Privacy Policy

How we collect, use and protect your personal information — written to comply with India's Digital Personal Data Protection Act, 2023.

Grace Care India ("we", "us") coordinates medical treatment in India for patients travelling from abroad. To do that we must handle some of the most sensitive information a person can share — medical reports, passport details, travel plans. This policy explains exactly what we collect, why, how long we keep it, and what you can ask us to do about it. It applies to this website and to every enquiry, appointment request, quote request and patient case we manage.

1. What we collect

  • Identity and contact details — your name, email, phone/WhatsApp number, country and city.
  • Medical information — the treatment or condition you ask about, and any reports, scans or discharge summaries you choose to upload.
  • Travel and identity documents — passport details and visa information, only when we begin arranging your visa invitation letter and flights.
  • Portal account data — your email and password (stored only as a one-way encrypted hash), profile details you add, and the messages, documents and timeline entries inside your case.
  • Technical data — pages visited, device type, browser language and referring site. We only record this for analytics after you accept analytics cookies, and you can withdraw that at any time from the cookie settings link in the footer.

2. Why we use it, and on what basis

Under the DPDPA we process your personal data only for the purposes you would reasonably expect, and we tell you what those are before or at the time we collect it:

  • Replying to your enquiry, preparing cost estimates and booking consultations — on the basis of your consent, given when you submit a form.
  • Arranging visas, flights, accommodation, hospital admission and follow-up care — on the basis of consent and, once your case is open, the performance of the service you have asked us for.
  • Sharing your medical reports with the doctors and hospitals reviewing your case — only with hospitals you have approved, and only the reports relevant to your treatment.
  • Meeting legal duties that apply to us in India, such as tax and record-keeping obligations.

We never sell your data, never share it with advertisers, and never use your medical information for marketing.

3. Who can see your data

Access is deliberately narrow. Only the coordinators working on your case, and the doctors and hospital international-patient teams you have asked us to approach, can see your medical information. Our website and database enforce this with role-based access controls, so administrative access is limited to verified staff accounts. We use service providers for email delivery, hosting and analytics; they process data only on our instructions under written contracts. If a service is ever performed outside India, we make sure the transfer meets the requirements Indian law places on us.

4. How long we keep it

Enquiries that never become cases are deleted after 24 months. Medical records and case documents are kept for as long as your case is active and for a reasonable period afterwards, so your treating doctors at home can reach us with questions — after that they are securely deleted. Cookie and analytics data is deleted or anonymised within 14 months. You can ask us to delete anything earlier; see your rights below.

5. Your rights under the DPDPA

You can, at any time and free of charge:

  • Ask for a summary of the personal data we hold about you and how we process it.
  • Ask us to correct inaccurate or incomplete data — including medical details.
  • Ask us to erase your data, unless a law requires us to keep it a little longer.
  • Withdraw your consent for any processing, including analytics cookies. We will stop, except where we still need the data to finish something you already agreed to (for example, completing a visa application you asked us to file).
  • Nominate another person to exercise these rights if you are unable to do so yourself.

We respond to every request within 30 days. Write to us using the details below.

6. Children's data

If a patient is under 18, we collect their information only through a parent or guardian, and we verify the guardian's identity and consent before processing. We never run behavioural advertising or tracking aimed at children, and we do not carry out processing likely to harm a child, as the DPDPA prohibits.

7. How we protect your data

Medical reports and case documents are stored in encrypted cloud storage with access limited to your care team. Data travels over encrypted connections, staff accounts use strong authentication, and access to the database is logged. No system is perfect, but we treat a medical report with the same care a hospital would.

8. Cookies

Strictly necessary cookies keep the site working and remember your language. Analytics cookies are set only after you accept them, and marketing cookies only if you allow those too. You can change your mind at any time via the "Manage cookie preferences" link in the footer. For the full picture of how we handle consent records, see our Laws & regulations page under the DPDPA section.

9. Grievance Officer

Questions, requests or complaints about your data go straight to a person, not a form:

Grievance Officer — Grace Care India

Email: help@gracecareindia.com
Phone / WhatsApp: +91 99997 87182
Address: JP Klassic, KNG-2, Sector 134, Noida, Uttar Pradesh 201304, India

If you are not satisfied with our response, you can escalate to the Data Protection Board of India once it is notified under the Act.

10. Changes to this policy

If this policy changes in a way that affects you, we will tell you — by email if we have it, and with a notice on the site — before the change takes effect. The date below always reflects the current version.

Last updated: 20 September 2026