Privacy Policy
1. INTRODUCTION
Asar Healthtech & Innovation Lab Private Limited, operating under the brand “ASAR Care” (“Asar”, “ASAR Care”, “we”, “us”, or “our”), respects your privacy and is committed to protecting the personal data of everyone who visits www.asar.care and any related websites, mobile applications, WhatsApp channels, or offline touchpoints through which we provide our services (together, the “Services”).
This Privacy Policy explains what personal data we collect, why we collect it, how we use, store, share, and protect it, and the rights available to you as a “Data Principal” under the Digital Personal Data Protection Act, 2023. This Privacy Policy should be read together with our Terms of Use and Cookie Policy, which together with this document form the “Agreement” governing your use of the Services.
By accessing or using the Services, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Services. If you are using the Services on behalf of another individual (such as a family member you are coordinating care for) or on behalf of an entity, you confirm that you are authorised to accept this Privacy Policy on their behalf and to provide their personal data to us for that purpose.
2. WHO WE ARE β THE DATA FIDUCIARY
For the purposes of the DPDP Act, the “Data Fiduciary” in respect of personal data collected through the Services is:
Asar Healthtech & Innovation Lab Private Limited
CIN: U52291HR2025PTC136186
Registered Office: SCO-47, M3M 113 Market, Dwarka Expy, Sector 113, Bajghera, Gurugram, Haryana 122017, India
Principal place of business: Gurugram, Haryana, India
Email: privacy@asar.care
Phone: +91 97188 62727
3. SCOPE AND APPLICABILITY
This Policy applies to:
- a. Personal data of individuals located in India, and personal data of individuals located outside India where such data is processed in connection with offering our Services to them (in line with Section 3 of the DPDP Act);
- b. Personal data collected online through the Site, mobile applications, chat/WhatsApp, and forms, as well as personal data collected offline (for example, over phone calls or during in-person coordination) that is subsequently digitised or stored digitally;
- c. Both personal data you provide directly, and personal data we receive about you from Healthcare Providers, hospitals, insurers, payment partners, and other third parties in connection with your care coordination.
This Policy does not govern the privacy practices of independent Healthcare Providers, hospitals, clinics, insurers, airlines, hotels, visa facilitators, or other third parties you may interact with through or alongside our Services. Their own privacy policies apply to information they collect directly from you.
3.1 How this Policy is organised β regional applicability
Sections 1 to 23 below set out our general privacy practices, framed with reference to Indian law (in particular the DPDP Act), and apply to all users of the Services. If you are located in the European Economic Area, the United Kingdom, or Switzerland, Section 24 sets out additional rights and information that apply to you under the GDPR, UK GDPR, and Swiss FADP, and prevails over Sections 1β23 to the extent of any conflict. If you are located in the United States, Section 25 sets out additional rights and information to you under applicable U.S. federal and state law. Where this Policy uses DPDP Act terminology, the following broadly corresponds: “Data Fiduciary” = “Controller” (GDPR) / “Business” (U.S. state law); “Data Principal” = “Data Subject” (GDPR) / “Consumer” (U.S. state law); “Processing” has an equivalent meaning across all three frameworks.
4. KEY DEFINITIONS
“Personal Data” means any data about an individual who is identifiable by or in relation to such data.
“Data Principal” means the individual to whom the personal data relates, and includes, where the individual is a child, the parent or lawful guardian of such child, and where the individual is a person with disability, their lawful guardian.
“Data Fiduciary” means Asar, who alone or with others determines the purpose and means of processing personal data.
“Data Processor” means any entity that processes personal data on our behalf, such as our IT hosting, analytics, or payment partners.
“Processing” means any operation performed on personal data, including collection, storage, use, sharing, and erasure.
“Consent Manager” means a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform, where such a mechanism is used by us.
5. PERSONAL DATA WE COLLECT
5.1 Data you provide directly
- Identity and contact data: name, email address, phone number, country of residence, date of birth, gender;
- Health-related data you voluntarily share: symptoms, medical history, prior diagnoses, reports, scans, prescriptions, and details of Healthcare Providers you have consulted, shared with us so we can coordinate an appropriate second opinion or appointment;
- Insurance data: insurer name, policy/plan details, member ID, where relevant to your treatment coordination;
- Travel-related data: passport details, visa status, travel dates, accompanying persons, where you seek assistance with logistics;
- Payment and billing data: billing name and address, transaction references (see clause 5.3 β we do not store full card numbers or CVV);
- Communications: content of enquiries, emails, chat messages, call recordings (where notified), feedback, and reviews you submit.
5.2 Data collected automatically
When you use the Site or app, we and our service providers may automatically collect: IP address, device and browser type, operating system, referring page, pages viewed, approximate geolocation (derived from IP or, where permitted, device GPS), and similar usage data, generally through cookies and similar technologies described in our Cookie Policy.
5.3 Payment information
Card and payment details are collected and processed by our third-party payment gateway partners under their own PCI-DSS-compliant systems. We do not store full card numbers or CVV. We retain limited transaction metadata (amount, currency, status, invoice references) for accounting, tax, and dispute-resolution purposes.
5.4 Data from third parties
We may receive personal data about you from Healthcare Providers, hospitals, insurers, referring agents, or, where you choose to log in via a third-party service, from that service (subject to your settings with that service).
6. HOW WE COLLECT DATA
We collect personal data when you: fill in an enquiry, appointment, or opinion-request form; create an account; message us via chat, email, phone, or WhatsApp; upload medical records or reports; interact with our marketing or referral partners; or browse the Site, through cookies and similar tools (see our Cookie Policy).
7. LAWFUL GROUNDS FOR PROCESSING
Under the DPDP Act, we process your personal data only where we have a valid legal ground, namely:
- a. Consent β freely given, specific, informed, unconditional, and unambiguous consent, given through clear affirmative action, for a specified purpose, which you may withdraw at any time as easily as you gave it (without affecting the lawfulness of processing carried out before withdrawal); or
- b. Legitimate Uses recognised under Section 7 of the DPDP Act, including (without limitation): where you have voluntarily provided personal data to us for a specified purpose and have not indicated that you do not consent to its use; for compliance with a judgment, decree, or order under Indian law; for responding to a medical emergency involving a threat to your life or immediate health; or as otherwise permitted by applicable law.
Where processing relates to health information for care-coordination purposes, we rely primarily on your explicit, itemised consent.
8. NOTICE AT THE TIME OF COLLECTION
Wherever we seek your consent, we will (in plain language, in English or another language you select where offered) tell you: what personal data is being collected; the specific purpose(s) of processing; how you can exercise your rights under clause 16; and how you can lodge a complaint with the Data Protection Board of India. This notice will be given independently of, or bundled clearly with, this Privacy Policy at the relevant collection point (for example, on an enquiry form).
9. HOW WE USE YOUR PERSONAL DATA
We use personal data to:
- i. Respond to your enquiry and coordinate second opinions, appointments, and treatment logistics with Healthcare Providers;
- ii. Verify your identity and eligibility for insurance-linked coordination;
- iii. Communicate with you, including appointment reminders and service updates;
- iv. Process payments and maintain accounting, invoicing, and tax records;
- v. Improve and personalise the Services, and develop new features;
- vi. Send you service-related and, where you have opted in, marketing communications;
- vii. Detect, prevent, and investigate fraud, abuse, or security incidents;
- viii. Comply with legal obligations, respond to lawful requests from authorities, and enforce our Terms of Use;
- ix. Resolve disputes and defend legal claims.
We do not use your health information for behavioural advertising, and we do not sell personal data.
10. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar technologies to operate, secure, and improve the Site, and, where you consent, for analytics and advertising purposes. Full details, including the categories of cookies used and how to manage your preferences, are set out in our separate Cookie Policy, which forms part of this Agreement.
11. HOW WE SHARE YOUR PERSONAL DATA
We may share personal data with:
- a. Healthcare Providers and hospitals you choose to engage with, to enable appointment booking and continuity of care;
- b. Insurers you identify to us, to verify eligibility and coverage;
- c. Data Processors who support our operations, such as cloud hosting, customer support tooling, analytics, payment gateways, and communications platforms, under written contracts requiring them to protect your data and process it only on our instructions;
- d. Professional advisors (legal, accounting, audit) as necessary;
- e. Government authorities, regulators, or courts, where required by law, regulation, or valid legal process;
- f. A successor entity in the event of a merger, acquisition, or sale of business assets, subject to equivalent protections.
We do not share your health or medical information with advertising or marketing partners. Content you voluntarily post publicly (such as reviews) is, by its nature, visible to other visitors and is not private.
12. CROSS-BORDER TRANSFER OF PERSONAL DATA
We may store and process personal data on servers located in India and, where necessary to deliver the Services (for example, cloud infrastructure or communication tools used by our Data Processors), in other countries. Under Section 16 of the DPDP Act, such transfers are permitted except to countries restricted by the Central Government by notification. We contractually require our processors to apply appropriate safeguards consistent with applicable law wherever your data is processed. If you are located in the EEA, UK, or Switzerland, transfers of your personal data out of those regions (including to India) are additionally subject to Section 24.6 below.
13. DATA RETENTION AND ERASURE
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by applicable law (including tax, accounting, and medical-record-adjacent obligations), whichever is longer. As a general guide:
- Enquiry and care-coordination records: retained for the duration of active coordination and a limited period thereafter for continuity of care and dispute resolution, unless you request earlier erasure and no legal ground requires retention;
- Account data: retained while your account is active and for a limited period after closure;
- Payment and billing records: retained as required under applicable tax and accounting law;
- Marketing consent records: retained to demonstrate compliance with consent and opt-out obligations;
- Security and access logs: retained for a defined period for security monitoring.
Where you withdraw consent or your personal data is no longer necessary for the purpose it was collected, we will erase it (or anonymise it), unless retention is required by law, in accordance with Section 8(7) of the DPDP Act.
14. DATA SECURITY
We implement reasonable security safeguards appropriate to the sensitivity of the personal data we hold, including: encryption of data in transit (TLS/HTTPS) and, for sensitive data, at rest; role-based access controls; multi-factor authentication for administrative access; audit logging; regular security reviews and patching; and vendor security assessments for processors handling personal data on our behalf.
No system is completely secure, and we cannot guarantee absolute security of information transmitted to us.
15. PERSONAL DATA BREACH NOTIFICATION
In the event of a personal data breach, we will, in accordance with Section 8(6) of the DPDP Act, notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Rules, and take reasonable steps to mitigate the impact of the breach.
16. YOUR RIGHTS AS A DATA PRINCIPAL
Subject to the DPDP Act and its exemptions, you have the right to:
- a. Obtain a summary of the personal data we hold about you and the processing activities undertaken;
- b. Request correction, completion, and updating of your personal data;
- c. Request erasure of personal data that is no longer necessary for the purpose for which it was processed, subject to legal retention requirements;
- d. Withdraw consent at any time, as easily as it was given;
- e. Nominate another individual to exercise your rights on your behalf in the event of death or incapacity;
- f. Have readily available means to register a grievance with us, and, if unresolved, to file a complaint with the Data Protection Board of India.
To exercise any of these rights, contact us at privacy@asar.care. We may need to verify your identity before acting on a request, and we will respond within the timeframe required by applicable law.
17. GRIEVANCE OFFICER
In accordance with the DPDP Act and the Information Technology Act, 2000 (and rules made thereunder), we have appointed a Grievance Officer to address your questions and complaints regarding this Privacy Policy and our processing of your personal data:
Grievance Officer: [Insert Name]
Email: privacy@asar.care
Address: Asar Healthtech & Innovation Lab Private Limited, SCO-47, M3M 113 Market, Dwarka Expy, Sector 113, Bajghera, Gurugram, Haryana 122017, India
We will acknowledge grievances promptly and aim to resolve them within the timelines prescribed under applicable law. If you remain unsatisfied, you may approach the Data Protection Board of India.
18. CHILDREN’S AND MINORS’ PERSONAL DATA
In accordance with Section 9 of the DPDP Act, we do not knowingly process the personal data of a child (an individual under 18 years of age) without verifiable consent of a parent or lawful guardian. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you are a parent or guardian coordinating care for a minor, you may provide the minor’s health information to us, and by doing so you confirm you are lawfully authorised to consent on their behalf.
19. THIRD-PARTY LINKS AND SERVICES
The Site may contain links to third-party websites, including those of Healthcare Providers, hospitals, and travel partners. This Privacy Policy does not apply to those third-party sites, and we encourage you to review their privacy policies independently.
20. MARKETING COMMUNICATIONS
Where you have opted in, we may send you marketing communications about our Services. You may withdraw consent or unsubscribe at any time via the link in such communications or by writing to privacy@asar.care. We will continue to send you essential service and transactional communications relevant to any active coordination.
21. HEALTHCARE PROVIDERS AND MEDICAL INFORMATION
We share limited personal data with a Healthcare Provider you choose to engage with, to enable appointment booking. That Healthcare Provider will independently obtain your consent for any further collection, storage, or use of your medical history and health records as part of your care. Asar is not responsible for the data-handling practices of independent Healthcare Providers once your information is shared with them at your instance, and does not control or have visibility into records they subsequently create or hold.
22. APPLICABLE LAWS
This Policy is framed with reference to, and we process personal data in accordance with, applicable Indian law including: the Digital Personal Data Protection Act, 2023 and rules made thereunder; the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent still applicable); the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, where relevant to user-generated content on the Site; the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020; and the Indian Contract Act, 1872. Where you access the Services from outside India, you remain responsible for your own compliance with any additional local data protection law applicable to you, and, where such law grants you additional rights, we will consider requests made under it in good faith even though this Policy is framed under Indian law.
23. GOVERNING LAW AND DISPUTE RESOLUTION
This Privacy Policy is governed by the laws of India. Any dispute, controversy, or claim arising out of or relating to this Privacy Policy, including its interpretation, breach, termination, or validity, shall be referred to and finally resolved by arbitration administered by the Delhi International Arbitration Centre (“DIAC”) in accordance with the DIAC (Arbitration) Rules in force at the time of commencement of arbitration, which rules are deemed incorporated by reference. The seat and venue of arbitration shall be New Delhi, India. The tribunal shall consist of a sole arbitrator appointed in accordance with the DIAC Rules. The language of arbitration shall be English. The courts at New Delhi shall have exclusive jurisdiction over any matters not subject to arbitration (such as interim relief). Nothing in this clause prevents you from approaching the Data Protection Board of India in respect of matters within its jurisdiction under the DPDP Act.
23.1 Regional carve-out
Nothing in this Section 23 limits your right, if you are located in the EEA, UK, Switzerland, or the United States, to lodge a complaint with your competent data protection supervisory authority or state Attorney General/regulator (see Sections 24.7 and 25 below), or deprives you of any non-waivable statutory protection of the law of your habitual residence. Where the mandatory consumer-protection law of your country or state of habitual residence would otherwise apply notwithstanding this choice-of-law and forum clause (for example, under Regulation (EC) No 593/2008 (“Rome I”) or equivalent local law), this clause does not deprive you of the protection of those mandatory provisions.
24. ADDITIONAL TERMS FOR USERS IN THE EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND
24.1 Application
This Section 24 applies where you are located in the EEA, UK, or Switzerland, and supplements the general provisions in Sections 1β23 in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection (“FADP”), as applicable to you.
24.2 Controller
For GDPR purposes, Asar Healthtech & Innovation Lab Private Limited acts as the “Controller” of your personal data (equivalent to “Data Fiduciary” in Section 2).
24.3 EU and UK Representatives
As we are established outside the EEA and UK, we have appointed representatives in accordance with Article 27 GDPR and Article 27 UK GDPR to act as your point of contact on data-protection matters:
EU Representative: [Insert name, address, and email of appointed EU Article 27 representative]
UK Representative: [Insert name, address, and email of appointed UK Article 27 representative]
[Drafting note: appointing these representatives is a distinct compliance step from drafting this Policy β you will need to engage a representative service or an EU/UK-based entity willing to act in this capacity before this clause can be completed.]
24.4 Legal Bases for Processing
We process your personal data only where we have a valid legal basis under Article 6 GDPR: (a) your consent; (b) performance of a contract with you, or steps taken at your request before entering into one β e.g., coordinating a second opinion or appointment you have requested; (c) compliance with a legal obligation; (d) protection of vital interests, such as responding to a medical emergency; or (e) our legitimate interests (such as securing our systems or preventing fraud), where not overridden by your interests or fundamental rights.
24.5 Special Category (Health) Data
Health data is a “special category” of personal data under Article 9 GDPR. We process your health data on the basis of your explicit, itemised consent (Article 9(2)(a)) β given, for example, through our Patient Informed Consent Form β or, exceptionally, where necessary for the establishment, exercise, or defence of legal claims (Article 9(2)(f)). You may withdraw this consent at any time, as described in Section 16.
24.6 International Transfers
Where we transfer your personal data from the EEA/UK to India or another country not covered by an applicable adequacy decision, we rely on appropriate safeguards β in particular the European Commission’s Standard Contractual Clauses (and, for UK-originating data, the UK International Data Transfer Addendum), together with supplementary technical and organisational measures. A copy of the relevant safeguard is available on request to privacy@asar.care.
24.7 Your GDPR Rights
In addition to the rights in Section 16, you have the right to: data portability (Article 20); object to processing based on our legitimate interests, including related profiling (Article 21); restriction of processing in certain circumstances (Article 18); and not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you, except in limited circumstances permitted under Article 22. Our Asar AI Systems (described in our Patient Informed Consent Form and Terms of Use) are used to assist our human coordination team and do not make final clinical, booking, or eligibility decisions about you without human review; if this changes, we will notify you and put in place the safeguards Article 22 requires. You also have the right to lodge a complaint with a supervisory authority β for EEA residents, the authority of your habitual residence, place of work, or place of the alleged infringement; for UK residents, the Information Commissioner’s Office (ICO); for Swiss residents, the Federal Data Protection and Information Commissioner (FDPIC) β without prejudice to any other administrative or judicial remedy.
24.8 Data Protection Officer
[Confirm whether your processing activities β e.g., large-scale processing of special-category health data β trigger a mandatory DPO appointment under Article 37 GDPR, and insert contact details if so. Even if not mandatory, a named contact here strengthens this section.]
24.9 Retention
Personal data of EEA/UK/Swiss users is retained in line with Section 13 and the data-minimisation principles of Article 5(1)(c)β(e) GDPR.
25. ADDITIONAL TERMS FOR USERS IN THE UNITED STATES
25.1 Application
This Section 25 applies where you are a resident of the United States, and supplements Sections 1β23. Certain rights below are specific to residents of particular states, as noted.
25.2 Sectoral Federal Laws
Asar is a non-clinical care-coordination facilitator. We are not, to our knowledge, a “covered entity” or “business associate” under the Health Insurance Portability and Accountability Act (“HIPAA”), and HIPAA does not, as a general matter, apply to the health information you provide to us directly.
[Confirm this remains accurate to your operating model; if you ever process data on behalf of, or under a data-sharing arrangement with, a HIPAA-covered entity or business associate, this representation and your obligations would change, potentially requiring a Business Associate Agreement.]
Where applicable, we comply with the FTC Health Breach Notification Rule (16 CFR Part 318) regarding breaches of unsecured identifiable health information maintained through any personal-health-record-like feature of the Services. We comply with the Children’s Online Privacy Protection Act (“COPPA”) and do not knowingly collect personal information from children under 13 without verifiable parental consent (see also Section 18).
25.3 State Consumer Health Data Laws
Certain states β including Washington (My Health My Data Act) and Nevada (its consumer health data law) β regulate “consumer health data” collected by any entity, not only HIPAA-covered ones, and California’s Confidentiality of Medical Information Act (CMIA) extends similar protections to health information collected through digital health services. Where these laws apply to you, we will: obtain your affirmative, opt-in consent before collecting or sharing your consumer health data beyond what is strictly necessary to provide the Service you requested; not use geofencing around healthcare facilities to target advertising to you; and provide a way to withdraw consent and request deletion of your consumer health data, in addition to the rights below.
[This is a fast-moving area of state law β confirm current obligations with counsel before publishing, particularly if you expect meaningful Washington or Nevada user volumes.]
25.4 California Residents β CCPA/CPRA
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, “CCPA”), gives you the right to: know the categories and specific pieces of personal information we have collected about you, its sources, our purpose for collecting it, and the categories of third parties to whom it is disclosed (see Sections 5 and 11 for these categories); request deletion, subject to statutory exceptions (e.g., completing a transaction or complying with a legal obligation); request correction of inaccurate information; opt out of the “sale” or “sharing” (as those terms are defined under the CCPA, including for cross-context behavioural advertising) of your personal information β we do not currently sell or share personal information, and if this changes we will provide a “Your Privacy Choices” mechanism and honour opt-out preference signals, including the Global Privacy Control (GPC); limit the use of “Sensitive Personal Information” (which includes health information and precise geolocation) to purposes permitted under Cal. Civ. Code Β§ 1798.121, such as providing the Services you request; data portability; an appeal of any denial of your request; and to designate an authorised agent to submit a request on your behalf β all without discrimination for exercising these rights.
To exercise them, contact privacy@asar.care; we will verify your request and respond within the timeframe required by law (generally 45 days, extendable once by a further 45 days). We have not sold or shared personal information in the preceding 12 months, and have no actual knowledge that we sell or share the personal information of minors under 16.
25.5 Other U.S. State Privacy Rights
If you are a resident of a state with a comprehensive consumer privacy law in effect (currently including, among others, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island β this list changes as new state laws take effect), you generally have the right to: confirm whether we process your personal data and access it; correct inaccuracies; request deletion; obtain a portable copy; opt out of processing for targeted advertising, sale, or profiling in furtherance of decisions with legal or similarly significant effects; and appeal our decision on your request.
Contact privacy@asar.care to exercise these rights; we will respond within the timeframe your state’s law requires and provide an appeal mechanism where required.
25.6 Cookies and Opt-Out Signals
See our Cookie Policy for how we handle browser Do Not Track signals and opt-out preference signals such as the Global Privacy Control.
25.7 Contact for U.S. Rights Requests
Asar Healthtech & Innovation Lab Private Limited, Email: privacy@asar.care, Phone: +91 97188 62727.
[Several state laws expect a toll-free number or an equally accessible method for California residents specifically β insert one here if you maintain it.]
26. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. Material changes will be notified by posting an updated version on this page with a revised “Last Updated” date, and, where required by law, through additional notice. Your continued use of the Services after such changes constitutes acceptance of the updated Policy.
27. CONTACT US
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, contact:
Asar Healthtech & Innovation Lab Private Limited
Email: privacy@asar.care
Phone: +91 97188 62727
Address: SCO-47, M3M 113 Market, Dwarka Expy, Sector 113, Bajghera, Gurugram, Haryana 122017, India