TEST SITE / SANDBOX | Active Persona: Sandbox Mode ()
Corelatin
TEST SITE Login Help

Privacy Policy โ€” Corelatin Private Limited

Version 3.0  |  Last Updated: August 2026  |  Effective upon use of the Platform

Please read carefully. By using Corelatin's Platform or services, you consent to collection, use, and disclosure of personal information as described here. This Privacy Policy is incorporated into our Terms of Service (Version 3.0).

Data fiduciary

  • Legal name: Corelatin Private Limited
  • CIN: Available on request โ€” contact support@corelatin.in
  • Registered office: Ghaziabad, Uttar Pradesh, India
  • Support: support@corelatin.in / +91-7398405299
  • Grievance Officer: Shubham โ€” below

1. Introduction

Corelatin Private Limited ("Corelatin", "we", "our", "us") is committed to protecting personal information, including health-related data voluntarily provided during booking. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our website, applications, and services (the "Platform").

This Policy is governed by the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules). It should be read together with our Terms of Service and Cancellation & Refund Policy.

Hospital Independence Notice

Corelatin is a fully independent service and has no affiliation, partnership, or contractual arrangement with any hospital, clinic, or diagnostic centre โ€” including those named on our platform. Hospital names (AIIMS, Apollo, Fortis, Max, Medanta, Safdarjung, etc.) are referenced only as locations where our companions operate. Any patient or hospital-related data you provide is collected solely to deliver your requested companion service and is never shared with the hospital or its staff.


2. Information We Collect

We collect the following categories of personal information:

2.1 Personal Information

  • Full name, email address, phone number
  • Residential address and location data
  • Aadhaar number (for companions only, verified but not stored)
  • Date of birth and age
  • Emergency contact information

2.2 Patient & health-related information

Information about physical or mental health condition voluntarily provided during booking may constitute sensitive personal data under IT (SPDI) Rules, 2011 and personal data under DPDPA 2023.

  • Patient name, age, and gender
  • Hospital details and appointment information
  • Special medical requirements or notes provided during booking
  • Mobility limitations and behavioral traits
  • Medical history disclosed voluntarily by the booker

2.3 Payment Information

  • UPI ID patterns (not stored in raw form)
  • Payment confirmation references
  • Billing and transaction history
  • Credit/debit card last 4 digits (for reference only)

2.4 Technical and Usage Data

  • IP address and device information
  • Browser type, operating system, and screen resolution
  • Pages visited, time spent, and click patterns
  • Referral source and search terms
  • Cookie identifiers and tracking data

2.5 Communication Data

  • Email communications and chat history
  • WhatsApp messages and call logs (for service delivery)
  • Support tickets and feedback submissions
  • Survey responses and ratings

2.6 Document Logistics & Hospital Authorization Data

When you book our Document Collection & Hospital Submission service, we collect specific details required strictly for counter identification, retrieval, and delivery:

  • Document identifiers (e.g., Medical Records Department / MRD case number, biopsy report reference, laboratory test token, discharge summary details)
  • Authorization declarations, consent slips, or ID proofs provided to authorize our executive to act on your logistical behalf at hospital counters
  • Physical delivery address, pincode, recipient contact number, or postal tracking details
  • Digital document scans or photographs taken strictly for immediate digital delivery to the Client via secure channels (WhatsApp/Email)

3. How We Use Your Information

We use your information for the following purposes:

3.1 Service Delivery

  • Provide and manage companion booking services
  • Match patients with suitable companions
  • Coordinate hospital visits and appointments
  • Execute document collection, MRD queue submissions, and secure report dispatches on Client authorization
  • Send booking confirmations and reminders
  • Provide real-time updates to family members
  • Generate care reports and visit summaries

3.2 Verification and Compliance

  • Verify companion identities and backgrounds
  • Conduct police verification and Aadhaar authentication
  • Ensure safety compliance and quality standards
  • Prevent fraud and detect suspicious activities
  • Comply with legal obligations under Indian law

3.3 Payment Processing

  • Process payments and generate invoices
  • Handle refunds and chargebacks
  • Validate payment methods and prevent fraud
  • Maintain financial records for accounting purposes

3.4 Service Improvement

  • Analyze usage patterns to improve our services
  • Conduct research and analytics
  • Develop new features and services
  • Monitor and review service quality
  • Train and improve companion matching algorithms

3.5 Communications

  • Send service-related notifications and updates
  • Respond to queries and support requests
  • Send promotional communications (with consent)
  • Request feedback and reviews

4. Data Protection for Patient Information

We implement safeguards aligned with DPDPA Section 8 and SPDI Rules Rule 8:

  • Encryption: Personal data encrypted in transit (TLS) and at rest using industry-standard methods
  • Access control: Role-based access; companions receive minimum necessary patient details for the assignment
  • Minimum data: We collect only what is needed for booking, safety, and service delivery
  • Health data standards: We follow hospital confidentiality norms and national digital health guidance; the proposed DISHA legislation is not yet enacted โ€” we do not claim DISHA statutory compliance
  • No marketing use of clinical notes: Patient medical history is not sold or used for unrelated marketing
  • Document Confidentiality: Medical records, discharge summaries, biopsy reports, and physical documents collected from hospitals or diagnostic centres are treated with strict confidentiality. Companions and staff are strictly prohibited from evaluating, reading, or disseminating clinical details. Digital scans transmitted directly to the Client are purged from operational mobile devices following successful delivery confirmation.
  • Data localization: Primary storage and processing in India unless transfer is permitted under DPDPA with appropriate safeguards
  • Security reviews: Periodic review of security practices and incident response procedures

5. Information Sharing

We may share limited information with the following parties:

5.1 Service providers & processors

  • Assigned companions (minimum necessary: patient name, hospital, appointment, mobility notes, emergency contact)
  • Hosting and infrastructure providers under contractual data-processing terms
  • SMS and WhatsApp Business API providers for service communications
  • Payment gateway / aggregator partners (we do not store full card numbers)
  • Email delivery providers for transactional messages

5.2 Legal Requirements

  • Law enforcement agencies when required by court order or Indian law
  • Regulatory authorities as required by applicable laws
  • Government agencies for public health or safety purposes

5.3 Business Transfers

  • In the event of merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity
  • Any such transfer will be subject to the same privacy protections as this policy

5.4 What We Never Share

  • We never sell your personal information to third parties
  • We never share patient medical history with hospitals or their staff
  • We never share your information for marketing purposes without explicit consent
  • We never share Aadhaar numbers or government IDs with third parties

5b. Testimonial Privacy & Consent

5b.1 Collection. We may collect testimonials, feedback, reviews, photographs, or video recordings from users who have received Services. Submission is entirely voluntary (Terms of Service Section 18).

5b.2 Information collected. Name (or pseudonym), testimonial content, photograph or video, location (city/state/country if provided), relationship to Patient, and service context (hospital, date, service type).

5b.3 Consent. By submitting a testimonial, you explicitly consent to collection and processing as described here and in Terms Section 18.

5b.4 Licence. You grant Corelatin a worldwide, royalty-free, non-exclusive licence to use, display, reproduce, adapt, publish, and distribute the testimonial on our website, apps, social media, marketing materials, case studies, and partner presentations, subject to withdrawal under 5b.10 and Terms Section 18.7.

5b.5 Permitted uses. Website and app display, marketing and promotional materials, case studies, investor or partner presentations, email newsletters, and similar promotional contexts โ€” not unrelated sale of personal data.

5b.6 Editing. We may edit for clarity, grammar, length, or style while preserving meaning; short excerpts may be used.

5b.7 Attribution. We may use first name, initials, or full name; you may request anonymity or a pseudonym where practicable.

5b.8 Photo and video. Submission grants the same licence for image, likeness, voice, and appearance; you warrant consent of all individuals appearing.

5b.9 Patient privacy. We do not disclose identifiable health information without explicit written consent. Testimonials are anonymised where required under DPDPA and SPDI Rules. Minor Patient testimonials require verifiable Representative consent (Terms Section 22.6).

5b.10 Withdrawal. You may withdraw consent by written notice to Shubham, Grievance Officer, at support@corelatin.in or +91-9625700843. We will use reasonable efforts to remove active marketing use within thirty (30) days and honour applicable erasure requests. We are not required to recall material already distributed outside our control.

5b.11 Retention. Testimonials are retained for marketing purposes until consent is withdrawn, then deleted from active databases within thirty (30) days subject to legal retention requirements.

5b.12 Third-party sharing. Testimonials may be shared with marketing agencies or media partners under data-processing agreements requiring protection consistent with this Policy.

5b.13 No compensation. Unless agreed in writing, no payment for testimonial use.

5b.14 Accuracy. You represent the testimonial reflects your actual experience, is accurate and not misleading, contains no confidential information, does not infringe third-party rights, and that you may grant the licence in 5b.4.

5b.15 DPDPA rights. Access, correction, and erasure rights apply to testimonial personal data. Contact the Grievance Officer (below).


6. Your Rights Under DPDPA 2023

Under the Digital Personal Data Protection Act, 2023, you have the following rights (subject to applicable exceptions):

6.1 Right to access

Request information about personal data we hold and how it is processed.

6.2 Right to correction

Request correction of inaccurate or incomplete personal data. We aim to respond within 30 days.

6.3 Right to erasure

Request deletion when data is no longer necessary for the stated purpose, subject to legal retention (tax, consumer disputes, regulatory obligations).

6.4 Right to withdraw consent

Withdraw consent for processing that relies on consent; this does not affect prior lawful processing.

6.5 Right to grievance redressal

Register a grievance with Shubham, our Grievance Officer (contact below). If unsatisfied, you may approach the Data Protection Board of India as prescribed under DPDPA rules.

6.6 Right to nominate

Nominate another individual to exercise your rights in the event of your death or incapacity, as permitted under DPDPA Section 13.

6.7 Marketing opt-out

Opt out of promotional communications via unsubscribe links or by contacting support.

Note: Unlike some foreign laws, DPDPA 2023 does not provide a standalone statutory "data portability" right. We will provide copies of your data in a readable format where required for access requests.


7. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy, or as required by applicable Indian law:

  • Booking records: Up to 5 years โ€” consumer dispute resolution, service records, and contractual enforcement
  • Payment & tax records: Up to 8 years โ€” Income Tax Act, 1961 record-keeping requirements
  • Communication logs: Up to 2 years โ€” service quality, safety, and dispute evidence
  • Account data: Until account deletion request, subject to legal retention above
  • Analytics: Aggregated/anonymized data may be retained longer for trend analysis

After the retention period expires, personal data is securely deleted or anonymized. We may retain certain data longer if required by law or for legitimate business purposes such as fraud prevention or dispute resolution.


8. Cookies and Tracking Technology

We use cookies and similar tracking technologies to enhance your experience on our Platform:

8.1 Types of Cookies

  • Essential Cookies: Required for the Platform to function properly
  • Performance Cookies: Help us understand how the Platform is used
  • Functionality Cookies: Remember your preferences and settings
  • Marketing Cookies: Used to deliver relevant advertisements (with consent)

8.2 Cookie Management

You can manage your cookie preferences through your browser settings. However, disabling essential cookies may affect the functionality of the Platform.

8.3 Third-Party Tracking

We may use third-party analytics services such as Google Analytics to understand how our Platform is used. These services may collect information such as your IP address, browser type, and device information.


9. Third-Party Links

Our Platform may contain links to third-party websites, resources, or services that are not owned or controlled by Corelatin. These links are provided for convenience only and do not constitute endorsement or recommendation by Corelatin.

Corelatin has no control over and assumes no responsibility for the content, privacy policies, or practices of any third-party websites or services. You acknowledge and agree that Corelatin shall not be liable for any damages or losses caused by your use of or reliance on any third-party content, goods, or services. We encourage you to review the privacy policies of any third-party websites you visit.


10. Data Security Measures

We implement industry-standard security measures to protect your personal information:

  • Encryption in transit and at rest using industry-standard protocols
  • Access controls including role-based permissions and strong authentication for admin systems
  • Documented security practices reviewed periodically, aligned with IT (SPDI) Rules Rule 8
  • Secure hosting with reputable infrastructure providers
  • Staff training on data protection and companion confidentiality (NDA)
  • Incident response: Procedures to investigate breaches and notify affected individuals and authorities as required under DPDPA

Despite these measures, no method of transmission over the internet is 100% secure. You acknowledge that you provide your information at your own risk.


11. Children's Privacy and Minor Patients

11.1 Account holders. The Platform is not intended for persons under eighteen (18) years of age. We do not knowingly collect personal information from children under 18 for Account registration. If you believe a child under 18 registered without lawful authority, contact the Grievance Officer and we will take steps to remove the information.

11.2 Minor Patients. A Client aged 18+ may book Services for a minor Patient. We process a minor Patient's personal data โ€” including health-related information necessary for the Service โ€” only on the basis of verifiable consent from the minor's parent or lawful guardian (Representative) at booking, in accordance with DPDPA Section 9 and Terms Section 22.6. We do not use a minor Patient's data for behavioural monitoring, tracking, or targeted advertising.


12. International Data Transfer

Your personal information is primarily processed and stored within India in compliance with DPDPA 2023 data localization requirements. We may transfer your information to countries outside India only if:

  • The transfer is necessary for providing our services
  • We have obtained your explicit consent for such transfer
  • The receiving country has adequate data protection laws
  • Appropriate safeguards are in place to protect your information

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, or for other operational reasons. We will notify you of any material changes by:

  • Posting the updated policy on our Platform with a new "Last Updated" date
  • Sending an email notification to registered users
  • Displaying a prominent notice on our Platform

Your continued use of our Platform after such changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.


14. Grievance Officer & Contact Information

For questions, grievances, or to exercise data principal rights under DPDPA 2023, contact our Grievance Officer (acknowledgement within 48 hours; resolution target within 30 days, per Consumer Protection (E-Commerce) Rules, 2020):

Grievance Officer & Contact

For complaints, data rights requests, refund disputes, and policy grievances under the Consumer Protection (E-Commerce) Rules, 2020 and DPDPA 2023.

Shubham
Grievance Officer
Monday to Saturday, 9:00 AM to 6:00 PM IST
Ghaziabad, Uttar Pradesh, India

Response timeline: acknowledgement within 48 hours; resolution target within 30 days. General support (non-grievance): support@corelatin.in / +91-7398405299

You also have the right to lodge a complaint with the Data Protection Board of India if you are not satisfied with our response.

Notifications
Real-time alerts & visit updates
Loading notifications...
Go to My Bookings