Privacy Policy
Your privacy is fundamental to our mission. This policy explains how Careitwell collects, uses, stores, and protects your personal data.
Effective Date:1 September 2026 | Last Updated: 1 September 2026
1. Introduction
Careitwell (operated by AshaCareWell, also referred to as “AshaCareWell,” “we,” “us,” or “our”) is a cloud-based Hospital Management System (“Platform”) that helps healthcare providers manage patient records, appointments, billing, pharmacy, laboratory, and other operational workflows.
This Privacy Policy applies to all users of our Platform, including hospital administrators, medical staff, patients, and visitors to our website www.ashacarewell.com (collectively, “Services”). By using our Services, you agree to the practices described in this policy.
This policy is prepared in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and applicable healthcare data protection guidelines.
2. Data Fiduciary Information
Under the DPDP Act 2023, we act as a Data Fiduciary for the personal data we collect and process.
- Entity Name: AshaCareWell (operating as Careitwell)
- Registered Address: 4, Bijal Apt., Gotri Road, Vadodara, Gujarat, India – 390021
- Data Protection Officer Email: privacy@ashacarewell.com
- Grievance Officer Email: grievance@ashacarewell.com
- Website: www.ashacarewell.com
3. Data We Collect
We collect the following categories of personal data depending on your role and interactions with the Platform:
3.1 Account & Identity Data
- Full name, email address, phone number
- Professional credentials (for healthcare staff)
- Google account information (if you use Google Sign-In)
- Login credentials (hashed passwords, session tokens)
3.2 Patient Health Data (Sensitive Personal Data)
- Medical records, diagnoses, prescriptions, and treatment plans
- Lab results, imaging reports, and clinical notes
- Allergy information and medication history
- Date of birth, gender, blood group
- Insurance and billing information
- Emergency contact details
3.3 Hospital & Organizational Data
- Hospital name, registration number, and configuration
- Department, ward, and room information
- Staff role assignments and access permissions
3.4 Technical & Usage Data
- IP address, browser type, device information
- Login timestamps and session activity
- Feature usage analytics (via Vercel Analytics)
- Error logs and performance metrics
4. Purpose of Processing
We process personal data for the following lawful purposes under the DPDP Act:
Healthcare Delivery
Managing patient records, appointments, prescriptions, billing, and clinical workflows as requested by the subscribing hospital.
Account Management
Creating, authenticating, and managing user accounts including multi-factor authentication and session security.
Platform Operations
Maintaining, securing, and improving our Platform; detecting fraud; preventing unauthorized access.
Legal Compliance
Fulfilling obligations under Indian healthcare regulations, NABH standards, and data protection laws.
Communication
Sending appointment reminders, system notifications, password resets, and support responses.
Analytics
Aggregated, anonymized usage analytics to improve service quality (no personal health data is used for analytics).
5. Lawful Basis for Processing
Under the DPDP Act 2023, we rely on the following lawful bases:
- Consent (Section 6): For collecting and processing your personal data when you register, use our Services, or enable Google Sign-In. You may withdraw consent at any time by contacting us.
- Legitimate Uses (Section 7): For processing data necessary for medical treatment or health services, performance of a contract (SaaS subscription), and compliance with applicable Indian law.
- Medical Emergency: Processing data where it is necessary to respond to a medical emergency involving a threat to the life of a Data Principal.
6. Google Sign-In & Third-Party Authentication
Our Platform offers Google Sign-In as an optional authentication method. When you choose to sign in with Google, we receive:
- Your Google account email address
- Your name (first name and last name)
- Your Google account identifier
We use this information solely for authentication and account creation. We do not access your Google Drive, Gmail, Google Calendar, contacts, or any other Google services. We do not store your Google password. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
Google Limited Use Disclosure:Careitwell's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Data Security Measures
We implement industry-standard security measures to protect your data:
Encryption
AES-256 encryption for sensitive data at rest; TLS 1.2+ for data in transit.
Access Control
Role-Based Access Control (RBAC) with granular permissions. Multi-Factor Authentication (MFA) support.
Password Security
Bcrypt hashing with 12 salt rounds. Password expiry and history policies. Account lockout after failed attempts.
Session Security
JWT-based authentication with token blacklisting. Single-session enforcement to prevent concurrent logins.
Audit Logging
Comprehensive login audit trails, security event monitoring, and access logs.
Infrastructure
Hosted on secure cloud infrastructure (Vercel, Render, Aiven) with automated backups and SOC 2 compliant providers.
8. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We share data only in these circumstances:
- Subscribing Hospitals:Patient health data is shared with the hospital that manages the patient's care. Each hospital operates as a separate tenant with isolated data access.
- Infrastructure Providers: Vercel (frontend hosting), Render (backend hosting), and Aiven (database hosting) process data on our behalf under strict data processing agreements.
- Google: Only for authentication via Google Sign-In (as described in Section 6). No health data is shared with Google.
- Legal Requirements: When required by Indian law, court order, or regulatory authority.
We do not transfer personal data outside of India except through our cloud infrastructure providers, which maintain servers and data processing in compliance with applicable cross-border data transfer provisions of the DPDP Act.
9. Data Retention
- Patient Health Records:Retained as long as required by applicable Indian healthcare regulations and the subscribing hospital's retention policy (typically a minimum of 3 years after the last date of treatment, as per MCI guidelines).
- User Account Data: Retained while your account is active. Upon account deletion or hospital subscription termination, data is deleted or anonymized within 90 days, unless retention is required by law.
- Audit Logs: Retained for a minimum of 1 year for security and compliance purposes.
- Analytics Data: Aggregated and anonymized analytics data may be retained indefinitely as it cannot identify individuals.
10. Your Rights Under the DPDP Act
As a Data Principal under the DPDP Act 2023, you have the following rights:
Right to Access
You can request a summary of the personal data we hold about you and the processing activities performed.
Right to Correction
You can request correction of inaccurate or incomplete personal data.
Right to Erasure
You can request deletion of your personal data, subject to legal retention requirements.
Right to Withdraw Consent
You may withdraw your consent at any time by contacting our Data Protection Officer. Withdrawal does not affect lawfulness of prior processing.
Right to Grievance Redressal
You may raise grievances with our Grievance Officer. We will acknowledge within 48 hours and resolve within 30 days.
Right to Nominate
You may nominate another person to exercise your rights in the event of your death or incapacity, as provided under Section 14 of the DPDP Act.
To exercise any of these rights, please contact us at privacy@ashacarewell.com.
11. Children's Data
Our Platform may process health data of minors (children under 18) as part of hospital patient management. Such data is processed only with the consent of the parent or lawful guardian, in compliance with Section 9 of the DPDP Act. We do not knowingly collect personal data from children for marketing purposes or behavioral tracking.
12. Cookies & Tracking Technologies
We use the following cookies and similar technologies:
- Essential Cookies: Session cookies required for authentication and security (NextAuth session token). These cannot be disabled.
- Analytics: Vercel Analytics and Speed Insights for aggregated performance monitoring. No personal health data is included in analytics.
We do not use advertising cookies, behavioral tracking, or retargeting technologies.
13. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the Data Protection Board of India as required under the DPDP Act.
- Notify affected Data Principals (users) without unreasonable delay.
- Take immediate steps to contain and remediate the breach.
- Maintain a breach register documenting all incidents and corrective actions.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the “Last Updated” date at the top of this policy.
- Provide notice through our Platform or via email for significant changes.
- Obtain fresh consent where required by the DPDP Act.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Data Protection Officer: privacy@ashacarewell.com
- Grievance Officer: grievance@ashacarewell.com
- General Inquiries: info@ashacareitwell.com
- Phone: (+91) 9106626759
- Address: 4, Bijal Apt., Gotri Road, Vadodara, Gujarat, India – 390021
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Board of India as established under the DPDP Act 2023.
Governing Law: This Privacy Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the rules made thereunder. Any disputes arising out of or in connection with this policy shall be subject to the exclusive jurisdiction of the courts in Vadodara, Gujarat, India.