SleepCare OS — Digital Personal Data Protection Policy & Patient Consent Framework
Statutory Notice under Section 5, Digital Personal Data Protection (DPDP) Act, 2023
This document serves as the official privacy notice for patients, clinicians, and partners accessing SleepCare OS. It outlines what personal medical data we process, the precise purposes, security safeguards, and your statutory rights to access, correct, and erase your data.
The primary Data Fiduciary for patient data processed through SleepCare OS is the registered somnology clinic, sleep diagnostic center, or treating hospital where you booked or received your sleep study. SleepCare OS acts as a technology platform and Data Processor facilitating digital diagnostics, machine rentals, and clinical reporting.
We process only such data as is strictly necessary for somnological evaluation and therapy:
Under Section 6 of the DPDP Act 2023, data is processed solely for:
A. Clinical Sleep Diagnostics
Generating diagnostic reports, AHI scoring, and doctor consultations.
B. Equipment Titration & Trials
Tracking CPAP/BiPAP trials, machine delivery, and therapy optimization.
C. Direct WhatsApp/SMS Communication
Delivering secure 1-click magic access links, test scheduling, and reminders.
D. Zero Commercial Data Sale
Your health data is NEVER sold, rented, or monetized to advertisers or third parties.
All patient records are protected using PostgreSQL Row Level Security (RLS) with cryptographic separation between organizations and patients. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Patient portal access uses temporary cryptographic tokens with automatic expiration.
Diagnostic sleep study recordings and medical reports are retained for a minimum period of 3 years in adherence to Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, or as mandated by your healthcare provider. After the statutory retention period, data is securely purged or anonymized.
As a Data Principal, you are entitled to:
In accordance with Rule 11 of the DPDP Framework, any privacy concern, data correction, or grievance may be addressed to our designated Data Protection Officer:
Officer: Grievance Redressal Officer, SleepCare Health
Email: privacy@sleepcare.app
Response Timeline: Within 72 working hours (DPDP Statutory SLA)