Privacy Policy
Last updated: 14 September 2026
This Privacy Policy explains how Bhadoo Surgical & Wellness Centre (“we”, “us”, “our”) collects, uses, and protects the personal information of visitors to https://bhadoosurgical.com (“the website”) and of users of our mobile applications, Arogyam Health (for patients) and Arogyam Business (for clinic staff) — together, “the apps” (see §12). We are committed to handling your information transparently and in compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made thereunder.
1. Who we are
| Clinic name | Bhadoo Surgical & Wellness Centre |
| Address | NH-4, Near Rehdi Market, Sector 17, Panchkula, Haryana 134109 |
| Lead doctor & Data Fiduciary | Dr Vivek Bhadoo, MBBS, MS (General Surgery), Haryana Medical Council Reg. No. HN 19870 |
| Grievance contact | help@bhadoosurgical.com · +91 90560 75777 |
Under the DPDP Act, the clinic acts as a Data Fiduciary when we collect your personal information through the website and apps.
2. What we collect — and when
The website collects the information you submit through the “Request Callback” form, along with technical and usage information described in §8. The form is not intended for clinical records: please do not submit diagnoses, prescriptions or detailed medical history in its free-text fields. App data is described separately in §12.
| What | Where | Why |
|---|---|---|
| Full name | Callback form | So we can address you when we call back |
| Phone number | Callback form | So we can call or message you back |
| Email address (optional) | Callback form | Alternative contact channel, only if you provide it |
| Reason for visit (optional) | Callback form | So the right person can prepare for your call |
| Free-text message (optional) | Callback form | Same as above |
The website does not ask for Aadhaar, PAN or other government-issued ID numbers, payment information, precise device location, or information from children (see §10). Information entered voluntarily in the callback form is included in the enquiry we receive, so please keep it to what is needed to arrange contact.
If you contact us on WhatsApp or by phone using the buttons on the website, you are communicating with us directly through those services under their own privacy practices. Website analytics can record that a contact button was clicked, but our click tracking does not capture the contents of your call or WhatsApp conversation.
3. Why we use your information
- Returning your enquiry — calling, messaging, or emailing you back.
- Scheduling an appointment, if you ask us to.
- Internal record-keeping, so we can refer back to your enquiry if you contact us again.
- Operating and improving the website, including usage measurement and protection against abuse (§8).
We do not use your information for advertising or marketing without your separate, explicit consent. We do not use website analytics to make clinical decisions, and we never sell, rent, or trade your information.
4. Legal basis
For callback enquiries, you give consent by ticking the form’s unticked-by-default consent checkbox. This permission concerns your enquiry; it is not consent to advertising, website analytics, or every type of app processing. Website analytics is described in §8 and app processing in §12. You may contact us to withdraw consent (see §7); withdrawal does not affect processing already lawfully carried out or override applicable record-keeping obligations.
5. How long we keep your data
| Data | Retention |
|---|---|
| Enquiries where you became a patient | May form part of the clinical record and remain after app-account deletion, subject to applicable medical-record obligations and any legal hold |
| Enquiries where you did not become a patient | Retained to handle the enquiry, follow-up and related record-keeping; contact us to request deletion or ask about the period applicable to your enquiry |
| App account, clinical and security records; provider copies and backups | Different records have different retention and cleanup processes; see §12 and the account-deletion page |
Retention depends on the record type, the purpose for keeping it and applicable obligations. You can ask us for the retention information applicable to your records or request deletion using §11. Deleting an account does not automatically delete clinical records, security logs, provider-held copies or backups. We do not promise that every category follows one fixed retention period or is erased immediately.
6. Who we share your information with
- Our own clinical and administrative staff, who need it to respond to your enquiry.
- Infrastructure providers strictly necessary to operate the website: Google Cloud Platform — our servers and database run in Google’s Mumbai (asia-south1) region, India, with Google’s global content delivery network in front of them.
- Google Analytics processes website usage information as described in §8. Our clinic email provider, GoDaddy, handles callback notification emails and support correspondence; these may contain the details you submit.
- App service providers include Firebase Authentication, Expo and the platform notification services described in §12. Their processing is not limited to the location of our clinical database.
- Authorities, only where required by law (e.g. a valid court order).
We do not sell or rent your information to marketers, advertisers or data brokers. The providers described here receive information needed for their services, and may process service and security data under their own terms. This policy describes those transfers even where an app store treats a service-provider transfer as an exception to its “data shared” label.
7. Your rights as a Data Principal
- Information about what personal data we hold about you.
- Correction of inaccurate or outdated data.
- Erasure — deletion of your data, subject to §5’s legal retention.
- Withdrawal of consent at any time.
- Grievance redressal if you believe we have mishandled your data.
- Nomination of another person to exercise these rights on your behalf in case of incapacity or death.
To exercise any of these, contact us using §11. We respond within 30 days.
8. Cookies, analytics & tracking
With your permission, the public website uses Google Analytics 4 to understand page visits and interactions, including clicks on call, WhatsApp and booking links and successful callback submissions. Analytics can use first-party cookies and collect browser/device information, page addresses, referrers and approximate location. Our interaction-event code does not include callback-form names, phone numbers, email addresses or messages.
Analytics is off until you select “Accept analytics”. Choosing “Reject analytics” does not affect the website or contacting the hospital. Use “Privacy choices” at the bottom of the page to change your choice or withdraw permission. Withdrawal stops subsequent analytics collection; it does not erase information already received by Google. We remove this site’s standard analytics cookies and, when your choice can be saved, reload the page after withdrawal.
We remember your analytics choice, its version and its date in your browser’s local storage for up to 180 days, including when you reject analytics. This preference does not contain your name, phone number or medical information. Clearing browser storage resets the choice. If we cannot save your choice, analytics remains off on that page; clear this site’s browser data before returning to reset any older choice.
Our website tag disables Google Signals and advertising-personalisation signals. This does not switch off analytics collection. Browser privacy settings or content blockers can restrict cookies or analytics requests; blocking cookies alone may not prevent all measurement. See Google Analytics data practices. Website hosting also processes technical request information, such as IP addresses, for delivery and security. Your language choice (English/हिंदी) is reflected in the page address. Mobile-app local storage and notifications are described separately in §12.
9. Security
- All traffic between your browser and our servers uses HTTPS (TLS).
- Form submissions are stored in an access-controlled database in India (Mumbai region), readable only by authorised staff.
- In the event of a personal data breach affecting you, we will notify you and the Data Protection Board of India in accordance with the DPDP Act and the rules made thereunder.
10. Children's data
This website is intended for adults. We do not knowingly collect personal information from individuals under 18. If you believe a child has submitted information through the website, contact us via §11 and we will delete it.
11. How to contact us
| Grievance Officer | Dr Vivek Bhadoo |
| help@bhadoosurgical.com | |
| Phone | +91 90560 75777 |
| Postal address | Bhadoo Surgical & Wellness Centre, NH-4, Near Rehdi Market, Sector 17, Panchkula, Haryana 134109 |
If you are not satisfied with our response, you may escalate to the Data Protection Board of India under the DPDP Act.
12. Our mobile apps — Arogyam Health & Arogyam Business
The apps exist to run your visit: booking, check-in, the live queue, and your prescription record. Unlike the website, the apps do handle medical information, because that is their purpose. Everything below is in addition to the sections above; your rights (§7), our security practices (§9), and the contact route (§11) also apply to the apps. Website analytics and callback-form consent are separate from app processing; the descriptions below explain the app-specific practices.
What Arogyam Health (the patient app) collects
| What | When | Why |
|---|---|---|
| Mobile number | Sign-in (one-time password via Firebase Authentication) | Your account identity and appointment communication |
| Name | Required at first sign-in | Identifying you to clinic staff; your medical record |
| Account identifiers | Account creation and authenticated use | Account management, access control and linking your visits |
| Family member profiles (name, sex, year of birth, relation) | Only if you add them | Maintaining your family profile list; dependent booking is currently paused pending guardian/delegated-authority controls |
| Appointments, check-ins, queue tokens | When you book or attend | Running your visit |
| Prescriptions (photographs and/or typed medicine lists) | Created by your doctor during or after a consultation | Your medical record, retrievable in your visit history |
| Device/app-installation identifiers and push tokens | Authentication and notification-service operation; our push registration checks OS notification permission | Service security and delivery of visit notifications; notification permission is not a guarantee that no SDK identifiers are processed |
| Account and patient-record actions, timestamps, account/record identifiers, IP addresses and user-agent information | When audited actions occur, such as profile edits, booking changes and prescription views | Security, access accountability and protecting clinical records; not advertising |
The current patient app displays prescriptions supplied by the clinic; it does not yet offer patient uploads of lab reports, photos or documents. If that feature is released, we will explain the upload, doctor-access and retention choices before collection begins. The camera scans the reception QR code locally; the app sends the hospital-bound check-in information, not camera images. Check-in records attendance at the selected clinic; the patient app does not request GPS coordinates.
What Arogyam Business (the staff app) additionally collects — staff accounts only
| What | When | Why |
|---|---|---|
| Clock-in and clock-out times | Non-doctor staff attendance | Shift records |
| Location at clock-in and periodic shift updates | Only with explicit in-app consent; discarded server-side without it | Verifying on-premises attendance |
| Actions on patient records (searches, record views) | When supported audited actions occur | Security audit records of searches, record views and clinical/administrative changes |
Storage and processing
- Our primary hospital application database and prescription storage are hosted in Google Cloud, Mumbai (asia-south1), India. Prescription photographs are stored in a private bucket and accessed through time-limited links issued to authorised users. This does not mean all app data or provider processing stays in India.
- Google Firebase Authentication handles phone-OTP sign-in and processes authentication data in the United States. It handles the phone number, account identifiers and technical/security information. Google also documents use of authentication phone numbers for spam and abuse prevention across Google services. See Firebase phone-authentication information and Firebase privacy, locations and retention. Before requesting a sign-in code, the apps show a phone-verification notice and ask you to agree using an unchecked acknowledgement. This permission is separate from optional analytics or advertising and does not establish consent from earlier app sessions. If you do not wish to use phone sign-in, contact reception to arrange care without creating an app account.
- Expo, Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS) process notification tokens, technical registration/delivery data and notification messages. These services may process data outside India. Visit alerts use generic text asking you to open the app; names, diagnoses and prescribed medicines are not included in that text. Message routing data is not the prescription itself. See Expo notification processing.
- On your device, the apps keep authentication state and, where used, notification preferences and token information so these features work across app restarts. Images displayed by the app may also be cached by the device. Account deletion does not guarantee an immediate wipe of every operating-system cache or provider identifier.
- The mobile apps contain no advertising or third-party analytics SDKs. Operational and security logging still occurs, including provider processing described above. We do not sell or trade app data. The website analytics described in §8 is separate from the mobile apps.
- No AI processing of patient data. Any future AI-assisted feature will be introduced only with a revision of this policy and its own consent step.
- Every prescription change is preserved in an unalterable clinical history — records cannot be silently rewritten.
Retention and account deletion
Request patient-account deletion in the app (Profile → Delete account) or using the support route at bhadoosurgical.com/account-deletion. Accounts with staff or owner access must be handled by the clinic administrator.
When an account-deletion request completes successfully, access to that app account is disabled. The phone number, name and email are cleared from its main account profile, and its registered push tokens are removed from our application database. Unstarted upcoming appointments are cancelled.
- Family profiles: profiles with no linked appointments are deleted. Profiles linked to visit records are retained with those records.
- Clinical records: appointment history, consultations, prescriptions and prescription revision history are not erased by deleting the app account. These records, including original prescription images and linked family profiles, may still identify the patient. Removing app access is not the same as anonymising medical records. Access remains restricted to authorised care and administrative purposes.
- Security records: audit events and limited account identifiers can remain to protect clinical records, prevent a deleted account from regaining access, and meet applicable record-keeping obligations. They do not provide a usable sign-in.
- Provider cleanup and backups: Firebase account deletion is requested separately; failed requests are queued for retry. Authentication-provider records, notification-service identifiers and backup copies are not guaranteed to disappear immediately. Providers have separate retention and deletion processes; removing our account or push-token registration does not itself erase every provider-held copy.
If a consultation is in progress or interrupted, account deletion cannot complete in the app until that visit is resolved. Contact reception or the support contacts below to initiate a request and arrange the next steps. We do not silently erase an active clinical record.
Retention depends on the record type, ongoing care, applicable medical-record obligations and any legal hold. Contact us for the retention information applicable to your records or to request deletion of information that does not need to be retained. Account deletion is not a promise of immediate erasure from clinical records, logs or backups.
For deletion requests, retention questions or help with an active visit, email help@bhadoosurgical.com or call +91 90560 75777. Avoid sending prescriptions or detailed medical information by email. We verify requests before acting on account data.
13. Updates to this policy
We may update this policy from time to time. The “Last updated” date above will reflect any change, and material changes will be highlighted on this page.