Legal

Privacy policy

Last updated: 5 September 2026 · Version 1.0

1. Who we are

Garv Health Systems Private Limited, registered at #1224, Sector 42-B, Chandigarh 160036, India, CIN U62099CH2026PTC047166. In this policy "we", "us" and "Garv" mean that company. For the personal data described in section 3 we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (the Act).

2. Two different roles

This policy covers personal data we handle as a Data Fiduciary: visitors to this website and people who contact us. Sections 3 to 10 describe that.

It does not cover patient data held in our software when it is deployed at a hospital. There the hospital is the Data Fiduciary and we act as a Data Processor under a written agreement, handling patient data only on the hospital's instructions and for the purposes it sets. Patients should refer to their hospital's own privacy notice.

Section 11 describes how the software protects patient data in that arrangement, because customers reasonably want that stated in public.

3. Personal data we collect

Information you give us. When you use the contact form or email us: your name, work email address, hospital or organisation, and the content of your message.

Technical information. Our hosting, network and font providers receive your IP address, browser user agent and request time in the ordinary course of serving the page. We do not combine this with anything else or use it to build a profile.

We run no analytics, no advertising tags, no tracking pixels and no third-party embeds on this site.

4. Please do not send us patient data

The contact form is an ordinary business enquiry channel and is not a secure clinical system. Do not send patient identifiable information, clinical records, screenshots containing patient details, or anything you are not entitled to share. If you send us patient data unprompted, we will delete it and tell you we have done so.

5. Why we process it, and on what basis

We process the information you give us to reply to your enquiry, to arrange and hold conversations about our software, and to keep a record of that correspondence. We rely on the consent you give when you submit the form, and on the certain legitimate uses permitted by the Act where you have approached us voluntarily for that purpose.

Technical log data is processed to keep the site secure and available. We do not use any of it for advertising, and we do not sell personal data.

6. Who else processes it

We share personal data only with providers who process it on our behalf, under contract and on our instructions:

· Cloudflare, Inc. hosts and serves this website, provides our domain name service and edge network, runs the function that receives contact form submissions, and delivers each submission to us as an email.

· Microsoft Corporation hosts the mailbox that receives your enquiry, and our correspondence with you thereafter, on Microsoft 365.

· Google Fonts (Google LLC) serves the two typefaces this site uses. Your browser requests those files directly, which means Google receives your IP address when you load a page.

We may also disclose personal data where we are required to by law. We will not disclose it to anyone else without telling you.

7. Transfers outside India

The providers named in section 6 operate infrastructure outside India, so enquiry data and technical log data may be processed abroad. Section 16 of the Act permits such transfers except to countries the Central Government restricts by notification. We do not transfer personal data to any country currently so restricted, and we will change this arrangement if that list changes.

8. How long we keep it

We keep enquiry correspondence for twenty-four months from our last exchange with you, then erase it, unless we are required to keep it longer for a legal or contractual purpose, or the correspondence has become part of a customer relationship governed by its own agreement. When the purpose is served and no legal requirement applies, we erase the data and ask our processors to do the same.

9. Your rights

As a Data Principal under the Act you may ask us for a summary of the personal data we hold about you and how we process it; ask us to correct, complete, update or erase it; withdraw your consent at any time; nominate another person to exercise your rights in the event of your death or incapacity; and raise a grievance with us.

Write to the contact in section 13. We will acknowledge promptly and respond within thirty days, and sooner where the Act requires it. Withdrawing consent does not affect processing already carried out.

If you are not satisfied with our response you may complain to the Data Protection Board of India.

10. Security and breach notification

This site is served over HTTPS and contact form submissions are encrypted in transit. Access to enquiry correspondence is limited to the people who need it to reply to you. We do not hold enquiry data in any system that is publicly reachable.

If a personal data breach occurs, we will notify the Data Protection Board of India and each affected Data Principal in the form and within the time the Act requires.

11. Patient data in our software

Where a hospital deploys our software, that hospital decides what is recorded, who may see it and how long it is kept. We process it only as its Processor. Depending on the organisation, its users, its patients and where it is hosted, a deployment may need to satisfy HIPAA, the EU or UK General Data Protection Regulation, the Act, or other regional requirements. The software's privacy request workflow tags each request with the framework that applies to it.

Within the software, health information is handled with role-based access controls, audit logging, encryption controls, session safeguards and administrative review workflows. Patient identifiers are encrypted in the database. The audit trail is append-only and enforced as such by the database itself. Retention periods for patient records, audit events and privacy requests are configured by the organisation.

Where the hospital requires it, the software runs entirely inside the hospital's own infrastructure and patient data does not reach us at all.

Patients or staff wishing to exercise rights over records held in a hospital's deployment should approach that hospital, which holds the relationship and the records. We will support it in responding.

12. Cookies and browser storage

This site sets no cookies at all. It stores one value in your browser's local storage, under the key garv-theme, to remember whether you chose the light or dark appearance. That value stays on your device, is never sent to us, and you can clear it through your browser at any time.

13. Contact and grievance redressal

For questions, requests and grievances about personal data, write to our Grievance Officer: Vishal Gupta, Director, info@garvhealth.com, at the registered address in section 1.

General enquiries that are not about personal data can go to info@garvhealth.com.

14. Children

This website is intended for healthcare professionals and business contacts. We do not knowingly collect personal data from children through it. Clinical records about children held in a hospital's deployment are the hospital's responsibility as Data Fiduciary, under section 9 of the Act.

15. Changes to this policy

If we change this policy we will update the date at the top and, where the change is significant, tell the people whose data we hold. Earlier versions are available on request.