Data Protection Policy
This Data Protection Policy explains, in plain language, how NeoKidsPro (Shri Hari Child Clinic) collects, uses, stores and protects your child's health data and your personal information. It applies to every appointment, prescription and payment made on the NeoKidsPro platform.
Data Protection Policy: Table of Contents
- 1. Scope of this Data Protection Policy
- 2. Why Our Data Protection Policy Matters
- 3. Data Classification Under this Data Protection Policy
- 4. Data Protection Policy Principles
- 5. Consent Management
- 6. Technical Safeguards
- 7. Organisational Safeguards
- 8. Third-Party Data Processors
- 9. Data Breach Response
- 10. Cross-Border Data Transfers
- 11. Your Rights Under this Data Protection Policy
- 12. Data Protection Policy for Telemedicine
- 13. Policy Review
- 14. Governing Law & Jurisdiction
- 15. Data Protection Policy FAQs
- 16. Contact Our Data Protection Officer
Encrypted by design
Every consultation, prescription and payment is protected end-to-end under this policy.
Child-first safeguards
Extra care is taken with minors' health data, consistent with our consent rules.
Full transparency
You can always ask what data we hold, correct it, or withdraw consent under this policy.
1. Scope of this Data Protection Policy
This Data Protection Policy applies to everyone who interacts with NeoKidsPro, whether through online pediatric consultation, our physical clinic in Borivali East, or our website and EMR system. Wherever NeoKidsPro collects, stores, or shares information, this policy governs how that information is handled.
- All patients (and parents / guardians) who use the NeoKidsPro platform
- All doctors and clinical staff onboarded to the platform
- All administrative staff and technology vendors who process data on our behalf
- All data processed through neokidspro.in and the associated EMR system
If any provision of this Data Protection Policy conflicts with our Telemedicine Guidelines on a clinical matter, the Telemedicine Guidelines will govern how the consultation itself is conducted, while this policy continues to govern how the resulting data is stored.
2. Why Our Data Protection Policy Matters
Parents trust NeoKidsPro with some of the most sensitive information there is: their child's health history. That is why this Data Protection Policy exists — to make sure every record, prescription and payment is handled with the same care we'd want for our own families. A strong policy like this is not just a legal requirement for us; it is a promise that your child's data will never be treated carelessly.
We designed this policy to be readable by parents, not just lawyers, so you always know exactly what happens to your information before, during and after a consultation.
3. Data Classification Under this Data Protection Policy
To apply the right level of protection, this policy classifies the information we collect into the following categories:
| Category | Examples | Classification |
|---|---|---|
| Patient identity | Name, DOB, gender, parent name | Personal Data |
| Contact information | Phone, email, address | Personal Data |
| Medical records | Diagnosis, prescriptions, vitals, history | Sensitive Personal Data (SPDI) |
| Payment records | Transaction ID, fee paid, settlement | Confidential Financial Data |
| Doctor credentials | Registration number, KYC documents | Confidential Professional Data |
| Platform usage | IP address, browser logs, session data | Technical Data |
4. Data Protection Policy Principles
The following principles guide every decision we make about your data, and form the backbone of our Data Protection Policy:
- Lawfulness: Data is collected only with valid consent or other lawful basis
- Purpose limitation: Data collected for one purpose is not used for another without fresh consent
- Data minimisation: We collect only what is necessary for the stated purpose
- Accuracy: We maintain accurate, up-to-date records and allow corrections on request
- Storage limitation: Data is retained only for as long as legally or medically required
- Integrity and confidentiality: We apply appropriate technical and organisational safeguards
- Accountability: We document our data processing and can demonstrate compliance
Every new feature we build on NeoKidsPro is checked against these principles before launch, so this policy stays a living part of how we work, not just a page on our website.
5. Consent Management
Consent is the foundation of this policy. Here is how we manage it in practice:
- Consent is obtained at the point of booking an appointment via a mandatory checkbox
- Granular consent — separate for marketing vs. essential medical communications
- Consent can be withdrawn at any time by writing to care@neokidspro.in
- Withdrawal does not affect lawfulness of prior processing
- Medical record retention obligations under MCI guidelines continue even after withdrawal
- For patients under 18, consent must be provided by a parent or legal guardian
6. Technical Safeguards
This Data Protection Policy is backed by concrete technical controls, including:
- All data transmitted over encrypted HTTPS / TLS connections
- Passwords hashed using bcrypt (12 salt rounds) — never stored in plaintext
- EMR access controlled via JWT authentication with role-based permissions
- Medical PDFs served through authenticated endpoints only — not publicly accessible URLs
- Database accessible only via application-layer queries — no direct external DB access
- Server infrastructure on Hostinger VPS with firewall and intrusion detection, aligned with CERT-In best practices
7. Organisational Safeguards
Beyond technology, this policy is enforced through internal processes and staff accountability:
- Only authorised clinical staff can view patient medical records
- Doctors access only records of patients they have personally consulted
- Admin staff access only operational data required for their role
- All third-party vendors contracted to process data only as instructed
- Staff trained on data protection obligations at onboarding
- Security incidents reviewed within 72 hours; affected users notified without undue delay
7.1 How Staff Are Trained on this Data Protection Policy
Every team member — from front-desk staff to doctors — completes a short onboarding module on this policy before they are given any system access. Refresher training happens annually so it stays top of mind, not just a document signed once.
8. Third-Party Data Processors
Under this policy, any vendor that touches your data is bound by contract to process it only for the purpose stated below:
| Processor | Purpose | Data Shared |
|---|---|---|
| Cashfree Payments | Payment processing | Name, phone, email, amount |
| Google LLC | Video consultation (Google Meet) | Appointment details, email |
| Meta Platforms | WhatsApp notifications | Phone number, appointment info |
| Hostinger | Server & database hosting | All platform data (infrastructure) |
| SMTP / Nodemailer | Email notifications | Name, email, appointment details |
9. Data Breach Response
Should a breach ever occur, this policy commits us to a clear, time-bound response:
- Breach contained and assessed within 24 hours of discovery
- Affected users notified within 72 hours where the breach poses risk to their rights
- Relevant authorities notified as required under the DPDP Act, 2023
- Post-incident report prepared documenting cause, impact, and remediation steps
10. Cross-Border Data Transfers
Some third-party processors named above, such as Google and Meta, may process data outside India. These transfers occur under the standard contractual protections and data processing agreements of those vendors, meeting the requirements of the Digital Personal Data Protection Act, 2023 and other applicable Indian law. We do not permit any transfer that falls outside these safeguards.
11. Your Rights Under this Data Protection Policy
As a data principal, this policy gives you the right to:
- Know what data we hold about you
- Correct inaccurate personal data
- Nominate an individual to exercise rights on your behalf
- Raise a grievance with our Data Protection Officer
- Approach the Data Protection Board of India if your grievance is unresolved
For details on cookies, analytics, and how we describe your rights as a website visitor more broadly, see our Privacy Policy. For refund-related data such as transaction records, see our Refund & Cancellation Policy.
12. Data Protection Policy for Telemedicine
When you use online pediatric consultation, this Data Protection Policy extends to the video call itself: session metadata is limited to what is needed to connect you with the doctor, and no consultation is recorded or stored beyond the clinical notes your doctor enters into the EMR. It works alongside our Telemedicine Guidelines, which set out the clinical rules doctors follow during a virtual visit.
13. Policy Review
This Data Protection Policy is reviewed annually, or whenever there is a material change in data processing activities or applicable law. The current version supersedes all previous versions.
14. Governing Law & Jurisdiction
This Data Protection Policy is governed by Indian law. Any disputes arising from it shall be subject to the exclusive jurisdiction of courts in Mumbai, Maharashtra, India.
15. Data Protection Policy FAQs
What does this Data Protection Policy actually cover?
It covers how NeoKidsPro collects, classifies, stores, shares and protects personal and medical data for every patient, parent, doctor and staff member on our platform.
How is my child's medical data protected under this Data Protection Policy?
Medical records are classified as Sensitive Personal Data and are encrypted in transit, access-controlled by role, and served only through authenticated endpoints — never public URLs.
Can I withdraw consent given under this Data Protection Policy?
Yes. You can withdraw consent at any time by emailing care@neokidspro.in, though medical record retention rules under MCI guidelines will still apply to past records.
Does this Data Protection Policy apply to payments made through NeoKidsPro?
Yes, payment data is treated as Confidential Financial Data and is processed by Cashfree Payments under contractual safeguards.
Does this Data Protection Policy cover video consultations?
Yes. It extends to online pediatric consultations conducted over Google Meet, limiting session data to what is strictly needed to connect you with your doctor.
Who do I contact about this Data Protection Policy?
You can reach our Data Protection Officer at admin@neokidspro.in or through our Contact Us page.
16. Contact Our Data Protection Officer
If you have any concern about how your data is handled, our Data Protection Officer is available to help:
NeoKidsPro — Data Protection Officer
Shri Hari Child Clinic, Borivali East, Mumbai — 400066
Email: admin@neokidspro.in · Phone: +91 98798 91082 · Contact Us
Have more questions about this Data Protection Policy?
Our team is happy to walk you through how your child's data is handled before your next visit.
© 2026 NeoKidsPro. All rights reserved. Last reviewed June 1, 2026. This Data Protection Policy is provided for informational purposes and does not constitute legal advice.
NeoKidsPro is a pediatric telemedicine platform operated by Shri Hari Child Clinic, Mumbai. Read more on our Online Pediatric Consultation page or get in touch with our team.