Your Data Stays in India, Always
OneMedAI is built with a privacy-first approach to healthcare data. Your clinical, diagnostic, and personal health information is stored and processed exclusively within India, in compliance with Indian data protection laws.
1. Your Rights Under Indian Law
As a user of OneMedAI, you have the following rights under applicable Indian data protection laws, including the Digital Personal Data Protection Act (DPDPA) 2023 and the Information Technology Act, 2000:
Right to Access & Portability
Request a copy of your personal and medical data in a structured, machine-readable format at any time.
Right to Rectification
Request correction of any inaccurate or incomplete personal or medical data we hold about you.
Right to Erasure (Right to be Forgotten)
Request deletion of your personal data when it is no longer necessary for the purpose it was collected.
Right to Restrict Processing
Request restriction of processing of your personal data in certain circumstances under applicable law.
Right to Object
Object to the processing of your personal data for direct marketing or legitimate interest purposes.
Right to Lodge a Complaint
Lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
India's Data Protection Bill
We comply with India's Digital Personal Data Protection Act (DPDPA) 2023 and all applicable data protection regulations.
India's IT Act & IT Rules
Full compliance with India's Information Technology Act, 2000 and the IT (Reasonable Security Practices) Rules, 2011.
📌 How to Exercise Your Rights: To exercise any of these rights, please contact our Data Protection Officer at privacy@onemedai.com. We will respond to your request within 30 days as required by applicable law.
2. Data Sharing Within India
We may share your data with the following categories of recipients, all located within India:
Safeguards for Third-Party Data Transfers
Legal Basis for Data Sharing Under Indian Law
International Transfer Compliance for Global Users
📌 Important: OneMedAI does not sell, rent, or trade your personal or medical data to any third parties for marketing or advertising purposes under any circumstances.
3. Data Retention Policy
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Medical Records / Reports | As per applicable medical record retention laws | Legal Obligation |
| Patient Records | 7 years from last interaction | Regulatory Compliance |
| Account Data | Duration of account + 30 days | Contractual Necessity |
| Usage Analytics | 24 months | Legitimate Interest |
| Audit Logs | 3 years | Legal / Security |
| Marketing Data | Until consent is withdrawn | Consent |
| Security & Access Logs | As required under ISO 27001 / SOC 2 | Security & Compliance |
⚠️ IMPORTANT: If you are a healthcare provider or institution, your data retention obligations may differ based on applicable medical record retention laws in India (e.g., MCI Guidelines, Clinical Establishments Act). Please consult your legal counsel for specific guidance.
4. AI-Specific Privacy Practices
OneMedAI uses artificial intelligence to process and analyze medical data. We are committed to transparency and ethical AI practices:
a) Training Data & Model Development Safeguards
b) Automated Decision-Making & Human Oversight
c) Algorithm Transparency & Accountability
📌 Breach Notification Policy: In the event of a data breach involving personal or medical data, OneMedAI will notify affected users and relevant authorities within 72 hours as required under DPDPA 2023 and applicable Indian regulations.
5. Children's Privacy & Pediatric Data
OneMedAI takes special care when processing data related to minors (under 18 years of age):
6. Cookies & Tracking Technologies
OneMedAI uses cookies and similar technologies to enhance your experience:
Essential Cookies
Required for platform functionality, authentication, and security. These cannot be disabled.
Functional Cookies
Used to remember your preferences, language settings, and customized interface options.
Analytics Cookies
Help us understand how users interact with our platform to improve services. All analytics data is anonymized.
You can manage cookie preferences through your browser settings or our cookie consent banner.
7. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors:
8. Contact Information
For any privacy-related questions, concerns, or to exercise your data protection rights, please contact us: