Privacy Policy

Effective 4 October 2026 · Version 2026-10-04

This Privacy Policy explains how Elena Digital Pvt. Ltd. ("we", "us", "our") collects, uses, stores, discloses and protects personal information when you use ARVIA ("Application", "App" or "Platform").

The Application is a doctor-focused patient and prescription management platform. It allows registered doctors to manage patient records, create and maintain prescriptions, upload prescription images, and provide restricted access to authorised compounders.

We take privacy and security seriously, particularly because information processed through the Application may include health and medical information.

Contents
  1. 1Who We Are
  2. 2Information We Collect
  3. 3Prescription and Medical Information
  4. 4Prescription Images and Camera Data
  5. 5Compounder Information
  6. 6Device and Technical Information
  7. 7How We Use Personal Information
  8. 8Legal Basis / Consent
  9. 9Patient Data Entered by Doctors
  10. 10Use of WhatsApp, SMS and Email
  11. 11Sharing of Personal Information
  12. 12Role-Based Access
  13. 13Data Security
  14. 14Data Retention
  15. 15Data Transfers
  16. 16Children's Data
  17. 17Your Privacy Rights
  18. 18How to Exercise Privacy Rights
  19. 19Complaints and Grievances
  20. 20Cookies and Similar Technologies
  21. 21Analytics
  22. 22Third-Party Services
  23. 23Data Breach and Security Incidents
  24. 24Account Closure
  25. 25Changes to This Privacy Policy
  26. 26Contact Us
  27. 27Acknowledgement

1Who We Are

  • Elena Digital Pvt. Ltd.
  • Registered Address: [REGISTERED ADDRESS]
  • Email: [GENERAL EMAIL]
  • Privacy Contact: [PRIVACY CONTACT NAME/ROLE]
  • Privacy Email: [PRIVACY EMAIL]
  • Phone: [PHONE NUMBER]

For applicable data-protection purposes, our role may differ depending on the data and processing activity. We may determine the purposes and means of processing certain information ourselves and may process information on behalf of a doctor or healthcare organisation under applicable contractual arrangements.

Where applicable, we will comply with the obligations imposed on us under applicable data-protection laws.

2Information We Collect

Depending on how you use the Application, we may collect the following categories of information.

2.1 Doctor Account Information

When a doctor registers, we may collect:

  • First name and last name;
  • Mobile number;
  • Email address, if provided;
  • Country;
  • Referral code, if applicable;
  • Password or authentication information;
  • OTP verification information;
  • Profile photograph, if provided;
  • Account preferences; and
  • Login/session and security information.

Mobile verification is mandatory during doctor registration; an email address is optional.

2.2 Patient Information

Doctors may enter patient information into the Application, including:

  • First name and last name;
  • Mobile number;
  • Email address, if provided;
  • Age;
  • Gender;
  • Fever/temperature;
  • Blood pressure;
  • Patient ID;
  • Visit information;
  • Prescription information;
  • Medicine information;
  • Dosage and frequency;
  • Duration;
  • Prescription instructions and notes; and
  • Amount charged.

A mobile number may be shared by multiple patient records, including family members. The Application therefore treats the patient record/Patient ID separately from the mobile number.

3Prescription and Medical Information

The Application may process information contained in prescriptions and related medical records.

This may include:

  • Medicines;
  • Potency;
  • Dosage;
  • Form;
  • Frequency;
  • Duration;
  • Prescription instructions;
  • Clinical notes entered by the doctor;
  • Vitals such as fever and blood pressure;
  • Prescription history; and
  • Images of physical prescriptions.

This information is processed to provide the patient-management and prescription-management functionality of the Application.

4Prescription Images and Camera Data

The Application may allow doctors to capture or upload photographs of existing physical prescriptions.

Where this feature is used:

  • The Application may request access to the device camera;
  • The doctor may select an image from the device gallery;
  • The image may be cropped or rotated;
  • The resulting image may be stored with the relevant patient prescription record.

We do not access your camera or gallery continuously. Access is requested when required for an applicable feature and subject to the permissions provided through your device.

5Compounder Information

A doctor may create an account for an authorised compounder.

We may collect:

  • Compounder's name;
  • Mobile number;
  • Email address, if provided;
  • Login/OTP information;
  • Account status; and
  • Access and security information.

The compounder receives restricted access and does not receive the same information available to the doctor. Compounder access is restricted to the information necessary for dispensing, such as patient name, prescribed medicine, potency and served/not-served status.

6Device and Technical Information

When you access the Application, we may automatically collect certain technical information, where necessary for operation, security and troubleshooting, such as:

  • IP address;
  • Device type;
  • Operating system;
  • Browser type;
  • Application version;
  • Device identifiers, where applicable;
  • Login timestamps;
  • Session information;
  • Error logs;
  • Security events; and
  • Other technical information necessary to operate and secure the Application.

The Application may display the app version/build number for troubleshooting purposes.

7How We Use Personal Information

We may process personal information for purposes including:

Account and Authentication

  • Creating and maintaining accounts;
  • Verifying mobile numbers;
  • Sending OTPs;
  • Authenticating users;
  • Password recovery;
  • Preventing unauthorised access; and
  • Managing login sessions.

Patient and Prescription Management

  • Creating patient records;
  • Maintaining prescription records;
  • Displaying prescription history;
  • Uploading and storing prescription images;
  • Searching patient records; and
  • Providing medicine auto-suggestion functionality.

Compounder Management

  • Creating and managing authorised compounder accounts;
  • Providing role-based access;
  • Tracking access and account status; and
  • Revoking access when required.

Service and Support

  • Responding to support requests;
  • Troubleshooting technical problems;
  • Sending service-related communications;
  • Maintaining application performance; and
  • Improving reliability and security.

Security and Compliance

  • Detecting fraud and unauthorised activity;
  • Protecting user and patient information;
  • Maintaining appropriate audit/security records;
  • Investigating security incidents; and
  • Complying with applicable legal obligations.

8Legal Basis / Consent

Where required by applicable law, we will process personal information based on appropriate legal grounds, including consent or another lawful basis available under applicable law.

Where processing is based on consent, you may withdraw consent through the mechanism made available by us, subject to legal and operational limitations.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

The DPDP Rules, 2025 require notices to clearly explain the personal data being processed and the specific purposes for processing, and provide mechanisms for withdrawal of consent and exercise of rights.

9Patient Data Entered by Doctors

Doctors may enter patient information into the Application as part of providing healthcare services.

The doctor remains responsible for ensuring that patient information is collected and processed lawfully and that any required patient notice, consent or other authorisation is obtained.

Where the doctor uses the Application on behalf of a clinic, hospital or other healthcare organisation, the relevant organisation may have additional responsibilities under applicable law and contractual arrangements.

We do not require patients to create an Application account merely because their information is entered by a doctor.

10Use of WhatsApp, SMS and Email

We may use third-party communication providers to send:

  • OTPs;
  • Login verification messages;
  • Password recovery communications;
  • Security alerts;
  • Service notifications;
  • Support communications; and
  • Promotional communications where legally permitted and appropriately authorised.

If you opt in to promotional WhatsApp, SMS or email communications, you may withdraw that preference using the available unsubscribe or notification-control mechanism.

Essential service and security communications may still be sent where necessary.

11Sharing of Personal Information

We do not sell personal information as a standalone product.

We may share or provide access to information where reasonably necessary with:

Service Providers

Technology providers supporting:

  • Cloud hosting;
  • Database infrastructure;
  • Authentication;
  • SMS/OTP delivery;
  • WhatsApp messaging;
  • Email delivery;
  • Security;
  • Monitoring;
  • Customer support; and
  • Other infrastructure necessary to provide the Application.

Authorised Users

Information may be accessible to the doctor who manages the relevant patient record and to authorised compounders/staff only to the extent permitted by their assigned role.

Legal and Regulatory Authorities

We may disclose information where required by applicable law, legal process, court order, governmental authority or other lawful request.

Business Transactions

Information may be transferred as part of a merger, acquisition, restructuring, financing, sale of assets or similar transaction, subject to applicable law and appropriate safeguards.

12Role-Based Access

We use role-based access controls to limit the information available to different users.

Doctors may access patient and prescription information associated with their records.

Compounders receive restricted access. Under the current Application requirements, compounders cannot access full prescription notes, patient contact information, vitals or billing/amount information.

We may modify access controls as the Application evolves, provided that applicable privacy and security requirements continue to be addressed.

13Data Security

We implement reasonable technical and organisational security measures designed to protect personal information against unauthorised access, alteration, disclosure, loss or destruction.

These measures may include:

  • Encryption in transit;
  • Encryption at rest;
  • Role-based access controls;
  • Authentication and OTP verification;
  • Access restrictions;
  • Security monitoring;
  • Secure session management;
  • Backup and recovery controls;
  • Security testing and maintenance; and
  • Audit/security logs.

The Application is required to encrypt patient data and prescriptions in transit and at rest, and to give each role only the access to patient records appropriate to it.

No digital system can guarantee absolute security. Users must also protect their passwords, OTPs, devices and account access.

14Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, to provide the services, to maintain appropriate records, to resolve disputes, to enforce agreements, to maintain security, or to comply with applicable legal obligations.

Retention periods may vary depending on:

  • The type of information;
  • Whether the account remains active;
  • The nature of the healthcare record;
  • Legal or regulatory requirements;
  • Security and fraud-prevention requirements;
  • Dispute resolution; and
  • Backup and disaster-recovery requirements.

When information is no longer required, we may delete, anonymise or otherwise securely dispose of it, subject to applicable law and legitimate retention requirements.

15Data Transfers

Personal information may be processed or stored using service providers located in India or other jurisdictions, subject to applicable law.

Where personal information is transferred across jurisdictions, we will implement applicable contractual, technical and organisational safeguards as required by law.

16Children's Data

The Application is intended primarily for healthcare professionals and authorised staff.

Patient records may nevertheless relate to children.

Where personal information relating to a child is processed, we will apply the requirements applicable to children’s personal data under relevant data-protection laws.

Doctors and other users must not knowingly use the Application to circumvent applicable requirements relating to children or parental/guardian consent.

17Your Privacy Rights

Subject to applicable law, individuals may have rights relating to their personal information, including rights to:

  • Obtain information about processing;
  • Request access to personal information;
  • Request correction of inaccurate information;
  • Request deletion/erasure where applicable;
  • Withdraw consent where processing is based on consent;
  • Raise grievances;
  • Nominate another person to exercise applicable rights in certain circumstances; and
  • Exercise other rights provided by applicable data-protection law.

The availability and scope of these rights may depend on the applicable law and the role of the relevant party in the processing.

18How to Exercise Privacy Rights

To submit a privacy request, contact:

  • Privacy / Grievance Contact: [PRIVACY CONTACT NAME/ROLE]
  • Email: [PRIVACY EMAIL]
  • Address: [REGISTERED ADDRESS]
  • Phone: [PHONE NUMBER]

Please include sufficient information for us to identify the relevant account or request.

We may request reasonable information to verify your identity before processing a request.

We will respond within the period required by applicable law.

19Complaints and Grievances

If you have a privacy-related complaint or believe your personal information has been processed improperly, you may contact our designated privacy/grievance contact at:

  • [GRIEVANCE OFFICER / PRIVACY CONTACT]
  • Email: [GRIEVANCE EMAIL]
  • Phone: [PHONE NUMBER]
  • Address: [REGISTERED ADDRESS]

If applicable law provides a right to escalate a complaint to a regulatory authority or the Data Protection Board of India, you may exercise that right in accordance with the applicable procedure.

20Cookies and Similar Technologies

The web version of the Application may use cookies or similar technologies necessary for:

  • Authentication;
  • Session management;
  • Security;
  • Preferences;
  • Performance monitoring; and
  • Other functionality.

Where non-essential cookies or similar technologies are used, appropriate consent or controls will be provided where required by applicable law.

21Analytics

If analytics or product-performance tools are used, they may collect technical or usage information such as:

  • Pages/screens accessed;
  • Feature usage;
  • Device information;
  • Application performance;
  • Error information; and
  • General usage patterns.

Analytics should not be used to access or disclose patient medical information beyond what is necessary and legally permitted for the stated purpose.

22Third-Party Services

The Application may integrate with third-party services such as WhatsApp, SMS providers, email providers, cloud infrastructure providers, authentication services and other technology providers.

Those providers may process information according to their own terms and privacy policies.

Where appropriate, users will be provided with relevant information about such third-party processing.

23Data Breach and Security Incidents

If we become aware of a personal-data breach affecting information processed through the Application, we will assess and respond to the incident in accordance with applicable law.

Where notification to affected individuals, authorities or other parties is legally required, we will provide the required notification within the applicable timeframe.

24Account Closure

A doctor may request closure of their account by contacting [SUPPORT EMAIL].

Account closure does not necessarily result in immediate deletion of every record.

Certain information may need to be retained for legal, regulatory, security, dispute-resolution, contractual or other lawful purposes.

Where deletion is appropriate, information will be deleted or anonymised subject to applicable retention requirements.

25Changes to This Privacy Policy

We may update this Privacy Policy when our services, data-processing practices, technology or legal obligations change.

When material changes are made, we will provide appropriate notice through the Application, website, email or another reasonable method.

The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently revised.

26Contact Us

For general questions about this Privacy Policy:

  • Elena Digital Pvt. Ltd.
  • Address: [REGISTERED ADDRESS]
  • Email: [PRIVACY EMAIL]
  • Phone: [PHONE NUMBER]
  • Website: [WEBSITE]

For privacy requests and complaints:

  • Privacy / Grievance Contact: [PRIVACY CONTACT NAME/ROLE]
  • Email: [GRIEVANCE EMAIL]

27Acknowledgement

By using the Application, you acknowledge that you have had an opportunity to review this Privacy Policy.

Where consent is required for a particular processing activity, the Application will seek the relevant consent through an appropriate mechanism.