Legal

Data Protection Policy

Effective: June 1, 2026 DPDP Act, 2023 & IT (SPDI) Rules, 2011 Mumbai, Maharashtra
This Data Protection Policy sets out the standards NeoKidsPro (Shri Hari Child Clinic) applies to the collection, handling, storage, and protection of personal and medical data. It is governed by the IT Act, 2000, the IT (SPDI) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Scope

  • All patients (and parents / guardians) who use the NeoKidsPro platform
  • All doctors and clinical staff onboarded to the platform
  • All administrative staff and technology vendors who process data on our behalf
  • All data processed through neokidspro.in and the associated EMR system

2. Data Classification

CategoryExamplesClassification
Patient identityName, DOB, gender, parent namePersonal Data
Contact informationPhone, email, addressPersonal Data
Medical recordsDiagnosis, prescriptions, vitals, historySensitive Personal Data (SPDI)
Payment recordsTransaction ID, fee paid, settlementConfidential Financial Data
Doctor credentialsRegistration number, KYC documentsConfidential Professional Data
Platform usageIP address, browser logs, session dataTechnical Data

3. Data Protection Principles

  • Lawfulness: Data is collected only with valid consent or other lawful basis
  • Purpose limitation: Data collected for one purpose is not used for another without fresh consent
  • Data minimisation: We collect only what is necessary for the stated purpose
  • Accuracy: We maintain accurate, up-to-date records and allow corrections on request
  • Storage limitation: Data is retained only for as long as legally or medically required
  • Integrity and confidentiality: We apply appropriate technical and organisational safeguards
  • Accountability: We document our data processing and can demonstrate compliance

4. Consent Management

  • Consent is obtained at the point of booking via a mandatory checkbox
  • Granular consent — separate for marketing vs. essential medical communications
  • Consent can be withdrawn at any time by writing to care@neokidspro.in
  • Withdrawal does not affect lawfulness of prior processing
  • Medical record retention obligations under MCI guidelines continue even after withdrawal
  • For patients under 18, consent must be provided by a parent or legal guardian

5. Technical Safeguards

  • All data transmitted over encrypted HTTPS / TLS connections
  • Passwords hashed using bcrypt (12 salt rounds) — never stored in plaintext
  • EMR access controlled via JWT authentication with role-based permissions
  • Medical PDFs served through authenticated endpoints only — not publicly accessible URLs
  • Database accessible only via application-layer queries — no direct external DB access
  • Server infrastructure on Hostinger VPS with firewall and intrusion detection

6. Organisational Safeguards

  • Only authorised clinical staff can view patient medical records
  • Doctors access only records of patients they have personally consulted
  • Admin staff access only operational data required for their role
  • All third-party vendors contracted to process data only as instructed
  • Staff trained on data protection obligations at onboarding
  • Security incidents reviewed within 72 hours; affected users notified without undue delay

7. Third-Party Data Processors

ProcessorPurposeData Shared
Cashfree PaymentsPayment processingName, phone, email, amount
Google LLCVideo consultation (Google Meet)Appointment details, email
Meta PlatformsWhatsApp notificationsPhone number, appointment info
HostingerServer & database hostingAll platform data (infrastructure)
SMTP / NodemailerEmail notificationsName, email, appointment details

8. Data Breach Response

  • Breach contained and assessed within 24 hours of discovery
  • Affected users notified within 72 hours where the breach poses risk to their rights
  • Relevant authorities notified as required under the DPDP Act, 2023
  • Post-incident report prepared documenting cause, impact, and remediation steps

9. Cross-Border Data Transfers

Some third-party processors (Google, Meta) may process data outside India. These transfers occur under standard contractual protections and the data processing agreements of those vendors, meeting the requirements of applicable Indian data protection law.

10. Data Subject Rights

  • Know what data we hold about you
  • Correct inaccurate personal data
  • Nominate an individual to exercise rights on your behalf
  • Raise a grievance with our Data Protection Officer
  • Approach the Data Protection Board of India if your grievance is unresolved

11. Policy Review

This policy is reviewed annually or whenever there is a material change in data processing activities or applicable law. The current version supersedes all previous versions.

12. Governing Law & Jurisdiction

Governed by Indian law. Any disputes shall be subject to the exclusive jurisdiction of courts in Mumbai, Maharashtra, India.

13. Contact — Data Protection Officer

NeoKidsPro — Data Protection Officer
Shri Hari Child Clinic, Borivali East, Mumbai — 400066
Email: admin@neokidspro.in  ·  Phone: +91 98798 91082


© 2026 NeoKidsPro. All rights reserved. Last reviewed June 1, 2026.