Skip to main content
Tathaast Health Care
Legal

Privacy Policy

Tathaast Health Care provides home-healthcare services across Delhi NCR and Varanasi. Families who reach us, over the phone, the website, or through a referral, trust us with deeply personal health information about people they love. We treat that trust as a responsibility, not a formality.

Effective: May 2026 Applies to: www.tathaast.com & all home-care engagements

This Policy applies to all users of www.tathaast.com and all patients, family members, caregivers, and visitors who engage with Tathaast Health Care's services. Our head office is in New Delhi; we also serve Varanasi.

What Information Do We Collect?

Depending on how you interact with us, we may collect the following:

Basic Contact Details

  • Your name, mobile number, and email address
  • Your city, state, and PIN code
  • An emergency contact name and phone number where relevant

Clinical & Medical Information

Because our work is clinical in nature, some of the information we handle is sensitive personal health data, collected strictly with your explicit prior consent and used only for your care:

  • Details of the patient's medical condition, diagnosis, and treatment plan
  • Medical history, existing health conditions, allergies, and current medications
  • Recent discharge summaries, lab reports, and referring-doctor instructions
  • Care-plan notes, vitals, progress observations, and shift handovers
  • Photographs, taken only when clinically necessary (e.g. wound assessment) and only with your written consent at the time. These images are never used for any promotional purpose.

Appointment & Service Records

  • Details of appointments, home visits, enquiries, and follow-ups
  • Feedback or satisfaction responses you share with us

Payment & Scheme Information

  • Billing and invoice records
  • Government health scheme eligibility details (e.g. CGHS, ESI, Ayushman Bharat)
  • Insurance information, only when you ask us to assist with a claim
  • We never store your card or net-banking details. All online payments flow through PCI-DSS certified third-party gateways that handle encryption and authentication independently.

Website Technical Data

  • IP address, browser type, and device information
  • Pages visited and time spent on our website
  • This data is used only in aggregate, anonymised form to understand how our website performs. It is never linked to your identity.

Tathaast does not run advertisements. We do not allow any third-party advertising network to track visitors on our website. Your browsing here stays here.

Why Do We Use Your Information?

Every piece of information we collect has a clear, specific reason behind it. We use your data to:

  • Assess the patient's care needs and match the right caregiver
  • Schedule and manage home visits, shifts, and replacements
  • Coordinate with your referring doctor, hospital, or physiotherapist, only with your permission
  • Process billing, insurance claims, or scheme reimbursements you have requested
  • Send shift reminders, care-plan updates, and operational notices
  • Respond to your enquiries and resolve any concerns
  • Meet our obligations under Indian health, financial, and data-protection laws
  • Improve our website and services using anonymised, non-identifiable aggregate data

We do not sell, rent, or trade your personal data with any third party for commercial gain.

How We Handle Sensitive Health Data

Health and clinical data are in a special category under Indian law, and we treat it that way. Patients and their families share some of the most personal information imaginable: medical diagnoses, treatment plans, and the realities of caring for a loved one. We take that trust seriously.

  • We collect health data only with your explicit prior consent, explained in plain language
  • We use it exclusively for the patient's care, never for any commercial or analytical purpose
  • Access is limited to the coordinator and caregiver(s) directly involved in the case
  • We do not share it with external parties without your explicit go-ahead
  • Photographs (e.g. wound progress) are taken only when clinically necessary and only with your fresh written consent each time. They are never published, shared online, or used in any promotional material
  • Any data shared with a lab or pharmacy partner is limited to the minimum required, under a strict confidentiality agreement

When Do We Share Your Information?

We share your information only in very specific situations. Here is exactly when and why:

With your treating medical team

If you have a referring doctor, surgeon, or physiotherapist involved in your care, we share the relevant clinical details with them, but only with your express consent, and only what they need to know.

With our caregivers on the case

The nurse, GDA, attendant or doctor assigned to the case receives only the medical and personal information they need to deliver care safely. Each member of the team signs a confidentiality agreement before placement.

For insurance, scheme or lab/pharmacy coordination

If you ask us to coordinate insurance claims, lab tests, or medicine delivery, we share the necessary information with the relevant partner. This happens only at your specific request.

When the law requires it

We may share information if required to do so by a court order, a statutory authority, or applicable law. In every such case, we share only the minimum necessary and, where legally permitted, we will inform you.

With technology and service providers

We work with vendors for website hosting, email delivery, and payment processing. These vendors process data only on our instructions and are contractually bound to keep it confidential.

In a business restructuring

If Tathaast Health Care were ever involved in a merger, acquisition, or ownership change, your data would transfer to the new entity, but you would be notified at least 30 days in advance, and the incoming entity would be bound by the terms of this Policy.

We will never share your Aadhaar number, PAN, passport, or driving licence details with any third party. We will never sell your data. Ever.

How We Keep Your Data Safe

We put real safeguards in place, not just policy words:

  • Clinical records on our systems are behind role-based access controls: only the coordinator and caregiver(s) assigned to your case can see them
  • Physical paper records are kept in locked storage at our head office
  • Our digital systems use password protection and encryption
  • Our website and server infrastructure is regularly patched and monitored
  • Every coordinator and caregiver is trained on confidentiality obligations
  • All external vendors and partners sign confidentiality agreements before touching any data

If a data breach occurs that is likely to harm you, we will notify you and the Data Protection Board of India as required by the DPDP Act, 2023. We will not wait, and we will not minimise.

How Long Do We Keep Your Data?

We keep data only as long as it is genuinely needed:

Case & care-plan recordsMinimum 5 years from last serviceClinical Establishments Act / NMC Act
Financial & billing recordsMinimum 7 yearsIncome Tax Act, 1961 & Companies Act, 2013
Website server logsUp to 180 daysUnless extended for security investigation
Enquiries & correspondence3 yearsFrom date interaction was closed

Once data is no longer required, it is securely deleted or irreversibly anonymised. We do not hold on to personal data out of habit.

Your Rights

Under the Digital Personal Data Protection Act, 2023 and the IT (SPDI) Rules, 2011, you have real, enforceable rights:

Know what we hold

Ask for a summary of the personal data we have about you and how we use it

Fix what is wrong

Request correction of any inaccurate or outdated information

Ask us to delete

Request erasure of data we no longer need for any lawful purpose

Withdraw consent

Pull back your consent to processing at any time, in writing

Raise a complaint

Bring a grievance to our Grievance Officer; escalate to the Data Protection Board if unresolved

Nominate someone

Appoint a person to exercise your data rights on your behalf if you become unable to do so

Access your records

Request your full case file at any time in writing, your right under the Clinical Establishments Act and the NMC Act

Write to our Grievance Officer at tathaast@gmail.com. We will acknowledge within 48 hours and respond fully within 7 working days.

Patients Under 18 & Patients with Disabilities

We regularly care for paediatric patients and young patients recovering from illness or surgery. When the patient is under 18, we collect information and obtain consent from the parent or legal guardian, who may also exercise all data rights on the child's behalf.

Many of our patients also live with significant physical or cognitive disabilities. We are committed to making every consent process accessible: clear language, face-to-face explanation, and family support wherever needed. Consent is never ticked off as a formality: we make sure it is genuinely understood.

Cookies on Our Website

Our website uses a small number of cookies to function properly and to understand how visitors use the site:

  • Essential cookies: Keep the site working via session management and form functionality. Cannot be switched off without breaking the site
  • Analytics cookies: Tell us which pages are visited most, in anonymised, aggregate form. No individual is identified
  • Preference cookies: Remember display choices like language or font size across visits

We do not run advertising cookies. We do not allow any third-party ad network to place trackers on our site. You can manage or delete cookies at any time through your browser settings.

Updates to This Policy

We will update this Policy when our practices change or when the law requires it. Any meaningful update will be posted on this page with a revised effective date. If you are an existing patient family, we will also let you know via email or WhatsApp, at least 30 days before the change takes effect. Continuing to use our website or Services after that point means you accept the updated terms.

Reach Our Grievance Officer

For any questions, requests, or concerns about how we handle your personal information, please contact us directly. We will acknowledge your message within 48 hours and resolve it within 30 days. For data access or correction requests, we will respond within 7 working days.

Grievance OfficerPriyanshu Pandey
Head OfficeD 371, Raghuveer Nagar, New Delhi - 110027
Varanasi BranchVaishno Nagar Colony, Near Uday Bajaj, Manduadih, Varanasi - 221103

If we are unable to resolve your concern to your satisfaction, you may escalate to the Data Protection Board of India once it is fully operational.

WhatsApp
Call Us
Email Us