Privacy Policy.
How we collect, use, store and protect your personal and health information. Compliant with India's Digital Personal Data Protection Act 2023.
Effective date: May 15, 2026
Last updated: May 15, 2026
Renacare Center for Kidney Disease and Research Pvt. Ltd. ("Renacare," "we," "us," or "our") operates the renacareckdr.com website and provides nephrology, dialysis and related medical services across Delhi NCR. This Privacy Policy explains how we collect, use, store, share and protect your personal and health information in accordance with the Digital Personal Data Protection Act 2023 (DPDP Act), the Information Technology Act 2000, and other applicable Indian laws.
1. Information we collect
We collect personal information that you voluntarily provide and information collected automatically when you use our services.
1.1 Information you provide
- Identification: Name, date of birth, gender, address, phone number, email, government ID (when required for scheme eligibility).
- Medical information: Medical history, current medications, lab reports, imaging, dialysis prescription, treatment notes, allergies and clinical observations.
- Insurance & payment: Insurance card details, scheme cards (PMJAY, CGHS, ECHS), TPA details, and payment instruments.
- Communications: Messages you send us via phone, WhatsApp, email or web forms.
1.2 Information collected automatically
- Device & usage data: Browser type, device identifiers, IP address, pages visited, referrer URLs, time on page.
- Cookies & similar tools: See Section 6 below.
2. How we use your information
- To provide nephrology consultation, dialysis and related medical services.
- To maintain accurate, complete and longitudinal medical records across our 7-centre network.
- To process appointments, billing and insurance/scheme claims.
- To communicate with you about scheduling, reports, follow-up and clinical alerts.
- To improve our services, train our staff and ensure quality.
- To comply with legal, regulatory and audit obligations.
- To respond to your queries submitted via phone, email, WhatsApp or web forms.
3. Data retention
Medical records are retained as required by Indian medical regulations and best practice — typically not less than 3 years from the last patient contact, and indefinitely where clinically necessary (for example, transplant patients, ongoing dialysis). Non-medical website logs are retained for up to 12 months unless required longer for security or legal reasons. You may request earlier deletion subject to medical record retention rules.
4. Patient rights (DPDP Act 2023)
You have the following rights regarding your personal information:
- Right to access: You can request a copy of your personal data we hold.
- Right to correction: You can request correction of inaccurate or outdated information.
- Right to erasure: You can request deletion of your personal data (subject to medical record retention requirements).
- Right to grievance redressal: You can raise complaints via our Data Protection Officer (DPO).
- Right to nominate: You can nominate another individual to exercise your rights in the event of incapacity or death.
- Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, email info@renacareckdr.com with subject line "DPDP Request — [your request type]." We respond within 30 days.
5. Third-party processors
To deliver our services, we use a limited set of third-party providers under contractual data-protection commitments:
- Hostinger — website hosting and domain.
- Google Analytics & Google Tag Manager — anonymous website usage analytics.
- Meta Pixel — aggregated advertising performance (when ad campaigns are active).
- Microsoft Clarity — session-level UX heatmaps with PII masking.
- WhatsApp Business (Meta) — patient communication when you message us.
- Insurance TPAs and scheme administrators — for cashless claim processing.
- Reference laboratories and imaging centres — for sample processing and reports.
We do not sell your personal data. We do not share personal data for marketing without your explicit consent.
6. Cookies and tracking
We use first-party cookies and limited third-party cookies for analytics and functionality. You can disable cookies in your browser settings, but some site features may not work correctly. We do not use cookies to identify you across unrelated websites.
7. Children's data
We do not knowingly collect personal data from children under 18 without parental or guardian consent. For pediatric patients, all data is collected from and managed with the parent or legal guardian. If you believe we have inadvertently collected a child's data without consent, contact us at info@renacareckdr.com and we will delete it promptly.
8. Data security
We maintain reasonable security practices including: encrypted website traffic (HTTPS), role-based access controls for staff, secure backups, signed confidentiality agreements with all employees and vendors, and physical security at our centres. No system is 100% secure; we make no guarantees but strive to follow industry best practice.
9. Cross-border transfers
Some of our third-party processors (Google, Meta, Microsoft) operate global infrastructure. Where data is processed outside India, it is subject to contractual safeguards and applicable Indian data-protection law.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting an updated "Last updated" date and, where appropriate, by direct notice. Continued use of our services after changes constitutes acceptance.
11. Contact — Data Protection Officer (DPO)
For privacy queries, requests, or grievances:
Data Protection Officer
Renacare Center for Kidney Disease and Research Pvt. Ltd.
Email: info@renacareckdr.com
Phone: +91 98181 83957
Address: Sector 37, Noida, Uttar Pradesh 201303, India
If you are not satisfied with our response, you may approach the Data Protection Board of India under the DPDP Act 2023.
Questions patients ask before they decide.
Medical records are retained as required by Indian medical regulations — typically not less than 3 years from your last visit, and indefinitely where clinically necessary (transplant, ongoing dialysis).
Yes. Email info@renacareckdr.com with subject "DPDP Request — Access". We respond within 30 days.
Only with your knowledge — for processing cashless claims under TPA, PMJAY, CGHS or ECHS empanelment. No other commercial sharing happens without your consent.
Email info@renacareckdr.com or call +91 98181 83957 with "DPO" in the subject. Our DPO operates out of our Sector 37 Noida head office.
Don't decide alone. Decide informed.
Whether you are weighing options, want a second opinion, or are ready to schedule — we'll route you to the right consultant within the day.