Emrald Medical Research Private Limited ("we", "us", "our", "the Company")
operates the website https://emraldpetscan.com/
(the "Site"). This Privacy Policy explains how we collect, use, disclose, and
safeguard your personal information when you visit the Site, book an
appointment, or make a payment. By using our Site you agree to the practices
described below.
This Policy is published in accordance with the Information Technology Act,
2000, the Information Technology (Reasonable Security Practices and Procedures
and Sensitive Personal Data or Information) Rules, 2011, and the Digital
Personal Data Protection Act, 2023 ("DPDP Act").
1. Information We Collect
a) Information you provide directly
- Identity data: name, gender, date of birth, age.
- Contact data: mobile number, email address, postal address.
- Health data (only when you book a diagnostic service or therapy):
symptoms, referring doctor's details, prescription / scan reports you upload,
clinical history you disclose. This is "sensitive personal data" and we treat
it with heightened protection.
- Payment data: amount, service selected, billing contact.
We do not collect or store your full card number, UPI PIN, CVV, or
net-banking password. Payment credentials are entered on the secure page of
our payment gateway partner, PhonePe Payment Gateway (operated by PhonePe
Private Limited), who is PCI-DSS compliant.
b) Information collected automatically
- IP address, browser type, operating system, device identifiers.
- Pages visited, time spent on the Site, referral URL, search terms used.
- Cookies and similar technologies — see Section 7.
c) Information from third parties
- Transaction status, payment reference numbers, and failure reasons received
from PhonePe after you complete a payment.
- Reports generated by our diagnostic equipment during the service you book.
2. How We Use Your Information
We use your information only for the purposes listed below:
- To schedule, confirm, reschedule, and deliver your appointment or therapy.
- To process payments, issue invoices/receipts, and reconcile transactions with PhonePe.
- To send you appointment reminders, reports, and service-related notifications
via SMS, WhatsApp, email, or phone call.
- To respond to your enquiries submitted through the contact form.
- To maintain medical records as required under the Indian Medical Council
(Professional Conduct, Etiquette and Ethics) Regulations, 2002 (minimum
3 years from last patient contact).
- To detect fraud, investigate chargebacks, and satisfy legal, regulatory,
audit, tax, and accounting obligations (including GST, under CIN
and GSTIN ).
- To improve the performance, content, and security of the Site.
3. Legal Basis (under the DPDP Act, 2023)
We process your personal data on one or more of the following lawful grounds:
your consent; performance of a contract you have entered into with us (e.g. a
booking); compliance with a legal obligation; provision of a medical/diagnostic
service that you have specifically requested.
For sensitive health data, we rely on your explicit consent,
collected at the time of booking. You may withdraw consent at any time by
writing to us at info@emraldmedical.com
— although withdrawal may make us unable to continue your treatment or release
reports.
4. How We Share Your Information
We never sell your personal data. We share it only as follows:
- PhonePe Payment Gateway — for payment processing. PhonePe's
own privacy policy applies to the data they collect during a transaction:
https://www.phonepe.com/privacy-policy
- Referring physicians / treating consultants — only the
report relevant to the service you booked, with your consent.
- Service providers — our hosting provider, SMS/email
delivery partners, and cloud backup provider, all under written
confidentiality obligations and a "need-to-know" basis.
- Regulatory authorities and law enforcement — only when
required by a valid court order, summons, or statutory obligation.
- Professional advisors — auditors, chartered accountants,
and legal counsel, under confidentiality obligations.
- Corporate transactions — in the event of merger,
acquisition, or reorganisation, data may be transferred to the successor
entity, subject to this Policy.
5. Data Retention
- Medical records and reports: retained for a minimum of 3 years from the
date of last patient contact, as required by the Indian Medical Council
regulations; certain records relating to minors are kept longer.
- Payment and tax records: retained for 8 years, as required under the
Companies Act, 2013, and the Income Tax Act, 1961.
- Appointment enquiries without a booking: deleted after 12 months.
- Website analytics: retained for up to 26 months in aggregated form.
6. Data Security
We implement reasonable security practices and procedures to protect your data:
- HTTPS (TLS) encryption for all data in transit.
- Encrypted database backups stored off-server.
- Role-based access to admin systems, with unique credentials and two-factor authentication.
- Payment data never stored on our servers — handled directly by PhonePe.
- Periodic security audits, software patching, and activity logging.
Despite these measures, no transmission over the Internet is 100% secure. If
you suspect that your data has been compromised, please contact us immediately
at info@emraldmedical.com.
We will notify the Data Protection Board of India and affected users in
accordance with the DPDP Act timelines in the event of a notifiable breach.
7. Cookies
We use cookies and similar technologies for session management (keeping you
logged in), CSRF protection, and basic analytics. You may disable cookies in
your browser; however, some features of the Site (such as the booking flow)
may not work without them.
8. Your Rights (Data Principal Rights under DPDP Act)
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request erasure of your data (subject to retention obligations above).
- Nominate another individual to exercise these rights in the event of your
death or incapacity.
- Withdraw consent previously given, at any time.
- Lodge a grievance with our Grievance Officer (see Section 11).
- Approach the Data Protection Board of India if unsatisfied.
To exercise any of these rights, email us at
info@emraldmedical.com
with the subject line "Data Request". We will respond within 30 days.
9. Children's Privacy
Our services include diagnostic tests for patients of all ages, including
minors. Where a patient is under 18, we require the consent of a parent or
legal guardian before booking an appointment or processing health information.
10. Third-Party Links
Our Site may contain links to third-party websites (such as PhonePe). This
Policy does not apply to those websites; please review their privacy policies
before sharing information with them.
11. Grievance Officer
In accordance with the Information Technology Act, 2000 and Rule 5(9) of the
IT Rules, 2011, the details of our Grievance Officer are published below:
Grievance Officer: Managing Director,
Emrald Medical Research Private Limited
Address: CTS NO-16035, PLOT NO-110, A-62, Shrikrishna Nagar, Ulkanagari, Chhatrapati Sambhajinagar, Maharashtra 431009
Email:
info@emraldmedical.com
Phone: +91 9876543210 (Mon–Sat, 9:00 AM – 6:00 PM)
We will acknowledge your grievance within 48 hours and resolve it within 30
days of receipt.
12. Changes to this Policy
We may update this Policy from time to time. The updated version will be
posted on this page with a new "Last updated" date. Material changes will be
notified by email or on the Site prominently.
13. Contact
Questions about this Privacy Policy should be sent to:
- Emrald Medical Research Private Limited
- CTS NO-16035, PLOT NO-110, A-62, Shrikrishna Nagar, Ulkanagari, Chhatrapati Sambhajinagar, Maharashtra 431009
- Email: info@emraldmedical.com
- Phone: +91 9876543210