Germanten Hospitals (“we,” “us,” “our”) values your privacy and is committed to protecting your personal information.
This Privacy Policy describes how we collect, use, store, transfer, disclose, and secure your personal and health-related data when you use our website
(www.germantenhospitals.com), our hospital services, telemedicine, diagnostics, or other interactions (collectively, our “Services”).
This policy is intended to comply with applicable Indian laws and also addresses obligations under the EU General Data Protection Regulation (GDPR) for individuals in the European Economic Area (EEA).
If you are located in the EU/EEA, additional rights and protections may apply.
This policy applies to data collected online, offline, and via third parties in relation to our Services.
For users in India, we aim to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) once it becomes operational.
For users in the EU/EEA or if we process their data, we comply with GDPR principles and obligations.
Where there is a conflict between local law and GDPR, we will apply the stricter requirement that protects your rights.
Term | Meaning |
---|---|
Personal Data / Personal Information | Any information relating to an identified or identifiable individual (e.g. name, contact, identifiers) |
Sensitive / Special Category Data | Health data, biometric data, medical history, test results, etc. (under GDPR classification) |
Processing | Collection, storage, use, disclosure, alteration, deletion, or other operations on personal data |
Data Subject / You | The individual whose personal data is processed (i.e. patient, website visitor, user) |
Data Controller / Data Fiduciary | We decide how and why your data is processed |
Data Processor | Third parties we engage to process data on our behalf |
Purpose | Legal Basis (India / DPDP) | Legal Basis (GDPR / EU) |
---|---|---|
Providing medical, diagnostic, telemedicine services | Consent, medical necessity | Consent, necessity for health care / vital interests |
Managing appointments, reminders, follow-ups | Consent, contractual, legitimate interest | Contract performance, legitimate interest |
Billing, claims, payment processing | Consent, compliance with laws | Legitimate interest, legal obligation |
Communication (e.g. newsletters, promotions) | Consent (opt-in) | Consent (explicit) |
Internal operations, quality control, training | Consent or legitimate interest | Legitimate interest |
Research, aggregated statistics (non-identifiable) | Use with anonymisation or consent | Legitimate interest, research exceptions |
Compliance, legal obligations, audits | Legal compliance | Legal obligation |
You have the right to withdraw consent at any time (subject to legal or medical constraints).
We require third parties to safeguard the confidentiality, security, and appropriate use of your data.
If your data is transferred outside India (for example, for processing, backup, or analytics), we will take appropriate safeguards in line with applicable laws (e.g. standard contractual clauses, binding corporate rules).
Under GDPR, cross-border transfer is permitted only with adequate safeguards or in jurisdictions approved by the EU.
Under India’s DPDP/DPDPA rules (once in effect), cross-border transfers will be allowed only under conditions defined by India’s government / subordinate rules.
We retain your data only as long as needed for the purposes listed (medical care, billing, compliance, legal claims). After that, we securely erase or anonymize it. If retention is required by law, we will retain it for the statutory period.
We maintain reasonable appropriate physical, technical and organizational measures to prevent unauthorized access, alteration, disclosure, or destruction of your data. Access is limited to authorized personnel.
However, no system is perfectly secure. If a data breach occurs, we will evaluate and respond promptly, notifying affected individuals and regulators where required by law (under GDPR or local law).
Depending on your jurisdiction:
To exercise your rights, contact us (details in section 13). We may require identity verification before fulfilling requests.
We do not knowingly seek data from children under 18. If we learn that we collected such data without parental or guardian consent, we will delete it. For users in EU, parental consent will be required where applicable under GDPR rules relating to minors.
You can block or disable cookies through your browser settings, but that may affect the functionality of the website.
We may update this policy over time (for example, when DPDP rules come into force or if we expand services). We will post the revised “Last updated” date and, when changes are material, notify you by email or via the website before they take effect.