Skip to content

This portal holds your health information — your blood sugar readings, your blood pressure, the medicines you take, what you eat, and the concerns you write down. That is sensitive, and this page explains exactly what happens to it.

The five things that matter most:

1. Your data is held in India.
2. We never sell it, and never share it with anyone outside the programme without your consent.
3. We never share your readings with a family member — including a spouse or a parent of an adult patient — without your consent.
4. We never use your data to train artificial intelligence models.
5. Your readings are never used in advertising, testimonials or success stories, even without your name.

1. Who we are

Data Fiduciary: [OJSP legal entity]

Registered office: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107.
CIN: U72900MH2022PTC387875.

Privacy contact: [email protected]

Grievance Officer: Rajeev Pillai.

The portal is built and hosted for us by a technology provider acting as our Data Processor under a written contract (§13).

2. What we hold

CategoryDetail
Identity and contactName, mobile number (verified by OTP), email if you give one, age, sex, city
Diabetes profileType and duration of diabetes, other conditions you tell us about, concerns you record
Daily entriesBlood pressure, fasting and post-prandial sugar, medicines taken, OJSP supplements taken, food history, and anything you write in a notes field
Diet chart recordsWhich chart was issued, at what calorie level, and who selected it
Programme recordsSupport conversations, adverse event reports, education material accessed
TechnicalDevice, browser, IP, sign-in records, audit logs of who accessed your record

3. Your health data

Everything in a daily entry is health data. So is a diet chart at a stated calorie level, and so is the fact that you are enrolled in a diabetes programme at all.

In India, a person's diabetes status can affect insurance, employment and family matters. We treat this data on the assumption that disclosure could genuinely harm you.

  • Record what is useful to you and your doctor. You do not have to fill every field.
  • Notes fields are free text — write what helps you, but remember that a support agent investigating a query you raise may read it.
  • You can export everything and take it to appointments. That is what it is for.

4. Why we process it

  • To create and operate your account, and verify your mobile number.
  • To store your entries and show your own history and progress back to you.
  • To issue diet charts, and to record who selected the calorie level and when.
  • To respond to questions you raise with our team.
  • To record, investigate and report adverse events as the law requires.
  • To send you programme communications about your account and the programme.
  • To secure the portal and prevent misuse.
  • To meet legal obligations, including record retention and incident reporting.

5. The basis on which we process

ProcessingBasis under the DPDP Act
Your account, entries, charts and supportYour consent, given at registration
Adverse event records and reportingCompliance with law — pharmacovigilance and AYUSH reporting obligations
Financial and tax records, where a purchase is involvedCompliance with law
System logs and incident reportingCompliance with law — CERT-In directions
Security and fraud preventionLegitimate use permitted by the Act
Responding to a query you raisedLegitimate use — you approached us

7. Who can see your data

WhoSees
YouEverything
Programme support staffYour profile and entries, where needed to answer a query you raised or handle an adverse event. Logged with a reason
Doctor or dietitian selecting a calorie levelWhat they need to make that decision safely
Programme administratorsAggregate figures. Individual records only where a specific task requires it, and it is logged
Sales, distribution and marketing staffNothing. No access to any patient record, ever
Your familyNothing without your consent — see §8
Your employer, insurer or bankNothing, ever
Other patientsNothing

The sales row is the important one. This programme is run by a company that sells products. The people who sell those products have no access to patient records — not to readings, not to progress, not to who is doing well. That separation is enforced in the system, not by policy alone.

8. Family, spouse and carers

We will not discuss your information with a family member without your consent — including a spouse, an adult child, or a parent of an adult patient.

This holds even when someone calls saying they are worried about you, and even when they are the person who bought the product.

  • Where you want a carer involved, you can add them, and you can remove them at any time.
  • A carer using the portal on your behalf must do so with your knowledge (Terms §15).
  • If someone else has been using your account, tell us and we will secure it.
  • Where a patient lacks capacity, contact [email protected] so the account is configured properly.

9. Never used to sell to you

Your health data is never used to market to you.

We do not use a rising sugar reading, a missed entry, or any pattern in your record to trigger a sales call, a message, an offer, or a suggestion that you buy anything.

This matters more here than on most platforms. A programme run by a product company that watched patient readings to time its sales calls would be exploiting people at their most anxious. We do not do it, the system does not permit it, and sales staff cannot see the data that would make it possible (§7).

Programme communications about your account are separate from marketing, and marketing consent can be withdrawn at any time without affecting your participation.

10. What we never do

We do not:

• sell, rent or trade your data
• share it with insurers, employers, banks or lenders
• share it with your family without your consent
• give sales or distribution staff access to patient records
• use your readings to trigger a sales approach
• use your readings, progress or story in advertising, testimonials or case studies — even anonymised
• use your data to train artificial intelligence models
• profile you or advertise to you across other sites

Why testimonials are excluded outright. A patient's improved readings shared as evidence that a product works is exactly what the Drugs and Magic Remedies Act, 1954 prohibits for a listed condition like diabetes. It would also be a use of your health data that no amount of consent makes appropriate for a company selling the product. So the answer is simply no.

11. Staff access

  • Programme staff access a record only where a specific task requires it — a query you raised, an adverse event, a chart issue.
  • Every access is logged with the person, time, record and reason, and the log is available to you on request.
  • Access is role-based. Sales, distribution and marketing roles have none.
  • Staff must not download, photograph, or discuss patient information outside the programme, and are bound by confidentiality obligations that survive their employment.
  • Production data is never copied into training, test or demonstration environments.

12. Messages we send you

Messages are deliberately vague. They do not mention diabetes, a reading, a product name or a condition — because a message may be read by whoever is holding your phone.

  • Reminders say only that an entry is due, not what the entry is about.
  • Tell us if your mobile number changes, so a new owner does not receive your messages.
  • Turn off lock-screen notification previews if others use your phone.
  • We never ask for your OTP. Any message doing so is fraudulent.

13. Our Data Processors

FunctionReceives
Technology provider — build and hosting (India)Access to run and support the portal, under contract
SMS providerMobile number and message text (worded per §12)
Email providerEmail address and message text

Each is engaged under a written contract imposing obligations equivalent to those we owe you. We remain liable to you for our Processors. The current list is at /subprocessors, and material changes are notified.

14. Where data is held

Your data, backups and disaster recovery copies are stored and processed within India. Staff access is from India. We do not transfer your data outside India, and would notify you in advance if that ever changed.

15. How long we keep it

DataRetention
Your profile and daily entriesWhile your account is active, plus [30] days after closure
Diet chart issue records, including who selected the level[3] years — evidence that the safety rule was followed
Support conversations[24] months
Adverse event recordsAs pharmacovigilance obligations require — typically several years, and not deletable on request
Audit log of record access[24] months
Financial and tax records, where applicableUp to 8 years
System logs required by lawMinimum 180 days, held in India
BackupsRolling [35] days
Inactive accountsDeleted after [24] months of no use, after notifying you

Export before you close. Your record of readings over months is genuinely useful to your doctor, and once deleted it is gone. Download it first.

16. Security

Encryption in transit and at rest; OTP authentication with reuse prevention; role-based access with sales and distribution roles holding none; multi-factor authentication for administrative accounts; audit logging of every record access with a reason; rate limiting and brute-force protection; no production data in non-production environments; verified backups; vulnerability scanning and periodic penetration testing.

Protect your own account: do not share your OTP, use a device lock, and turn off notification previews if others use your phone.

17. If something goes wrong

  • We notify affected patients of a personal data breach without undue delay, and in any event within [24] hours of confirmation.
  • The notification is worded so that it does not itself disclose that you have diabetes — including where it may be read on a lock screen.
  • We report to the Data Protection Board of India as the Act requires, and to CERT-In within 6 hours where its directions apply.
  • Evidence is preserved, and we publish a root cause analysis with corrective actions within [10] working days.

18. Your rights

RightWhat it means here
Access and summaryA summary of what we hold, what we do with it, and who it has been shared with
CorrectionCorrect wrong or incomplete data. Corrections to entries are recorded alongside the original, not overwritten, so the record stays trustworthy for your doctor
ErasureErasure of data no longer needed and not legally required to be kept (§15)
Grievance redressalA named officer, answering within the statutory period (§24)
NominationNominate someone to exercise your rights on death or incapacity (§21)
Withdraw consentAt any time, as easily as it was given (§6)

19. How to exercise them

  • In the portal: see everything, export everything, correct entries, close your account.
  • By email: [email protected] from your registered account, or by calling our support line.
  • We verify identity through your registered mobile number.
  • We respond within 30 days, at no charge.
  • Where we cannot fully comply, we tell you specifically which data and which obligation — not a general refusal.

Adverse event records cannot be erased on request. Pharmacovigilance obligations require them to be retained and reported. This protects everyone using the product, including you.

20. Children

This programme is for adults aged 18 and over. We do not knowingly process a child's personal data. An account found to belong to someone under 18 is closed and the data deleted, except anything legally required to be retained. The Act's prohibitions on tracking and targeted advertising to children are satisfied because we do neither for anyone, of any age. If you believe a minor has registered, tell us at [email protected] .

21. Nominating someone

You may nominate a person to exercise your rights if you die or become unable to. Do it in your account settings, or by writing to us; you can change or remove it at any time.

Think about what a nominee would see — your full record of readings, medicines and notes. For some people that is exactly right; for others it is not. Choosing not to nominate anyone is perfectly proper.

22. Your duties under the Act

  • Do not impersonate anyone when giving your data.
  • Give accurate information — in a health record, this one protects you directly.
  • Do not register a false or frivolous grievance.
  • Give authentic information when asking for a correction.

23. Cookies

Strictly necessary cookies for sign-in, session and security; functional cookies for language preference; analytics only with consent. The patient portal carries no advertising, tracking or retargeting cookies, and we place no third-party advertising pixel on any page a patient sees while signed in.

24. Grievance and the Board

Grievance Officer

Name: Rajeev Pillai

Address: 311, Mahesh Industrial Estate , Silver Park, Mira Road East , Thane -401107.

Acknowledgement within 24 hours; resolution within 15 days.

Safety and adverse events: [email protected] — acknowledged within [24] hours.

If you are not satisfied, you may complain to the Data Protection Board of India. Please raise it with us first, as the Act requires. We will not obstruct, discourage or penalise a complaint to the Board.

Significant Data Fiduciary. Given the sensitivity of health data and the number of patients this programme serves, we operate on the assumption that these additional obligations may apply to us. If we are notified as a Significant Data Fiduciary, this notice will be updated with our Data Protection Officer's contact details.

25. Changes

We may update this notice. The version date will change. Material changes are notified at least [30] days in advance. Any change to §7, §8, §9 or §10 will be notified prominently and in advance — those are the commitments that make it safe to record honest health information with a company that sells products.

Where a change would require fresh consent, we will ask for it rather than treating continued use as agreement.