Legal
Privacy Policy
This policy explains what information the Dr.20 app and this website collect, why we collect it, who can see it, how long we keep it and how you can control it.
DRAFT — pending legal review
This page is a draft. It has not yet been reviewed by a lawyer and may change before the Dr.20 app launches.
- Last updated:
- Version:
- 0.1 (draft)
Who we are
Dr.20 is a healthcare service run by DR20 TRUST, a Public Charitable Trust registered under the Indian Trusts Act, 1882 (registration No. 4/2026/39, Sub-Registrar, Panagudi). DR20 TRUST decides how your information is used and is responsible for it.
This policy covers the Dr.20 mobile app and the website www.dr20.in. Our contact details are at the end of this policy.
Information we collect
We collect only what we need to provide care and run the service.
| Type of information | Examples |
|---|---|
| Account details | Name, mobile number (used to sign in with a one-time password), date of birth or age, gender and preferred language |
| Family members you add | Name, age, gender and relationship to you, and the health information below for each of them |
| Health information | Allergies, medical conditions, current medicines, vital signs, consultation and visit notes, prescriptions, and lab reports and photos uploaded by you or our staff |
| Bookings and visits | The service, date, time and branch; the address for home visits; staff check-in and check-out times, task checklists, and notes and photos recorded during a visit or shift; your ratings and reviews |
| Payments | Invoices, amounts, payment status, the type of payment method (for example UPI or card) and transaction references. Card and UPI details are entered on the payment provider’s secure page; we never see or store your full card number or UPI PIN |
| Support and complaints | Your messages, complaint tickets and our replies |
| Device and security information | App version, device type, the token used to send you notifications, and security logs such as IP address and time of access |
| Staff details | For doctors, nurses and other staff who work with the Trust: registration number, qualifications, identity and verification documents, and bank details |
We do not use GPS or track your location; for home visits we use only the address you give us. We do not read your SMS messages, contacts or call logs, and we do not use advertising identifiers.
How we use your information
- To create and secure your account, and to sign you in with a one-time password.
- To book, schedule and deliver consultations, home visits and shifts, including assigning staff from your branch.
- To let the doctors and staff caring for you see the health information they need.
- To issue invoices and receipts, take payments and process refunds.
- To send you updates about your bookings and payments by push notification and SMS.
- To handle support requests, complaints and grievances.
- To keep the service safe, prevent fraud and misuse, and meet our legal duties, such as medical record, tax and cyber security rules.
- To understand how the service is used, using combined figures that do not identify you, so that we can improve it.
We do not sell your information. We do not show advertising, and we never use your health information for marketing.
Who can see your health information
- Doctors at your branch can see the records of that branch’s patients.
- Nurses, physiotherapists, caregivers and counsellors can see the records only of the patients assigned to them.
- You can see your own records, and the records of family members you manage in your account.
- Everyone who works with the Trust must keep patient information confidential.
Your consent and choices
- We ask for your consent before we collect health information. You can withdraw your consent at any time. This does not affect care already given, but we may not be able to continue some services.
- When you book for someone else, you must have their permission to share their details with us.
- A person under 18 cannot create their own account. A parent or guardian can add a child as a family member, and we ask for the verifiable consent of the parent or guardian before we process the child’s information. We do not track children or show them advertising.
Your rights
You can ask us to:
- Give you a copy of your information and tell you whom we have shared it with.
- Correct, complete or update information that is wrong or out of date.
- Delete your information, except the records we must keep by law (see “How long we keep information”).
- Let a person you nominate use these rights for you if you die or can no longer use them yourself.
- Resolve a complaint about how we handle your information.
You can do most of this in the app, or by contacting our Grievance Officer. We acknowledge requests within 24 hours and aim to complete them within 7 days.
How we protect information
- Information is encrypted while it travels between the app and our servers, and while it is stored.
- Access to health records is limited by role, and access is logged.
- Our servers are located in India, and we keep regular backups.
- Everyone who works with the Trust is bound to keep information confidential.
- If a data breach affects you, we will inform you and the authorities as the law requires.
How long we keep information
| Information | How long we keep it |
|---|---|
| Medical records: consultation notes, prescriptions, vital signs and lab reports | At least 3 years from your last consultation, or longer if the law requires |
| Invoices, receipts, and payment and refund records | As long as tax and accounting laws require |
| Security and system logs | 180 days to 1 year, as the law requires |
| Registration details of a deleted account | 180 days after deletion |
| Complaint and grievance records | Until resolved, and after that as long as the law requires |
| Other account information | Deleted or anonymised when you delete your account, or when it is no longer needed |
Information we must keep after you delete your account is stored securely, used only for the legal reason it is kept, and deleted or anonymised at the end of that period.
This website
www.dr20.in is an information website. It does not use cookies, analytics, advertising or third-party tracking, and it does not ask for your personal information. Our hosting provider may keep standard server logs, such as IP addresses, for security.
Changes to this policy
When we change this policy, we update the version number and date at the top of this page. We will tell you in the app before an important change takes effect.
Contact and grievances
For privacy questions, requests or complaints, contact our Grievance Officer:
Grievance Officer
- Name
- J John Milton
- Designation
- Managing Trustee and Grievance Officer, DR20 TRUST
- grievance@dr20.in (pending)
- Phone
- +91 XXXXX XXXXX (pending)
- Registered office
- DR20 TRUST, 4-214 S, Vadakkankulam Road, Near New Water Tank, Kavalkinaru – 627105, Radhapuram Taluk, Tirunelveli District, Tamil Nadu
If you are not satisfied with our response, you may complain to the Data Protection Board of India once its complaint process applies, or approach any other authority the law allows.
