PRIVACY & POLICY
Galaxy Tech Solutions Private Limited (“we”, “our”, or “us”), operates and manages www.rainbowsepciality.com (“Website”). Our aim is to provide affordable and high quality health care service to all users(“you” or “your”). We actas a personal assistant that helps you to navigate through your entiresurgical and/or diagnostic processfrom discovery to recovery(“Services”).
1.3. The User’s consent shall be taken for the purpose of sharing data collected by Rainbow Super Speciality Hospital with the hospitals and/or insurance agency and/or EMI Service providers.
2.Information we collect about you:
2.2. Personal Information means any information about you from which you can be identified, including but not limited to:
- (a) Identity information: your full name, age, date of birth and gender;
- (b) Contact information:your contact number, e-mail address, residential address (present and permanent);
- (c) Technical information: internet protocol address, cookie data, browser type, browser language, referring URL, errors generated at the time of usage of Website, date and time zone.
- (d) Usage information: includes information about how you use the Website including but not limited to content viewed, content shared, pages visited on the Website, appointmentstaken and/or consultationsbooked by you, by using our Services;
- (e) Your insurance related information; and
- (f) Any other personal information that is willingly and freely shared by youon the Website or in the course of availing our Services.
2.3. Sensitive Personal Information means personal information revealing, related to, or constituting, as may be applicable-
- (a) Username and passwordkeys to enable access to our Website ;
- (b) Financial information such as bank account details, credit and debit card details or any other payment instrument details;
- (c) Health information including but not limited to medical records, symptoms, and appointment or consultations history, medications, physical, psychological and mental health condition and surgical procedures;
- (d) Official identifier;
- (e) Biometric information;
- (f) Genetic information;
- (g) Transgender status; and
- (h) Intersex status;
2.4. We may collectyour information included in your personal profile which is created on the Website after you register, any Personal Information and/or Sensitive Personal Information contained in any enquirymade by you regarding our Services, and any Personal Information and/or Sensitive Personal Informationcontained in or in relation to any communication that you share withus.
2.5. However, we may collectany information where your identity has been anonymised and is not in any manner personally identifiable to you. We will also be free to collect any such information that is freely available in the public domain without your consent.
3. Ways of collection of your information:
3.1. We may use different methods to collect information from and about you, including but not limited to:
- (a) Information provided by you during direct interactions with us: You may give us informationduring the course of receiving any Services or otherwise, whenyou access our Website, use any of the features of our Website, when you register on our Website, by filling in forms (electronically or physically),via e-mail, phone, social media platforms (including but not limited to Facebook or YouTube), messages (including but not limited to short message service, WhatsApp), or by contacting any of our representatives/employees, or when you givefeedback to us.
- (c) Information from third parties: we may collect information about you from our authorised third partiesincluding but not limited to physicians, doctors, hospitals, clinical labs, diagnostic labs, pharmacies, payment gateways andadvertisers, that may include your Personal Information and/or Sensitive Personal Information .
4. Use of your information:
4.1. We may use your information only for lawful purposes and for which you have given your consent. We believe in using any information provided by you fairly and in a transparent manner. We may use your information for the following lawful purposes:
Where it is necessary for the performance of a contract (already entered into or prior to entering into), and/or where it is necessary for fulfilling legitimate interests pursued by us or by an authorised third party:
- (a) We may collect information including but not limited to your identity, contact details, medical conditions and medical history in order to (i) provide you with an estimated cost for performingthe required procedure or surgery; (ii)provide you with information about expert surgeons who perform required procedure or surgery; (iii) provide you with information about best hospitals which facilitates required procedure or surgery; and (iv) where it is necessary for provision of Services, including medical diagnosis and the provision of healthcare or treatment.
- (b) We may collect informationincluding but not limited to your identity, contact details, medical conditions and medical history and financial data in order to (i)provide you with information regarding financing/ EMI options of procedures or surgery; (ii) facilitate immediate, easy and secured bill payments; and (iii) assist you in claiming your medical insurance during the provision of Services .
- (c) We may collect information including but not limited to your identity, contact details and communications in order to (i) get in touch with you via e-mail, phone, social media platforms (including but not limited to Facebook or YouTube), messages (including but not limited to short message service, WhatsApp), for appointments, consultations, technical issues, payment reminders and for providing other information; (ii) provide you effective, efficient, appropriate and most affordable treatment; (iii) maintain valuable communications with you; and (iv) retain call records for internal training and quality assessment purposes .
- (d) We may collect information including but not limited to your identity, contact details and technical data in order to (i) carry out research and analytics for improving our Website and Services; (ii) maintain security and service quality of our Website and Services; (iii) bring to you relevant Website information and to understand the usefulness of such information; and (iv)enable us to monitor your use of the Website and Services.
- (e) Where we are subjected to comply with any legal or regulatory obligation under any applicable law
4.2. In order to protect your vital interests as also of any other natural person, we may collect, use and share your information, including but not limited to medical records, symptoms, consultations, medical history and medications to prevent a serious threat to your health and safety or that of others. Your information will only be shared by us with persons, authorities or organisationthatmay help you in preventingsuch a threat
5. Sharing Your information:
5.1. Authorised person: we may share information about you with persons including employees and processors appointed by us to collect, use, share, disclose and/or transfer information and/or provide Services on our behalf. However, all disclosures of your information with authorised persons are subject to confidentiality obligationsto reasonably protect your information.
5.2. Data analytics: we may share information about you with authorised third parties hired to track the Website usage and analyse your information. Data analytics is performed in order to better understand usage ofour Servicesand enhance the Website experience by helping us make better business decisions.However, all such third parties are subject to confidentiality obligations to reasonably protect your information.
5.3. Performance of a contract: we may share your information including but not limited to medical records, symptoms, consultations, medical history and medications, with doctors, hospitals, and medical establishments including but not limited to clinical labs and diagnostic labs, in order to enforce any contract between us.
5.4. Business development: we may share anonymised data which does not personally identify you with prospective businesses in order to expand our field of services.
5.5. Compliance of legal obligation or dispute resolution: we may share information about you in compliance with any law and/or order of any court or tribunal. We may also disclose your information in order to resolve any dispute.
Please note that except as stated above, we will not share youridentifiable information with any other person without your consent. However, we reserve the right to share anonymised data for the purposes we deem fit.
6. Your data protection rights:
6.1. The right to withdraw your consent: You have the right to withdraw your consent for thecollection, storage, usage, disclosure and/or transfer of information by us at anytime.However, on withdrawal of your consent, we shall have the option not to provide Services for which your information was sought.
6.3. The right to correct your information: You have the right to request us for correctionof any inaccurate information, completion of incomplete information or updating any outdated information about you.
6.5. The right to restrict processing: You have the right to request us to restrict the collection, storage, usage, disclosure and/or transferof your information in the following circumstances: (i) when you want to establish information’s accuracy; (ii) where our use of your information is unlawful but you do not want us to erase such information; (iii) where we no longer need to collect, store, use, disclose and/or transferyour information, but you need us to hold yourinformation as you need it to establish, exercise or defend legal claims; and/or (iv) when you have objected to our collection, storage, usage, disclosure and/or transfer of your information, but we need to verify whether we have overriding legitimate grounds to use such information.
6.6. The right to object to processing: Youhave the right to object to ourcollection, storage, usage, disclosure and/or transfer of information: (i) where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impactsyour fundamental rights and freedoms; and (ii) where collection, storage, usage, disclosure and/or transfer ofyour information is used for marketing purposes.
6.7. The right to information portability: You have the right to transmit your information from us to any other service provider.
6.8. Rights in relation to automated decision making and profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling. We do not take any decision about you based on automated decision making and profiling, unless we take your explicit consent for the same .
6.9. If you wish to make a request for invoking any of your above mentioned rights, you may contact us at firstname.lastname@example.org, we may take all reasonable efforts to incorporate the changes within a reasonable time in accordance with applicable law.
7. Retention of your information:
7.2. We may retain all or any of your information in anonymised form without giving you any notice,for such period as may be requiredfor the purpose of, including but not limited to, internal usage, business development, scientific research purposes and statistical purposes.
8. Security safeguards:
8.1. Information collected from you is stored on secured network/server and access to such information is restricted only to authorised personnel.
8.2. Any communications between your browser and portions of the Website containing personally identifiable information are protected with Secure Socket Layer (SSL) encryption. This encryption helps to protect your information while it is being transmitted. Once we receive your information, we strive to maintain the physical and electronic security of your personal information using reasonable efforts.
8.3. We maintain backup files as a protection against natural disasters, equipment failures, or other disruptions. These backup files help us to protect your personal information because they lower the risk of losing valuable data.
8.4. We have implemented managerial and operational policies as well as adopted business practices to prevent any misuse, unauthorised access, modification, disclosure or destruction of your information.