This privacy policy explains how we collect, use, and protect your personal information when you visit our website or use our services. It also explains what rights you have over your data and how you can contact us if you have any questions or requests.
1. Information We Collect
1.1 Contact Information
- Full name
- Email address
- Phone number
- Postal address
1.2 Health Information
- Medical history
- Current symptoms
- Diagnosis and treatment records
- Progress notes
- Prescription details
1.3 Payment Information
- Credit/debit card details (processed securely)
- Billing address
- Transaction history
1.4 Technical Information
- IP address
- Browser type and version
- Device type
- Operating system
- Cookies and tracking data
1.5 Usage Information
- Browsing activity on our website
- Preferences and settings
- Feedback and survey responses
2. How We Use Your Information
2.1 Healthcare Services
- Booking and managing appointments
- Delivering physiotherapy treatments
- Sending appointment reminders
- Maintaining medical records
2.2 Communication
- Service updates and notifications
- Health tips and newsletters
- Promotional offers (with consent)
- Emergency medical communications
2.3 Business Operations
- Processing payments and issuing receipts
- Analyzing usage data for improvements
- Conducting medical research (anonymized)
- Testing new features and services
2.4 Legal Compliance
- Maintaining regulatory records
- Reporting to healthcare authorities
- Resolving disputes and claims
- Preventing fraud and abuse
3. How We Share Your Information
3.1 Internal Sharing
Our physiotherapists and staff have access to your information to provide quality healthcare services.
3.2 Service Providers
We work with trusted third parties for:
- Website hosting and maintenance
- Cloud data storage (Supabase)
- Payment processing (secure gateways)
- Email and SMS services
- Analytics (Google Analytics)
3.3 Professional Advisors
- Legal counsel
- Accounting services
- Healthcare consultants
3.4 Legal Obligations
We may disclose information to:
- Healthcare regulatory authorities
- Law enforcement agencies (when legally required)
- Courts and tribunals
3.5 What We Don't Do
We do NOT:
- Sell your personal information
- Rent your data to third parties
- Trade your information for marketing
- Share with insurance companies (without consent)
4. Data Security Measures
4.1 Technical Security
- SSL/TLS encryption for all data transmission
- Encrypted database storage
- Secure password policies
- Two-factor authentication for staff
- Regular security audits and updates
4.2 Administrative Security
- Access controls - Role-based permissions
- Staff training on data privacy
- Confidentiality agreements with all employees
- Regular backup procedures
- Incident response plan for data breaches
4.3 Physical Security
- Secure clinic premises with access control
- Locked storage for physical records
- Visitor authentication system
- CCTV surveillance at facility
4.4 Important Note
While we implement industry-standard security measures, no method is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any security concerns.
5. Data Retention Policy
5.1 Retention Periods
| Data Type | Retention Period |
|---|---|
| Active patient records | Duration of treatment + 7 years |
| Inactive records | 10 years from last consultation |
| Marketing data | Until consent is withdrawn |
| Financial records | 7 years (tax regulations) |
| Website analytics | 26 months (Google Analytics) |
| Appointment history | 5 years from last visit |
5.2 Data Disposal
When data is no longer needed:
- Digital records: Securely deleted and overwritten
- Physical records: Shredded or incinerated
- Backup copies: Removed from all systems
- Anonymization: Where legally required to retain
6. Your Privacy Rights
6.1 Right to Access
- Request a copy of your personal and medical information
- Review what data we hold about you
- Understand how your data is processed
6.2 Right to Correction
- Update inaccurate or incomplete information
- Modify your contact details
- Correct medical history errors
6.3 Right to Deletion
- Request deletion of your information
- Remove your account and associated data
- Subject to legal record-keeping requirements
6.4 Right to Restriction
- Restrict processing for marketing purposes
- Object to automated decision-making
- Limit use of your data temporarily
6.5 Right to Portability
- Receive your data in structured format (PDF/JSON)
- Transfer records to another healthcare provider
- Export your medical history
6.6 Right to Withdraw Consent
- Unsubscribe from marketing emails
- Opt-out of WhatsApp communications
- Stop non-essential data processing
6.7 Right to Complain
- Contact our Grievance Officer (details below)
- File complaint with data protection authority
- Seek legal remedies if dissatisfied
6.8 How to Exercise Your Rights
Contact us at:
- Email: hello@c7physio.in
- Phone: +918756700567
- Response time: Within 30 days
We may verify your identity before processing requests.
7. Cookies & Tracking Technologies
7.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help us provide a better user experience.
7.2 Types of Cookies We Use
- Essential Cookies: Required for website functionality
- Analytics Cookies: Help us understand usage patterns
- Performance Cookies: Improve website speed and responsiveness
- Functional Cookies: Remember your preferences
7.3 Third-Party Cookies
- Google Analytics for website analytics
- Payment gateway providers for transaction processing
- Social media platforms (if you choose to share)
7.4 Managing Cookies
You can control cookies through your browser settings. Note that disabling cookies may affect website functionality.
8. Third-Party Services
8.1 Service Providers We Use
- Supabase: Database and authentication services
- Google Analytics: Website analytics and reporting
- Payment Gateways: Secure payment processing
- Email Services: Appointment reminders and communications
- SMS Services: Text message notifications
8.2 Third-Party Privacy Policies
These services have their own privacy policies. We encourage you to review them:
- Google Analytics Privacy Policy
- Payment gateway privacy policies
- Cloud service provider policies
8.3 Data Sharing Limits
We only share the minimum necessary data with third parties and require them to:
- Maintain confidentiality
- Use data only for specified purposes
- Comply with data protection laws
- Implement security measures
9. International Data Transfers
9.1 Data Storage Location
Your data is primarily stored on servers located in India. Some third-party services may store data internationally.
9.2 Cross-Border Transfers
When data is transferred outside India, we ensure:
- Adequate data protection measures
- Compliance with Indian data protection laws
- Contractual safeguards with service providers
- Your rights remain protected
10. Children's Privacy
10.1 Age Restrictions
Our services are intended for adults (18+) and children with parental consent. We do not knowingly collect information from children under 13 without parental consent.
10.2 Parental Consent
For minors (under 18):
- Parent or guardian must provide consent
- Parent/guardian information collected
- Parent can access and delete child's data
- Parent receives all communications
10.3 Child Data Protection
If we discover we've collected data from a child without consent, we will:
- Delete the information immediately
- Notify the parent/guardian
- Cease processing the data
- Document the incident
11. Data Breach Procedures
11.1 Our Commitment
We take data security seriously. In the unlikely event of a data breach, we will:
- Investigate immediately
- Contain the breach
- Assess the impact
- Notify affected individuals
- Report to authorities as required
11.2 Notification Timeline
- High-risk breaches: Within 72 hours
- Standard breaches: Within 7 days
- Notification method: Email and/or phone
11.3 What We'll Tell You
- Nature of the breach
- Data affected
- Potential consequences
- Measures taken
- Steps you should take
- Contact information for questions
12. Marketing Communications
12.1 Types of Communications
With your consent, we may send:
- Health tips and wellness advice
- Special offers and promotions
- New service announcements
- Educational content
- Newsletter updates
12.2 Opt-In Consent
We require explicit consent for marketing communications. You can opt-in through:
- Checkbox during registration
- Account settings
- Verbal consent (documented)
12.3 Opt-Out Options
You can unsubscribe anytime by:
- Clicking "unsubscribe" in emails
- Replying "STOP" to SMS messages
- Updating account preferences
- Contacting us directly
12.4 Transactional Communications
You cannot opt-out of essential service communications:
- Appointment confirmations
- Appointment reminders
- Cancellation notifications
- Payment receipts
- Policy updates
13. Policy Updates
13.1 Changes to This Policy
We may update this privacy policy to reflect:
- Changes in our practices
- New legal requirements
- Technology improvements
- Service enhancements
13.2 Notification of Changes
We will notify you of significant changes through:
- Email notification
- Website banner
- In-app notification
- SMS (for major changes)
13.3 Your Acceptance
Continued use of our services after policy changes constitutes acceptance. If you disagree with changes, please:
- Contact us with concerns
- Request data deletion
- Discontinue service use
14. Contact Information
14.1 General Inquiries
C7Physio Clinic
O-5, Hospital Road, C Scheme
Jaipur - 302004, Rajasthan, India
📞 Phone: +918756700567
📧 Email: hello@c7physio.in
🌐 Website: www.c7physio.in
Business Hours:
Monday - Saturday: 9:00 AM - 7:00 PM
Sunday: Closed
14.2 Privacy-Specific Contacts
📧 Privacy Email: hello@c7physio.in
📞 Privacy Hotline: +918756700567
⏱️ Response Time: Within 30 days
15. Grievance Redressal
15.1 Grievance Officer
Name: Dr. Raj Maheshwari
Designation: Founder & Chief Physiotherapist
Email: hello@c7physio.in
Phone: +918756700567
15.2 Complaint Process
- Submit complaint via email or phone
- Acknowledgment within 48 hours
- Investigation within 15 days
- Resolution within 30 days
15.3 Escalation
If unsatisfied with resolution:
- Contact Data Protection Authority
- File complaint with Consumer Forum
- Seek legal remedies
Last Reviewed: August 15, 2025
Next Review Date: February 15, 2026
Version: 2.0
This privacy policy is effective immediately and supersedes all previous versions.
