Skip to main content
Medtu Care

Privacy Policy

This policy is being reviewed by counsel and will be updated. Until then, only the general statements below apply, and nothing on this page overrides your statutory rights.

Summary (the part most people want)

Medtu Care is the data fiduciary/controller for the personal data described here. We serve international patients, so this policy is written to India's Digital Personal Data Protection (DPDP) Act, 2023 and to the data-protection laws of the countries our patients live in (for example Kenya's Data Protection Act 2019, Nigeria's Data Protection Act 2023, and the EU/UK GDPR). Where your country's law gives you a stronger right, that stronger right applies.

  • What we collect via the website form: your name, country, city, WhatsApp number, email (optional), a one-line description of your condition or the treatment you have been advised, and your preferred contact time. We also record which page the inquiry came from.
  • Why: solely to respond to your inquiry and, if you engage us, to coordinate the services you request. That is the purpose you consent to when you tick the box on the form — nothing broader.
  • Health data: your medical reports are sensitive personal data and we treat them that way. We deliberately do not collect medical reports through the website or over WhatsApp. If you engage us, documents are exchanged through a secure link we set up with you, and shared only with the doctors and hospitals working on your case, with your consent, one recipient at a time.
  • Where your data goes: we operate from India, so coordinating your care means your data is processed in India. If you are outside India, you give explicit consent to that transfer before anything moves (see “Sending your data to India” below).
  • No sale of data: we do not sell your personal data, and we do not share it with advertisers or data brokers. Ever.
  • Your rights: you may ask what we hold about you, ask us to correct it, withdraw consent, or ask us to delete it. Write to aditya@medtu.care with the subject line “Data request” and we will act on it.

The consent you give, itemized

We ask for consent in separate, specific pieces — never one bundled tick, never a pre-ticked box. You can give some and not others, and withdraw any of them at any time:

  • consent to contact you and coordinate your care;
  • consent to process your medical records for an opinion or treatment planning;
  • consent to share your records with a specific doctor or hospital, named at the time;
  • consent to send your data to India for processing (if you are outside India);
  • consent to send an opinion or records back to a doctor in your home country;
  • consent to marketing follow-ups — always separate, never assumed.

Sending your data to India (cross-border transfer)

Because we coordinate your care from India, using our services means your personal and health data is transferred to and processed in India. For patients in the EU, the UK, Kenya, Nigeria and other countries, we rely on your explicit, informed consent to that transfer, and on the necessity of the transfer to perform the service you asked for. We show you this clearly and get your agreement before any data is sent. You can withdraw this consent, though doing so may mean we can no longer coordinate care that requires an India-based doctor or hospital.

How we protect your data

We protect your medical records with encryption in transit and at rest, single-use per-case access links, full access logging, strict data-minimization, and a documented breach-response procedure — security practices aligned with the data-security principles of the EU GDPR and India’s Digital Personal Data Protection Act.

To be precise about what these words mean: these are the security practices we follow. We do not claim any certification, and we do not describe ourselves as “compliant with” any particular law — data-protection compliance is broader than security alone, and we would rather tell you exactly what we do than use a label.

What we collect and when

We collect personal data only when you give it to us: through the inquiry form, over WhatsApp, by email, or on a call. We do not require an account and we do not collect data from you silently beyond standard server logs needed to operate the website.

How long we keep it

We keep your data only as long as needed to handle your inquiry and any engagement that follows, and then as required by applicable law (for example, tax records have their own statutory retention). If you ask us to delete your data, we delete it unless a legal obligation requires a copy to be retained, and we confirm the deletion to you in writing.

Who we share it with

Only the people needed to serve you: the specialist doctors and hospitals working on your case, and — for travel arrangements only — our sister company Tripcuro, which receives your name, dates and travel needs but no medical content. Service providers that process data for us (messaging, CRM, storage) are bound to use it only on our instructions and not for their own purposes.

Your rights

Wherever you live, you can ask us to give you access to your data, correct it, delete it, or stop processing it, and you can withdraw any consent you gave. If you are in the EU or UK you also have the rights the GDPR gives you (including data portability and the right to complain to your supervisory authority); if you are in Kenya, Nigeria or another country with its own law, the rights that law gives you apply. To exercise any of these, contact our grievance officer below — we aim to acknowledge within 48 hours and resolve within 30 days.

Grievance officer and contact

For access, correction, deletion, or any privacy question or complaint, contact our grievance officer, Medtu Care (Aditya, founder), at aditya@medtu.care, or WhatsApp +91 98842 99324. If we have not resolved your concern, you may escalate to the data-protection authority in your country.

Chat with Medtu Care on WhatsApp