Privacy Notice
How Inmedism Healthcare Pvt. Ltd. collects, uses, shares, protects and retains personal data during website use, international patient coordination and related non-clinical services.
Who we are and who controls your data
Inmedism Healthcare Pvt. Ltd. (“InMedism®”, “we”, “us”) determines why and how it processes personal data collected through this website and its patient-coordination services. Independent hospitals, doctors and other providers separately control the information they receive for their own services.
- Corporate Identification Number: U86100DL2023PTC412325
- Registered office: WZ-1598/2, Nangal Raya, New Delhi - 110046, India
- Corporate office: UG-12 G/F 10 Upper, Vishal Tower, District Centre, Janak Puri, New Delhi - 110058, India
- Privacy email: [email protected]
- Phone / WhatsApp: +91 98212 12615
The information we may collect
We collect data according to the service requested and seek to limit it to what is reasonably necessary.
- Identity and contact data: name, email, telephone, country, nationality, language and communication preferences
- Enquiry and case data: medical need, requested specialty, hospital or doctor preferences, quotation and coordination history
- Health data: symptoms, diagnosis, reports, scans, prescriptions, pathology, treatment history and other records voluntarily provided through the approved process
- Passport and visa data: passport details or copies, photograph, visa status, invitation-letter information and immigration documents when required for requested travel support
- Attendant, guardian and representative data: identity, contact, relationship, authority and travel information
- Travel and practical-support data: itinerary, flight, accommodation, airport transfer, interpreter, accessibility, dietary and emergency-contact details
- Communications and consent data: email, telephone, WhatsApp and message history, permissions, withdrawals and recipient instructions
- Technical and security data: browser/device data, timestamps, security logs, approximate location inferred from network information and protected identifiers used for fraud and abuse prevention
Why we process each category
We process information only for identified patient-coordination, operational, security or legal purposes. InMedism does not sell patient personal data.
- Contact and enquiry data: respond, authenticate the enquiry and identify an appropriate starting point
- Health data: organize the case and, with authorization, request review, appointment availability or a hospital estimate from selected clinicians or providers
- Passport and visa data: coordinate hospital invitation documentation and requested visa-related administrative support; government authorities independently decide visa matters
- Attendant and guardian data: verify authority, coordinate communication, travel and safeguarding, particularly for children or dependent adults
- Travel data: arrange requested accommodation, transport, interpretation and arrival support
- Technical data: operate, protect, troubleshoot and measure the reliability of the website and prevent spam, fraud or misuse
- Transaction and service records: disclose coordination charges, maintain accounts, resolve disputes and meet applicable legal obligations
Consent, authorization and patient control
Where consent is used, we request a clear affirmative action for a specified purpose. Optional consent is not bundled with an unrelated service. You may refuse optional processing, choose which provider may receive records, or withdraw consent. Withdrawal does not invalidate processing already completed and can limit a service that cannot operate without the information.
- A general enquiry permits initial contact and coordination; it does not authorize medical-record disclosure
- Medical-record use and sharing require a separate consent-controlled workflow
- A representative must confirm lawful authority to act for the patient
- We may process information without consent only where applicable law permits or requires it and the relevant conditions are met
Health information and medical records
Health information is sensitive and receives additional handling controls. Do not upload medical files to the general enquiry form or send them through an unsolicited ordinary email. After verification, use the dedicated, time-limited medical-record process and share only records relevant to the requested review.
- Files are type- and size-restricted, encrypted before storage, stored outside the public web directory and initially quarantined
- Access is limited to authorized personnel with a case-related need
- The upload consent identifies the purpose and intended hospital or clinician disclosure
- Uploading does not mean that a hospital has accepted the patient or that a clinician has reviewed the case
- Never upload passwords, banking credentials or another person’s records without authority
Passport, visa and identity documents
We request passport, visa or identity information only when necessary for a service the patient has requested, such as hospital invitation documentation, travel coordination or identity verification. These documents should be submitted only through an approved secure process, never through the public enquiry form.
- We disclose only the fields or copy reasonably required by the selected hospital, travel provider or lawful authority
- InMedism cannot decide or guarantee visa issuance, entry, extension or immigration outcomes
- Unneeded identity copies are placed on a shorter deletion schedule than general case records
Children, guardians and dependent adults
For a child or a person unable to provide valid instructions, a parent, lawful guardian or properly authorized representative must act on their behalf. We may request evidence of identity, relationship or authority and may pause processing where authority is unclear.
- We seek to collect only information necessary for the child’s case and travel
- A child’s data is not used for behavioural advertising
- The treating hospital remains responsible for clinical consent and safeguarding within its services
- Where appropriate and practicable, the patient’s own views should be respected alongside lawful guardian instructions
Sharing with hospitals and doctors
We share health or identity information only with a specific hospital, department or licensed clinician selected for the patient’s requested review and only after the relevant authorization. Inclusion in the InMedism directory does not itself authorize disclosure or imply partnership.
- The recipient may use the information to assess clinical suitability, request further tests, propose an appointment or prepare an estimate
- Hospitals and doctors become independently responsible for their subsequent clinical records and legal duties
- A preliminary review is not a diagnosis, admission guarantee or treatment commitment
- Consent withdrawal cannot reverse a disclosure already made with authorization; contact the recipient about its retained copy
Sharing with travel and support providers
If requested, we may provide the minimum information needed to an accommodation provider, transport operator, interpreter, document translator or other practical-support provider. Medical details are not shared unless necessary for the requested service and authorized.
- Hotels may need guest identity and dates, not full medical records
- Transport providers may need passenger, flight and accessibility information
- Interpreters may receive relevant context and are expected to respect confidentiality
- Each independent provider applies its own privacy notice and legal obligations
Email, cloud, security and IT processors
We use service providers to host, secure, back up and operate communications and information systems. They may process data only to provide contracted services under appropriate instructions, access restrictions and confidentiality obligations. Provider locations and subprocessors may change as systems are maintained.
- Website and cloud hosting infrastructure
- Business email and workspace services
- Security, spam prevention, logging and monitoring services
- File storage, backup and recovery services
- Professional advisers where access is necessary and subject to confidentiality
WhatsApp, telephone and communication channels
If you contact us through WhatsApp, telephone, social media or another third-party channel, that provider processes information under its own terms and privacy practices. These channels may involve storage or routing outside India. Use them for general coordination, not unsolicited medical records, passport copies, passwords or banking information.
- You may request communication by email or another reasonably available channel
- We may record the substance of communications in the case record for continuity and accountability
- Calls are not recorded unless notice and any required consent are provided
- Do not use InMedism communication channels for emergencies
International and cross-border processing
Medical travel coordination commonly begins outside India and requires data to be received in India or sent to a selected provider. Information may also be processed by technology or communication suppliers in other countries. We limit transfers to the stated purpose, apply reasonable contractual and technical safeguards and follow applicable transfer restrictions.
- Privacy laws and enforcement rights differ between countries
- A patient may ask which selected hospital or service-provider category is expected to receive information
- Government, immigration or consular disclosures occur only when requested by the patient or required by law
Retention schedule
We retain each category only for as long as needed for its purpose, then securely delete or anonymize it where reasonably practicable. The ordinary review periods below may be extended by a legal hold, active dispute, fraud investigation, accounting requirement or binding legal obligation.
- Unconverted general enquiries: reviewed for deletion or anonymization 12 months after the last meaningful interaction
- Medical files submitted for preliminary coordination: reviewed within 180 days after the enquiry is closed or becomes inactive
- Passport and visa copies: reviewed within 180 days after the relevant travel support ends
- Active-case coordination, consent and disclosure records: ordinarily retained for up to 7 years after case closure for accountability and legal requirements
- Security and access logs: ordinarily retained for up to 12 months unless needed to investigate an incident
- Marketing contact data: retained until consent is withdrawn or the data is no longer useful; a minimal suppression record may be retained to respect an opt-out
- Approved testimonial materials: retained for the stated publication period or until valid consent withdrawal, subject to content already lawfully distributed
Security practices
We use reasonable administrative, technical and physical safeguards proportionate to the information and risk. These measures reduce risk but no internet or storage system can be guaranteed completely secure.
- Encrypted website connections and protected transmission
- Role-based access and need-to-know handling
- Restricted upload types, size limits, quarantine and storage outside the public directory
- Authentication, session protection, anti-spam and abuse controls
- Logging, backup, recovery and controlled administrative access
- Staff confidentiality expectations and periodic access review
Security incidents and breach handling
We assess suspected loss, unauthorized access, disclosure, alteration or destruction and take proportionate steps to contain, investigate, preserve evidence and reduce harm. Where applicable law requires notification, we will notify the relevant authority and affected individuals in the required manner and timeframe.
- Immediately email [email protected] if a private link or document reaches the wrong person
- Do not open, copy, forward or further disclose information received in error
- Include the enquiry reference but do not attach exposed medical or identity documents to the incident email
- We may ask for identity verification before discussing affected records
Your access, correction, deletion and grievance rights
Subject to applicable law and identity verification, you may request a summary of personal data and processing, correction, completion or updating, erasure where retention is no longer necessary, withdrawal of consent and grievance handling. Where applicable, you may nominate another person to exercise rights in specified circumstances.
- We will acknowledge and assess requests through the privacy contact
- We may request proportionate identity or authority evidence
- We will explain a lawful retention requirement or other exception that prevents full deletion
- A request concerning a hospital’s independent record should be directed to that hospital
How to withdraw consent
Email [email protected] with the subject “Consent withdrawal” and the enquiry reference. State which processing or recipient authorization you wish to stop; do not attach medical or passport files. We will record and act on a valid withdrawal as required, but cannot undo sharing or processing already lawfully completed.
Marketing choices
Promotional email, messaging or telephone contact requires a separate choice where consent is the applicable basis. Refusing marketing does not affect patient coordination. Every electronic marketing message should provide a practical opt-out, and a withdrawal request will be applied to future campaigns after reasonable processing time.
- Service messages about an active enquiry are not marketing
- We do not sell or rent contact lists
- We do not use health information to create advertising audiences
- A minimal suppression record may be retained so an opt-out is not accidentally reversed
Patient stories, reviews, photographs and testimonials
We do not publish an identifiable patient story, image, video, quotation or treatment experience merely because the person used our services. Publication requires separate, specific and recorded permission describing the material, channels, purpose and intended duration.
- Clinical care or coordination is not conditional on testimonial consent
- Consent can be limited to named content or channels
- Withdrawal applies to future use where reasonably possible but may not retrieve material already printed, downloaded or lawfully redistributed
- Hospitals and clinicians must obtain their own permission for their independent publications
Cookies, analytics and advertising technologies
The website uses necessary session and security technologies to operate forms and protect the service. It also uses limited first-party aggregate measurement by default to understand whether broad public-site functions are being used and to improve reliability.
- Aggregate measurement counts a limited event type and broad public-content category by day
- It does not store search terms, medical page names or slugs, form content, IP addresses, email addresses, phone numbers or patient identifiers in the analytics table
- We do not use health information for targeted advertising and do not currently run third-party advertising trackers
- Third-party links and services operate under their own notices
- Browser controls may block necessary storage but can affect security or form continuity
Legal framework and readiness
We design this notice and workflow with reference to applicable Indian privacy and information-security requirements, including reasonable security practices under the Information Technology framework and the staged commencement of the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025. Legal obligations apply according to their notified commencement and the facts of each processing activity.
Privacy grievance contact and escalation
Send privacy questions, rights requests, consent withdrawals or complaints to the Privacy Grievance Officer at [email protected] with the subject “Privacy grievance”. You may also write to the corporate office or use the official phone/WhatsApp number below. We aim to acknowledge a grievance promptly and provide a substantive response within the period required by applicable law.
- Privacy Grievance Officer, Inmedism Healthcare Pvt. Ltd.
- Corporate office: UG-12 G/F 10 Upper, Vishal Tower, District Centre, Janak Puri, New Delhi - 110058, India
- Email: [email protected]
- Phone / WhatsApp: +91 98212 12615
Changes to this notice
We may update this notice when services, providers, safeguards or legal requirements change. Material changes will be displayed here with a new version and effective date. If a change materially affects an existing consent-based purpose, we will request a new choice where required.
Written by the InMedism Editorial Team and reviewed by the InMedism Content Review Team on 26 August 2026 for clarity, facilitation scope and source quality. This is not a clinical review; medical decisions require a qualified treating professional.
Questions patients often ask
These answers provide general coordination information. Questions about diagnosis, risks or treatment require a qualified clinician.
Ask a different question →Should I attach medical records or a passport to the general enquiry form?+
No. Use the general form only to describe the assistance needed. Submit health or identity documents only through the approved secure process when specifically requested.
Who decides which hospital receives my records?+
The patient or authorized representative chooses the requested review pathway. InMedism should identify the proposed recipient and purpose before the separate medical-record authorization is completed.
Does InMedism sell patient information or use health records for advertising?+
No. InMedism does not sell patient personal data and does not use health information to create targeted-advertising audiences.
Can I withdraw permission after records have been shared?+
You can stop future consent-based use or sharing, but withdrawal cannot undo an authorized disclosure already completed. The receiving hospital or doctor controls its own retained clinical or administrative record.
How long are uploaded medical records kept?+
Medical files submitted for preliminary coordination are ordinarily reviewed for deletion within 180 days after the enquiry closes or becomes inactive, unless an active case, legal hold or binding requirement justifies longer retention.
How do I report a privacy or security concern?+
Email [email protected] with the subject “Privacy grievance” or “Security incident” and include the enquiry reference without attaching sensitive files.
When was this notice updated?+
This Privacy Notice is version 2026-09-05 and is effective from 5 September 2026.
