This Privacy Policy describes how CareConnect India Pvt Ltd (CIN: available on request) collects, uses, discloses, and safeguards Personal Data when you use our Platform.
"Personal Data" has the meaning assigned under §2(j) DPDP Act 2023.
"Sensitive Personal Data" ("SPD") includes health information, biometrics, and financial data per Rule 3, SPDI Rules 2011.
"Processing", "Data Principal", and "Data Fiduciary" bear the meanings in the DPDP Act.
Category | Examples | Purpose | Retention |
---|---|---|---|
Identity | Name, Aadhaar/PAN, passport, profile photo | Registration, KYC | 7 yrs post‑last transaction |
Contact | Address, email, phone, emergency contacts | Communication, SOS | 7 yrs |
Professional | Certifications, licences, background‑check reports | Credentialing Caregivers | While active + 7 yrs |
Financial | Bank a/c, UPI ID, payment tokens | Escrow payouts | 7 yrs |
Health (SPD) | Diagnoses, medication schedule, care plans | Tailoring Care Services | 5 yrs after last service |
Usage | Device IDs, IP, cookies, analytics | Security, product improvement | 3 yrs; cookies per type |
Communications | Chat transcripts, call recordings | Quality assurance, dispute resolution | 2 yrs |
Location | GPS during active visits | Safety, attendance verification | 1 yr rolling |
We share necessary data with: Razorpay, Stripe India (payments); Twilio (OTP/SMS); Hyperverge (KYC & background checks); Google Analytics; Freshchat (support); Mailchimp (email); AWS Mumbai (hosting); accredited labs for home diagnostics; certified equipment rental vendors; and EU‑based support contractors under EU Standard Contractual Clauses.
Personal Data may be processed outside India (e.g., EU customer‑support centre). Such transfers rely on (a) Contractual Clauses incorporating DPDP‑compliant safeguards; (b) audits; and (c) encryption in transit (TLS 1.3).
We retain Personal Data no longer than necessary for the purposes stated above or to comply with legal obligations. On expiry of retention periods, data are irreversibly anonymised or securely erased using NIST SP 800‑88 standards.
Subject to verification, Data Principals may access, correct, erase, restrict, port, or withdraw consent via in‑app settings or by emailing privacy@care-connect.online. Requests will be fulfilled within 15 days unless an extension (max 15 days) is notified.
The Platform is not directed at minors (<18). If we learn we have collected data from a minor, we delete it within 72 hours.
We use first‑party session cookies, JWT‑based auth tokens, and third‑party analytics cookies. Users can manage preferences via the Cookie Settings panel or browser settings. Essential cookies cannot be disabled.
Grievance Officer: Mr Hanuman Prasad — hello@care-connect.online (address as §1.15)
Data Protection Officer: Mr Hanuman Prasad — hello@care-connect.online (same postal)
Material changes will be notified at least 15 days in advance through email and in‑app banners. Version history will be archived at care-connect.online/privacy.