Privacy Policy
Last updated: 2026-08-19
This notice tells you what personal data CareMedico Medtech Private Limited collects, why, and what you can do about it. It is written to meet s.5 of India's Digital Personal Data Protection Act 2023 and Articles 13 and 14 of the UK/EU GDPR.
Who we are
CareMedico Medtech Private Limited (CIN U74999UP2022PTC173025), B-7, 1st Floor, Sector-2, Noida, Uttar Pradesh 201301, India, is the Data Fiduciary and Data Controller for the information described here. We are a medical-travel facilitator and membership provider. We are not a hospital, doctor or insurer, and we do not provide medical care.
What we collect
- When you send an enquiry: your name, country, phone number, email address, the treatment you are asking about, anything you write in the message box, and a truncated form of your network address used only to detect abuse.
- When you apply for a Healthcare Card: the above, plus the plan you chose, the amount payable, the last four digits of your passport, and an emergency contact.
- Automatically: cookies that are strictly necessary for the site to function. Analytics and advertising cookies are set only if you agree — see Cookies below.
Information about the treatment you are seeking is health data. Under GDPR Article 9 that is special category data, and under the SPDI Rules 2011 it is sensitive personal information. We process it only with your explicit consent.
Why we use it, and on what basis
- To answer your enquiry and coordinate your care — on your consent (DPDP s.6; GDPR Art 6(1)(a) and Art 9(2)(a)).
- To issue and administer your Healthcare Card — to perform the contract you entered into (GDPR Art 6(1)(b)), with your explicit consent for any health details.
- To keep financial records — to comply with Indian tax and company law (GDPR Art 6(1)(c)).
- To measure how the site is used and how our advertising performs — only if you consent, and you can withdraw at any time.
Who we share it with
We share your case with the hospitals and doctors you approve, so they can give an opinion and a quotation. We do not sell personal data and we do not share it with anyone else for their own marketing.
Our website is hosted by Hostinger. If you consent to analytics or advertising cookies, Google and Meta will also receive the pages you visit on this site. Because our page addresses name medical treatments and specialists, that tells them something about the condition you are researching. This is exactly why those cookies are off until you turn them on.
Sending data outside India
Your data is stored in India. If you are in the EU, EEA or UK, sending it to us is a transfer outside your region; we rely on your explicit consent for that transfer (GDPR Art 49(1)(a)). Google and Meta, if you enable them, process data in the United States and elsewhere under their own transfer safeguards.
How long we keep it
- Enquiries: deleted automatically 3 years after you send them.
- Card applications and membership records: deleted automatically 7 years after they are created, which is the period Indian tax law requires us to keep financial records.
- Your consent choice for cookies: 6 months, then we ask again.
Deletion runs automatically. You do not have to ask, and you can ask us to delete your data sooner.
Your rights
You can ask us to give you a copy of your data, correct it, or erase it; to withdraw your consent; or to raise a grievance. Withdrawing consent is as easy as giving it and costs nothing. Use our data rights form, or write to the Grievance Officer at privacy@caremedico.com. We respond within 30 days.
We verify identity before acting on a request, because otherwise anyone could read or delete someone else's medical enquiry.
If you are not satisfied, you may complain to the Data Protection Board of India. If you are in the EU, EEA or UK you may complain to your local supervisory authority.
Cookies
Strictly necessary cookies keep the site working and remember your privacy choice; these cannot be switched off. Analytics and advertising cookies are set only after you agree. You can change or withdraw your choice at any time using Privacy choices at the bottom of any page.
How we protect it
Data is encrypted in transit using HTTPS. Access to the admin system requires an individual account with a role that limits what that person can see, sign-in attempts are rate-limited and locked after repeated failures, and reads, changes and exports of your data are written to an audit log.
We want to be straightforward with you: our database is not currently encrypted at rest, and the site runs on shared hosting. We are telling you this rather than implying protection we have not yet built. Do not send us documents you would not want stored under those conditions; if you would like to share medical reports, ask us and we will arrange a more secure route.
If something goes wrong
If a breach affects your data we will notify the Data Protection Board of India and tell you, as DPDP s.8(6) requires; where GDPR applies we will notify the relevant supervisory authority within 72 hours under Article 33 and tell you where Article 34 requires it.
Changes
If we change how we use your data we will update this notice and, where the change needs it, ask for your consent again.