Legal · Data Protection

Privacy Policy

This Privacy Policy explains how Arivara AI Robotics and Innovations LLP (“Arivara”, “HealthCircles”, “we”, “our”, or “us”) collects, uses, discloses, retains, and safeguards personal data (including sensitive personal data and health information) processed through the HealthCircles website, mobile applications, AI Voice EMR, and allied services (collectively, the “Platform”).

Effective Date: 15 February 2026 Last Updated: 15 February 2026 Version: 1.0

Preamble & Applicability

Arivara AI Robotics and Innovations LLP is a Limited Liability Partnership incorporated under the Limited Liability Partnership Act, 2008, having its registered office at New No.188 / Old No.207, Bharathi Salai, Royapettah, D4 Police Station, Chennai – 600014, Tamil Nadu, India. HealthCircles is a technology platform operated by Arivara that offers software services to independent, duly-registered medical practitioners (“Doctors”) to enable digital clinical documentation, remote consultation, care-plan participation, professional networking, and content-led professional visibility.

This Policy applies to all visitors of our website, prospective Doctor leads, registered Doctor users, patients (“Patients”) whose data is processed by their treating Doctor through the Platform, and any other individual whose Personal Data is processed by us (collectively, “you” or “Data Principal”).

This Policy is published in accordance with the requirements of:

  • The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules issued thereunder;
  • The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”);
  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediary Rules”);
  • The Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020;
  • The Telemedicine Practice Guidelines, 2020 issued by the erstwhile Board of Governors in supersession of the Medical Council of India (now the National Medical Commission);
  • The Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002 and equivalent regulations under the National Medical Commission Act, 2019, in respect of Doctor obligations of confidentiality; and
  • Applicable circulars, notifications, and guidelines issued from time to time.

By accessing or using the Platform, or by voluntarily providing any Personal Data to us, you acknowledge that you have read, understood, and agreed to be bound by this Policy.

Definitions

Capitalised terms used in this Policy have the meanings set out below or elsewhere in this Policy:

  • Personal Data means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act.
  • Sensitive Personal Data or Information (“SPDI”) means information as defined in Rule 3 of the SPDI Rules, including passwords, financial information, physical, physiological and mental health condition, sexual orientation, medical records and history, biometric information, and any information received under lawful contract for processing.
  • Health Data means any Personal Data relating to the physical or mental health of a Data Principal, including medical history, diagnoses, prescriptions, laboratory results, imaging, audio-visual recordings of clinical consultations, and any information derived by the AI Voice EMR.
  • Processing means any operation performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, transmission, alignment, erasure or destruction.
  • Data Fiduciary means Arivara, which determines the purpose and means of Processing.
  • Data Processor means any person who processes Personal Data on behalf of the Data Fiduciary.
  • Data Principal means the individual to whom Personal Data relates.
  • Consent means free, specific, informed, unconditional and unambiguous indication of the Data Principal’s wishes, signified by clear affirmative action.

Data Fiduciary & Contact

For the purpose of Personal Data processed through the HealthCircles Platform, the Data Fiduciary is:

Arivara AI Robotics and Innovations LLP

Registered Office: New No.188 / Old No.207, Bharathi Salai, Royapettah, D4 Police Station, Chennai – 600014
Grievance Officer: Mr. Makesh G, Director — +91-7871700330

In respect of Health Data uploaded, generated, or otherwise processed by a treating Doctor through the Platform in the course of clinical practice, the treating Doctor is the primary Data Fiduciary vis-à-vis their Patient, and Arivara acts as a Data Processor providing the technological infrastructure on the Doctor’s instructions. Nothing in this Policy transfers the professional responsibilities of a Doctor to Arivara.

Personal Data We Collect

We collect Personal Data in the following categories, depending on how you interact with the Platform:

4.1 Prospective Doctor Leads

When you submit the lead-capture form on our website, we collect: full name, professional email address, mobile telephone number, clinic name (if provided), city, medical specialisation, and how you heard about us. We also collect technical metadata such as the page URL, referrer, timestamp, and, where present, UTM attribution parameters.

4.2 Registered Doctor Users

Upon on-boarding as a Doctor user, we collect: full name; date of birth; gender; professional qualifications; National Medical Commission or State Medical Council registration number; specialisation and sub-specialisation; years of practice; clinic/hospital affiliation and address; digital signature; identity and address proof (as required for KYC and telemedicine compliance); photograph; bank account details for fee remittance; GSTIN, PAN, and other tax identifiers as required.

4.3 Patient Data (via Doctors)

When a Doctor uses the Platform to document, treat, follow up with, or otherwise attend to a Patient, the Doctor may upload or generate Personal Data and Health Data relating to that Patient, including: name, age, gender, contact details; symptoms, complaints, and clinical history; diagnostic and laboratory reports; imaging, photographs, and audio-visual recordings; prescriptions; care-plan enrollment; consultation summaries; and follow-up notes.

4.4 AI Voice EMR Data

When a Doctor uses the AI Voice EMR feature, we process audio recordings of the clinical consultation (only where the Doctor initiates recording and represents that appropriate Patient consent has been obtained), together with derived transcripts, extracted clinical entities, and structured clinical notes.

4.5 Payment & Financial Data

Fees are collected via an authorised third-party payment gateway. We do not store full payment card numbers, CVV, or net-banking credentials on our servers. We store limited transaction metadata (payment reference, amount, timestamp, plan) for accounting, invoicing, and dispute-resolution purposes.

4.6 Communications & Support

When you contact us, we retain records of the correspondence, including your name, contact details, and the content of the query.

4.7 Device, Log, and Usage Data

We automatically collect device and log information, including IP address, browser type and version, operating system, device identifiers, referring URLs, pages viewed, features used, timestamps, and diagnostic data.

Purposes & Legal Bases

We Process Personal Data for the following purposes, on the corresponding lawful bases under the DPDP Act and applicable law:

  • Lead follow-up and onboarding — on the basis of your consent to be contacted, obtained at the time of form submission.
  • Provision of the Platform to Doctor users — on the basis of the contract entered into with the Doctor upon subscription.
  • Facilitation of clinical documentation and consultations — on the instructions of the treating Doctor, with the Patient’s consent obtained by the Doctor pursuant to the Telemedicine Practice Guidelines, 2020.
  • Compliance with law — including tax, medical, telemedicine, consumer-protection and data-protection laws, and the maintenance of statutory records.
  • Payment processing and accounting — on the basis of contractual necessity and compliance with the Income-tax Act, 1961 and the Goods and Services Tax Act, 2017.
  • Fraud prevention, security, and abuse detection — as a legitimate use permitted under the DPDP Act.
  • Analytics, improvement, and research — in aggregated or de-identified form; consent is sought where identifiable data is used.
  • Marketing communications from HealthCircles — only with your prior consent, which you may withdraw at any time.

Sensitive Personal Data & Health Information

Health Data, including all data described in Section 4.3 and 4.4, is treated as SPDI under the SPDI Rules and receives heightened protection.

  • Access to Health Data is restricted, on a need-to-know basis, to the treating Doctor, authorised clinical assistants nominated by the Doctor, and a limited number of Arivara personnel bound by written confidentiality obligations.
  • Health Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
  • Health Data is not used for any secondary purpose (including advertising or profiling) without your explicit, opt-in consent.
  • Where research or population-level analytics are performed, Health Data is de-identified and aggregated in a manner that does not permit re-identification.
  • Where a Patient is a minor or lacks legal capacity, consent shall be obtained from a lawful guardian in accordance with the DPDP Act.

AI Voice EMR & AI Features

The AI Voice EMR is a decision-support and documentation aid. It is not a medical device, is not intended for use in emergency care, and does not replace the professional judgement of a qualified medical practitioner.

Doctor responsibility: The Doctor is solely responsible for (i) informing the Patient that the consultation is being recorded, (ii) obtaining the Patient’s valid consent for such recording and for the derivative processing, (iii) verifying and finalising the AI-generated clinical notes and any prescription prior to release, and (iv) complying with the Telemedicine Practice Guidelines, 2020 and the National Medical Commission’s ethical and record-keeping requirements.

Audio recordings and derived transcripts are stored in encrypted form, are accessible only to the recording Doctor and their authorised assistants, and are deleted upon: (a) the Doctor’s instruction, (b) closure of the Doctor’s account (subject to any statutory retention obligation), or (c) the expiry of the retention period specified in Section 13, whichever is earlier.

AI models employed on the Platform may be trained or fine-tuned only using de-identified and aggregated data, and never on identifiable Patient Health Data without express opt-in consent from the concerned Data Principal.

Consent

Where our Processing of your Personal Data is based on consent, that consent will be sought through a clear, plain-language notice and an affirmative action such as ticking a check-box, submitting a form, or clicking “I agree”. You may withdraw your consent at any time by writing to the Grievance Officer at the contact details in Section 19. Withdrawal of consent will not affect the lawfulness of Processing carried out prior to such withdrawal, and may result in restriction or discontinuation of certain services.

Sharing & Disclosure

We share Personal Data only in the following circumstances:

  • With the treating Doctor and Patient in the ordinary course of clinical documentation and consultation.
  • With authorised Data Processors who provide services on our behalf, under written contractual terms that require them to Process Personal Data solely on our instructions and to maintain appropriate security safeguards.
  • With regulators, law-enforcement agencies, courts, or other governmental authorities, where required by law, court order, subpoena, or in the good-faith belief that such disclosure is necessary to comply with legal obligations, protect our rights or property, or prevent harm.
  • In connection with a corporate transaction such as a merger, acquisition, financing, reorganisation or sale of assets, subject to the acquirer’s undertaking to honour the terms of this Policy.
  • With your explicit consent for any purpose not otherwise described.

We do not sell your Personal Data. We do not disclose identifiable Health Data to advertising networks or third-party marketers.

Third-Party Processors

We engage the following categories of third-party service providers, each bound by contractual data-protection obligations:

  • Google reCAPTCHA v3 (Google LLC) — bot-detection and form-submission security on our public pages. Processes IP address, browser fingerprint and interaction signals. Governed by Google’s Privacy Policy and Terms of Service.
  • PostHog (PostHog Inc.) — product analytics and anonymised behavioural insight to improve the Platform. Governed by the PostHog Privacy Policy.

Where we engage additional processors in the future (including payment gateways, cloud-hosting providers, transactional-email vendors, or AI infrastructure providers), we will update this Policy and, where required, obtain fresh consent.

Cross-Border Transfers

Personal Data is primarily stored on servers located in India. Where Personal Data is transferred outside India for the limited purposes of engaging a third-party Processor (for example, cloud infrastructure or analytics), we ensure that such transfer is carried out only to jurisdictions that are not restricted by the Central Government under Section 16 of the DPDP Act, and that adequate contractual, technical, and organisational safeguards are in place.

Cookies & Analytics

We use cookies, similar tracking technologies, and browser-storage mechanisms for essential Platform functionality (session management, security, load balancing) and to understand aggregate usage. Non-essential analytics cookies are placed only where permitted by applicable law and, where required, with your consent. You may configure your browser to block cookies; certain features of the Platform may not function correctly if cookies are disabled.

Data Retention

We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

  • Lead-form submissions: up to twenty-four (24) months from the date of submission, unless earlier converted to a Doctor account, unless deletion is requested.
  • Doctor account data: for the duration of the subscription and for such further period as is required to defend any actual or threatened legal claim.
  • Patient clinical records and prescriptions: for a minimum of three (3) years from the date of the last entry, and up to such longer period as may be prescribed under the Clinical Establishments (Registration and Regulation) Act, 2010 and rules thereunder, the Medical Council of India Regulations, and other applicable law.
  • Financial and tax records: for eight (8) years as required under the Income-tax Act, 1961 and the Companies Act, 2013.
  • AI Voice EMR audio recordings: up to twelve (12) months unless a longer period is specifically required by the treating Doctor for continuity of care or by law; derived structured notes are retained per clinical-records retention above.

Upon expiry of the applicable retention period, Personal Data is securely deleted or irreversibly de-identified.

Security Practices

We implement reasonable security practices and procedures aligned with recognised standards including ISO/IEC 27001, and consistent with Rule 8 of the SPDI Rules. Our controls include, without limitation:

  • Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256 or stronger);
  • Role-based access control, least-privilege access, and multi-factor authentication for privileged operations;
  • Network segmentation, firewalling, and secure key management;
  • Periodic vulnerability assessment and penetration testing;
  • Regular back-ups and tested disaster-recovery procedures;
  • Written confidentiality obligations on personnel and third-party Processors;
  • Incident-response and breach-notification procedures.

Notwithstanding these measures, no method of transmission over the internet or method of electronic storage is fully secure, and we cannot guarantee absolute security.

Your Rights

Subject to the DPDP Act and applicable exemptions, you have the following rights in respect of your Personal Data:

  • Right to access a summary of the Personal Data we hold about you and the Processing activities undertaken.
  • Right to correction and erasure of inaccurate, incomplete, or outdated Personal Data, and to erasure of Personal Data no longer required for the stated purpose or that we are not required to retain by law.
  • Right to nominate any other individual to exercise your rights in the event of your death or incapacity.
  • Right of grievance redressal as set out in Section 19.
  • Right to withdraw consent as set out in Section 8.

To exercise any of the above rights, please contact the Grievance Officer at the details set out in Section 19. We will respond within the timelines prescribed by law.

Children & Minors

The Platform is not directed at children under the age of 18 as end-users. Where a Patient who is a minor receives care through a Doctor on the Platform, the treating Doctor is responsible for obtaining valid consent from a parent or lawful guardian in accordance with the DPDP Act. We do not knowingly Process Personal Data of a child in a manner that is detrimental to the well-being of the child, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

Data Breach Notification

In the event of a Personal Data breach, we will notify the Data Protection Board of India and affected Data Principals in accordance with the DPDP Act and applicable law. Notification shall include, to the extent reasonably known at the time, the nature of the breach, the categories and approximate number of Data Principals affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects.

Changes to this Policy

We may amend this Policy from time to time to reflect changes in law, technology, or our practices. The revised Policy will be posted on this page with an updated “Last Updated” date. Material changes will, where practicable, be notified by email or in-Platform notice. Your continued use of the Platform after the effective date of the revised Policy constitutes your acceptance of it.

Grievance Officer

In accordance with Rule 5(9) of the SPDI Rules, Rule 3(2) of the Intermediary Rules, and Section 8(9) of the DPDP Act, the following officer has been designated to address grievances relating to Personal Data or content on the Platform:

Grievance Officer

Name: Mr. Makesh G
Designation: Director, Arivara AI Robotics and Innovations LLP
Address: New No.188 / Old No.207, Bharathi Salai, Royapettah, D4 Police Station, Chennai – 600014
Hours: Monday to Friday, 10:00 hrs to 18:00 hrs IST (excluding gazetted holidays)

Grievances will be acknowledged within twenty-four (24) hours of receipt and endeavoured to be resolved within fifteen (15) days, subject to complexity and cooperation of the complainant.