PRIVACY POLICY FOR HEALTHFLO AI SOLUTIONS PVT.LTD.

Comprehensive data protection and privacy policy governing the collection, use, and protection of personal information.

1. GENERAL

This Privacy Statement elucidates the utilization and safeguarding of personal information gathered by HealthFlo. It is applicable to any data collected and may include, but is not limited to, your personal information, medical history, clinical records, prescriptions, laboratory reports, blood test results, imaging reports, pathology reports, and any other medical or diagnostic data that you voluntarily provide to HealthFlo and, as permitted by applicable law, any personal information acquired from different sources.

This Policy underlines the requirement to comply with the rules and regulations applicable to HealthFlo AI SOLUTIONS PVT. LTD. (herein referred to as HealthFlo or Company or Data Fiduciary or Us/We) and the Clients, Patients, Customers, Suppliers, Third parties, etc., (herein referred to as, "Data Principal", "You" or "Your") with regard to any data collected may include, but is not limited to, your personal information, medical history, clinical records, prescriptions, laboratory reports, blood test results, imaging reports, pathology reports, and any other medical or diagnostic data that you voluntarily provide to HealthFlo.

The HealthFlo takes the security and privacy of your data seriously. The HealthFlo needs to gather and use information or 'data' about you as part of medical requirements. It intends to comply with all legal obligations under the relevant laws of the jurisdiction including Digital Data Protection Act, 2023, Information Technology Act, 2000, General Data Protection Regulation ('GDPR') in alignment with HIPAA guidelines and PHI, in respect of data privacy and security.

2. SCOPE OF THE POLICY

This policy applies to any collected data that may include, but is not limited to, personal information, medical history, clinical records, prescriptions, laboratory reports, blood test results, imaging reports, pathology reports, and any other medical or diagnostic data that Patients, Clients, Customers, Suppliers, Third parties, etc voluntarily provide to HealthFlo.

The Company/HealthFlo is a 'Data Fiduciary' for the purposes of your personal data. This means that we determine the purpose and means of processing your personal data.

3. DEFINITIONS

"Data"

means personal information, medical history, clinical records, prescriptions, laboratory reports, blood test results, imaging reports, pathology reports, and any other medical or diagnostic data.

"Personal Data"

means any data about an individual who is identifiable by or in relation to such data; information that relates to a living person who can be identified from that data on its own, or when taken together with other information which is likely to come into our possession.

"Processing"

in relation to personal data means an automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction.

"Data Fiduciary"

means any person who alone or in conjunction with other persons determines the purpose and means of processing personal data.

"Data Principal"

means the individual to whom the personal data relates and where such individual is a child includes the parents or lawful guardian of such a child.

4. COLLECTION OF PERSONAL DATA

Personal Identifiable Information (PII)

  • • Full name
  • • Date of birth
  • • Contact details (email, phone number)
  • • Government-issued ID (where required)
  • • Address

Medical and Health Data (PHI)

  • • Medical history and records
  • • Doctor's notes and prescriptions
  • • Diagnostic reports and lab results
  • • Symptoms and physical/mental health data
  • • Biological samples (where integrated via labs)
  • • Appointment history

Collection Methods

Direct Collection

  • • Forms and applications
  • • Website interactions
  • • Email communications
  • • Phone consultations

Automatic Collection

  • • Web server logs
  • • IP addresses
  • • Device specifications
  • • Cookies and web beacons

5. HOW DOES HealthFlo USE YOUR DATA

Primary Uses

  • • Providing information and services as per your requests
  • • Assessing queries and processing requests for diagnosis
  • • Providing AI-generated preliminary diagnoses
  • • Enabling healthcare professionals to review health data
  • • Storing and managing medical records securely

Secondary Uses

  • • Facilitating communication with healthcare providers
  • • Improving AI model accuracy and performance
  • • Complying with legal and regulatory obligations
  • • Notifying of updates or relevant health alerts
  • • Platform improvement and optimization

6. SHARING PERSONAL DATA WITH THIRD PARTY

Important Notice

HealthFlo places strong emphasis on safeguarding your personal information and generally does not disclose it to third parties except in specific circumstances outlined below.

Medical Partners

Sharing with medical specialists, diagnostic laboratories, imaging centers, or referral partners on a need-to-know basis for treatment continuity.

Legal Compliance

Sharing with statutory authorities, law enforcement agencies, or courts when required by law or legal process.

Safety & Security

Sharing when necessary to investigate, prevent, or address illegal activities or suspected fraud.

With Consent

Your informed and voluntary consent will be obtained before any disclosure for medical purposes.

7. RIGHTS OF DATA PRINCIPAL

Right to Access

Access your data and request its correction or deletion if inaccurate or no longer necessary.

Right to Withdraw Consent

Withdraw consent at any time. HealthFlo will cease processing within a reasonable time upon withdrawal.

8. OBLIGATIONS OF DATA PRINCIPAL

• Provide authenticated personal data to HealthFlo and handle data with care ensuring integrity and accuracy

• Not misuse any data or information provided by HealthFlo for official purposes

• Not transfer or share HealthFlo data to third parties without prior approval

• Not store HealthFlo data on unauthorized personal devices or cloud services

• Report security incidents or suspected unauthorized access immediately

9. RIGHTS AND OBLIGATIONS OF HEALTHFLO

• Collect and process data legally with prior consent clearly describing what data is collected

• Make reasonable efforts to ensure personal data is accurate and complete

• Provide proper procedure and effective redressal mechanism

• Protect personal data with necessary security measures

• Not retain data longer than necessary unless required by law

10. DATA PROTECTION AND SECURITY MEASURES

Administrative Safeguards

Robust policies and procedures for data handling

Technical Safeguards

End-to-end encryption and access controls

Physical Safeguards

Secure facilities and audit logs

11. ACCESS AND RECTIFICATION

You have the right to request access to your personal information held by HealthFlo. We will make sincere efforts to respond to your request in a timely manner. You can request rectification of your data by contacting HealthFlo at the designated contact information.

12. DISCLOSURE OF INFORMATION

HealthFlo will share your information in the following circumstances:

  • • With your consent
  • • When necessary to comply with a legal obligation
  • • When required by government agencies mandated by law
  • • HealthFlo will ensure recipients do not further disclose unless permitted by law

13. PRIVACY BREACH

In the event of a privacy breach, HealthFlo shall promptly assess the impact and take necessary steps to mitigate risks and prevent further breaches. We will notify the designated Data Protection Authority within 72 hours and affected individuals when required by law.

Breach Notification Includes:

  • • Description of the breach and affected data
  • • Contact details for further information
  • • Potential consequences of the breach
  • • Actions taken to address and mitigate the breach

14. AUTHENTICITY

HealthFlo will not be held responsible for verifying the authenticity of personal information provided by service providers. It is the duty of data principals to ensure that the information they supply is authentic and accurate.

15. GRIEVANCE REDRESSAL

If you have any grievances or complaints regarding the processing of your personal information, you can submit them in writing to HealthFlo. We will address your grievance as quickly as possible.

Contact details will be provided upon policy finalization

16. EFFECTIVE DATE

This Privacy Statement comes into effect on ______________ 2025 and replaces all existing policies related to this subject matter.

Failure to comply with this Policy may result in serious consequences including damages, legal actions, fines, and penalties. HealthFlo AI SOLUTIONS PVT. LTD. reserves the right to amend this Policy from time to time.