Privacy Policy

1. INTRODUCTION

Visit Health Private Limited ("Visit", "Company", "we", "us" or "our") owns and operates the website www.getvisitapp.com, its associated websites, mobile applications, software products, practitioner and member interfaces, APIs, customer support channels, integrations and all related digital platforms and services made available by the Company (collectively, the "Platform" or the "Services").

This Privacy Policy describes how Visit collects, receives, records, stores, organises, uses, shares, discloses, transfers, retains, deletes and otherwise processes personal data in connection with the Services. It applies to personal data relating to individuals who access or use the Services or whose personal data is processed in connection with the Services, including patients, members, dependants, employees, prospective employees, corporate client representatives, insurance and benefits programme participants, healthcare practitioners, prospective users, website visitors, vendors, business partners and any other individual whose personal data is processed by Visit (collectively referred to as "Users" or "you").

This Privacy Policy applies to personal data processed in digital form and to personal data collected in non-digital form that is subsequently digitised in connection with the Services. It explains the categories of personal data we collect, the purposes for which such personal data is processed, the circumstances in which it may be shared, the safeguards adopted by Visit, and the rights available to individuals under applicable law.

This Privacy Policy should be read together with the applicable Terms of Use, enterprise agreements, insurance or employer programme terms, consent notices, just-in-time privacy notices, product-specific privacy notices and any other terms, policies or notices issued by Visit from time to time. Where any such document contains specific privacy terms applicable to a particular Service, programme or feature, those terms shall be read in conjunction with this Privacy Policy.

2. DEFINITIONS

For the purposes of this Privacy Policy, unless the context otherwise requires:

"Applicable Law" means all applicable laws, statutes, rules, regulations, notifications, directions and governmental or regulatory requirements in force from time to time relating to privacy, data protection, cybersecurity, healthcare or the Services.

"Data Fiduciary", "Data Processor", "Data Principal", "Personal Data" and "Processing" shall have the meanings respectively assigned to them under the Digital Personal Data Protection Act, 2023, as amended from time to time.

"Platform" means the websites, mobile applications, software products, APIs, practitioner interfaces, customer support channels and all other digital platforms or services operated by Visit.

"Services" means the healthcare, wellness, insurance, technology, diagnostic, pharmacy, teleconsultation, employee healthcare benefit and other products or services offered or facilitated by Visit.

3. LEGAL BASIS AND COMPLIANCE STATEMENT

This Privacy Policy has been prepared in accordance with applicable laws of India governing the processing and protection of personal data, including, where applicable:

i. The Digital Personal Data Protection Act, 2023 and the rules, notifications and directions issued thereunder, as amended from time to time;

ii. The Information Technology Act, 2000, to the extent applicable;

iii. Directions, advisories and cybersecurity requirements issued by the Indian Computer Emergency Response Team ("CERT-In") and other competent governmental or regulatory authorities;

iv. Applicable healthcare, insurance, employment, taxation, consumer protection, anti-fraud, accounting, record-retention and other sector-specific laws, regulations, standards and contractual obligations governing the Services.

Visit processes personal data only for lawful purposes and implements technical, organisational and contractual measures designed to ensure that such processing is carried out in accordance with applicable law.

Depending upon the nature of the Services, the relevant contractual arrangements and the purposes for which personal data is processed, Visit may process personal data either as an independent Data Fiduciary or as a Data Processor acting on behalf of an employer, insurer, hospital, clinic, healthcare practitioner, corporate client, benefits administrator or another authorised entity. Where Visit processes personal data on behalf of another Data Fiduciary, such processing shall be undertaken in accordance with the applicable contractual arrangements and applicable law.

Nothing contained in this Privacy Policy shall be construed as limiting any statutory rights available to individuals under applicable law or any obligations imposed upon Visit under applicable law.

4. SCOPE

This Privacy Policy applies to the processing of personal data by Visit in connection with the Services. It applies to personal data processed in digital form and to personal data collected in non-digital form that is subsequently digitised, irrespective of the manner in which such personal data is collected, including through the Platform, customer support channels, healthcare providers, enterprise programmes, authorised partners, integrations or other lawful sources.

This Privacy Policy applies only to the processing of personal data carried out by or on behalf of Visit and does not govern the independent processing activities of healthcare practitioners, hospitals, diagnostic laboratories, pharmacies, insurers, employers or other third parties that may process personal data in accordance with their own legal obligations, contractual arrangements or privacy policies.

This Privacy Policy does not apply to:

i. Information that has been irreversibly anonymised or aggregated such that it no longer relates to an identifiable individual or is incapable of identifying an individual;

ii. Publicly available personal data or information made publicly available by the Data Principal or under any law for the time being in force;

iii. Personal data processed by third-party websites, applications, platforms, products or services that are not owned, operated or controlled by Visit, even if such third-party services are accessible through, linked to or integrated with the Platform. Visit is not responsible for the privacy practices or content of such third parties, and users are encouraged to review their respective privacy policies before sharing personal data.

5. CATEGORIES OF PERSONAL DATA

Depending upon the nature of your interaction with the Services, Visit may collect and process the following categories of personal data:

i. Account and identity data: name, username, user ID, profile identifiers, date of birth, age, gender, relationship details of dependants or nominees, employee identification number, membership or policy identifiers, authentication credentials, verification information and other information necessary to create or administer an account.

ii. Contact data: mobile number, email address, postal address, emergency contact details, preferred language and communication preferences.

iii. Health, medical and wellness data: symptoms, medical history, diagnoses, prescriptions, consultation records, treatment information, referral records, laboratory reports, diagnostic reports, medical certificates, vaccination records, allergies, lifestyle information, wellness information, fitness and activity data, step count, heart rate or similar wearable device data (where enabled), medical images, photographs, audio or video consultation records (where applicable), claims-support information and other health-related information provided by you or lawfully received from your employer, insurer, TPA, healthcare practitioner, hospital, diagnostic centre, pharmacy or another authorised person.

iv. Insurance and benefits data: insurance policy details, policy and membership numbers, TPA details, claims information, employer-sponsored healthcare benefits, eligibility information, utilisation information, reimbursement information and other information necessary for administering healthcare benefits.

v. Professional data: where you are a healthcare practitioner or professional using the Services, qualification details, professional registration number, licences, specialisation, clinic or hospital affiliation, availability, experience, professional profile, ratings, credentials and professional communications.

vi. Payment and transaction data: billing details, transaction identifiers, invoices, subscription information, refund information and limited payment-related information necessary to process transactions or reconcile payments. Payment card information is ordinarily processed directly by regulated payment service providers in accordance with applicable industry standards and is not stored by Visit except to the limited extent necessary for reconciliation, fraud prevention, dispute resolution or compliance with applicable law.

vii. Device, technical and usage data: internet protocol (IP) address, device identifiers, browser type, operating system, application version, authentication logs, security logs, crash reports, cookie identifiers, SDK identifiers, approximate location information (where enabled), network information, date and time stamps, time zone and information relating to your access to and use of the Services.

viii. Communication data: customer support requests, chat transcripts, chatbot interactions, in-app messages, email correspondence, call recordings, WhatsApp or SMS communications, survey responses, reviews, ratings, feedback, complaints, grievance records and other communications exchanged with Visit.

ix. Document and verification data: government-issued identification documents, employee records, insurance documents, prescriptions, referral records, medical certificates, invoices, reimbursement documents, verification records and any other documents submitted for identity verification, eligibility determination, lawful service delivery or regulatory compliance.

x. Employment-related data: where processed in connection with employees, consultants or employment applicants, information relating to recruitment, background verification, employment history, attendance, payroll inputs, compensation, statutory benefits, performance management, disciplinary matters, emergency contacts and other information required for employment administration or compliance with applicable law.

xi. Consent, preference and compliance data: records of notices issued, consents obtained or withdrawn, nominations, privacy preferences, communication preferences, grievance requests, account settings and other information maintained for demonstrating compliance with applicable law.

xii. Derived and inferred data: service history, healthcare benefit eligibility indicators, authentication and fraud-prevention indicators, user preferences, engagement metrics, analytics and other information reasonably derived from your use of the Services for improving functionality, security, service delivery and user experience.

Visit collects and processes only such personal data as is reasonably necessary for specified, lawful and legitimate purposes connected with the Services and does not knowingly seek or retain personal data that is unnecessary for those purposes.

6. SOURCES OF PERSONAL DATA

Visit may collect personal data directly from you or, where permitted under applicable law, from the following sources:

i. Your employer, group company, corporate client, insurer, broker, third-party administrator (TPA), corporate benefits administrator or any other organisation through which the Services are made available to you;

ii. Hospitals, clinics, healthcare practitioners, diagnostic centres, laboratories, pharmacies, wellness partners and other healthcare service providers engaged by you or made available through the Services;

iii. Your parent, legal guardian, nominee, authorised representative, family member, dependant, caregiver or any other person duly authorised to provide information on your behalf;

iv. Payment service providers, banking partners, identity verification or KYC service providers, communication service providers, technology vendors, cloud service providers and other authorised business partners supporting the delivery of the Services;

v. Publicly available sources, government authorities, regulators, statutory databases, professional registries, fraud prevention agencies and other lawful sources, where such collection is permitted or required under applicable law;

vi. Integrated platforms and third-party systems, including employer HR systems, insurance platforms, hospital information systems, electronic medical record systems, wellness platforms and other authorised integrations enabled by you or the relevant enterprise customer;

vii. Cookies, software development kits (SDKs), APIs, device permissions, analytics technologies, log files and other technologies deployed on or through the Platform that automatically collect technical, device and usage information during your interaction with the Services.

Where Visit receives personal data from a third party, it expects such third party to have the requisite authority or other lawful basis to disclose such personal data to Visit. Where required under applicable law, Visit shall provide appropriate privacy notices and obtain consent or rely upon another lawful basis before processing such personal data.

7. PURPOSES OF PROCESSING

Visit processes personal data only for specified, lawful and legitimate purposes connected with the provision, administration, improvement and protection of the Services. Depending on the nature of your interaction with the Services, personal data may be processed for one or more of the following purposes:

i. Creating, verifying, administering and securing user accounts, profiles and registrations;

ii. Facilitating appointment booking, teleconsultation, healthcare consultations, care navigation, diagnostics, pharmacy services, wellness programmes, preventive healthcare initiatives, claims assistance, reimbursement support and other healthcare or allied services made available through the Platform;

iii. Verifying identity, age, eligibility, employment affiliation, insurance coverage, practitioner credentials, benefit entitlements and other information necessary for providing the Services;

iv. Facilitating communication between users, healthcare practitioners, hospitals, diagnostic centres, pharmacies, employers, insurers, TPAs, authorised partners and customer support personnel;

v. Providing customer support, resolving complaints, addressing grievances, responding to requests and improving user experience;

vi. Processing payments, subscriptions, refunds, invoicing, accounting, financial reconciliation, fraud prevention and transaction management;

vii. Operating, maintaining, monitoring, analysing, testing, securing, troubleshooting and improving the Platform, developing new products, features and services, conducting analytics, quality assurance, internal reporting, research and business administration, including AI-assisted features, where applicable and in accordance with applicable law;

viii. Complying with applicable laws, regulatory requirements, judicial or governmental directions, law enforcement requests, contractual obligations, audits, investigations, reporting obligations and record-retention requirements;

ix. Protecting the rights, property, safety, security and legitimate interests of Visit, its users, healthcare practitioners, enterprise customers, business partners and other third parties, including preventing fraud, abuse, unauthorised access, cyber incidents and other unlawful activities;

x. Sending service-related communications, including account notifications, appointment reminders, prescription reminders, wellness reminders, security alerts, transactional communications, policy updates and, where permitted under applicable law, promotional or marketing communications;

xi. Administering employer-sponsored healthcare programmes, insurance and employee benefit programmes, eligibility verification, utilisation reporting, programme administration and related contractual obligations;

xii. Maintaining business records, enforcing contractual rights, recovering dues, establishing, exercising or defending legal claims, resolving disputes and facilitating mergers, acquisitions, investments, financing, corporate restructuring or other legitimate business transactions.

Visit will not process personal data for any purpose that is incompatible with the purpose for which it was collected, except where such processing is permitted or required under applicable law or is otherwise carried out after providing any notice or obtaining any consent required under applicable law. Visit shall process only such personal data as is reasonably necessary for the relevant purpose.

8. CONSENT AND OTHER LAWFUL GROUNDS

Visit processes personal data in accordance with applicable law. Where required, Visit shall provide an appropriate privacy notice and obtain your free, specific, informed, unconditional and unambiguous consent through a clear affirmative action before processing your personal data.

Where permitted under applicable law, Visit may process personal data without obtaining separate consent where such processing is necessary for a legitimate use recognised under applicable law, including for:

i. Providing, maintaining or improving the Services requested by you or made available through an employer, insurer, healthcare provider or another authorised enterprise customer;

ii. Complying with applicable laws, judicial or governmental directions, regulatory requirements, law enforcement requests or other legal obligations;

iii. Preventing, detecting or investigating fraud, unauthorised activities, cybersecurity incidents or other unlawful conduct affecting the Services;

iv. Protecting the rights, safety, security or legitimate interests of Visit, its users, healthcare practitioners, enterprise customers or other persons;

v. Administering employment, insurance, healthcare, wellness or employee benefit programmes, or otherwise processing personal data for purposes permitted under applicable law or pursuant to a lawful arrangement with an employer, insurer, healthcare provider or another authorised entity.

Where processing is based on your consent, you may withdraw such consent at any time by using the facilities made available through the Platform or by contacting Visit using the details provided in this Privacy Policy. Withdrawal of consent shall not affect the lawfulness of any processing undertaken prior to such withdrawal and may result in the suspension, limitation or discontinuation of those Services that necessarily depend upon such consent. Visit may nevertheless continue to retain or process personal data where such retention or processing is required or permitted under applicable law.

9. ENTERPRISE, INSURANCE AND EMPLOYER-SPONSORED PROGRAMMES

Where the Services are made available through an employer, corporate client, insurer, broker, third-party administrator (TPA), hospital, clinic or another enterprise customer, Visit may receive or process personal data for enrolment, eligibility verification, identity verification, service delivery, appointment management, healthcare administration, claims facilitation, reimbursement support, utilisation reporting, fraud prevention, programme administration and other purposes connected with the relevant programme.

Depending on the nature of the Services and the applicable contractual arrangements, Visit may process such personal data either as an independent Data Fiduciary or as a Data Processor acting on behalf of the relevant enterprise customer.

Where applicable, the relevant employer, insurer, healthcare provider or enterprise customer may also process your personal data independently in accordance with its own privacy policy and legal obligations. Users are encouraged to review the privacy notices issued by such organisations.

Unless required by applicable law, necessary for administering the relevant healthcare programme, or expressly authorised by you, Visit does not ordinarily disclose the contents of medical consultations, diagnoses, prescriptions or other confidential clinical information to employers or other enterprise customers.

10. PROCESSING OF HEALTH INFORMATION

Given the nature of the Services, Visit may process personal data relating to an individual's health, medical condition, diagnosis, treatment, prescriptions, consultation records, laboratory reports, diagnostic information, insurance claims, wellness information and other healthcare-related information for the purposes described in this Privacy Policy.

Recognising the confidential nature of such information, Visit implements technical, organisational and contractual safeguards designed to protect it against unauthorised access, disclosure, alteration, misuse or loss. Such safeguards may include role-based access controls, least-privilege access principles, encryption, authentication controls, audit logging, secure storage, contractual confidentiality obligations, vendor due diligence and periodic review of access permissions.

Visit requires its directors, employees, healthcare practitioners, contractors, service providers and Data Processors having access to such information to comply with appropriate confidentiality, privacy and information security obligations and to access such information strictly on a need-to-know basis for authorised purposes.

Visit does not use health information for advertising, profiling or marketing purposes except where expressly permitted under applicable law and, where required, with the individual's consent.

11. MEDICAL DISCLAIMER

Visit is a technology platform that facilitates access to healthcare and allied services through independent healthcare practitioners, hospitals, diagnostic centres, pharmacies, insurers, wellness partners and other authorised service providers.

Medical advice, diagnosis, treatment, prescriptions and clinical decisions are provided solely by the relevant healthcare professional or healthcare provider. Nothing contained on the Platform or in this Privacy Policy shall be construed as medical advice or as creating a doctor-patient relationship between Visit and any user.

Users should not disregard or delay obtaining professional medical advice on the basis of information available through the Platform. In the event of a medical emergency, users should immediately contact the appropriate emergency services or their healthcare provider.

12. CHILDREN AND PERSONS WITH DISABILITY

Visit recognises that the privacy of children and persons with disabilities requires enhanced protection.

Where the Services are used by or on behalf of a child or a person with disability having a lawful guardian, Visit shall process personal data in accordance with applicable law and shall, where required, obtain verifiable consent from the parent, lawful guardian or other authorised representative before processing such personal data.

Visit may take reasonable measures to verify the age of users and the identity or authority of a parent, lawful guardian or authorised representative where required under applicable law.

Visit does not knowingly undertake tracking, behavioural monitoring or targeted advertising directed at children where prohibited under applicable law and processes personal data relating to children only for lawful purposes connected with the provision and administration of the Services.

Any person providing personal data on behalf of another individual represents and warrants that they are duly authorised to do so and that all necessary consents, permissions or authorisations required under applicable law have been obtained.

13. COOKIES, SDKS AND SIMILAR TECHNOLOGIES

Visit uses cookies, pixels, software development kits (SDKs), application programming interfaces (APIs), local storage technologies and similar technologies to operate, secure and improve the Services.

These technologies may be used for purposes including user authentication, security, fraud prevention, session management, remembering user preferences, performance monitoring, analytics, diagnostics, service improvement and other functions necessary for the operation of the Platform.

Where required under applicable law, Visit shall provide appropriate notice and obtain consent for the use of cookies or similar technologies through a cookie banner, consent management platform or other appropriate mechanism. Certain cookies or technologies that are strictly necessary for the functioning, security or administration of the Platform may continue to operate without separate consent where permitted by applicable law.

Users may manage or disable cookies through their browser or device settings. However, disabling certain cookies or similar technologies may affect the availability, functionality or performance of some features of the Services.

14. COMMUNICATIONS

Visit may communicate with you through email, SMS, telephone calls, WhatsApp, in-app notifications, push notifications or other electronic means in connection with the Services.

Such communications may include one-time passwords (OTPs), account verification messages, appointment confirmations and reminders, consultation updates, prescription and wellness reminders, payment confirmations, invoices, customer support communications, grievance responses, security alerts, fraud prevention notifications, policy updates and other service-related communications necessary for the administration, operation and security of the Services.

Where permitted under applicable law, Visit may also send information regarding new products, features, offers, surveys, wellness programmes or other promotional communications. Where applicable law requires consent for such communications, Visit shall obtain such consent before sending them.

You may opt out of receiving promotional or marketing communications at any time by using the unsubscribe facility provided in the communication, modifying your account preferences where available, or contacting Visit using the details provided in this Privacy Policy. Opting out of promotional communications shall not affect Visit's ability to send communications that are necessary for providing the Services, complying with applicable law, protecting account security or administering your relationship with Visit.

15. DISCLOSURE OF PERSONAL DATA

Visit may disclose personal data only where such disclosure is necessary for the purposes described in this Privacy Policy, is made with appropriate safeguards, or is otherwise permitted or required under applicable law.

Subject to applicable law, personal data may be disclosed on a need-to-know basis to:

i. Employers, corporate clients, insurers, brokers, third-party administrators (TPAs), hospitals, clinics, healthcare practitioners, diagnostic centres, pharmacies, wellness partners and other authorised persons involved in providing, administering or supporting the Services;

ii. Visit's affiliates and group companies, where such disclosure is necessary for internal administration, service delivery, business operations or other lawful purposes;

iii. Data Processors, cloud infrastructure providers, payment service providers, identity verification providers, analytics providers, communication service providers, cybersecurity providers, fraud prevention providers, technology vendors and other authorised service providers engaged by Visit under appropriate contractual and confidentiality obligations;

iv. Auditors, accountants, legal advisers, consultants and other professional advisers engaged by Visit and bound by contractual, professional or statutory duties of confidentiality;

v. Courts, tribunals, regulatory authorities, government agencies, law enforcement authorities or other statutory bodies where disclosure is required or permitted under applicable law, pursuant to a lawful order or direction, or is necessary for establishing, exercising or defending legal rights or claims;

vi. Any purchaser, investor, lender, assignee, successor, merger partner or participant in a proposed or completed merger, acquisition, financing, corporate restructuring, business transfer, insolvency proceeding or other legitimate corporate transaction, subject to appropriate confidentiality and data protection obligations.

Visit does not sell personal data in a manner prohibited by applicable law. Except as described in this Privacy Policy or as otherwise required or permitted under applicable law, Visit does not disclose personal data to third parties without an appropriate legal basis or authorisation.

Visit requires third parties receiving personal data on its behalf to implement appropriate technical, organisational and contractual safeguards to protect such personal data and to process it only for the purposes authorised by Visit or otherwise permitted under applicable law.

16. VENDOR AND DATA PROCESSOR OBLIGATIONS

Visit engages third-party service providers and Data Processors to support the provision of the Services. Where personal data is processed on Visit's behalf, such service providers and Data Processors are required to process personal data only for authorised purposes and in accordance with applicable contractual obligations and applicable law.

Visit undertakes reasonable due diligence while engaging such service providers and requires them to implement appropriate technical, organisational and security measures designed to protect personal data against unauthorised access, disclosure, alteration, misuse or loss.

17. CROSS-BORDER TRANSFERS

Personal data may be stored, processed or accessed within or outside India by Visit or its authorised Data Processors, service providers or affiliates for the purposes described in this Privacy Policy and in accordance with applicable law.

Where personal data is transferred outside India, Visit shall take reasonable measures to ensure that such transfer is carried out only in accordance with applicable law, including any restrictions, conditions or notifications issued by the Government of India from time to time. Visit also requires its authorised recipients to implement appropriate technical, organisational and contractual measures designed to protect personal data against unauthorised access, disclosure, alteration, misuse or loss.

Nothing contained in this Privacy Policy shall be construed as permitting the transfer of personal data to any country or territory where such transfer is prohibited or restricted under applicable law.

18. DATA RETENTION

Visit retains personal data only for so long as is reasonably necessary to fulfil the purposes for which it was collected or otherwise processed, or for such longer period as may be required or permitted under applicable law, contractual obligations, applicable limitation periods, accounting and taxation requirements, healthcare and insurance record-keeping obligations, fraud prevention, audit requirements, dispute resolution or the establishment, exercise or defence of legal claims.

The applicable retention period may vary depending upon the nature of the personal data, the purpose of processing, the Services used and applicable legal or regulatory requirements.

Upon expiry of the applicable retention period, or once retention is no longer necessary for the relevant purpose, personal data shall, as appropriate, be securely deleted, destroyed, anonymised or irreversibly de-identified, unless its continued retention is required or permitted under applicable law.

Visit maintains internal record-retention schedules and information governance practices designed to ensure that personal data is retained only for so long as reasonably necessary for legitimate business, operational and legal purposes. Such internal retention schedules may be updated from time to time and are not required to be published as part of this Privacy Policy.

Where personal data forms part of medical records, insurance claim records, employment benefit records or other records that are subject to mandatory statutory or contractual retention requirements, Visit may retain such records for the period prescribed under the applicable law, contract or regulatory requirement notwithstanding any request for deletion, after which such records shall be securely deleted or anonymised in accordance with this Privacy Policy.

19. DATA ACCURACY

Users are responsible for ensuring that the personal data provided to Visit is accurate, complete and kept up to date. Where personal data changes, users are encouraged to promptly update their information through the Platform or notify Visit using the contact details provided in this Privacy Policy.

Visit shall not be responsible for any inability to provide the Services, or for any loss arising from inaccurate, incomplete or outdated personal data provided by or on behalf of a user.

20. ARTIFICIAL INTELLIGENCE AND AUTOMATED TECHNOLOGIES

Visit may utilise artificial intelligence, machine learning and other automated technologies to support the provision and improvement of the Services, including customer support, appointment management, wellness recommendations, fraud prevention, analytics, operational efficiency, quality assurance and other administrative or informational functions.

Where such technologies are used, they are intended solely to assist in the delivery and administration of the Services and to enhance user experience. Any information, recommendation or output generated through such technologies is informational in nature and is not intended to replace the independent professional judgment of a qualified healthcare practitioner or to constitute medical advice, diagnosis or treatment.

Visit shall deploy such technologies in accordance with applicable law and implement appropriate technical and organisational measures designed to safeguard personal data and promote the responsible use of such technologies. The use of artificial intelligence or automated technologies shall not affect the confidentiality obligations applicable to personal data processed through the Platform.

21. YOUR RIGHTS

Subject to applicable law, you may exercise the following rights in relation to your personal data:

i. To obtain information regarding the personal data processed by Visit, including a summary of such personal data and such other information as may be required to be provided under applicable law;

ii. To seek correction, completion or updating of inaccurate, incomplete or misleading personal data;

iii. To request the erasure of personal data that is no longer necessary for the purpose for which it was processed, subject to applicable legal, regulatory, contractual and record-retention requirements;

iv. To withdraw consent previously provided for the processing of personal data, where processing is based on consent;

v. To seek information regarding the categories of recipients or third parties with whom your personal data has been shared, where such information is required to be provided under applicable law;

vi. To nominate another individual to exercise your rights in accordance with applicable law;

vii. To submit a grievance regarding the processing of your personal data and, where applicable, to seek further remedies before the competent authority in accordance with applicable law.

The exercise of the foregoing rights shall be subject to applicable law, including legal obligations, statutory exemptions, contractual commitments, protection of the rights of other individuals, technical feasibility, cybersecurity considerations and applicable record-retention requirements.

22. CORRECTION, DELETION AND ACCOUNT CLOSURE

Where the relevant functionality is available, you may review and update certain profile information directly through your account.

Requests relating to correction, updating, completion, erasure, withdrawal of consent, nomination, account closure or any other privacy-related matter may be submitted using the contact details specified in this Privacy Policy. Before acting upon any request, Visit may take reasonable steps to verify the identity, authority and authenticity of the request to protect personal data against unauthorised access or misuse.

Visit shall consider and respond to such requests within the period prescribed under applicable law. Where a request cannot be fully complied with, Visit may communicate the reasons to the extent permitted by applicable law.

Closure of an account does not automatically result in the deletion of all associated personal data. Visit may retain personal data, including healthcare records, insurance records, financial records, audit logs, fraud prevention records and other information, where such retention is required or permitted under applicable law, contractual obligations, regulatory requirements, dispute resolution, the establishment, exercise or defence of legal claims or other legitimate business purposes. Personal data that is no longer required shall thereafter be securely deleted, anonymised or irreversibly de-identified in accordance with Visit's record-retention practices.

Visit reserves the right to decline or limit a request to the extent permitted under applicable law where the request is manifestly unfounded, technically infeasible, would adversely affect the rights of another individual, would compromise the security or integrity of the Services, or where Visit is otherwise legally entitled or required to retain or continue processing the relevant personal data.

23. SECURITY PRACTICES

Visit implements appropriate technical, organisational and contractual measures designed to safeguard personal data against unauthorised access, disclosure, alteration, misuse, destruction, loss or accidental damage.

Such measures may include role-based and least-privilege access controls, encryption, authentication mechanisms, key management, secure software development practices, vulnerability assessments, security monitoring, audit logging, backup and recovery procedures, periodic access reviews, vendor security assessments, employee training, contractual confidentiality obligations, incident response procedures and periodic review of information security controls.

While Visit endeavours to maintain appropriate safeguards, no method of electronic transmission or storage is completely secure. Users are responsible for maintaining the confidentiality of their account credentials, using appropriate security measures while accessing the Services and promptly notifying Visit of any suspected unauthorised access, compromise or security incident relating to their account.

24. CYBER INCIDENT MANAGEMENT

Visit maintains policies, procedures and escalation mechanisms for the identification, assessment, containment, investigation, mitigation, response and recovery of cybersecurity incidents and personal data incidents.

Where required under applicable law or regulatory direction, Visit may notify the Indian Computer Emergency Response Team (CERT-In), other competent governmental or regulatory authorities, enterprise customers or affected individuals, as appropriate, having regard to the nature of the incident, applicable legal obligations and operational considerations.

Visit may also take such additional measures as it considers appropriate to mitigate the impact of an incident, restore the security and availability of the Services and prevent recurrence.

25. GRIEVANCE REDRESSAL AND DATA PROTECTION CONTACT

For privacy-related queries, grievances, requests relating to your rights, withdrawal of consent or any complaint regarding the processing of personal data, you may contact:

Grievance Officer / Privacy Contact
Visit Health Private Limited
237, Okhla Industrial Estate Phase 3, New Delhi, India - 110020.
Email: support@getvisitapp.com

Visit may take reasonable steps to verify the identity or authority of the person submitting a request before acting upon it.

Visit shall endeavour to acknowledge and address grievances within the timelines prescribed under applicable law or, where no specific timeline is prescribed, within a reasonable period.

If you are not satisfied with the resolution of your grievance, you may avail such remedies as may be available before the competent authority or other forum in accordance with applicable law.

26. THIRD-PARTY SERVICES

The Platform may integrate with or enable access to third-party products and services, including payment gateways, cloud service providers, communication platforms, analytics providers, identity verification providers, insurance systems, hospital information systems, electronic medical record systems, wellness platforms, Health Connect integrations, application programming interfaces (APIs) and other authorised third-party services.

Such third parties may independently collect, process or store personal data in accordance with their own privacy policies, contractual arrangements and applicable law. Visit does not control and is not responsible for the privacy practices or content of such third-party services. Users are encouraged to review the applicable privacy policies before enabling or using any third-party integration.

27. GOOGLE FIT AND SIMILAR INTEGRATIONS

Where you choose to connect Google Fit, Health Connect or any similar health or wellness platform, Visit may access and process activity data, step count, heart rate, sleep information, calories, fitness metrics and other wellness information strictly in accordance with the permissions granted by you, the functionality enabled by you, the applicable platform policies and applicable law.

Such information shall be processed solely for the purposes explained at the time the integration is enabled and may be disconnected at any time through the relevant application, account or device settings, subject to applicable technical limitations and lawful retention obligations.

28. CHANGES TO THIS PRIVACY POLICY

Visit may amend or update this Privacy Policy from time to time to reflect changes in applicable law, regulatory requirements, technology, security practices, business operations, products or services.

The revised Privacy Policy shall be published on the Platform together with the revised effective date. Where required under applicable law or where the changes are material, Visit may provide additional notice through the Platform, email or any other appropriate communication channel.

Your continued use of the Services following the effective date of the revised Privacy Policy shall constitute your acknowledgement of such revised Privacy Policy, to the extent permitted under applicable law.

29. LANGUAGE AND PREVAILING VERSION

This Privacy Policy may be made available in multiple languages for convenience.

In the event of any ambiguity, inconsistency or conflict between different language versions, the English version published by Visit shall prevail, unless otherwise required under applicable law.