Version 3.5 · Effective 10 August 2026

Privacy Policy

Zyvai Technologies Private Limited / operating as Nadi Health

1. Introduction

Zyvai Technologies Private Limited, a company incorporated under the Companies Act 2013 with CIN U62011DL2026PTC465961, registered at 14/12, 2nd Floor, Kalkaji, New Delhi, South Delhi – 110019, Delhi, India, operates the Nadi Health platform (“Nadi”, “we”, “our”). This Privacy Policy is effective from 10 August 2026.

This Privacy Policy applies to: patients using Sehat (sehatapp.in and the Sehat mobile application), doctors using the Nadi Doctor portal (doctor.nadihealth.co), hospital administrators using the Hospital portal, and all users of Nadi Health services. We are committed to protecting your personal and health data in compliance with the Digital Personal Data Protection Act 2023 (DPDPA), the Information Technology Act 2000, and all applicable Indian regulations.

Zyvai Technologies Private Limited may be required to register as a Significant Data Fiduciary under the DPDPA 2023 upon notification by the Central Government. We will comply with all applicable registration and audit requirements as they are notified.

2. Data We Collect

2.1 Patient Data

2.2 Doctor Data

2.3 Automatically Collected Data

3. Consent Architecture (DPDPA Section 6)

When a patient scans a clinic QR code or grants consent through any Nadi platform, the following consent states are handled:

Consent StateWhat Happens
No prior consentPatient is offered the option to grant consent or check in without granting record access.
Active consentPatient is automatically checked in. Doctor has full access to consented records.
Lapsed consentPatient is shown expiry notice and offered renewal or check-in without consent.
Revoked consentDoctor cannot access records. Patient may re-grant consent at any time.

Consent is recorded with: timestamp, method (QR scan, verbal attestation, WhatsApp confirmation), IP address, and document version. Consent can be revoked at any time from the Sehat app.

4. AI Features and Cross-Border Data Processing

4.1 Cross-Border Transfer Disclosure

Audio for scribe transcription, prescription images for OCR, and medical documents you upload (lab reports, prescriptions, and other documents) are processed by Google Vertex AI (Gemini) in Google Cloud’s Mumbai region (asia-south1), within India. Scribe audio is processed in memory for transcription only and is not stored — it is discarded as soon as transcription completes. Prescription scan images and documents you upload are stored in Google Cloud Storage (Mumbai) as part of your medical record (see Section 4.3, Section 4.4, and Section 5). By using AI features, you consent to this processing for the sole purpose of AI transcription, OCR, and document extraction. Should any AI processing occur outside India in future, Nadi Health will comply with all applicable cross-border data transfer requirements under DPDPA 2023 Section 16 as the Central Government notifies approved countries and frameworks.

Transactional WhatsApp messages (including prescription notifications, appointment confirmations, and queue updates) are delivered via the WhatsApp Cloud API operated by Meta Platforms, Inc., whose infrastructure is located outside India. In accordance with DPDPA 2023, message content sent via WhatsApp is limited to notification metadata only — no clinical records, prescription details, or health data are transmitted through WhatsApp. Prescription PDFs and health records remain stored exclusively in GCP Mumbai and are accessed directly from sehatapp.in by authenticated users. By registering on Sehat or the Nadi Doctor portal, you consent to transactional notification messages being delivered via WhatsApp Cloud API for the sole purpose of service communication.

4.2 Ambient Scribe

When a doctor starts an AI scribe session with patient consent, audio is streamed to Google Vertex AI (Gemini), processed in Mumbai (asia-south1) within India for transcription only, and is not stored — the raw audio is discarded as soon as the transcript is generated. Only the resulting SOAP notes and transcript are saved with the consultation record. Scribe requires separate explicit patient consent, distinct from general record-sharing consent.

4.3 Rx Scan (Gemini OCR)

When an assistant scans a handwritten prescription, the image is sent to Gemini for OCR processing. The extracted prescription draft is presented to the doctor for review and approval before entering the patient record. The original scan image is stored in Google Cloud Storage.

4.4 Document & Lab-Report Reading (Your Uploads)

When you upload a lab report, prescription, or medical document in Sehat, the document image or PDF is sent to Google (Vertex AI / Gemini) and processed in Google Cloud’s Mumbai (asia-south1) region, within India, to read and extract the details (test values, medicines, dates) into your record. Google does not use your document to train its foundation models (Training Restriction, Google Cloud Service Specific Terms; processing under the Cloud Data Processing Addendum). You may upload without AI reading — the file is then stored without automatic extraction and you can enter the details yourself. This processing happens only with your in-app consent, which you can withdraw at any time in Sehat under Privacy & Consent.

4.5 Second Opinion Structured Response

When a specialist submits a second opinion, our system uses AI to assist with categorising recommendations. All clinical content is authored and reviewed by the specialist doctor. AI assistance is limited to formatting and categorisation only.

4.6 AI Limitations

AI features may produce hallucinations — confident-sounding outputs that are factually incorrect. Doctor review is the mandatory safeguard. No AI feature on Nadi Health is approved by any Indian regulatory body as a medical device.

5. Data Storage and Retention

If you request account deletion, we remove your identifying details — your name, contact information and profile data — and delete the records you provided yourself, such as self-logged vitals, symptom entries and documents you uploaded.

Your clinical records — prescriptions, consultation notes and lab results created by a doctor — are retained, because medical records regulations require a doctor’s record of a consultation to survive a patient leaving the platform. We keep a separate, restricted record of the identifiers needed to locate those records, so that we can act on a future request about them and so the retained records remain accurate. That record is not used for any other purpose. You may request a copy of your records before deletion at hello@nadihealth.co.

Data TypeStorage LocationRetention
Health recordsGCP Mumbai (Cloud SQL)Indefinite while your account is active. On deletion, doctor-created clinical records are retained; your identifying details are removed.
Documents and imagesGCP Mumbai (Cloud Storage)Indefinite. You can delete clinical photos yourself; other documents are deleted on request.
OTP codesGCP Mumbai (Cloud SQL)Valid for 10 minutes. Deleted when used, overwritten on the next request, and swept daily.
Scribe audioProcessed in memory (Mumbai, India)Never stored. Audio is transcribed in memory and discarded; there is no audio column and no storage bucket.
Consent and delivery tokensGCP Mumbai (Cloud SQL)Expire 4 hours after issue. The expired record is retained as part of the consent audit trail.
Clinical audit logsGCP Mumbai (Cloud SQL)Permanent and append-only. Audit records cannot be edited or deleted, by design — this is what makes the record trustworthy.
Login and session recordsGCP Mumbai (Cloud SQL)Retained indefinitely as security telemetry, on the same append-only basis as the clinical audit trail.
Push notification tokensGCP Mumbai (Cloud SQL)Removed when a device stops accepting notifications.
Appointment and booking recordsGCP Mumbai (Cloud SQL)Retained as part of your clinical history, on the same basis as health records.

Backups.Our database is backed up automatically each night, and we retain seven daily backups and seven days of transaction logs so that we can recover from a failure. This means that for up to seven days after data is deleted, it may still exist in a backup. Backups are encrypted, are held in the same region (Mumbai, India), and are accessible only to restore the service — never for ordinary access. We maintain a permanent, separate record of every erasure request we have completed, held outside the backup system, so that a restore cannot silently undo a deletion you asked for.

6. Third-Party Data Processors

ProcessorPurposeData Shared
Google Cloud Platform (Mumbai)Database, file storage, API hostingAll platform data
Google Vertex AI / GeminiScribe transcription, Rx OCR, patient-uploaded document and lab-report OCR/extraction, structured responseScribe audio (not stored, processed in Mumbai), prescription images (stored, Mumbai), patient-uploaded document images/PDFs, opinion text — see Section 4.1
Firebase (Google)Authentication, push notificationsPhone number, FCM token
Meta Platforms (WhatsApp Cloud API)WhatsApp OTP and transactional messagingPhone number, message content
MSG91SMS OTP, transactional SMS, and transactional emailPhone number, email address, message content
RazorpayPayment processing and recurring mandatesPayment amount, order ID, subscription identifiers

7. Your Rights (DPDPA 2023)

8. Cookies

Our web portals use essential cookies for authentication and session management using Firebase Authentication. We do not use third-party advertising cookies or tracking cookies. You can manage cookie preferences in your browser settings, but disabling essential cookies will prevent you from logging in to any Nadi Health web portal.

9. Security

We implement the following security measures:

10. Personal Data Breach Notification

In the event of a personal data breach, we follow the notification obligations under the Digital Personal Data Protection Act 2023 and its rules:

We maintain internal records of personal data breaches and the actions taken in response, and we will cooperate with the Board as required.

11. Changes to This Policy

We will notify you of material changes to this Privacy Policy via WhatsApp and in-app notification at least 15 days before they take effect. Continued use of Nadi Health services after notification constitutes acceptance of the updated policy. The version of the Privacy Policy accepted by each user is recorded in our systems. Version history is available at nadihealth.co/privacy.

12. Contact and Grievance Officer

Grievance Officer & Data Protection Officer (as required under DPDPA 2023, IT Act 2000, IT Rules 2021)

Juhi Sharma Malik, Director
Zyvai Technologies Private Limited (Nadi Health)
14/12, 2nd Floor, Kalkaji, New Delhi, South Delhi – 110019, Delhi, India
CIN: U62011DL2026PTC465961
Email: hello@nadihealth.co · Website: nadihealth.co/grievance

We will respond to grievances within 30 days as required by the DPDPA 2023 and within 48 hours for acknowledgement as required under the Consumer Protection Act 2019.