1. About this policy
NivaCare is a doctor–patient connecting Healthcare AI operating system developed and operated by Nivaris Healthcare Private Limited ("Nivaris Healthcare Private Limited", "we", "us" or "our"). This Privacy Policy applies to the NivaCare website, applications, connected services and communications that link to it (together, the "Services").
It explains what information we may process, why we process it, who may receive it, how long it may be retained and the choices available to individuals. A healthcare organisation using NivaCare may provide an additional privacy notice governing its own collection and clinical use of information.
2. Our role and the healthcare organisation's role
Depending on the circumstances, Nivaris Healthcare Private Limited may determine why and how personal data is processed, or may process information on documented instructions from a clinic, hospital, practitioner or other customer. Healthcare organisations remain responsible for their clinical records, lawful authority to use patient information, patient notices and consent where required.
If your request concerns information held in a healthcare organisation's clinical record, contacting that organisation directly may be the fastest way to exercise your rights.
3. Information we may collect
- Identity and contact information: name, age or date of birth, gender where relevant, email address, telephone number, address and identifiers supplied by you or an authorised organisation.
- Professional and account information: organisation, role, professional credentials, account settings, authentication records and authorised-user permissions.
- Health and care information: medical history, consultation information, observations, medications, allergies, investigations, prescriptions, care plans, patient-reported information and other records entered or connected by an authorised user.
- Remote-care information: readings from connected devices, symptom responses, activity or adherence information, monitoring thresholds and related alerts.
- Consultation and communication information: appointment requests, telehealth information, messages, support enquiries and, where enabled with appropriate notice or consent, audio or transcripts used for clinical documentation.
- Technical information: device and browser type, IP address, timestamps, diagnostic events, security logs, cookie identifiers and information about use of the Services.
- Business information: subscription, billing, contracting and customer-support records. Payment card details may be processed directly by an authorised payment provider rather than stored by Nivaris Healthcare Private Limited.
4. How information is collected
Information may be provided by patients, clinicians, authorised staff, customer organisations or carers; collected through use of the Services; generated by connected devices; or received from systems and services that an authorised user chooses to connect, including clinical systems, laboratories, pharmacies, communications providers and ABDM-compatible services where available.
5. Why we use information
We may process information to:
- provide, configure, secure and support the Services;
- help authorised care teams organise records, consultations, documentation, workflows, telehealth and remote monitoring;
- generate clinician-reviewable summaries, drafts, simulations and prioritisation signals;
- authenticate users, manage permissions and maintain audit trails;
- communicate about appointments, care workflows, service operation, support and security;
- monitor reliability, prevent misuse and improve accessibility and performance;
- meet contractual, legal, regulatory, safety and dispute-resolution obligations; and
- create aggregated or de-identified insights where the information is no longer reasonably capable of identifying an individual.
6. Consent and other lawful grounds
We process personal data only where an appropriate lawful ground is available under applicable law. This may include consent, performance of a contract, compliance with law, protection of individuals, legitimate uses permitted by law, or processing under the instructions and authority of a healthcare organisation. Consent may be withdrawn through the relevant setting or by contacting the responsible organisation, subject to legal and clinical recordkeeping requirements.
ABHA linking and exchange of health records through the Ayushman Bharat Digital Mission are performed only through supported workflows and the applicable consent process. NivaCare does not make an ABHA number mandatory merely to visit the public website.
7. AI-supported features and ambient documentation
NivaCare may use automated systems to organise information, prepare documentation drafts, identify workflow items, compare illustrative treatment-response scenarios or surface monitoring signals. These outputs are decision-support tools and require review by an appropriately qualified healthcare professional. They do not independently diagnose, prescribe or replace professional judgement.
Where ambient documentation is enabled, the organisation is responsible for giving appropriate notice and obtaining consent where required. Whether source audio is retained, and for how long, depends on the configured service, the customer agreement and applicable law. We do not use identifiable patient information to train general-purpose models unless this is specifically authorised under an appropriate agreement and lawful basis.
8. When information may be shared
Information may be disclosed only as reasonably necessary to:
- the healthcare organisation and its authorised clinicians, staff and service administrators;
- vendors that provide hosting, security, communications, analytics, support, payment or other contracted infrastructure under confidentiality and data-protection obligations;
- integrated healthcare or device services selected or authorised by the customer or individual;
- professional advisers, auditors, insurers, regulators, courts or law-enforcement bodies where required or permitted by law;
- a successor organisation in connection with a merger, financing, reorganisation or transfer of business, subject to appropriate safeguards.
We do not sell personal health information. We do not disclose identifiable clinical information to advertisers for targeted advertising.
9. Storage, transfers and retention
Hosting location and permitted cross-border transfers depend on the customer deployment, service configuration and applicable contractual or legal requirements. Where personal data is transferred between jurisdictions, we use contractual, organisational or technical safeguards appropriate to the transfer.
Information is retained only for as long as needed for the relevant service, clinical and legal purposes. Retention periods may be determined by the healthcare organisation, applicable medical-record obligations, contractual commitments, security needs and dispute-resolution requirements. Information is then deleted, de-identified or returned where appropriate and technically feasible.
10. Security
We use reasonable administrative, technical and organisational measures intended to protect information, which may include access controls, authentication, encryption in transit, logging, backup controls, vulnerability management and workforce confidentiality obligations. No online service can guarantee absolute security. Users must protect their credentials, use authorised devices and promptly report suspected misuse.
11. Your privacy rights
Subject to applicable law and relevant clinical record requirements, individuals may be entitled to request access, correction, completion, erasure, information about processing, withdrawal of consent or grievance redressal. We may need to verify identity and authority before acting on a request. Some information may need to be retained where law, patient safety, professional standards or the establishment or defence of legal claims requires it.
12. Children and dependent patients
Information about children or individuals represented by another person must be provided only by a parent, lawful guardian, authorised carer or healthcare organisation with appropriate authority. The Services are not intended for children to create independent professional accounts.
13. Cookies and website analytics
The public website may use essential storage and limited analytics technologies to operate securely, remember preferences and understand site performance. Browser controls can be used to restrict cookies, although some features may then work differently. Third-party websites linked from NivaCare operate under their own privacy policies.
14. Changes to this policy
We may update this Policy to reflect changes in the Services, law or our practices. The effective date will be revised and material changes may also be communicated through the Services or directly to affected customers where appropriate.
15. Privacy and grievance contact
Questions, privacy requests and grievances can be sent to:
Nivaris Healthcare Private Limited
Bengaluru, Karnataka, India
General enquiries: info@nivacare.ai
Support enquiries: support@nivacare.ai
Website: nivarishealth.com
