Privacy Policy
Your privacy is important to us. This policy explains how we collect, use, and protect your personal and health information.
Important: If you are located in a jurisdiction with specific privacy laws (India's DPDP Act, EU's GDPR, California's CCPA), additional rights and obligations may apply.
This Privacy Policy describes how Zoom Doctor ("Zoom Doctor", "we", "our", or "us") collects, uses, discloses, transfers, stores, and protects personal information when you use our mobile application and related services (the "App" or the "Services"). The policy explains the choices you can make about your information and how you can exercise your privacy rights.
Important: If you are located in a jurisdiction with specific laws (for example India's Digital Personal Data Protection Act, the European Union's GDPR, or the California Consumer Privacy Act), additional rights and obligations may apply. We describe those rights below and the ways we comply with applicable rules. Please read this Privacy Policy carefully.
1. Who we are / Controller details
- App name: Zoom Doctor
- Operated by: Strio Healthcare
- Registered address: 212 Sahajanand Estate, Behind Lalji-Mulji Transport, Sarkhej, Ahmedabad, Gujarat - 382210
- Email for privacy inquiries: zoomdoctor1@gmail.com
- DPO / Privacy contact: shibambiswas@strio.in
2. Scope — where this policy applies
This policy applies to personal data collected when you:
- Use the Zoom Doctor mobile app (including features to search doctors/clinics, view profiles, book appointments, and message providers)
- Use our website pages that link to this policy
- Communicate with us (email, chat, support)
- Interact with third-party plugins or integrations we provide inside the App
Note: This policy does not apply to personal data processed by doctors, clinics, or third-party booking partners after a referral or booking is completed — you should review the privacy terms of those providers separately.
3. Summary — what we do with your data (short)
- We collect identity, contact, device, health-related and appointment information so you can discover doctors, view clinic details, and book appointments
- We access and use User Data to provide, personalise and improve the user experience. To achieve this, we may share data with trusted third-party service providers and partners (for example: appointment booking processors, analytics providers, cloud hosts, payment processors, messaging providers). Any such sharing is limited to what is necessary and is governed by contractual, technical, and organizational safeguards. (See Section 8: Sharing & third parties below.)
4. Types of information we collect
We collect information you provide directly and information collected automatically or obtained from third parties. We use the following categories:
A. Information you provide directly
- Account & identity data: name, email, phone number, profile photo, password (hashed)
- Profile & professional data: for doctors/clinics that register: practice name, qualifications, specialisations, medical registration number, clinic address, clinic hours, fees, insurance acceptances and public profile data
- Booking information: appointment date/time, doctor's name/clinic, symptoms or reason for visit (if you enter them), any messages exchanged via the App
- Health-related information: details you voluntarily enter that relate to your health (symptoms, medical history, prescriptions) — Note: health data is sensitive personal data. We will only collect this if you choose to provide it and we will process it with heightened protections. (See Section 6: Legal basis & sensitive data.)
- Payment & billing data: payment card (via third-party processors), billing address, transaction records — processed through payment partners
- Support & feedback: correspondence, support requests, survey responses
B. Information collected automatically
- Usage & analytics: pages/screens visited, features used, timestamps, in-app behavior, crash logs
- Device & technical data: device identifiers (e.g., Advertising ID), OS version, app version, IP address, browser type (for web), mobile network, device model
- Location data: approximate location derived from IP and, where you give permission, precise device location (GPS) to show nearby clinics
- Cookies and similar technologies: for web-based parts of our service we use cookies and local storage for functionality and analytics
C. Information from third parties
- Publicly available profiles (e.g., doctor licensing registries), third-party data enrichment providers, analytics SDKs, and marketing partners
5. How we collect data
- Directly from you: when you register, fill forms, submit a booking, message, upload profile info, or contact support
- Automatically: when you use the App (logs, cookies, SDKs)
- From third parties: doctor registries, clinic partners, analytics providers, advertising networks, identity verification providers
6. Legal basis for processing & special categories (where applicable)
We describe the legal bases for processing personal data depending on applicable law. If your jurisdiction requires a specific legal basis, that law will govern.
- Performance of a contract / provision of services: we process the data necessary to provide the App's core functionality (searching doctors, displaying profiles, booking appointments, processing payments)
- Consent: where required (for example, for processing sensitive health data, precise location, marketing communications), we rely on your explicit consent. You may withdraw consent at any time (see Your rights, Section 12)
- Legitimate interests: for analytics, fraud detection, improving the App and services, and for security — balanced against your privacy rights. We ensure legitimate interest processing is reasonable and not overridden by your rights
- Compliance with legal obligations: when required to comply with court orders, law enforcement requests, or applicable regulations
Sensitive information (health data)
Health and medical information is considered sensitive personal data under many privacy laws. We process sensitive personal data only where you have given explicit consent or where permitted by law for the provision of healthcare-related services, and we apply extra safeguards (limited access, encryption, data minimisation). For processing of such data within India, the Digital Personal Data Protection Act, 2023 applies to digital personal data and contains special protections and obligations; we will handle health data consistent with that Act.
7. Purposes of processing — how we use your data
We use personal data for these core purposes:
- Provide and operate the Service: enabling search, profile display, appointment booking, messaging and payment facilitation
- User account management: registration, authentication, profile updates, account recovery
- Personalisation: tailoring search results, recommended clinics/doctors, location-based suggestions
- Customer support: responding to requests, troubleshooting and dispute resolution
- Communications & notifications: appointment reminders, service updates, transactional emails, and (with consent) marketing/promotional messages
- Analytics & product improvement: analyzing usage to detect bugs, improve features and user experience
- Fraud prevention & security: verifying identities, detecting abuse, and protecting the platform
- Legal & compliance: complying with applicable laws, regulatory investigations, and responding to legal process
- Business operations & third-party services: to partners who provide hosting, analytics, payment processing, messaging, or other infrastructure needs
When we process your data to improve engagement or refine services, we may use aggregated, de-identified, or pseudonymised data; where re-identification is possible or required, protections described in this Policy apply.
10. International transfers & safeguards
Because we operate globally and use third-party cloud and service providers, personal data may be transferred to, stored, and processed in countries outside your jurisdiction. When we transfer data internationally, we use appropriate legal mechanisms and technical safeguards (e.g., standard contractual clauses, encryption, data processing agreements) to protect your information in accordance with applicable law.
11. Data security
We implement industry-standard technical and organisational measures to protect personal data, including: access controls, encryption in transit (TLS) and at rest where feasible, regular security testing, internal audit practices, least-privilege access for employees, and contractual security obligations for processors.
Important: However, no system is 100% secure. If we become aware of a data breach that creates a real risk of harm to you, we will notify affected users and regulators as required by applicable law.
12. Data retention and deletion
We retain personal data as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data type and purpose; typical examples:
- Account data: retained while account active + [X] years after deactivation for fraud prevention and record keeping
- Booking & transaction data: retained for tax and accounting obligations per local law (commonly 3–7 years)
- Support logs and communications: retained as necessary for support and quality improvements
You may request deletion of your account and personal data via the App or by contacting zoomdoctor1@gmail.com. Certain data may be retained in anonymized or aggregated form. For request handling, we will verify your identity before fulfilment.
13. Children & minors
Our Services are not directed to children under 18. We do not knowingly collect personal information from children under 18 without parental or guardian consent. If you believe we have collected data from a child under 18 without appropriate consent, please contact us and we will take steps to delete it.
14. Your rights (how to access, correct, delete, object, port data)
Subject to applicable law, you may have the following rights:
- Access: request a copy of the personal data we hold about you
- Correction: request corrections to inaccurate or incomplete data
- Deletion: request deletion of your personal data where lawful to do so
- Restriction / Objection: object to or request restriction of certain processing (e.g., direct marketing)
- Data portability: request a machine-readable copy of data you provided to us
- Withdraw consent: where processing is based on consent, withdraw consent going forward
To exercise rights, use the in-app settings or contact zoomdoctor1@gmail.com. We will verify your identity before acting on requests and respond within the timeframes required by applicable law.
Jurisdictional rights
If you are an EU resident you may lodge a complaint with an EU supervisory authority; if you are in India you may contact the relevant regulator; California residents have additional rights under CCPA and can submit requests per the mechanisms described above.
15. Marketing communications & opt-out
We will only send marketing communications with your consent (where required). You may opt out of promotional messages by following the unsubscribe link in emails, using in-app settings, or contacting zoomdoctor1@gmail.com. Transactional messages (appointment confirmations, booking reminders) are not optional communications required to run the Service.
16. Data protection for doctors & clinics
If you are a doctor or clinic creating a profile, you represent and warrant you have the right to publish the information submitted and that it complies with local rules. We may verify public credentials using third-party registries. Doctor and clinic profile information intended to be publicly discoverable will appear in search results unless removed in accordance with our profile management features.
17. Third-party links & embedded content
The App may include links, widgets, or embedded content from third parties. Their privacy practices are not controlled by us. Please review the privacy policies of third parties before interacting with their services.
18. Data processors & contracts
Where third parties process data on our behalf, we use written data processing agreements that require processors to implement security measures, restrict further processing, and assist us in responding to data subject requests and breaches. For transfers outside certain jurisdictions, we will use adequate safeguards such as contractual clauses.
19. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our practices or legal requirements. We will post the revised policy in the App and on our website with an updated "Last updated" date. Where required, we will notify users of material changes and (where legally required) obtain consent.
20. Google Play requirements & App store disclosures
We will publish this Privacy Policy in our Google Play Store listing and within the App, and we will keep the Google Play Data Safety form accurate and up to date, disclosing the data we collect and how it's used, consistent with Google Play's developer policies and Data Safety requirements.
21. International & jurisdictional notes (India, EU, California)
- India: The Digital Personal Data Protection Act, 2023 applies to digital personal data processing in India and imposes obligations on data fiduciaries and rights for data principals. Where the Act applies, we will comply with its requirements
- EU / EEA: If you are located in the EU/EEA, you may have rights under the GDPR including access, rectification, erasure, restriction, portability and the right to object. We act as controller of your data for these purposes
- California: California residents have specific rights under the CCPA/CPRA, including the right to request categories of information collected, deletion, and to opt-out of sale/sharing. We comply with applicable California requirements where they apply
If you are located outside India, the EU or California, similar privacy protections may apply under local law.
22. Enforcement, audits & regulatory cooperation
We cooperate with lawful requests from regulators and enforcement agencies, and we may disclose information to comply with local legal obligations. We also conduct regular internal and third-party audits and security assessments to ensure compliance with this Policy and applicable law.
23. How to contact us
For privacy questions, data requests or complaints please contact:
Zoom Doctor (operated by Strio Healthcare)
Email: zoomdoctor1@gmail.com
Address: 212 Sahajanand estate, Behind Lalji-Mulji transport, Sarkhej, Ahmedabad, Gujarat - 382210
If you are not satisfied with our response you have the right to lodge a complaint with your local data protection authority (for example: the European Data Protection Authorities, the Indian Data Protection Regulator once constituted under the DPDP Act, or the California Attorney General for CCPA/CPRA matters).
24. Additional practical examples & FAQs
Can we access your data to improve experience?
Yes. We access and use certain User Data (with appropriate safeguards) to provide essential features (bookings, reminders) and to personalize and improve the App. We only access data necessary for these purposes and limit internal access to authorized personnel.
Will we share data with third parties for engagement & service improvement?
Yes, but only with trusted service providers and partners under contract and technical safeguards. We never "sell" personal data for profit. Any third-party sharing is disclosed in the App and, where required, in the Data Safety form in our Play Store listing.
25. Legal disclaimers & important notes
This Privacy Policy is intended to describe our current practices. It does not create contractual or other legal rights in favour of any person. The policy may be updated periodically; when material changes occur we will notify users as required by law.
Legal Notice
This privacy template is provided for informational purposes and does not constitute legal advice. For a policy tailored to your business model, jurisdictions, and regulatory obligations (especially given the sensitivity of health data), consult with qualified legal counsel before publishing.