Data Protection Policy
1. Scope
- All patients (and parents / guardians) who use the NeoKidsPro platform
- All doctors and clinical staff onboarded to the platform
- All administrative staff and technology vendors who process data on our behalf
- All data processed through neokidspro.in and the associated EMR system
2. Data Classification
| Category | Examples | Classification |
|---|---|---|
| Patient identity | Name, DOB, gender, parent name | Personal Data |
| Contact information | Phone, email, address | Personal Data |
| Medical records | Diagnosis, prescriptions, vitals, history | Sensitive Personal Data (SPDI) |
| Payment records | Transaction ID, fee paid, settlement | Confidential Financial Data |
| Doctor credentials | Registration number, KYC documents | Confidential Professional Data |
| Platform usage | IP address, browser logs, session data | Technical Data |
3. Data Protection Principles
- Lawfulness: Data is collected only with valid consent or other lawful basis
- Purpose limitation: Data collected for one purpose is not used for another without fresh consent
- Data minimisation: We collect only what is necessary for the stated purpose
- Accuracy: We maintain accurate, up-to-date records and allow corrections on request
- Storage limitation: Data is retained only for as long as legally or medically required
- Integrity and confidentiality: We apply appropriate technical and organisational safeguards
- Accountability: We document our data processing and can demonstrate compliance
4. Consent Management
- Consent is obtained at the point of booking via a mandatory checkbox
- Granular consent — separate for marketing vs. essential medical communications
- Consent can be withdrawn at any time by writing to care@neokidspro.in
- Withdrawal does not affect lawfulness of prior processing
- Medical record retention obligations under MCI guidelines continue even after withdrawal
- For patients under 18, consent must be provided by a parent or legal guardian
5. Technical Safeguards
- All data transmitted over encrypted HTTPS / TLS connections
- Passwords hashed using bcrypt (12 salt rounds) — never stored in plaintext
- EMR access controlled via JWT authentication with role-based permissions
- Medical PDFs served through authenticated endpoints only — not publicly accessible URLs
- Database accessible only via application-layer queries — no direct external DB access
- Server infrastructure on Hostinger VPS with firewall and intrusion detection
6. Organisational Safeguards
- Only authorised clinical staff can view patient medical records
- Doctors access only records of patients they have personally consulted
- Admin staff access only operational data required for their role
- All third-party vendors contracted to process data only as instructed
- Staff trained on data protection obligations at onboarding
- Security incidents reviewed within 72 hours; affected users notified without undue delay
7. Third-Party Data Processors
| Processor | Purpose | Data Shared |
|---|---|---|
| Cashfree Payments | Payment processing | Name, phone, email, amount |
| Google LLC | Video consultation (Google Meet) | Appointment details, email |
| Meta Platforms | WhatsApp notifications | Phone number, appointment info |
| Hostinger | Server & database hosting | All platform data (infrastructure) |
| SMTP / Nodemailer | Email notifications | Name, email, appointment details |
8. Data Breach Response
- Breach contained and assessed within 24 hours of discovery
- Affected users notified within 72 hours where the breach poses risk to their rights
- Relevant authorities notified as required under the DPDP Act, 2023
- Post-incident report prepared documenting cause, impact, and remediation steps
9. Cross-Border Data Transfers
Some third-party processors (Google, Meta) may process data outside India. These transfers occur under standard contractual protections and the data processing agreements of those vendors, meeting the requirements of applicable Indian data protection law.
10. Data Subject Rights
- Know what data we hold about you
- Correct inaccurate personal data
- Nominate an individual to exercise rights on your behalf
- Raise a grievance with our Data Protection Officer
- Approach the Data Protection Board of India if your grievance is unresolved
11. Policy Review
This policy is reviewed annually or whenever there is a material change in data processing activities or applicable law. The current version supersedes all previous versions.
12. Governing Law & Jurisdiction
Governed by Indian law. Any disputes shall be subject to the exclusive jurisdiction of courts in Mumbai, Maharashtra, India.
13. Contact — Data Protection Officer
NeoKidsPro — Data Protection Officer
Shri Hari Child Clinic, Borivali East, Mumbai — 400066
Email: admin@neokidspro.in · Phone: +91 98798 91082
© 2026 NeoKidsPro. All rights reserved. Last reviewed June 1, 2026.