AtYourHome
...
Legal

Privacy Policy

How AtYourHome collects, uses, protects, and respects your personal and health information.

Effective: 1 May 2025 Version 1.0 Governed by Indian Law
At a Glance

What This Policy Covers

A plain-language summary — full details are in the sections below.

What We Collect

Name, contact details, health information you share, payment data, and standard web usage data.

How We Use It

To deliver healthcare services, process payments, communicate with you, and improve our platform.

Who We Share With

Only our verified healthcare professionals and essential service providers — never sold to advertisers.

Your Rights

Access, correct, or delete your data. Withdraw consent. File a grievance with our designated officer.

1

About Us

This Privacy Policy is published by SYNQORA TECHNOLOGIES PRIVATE LIMITED, a company incorporated under the Companies Act, 2013, operating the platform AtYourHome accessible at atyourhome.co.in (collectively, the "Platform").

Registered Address: 6-65/2/102 Datta Sai Enclave, Chanda Nagar, Hyderabad – 500050, Telangana, India.

This policy governs how we collect, use, store, share, and protect personal information of users, patients, and visitors who access or use our Platform or services. By using our Platform, you agree to the practices described in this policy.

This policy is published in compliance with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023.
2

Information We Collect

We collect only the information necessary to provide you with our services safely and effectively.

Category Examples When Collected
Identity & Contact Full name, email address, mobile number, date of birth, gender Account registration, booking forms
Patient Details Patient name, age, gender, relationship to account holder Service booking
Health Information Medical conditions, prescriptions, diagnoses shared by you Service requests, care notes
Location Data Service address, pin code, GPS coordinates (with permission) Address entry, professional dispatch
Payment Information Transaction ID, payment method type (card, UPI, net banking) Checkout — processed by PCI-DSS gateways; full card data never stored by us
Device & Usage Data IP address, browser type, pages visited, session duration, OS Automatically on Platform access
Communications Messages, support queries, feedback, reviews Contact form, WhatsApp, in-app messaging
Uploaded Documents Prescriptions, reports, resume (for job applicants) Voluntarily uploaded by you

We do not collect information beyond what is stated above. You may choose not to provide certain information, but this may limit your ability to use some features of the Platform.

3

Sensitive Health & Personal Data

Health and medical information you share with us is classified as Sensitive Personal Data or Information (SPDI) under the SPDI Rules, 2011, and as a special category of personal data under the DPDPA, 2023. This data receives the highest level of protection we apply.

We collect health information only with your explicit, informed consent and use it solely for the purpose of arranging and delivering the healthcare service you have requested. We never use health data for advertising, profiling, or sale to third parties.

Health data shared by you includes:

  • Medical conditions, diagnoses, or symptoms described in booking notes
  • Prescriptions or medical reports you upload
  • Observations recorded by our professionals during a service visit (with your consent)
  • Post-visit care instructions and clinical notes shared with your treating physician

You may withdraw consent for the processing of your health data at any time by contacting our Grievance Officer. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.

4

How We Use Your Information

We use your personal information for the following purposes only:

  • Service Delivery: To match you with the appropriate healthcare professional, schedule visits, and coordinate care.
  • Account Management: To create and maintain your account, verify your identity, and manage your bookings and preferences.
  • Payment Processing: To process transactions securely through our PCI-DSS-compliant payment gateway partners.
  • Communications: To send booking confirmations, appointment reminders, service updates, and support responses via SMS, WhatsApp, or email.
  • Safety & Verification: To verify the identity of professionals, screen for compliance, and ensure the safety of all parties.
  • Legal Compliance: To comply with applicable Indian laws, court orders, or regulatory requirements.
  • Platform Improvement: To analyse anonymised usage data, detect bugs, and improve our services — this analysis does not involve identifiable personal data.
  • Marketing (with consent only): To send promotional messages about new services, offers, or health content — only if you have opted in. You may unsubscribe at any time.
We do not use your personal or health information to train AI or machine-learning models, sell to data brokers, or share with advertisers.
5

Legal Basis for Processing

Under the Digital Personal Data Protection Act, 2023, we process your personal data on one or more of the following lawful grounds:

  • Consent: You have given explicit consent for specific purposes (e.g., health data collection, marketing communications).
  • Contractual Necessity: Processing is necessary to fulfil the service contract between you and us when you place a booking.
  • Legal Obligation: Processing is required to comply with applicable Indian law (e.g., GST records, court orders).
  • Legitimate Interest: Processing is necessary for our legitimate business interests (e.g., fraud prevention, platform security) provided this does not override your rights.
6

Sharing Your Information

We do not sell, rent, or trade your personal information. We share your data only in the following limited circumstances:

  • Healthcare Professionals: We share relevant booking details and health information with the assigned nurse, physiotherapist, or caregiver to enable them to deliver the service safely. They are contractually bound to maintain confidentiality.
  • Payment Gateways: Transaction data is shared with our PCI-DSS-compliant payment partners (e.g., Razorpay) to process payments. We do not store full card numbers or CVV data.
  • SMS / WhatsApp Providers: Your mobile number is shared with communication service providers (e.g., Twilio, MSG91) solely for the purpose of sending booking notifications and OTPs.
  • Analytics Providers: Anonymised, aggregated usage data may be shared with analytics tools (e.g., Google Analytics). No personally identifiable information is included.
  • Legal & Regulatory Authorities: We disclose personal information when required by law, court order, government authority, or to protect our legal rights.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.
All third-party service providers who access your data are bound by data processing agreements requiring them to protect your information and use it only for the purposes we specify.
7

Data Storage & Retention

Your data is stored on secure servers located within India, in compliance with the data localisation requirements of applicable Indian law.

We retain your personal data for the following periods:

  • Account data: For the duration of your account, plus 3 years after account deletion (required for legal and audit purposes).
  • Booking and health data: For 7 years from the date of the service, in compliance with medical records standards under the Clinical Establishments Act and applicable guidelines.
  • Payment transaction records: For 8 years, as required under the Prevention of Money Laundering Act (PMLA) and GST regulations.
  • Communication records (support queries, emails): For 3 years.
  • Uploaded documents: Retained for the period required to deliver the service, then deleted unless longer retention is mandated by law.

After the applicable retention period, data is securely deleted or anonymised so it can no longer be linked to any individual.

8

Security Measures

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, or disclosure:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS).
  • Encryption at rest: Sensitive personal and health data is encrypted at rest using AES-256.
  • Access controls: Access to personal data is restricted to authorised personnel on a strict need-to-know basis. All access is logged and audited.
  • Secure payment processing: Payment data is handled by PCI-DSS-certified payment gateways. We never store full card numbers or CVV codes on our systems.
  • Regular security reviews: We conduct periodic security assessments of our infrastructure, code, and data handling practices.
  • Staff training: All employees and contractors with data access receive training on data protection obligations and confidentiality.
No method of transmission over the internet is 100% secure. While we take every reasonable precaution, we cannot guarantee absolute security. If you believe your data has been compromised, please notify our Grievance Officer immediately at contact@synqora.in.
9

Cookies & Tracking Technologies

We use cookies and similar technologies on our Platform. Cookies are small text files stored on your device that help us provide a better experience.

  • Strictly Necessary Cookies: Required for the Platform to function (e.g., session authentication, shopping cart). Cannot be disabled.
  • Preference Cookies: Remember your settings and preferences (e.g., language, location). Can be disabled in browser settings.
  • Analytics Cookies: Collect anonymised data about how users interact with the Platform to help us improve it (e.g., Google Analytics). You may opt out via your browser settings or the Google Analytics opt-out tool.
  • Communication Cookies: Used for WhatsApp chat widgets or similar tools integrated on the Platform.

You can manage or delete cookies at any time through your browser settings. Disabling cookies may affect the functionality of some parts of the Platform. We do not use cookies for cross-site advertising or behavioural profiling.

10

Your Rights

Under the Digital Personal Data Protection Act, 2023 and the IT (SPDI) Rules, 2011, you have the following rights with respect to your personal data:

Right to Access Request a copy of the personal data we hold about you.
Right to Correction Request correction of inaccurate or incomplete data.
Right to Erasure Request deletion of your data, subject to legal retention obligations.
Right to Withdraw Consent Withdraw consent at any time without affecting past lawful processing.
Right to Nominate Nominate another person to exercise your rights in the event of your death or incapacity.
Right to Grievance Redressal File a complaint with our Grievance Officer or the Data Protection Board of India.

To exercise any of these rights, contact our Grievance Officer at contact@synqora.in. We will respond within 30 days of receiving your request.

11

Children's Privacy

Our Platform is not directed at children under the age of 18. We do not knowingly collect personal information from minors. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at contact@synqora.in and we will delete that information promptly.

When a booking is made on behalf of a minor patient by a parent or guardian, the parent or guardian is the account holder and is responsible for providing consent for the collection and processing of the minor's health data.

12

Third-Party Links

Our Platform may contain links to third-party websites or services (e.g., payment gateways, social media pages, WhatsApp). This Privacy Policy applies only to the AtYourHome Platform. Once you leave our Platform by clicking a third-party link, we have no control over and assume no responsibility for the privacy practices or content of those third-party sites.

We encourage you to review the privacy policies of every third-party website you visit.

13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page.
  • Notify registered users via email or an in-app notification before the changes take effect (for significant changes).
  • Seek fresh consent where required by applicable law.

Your continued use of the Platform after any changes constitutes acceptance of the updated policy. If you do not agree with the changes, you may close your account and request deletion of your data.

14

Grievance Officer

In accordance with the Information Technology Act, 2000 and the SPDI Rules, 2011, we have appointed a Grievance Officer to address any complaints or concerns regarding the processing of your personal data.

Grievance Officer — AtYourHome

SYNQORA TECHNOLOGIES PRIVATE LIMITED
6-65/2/102 Datta Sai Enclave, Chanda Nagar, Hyderabad – 500050, Telangana, India.
Response time: within 30 days of receipt of complaint

If you are not satisfied with the resolution provided by our Grievance Officer, you may escalate your complaint to the Data Protection Board of India once constituted under the Digital Personal Data Protection Act, 2023.


Questions?

Have a Privacy Question or Request?

Reach our Grievance Officer directly — we respond to all data requests within 30 days.