QVitals Health
Privacy Policy
- Effective
- 23 August 2026
- Last updated
- 23 August 2026
This Privacy Policy explains how Jeevika Health Tech Private Limited, operating the healthcare technology platform and brand QVitals Health (“QVitals”, “we”, “us”, or “our”), collects, uses, stores, shares and protects personal data when you visit or use qvitalshealth.com and related services.
It is written to meet our obligations under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the rules made under it. Under that Act, QVitals is a Data Fiduciary and you are a Data Principal.
- Registered office
- Begum Vihar, New Delhi 110086, India
- Privacy contact
- privacy@qvitalshealth.com
- Grievance Officer
- Manoj Vashisth — +91 88002 33723
By using our website or submitting information through our forms, you acknowledge that you have read this Privacy Policy.
01What QVitals does
QVitals Health is building a technology-driven healthcare growth and connectivity platform for healthcare providers.
At the current stage, healthcare providers — including doctors and hospitals — may submit information through our website to request a free healthcare growth audit.
We use the information submitted through that form to understand the provider’s requirements, to communicate with them, and to conduct the requested audit. We share it with anyone else only where you have separately and expressly agreed to that, as described in section 6.
02Personal data we collect
A. Information you give us
The growth audit form collects the following, and nothing beyond it:
- Your full name, or the hospital name and the name of a contact person
- Mobile number
- Email address
- City, and clinic or practice address where you provide one
- Specialization or hospital speciality
- Educational qualifications and years of experience
- Your working arrangement, and whether you run your own clinic
- Hospital age and number of departments, for hospital enquiries
- Anything you write to us directly, by email, phone or message
B. Information collected automatically
When you use the growth audit form, our servers also record:
- A one-way cryptographic hash of your IP address. We do not store the address itself and cannot recover it from the hash. It exists only so we can recognise repeated abuse of the form.
- Your browser and device identifier string (user agent)
- The date and time of your submission, and of each consent you gave
- A registration ID we generate for you, which is how our team identifies your request without needing to read out your phone number
When you browse the rest of the site, standard technical information such as pages requested and referring page may be processed by our hosting provider for security and operational purposes. See section 8 for what we do and do not run in your browser.
03Health information
Please do not send us medical information. The growth audit form is for healthcare providers and asks only about your practice. It is not a secure channel for patient data.
Do not submit medical records, prescriptions, diagnostic reports, medical history, or any patient’s health information through this form or by email to us.
We do not request, and do not want, health information through the current growth audit form. If any reaches us it will be deleted rather than retained.
If QVitals later introduces patient-facing services that genuinely require health information, we will publish a separate notice and put appropriate consent and security measures in place for those services before launching them.
04Why we collect personal data
We process the personal data described above for these purposes only:
- Responding to your enquiry.
- Providing the free growth audit you requested.
- Understanding what your practice or hospital needs.
- Communicating with you about that audit and about our services.
- Where — and only where — you have given the separate optional consent described in section 6, introducing you to relevant hospitals, doctors or partners.
- Preventing fraud, abuse and security incidents.
- Improving our website and services.
- Keeping business and accounting records.
- Complying with our legal and regulatory obligations.
We limit collection and processing to what is reasonably necessary for the purpose you gave the data for.
05Consent and lawful processing
Under the DPDP Act we process personal data on the basis of your consent, or on another lawful basis where the Act permits one. Before you submit the form we tell you what we are collecting and why.
The two consents on our form
- Required
- That we may contact you about the growth audit you asked for. Without this we cannot provide the audit, so it is the one tick the form requires.
- Optional
- That we may introduce you to relevant hospitals, doctors or partners and share your details for that purpose. This is a separate, unticked box. Declining it does not affect your audit in any way.
We record each consent separately, with the date and time it was given, so that we can always show what you agreed to and when.
Withdrawing consent
You can withdraw either consent at any time by emailing privacy@qvitalshealth.com with the words “withdraw consent” and your registration ID or mobile number. No form, no reason required, no charge.
We will act on it within seven working days. Withdrawing the optional consent stops introductions but leaves your audit unaffected. Withdrawing the required consent means we can no longer provide the audit, and we will delete your data unless we are required by law to keep it. Withdrawal does not undo processing that was lawful before you withdrew.
06Sharing of information
We do not sell personal data. We do not trade, rent or licence it, and we do not share it for anyone else’s advertising.
Introductions to hospitals, doctors and partners
We share your details with another healthcare provider or partner only if you ticked the optional consent box described in section 5. If you did not tick it, your details stay with QVitals.
Where you did consent, we share only what is relevant to that introduction, and we tell you who we are introducing you to.
Everyone else who sees the data
Regardless of consent, the following may process personal data on our behalf, purely so that our own services can run:
- Our hosting and database providers (see section 14)
- Our email delivery provider, for sending you replies and notifications
- Our professional advisers, where they need it to advise us
- Legal, regulatory or governmental authorities, where we are required by law to disclose it
These are processors acting on our instructions under contract. They may not use your data for their own purposes.
07Third-party service providers
We currently use these providers, and no others:
- Supabase
- Database and storage of enquiries. Servers in Singapore.
- Netlify
- Website hosting and delivery. Servers in the United States and on a global network.
- Resend
- Sending notification and reply emails. Servers in the United States.
- Cloudflare
- Bot protection on our form, where enabled. It checks whether a visitor is human; it does not receive your form data.
We keep this list current. If we add a provider that processes personal data, we will update this section.
08Cookies and analytics
We use one cookie today. It is set only for members of the QVitals team who sign in to our internal enquiry page, it keeps them signed in, and it is strictly necessary for that page to work. If you are a visitor to the public site, we set no cookies at all.
We intend to add website analytics so we can understand which pages are useful. When we do, this section will be updated first, and if that analytics uses cookies or similar technologies that are not strictly necessary, we will ask for your consent before setting them and give you a way to change your mind.
You can also control cookies through your browser settings. Blocking strictly necessary cookies may stop parts of the site working.
09Data security
Section 8(5) of the DPDP Act requires reasonable security safeguards. The measures we take include:
- All traffic to and from this website is encrypted in transit (HTTPS).
- Enquiry data is held in a database that denies all access by default. No part of the public website can read it; only our server can, using credentials that never reach your browser.
- Our internal enquiry page is password protected and its sessions expire.
- Access is limited to team members who need it to do their work.
- Your IP address is stored only as a one-way hash, never in full.
- Rate limiting and bot protection on our forms.
- Security headers that prevent our pages being framed or injected into.
- Backups, with restoration tested.
No internet-based system can be guaranteed completely secure. We take reasonable measures, but we cannot promise absolute security.
10Data retention
Under section 8(7) of the DPDP Act we must erase personal data once the purpose is served, unless the law requires us to keep it. Our periods are:
- Growth audit enquiries
- Up to three years from your last contact with us, then deleted. If you tell us you are not interested, we delete within 30 days of that.
- Consent records
- Kept as long as the underlying data, plus one year, so we can show what you agreed to if you ever ask.
- Security records
- Hashed IP and browser information, up to 12 months.
- Accounting records
- As long as tax and companies law require, currently eight years.
You do not have to wait for these periods. Ask us to delete your data and we will, as described in section 11.
11Your rights
The DPDP Act gives you the following rights, and we honour all of them:
- Access
- A summary of the personal data we hold about you, what we are doing with it, and who we have shared it with.
- Correction
- Correction of anything inaccurate, and completion of anything incomplete.
- Erasure
- Deletion of your personal data, unless the law requires us to keep it.
- Withdraw consent
- At any time, as easily as you gave it. See section 5.
- Grievance
- A complaint to our Grievance Officer, answered within the times set out in section 12.
- Nominate
- Nominate another person to exercise these rights on your behalf if you die or become incapable of exercising them yourself.
To exercise any of these, email privacy@qvitalshealth.com. Tell us what you want and give us your registration ID or mobile number.
We respond within seven working days and complete most requests within 30 days. There is no charge. We may need to verify who you are first — that check protects your data from someone else asking for it.
The DPDP Act also places duties on you as a Data Principal: not to impersonate someone else, not to suppress material information, and not to file a false or frivolous complaint.
12Grievance redressal
If you are unhappy with how we have handled your personal data, contact our Grievance Officer.
Grievance Officer: Manoj Vashisth
Jeevika Health Tech Private Limited
Email: privacy@qvitalshealth.com
Phone: +91 88002 33723
We acknowledge every grievance within 24 hours and aim to resolve it within 15 days.
If we do not respond, or you are not satisfied with our response, you may complain to the Data Protection Board of India established under the DPDP Act. The Act requires you to raise the matter with us first and give us a chance to resolve it before approaching the Board.
13Children’s data
Our services are for healthcare professionals and businesses. You must be 18 or over to use our forms. We do not knowingly collect personal data from anyone under 18.
Section 9 of the DPDP Act requires verifiable parental consent before processing a child’s personal data, and prohibits tracking, behavioural monitoring and targeted advertising directed at children. We do none of these things, and any analytics we add will not be used to track or profile children.
If you believe a child has given us personal data, write to privacy@qvitalshealth.com and we will delete it.
14Where your data is processed
Some of our providers process data outside India. Specifically:
- Enquiry data is stored in Singapore (Supabase).
- Website hosting and email delivery are in the United States and on global content networks (Netlify, Resend).
Section 16 of the DPDP Act permits transfer of personal data outside India except to countries the Central Government restricts by notification. Neither Singapore nor the United States is currently restricted. If that changes, we will move the data.
Wherever it sits, the data remains under contract with us, and this policy continues to apply to it.
15Data breach
If we become aware of a personal data breach we will contain it, assess what happened, and act on our obligations under section 8(6) of the DPDP Act.
- We will notify each affected person without delay, telling you what happened, what data was involved, what we are doing about it, and what you should do.
- We will notify the Data Protection Board of India promptly, and in any case within 72 hours of becoming aware, with the detail the rules require.
16Changes to this policy
We may update this policy as our services, technology or legal obligations change. The current version is always published here with a revised “Last updated” date.
If a change materially affects how we use data you have already given us — particularly anything about sharing — we will contact you and, where the law requires it, ask for your consent afresh rather than assume it.
17Contact us
Jeevika Health Tech Private Limited
Operating brand: QVitals Health
Registered office: Begum Vihar, New Delhi 110086, India
CIN: U62011DC2026PTC474555
Website: qvitalshealth.com
Privacy and data rights:
privacy@qvitalshealth.com
Grievance Officer: Manoj Vashisth,
+91 88002 33723
A copy of this policy is available in English. If you would prefer it in another language listed in the Eighth Schedule to the Constitution of India, write to us and we will provide one.