MediCiti Hospitals (“MediCiti”, “we”, “us” or “our”) respects the privacy of everyone whose information we handle — our patients, our employees, our vendors and the visitors to our website. This is our single, common privacy policy: it explains what information our applications and website collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have.
We are the data fiduciary for the information described here. We handle it in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the confidentiality obligations that apply to us as a clinical establishment in India.
Please read this policy together with any specific notice, consent form or terms of use shown to you inside an application or at the point where we collect your information.
This policy applies to every application published by MediCiti Hospitals — on Google Play, on the Apple App Store and through our internal distribution — together with their web versions and our website at https://mediciti.co.in.
It covers the applications listed below and any application we release in the future. This page is the permanent privacy policy URL for all of them; it does not change when a new application is launched. If a new application collects information that is not already described here, we will update this policy, and the notice inside that application, before it is released.
Hospital Information Management System
The clinical and administrative system used to run hospital operations — registration, appointments, electronic medical records, diagnostics, pharmacy and billing.
Who uses it: Authorised hospital staff (clinicians, nursing, front office, diagnostics, pharmacy and billing teams). It is not a consumer application and is issued only to personnel authorised by MediCiti Hospitals.
Human Resource Management System
The employee self-service and workforce management system — attendance, leave, payroll, documents, appraisals and internal communication.
Who uses it: Employees, contract staff and authorised HR and payroll administrators of MediCiti Hospitals. It is not a consumer application and access is tied to an active engagement with the organisation.
Healthcare Supply Chain Management System
The procurement, inventory and materials management system — indents, purchase orders, goods receipt, stock movement, expiry tracking and vendor management.
Who uses it: Authorised stores, purchase, pharmacy and finance personnel, and approved vendors and suppliers who have been issued access. It is not a consumer application.
We collect only the information we need to run these applications and to meet our legal obligations. The categories below are set out per application; an application collects only what its own table lists.
| Category | What this includes |
|---|---|
| Staff account data | Employee ID, name, official e-mail and mobile number, department, role and access rights, login and audit-trail records. |
| Patient identity and contact data | Name, age, gender, date of birth, address, mobile number, e-mail, emergency contact, and government identifiers (such as ABHA ID or an identity document number) where required for registration, insurance or statutory reporting. |
| Health data (sensitive personal data) | Clinical history, symptoms, diagnoses, vitals, allergies, prescriptions, diagnostic and imaging reports, treatment and surgical notes, discharge summaries and other medical records. |
| Financial and insurance data | Bills, payment records, payer or TPA details, policy and claim references. Card details are handled by the payment gateway and are not stored in the application. |
| Device and diagnostic data | Device model, operating-system version, app version, IP address, crash logs and in-app activity logs used for security monitoring and audit trails. |
| Category | What this includes |
|---|---|
| Employee identity and contact data | Name, employee ID, photograph, date of birth, gender, personal and official contact details, residential address and emergency contact. |
| Employment data | Designation, department, reporting line, date of joining, employment type, shift and roster, leave balances, appraisal and disciplinary records. |
| Attendance data | Punch-in and punch-out timestamps, the work location associated with a punch, and — where selfie or geo-verified attendance is enabled — the attendance photograph and the coarse location captured at the moment of punching. |
| Payroll, tax and statutory data | Salary structure, bank account details for salary credit, PAN, Aadhaar (where legally required), UAN and provident fund details, ESI number, tax declarations and investment proofs. |
| Documents | Identity and address proofs, educational and professional certificates, medical-council registration where applicable, and other onboarding documents you upload. |
| Device and diagnostic data | Device model, operating-system version, app version, IP address, crash logs and login history used for security and audit purposes. |
| Category | What this includes |
|---|---|
| User account data | Employee or vendor user ID, name, official e-mail and mobile number, organisation, role and approval limits, login and audit-trail records. |
| Vendor and supplier data | Business name and address, contact-person name, phone and e-mail, GSTIN, PAN, drug-licence and other statutory registration numbers, and bank details used for payment. |
| Transaction data | Indents, quotations, purchase orders, invoices, goods-receipt and returns records, batch and expiry details, stock levels and movements, and approval history. |
| Device and diagnostic data | Device model, operating-system version, app version, IP address, crash logs and activity logs used for security monitoring and audit trails. |
What we never do. We do not sell your personal information. We do not share it with data brokers. We do not use it to serve advertising, and our applications carry no advertising SDKs and no cross-app or cross-site tracking for advertising purposes. This holds for every application we publish.
We use the information described above for the following purposes and no others:
Across all of our applications we also use information to:
We process personal data on one or more of the following bases:
Our applications ask for device permissions only for the specific features described below. Permissions marked Optional can be declined, and you can withdraw any of them later in your device settings — the rest of the application will continue to work, though the feature that needs the permission will not.
| Permission | Why we ask for it | Status |
|---|---|---|
| Camera | To capture patient documents, wound or clinical images into the record, and to scan patient wristband or sample barcodes. | Optional |
| Photos and files | To attach reports and documents to a patient record, and to save or share reports the user generates. | Optional |
| Notifications | To alert staff to critical results, new orders, admissions and task assignments. | Optional |
| Biometric / device screen lock | To unlock the app. Biometric matching happens on the device — we never receive or store your fingerprint or face data. | Optional |
| Network access | Required to connect to the hospital servers. The application does not function offline. | Required |
| Permission | Why we ask for it | Status |
|---|---|---|
| Location | Only when you tap to mark attendance, and only if geo-verified attendance is enabled for your role — to confirm the punch was made at an authorised work location. Location is not collected in the background and is not tracked between punches. | Optional |
| Camera | To take a selfie for verified attendance and to photograph documents you submit to HR. | Optional |
| Photos and files | To upload documents and proofs, and to save payslips and tax statements to your device. | Optional |
| Notifications | To send approval requests, roster changes, payroll and HR announcements. | Optional |
| Biometric / device screen lock | To unlock the app. Biometric matching happens on the device — we never receive or store your fingerprint or face data. | Optional |
| Network access | Required to sync with the HR servers. | Required |
| Permission | Why we ask for it | Status |
|---|---|---|
| Camera | To scan item, batch and shipment barcodes or QR codes, and to photograph delivered goods, damages or supporting documents. | Optional |
| Photos and files | To attach invoices, challans and certificates of analysis, and to save purchase and stock reports to your device. | Optional |
| Notifications | To alert users to approval requests, low or expiring stock and delivery updates. | Optional |
| Location | Only when a goods receipt or delivery is confirmed in the app, and only where site verification is enabled — to record the store or site at which the receipt was made. It is not collected in the background. | Optional |
| Network access | Required to sync with the supply-chain servers. | Required |
Across every application we publish, location, camera and microphone are never accessed in the background. They are used only in the foreground, at the moment you use the feature that needs them.
We share personal information only in these situations:
Our applications use a small number of third-party services. They receive only the data they need to perform their function, and none of them are permitted to use it for their own purposes.
| Service | What it is used for |
|---|---|
| Google Firebase (Cloud Messaging & Crashlytics) | Delivering push notifications and receiving anonymised crash diagnostics. |
| Google Play Services / Apple Push Notification service | Platform services required for app distribution, integrity checks and notification delivery. |
| SMS and e-mail gateway providers | Sending one-time passwords, appointment and transaction alerts on our instruction. |
| Cloud hosting and backup providers | Hosting the application servers, databases and encrypted backups within India. |
We apply reasonable security practices and procedures appropriate to the sensitivity of the information, including:
No system can be guaranteed completely secure. If a personal data breach occurs, we will notify the Data Protection Board of India, CERT-In and the affected individuals as required by law, and take prompt steps to contain and remedy it.
We keep personal information only for as long as it is needed for the purposes described in this policy, or for the longer period required by law.
Medical records are retained for the periods required of a clinical establishment in India — as a minimum, three years from the date of the last entry under the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002, and longer where a medico-legal case, insurance claim, litigation or statutory audit requires it. Staff account and audit-trail records are retained for the duration of the user's authorisation and for the statutory audit period thereafter.
Employee records are retained for the duration of employment and thereafter for the periods prescribed by labour, provident fund, tax and company law — payroll, tax and statutory records are generally retained for up to eight years. Attendance photographs and punch locations are retained only for the attendance and payroll cycle they support, and for any period needed to resolve a dispute or complete a statutory audit.
Procurement, inventory and vendor records are retained for the periods required under the Companies Act, 2013, the Goods and Services Tax law, and the Drugs and Cosmetics Act and rules — generally eight years from the end of the relevant financial year, and longer where an audit, dispute or investigation requires it.
When a retention period ends, we delete the information or irreversibly anonymise it. Aggregated and anonymised statistics, which cannot identify anyone, may be kept for planning, quality and research purposes.
You can ask us to delete your account and the personal data associated with it, in any of our applications. Write to infolbn@mediciti.co.in from your registered e-mail address, or call +91 8371030303, with:
We verify every request before acting on it. We acknowledge requests within 7 working days and complete them within 30 days. Once the request is completed, your account is deactivated and the personal data linked to it is deleted, except for records we are legally required to retain — medical records, payroll and tax records, and procurement and statutory books of account, as described in section 10. Those records are locked down and kept only for the remaining statutory period, then deleted.
Deleting the app from your device does not delete your account or your data. To have the data removed, send us the request described above.
Subject to verification of your identity and to the exceptions the law allows, you have the right to:
To exercise any of these rights, contact us using the details in section 17. We do not charge a fee, and we will not treat you differently for making a request.
Our applications are intended for use by adults acting in a professional capacity, and are not directed at children.
Where a child receives treatment at our hospital, the child's health information is entered into the hospital record by our staff on the basis of consent given by a parent or lawful guardian, in line with the Digital Personal Data Protection Act, 2023. We do not use children's data for tracking, behavioural monitoring or advertising.
Personal data collected through our applications is stored on servers located in India. We do not routinely transfer personal data outside India. Where a service provider processes limited technical data outside India — for example crash diagnostics or push-notification delivery — the transfer is made only to countries not restricted by the Central Government, under contractual safeguards requiring a comparable level of protection.
When you visit https://mediciti.co.in we collect the information you submit through our appointment, contact and newsletter forms — your name, phone number, e-mail and the message or preference you provide — so that we can respond to you.
The website also uses cookies and similar technologies, including Google Analytics and Google Tag Manager, to understand how visitors use the site and to improve it. These record information such as pages viewed, time on page, approximate region and referring source. You can block or delete cookies in your browser settings; parts of the site may not work as intended if you do. We do not place advertising cookies that build a profile of you across other websites.
Our website may link to external sites. We are not responsible for their content or their privacy practices, and we encourage you to read their policies.
We may update this policy as our applications, services or legal obligations change. The current version is always published at https://mediciti.co.in/privacy-policy, with the effective date shown at the top — this address stays the same, so it remains valid for every application, including ones we launch later. Where a change materially affects how we use your information, we will give notice inside the affected application, by e-mail or by SMS before it takes effect and, where the law requires it, ask for your consent again.
If you have a question about this policy, want to exercise a right, or wish to complain about how we have handled your personal data, please contact our Grievance Officer. We acknowledge every grievance within 7 working days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.