This page is a draft prepared for early development purposes and has not yet been reviewed by a lawyer. It should not be relied upon as final until reviewed.
Privacy policy
Draft. Last updated: September 2026.
Core commitments
Jivadra is a professional network for healthcare professionals in India. We intend to comply with the Digital Personal Data Protection Act, 2023. This page is a draft until counsel reviews it.
- Patient-identifying data must never be stored. Case Consult and referrals are limited to anonymized clinical context (age range and sex). Submission is blocked without anonymization confirmation.
- Raw Aadhaar is never stored, logged, or shown — including to superadmin. DigiLocker identifiers, when used, are SHA-256 hashed with salt only.
- Primary databases, backups, and app infrastructure are intended to stay in India (DigitalOcean Bangalore).
What we collect now
The previous version of this page only listed waitlist identity fields and DigiLocker tokens. The live product also stores the following (this is an audit of current systems, not a promise of every future field).
- Account: email, optional phone, password hash, verification status, email-verified time, last login time, lockout fields. Historical waitlist rows (name, role, city, consent) may still exist from the public waitlist period and from registration upserts.
- Profile: display name, bio, qualifications, hospital, city, years of experience, directory opt-out flag, publication titles/URLs/years, experience entries.
- Connections between doctors (request, accept, decline, remove).
- Posts, comments, reactions, and community membership. Case Consult stores anonymized age range, sex, investigations text, and an anonymization timestamp — not patient name or exact age.
- Direct messages and community chat: message type, optional text body, optional pointer to a post or referral. Image URLs for posts live in object storage; Postgres stores the URL only. Media does not land on app-server disk.
- Referrals (when used): referring and receiving doctor ids, anonymized age range and sex, clinical reason, urgency, status, anonymization timestamp. Clinical reason is not copied into the chat table.
- Staff audit logs: actor, action, target type/id, reason, IP and user-agent as collected for security. Notes that may contain registration numbers are not copied into the audit summary where the product already redacts them.
- Public contact-form submissions (name, email, subject, message).
Why we use it
To operate accounts, verify professionals, show the feed and directory, enable messaging and referrals between connected doctors, moderate abuse, send transactional email, and keep the service secure. We do not sell personal data or use it for third-party advertising.
Retention
Account PII is kept while the account is open and erased on deletion as described on account deletion. Anonymized clinical posts/comments are soft-deleted and may remain attributed as "Deleted user". App logs are retained for a limited period and redacted. Audit logs of staff actions are kept as a longer compliance record.
Processors
Email delivery uses Resend. Hosting, PostgreSQL, Redis, and object storage use DigitalOcean (Bangalore). The public site may sit behind Cloudflare. We do not send patient-identifying data to these processors because we do not collect it.
Your rights (DPDP)
You may request access, correction, and erasure of personal data. Use in-product profile edit for display name and biography. For erasure, follow account deletion. Grievances: grievance redressal. Contact: contact form or support@jivadra.com.