Skip to main content
Back

Privacy Policy

JOPANA Healthcare Technology Private Limited ("JOPANA", "we", "us") operates the JOPANA home-healthcare mobile application and website. This policy explains what personal data we collect from patients and customers, why we collect it, how long we keep it, and how you can access, correct, or delete it. It is written for the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices) Rules, 2011. Last updated: September 2026.

1. WHO WE ARE

JOPANA Healthcare Technology Private Limited, a company incorporated in India with its registered office in Bengaluru, Karnataka, is the Data Fiduciary responsible for your personal data. You can reach us at support@jopana.in for any question about this policy or about your data.

JOPANA is a technology platform that connects patients with independent healthcare Service Partners (nurses, physiotherapists, caretakers and doctors). Service Partners deliver clinical care; JOPANA operates the platform through which the booking, payment, and visit record are managed.

2. THE DATA WE COLLECT

We collect only what is needed to book, deliver, and account for a home-healthcare visit:

  • Account and identity data: your name, mobile number, email address, and profile photo. Your mobile number is verified by OTP at sign-up.
  • Patient and family-member data: the name, age, gender, and relationship of each person you book care for. If you book for someone else, you confirm that you are authorised to share their details with us.
  • Health data: the service you book, the symptoms, conditions, care notes, prescriptions, vitals, and clinical observations recorded against a visit, and any documents or images you upload. Health data is sensitive personal data and is treated as such.
  • Address and location data: the service address you save, and — during an active booking only — the Service Partner's live location, used for Electronic Visit Verification and for showing you their arrival status. See section 5.
  • Payment data: the amount, date, status, and reference of each transaction, plus refund records. Card, UPI, and bank details are collected and stored by our payment gateway, not by JOPANA. We never see or store your full card number.
  • Communications: your in-app support messages, notification preferences, ratings and reviews, and metadata (not audio) of calls made through our masked-calling feature.
  • AI assistant conversations: the messages you send to the in-app care assistant, and its replies.
  • Device and diagnostic data: device model, operating system version, app version, IP address, crash reports, and error logs.

We do not collect data we do not need, and we do not buy personal data about you from data brokers.

3. WHY WE USE YOUR DATA

We use your data for these purposes and no others:

  • To create and secure your account, and to sign you in.
  • To match you with a suitable Service Partner and to schedule, reschedule, or cancel a visit.
  • To let the assigned Service Partner deliver care safely — they see the patient details, address, and clinical notes relevant to their visit, and nothing more.
  • To verify that a visit actually happened, at the right place and time (Electronic Visit Verification).
  • To take payment, issue invoices, calculate cancellation fees, and process refunds.
  • To contact you about your booking by push notification, SMS, WhatsApp, email, or a masked phone call.
  • To answer your support requests and resolve disputes.
  • To keep the platform safe and working — fraud prevention, abuse detection, crash diagnosis, and security monitoring.
  • To meet legal, tax, and regulatory obligations that apply to us in India.

We do not sell your personal data. We do not use your health data for advertising, and we do not share it with advertising networks or data brokers. Where the in-app care assistant sends a message to a language-model provider, we require that provider to retain nothing and to train nothing on it.

4. THE BASIS ON WHICH WE PROCESS YOUR DATA

We process your personal data on the basis of the consent you give when you create an account and when you make a booking. Where the law requires us to keep certain records — for example financial and tax records — we process that data to meet those legal obligations.

You can withdraw your consent at any time (see section 9). Withdrawing consent does not affect processing already carried out, and it may mean we can no longer provide services that depend on the data you withdrew — for example, we cannot dispatch a Service Partner without a service address.

5. LOCATION DATA AND ELECTRONIC VISIT VERIFICATION

  • Service Partner location: while a Service Partner is travelling to and attending your booking, their app records location points so we can confirm arrival at the correct address and show you live status. This runs only for the duration of an active booking, and stops when the visit is closed.
  • Your location: the customer app requests location permission to suggest a nearby saved address and to check that your area is serviceable. This is used at the moment you ask for it. The customer app does not track your location in the background.
  • Arrival verification: at the start of a visit the Service Partner records an arrival check (a timestamp, a location point, and in some services a selfie) to confirm the visit began.

You can turn off location permission for the JOPANA app at any time in your device settings. Some features — nearby address suggestions and serviceability checks — will stop working, but you can still book by entering an address manually.

6. WHO WE SHARE YOUR DATA WITH

We share your data only with the following categories of recipient, and only to the extent each one needs it:

  • The Service Partner assigned to your booking — the patient details, address, and clinical information relevant to that visit. Service Partners are bound by confidentiality obligations and may not store your records outside the JOPANA app.
  • Razorpay Software Private Limited — our payment gateway, which collects and processes your payment instrument to take payment and issue refunds.
  • Supabase — our authentication, database, and file-storage provider, which hosts your account and the documents you upload.
  • Exotel Techcom Private Limited — our masked-calling provider, which connects calls between you and a Service Partner without either side seeing the other's real number.
  • Notification providers, including WhatsApp Business and push-notification services, used to send booking updates.
  • OpenRouter, Inc. — the AI gateway behind the optional in-app care assistant, which passes the messages you send to that assistant to a language-model provider in order to generate a reply. We route these requests with zero-data-retention and no-training settings enabled, so the model provider does not keep or learn from your messages.
  • Google Maps — used for address lookup, geocoding, and serviceability checks.
  • Sentry — our crash and error reporting tool, where enabled, used so we can diagnose defects. Health data is not intentionally included in these reports.
  • Professional advisers, auditors, and insurers, where necessary and under confidentiality.
  • Courts, law-enforcement, and regulators, where we are legally required to disclose.

Each of these providers acts as a Data Processor on our instructions, under a written contract that restricts them to the purposes described above.

7. WHERE YOUR DATA IS STORED

Your data is stored on cloud infrastructure operated by our providers. Some of these providers — notably the AI gateway behind the care assistant, and our error-monitoring tool — process data on servers located outside India. Where that happens, we transfer only the minimum data required for that specific function, under contractual safeguards, and only to countries not restricted by the Central Government under the DPDP Act. If you would prefer not to have your messages processed abroad, do not use the in-app AI assistant; every other feature of the app remains fully available.

8. HOW LONG WE KEEP YOUR DATA

We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires us to keep it. Our retention periods are:

DataHow long we keep itWhy
Account profile (name, phone, email, photo)Until you delete your account, then erased within 30 daysNeeded to operate your account
Patient and family-member recordsUntil you delete the member or your account, then erased within 30 daysNeeded to book and deliver care
Clinical notes, prescriptions, and visit records3 years from the date of the visitMedical record-keeping obligations applicable to healthcare services in India
Documents and images you uploadUntil you delete your account, then erased within 30 daysNeeded to deliver care
Booking, invoice, payment, and refund records8 financial yearsCompanies Act, 2013 and income-tax / GST record-keeping requirements
Electronic Visit Verification location points and arrival checks18 months from the visitDispute resolution and proof that a visit was delivered
AI care-assistant conversations14 daysShort-term context only; purged automatically
Masked-call metadata (numbers connected, time, duration)12 monthsSafety and dispute resolution. We do not record call audio.
In-app notifications10 daysPurged automatically
Crash reports and diagnostic logs90 daysDefect diagnosis
Security and access audit logs12 monthsSecurity monitoring and breach investigation

When a retention period ends, the data is deleted or irreversibly anonymised so that it can no longer be linked to you.

9. HOW TO DELETE YOUR ACCOUNT AND YOUR DATA

You can ask us to delete your account and your personal data at any time, free of charge. There are two ways to do it. These same instructions are also published on their own page at https://www.jopana.in/data-deletion.

Option A — delete it yourself from inside the app (fastest):

  • Open the JOPANA app and sign in.
  • Go to the Profile tab.
  • Scroll to the bottom and tap "Delete Account".
  • Read the confirmation dialog and tap "Delete" to confirm.
  • Your account is closed immediately and you are signed out. You will see a confirmation that your data will be permanently removed within 30 days.

Option B — ask us by email (works even if you no longer have the app installed):

  • Email support@jopana.in from the email address on your account, or from any address if you tell us the mobile number you registered with.
  • Use the subject line "Delete my account".
  • We will verify that the request is genuinely from you — usually by sending an OTP to your registered mobile number — and then process the deletion.
  • We acknowledge deletion requests within 7 days and complete them within 30 days.

What happens when you delete your account:

  • Immediately: your account is closed, you are signed out of every device, your login identity is released, and your profile is hidden from the platform. You can no longer book services, and no Service Partner can see your details. Your mobile number is freed, so signing up again creates a brand-new, empty account — it does not restore the old one.
  • Within 30 days: your name, phone number, email, profile photo, saved addresses, patient and family-member records, uploaded documents and images, clinical notes, AI assistant conversations, chat history, and notification history are permanently erased from our production systems.
  • Within 60 days: the same data is removed from our encrypted backups, as backups age out on their normal rotation.

What we must keep even after you delete your account, and why:

  • Invoice, payment, and refund records — retained for 8 financial years because Indian company, income-tax, and GST law require it. These are kept in a form that no longer identifies you beyond the transaction reference and amount.
  • Clinical visit records for care already delivered — retained for 3 years under medical record-keeping obligations, then erased.
  • Records we are required to preserve because of an active legal claim, investigation, or regulatory direction — retained only for as long as that requirement lasts, then erased.

Nothing we retain is used to contact you, to market to you, or to rebuild your account. Deletion is final: we cannot undo it or recover your data afterwards, so please download anything you want to keep before you confirm.

If you want us to delete only part of your data — for example a single family member, a saved address, or an uploaded document — you can remove those individually inside the app without closing your account, or ask us at support@jopana.in.

10. YOUR RIGHTS

Under the DPDP Act you have the following rights, and we will not charge you for exercising any of them:

  • Right to access: ask us for a summary of the personal data we hold about you and who we have shared it with.
  • Right to correction: ask us to correct data that is inaccurate, or complete data that is incomplete. You can edit most of your profile directly in the app.
  • Right to erasure: ask us to delete your personal data — see section 9.
  • Right to withdraw consent: withdraw consent for any processing based on it, at any time, as easily as you gave it.
  • Right to nominate: nominate another person to exercise these rights on your behalf if you die or become incapacitated.
  • Right to grievance redressal: complain to us about how we handle your data, and escalate to the Data Protection Board of India if you are not satisfied with our response.

To exercise any of these rights, email support@jopana.in. We will verify your identity and respond within 30 days.

11. HOW WE PROTECT YOUR DATA

  • Encryption: your data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest on our providers' infrastructure using AES-256.
  • Access control: staff and Service Partners can see only the data their role requires. A Service Partner sees the details of the bookings assigned to them, and nothing else.
  • Contact masking: calls between you and a Service Partner are routed through a masked number so neither side sees the other's real phone number.
  • Monitoring: we log access to sensitive records and monitor for unusual activity.
  • Breach notification: if a personal data breach occurs, we will notify the Data Protection Board of India and every affected user, as required by the DPDP Act.

No system is perfectly secure. Please keep your device locked, do not share your OTP with anyone, and tell us immediately at support@jopana.in if you think someone else has accessed your account.

12. CHILDREN

The JOPANA app is intended for users aged 18 and over. You must be 18 or older to create an account. Care can of course be booked for a child, but the account must be held by a parent or legal guardian, who provides consent for the child's data on the child's behalf. We do not knowingly create accounts for children, and we do not use a child's data for tracking, profiling, or targeted advertising. If you believe a child has created an account, write to support@jopana.in and we will delete it.

13. COOKIES AND SIMILAR TECHNOLOGIES

  • Essential cookies and secure session tokens: used to keep you signed in and to protect your session. These cannot be turned off without breaking sign-in.
  • Diagnostic and performance data: used to measure app stability and to fix crashes.
  • No advertising trackers: JOPANA does not use advertising or cross-site tracking cookies, and does not share your health-related activity with advertisers.

14. CHANGES TO THIS POLICY

We may update this policy as the service changes or the law changes. We will post the updated version at https://www.jopana.in/privacy with a new "last updated" date, and where the change is significant we will notify you in the app or by email before it takes effect.

15. CONTACT US AND GRIEVANCE REDRESSAL

For any question, request, or complaint about your personal data, contact our Grievance Officer:

  • Grievance Officer, JOPANA Healthcare Technology Private Limited
  • Email: support@jopana.in
  • Registered office: Bengaluru, Karnataka, India
  • We acknowledge every complaint within 7 days and resolve it within 30 days.

If you are not satisfied with our response, you may complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.