Krishna Hospital

Privacy Policy

In plain words. This app is the clinic's own record book for its GLP‑1 weight programme. It is used by the front desk and by the doctor — patients do not install it and do not have a login.

It holds a patient's name, contact number, measurements, five safety answers, her treatment plan and what she has paid. It is used to treat her and to run the clinic, and for nothing else. We do not sell it, we do not advertise with it, and no card or UPI details ever go into it.

1. Who this policy is about

This policy is published by Krishna Hospital (“the clinic”, “we”, “us”), We are the data fiduciary for the information described below.

It covers two groups of people:

2. What we record about a patient

Everything below is entered by clinic staff at the counter or in the consulting room. The app collects nothing on its own.

What Details
Identity Name, age, sex, mobile number, area, and the hospital number the clinic issues.
Measurements Height, weight, waist and hip, taken at registration and at each visit. BMI and waist‑to‑hip ratio are calculated from these and never stored.
Safety answers Yes or no to five questions about pregnancy, family thyroid cancer or MEN2, pancreatitis, insulin use and gallstones — asked before the programme can begin.
Treatment The dose for each week, the dates of the course, the doctor's own notes on the patient's history, and appointments.
Visit check‑ins Whether the injection was taken, and how the patient said she was feeling.
Payments The amount, what it was for, whether it was cash, UPI or card, who collected it and when. Only the kind of payment is recorded. No card number, no UPI ID and no bank detail is ever entered or stored.

Measurements, safety answers and treatment records are health data, and we treat them as the most sensitive information we hold.

3. What we record about staff

Every payment records who collected it. That is deliberate: money handled at the clinic must always be traceable to a person.

4. Why we hold it

We do not use any of it for advertising, for profiling, or for any purpose other than the treatment and administration of this programme.

5. Consent

Before the programme begins, the front desk explains what is being recorded and why, and the patient's agreement to start the programme is recorded in the app. A patient may refuse, and may withdraw her consent later by contacting us using the details in section 12. Withdrawing consent does not undo treatment already given, and does not remove records we are required by law to keep.

6. Who can see it inside the clinic

The two roles do not see the same things, and this is enforced by the clinic's records system rather than by which screens the app happens to show.

Front desk Doctor
Name, contact, hospital number Yes Yes
Measurements and BMI Yes Yes
Safety answers Records them; cannot read them back Yes
Medical history notes No Yes
Dose and treatment plan No Yes
Consultation fees and clinic earnings No Yes
The one‑time file charge Yes Yes

A front‑desk account that asks for a patient's history, her dose or the clinic's earnings is refused by the records system itself — not merely hidden from view in the app.

7. Where it is kept

Records are stored using Google Firebase (Cloud Firestore, Firebase Authentication and Firebase Cloud Messaging), provided by Google, on servers in the asia‑south1 region (Mumbai, India). Google processes this data on our instructions as our processor; it does not use it for its own purposes.

A copy is also kept on the clinic's own phones so the app keeps working when the internet does not. That copy is protected by the device's own security, is reachable only by someone signed in, and is cleared when the app is uninstalled. Clinic devices are kept locked, at the clinic, and are not personal phones.

8. Who we share it with

We do not sell patient information, and we do not share it for advertising. It leaves the clinic only in these cases:

9. How long we keep it

Medical records are kept for 1 year from the last visit, in line with the clinic's records policy and the applicable Indian regulations for clinical establishments. Payment records are kept for as long as tax and accounting law requires. Staff accounts are switched off rather than deleted, so that past receipts continue to show who collected the money.

10. Keeping it safe

No system is perfectly secure. If a breach affects your information, we will inform you and the Data Protection Board of India as required by law.

11. Your rights

Under the Digital Personal Data Protection Act, 2023, you may:

Ask at the front desk or write to the contact in section 12. We will respond within [NUMBER] days. We may ask you to confirm your identity first, so that nobody else can obtain your records.

12. Children

This programme is for adults. We do not knowingly enrol anyone under 18. If we learn that we hold information about a child without a parent's or guardian's consent, we will delete it.

13. Changes to this policy

If we change this policy we will update the date at the top and, where the change is significant, tell patients at the clinic before it takes effect.