Skip to main content

Dr.20 is not for emergencies. For emergencies call 108 / 112

Dr.20DR20 TRUST, home page

Legal

Privacy Policy

This policy explains what information the Dr.20 app and this website collect, why we collect it, who can see it, how long we keep it and how you can control it.

DRAFT — pending legal review

This page is a draft. It has not yet been reviewed by a lawyer and may change before the Dr.20 app launches.

Last updated:
Version:
0.1 (draft)

Who we are

Dr.20 is a healthcare service run by DR20 TRUST, a Public Charitable Trust registered under the Indian Trusts Act, 1882 (registration No. 4/2026/39, Sub-Registrar, Panagudi). DR20 TRUST decides how your information is used and is responsible for it.

This policy covers the Dr.20 mobile app and the website www.dr20.in. Our contact details are at the end of this policy.

Information we collect

We collect only what we need to provide care and run the service.

Types of information the Dr.20 app collects
Type of informationExamples
Account detailsName, mobile number (used to sign in with a one-time password), date of birth or age, gender and preferred language
Family members you addName, age, gender and relationship to you, and the health information below for each of them
Health informationAllergies, medical conditions, current medicines, vital signs, consultation and visit notes, prescriptions, and lab reports and photos uploaded by you or our staff
Bookings and visitsThe service, date, time and branch; the address for home visits; staff check-in and check-out times, task checklists, and notes and photos recorded during a visit or shift; your ratings and reviews
PaymentsInvoices, amounts, payment status, the type of payment method (for example UPI or card) and transaction references. Card and UPI details are entered on the payment provider’s secure page; we never see or store your full card number or UPI PIN
Support and complaintsYour messages, complaint tickets and our replies
Device and security informationApp version, device type, the token used to send you notifications, and security logs such as IP address and time of access
Staff detailsFor doctors, nurses and other staff who work with the Trust: registration number, qualifications, identity and verification documents, and bank details

We do not use GPS or track your location; for home visits we use only the address you give us. We do not read your SMS messages, contacts or call logs, and we do not use advertising identifiers.

How we use your information

  • To create and secure your account, and to sign you in with a one-time password.
  • To book, schedule and deliver consultations, home visits and shifts, including assigning staff from your branch.
  • To let the doctors and staff caring for you see the health information they need.
  • To issue invoices and receipts, take payments and process refunds.
  • To send you updates about your bookings and payments by push notification and SMS.
  • To handle support requests, complaints and grievances.
  • To keep the service safe, prevent fraud and misuse, and meet our legal duties, such as medical record, tax and cyber security rules.
  • To understand how the service is used, using combined figures that do not identify you, so that we can improve it.

We do not sell your information. We do not show advertising, and we never use your health information for marketing.

Who can see your health information

  • Doctors at your branch can see the records of that branch’s patients.
  • Nurses, physiotherapists, caregivers and counsellors can see the records only of the patients assigned to them.
  • You can see your own records, and the records of family members you manage in your account.
  • Everyone who works with the Trust must keep patient information confidential.

When we share information

We share information only when it is needed, and only as much as is needed:

  • With service providers who work for us under contract: cloud hosting in India, SMS and notification delivery, and payment gateways. They may use the information only to provide their service to us.
  • With a partner clinic or lab, when you book with that clinic or your doctor refers you for tests. They receive only the details needed for that booking or referral.
  • With government authorities, courts or regulators, when the law requires it.

We do not share your information with anyone else without your permission.

Your rights

You can ask us to:

  • Give you a copy of your information and tell you whom we have shared it with.
  • Correct, complete or update information that is wrong or out of date.
  • Delete your information, except the records we must keep by law (see “How long we keep information”).
  • Let a person you nominate use these rights for you if you die or can no longer use them yourself.
  • Resolve a complaint about how we handle your information.

You can do most of this in the app, or by contacting our Grievance Officer. We acknowledge requests within 24 hours and aim to complete them within 7 days.

How we protect information

  • Information is encrypted while it travels between the app and our servers, and while it is stored.
  • Access to health records is limited by role, and access is logged.
  • Our servers are located in India, and we keep regular backups.
  • Everyone who works with the Trust is bound to keep information confidential.
  • If a data breach affects you, we will inform you and the authorities as the law requires.

How long we keep information

How long DR20 TRUST keeps each type of information
InformationHow long we keep it
Medical records: consultation notes, prescriptions, vital signs and lab reportsAt least 3 years from your last consultation, or longer if the law requires
Invoices, receipts, and payment and refund recordsAs long as tax and accounting laws require
Security and system logs180 days to 1 year, as the law requires
Registration details of a deleted account180 days after deletion
Complaint and grievance recordsUntil resolved, and after that as long as the law requires
Other account informationDeleted or anonymised when you delete your account, or when it is no longer needed

Information we must keep after you delete your account is stored securely, used only for the legal reason it is kept, and deleted or anonymised at the end of that period.

This website

www.dr20.in is an information website. It does not use cookies, analytics, advertising or third-party tracking, and it does not ask for your personal information. Our hosting provider may keep standard server logs, such as IP addresses, for security.

Changes to this policy

When we change this policy, we update the version number and date at the top of this page. We will tell you in the app before an important change takes effect.

Contact and grievances

For privacy questions, requests or complaints, contact our Grievance Officer:

Grievance Officer

Name
J John Milton
Designation
Managing Trustee and Grievance Officer, DR20 TRUST
Email
grievance@dr20.in (pending)
Phone
+91 XXXXX XXXXX (pending)
Registered office
DR20 TRUST, 4-214 S, Vadakkankulam Road, Near New Water Tank, Kavalkinaru – 627105, Radhapuram Taluk, Tirunelveli District, Tamil Nadu

If you are not satisfied with our response, you may complain to the Data Protection Board of India once its complaint process applies, or approach any other authority the law allows.