Privacy Policy

vcdoc.in - Healthcare Digital Platform
Last Updated: March 2026  |  Effective Date: March 2026
Compliance Notice

This Privacy Policy is prepared in accordance with: the Digital Personal Data Protection Act, 2023 (DPDPA); the Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules); the Information Technology Act, 2000; Telemedicine Practice Guidelines 2020 (Board of Governors in supersession of MCI); Ministry of Health & Family Welfare EHR Standards 2016; the Ayushman Bharat Digital Mission (ABDM) Health Data Management Policy; the Clinical Establishments (Registration and Regulation) Act, 2010; the Drugs and Cosmetics Act, 1940 (for e-Pharmacy operations); and the Consumer Protection Act, 2019.

1. Introduction

vcdoc.in ("vcdoc", "we", "our", or "us") is a digital healthcare platform providing online doctor consultations, e-Pharmacy, e-Diagnostics, and Electronic Health Record (EHR) management services. We are operated by the entity registered at the address provided in Section 13 of this policy.

We are deeply committed to protecting the privacy, confidentiality, and security of all personal data, and in particular, Sensitive Personal Data or Information (SPDI) relating to health and medical information, which we collect in the course of delivering healthcare services.

This Privacy Policy explains how we collect, process, store, share, and protect your personal and health data. It applies to all users of the vcdoc.in website and mobile platform, including patients, caregivers, registered healthcare professionals, and partner institutions.

By accessing or using vcdoc.in, you consent to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the platform. For healthcare services involving Sensitive Personal Data, we will additionally seek your free, informed, and specific consent at the point of data collection, as required under applicable law.

2. Identity of the Data Fiduciary

Under the Digital Personal Data Protection Act, 2023, vcdoc.in acts as the Data Fiduciary - the entity that determines the purposes and means of processing your personal data.

Platform Namevcdoc.in
Legal EntityM J Mediport Private Limited
CIN / RegistrationU86201TS2025PTC194133
Registered AddressPrashanthi Nivas, H.No: 2-2-22, D D Colony, Bagh Amberpet, Amberpet, Hyderabad, Telangana 500013
Primary Emailharshavardhan@vcdoc.in
Websitewww.vcdoc.in
Services OfferedOnline Consultations, e-Pharmacy, e-Diagnostics, EHR Management
JurisdictionIndia
Grievance OfficerSee Section 13 for contact details

3. Information We Collect

We collect the following categories of data, which include Sensitive Personal Data or Information (SPDI) as defined under the IT (SPDI) Rules, 2011. Health and medical information constitutes SPDI and is afforded the highest level of protection under Indian law.

3.1 Personal Identification Information

  • Full name, date of birth, gender, contact number, and email address
  • Government-issued ID details (Aadhaar number, PAN, or passport) for identity verification - collected only with your explicit consent and used solely for verification purposes
  • Address details for medicine delivery (e-Pharmacy) or diagnostic sample collection (e-Diagnostics)
  • Photograph, if provided for profile identification

3.2 Health & Medical Information (Sensitive Personal Data - SPDI)

  • Medical history, pre-existing conditions, symptoms, diagnoses, and treatment plans
  • Prescriptions uploaded or generated through the e-Pharmacy module
  • Diagnostic test results, pathology reports, imaging data (X-rays, MRIs, scans), and laboratory reports
  • Electronic Health Records (EHR) created, accessed, and managed on the vcdoc platform
  • Consultation notes, clinical summaries, and follow-up care information
  • Vaccination records and immunisation history
  • Mental health and psychological assessment information (treated with the strictest confidentiality)
  • Biometric data, where applicable (e.g. for patient identification - only with explicit consent)

3.3 Technical & Usage Information

  • IP address, device type, browser type, and operating system
  • Log files, session data, cookies, and platform usage activity
  • Payment transaction metadata - we do not store full card or banking details; payments are processed through PCI-DSS compliant third-party gateways
  • Appointment booking history and platform interaction logs

3.4 Information from Healthcare Partners

  • Referral data from affiliated hospitals, clinics, and healthcare institutions
  • Test reports and imaging results shared by partner diagnostic laboratories
  • Discharge summaries or clinical data from partner hospitals (shared for continuity of care, with consent)

3.5 Data Collected for Telemedicine (Telemedicine Practice Guidelines, 2020)

For online consultations conducted on the vcdoc platform, in compliance with the Telemedicine Practice Guidelines 2020 (issued by the Board of Governors in supersession of the Medical Council of India):

  • Patient identity is verified before consultation
  • Consultation mode (audio, video, or text) is recorded
  • Registered Medical Practitioners (RMPs) on the platform are identified, and their registration details are retained
  • Consent for teleconsultation is recorded explicitly
  • Prescription details are maintained as part of the consultation record

4. How We Use Your Information

We use collected data solely for the purposes described below. We do not use health or personal data for advertising, profiling for commercial purposes, or any purpose unrelated to healthcare delivery.

Purpose of ProcessingData Categories UsedLegal Basis (DPDPA / SPDI Rules)
Facilitate online consultations with licensed Registered Medical Practitioners (RMPs)Identity, health/medical (SPDI), consultation dataConsent + Contract performance
Maintain and update Electronic Health Records (EHR) in line with MoHFW EHR Standards 2016All health data (SPDI), identity dataConsent + Legal obligation
Process e-Pharmacy prescriptions and coordinate medicine deliveryIdentity, address, prescription (SPDI)Consent + Contract performance
Manage diagnostic bookings and deliver test reportsIdentity, address, health data (SPDI)Consent + Contract performance
Send appointment reminders, health alerts, and service updatesContact data, appointment dataConsent
Verify identity and prevent unauthorised access or fraudIdentity, technical dataLegitimate use + Legal obligation
Comply with healthcare laws, medical regulations, and court ordersAll relevant categoriesLegal obligation
Improve platform performance and user experienceUsage data (anonymised where possible)Legitimate use
Conduct anonymised analytics for service and clinical improvementAnonymised/aggregated health dataLegitimate use (data de-identified)
Integrate with ABDM / National Digital Health Ecosystem (with consent)Health data, ABHA ID (if linked)Explicit consent
Support medico-legal documentation when required by lawHealth, identity, consultation recordsLegal obligation

5. Consent

In accordance with the Digital Personal Data Protection Act, 2023 and the IT (SPDI) Rules, 2011, we rely on consent as the primary lawful basis for collecting and processing your personal data, especially Sensitive Personal Data.

5.1 Nature of Consent

  • • Consent is free, informed, specific, and unambiguous.
  • • For SPDI (health and medical data), consent must be explicit and in writing (including electronic form).
  • • For teleconsultations, consent to the telemedicine mode of service and any sharing of records with other practitioners involved in your care is sought at the start of each consultation.
  • • Consent for ABDM / Ayushman Bharat Health Account (ABHA) integration is sought separately and is entirely optional.

5.2 Withdrawal of Consent

You may withdraw your consent for data processing at any time by writing to harshavardhan@vcdoc.in. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal. Note that withdrawal may affect our ability to continue providing certain services that depend on the use of that data.

5.3 Consent for Minors

For patients under 18 years of age, consent is obtained from a parent or legal guardian. We do not permit minors to independently register, access medical services, or consent to data processing. Verifiable parental/guardian consent is required. See also Section 10 (Children's Privacy).

6. Sharing of Information

We do not sell, rent, or trade your personal or health data to any third party for commercial purposes. Sharing is strictly limited to the purposes described below.

6.1 With Healthcare Providers (Need-to-Know Basis)

Your health data is shared with the doctors, specialists, hospitals, diagnostic centres, and pharmacies directly involved in your care through the vcdoc platform. This sharing is necessary to deliver connected, coordinated healthcare services and is governed by medical confidentiality obligations under the National Medical Commission (NMC) Code of Ethics.

6.2 With Technology and Service Partners

vcdoc engages third-party vendors for cloud hosting, payment processing, SMS/email communication, and logistics. Such partners:

  • • Are bound by confidentiality and data processing agreements.
  • • Are prohibited from using your data for any purpose other than the contracted service.
  • • Are required to implement security standards equivalent to those maintained by vcdoc.
  • • Are permitted to process data only within India, unless cross-border transfer is specifically authorised (see Section 9).

6.3 Legal and Regulatory Compliance

We may disclose your information when required by:

  • • Indian courts, tribunals, or law enforcement agencies under lawful order.
  • • The Data Protection Board of India (under DPDPA 2023).
  • • The Ministry of Health & Family Welfare or National Health Authority.
  • • State medical councils or the National Medical Commission (NMC).
  • • Regulatory bodies under the Drugs and Cosmetics Act, 1940 (for e-Pharmacy compliance)
  • • Any competent authority under the Clinical Establishments Act, 2010.

6.4 Ayushman Bharat Digital Mission (ABDM)

If you choose to link your vcdoc account with your Ayushman Bharat Health Account (ABHA), your health records may be shared with the National Digital Health Ecosystem in accordance with the ABDM Health Data Management Policy. This integration is entirely optional and requires your separate, explicit consent.

6.5 With Your Explicit Consent

For any sharing not described above, we will obtain your prior, explicit, written consent before disclosing your data.

7. Data Security

vcdoc implements industry-standard and healthcare-grade security measures in accordance with the IT (SPDI) Rules, 2011, Rule 8 (Reasonable Security Practices), and ISO/IEC 27001 standards, including:

Security MeasuresDetails
Encryption in TransitTLS 1.2+ / TLS 1.3 end-to-end encryption for all health data transmitted to/from the platform.
Encryption at RestAES-256 encryption for all stored health data, including EHRs, prescriptions, and test reports.
Access ControlRole-Based Access Control (RBAC) ensures only authorised clinicians and staff access patient records on a need-to-know basis
AuthenticationMulti-Factor Authentication (MFA) is required for all doctors, administrators, and platform staff
Security AuditsRegular vulnerability assessments, penetration testing, and third-party security audits
Data BackupSecure, geographically redundant backup systems with tested disaster recovery procedures
Audit TrailsFull audit logs are maintained for all access to and modifications of patient health records
Staff TrainingMandatory data privacy and security training for all staff handling personal or health data
Incident ResponseDocumented data breach response plan with defined escalation procedures and regulatory notification timelines

8. Data Retention

We retain personal and health data only as long as necessary for the purposes for which it was collected, and in compliance with applicable Indian healthcare and data protection regulations.

Data CategoryRetention PeriodLegal / Regulatory Basis
Patient health records & EHRMinimum 3 years from last consultation; typically, 5+ yearsMCI / NMC Regulations; MoHFW EHR Standards 2016
Consultation notes & prescriptionsMinimum 3 years; 5 years for surgical or complex casesTelemedicine Practice Guidelines 2020; Clinical Establishments Act 2010
Diagnostic reports & imagingMinimum 5 yearsNABH standards; Clinical best practice
Registered user profile dataDuration of account + 3 years’ post-closureDPDPA 2023; IT Act 2000
Pharmacy prescription recordsMinimum 2 yearsDrugs and Cosmetics Act 1940; Pharmacy Practice Regulations
Minor patient recordsUntil the patient reaches 21 years of age + 3 yearsStandard medico-legal practice
Medico-legal case recordsMinimum 10 years or as directed by the court/authorityEvidence Act; court/authority direction
Payment transaction metadata8 yearsIncome Tax Act 1961; GST regulations
Audit logs and access records3 yearsIT (SPDI) Rules 2011; DPDPA 2023
Security incident records5 yearsDPDPA 2023; CERT-In guidelines

After the applicable retention period, personal and health data will be securely deleted or anonymised in accordance with the DPDPA 2023 and CERT-In data destruction guidelines. Users may request early deletion of their personal data, subject to our legal retention obligations.

9. Cross-Border Data Transfers

vcdoc processes and stores all patient health data (SPDI) within India, consistent with the data localisation considerations under the Digital Personal Data Protection Act, 2023 and the ABDM Health Data Management Policy.

Where any processing involves transfer of personal (non-health) data to service providers located outside India (e.g., cloud infrastructure providers), such transfers are conducted only:

  • • To countries or territories notified by the Central Government as providing adequate protection for personal data; or
  • • Under contractual terms that ensure the recipient provides a level of protection equivalent to Indian law; or
  • • With your explicit, informed consent for the specific transfer.

Health data (SPDI) is not transferred outside India without explicit written consent and compliance with applicable Indian healthcare regulations.

10. Your Rights as a Data Principal

Under the Digital Personal Data Protection Act, 2023 (Sections 11–14) and the IT (SPDI) Rules, 2011, you have the following rights as a Data Principal:

RightWhat This Means
Right to Access (Sec. 11)Request a summary of personal data held by us, the purposes of processing, and entities with whom it has been shared.
Right to Correction & Erasure (Sec. 12)Request correction of inaccurate, incomplete, or misleading data; request erasure of data that is no longer necessary for the stated purpose, subject to legal retention obligations.
Right to Data PortabilityReceive your personal and health data in a structured, commonly used, machine-readable format (e.g. FHIR-compliant EHR export for ABDM-linked records).
Right to Grievance Redressal (Sec. 13)File a complaint with our Grievance Officer (see Section 13). We will respond within 30 days.
Right to Nominate (Sec. 14)Nominate another individual to exercise your data rights in the event of your death or incapacity.
Right to Withdraw ConsentWithdraw consent for processing at any time (see Section 5.2). Withdrawal does not affect prior lawful processing.
Right to Complain to DPBIf unsatisfied with our response, lodge a complaint with the Data Protection Board of India (once constituted under DPDPA 2023).

To exercise any of these rights, submit a written request to harshavardhan@vcdoc.in or use the data rights request form available on the platform. We will verify your identity before processing your request and respond within 30 days.

11. Children's Privacy

vcdoc may collect and process health information for patients under 18 years of age (minors) when such information is submitted by a verified parent or legal guardian. The following safeguards apply:

  • • Minors under 18 are not permitted to independently register, create accounts, or consent to data processing on the platform.
  • • Parental or guardian consent, which must be verifiable, is required before any minor's health data is collected or processed.
  • • Minor patient records are subject to extended retention periods (until the patient reaches 21 years of age plus 3 years, or as required by applicable medical regulations).
  • • Parental or guardian access to a minor's health records is provided in accordance with applicable medical ethics guidelines.

If you believe a minor's data has been collected on vcdoc without appropriate guardian consent, please contact our Grievance Officer immediately at harshavardhan@vcdoc.in. We will investigate and take immediate remedial action.

12. Cookies and Tracking Technologies

vcdoc uses cookies and similar technologies to support platform functionality and improve user experience. Cookies used on vcdoc.in fall into the following categories:

Cookie TypeSourcePurposeDuration
Essentialvcdoc.inRequired for login, session management, and core platform securitySession
Functionalvcdoc.inRemember your preferences, language settings, and platform layoutUp to 1 year
AnalyticsThird-partyAnonymised usage statistics to improve platform performance (no personally identifiable data)Up to 13 months
Securityvcdoc.inCSRF protection, rate-limiting, bot detection, and fraud preventionSession

You can manage or disable cookies through your browser settings. Disabling essential cookies may affect your ability to use core platform functions, including login and consultation services. Health data is never stored in cookies.

13. Embedded Content from Other Websites

Pages on vcdoc.in may include embedded content such as videos, health information resources, maps, or social media posts. Embedded content from other websites behaves in the same way as if you had visited those websites directly. Third-party embedded content providers may:

  • • Collect data about you and your device.
  • • Set their own cookies and tracking technologies.
  • • Monitor your interaction with the embedded content.
  • • Track your activity if you are logged into their platforms.

We do not embed third-party content on pages containing health data or within clinical/consultation areas of the platform. We encourage you to review the privacy policies of any third-party platforms whose content appears on vcdoc.in. We are not responsible for third-party data practices.

14. Third-Party Links

The platform may contain links to external websites, including healthcare information resources, regulatory bodies, and partner institutions. These third-party sites are not governed by this Privacy Policy. We encourage you to review their privacy policies independently. vcdoc assumes no responsibility for the privacy practices of third-party websites.

15. Telemedicine-Specific Privacy Obligations

vcdoc's online consultation services are subject to the Telemedicine Practice Guidelines, 2020. The following specific obligations apply:

15.1 Doctor-Patient Confidentiality

All Registered Medical Practitioners (RMPs) on the vcdoc platform are bound by medical confidentiality obligations under the NMC Code of Professional Conduct. Patient information disclosed during consultations may not be shared by the RMP with any third party without patient consent, except as required by law.

15.2 Consultation Record Keeping

Records of all telemedicine consultations, including mode of consultation, patient identity, chief complaints, clinical notes, and any prescriptions issued, are maintained as part of the patient's EHR in accordance with the Telemedicine Practice Guidelines 2020 and MoHFW EHR Standards 2016.

15.3 Prescription Privacy

Digital prescriptions generated through the vcdoc platform are stored securely as part of the patient's health record and are shared only with the patient and the dispensing pharmacy. Prescriptions for Schedule H, H1, and X drugs are handled with additional controls in compliance with the Drugs and Cosmetics Act, 1940.

16. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our services, technology, or applicable legal and regulatory requirements. When material changes are made:

  • • The "Last Updated" date at the end of this page will be revised
  • • Registered users will be notified via email and/or a prominent notice on the platform.
  • • Where the change affects how SPDI or health data is processed, we will seek fresh explicit consent before applying the change to your data.

We encourage you to review this policy periodically. Continued use of the platform after the effective date of changes constitutes acceptance of those changes.

17. Grievance Officer and Contact Information

In accordance with Section 13 of the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the IT (SPDI) Rules, 2011, vcdoc has designated a Grievance Officer to address complaints and queries related to personal data processing.

RoleGrievance Officer / Data Protection Officer
NameMr Harshavardhan Reddy
Emailharshavardhan@vcdoc.in
Postal AddressPrashanithi Nivas, H.No: 2-2-22, D D Colony, Bagh Amberpet, Amberpet, Hyderabad, Telangana 500013
Websitewww.vcdoc.in
Response TimeWithin 30 days of receipt of complaint
EscalationData Protection Board of India (www.meity.gov.in) - once constituted under DPDPA 2023