Legal
Privacy Policy
How Treato collects, uses, shares, and protects your personal and health information, and the rights you have as a Data Principal.
Last updated: July 2, 2026
Introduction
Treato Private Limited ("Treato", "we", "our", or "us") is the Data Fiduciaryresponsible for the personal data processed through our mobile application, website, and related services (collectively, the "Services"). This Privacy Policy explains what data we collect, why, who we share it with, how long we keep it, and the rights you have as a Data Principal.
We handle your data in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules, 2025, along with applicable healthcare and telemedicine regulations. Because Treato is a healthcare platform, much of the data we handle issensitive health information, which we treat with heightened care.
Scope & Who This Applies To
This Policy applies to everyone who interacts with Treato and covers both our website and mobile applications:
- Patients & users who book appointments, consult doctors, or use health tools and content.
- Doctors, clinics & healthcare providers who list, manage schedules, and consult through Treato.
- Creators & wellness educators who publish health content on our platform.
- Visitors who browse our website without an account.
Where a specific service has its own supplemental notice (for example,telemedicine consent), that notice applies together with this Policy.
Key Definitions
- Personal Data — any data about an identifiable individual.
- Sensitive / Health Data — information about your physical or mental health, conditions, prescriptions, and care; handled with heightened protection.
- Data Principal — you, the individual the data is about.
- Data Fiduciary — Treato, which determines the purpose and means of processing.
- Data Processor — a vendor that processes data on our behalf under contract.
- Processing — any operation on data (collection, storage, use, sharing, deletion).
- De-identified / Aggregated Data — data that no longer identifies you, used for analytics and research.
Legal & Regulatory Framework
We process personal data in accordance with applicable Indian law, including:
- The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
- The Information Technology Act, 2000 and the SPDI Rules, 2011 (to the extent applicable).
- The Telemedicine Practice Guidelines, 2020 and applicable National Medical Commission regulations.
- Applicable medical-record retention and healthcare standards.
Consent & Legal Basis
We process your personal data on the basis of your consent and, where applicable, for legitimate uses and legal obligations permitted under the DPDP Act. When we ask for consent, we tell you what we collect and why, in clear language.
- Consent is specific, informed, and freely given, and is requested at or before the point of collection.
- You may withdraw consent at any time — through in-app settings or by emailing our Grievance Officer. Withdrawing consent is as easy as giving it.
- Withdrawing consent stops future processing for that purpose; it does not affect processing already carried out, or data we must retain by law (see Data Retention).
- Some features (e.g., booking a consultation or accessing records) cannot function without the related data — declining or withdrawing consent may limit those features.
Information We Collect
We collect information you provide directly, and information collected automatically when you use the Services:
Personal Information
- Identity information (name, date of birth, gender, profile photo)
- Contact information (email address, phone number, address)
- Health & medical information (symptoms, conditions, prescriptions, lab reports, consultation history) — sensitive data processed with your consent
- Payment and billing information (processed by our payment partner)
- Communications with healthcare providers and support
Automatically Collected
- Device information (device type, operating system, app-generated identifiers)
- Usage & product-interaction data (features used, time spent, interaction patterns)
- Location data (only with your permission)
- Log data (IP address, browser type, access times)
How & From Where We Collect
- Directly from you — when you create an account, complete your profile, book or attend a consultation, chat, or contact support.
- Automatically — through your use of the Services (device, usage, and log data).
- From healthcare providers & clinics — e.g., prescriptions, diagnoses, and consultation notes generated during your care.
- From people acting for you — a parent/guardian managing a dependent's account, or someone booking on your behalf.
- From service providers — e.g., payment status from our payment partners.
How We Use Your Information
Service Delivery
- Provide, maintain, and improve our Services
- Process appointments, consultations, and payments
- Send notifications, reminders, and updates
- Respond to inquiries and support requests
Research & Improvement
- Analyze usage patterns to improve UX
- Develop new features and services
- Conduct internal research with aggregated/de-identified data
- Maintain safety, security, and prevent fraud/abuse
Purpose Limitation & Data Minimization
We collect only the data we need for the purposes described in this Policy, and we use it only for those purposes or compatible ones. If we ever want to use your data for a new, incompatible purpose, we will update this Policy and, where the law requires it, ask for your consent first. We do not repurpose your health data for advertising.
Automated Processing & AI
Some features use automated processing and artificial intelligence — for example, suggesting a relevant specialty from symptoms you describe, or improving search and recommendations.
- AI suggestions are assistive only and are not a medical diagnosis or a substitute for professional advice from a qualified doctor.
- We do not use your data for solely automated decisions that produce legal or similarly significant effects without a human in the loop.
- We do not use your health data to train advertising models or profile you for third-party advertising.
Data Sharing & Disclosure
- Healthcare Providers: To facilitate appointments, consultations, and continuity of care.
- Service Providers (Data Processors): Vendors who process data on our behalf under contract (see Sub-Processors below).
- Payments & payouts: Our payment partners process transactions and payouts; we do not store full card details.
- Legal & Safety: When required by law, court order, or to protect rights, safety, and prevent harm.
- Business Transfers: In a merger, acquisition, or asset sale, with continued protection of your data.
We do not sell your personal data, and we do not share it with data brokers or use it to track you across other companies' apps or websites for advertising.
Third-Party Sub-Processors
We use trusted third-party providers to operate the Services. Each processes only the data needed for its function, under a data processing agreement. Our key sub-processors are:
PostHog (EU-hosted)
Product usage analytics and masked, sampled in-app session replay.
Sentry
Crash and error diagnostics for app stability.
Crisp
In-app support chat (name, contact details, and messages when you contact support).
Razorpay
Payment processing.
Cashfree
Payments and payouts (e.g., doctor wallet withdrawals), including bank-account verification.
Stream
In-app chat and video consultations.
Cloud hosting & storage
Secure hosting and file storage.
Messaging providers
SMS/WhatsApp and push notifications for OTP, reminders, and updates.
International Data Transfers
We operate primarily in India, and your data is stored and processed here wherever practicable. Some of our sub-processors may process limited data on servers located outside India (for example, EU or US regions). Where data is transferred internationally, we do so in accordance with the DPDP Act and rely on contractual and security safeguards to protect it. We do not transfer personal data to any country restricted by the Government of India.
Analytics, Session Replay & Your Choices
To improve the app, we collect product-usage data linked to your account and may record masked, sampled in-app session replays (screen interactions). Text inputs and images are masked, and sensitive health screens (such as medical records, prescriptions, chats, and your Health ID) are excluded from recording.
- Analytics is first-party and used only to operate and improve the Services — not for cross-app advertising.
- You can turn off analytics and session replay anytime in the app under Settings → Privacy & Security → Analytics & usage data.
- Disabling it stops all analytics and replay collection from your device.
Cookies & Similar Technologies
On our website we use strictly necessary cookies to keep you signed in and secure, and limited analytics cookies to understand usage. Our mobile apps use secure on-device storage rather than cookies. You can control cookies through your browser settings; blocking strictly necessary cookies may affect core functionality. See our Cookie Policy for details.
Data Security
We implement encryption in transit and at rest, access controls, audit logging of access to medical records, and regular security reviews. No method of transmission or storage is 100% secure, but we take every reasonable measure to protect your data.
Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected users in accordance with the DPDP Act and its rules, and take prompt steps to contain and remediate the incident.
Data Retention
We keep data only as long as necessary for the purpose it was collected, or as required by law. When you delete your account, your identity is anonymized after a 90-day grace period; records we must keep are retained de-linked from your identity.
- Medical records (prescriptions, lab reports, consultations) — at least 3 years (healthcare regulations).
- Transaction & payment records — at least 1 year (DPDP Rules).
- Account & profile data — until deletion + 90-day grace, then anonymized.
- Usage & analytics data — removed on deletion; opt-out available anytime.
Your Rights
As a Data Principal under the DPDP Act, you have the right to:
Access
Request a summary and copy of your personal data.
Correction
Correct or complete inaccurate data.
Erasure
Delete your account — deactivated immediately and permanently erased after a 90-day grace period; cancel within 90 days by logging back in.
Withdraw consent
Stop further processing at any time.
Portability
Receive your data in a structured format.
Nominate
Nominate another person to exercise your rights in case of death or incapacity.
Grievance redressal
Raise a complaint and receive a timely response.
Opt-out
Unsubscribe from marketing communications.
To exercise any right, use in-app settings or email our Grievance Officer (below). We will verify your identity and respond within the timelines prescribed under applicable law. You may also complain to the Data Protection Board of India if you are not satisfied with our response.
Children & Minors
Some Treato features let a parent or guardian manage healthcare for a dependent, including a minor. Where we process a child's data:
- We require verifiable parental/guardian consent and the account is managed by that adult.
- We do not conduct behavioural tracking, profiling, or targeted advertising directed at children.
- A child's data is used only to provide the requested healthcare services.
- A parent/guardian may access, correct, or delete a managed minor's data at any time.
We do not knowingly allow children to create independent accounts. If you believe a child has provided data without proper consent, contact our Grievance Officer to have it removed.
Grievance Officer
In line with the DPDP Act and the Information Technology Rules, you can reach our Grievance Officer for any privacy question, request, or complaint. We aim to acknowledge complaints promptly and resolve them within the timelines prescribed under applicable law.
Grievance Officer, Treato Private Limited
Email: [email protected]
Data of Doctors, Clinics & Creators
If you join Treato as a doctor, clinic, or creator, we process additional professional information to operate your presence on the platform:
- Professional details (qualifications, registration/IMR number, specialties, experience, clinic affiliations).
- Practice information (schedules, fees, locations) and consultation activity.
- Payout and verification details (bank account, KYC) processed via our payout partner.
- Public profile content (bio, photo, intro video, reviews) shown to patients.
Some professional information (e.g., name, specialty, clinic, reviews) is public so patients can find and choose a provider.
Marketing & Communications
- Transactional messages (OTP, booking confirmations, reminders, receipts) are part of the Service and are always sent.
- Promotional messages (offers, health tips, product news) are sent only with your consent, and you can opt out any time.
- WhatsApp messages are sent only where you have given WhatsApp consent, and you can revoke it.
- You can manage notification preferences in-app under Settings, or unsubscribe via the link/instructions in each message.
Anonymized & Aggregated Data
We may create de-identified or aggregated data that cannot reasonably be used to identify you, and use it for analytics, research, service improvement, and reporting. Because this data is not personal data, it is not subject to the consent and rights described above. We do not attempt to re-identify de-identified data.
How We Respond to Legal Requests
We may access, preserve, and disclose your information to law enforcement, courts, regulators, or other authorities if we have a good-faith belief it is required by law or legal process, or is necessary to detect or prevent fraud, protect the safety of any person, or protect the rights and property of Treato and our users. Where permitted, we review such requests and object to those that are overbroad or improper.
Third-Party Links & Services
The Services may link to or integrate third-party websites and services that we do not control. Their privacy practices are governed by their own policies, not this one. We encourage you to review the privacy policy of any third party before providing your information.
Your Responsibilities
- Keep your login credentials confidential and your device secure.
- Provide accurate information and keep your profile and health details up to date.
- Only share another person's data (e.g., a dependent's) if you are authorized to do so.
- Notify us promptly if you suspect unauthorized access to your account.
Do Not Track & Global Privacy Signals
Because we do not track you across other companies' apps or websites for advertising, our Services respond to standard privacy signals by simply not engaging in cross-context tracking. You can additionally control analytics and session replay in-app, and manage cookies through your browser.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy and revise the "Last updated" date, and for material changes we will provide a prominent notice and, where required by law, seek fresh consent. Continued use of the Services after an update constitutes acceptance of the revised policy to the extent permitted by law.
Governing Law & Jurisdiction
This Privacy Policy is governed by the laws of India. Any disputes are subject to the exclusive jurisdiction of the competent courts in India, without regard to conflict-of-law principles.
Contact Us
Treato Private Limited
Privacy queries: [email protected]
Data Protection Officer: [email protected]
Grievance Officer: [email protected]
