Privacy Policy and Account Data Deletion
Effective Date: August 2, 2026
Last Updated: August 2, 2026
Introduction to Privacy Policy
Salekcha Healthcare Private Limited, operating under the brand name Ghar Pe Diagnostics, also referred to as GPD, "we," "us," or "our," respects the privacy and confidentiality of patients, customers, healthcare professionals, technicians, phlebotomists, employees, operations personnel and other users of our services.
This Privacy Policy explains how we collect, use, process, store, protect, share, retain and delete personal data when users access or use:
- The Ghar Pe Diagnostics website
- The Ghar Pe Diagnostics customer dashboard
- Any GPD customer application used to book diagnostic or healthcare services
- GPD Connect, used by authorised doctors, technicians, phlebotomists and healthcare professionals
- Any GPD operations application used by authorised employees or operations personnel
- Related booking, payment, communication, reporting and customer-support services
All these platforms are collectively referred to in this Privacy Policy as the "GPD Platforms."
Quick Account and Data Deletion Access
Customers can initiate permanent account and data deletion through:
Customer Mobile App: Profile → Privacy and Data → Delete Account and Data
Customer Website Dashboard: Account Settings → Privacy and Data → Delete Account and Data
Users can also submit a deletion request directly from this Privacy Policy page by using the Request Account and Data Deletion form displayed below.
Where the form is unavailable, users may email:
info@gharpediagnostics.com
Email subject: Account and Data Deletion Request
Account deletion is permanent. Eligible deleted data cannot be restored. Users should download all reports, prescriptions and documents they wish to retain before confirming deletion.
Certain medical, diagnostic, payment, taxation, accounting, security, audit and legal records may be retained where required by applicable law or for legitimate compliance purposes. Such retained information will be access-restricted and will not remain available through the deleted user account.
1. About Ghar Pe Diagnostics
Ghar Pe Diagnostics provides home-based diagnostic and healthcare-support services, which may include:
- Blood tests and laboratory services
- X-ray services
- ECG services
- PFT services
- EEG services
- ENMG services
- Holter monitoring
- Sleep studies
- NST services
- Physiotherapy
- Doctor home visits
- Other diagnostic and healthcare services displayed on GPD Platforms
The GPD Platforms support service booking, scheduling, payment, professional assignment, home-visit management, report delivery, customer communication and healthcare operations.
The GPD Platforms do not independently diagnose medical conditions, prescribe medication, recommend treatment or replace consultation with a qualified healthcare professional.
Reports, test results, prescriptions and clinical interpretations are prepared or issued by qualified healthcare professionals, laboratories or diagnostic service providers, as applicable.
2. Applications and User Categories
2.1 Customer Application and Website Dashboard
The customer application and website dashboard may allow users to:
- Create and manage an account
- Book diagnostic and healthcare services
- Book services for themselves or an authorised family member or dependent
- Enter patient and service information
- Add or manage service addresses
- Schedule or reschedule home visits
- Make online payments
- View payment status
- Track appointments and services
- Receive service-related notifications
- Upload prescriptions and supporting documents
- View and download reports
- Contact customer support
- Correct account information
- Download eligible records
- Delete their account and eligible personal data
2.2 GPD Connect
GPD Connect is an authorised-access application intended for doctors, phlebotomists, radiology technicians, ECG technicians, diagnostic professionals and other approved healthcare personnel.
GPD Connect may allow authorised users to:
- View assigned appointments
- View information required to perform an assigned service
- Manage daily schedules
- Update appointment status
- Update visit status
- Update collection or payment status
- Schedule or reschedule home visits
- Upload service records, reports or supporting documents
- Record service completion
- Coordinate with GPD operations personnel
- View authorised service history
- Track assigned healthcare services
GPD Connect does not provide automated diagnosis, clinical decision support or treatment recommendations.
2.3 GPD Operations Application
The GPD operations application is intended for authorised GPD employees, managers and operations personnel. The operations application may allow authorised users to:
- View customer bookings
- Assign doctors, technicians or phlebotomists
- Schedule and coordinate home visits
- Track appointment and service status
- View payment status
- Manage daily operational schedules
- Communicate with customers and professionals
- Support service delivery
- Resolve service-related issues
- Review authorised operational records
- Maintain service and assignment history
Access to professional and operations applications is restricted to authorised personnel.
3. Personal Data We Collect
The information collected depends on the GPD Platform used, the user's role and the service requested.
3.1 Identity and Contact Information
We may collect:
- Full name
- Registered mobile number
- Email address
- Date of birth or age
- Gender, where relevant to the requested service
- Account identifier
- Profile photograph, where provided
- Alternate contact information
- Emergency contact information
- Relationship to a patient or dependent
3.2 Patient and Dependent Information
Where a customer books a service for another person, we may collect:
- Patient's name
- Patient's age or date of birth
- Gender
- Relationship to the account holder
- Contact information
- Service address
- Relevant prescription or service details
- Diagnostic reports
- Appointment and service history
The person making the booking confirms that they are authorised to provide the patient's information and request the applicable service.
3.3 Address and Location Information
We may collect:
- Home or service address
- Billing address
- Landmark
- Postal code
- Service-delivery instructions
- Approximate or precise device location, where permission is granted
- Location of an assigned professional during an active service or home visit, where operationally required
Location information is used for service delivery, professional assignment, route coordination, visit tracking and safety. Where technically available, customers may manually enter an address instead of granting device-location access.
3.4 Health and Diagnostic Information
Depending on the service requested, we may collect or process:
- Diagnostic services booked
- Prescription copies
- Diagnostic reports
- Test results
- Referring doctor information
- Symptoms or service notes voluntarily provided
- Medical information necessary to perform the requested service
- Previous service information
- Sample collection details
- Appointment records
- Service-completion information
- Relevant patient instructions
- Uploaded healthcare documents
We seek to collect only the health information reasonably required to book, coordinate, perform, document or support the requested service.
3.5 Appointment and Service Information
We may collect:
- Booking number
- Service selected
- Appointment date and time
- Assigned professional
- Visit status
- Rescheduling or cancellation information
- Service notes
- Sample status
- Report status
- Service-completion status
- Customer feedback
- Complaint or support history
3.6 Payment and Transaction Information
We may collect or receive:
- Order number
- Transaction identifier
- Payment amount
- Payment date and time
- Payment status
- Payment method category
- Invoice information
- Refund status
- Chargeback or dispute status
- Billing information
- Payment verification information
Online payments may be processed through third-party payment service providers, including Razorpay and Cashfree Payments.
Payment credentials such as complete card numbers, CVV numbers, UPI PINs, net-banking passwords and similar confidential payment authentication information are entered directly into the payment provider's secure payment interface.
GPD does not intentionally store complete card credentials, CVV numbers, UPI PINs or net-banking passwords in its database.
3.7 Healthcare Professional and Workforce Information
For doctors, technicians, phlebotomists, employees and authorised service personnel, we may collect:
- Full name
- Mobile number
- Email address
- Employee or professional identifier
- Role and department
- Professional qualifications
- Registration or licence details, where applicable
- Identity-verification documents
- Profile photograph
- Work availability
- Daily schedule
- Assigned-service history
- Service-completion information
- Attendance or visit information
- Payment collection status
- Reimbursement or payout information
- Location during assigned services
- Account and activity records
- Security and access logs
3.8 Camera, Photo and Document Access
With user permission, GPD Platforms may access the device camera, photo library or document storage for purposes such as:
- Uploading a prescription
- Uploading a diagnostic report
- Uploading an identity or professional document
- Capturing proof of service
- Adding a profile photograph
- Uploading a referral document
- Sharing a document with customer support
GPD Platforms should access only the files selected by the user or reasonably required for the requested function.
3.9 Device, Technical and Usage Information
We may collect:
- Device type and model
- Operating system
- Application version
- IP address
- App or device identifiers
- Login date and time
- Session information
- Security events
- Crash reports
- Error logs
- Features accessed
- App performance information
- Account activity logs
This information is used for account security, fraud prevention, troubleshooting, service reliability and platform improvement.
3.10 Communication Information
We may collect and retain communications made through:
- Customer-support calls
- SMS
- In-app communication
- Push notifications
- WhatsApp, where selected or permitted by the user
- Support forms
- Complaints
- Feedback submissions
- Grievance requests
4. How We Collect Personal Data
We may collect information:
- Directly from the user
- When an account is created
- When a service is booked
- When a payment is made
- When a document is uploaded
- When a user contacts customer support
- When a service is assigned or completed
- From an authorised family member or representative
- From an assigned doctor, technician or phlebotomist
- From diagnostic laboratories and healthcare providers
- From payment service providers
- Through permissions granted by the user
- Automatically through security, technical and usage logs
5. Purposes for Which We Use Personal Data
We may use personal data to:
- Create and authenticate user accounts
- Verify mobile numbers and email addresses
- Book diagnostic and healthcare services
- Schedule or reschedule appointments
- Assign healthcare professionals
- Coordinate home visits
- Confirm service addresses
- Communicate with customers
- Process payments
- Generate invoices
- Process refunds
- Verify payment status
- Collect samples
- Perform requested services
- Upload and deliver reports
- Enable report downloads
- Maintain service history
- Provide customer support
- Investigate complaints
- Ensure patient and professional safety
- Prevent fraud
- Prevent unauthorised account access
- Maintain cybersecurity
- Troubleshoot technical issues
- Maintain operational and security logs
- Improve app and website performance
- Comply with medical, diagnostic, payment, taxation, accounting, regulatory and legal obligations
- Establish, exercise or defend legal claims
- Respond to lawful government or regulatory requests
We do not use medical reports, prescriptions, diagnostic results or identifiable health information for data brokerage, behavioural advertising or unrelated advertising profiling.
6. Consent and User Choices
Where consent is required, GPD will request consent through a clear affirmative action. Users may:
- Decline optional permissions
- Withdraw optional consent
- Disable device-location access
- Choose files or photographs to upload
- Opt out of promotional communication
- Correct account information
- Request access to their data
- Download available reports
- Request account and data deletion
Withdrawal of consent does not affect processing that was lawfully completed before consent was withdrawn.
Certain GPD Platform functions may not work where information or permissions necessary to provide the requested service are not provided.
Transactional messages related to OTPs, appointments, payments, reports, account security, service delivery or deletion may continue where necessary to complete the requested service or comply with applicable obligations.
7. Protection of Medical Reports and Confidential Information
Medical reports, prescriptions and confidential healthcare information stored in the GPD database are encrypted.
Access to such information is controlled through authenticated accounts and role-based permissions. After a report is finalised and released:
- It is made available to the relevant customer through their authenticated account
- It is not publicly accessible
- It is not available to unrelated professionals or operations personnel
- Authorised personnel may access it only where required for upload, validation, correction, customer support, service delivery, security investigation or legal compliance
- Administrative access is restricted to authorised personnel
- Access may be monitored and recorded where technically implemented
Customers are responsible for protecting their passwords, OTPs, registered devices and downloaded report copies. Users should not share account credentials with another person.
8. Role-Based Access Controls
Access to personal and health information is limited according to the user's authorised role.
Doctors, Technicians and Phlebotomists
Assigned healthcare professionals may access only the information reasonably necessary to perform, update or complete an assigned service.
Operations Personnel
Operations personnel may access booking, contact, address, scheduling, payment-status and service-status information required to coordinate the service.
Operations personnel should not access the clinical contents of reports except where access is specifically authorised for report delivery, correction, customer support, security, legal compliance or service resolution.
System Administrators
Restricted system-administrator access may be provided where necessary to:
- Maintain platform security
- Resolve technical incidents
- Correct system errors
- Restore services
- Investigate unauthorised access
- Comply with lawful requirements
Professional and operations users must use individually assigned accounts. Account credentials must not be shared.
9. Sharing and Disclosure of Personal Data
GPD may share limited information with the following recipients where necessary.
9.1 Healthcare Professionals and Diagnostic Providers
Information may be shared with:
- Doctors
- Phlebotomists
- Radiology technicians
- ECG technicians
- Diagnostic laboratories
- Radiology centres
- Other authorised healthcare professionals
Only information reasonably necessary to complete the requested service should be shared.
9.2 Payment Service Providers
Payment and transaction data may be processed by:
- Razorpay
- Cashfree Payments
- Banks
- Card networks
- UPI service providers
- Payment-processing partners
- Fraud-prevention providers
These providers may process payment information under their own privacy policies, regulatory obligations and security requirements.
9.3 Technology and Operational Service Providers
We may use contracted service providers for:
- Cloud hosting
- Database infrastructure
- Application hosting
- Authentication
- OTP delivery
- Email delivery
- SMS delivery
- Push notifications
- Mapping and location services
- Customer support
- Cybersecurity
- Analytics
- Error reporting
- Backup and recovery
- Communication services
These providers may process information only where required to provide contracted services and are expected to maintain appropriate confidentiality and security protections.
9.4 Legal and Regulatory Disclosures
Information may be disclosed where reasonably necessary to:
- Comply with applicable law
- Respond to a court order
- Respond to a lawful government or regulatory request
- Protect the safety of patients, users or healthcare professionals
- Investigate fraud
- Investigate a cybersecurity incident
- Resolve a dispute
- Establish, exercise or defend legal claims
- Meet medical, taxation, accounting, insurance or regulatory requirements
9.5 Business Reorganisation
If GPD undergoes a merger, acquisition, restructuring, financing or transfer of business, relevant data may be transferred subject to applicable confidentiality, security and legal requirements.
10. Information We Do Not Sell
GPD does not sell:
- Medical reports
- Prescriptions
- Diagnostic results
- Patient health information
- Customer identity information
- Professional account information
We do not share identifiable health information with advertising networks or data brokers for targeted advertising.
11. Cookies and Website Technologies
The Ghar Pe Diagnostics website may use cookies and similar technologies for:
- Essential website functionality
- Account sessions
- Security
- User preferences
- Performance monitoring
- Analytics
- Consent-based marketing
Non-essential cookies should be used only in accordance with applicable consent requirements.
Analytics or marketing tools must not be provided with the contents of medical reports, prescriptions, diagnostic results or other confidential clinical records.
Users may control cookies through the website cookie preferences and browser settings.
12. Data Retention
GPD follows a standard 12-month retention framework for eligible customer-facing information, subject to legal and operational exceptions.
12.1 Account Information
Eligible customer account information may be retained while the account remains active and for up to 12 months from the user's last account activity, unless deleted earlier at the user's request or retained longer for a lawful purpose.
12.2 Reports and Prescriptions
Customer-accessible reports and prescriptions may remain available for up to 12 months from the date they are uploaded or released.
Before eligible reports or prescriptions are scheduled for deletion, GPD will attempt to notify the registered user at least 30 days in advance through:
- In-app or push notification
The notification will advise the user to download any records they wish to retain.
Failure to receive the notification because of outdated contact details, disabled notifications, email filtering or technical delivery failure does not necessarily extend the retention period.
12.3 Appointment and Service Information
Eligible appointment and service information may be retained for up to 12 months from service completion, cancellation or the last related activity.
12.4 Professional and Operations Information
Professional and operations account information may be retained while the individual remains authorised and for up to 12 months following account deactivation, unless longer retention is required for employment, payment, medical, audit, security, dispute or legal purposes.
12.5 Information That May Be Retained for Longer
Certain information may be retained beyond 12 months where necessary for:
- Applicable medical-record obligations
- Diagnostic or laboratory compliance
- Accreditation requirements
- Payment reconciliation
- Refunds and chargebacks
- Taxation and accounting
- Insurance claims
- Fraud prevention
- Cybersecurity
- Internal or regulatory audits
- Complaint resolution
- Legal proceedings
- Establishment, exercise or defence of legal claims
- Compliance with a court, government or regulatory direction
Information retained for such purposes will be access-restricted and will not remain available through a deleted customer account. It will be deleted or anonymised when the applicable retention requirement ends.
12.6 Backup Copies
Following deletion from active systems, limited copies may temporarily remain in protected backups until those backups are overwritten through the normal backup lifecycle.
Backup copies will not be restored for ordinary business use following a valid deletion request, except where necessary for cybersecurity, disaster recovery, legal compliance or investigation of an incident.
13. Account and Data Deletion
13.1 Customer Mobile Application
Customers can initiate deletion through:
Profile → Privacy and Data → Delete Account and Data
Before confirmation, the application will display a deletion notice explaining:
- Deletion is permanent
- Deleted information cannot be recovered
- Reports and prescriptions should be downloaded before deletion
- Eligible account and personal data will be deleted
- Certain legally required records may be retained
- Retained records will not remain accessible through the account
- Deletion does not automatically generate a refund
The user must complete the required confirmation step before deletion begins.
13.2 Customer Website Dashboard
Customers can initiate deletion through:
Account Settings → Privacy and Data → Delete Account and Data
The website dashboard will display the same permanent-deletion notice and confirmation process.
13.3 Deletion Request From This Privacy Policy Page
Users can request deletion outside the application by selecting the Request Account and Data Deletion button or form displayed on this page. The deletion form should request:
- Full name
- Registered mobile number
- Registered email address
- Relevant GPD application or platform
- Reason for deletion, optional
- Confirmation that reports have been downloaded
- Confirmation that the user understands deletion is permanent
- Submission of the deletion request
GPD may verify the requester's identity through OTP, registered email, registered mobile number or another reasonable verification process.
13.4 Email Deletion Request
Where the online form is unavailable, users may email info@gharpediagnostics.com with the subject line "Account and Data Deletion Request". The request should include:
- Full name
- Registered mobile number
- Registered email address
- Relevant GPD application
- A clear request to delete the account and associated data
13.5 Professional and Operations Accounts
Doctors, technicians, phlebotomists, employees and operations personnel may request account closure through:
- The account or privacy section of the relevant application
- Their authorised GPD administrator
- Email to info@gharpediagnostics.com
Professional, assignment, service, payment, employment, security and audit records may be retained where necessary for legitimate operational, medical, contractual, security or legal purposes.
13.6 What Will Be Deleted
Subject to identity verification and lawful retention requirements, GPD will automatically delete or irreversibly anonymise eligible information from active systems, including:
- Account profile information
- Login credentials controlled by GPD
- Saved addresses
- User preferences
- Eligible uploaded files
- Eligible reports and prescriptions
- Eligible appointment information
- Eligible service information
- Eligible app activity connected to the account
- Other personal information no longer required
13.7 What May Be Retained
GPD may retain limited records where required for:
- Medical-record obligations
- Diagnostic compliance
- Payments
- Refunds
- Chargebacks
- Taxation
- Accounting
- Insurance
- Fraud prevention
- Cybersecurity
- Audits
- Complaints
- Disputes
- Legal proceedings
- Compliance with applicable law
Retained data will be isolated or access-restricted where reasonably possible and will not remain available through the deleted account.
13.8 Effect of Deletion
After confirmed deletion:
- The user's account will be deactivated
- Account access will be revoked
- Eligible data will be permanently deleted or anonymised
- Eligible reports will no longer be available
- Legally retained information will be access-restricted
- The user may receive confirmation through registered contact details
Deleted eligible data cannot be restored after it has been removed from active systems and applicable backup cycles.
Deleting an account does not automatically cancel an appointment or create a refund. Appointment cancellation and refunds are handled under the applicable cancellation and refund terms.
14. Data Download
Before scheduled or user-requested deletion, customers should download reports through: Account → Reports → Download
Where available, customers may download:
- Diagnostic reports
- Prescriptions
- Invoices
- Booking information
- Other downloadable records
Users may also contact GPD to request a copy of eligible personal information, subject to identity verification and applicable legal restrictions.
15. Correction and Updating of Information
Users may update certain information through their account settings.
Users may request correction, completion or updating of information by contacting GPD.
We may require identity verification before changing:
- Identity information
- Patient information
- Medical information
- Professional credentials
- Payment information
- Transaction records
Historical medical or transaction records may not be altered where retention of the original record is legally or operationally required. Corrections may instead be recorded through an authorised amendment or supplementary entry.
16. Security Measures
GPD uses reasonable technical, administrative and organisational safeguards appropriate to the nature of the information processed. These measures may include:
- Encryption of medical reports and prescriptions stored in the database
- Authenticated account access
- Role-based permissions
- Restricted administrative access
- Secure communication between applications and servers
- Access revocation
- Security monitoring
- Protected backups
- Database security controls
- Confidentiality obligations for authorised personnel
- Periodic review of user permissions
- Incident investigation procedures
No website, application, network, transmission method or electronic storage system can be guaranteed to be completely secure.
Users should immediately contact GPD if they suspect:
- Unauthorised account access
- Loss of a registered device
- Compromise of a password or OTP
- Unauthorised disclosure of a report
- Suspicious account activity
17. Data Security Incidents
Where GPD becomes aware of a data-security incident, it may:
- Investigate the incident
- Contain unauthorised access
- Secure affected systems
- Maintain incident records
- Take corrective action
- Notify affected users where required
- Notify relevant authorities where required by applicable law
18. Children and Dependent Patients
The GPD customer application is not intended for independent account creation by children.
A parent, lawful guardian or authorised adult may book a service for a child or dependent.
The account holder confirms that they are authorised to:
- Provide the dependent's information
- Upload relevant prescriptions
- Request the diagnostic service
- Receive reports
- Manage the dependent's information
GPD may request age, guardian or relationship information where reasonably necessary.
19. Marketing and Service Communications
GPD may send transactional communications relating to:
- OTP verification
- Account security
- Booking confirmation
- Appointment reminders
- Professional arrival or visit updates
- Payment confirmation
- Refund status
- Report availability
- Scheduled data deletion
- Account deletion
- Customer support
Promotional communication will be sent only where permitted.
Users may opt out of promotional communication through the unsubscribe mechanism, account preferences or by contacting GPD.
Opting out of promotional communication will not stop essential transactional or service-related messages.
Health information and diagnostic report contents will not be used for unrelated promotional targeting.
20. Third-Party Websites and Services
GPD Platforms may include links to or integrations with third-party services.
Third-party providers operate under their own terms and privacy policies.
GPD is not responsible for the independent privacy practices of third-party websites or applications that are not controlled by GPD.
21. User Privacy Rights
Subject to applicable law, users may request:
- Access to their personal data
- Information about how their data is processed
- Correction of inaccurate data
- Completion of incomplete data
- Updating of outdated data
- Withdrawal of consent
- A copy of eligible data
- Deletion of their account
- Erasure of eligible personal data
- Grievance redressal
Requests may be subject to identity verification and lawful retention requirements.
23. Changes to This Privacy Policy
GPD may update this Privacy Policy when:
- Services change
- Applications change
- New features are introduced
- Payment providers change
- Technology providers change
- Security practices change
- Applicable laws or platform requirements change
Material changes may be communicated through:
- The website
- An in-app notice
- Push notification
- An updated effective date
Where additional consent is required, GPD will request consent before using information for the new purpose.
24. Governing Law and Jurisdiction
This Privacy Policy is governed by applicable laws of India.
Subject to applicable law, disputes arising from this Privacy Policy will be subject to the jurisdiction of the competent courts in Bengaluru, Karnataka.
22. Privacy and Grievance Redressal
Privacy, data-protection, account-deletion and security requests may be submitted to:
Salekcha Healthcare Private Limited
Operating under the brand name Ghar Pe Diagnostics
Address: 6 & 7, Promenade Road, Near Coles Park, Bangalore - 560005, Karnataka, India
Privacy and grievance email: info@gharpediagnostics.com
Phone: +91 9611508886
Users should include:
- Full name
- Registered email address
- Registered mobile number
- Relevant GPD application or service
- Clear description of the request
GPD may verify the user's identity before acting on a privacy or deletion request. We will review and respond to valid requests within the period required under applicable law.
25. Contact Confirmation
For privacy, data-access, data-correction, account-deletion or security-related enquiries, contact:
Ghar Pe Diagnostics
Salekcha Healthcare Private Limited
Email: info@gharpediagnostics.com
Phone: +91 9611508886
Address: 6 & 7, Promenade Road, Near Coles Park, Bangalore - 560005, Karnataka, India

