health records are retained for 7 years as required by the Clinical Establishments Act. Account data is deleted within 30 days of an erasure request. Backups are purged within 90 days.

8. Security & Breach Notification

We employ ISO 27001-aligned safeguards including TLS 1.2+ in transit, AES-256 at rest, role-based access controls, and an immutable audit log of every record access. In the event of a personal data breach affecting your data, we will:

  • Report to CERT-In within 6 hours of detection (CERT-In Directions, April 2022).
  • Notify the Data Protection Board of India without delay (DPDP §8(6)).
  • Notify you within 72 hours via your registered email, WhatsApp, and a dashboard banner with the nature of the breach, the data affected, and remedial steps you should take.
  • Publish a blameless post-mortem summary within 30 days at medkura.in/security/incidents.

9. Contact & Grievance Redressal

Data Protection Officer (DPO): Rishi Bhargava
DPO email: privacy@medkura.in
Grievance Officer (DPDP §32): Rishi Bhargava
Grievance email: grievance@medkura.in
Postal address: MedKura Health Private Limited, Nellore, Andhra Pradesh — 524001, India
CIN: U62013AP2025PTC122246
Response SLA: First acknowledgement within 72 hours; resolution within 30 days.

If you are unsatisfied with our response, you may file a complaint with the Data Protection Board of India under DPDP §27 once notified.