Privacy Policy
Effective Date: 01 August 2026 Last Updated: 27 August 2026
1. Introduction
auraCare is a digital Hospital Management Information System ("HMIS") designed to support healthcare providers in managing patient registration, appointments, queues, consultations, clinical records, diagnostics, pharmacy, billing, discharge, administrative workflows and related healthcare operations.
auraCare is provided by Nrisimha Tech Solutions, a sole proprietorship of Tapash Datta, having its registered office at Sachi Garens A1, ISKCON Mayapur, Nadia, West Bengal 741313, India ("auraCare", "we", "us" or "our").
We recognise that health information is highly sensitive and requires a high level of confidentiality, security and responsible handling.
This Privacy Policy explains how personal data is collected, used, stored, disclosed and protected when individuals interact with auraCare, our websites, applications, services and integrations.
We process personal data in accordance with applicable Indian law and regulatory requirements, including, where applicable:
- the Information Technology Act, 2000;
- the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules");
- the Digital Personal Data Protection Act, 2023 ("DPDP Act"), as its provisions come into force;
- the Digital Personal Data Protection Rules, 2025, as their provisions come into force;
- applicable directions issued by the Indian Computer Emergency Response Team ("CERT-In");
- the Ayushman Bharat Digital Mission ("ABDM") Health Data Management Policy and applicable ABDM specifications, where auraCare participates in the ABDM ecosystem; and
- other healthcare, record-retention, information-security and regulatory requirements applicable to the relevant healthcare provider.
This Privacy Policy should be read together with the privacy notices and policies of the hospital, clinic, laboratory, pharmacy or other healthcare organisation using auraCare.
This Privacy Policy is published in English. Where required under section 5 of the DPDP Act, a version in any language specified in the Eighth Schedule to the Constitution of India will be made available on request to the contact given in section 28.
Status of auraCare
auraCare is an independent software product built by an early-stage company.
auraCare is not certified, accredited, approved, empanelled or endorsed by any healthcare institution, regulatory authority, standards body or government body, except where we state otherwise expressly and in writing. Nothing in this Privacy Policy should be read as a claim of any such approval, and a reference to a law, standard or programme describes an obligation we work to meet, not an assessment anyone has made of us.
References in this Privacy Policy to ABDM describe how auraCare is designed to behave if and when ABDM functionality is implemented and enabled. As at the "Last Updated" date above, our ABDM registration is under application, and no ABDM functionality is available in any auraCare deployment. Section 7 sets this out in full.
2. Our Role and the Healthcare Provider's Role
When auraCare is used by a healthcare provider
Hospitals, clinics, laboratories and other healthcare organisations using auraCare generally determine why and how their patients' personal and health information is processed.
Accordingly, for patient information processed through auraCare on behalf of a healthcare organisation:
- the healthcare organisation generally acts as the entity responsible for determining the purpose and means of processing and, where the DPDP Act applies, may act as the Data Fiduciary; and
- auraCare generally processes such information on behalf of the healthcare organisation and may act as a Data Processor.
Healthcare providers remain responsible for establishing an appropriate lawful basis for processing patient information, providing required privacy notices, obtaining consent where required, establishing appropriate retention periods and responding to patient requests.
auraCare assists healthcare providers in fulfilling these responsibilities through appropriate technical and organisational capabilities.
How auraCare is deployed
auraCare is deployed as an isolated instance for each healthcare provider, in a cloud space of that provider's choosing, including the hosting region. We do not operate a shared, multi-tenant database of patient records, and one healthcare provider's deployment is separate from every other's.
It follows that:
- we do not hold patient records of our own, and patient records are not centralised with us;
- the healthcare provider controls the environment in which its patient data is stored, and satisfies the data-localisation requirements that apply to it by choosing an appropriate region;
- we have no standing access to a healthcare provider's patient data; and
- where access is required for support, implementation, migration or diagnosis of a fault, that access is granted by the healthcare provider, limited to what the task requires, time-bound so far as practicable, and recorded in the audit trail described in section 13.
Information a healthcare provider chooses to send us — for example a screenshot, an exported record or a log extract attached to a support request — is processed only to handle that request and is deleted when it is no longer needed for that purpose. Healthcare providers should avoid including patient identifiers in support requests unless they are necessary to resolve the issue.
We separately operate demonstration environments, which contain demonstration data only. Section 14 describes them.
When auraCare determines the purpose of processing
For certain information processed directly by us — for example information concerning:
- our website visitors;
- customer organisations;
- authorised account administrators;
- billing contacts;
- prospective customers;
- support requests; or
- security and service administration —
Nrisimha Tech Solutions may act as the Data Fiduciary or otherwise be directly responsible for the processing.
3. Personal Data We May Process
The categories below describe the information the auraCare software processes within a healthcare provider's own deployment, depending upon the services that provider uses.
As described in section 2, that information stays in the provider's environment. Listing a category here does not mean that we hold a copy of it.
3.1 Identification and demographic information
This may include:
- name;
- date of birth or age;
- sex or gender information where clinically or administratively relevant;
- photograph;
- patient or hospital identification number;
- address;
- telephone number;
- email address;
- emergency contact information;
- family or guardian information; and
- other information necessary to identify or administer the patient.
3.2 Health and clinical information
This may include:
- medical history;
- symptoms and clinical observations;
- diagnoses;
- allergies;
- prescriptions and medication history;
- consultation notes;
- vital signs;
- laboratory requests and results;
- diagnostic reports;
- imaging references or results;
- procedure information;
- treatment plans;
- admission and discharge information;
- referrals;
- nursing information;
- clinical documents;
- health certificates; and
- other information created in the course of providing healthcare.
Health information may constitute sensitive personal data or information under applicable Indian law.
3.3 ABDM and ABHA information
ABDM functionality is not currently available — see section 7. If and when it is implemented, approved and enabled by a healthcare provider, auraCare may process information such as:
- ABHA Number;
- ABHA Address;
- demographic information returned through authorised ABDM workflows;
- healthcare facility identifiers;
- healthcare professional identifiers;
- care-context information;
- health-information exchange references;
- consent artefacts and consent status;
- transaction identifiers; and
- other information required for authorised ABDM transactions.
Participation in ABDM and the use of an ABHA are subject to applicable ABDM requirements.
A patient should not be denied healthcare solely because they choose not to create or use an ABHA, except where otherwise required by applicable law or a specific programme.
3.4 Billing and financial information
Depending upon the healthcare provider's configuration, auraCare may process:
- invoices;
- charges;
- payment status;
- insurance details;
- claims information;
- payer information;
- transaction references; and
- limited payment-related information.
Where payments are processed by an external payment provider, card or banking credentials may be collected directly by that provider rather than by auraCare.
3.5 Healthcare workforce information
For doctors, nurses, receptionists, administrators and other users, we may process:
- name;
- professional role;
- department;
- employee or practitioner identifier;
- contact details;
- username;
- authentication information;
- permissions;
- assigned facility or location;
- professional registration information where applicable; and
- activity and audit records.
3.6 Technical, security and usage information
We may collect:
- IP address;
- device and browser information;
- authentication events;
- date and time of access;
- user activity;
- audit events;
- API transaction information;
- system logs;
- error reports;
- security events; and
- performance information.
Such information may be required for security, troubleshooting, regulatory compliance, fraud prevention and operation of the service.
4. How Personal Data Is Collected
Personal data may be obtained:
- directly from patients or their representatives;
- from healthcare professionals and authorised hospital staff;
- from healthcare organisations using auraCare;
- from diagnostic systems, laboratory systems, pharmacy systems and other authorised integrations;
- through ABDM or other government systems where authorised;
- from insurers or other authorised healthcare participants;
- automatically through use of the auraCare platform; or
- from another source where collection is authorised by the individual or permitted by law.
We seek to process only information reasonably necessary for the relevant healthcare, administrative, security or legal purpose.
5. Why We Process Personal Data
Personal data processed through auraCare may be used for purposes including:
Healthcare delivery
- registering and identifying patients;
- arranging appointments;
- managing patient queues and visits;
- supporting consultation and treatment;
- maintaining clinical records;
- issuing prescriptions;
- conducting diagnostics;
- managing laboratory and pharmacy workflows;
- coordinating referrals;
- managing admissions and discharge; and
- supporting continuity of care.
Healthcare administration
- billing and invoicing;
- insurance and claims administration;
- operational reporting;
- facility management;
- staff administration;
- appointment and communication management; and
- healthcare-provider compliance obligations.
ABDM interoperability
Where enabled and authorised, data may be processed to:
- create or verify an ABHA;
- link appropriate health records or care contexts;
- operate as or support a Health Information Provider ("HIP");
- operate as or support a Health Information User ("HIU");
- process consent-based health-information exchange;
- interact with ABDM registries;
- transmit or receive permitted health information; and
- maintain records of ABDM transactions.
ABDM health-information exchange will be performed in accordance with applicable ABDM consent requirements.
Security and platform administration
We may process information to:
- authenticate users;
- enforce role-based permissions;
- maintain audit trails;
- detect unauthorised access;
- investigate security incidents;
- prevent fraud or misuse;
- maintain backups;
- troubleshoot errors;
- monitor service availability;
- protect patients and healthcare organisations; and
- comply with legal and cybersecurity obligations.
Legal and regulatory compliance
Information may also be processed where reasonably necessary to:
- comply with applicable law;
- respond to lawful government or judicial requests;
- meet healthcare record-retention obligations;
- investigate security incidents;
- protect legal rights;
- establish or defend legal claims; or
- protect an individual's vital interests in situations permitted by applicable law.
6. Consent and Choice
Where consent is required, the responsible healthcare provider or auraCare, as applicable, will seek consent that is appropriate to the particular processing activity.
Consent should be:
- informed;
- specific;
- freely given where required;
- capable of being withdrawn where applicable; and
- obtained through a clear affirmative action.
Withdrawal of consent will not make processing already lawfully undertaken invalid.
Certain information may continue to be retained or processed after consent is withdrawn where retention or processing is required or permitted by applicable law, including healthcare record-retention requirements, legal obligations, security requirements or the establishment, exercise or defence of legal claims.
7. ABDM Consent and Health Information Exchange
ABDM functionality is not currently available. As at the "Last Updated" date above:
- our ABDM registration is under application and has not been granted;
- no auraCare deployment is connected to ABDM; and
- no ABHA number, ABHA address, consent artefact or health-information-exchange data is processed by auraCare.
The remainder of this section describes how auraCare is designed to behave if and when ABDM functionality is implemented, approved and enabled for a healthcare provider. It is a statement of design intent, not of present capability. Healthcare providers should confirm current ABDM availability with us in writing before relying upon it.
auraCare is designed to support the consent-based architecture of ABDM.
Where an ABDM transaction requires patient consent, health information will be linked, requested, accessed or shared only in accordance with the applicable ABDM workflow and valid consent or other lawful authority.
ABDM consent may specify matters including:
- the health information requested;
- the purpose of access;
- the requesting organisation;
- the healthcare organisation providing the information;
- the relevant period of health information; and
- the period for which the consent is valid.
Withdrawal or expiry of ABDM consent will be respected in accordance with the applicable ABDM framework.
auraCare does not treat the creation or possession of an ABHA as blanket consent to access or disclose a person's medical records.
8. Aadhaar
Where Aadhaar-based functionality is used as part of an authorised ABHA or government workflow, auraCare will process Aadhaar-related information only to the extent permitted by applicable law and the authorised integration.
Use of Aadhaar for an ABDM-related workflow does not by itself authorise unrestricted use or retention of Aadhaar information.
auraCare will not use Aadhaar information for unrelated advertising, profiling or marketing purposes.
9. Sharing and Disclosure of Personal Data
Personal data may be made available only where appropriate to the purpose for which it is processed.
Recipients may include:
Healthcare provider personnel
Authorised doctors, nurses, pharmacists, laboratory personnel, reception staff, billing staff, administrators and other personnel may access information according to their assigned role and permissions.
Service providers
We may use carefully selected organisations to provide services such as:
- cloud infrastructure;
- hosting;
- data backup;
- email or SMS delivery;
- monitoring;
- cybersecurity;
- customer support; and
- other technical services.
Such providers must process information only for authorised purposes and must be subject to appropriate confidentiality, security and contractual obligations.
Our own service providers support our website, our demonstration environments and the running of our business. Where a visitor to our website consents to analytics, Google is a recipient of that website-usage information, as described in section 20. They are not a route by which patient records reach us, because patient records are held in the healthcare provider's own deployment (section 2). A healthcare provider's deployment may itself rely on service providers — its cloud provider, for example — under arrangements that provider controls.
ABDM participants
Where authorised, information may be exchanged with participants in the ABDM ecosystem, including HIPs, HIUs, consent-management infrastructure, registries and other authorised systems.
Government and regulatory authorities
Information may be disclosed where required under applicable law, regulation, court order or valid request from an authorised government or regulatory authority.
Where legally permitted, we will seek to ensure requests are appropriately authorised and limited to the information lawfully required.
Corporate transactions
If the business operating auraCare undergoes a merger, acquisition, restructuring or transfer, personal data may be transferred subject to applicable law, confidentiality obligations and appropriate protection.
10. Sale, Advertising and Unrelated Use of Health Data
auraCare does not sell patient medical records or personal health information.
Patient clinical information processed through auraCare is not intended to be used for targeted advertising.
Personal health information will not be disclosed to advertisers or data brokers for unrelated commercial advertising purposes.
Where de-identified or aggregated information is used for service improvement, reporting or analytics, reasonable measures will be used to prevent identification of individuals.
Identifiable patient clinical information will not be used to train a general-purpose artificial intelligence model unless such processing is separately authorised, legally permitted and subject to appropriate safeguards.
11. Data Minimisation and Purpose Limitation
We seek to collect and process only the personal data reasonably necessary for a specified purpose.
Personal data collected for one purpose will not be used for a materially incompatible purpose unless:
- appropriate consent has been obtained;
- the use is reasonably necessary to provide the requested service; or
- such processing is otherwise permitted or required by law.
Access to patient information should be based upon professional responsibility and legitimate operational need rather than general availability within the organisation.
12. Security of Personal Data
Because auraCare processes healthcare information, we apply technical and organisational safeguards appropriate to the nature and sensitivity of the information.
Depending upon the deployment and service, safeguards may include:
- encryption of data in transit;
- encryption of sensitive data at rest;
- role-based access control;
- least-privilege access;
- secure authentication;
- multi-factor authentication for appropriate privileged access;
- audit logging;
- session-management controls;
- database access controls;
- secure backup procedures;
- network and infrastructure security;
- vulnerability management;
- software security testing;
- monitoring for suspicious activity;
- incident-response procedures;
- access reviews;
- separation of production and development environments; and
- contractual confidentiality requirements for personnel and service providers.
We maintain or seek to maintain documented information-security practices appropriate to the sensitivity and scale of the information processed.
No computer system can be guaranteed to be completely secure. We therefore continuously review and improve security controls according to identified risks and applicable requirements.
13. Audit Trails
auraCare may maintain audit records showing activities such as:
- patient-record access;
- creation or alteration of clinical information;
- login and authentication events;
- permission changes;
- administrative actions;
- ABDM transactions;
- consent-related transactions; and
- other security-relevant activities.
Audit information is used for accountability, security investigations, legal compliance and healthcare-provider governance.
Audit records are protected from unauthorised modification to the extent reasonably practicable.
System and security logs will be retained for the periods required under applicable Indian cybersecurity requirements, including the CERT-In directions of 28 April 2022, which require specified logs to be maintained for a rolling period of 180 days and within Indian jurisdiction.
14. Data Storage and Location
Patient information remains under the stewardship of the relevant healthcare provider.
ABDM follows a federated health-information architecture: participating healthcare providers remain responsible for the health records they create, and ABDM enables authorised interoperability rather than creating an unrestricted central repository of clinical records.
auraCare is built for healthcare providers in India. Health data created in an Indian healthcare deployment is subject to Indian data-localisation requirements, including the ABDM Health Data Management Policy and the CERT-In directions concerning maintenance of logs within Indian jurisdiction.
As described in section 2, auraCare is not a central service that patient records are sent to. There are three distinct kinds of environment, and they hold different kinds of data:
Production healthcare deployments. Each production deployment is an isolated auraCare instance running in a cloud space belonging to, or chosen by, the healthcare provider. The provider chooses the hosting region, which is how a provider subject to Indian data-localisation requirements satisfies them. Patient records created in that deployment stay in that environment. We do not keep a copy, and no patient records are pooled across providers. The arrangements for a deployment are recorded in the written agreement with that provider before any patient data is processed, and a provider may request the details at any time using the contact in section 28.
Demonstration environments. We operate demonstration instances for evaluation and product demonstration. They contain demonstration data only. Real patient records must not be entered into a demonstration environment, and no healthcare provider should use one to deliver care.
Public website. The website at https://auracare.cc is a static publication. It holds no patient data, no clinical data and no user accounts. Section 20 describes exactly what it does and does not do.
Where personal information is transferred between systems or jurisdictions, such transfer will be subject to applicable legal requirements and appropriate contractual and security safeguards.
15. Retention and Deletion
Personal data is retained only for as long as reasonably necessary for:
- provision of healthcare;
- maintaining legally required medical records;
- the purpose for which the information was collected;
- contractual requirements with the healthcare provider;
- patient safety;
- security and audit requirements;
- dispute resolution;
- compliance with applicable law; or
- establishment, exercise or defence of legal claims.
Because hospitals and other healthcare providers may be legally required to retain certain medical records, a request to delete information does not necessarily require immediate deletion of every healthcare record.
When information is no longer required and no lawful retention obligation applies, it will be deleted, anonymised or otherwise disposed of securely in accordance with applicable procedures.
Healthcare providers using auraCare establish retention periods for their patient records based upon applicable healthcare laws and their own lawful policies.
Because patient records are held in the healthcare provider's own deployment rather than by us (section 2), retention and deletion of those records are carried out in that environment, under the provider's control. We hold no separate copy of them to retain or to delete. Where a provider has sent us information in the course of a support request, that information is deleted once it is no longer needed for the request.
16. Rights of Individuals
Subject to applicable law and the nature of the processing, individuals may have rights including the ability to:
- obtain information about how their personal data is processed;
- request access to information relating to them;
- request correction of inaccurate or misleading personal data;
- request completion of incomplete personal data;
- request erasure where legally available;
- withdraw consent where processing depends upon consent;
- submit a grievance concerning processing of personal data; and
- nominate another individual to exercise applicable rights in circumstances recognised by law.
Some of these rights arise or will arise under provisions of the DPDP Act as those provisions become legally effective.
Requests concerning hospital records
Where auraCare processes patient information on behalf of a hospital or other healthcare provider, individuals should ordinarily submit privacy requests directly to that healthcare provider.
auraCare will reasonably assist the healthcare provider in responding to valid requests.
We may need to verify the identity and authority of a person making a request before releasing or modifying information.
17. Children and Persons Requiring a Lawful Guardian
Healthcare services frequently involve children.
Personal data concerning a child will be processed in accordance with applicable healthcare and data-protection requirements.
Where legally required, appropriate consent or authorisation will be obtained from a parent or lawful guardian.
This does not prevent processing permitted by law for purposes such as healthcare, medical emergencies or other circumstances where specific healthcare-related legal provisions or exemptions apply.
Healthcare organisations are responsible for identifying the appropriate lawful authority for treatment and related processing.
18. Emergencies
Applicable law may permit healthcare information to be processed without ordinary consent procedures in limited circumstances, including certain medical emergencies, threats to life or health, disasters, epidemics or other situations recognised by law.
Any such processing should remain limited to what is reasonably necessary for the applicable purpose.
19. Personal Data Breaches and Security Incidents
auraCare maintains procedures for identifying, investigating, containing and responding to suspected personal-data breaches and cybersecurity incidents.
Where a breach occurs, we will take reasonable steps to:
- contain and investigate the incident;
- mitigate potential harm;
- preserve relevant evidence and logs;
- notify the affected healthcare organisation where auraCare processes data on its behalf;
- report cybersecurity incidents of the kinds specified in the CERT-In directions to CERT-In within six hours of noticing them or being notified of them; and
- make notifications to affected individuals, the Data Protection Board of India or other authorities where and within the period required by applicable law.
Healthcare organisations using auraCare are expected to cooperate with incident investigations and regulatory reporting where required.
20. The auraCare Website
The public auraCare website at https://auracare.cc is a static publication. It operates no login, holds no user account, and contains no patient data of any kind.
Before you choose
Until you make a choice about analytics, the website sets no cookies at all. If you decline, the only cookie set is the one recording that decision, described below.
Whatever you choose, the website:
- loads no advertising or tracking scripts;
- makes no request to any third-party server other than Google Analytics, and then only if you have accepted it — every font, stylesheet, script and image is served from auracare.cc itself; and
- receives no form submissions. The "Book a demo" form composes a message in the visitor's own email application, addressed to us. Nothing from that form is transmitted to auracare.cc.
Analytics, and the choice we ask you to make
We use Google Analytics 4 to understand how the website is used — which pages are read, how visitors arrive, and on what kind of device — so that we can improve it.
Analytics is off until you accept it. On a first visit the website asks, and no Google script is downloaded and no analytics cookie is set unless and until you choose "Accept analytics". If you decline, or simply ignore the request, nothing is loaded and nothing is sent.
If you accept:
- a script is loaded from googletagmanager.com and Google Analytics sets cookies in your browser — principally _ga and a per-stream cookie beginning _ga_ — used to distinguish one visit from another;
- Google receives information about the visit, including the pages viewed, the referring page, approximate location derived from your IP address, and general device and browser characteristics;
- we do not enable Google Analytics advertising features. Google's consent signals for advertising storage, advertising user data and advertising personalisation are all set to denied, and only analytics storage is enabled; and
- we do not use analytics to identify individual visitors, and we do not combine analytics information with any hospital or patient data. There is none on this website to combine it with.
Google acts as our processor for this purpose and may process the information outside India, on Google's infrastructure. This concerns website-usage information only. It is separate from, and has no bearing on, the patient data held in a healthcare provider's own auraCare deployment, which is governed by section 14.
Changing your mind
You can change or withdraw your choice at any time using the Cookie settings link in the website footer. Withdrawing takes effect immediately: the analytics cookies already set are deleted from your browser, the tag is told to stop, and nothing further is loaded on subsequent visits. Google's own information about how it handles data for Analytics customers is published at policies.google.com/technologies/partner-sites.
The cookie we set whatever you choose
Recording your answer requires remembering it. We store your analytics choice in a first-party cookie named auracare_consent — it holds nothing but the word granted or denied, lasts six months, and is never sent to anyone else. This is what stops the website asking again on every page, so it is set whether you accept or decline. If your browser refuses cookies, the choice is kept in local storage instead.
The website also stores one appearance preference — whether you chose the light or dark theme — in your browser's local storage. It remains in that browser, is never transmitted to us, and is not used to identify anyone.
Server logs
Standard web-server logs, containing information such as IP address, date and time, requested path and browser user-agent, are generated by the hosting infrastructure for security, abuse prevention and diagnostics, and are handled as described in sections 13 and 15. These are generated for every visitor and are not affected by the analytics choice, because they are necessary to operate and protect the service.
If any further non-essential technology is introduced in future, it will be subject to the same consent requirement and this section will be updated before it is enabled.
The public auraCare website must not be used to submit confidential medical information. It is not a secure channel for clinical data.
21. Communications
Healthcare providers may use auraCare to send operational communications including:
- appointment confirmations;
- queue notifications;
- prescription or report availability notices;
- billing notifications;
- patient-care reminders; and
- service-related messages.
Such communications are controlled by the relevant healthcare provider.
Marketing communications sent directly by auraCare will provide an appropriate method of opting out where required.
Essential security, administrative or transactional communications may still be sent where necessary.
22. Data Accuracy
Healthcare providers and authorised users are expected to take reasonable steps to ensure that personal and clinical information entered into auraCare is accurate and appropriately updated.
Individuals who believe information in their medical record is inaccurate should contact the healthcare provider responsible for that record.
Clinical records may be subject to rules concerning amendment, correction and preservation of historical entries. A healthcare record may therefore be corrected through an auditable amendment rather than deletion or overwriting of the original clinical entry.
23. Employee and Authorised User Responsibilities
Access to auraCare is intended only for authorised personnel.
Users must:
- access patient information only where necessary for their authorised duties;
- protect account credentials;
- not share passwords;
- respect patient confidentiality;
- not export or disclose information without authority;
- immediately report suspected misuse or security incidents; and
- comply with their healthcare organisation's privacy and information-security policies.
Access to patient information may be logged and audited.
24. Automated Processing and Artificial Intelligence
Where auraCare provides automated decision-support, analytics or artificial-intelligence-assisted features, such features are intended to support authorised healthcare professionals and administrative users rather than replace appropriate professional judgement.
Where an AI-enabled function processes identifiable patient information, the information must be processed only for authorised purposes and subject to applicable privacy, security and healthcare requirements.
auraCare will not represent automated output as a substitute for professional medical diagnosis where human clinical judgement is required.
25. Third-Party Integrations
Healthcare organisations may connect auraCare with external services including:
- laboratories;
- diagnostic systems;
- pharmacies;
- insurers;
- payment providers;
- messaging services;
- government systems;
- ABDM services; and
- other healthcare applications.
Those organisations may have their own privacy policies and legal responsibilities.
auraCare is not responsible for independent processing undertaken by a third party outside our instructions or control.
Healthcare providers should review integrations before enabling them and ensure that personal data is disclosed only where authorised.
26. Grievance Redressal
Questions, concerns or grievances regarding personal-data processing by auraCare may be directed to:
Grievance / Privacy Officer
- Name: Tapash Datta
- Organisation: Nrisimha Tech Solutions
- Address: Sachi Garens A1, ISKCON Mayapur, Nadia, West Bengal 741313, India
- Email: [email protected]
- Telephone: +91 93390 95339
We will acknowledge and address privacy grievances within the period prescribed under applicable law.
If the concern relates primarily to a patient's medical record maintained by a healthcare provider using auraCare, the individual may also contact that healthcare provider's designated privacy or grievance contact.
Where legally available and after the applicable grievance process has been followed, an individual may have the right to approach the competent statutory authority, including the Data Protection Board of India once the relevant provisions are applicable.
27. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
- changes to auraCare;
- new integrations;
- changes in law or regulation;
- ABDM requirements;
- security practices; or
- changes in how personal data is processed.
Where a change materially affects the way personal data is processed, appropriate notice will be provided as required by applicable law.
The "Last Updated" date at the top of this document indicates the most recent revision.
A new purpose requiring fresh consent will not be treated as authorised merely because this Privacy Policy has been updated, where applicable law requires separate consent.
28. Contact Us
For general privacy questions:
- Nrisimha Tech Solutions
- Product: auraCare
- Website: https://auracare.cc
- Privacy and security: [email protected]
- ABDM enquiries: [email protected]
- General enquiries: [email protected]
- Registered address: Sachi Garens A1, ISKCON Mayapur, Nadia, West Bengal 741313, India
- Telephone: +91 93390 95339
29. Commitment to Privacy by Design
auraCare is designed around the principle that healthcare information should be accessible to the right person, for the right purpose, at the right time — and not otherwise.
We seek to incorporate privacy and security throughout the lifecycle of the service through:
- data minimisation;
- purpose limitation;
- role-based access;
- auditable access;
- secure system design;
- consent-based interoperability;
- controlled data sharing;
- appropriate retention;
- accountability; and
- continuous security improvement.
Our objective is to support healthcare organisations in delivering efficient, interoperable healthcare while preserving patient confidentiality, autonomy and trust.