Skip to content

Alitheau · Policy

Privacy notice

This notice explains what personal data Alitheau collects, why, how long we keep it and what you can ask us to do with it. It is written to meet India’s Digital Personal Data Protection Act, 2023 (“the DPDP Act”), and it is written to be read rather than skimmed past.

Last updated 7 August 2026

The short version

  • We collect only what a form asks for. There is no advertising tracking on this site and we do not sell or rent your data.
  • Anything you write in a “what is troubling you” box is deleted 90 days after your consultation or enquiry.
  • You can ask us what we hold, correct it, or have it erased — email our grievance officer.
  • Medical records created during an actual consultation are handled separately, under the record-keeping rules that apply to doctors.

Who is responsible for your data

The DPDP Act calls the organisation that decides why and how your data is processed the Data Fiduciary, and it calls you the Data Principal. In plain terms: we are responsible for your data, and it is your data.

The Data Fiduciary for this website is [registered legal entity name — to be confirmed before launch], the entity that operates Alitheau and the practice of Dr Tarang Jain Arora.

Our published contact point for anything to do with personal data is the grievance officer: [grievance officer email — to be confirmed before launch].

What we collect, and why

We collect personal data in four places. Nothing is collected silently in the background beyond what is listed under “technical data”.

1. Booking a consultation

When you book a consultation, the form asks for:

  • Your name — to identify your booking and address you correctly.
  • Phone number — to confirm the appointment, send reminders, and reach you if a slot has to change.
  • Email address — to send the booking confirmation and joining details.
  • Preferred clinic, or online — to schedule you in the right place.
  • Preferred time — to offer you a slot that works.
  • What you would like help with — a free-text box. Most people describe symptoms, test results, diagnoses or medicines here. That makes it the most sensitive thing on this site, and it is treated accordingly: see how long we keep things.

Please share what you need to and no more. The box exists so the consultation starts in a useful place, not so we can build a file on you.

2. Registering interest in the WhatsApp community

The community interest form collects your name and phone number, so we can send you the invite and so we know who asked. Once you join, the group itself runs on WhatsApp: your phone number and anything you post there are visible to other members and are governed by WhatsApp’s own terms and privacy policy, not this notice. Please do not post personal medical details in a group.

3. Registering for a learning session

Session registration collects your name, email address and, where the session is paid, the information needed to take payment. We use these to send you the joining link, any materials, and a reminder. We do not see or store your full card details — those go directly to the payment provider.

4. Technical data

  • A hashed IP address, for abuse prevention. When a form is submitted, we take the connecting IP address, combine it with a secret salt and store only the resulting hash. The raw IP address is never written to storage. The hash lets us spot the same source submitting a form fifty times; it cannot be turned back into an address or used to look you up.
  • Bot protection. Forms are protected by Cloudflare Turnstile, which checks that a submission comes from a person rather than a script.
  • Server logs kept by our hosting provider in the ordinary course of running a website, for security and reliability.
  • No third-party advertising or profiling trackers. There are no advertising pixels, no cross-site tracking and no data brokers on this site. We do not build behavioural profiles and we do not sell, rent or trade personal data to anyone.

The DPDP Act permits processing on two grounds: your consent (section 6), or a short closed list the Act calls “certain legitimate uses” (section 7) — things like a medical emergency, or data you have voluntarily given for a specific purpose without indicating that you object to its use for that purpose.

Indian law has no general “legitimate interests” balancing test of the kind found in European law, and we do not rely on one.

  • Booking, community and session forms: consent. You give it by completing and submitting the form after reading the notice next to it.
  • Confirmations and reminders about a booking you made: consent, given at the point of booking, for that specific purpose.
  • Hashed IP addresses and bot checks: the voluntary-provision legitimate use in section 7, because they arise from you choosing to submit a form and exist only to keep that form working. They are also not, in practice, data that identifies you — we hold a hash, not an address.
  • A medical emergency: section 7 permits processing to respond to a threat to someone’s life or immediate health. We hope never to rely on this, and would rely on it only for exactly that.

Marketing is never bundled into a booking. If we want to send you anything other than what you asked for, we ask separately, and you can say no without losing the thing you came for.

How long we keep things

We delete data when the purpose it was collected for is done. Three periods matter, and the site’s automated purge runs on exactly these numbers.

Health concerns: purged after 90 days

Anything you write in a free-text health box — on the booking form or any enquiry form — is permanently deleted 90 days after your consultation or enquiry.

Why: a paragraph describing your symptoms is a health narrative about you. It is genuinely useful for the few weeks around a consultation and it is a liability afterwards. Holding it for years “just in case” would create risk for you and no value for you. So we do not. Anything clinically necessary beyond that point lives in your clinical record, written by the doctor — not in a form submission.

  • Free-text health concerns: 90 days after the consultation or enquiry, then permanently deleted.
  • Booking contact details (name, phone, email, appointment history): 36 months, so that if you come back we can pick up where we left off rather than starting from nothing.
  • Abuse-prevention logs (hashed IPs): 30 days, then deleted.
  • Community and session registrations: kept while you are a member or until the session has run and its materials have been sent, and deleted when you leave or ask us to.
  • Payment and invoice records: kept for as long as tax and accounting law requires us to keep them.

Website data and medical records are not the same thing

This notice covers data collected by the website. It does not cover the clinical record created when you actually consult a doctor.

Your medical record — history, examination findings, investigations, diagnoses, prescriptions and clinical notes — is created and kept by Dr Tarang Jain Arora as a registered medical practitioner, under the record-keeping obligations that apply to medical practice in India. It is stored separately from the website, retained for the period those obligations require, and released only as medical confidentiality allows or the law requires.

The practical consequence: we can delete your website data on request, but we cannot delete a clinical record that a doctor is required to keep. If you ask us to erase everything, we will tell you plainly what was deleted and what had to stay.

How we ask

  • We ask at the point of collection, next to the form, not buried in a document you have to go looking for.
  • We ask separately for separate things. Consent to be contacted about your booking is not consent to receive a newsletter, and ticking one never silently ticks the other.
  • Nothing is pre-ticked. Consent needs a clear action from you.
  • We ask only for what the purpose needs. If a field is optional, it says so.

How to withdraw it

You can withdraw consent at any time, and it must be as easy to withdraw as it was to give. Email [grievance officer email — to be confirmed before launch] saying what you want to withdraw — one line is enough. Emails we send you also carry an unsubscribe link, and leaving the WhatsApp community withdraws your consent for it.

When you withdraw consent we stop the processing that relied on it and delete the data, unless we are legally required to keep it. Withdrawing consent does not make anything we did before it unlawful, and it may mean we can no longer provide the thing you had asked for — for example, we cannot confirm an appointment if we may not contact you.

Your rights

The DPDP Act gives you the following rights. To use any of them, email [grievance officer email — to be confirmed before launch]. Please write from the email address you gave us, or include enough detail for us to find your record — we may ask a question or two to confirm it is you before we act, because handing your data to the wrong person is the failure that matters most.

  • Access and a summary of processing (section 11). Ask us what personal data of yours we hold, what we are doing with it, and who we have shared it with. We will send you a written summary.
  • Correction, completion and updating (section 12). If something we hold is wrong, incomplete or out of date, tell us and we will fix it.
  • Erasure (section 12). Ask us to delete your personal data. See the next section for exactly what that means in practice.
  • Grievance redressal (section 13). Complain to us directly about how we have handled your data, and get an answer. You do not have to go to the regulator first.
  • Nomination (section 14). You may nominate another person to exercise these rights on your behalf if you die or become unable to act for yourself. Email us the nominee’s name and contact details and we will record the nomination against your data. You can change or remove it whenever you like.

We will acknowledge any request within seven days and complete it within 30 days. If a request is genuinely complicated we will tell you why and when it will be done. We do not charge for any of this.

Asking us to delete your data

Email [grievance officer email — to be confirmed before launch] with “Delete my data” and, if you can, the name, phone number or email address you used. That is the whole process.

What we will delete: your booking records and contact details, anything you wrote in a health concern box that has not already been purged, community and session registrations, and any correspondence held on the website systems.

What we cannot delete: clinical records arising from a consultation you actually attended, which a registered medical practitioner is obliged to retain; and financial records such as invoices, which tax law requires us to keep. We will tell you which of these applies to you.

Timeline: acknowledgement within seven days, deletion completed within 30 days, including from routine backups on their next cycle. Deletion is permanent — we cannot restore data afterwards, so please be sure.

Who else touches your data

We do not sell, rent or trade personal data. We do use a small number of service providers — the DPDP Act calls them Data Processors — who process data only on our instructions and only for these purposes:

  • Cloudflare — hosts the website, runs the application (Cloudflare Workers) and stores form submissions in a Cloudflare D1 database. Cloudflare Turnstile provides the bot check on our forms.
  • Resend — sends transactional email such as booking confirmations, reminders and joining links. It receives your email address and the contents of that message.
  • Payment providers, for paid consultations and sessions. They handle payment details directly; we receive confirmation that a payment succeeded, not your card number.

We will also disclose personal data where the law requires it — for example, under a valid legal order — and, in a medical emergency, where it is needed to protect someone’s life or immediate health.

Where your data is stored

Our providers run global infrastructure, so your data may be processed or stored on servers outside India. The DPDP Act permits transfer of personal data outside India, except to countries the Central Government restricts by notification. We do not transfer data to any country currently subject to such a restriction, and we will change providers if that becomes necessary.

Children

This site is written for adults and is not directed at anyone under 18. We do not knowingly collect personal data from children.

The DPDP Act requires verifiable consent from a parent or lawful guardian before a child’s data is processed, and prohibits tracking, behavioural advertising and targeted advertising directed at children. We do not attempt to obtain verifiable parental consent through this website, because we are not equipped to verify it properly. If you are under 18, please do not submit any form on this site. A parent or guardian should contact us instead.

If you believe a child has submitted personal data to us, email [grievance officer email — to be confirmed before launch] and we will delete it.

How we protect it

We take reasonable security safeguards, as the DPDP Act requires, proportionate to the fact that some of what we hold concerns health. In general terms:

  • Everything travels over encrypted connections (HTTPS), and stored data sits on infrastructure with encryption at rest.
  • Access is limited to the few people who need it to do their job, and is protected by strong authentication.
  • We collect as little as we can, and delete on the schedule above. The data we do not hold cannot leak.
  • IP addresses are hashed with a secret salt rather than stored, so our abuse logs contain nothing that identifies a person.
  • Forms are rate-limited and protected against automated abuse.

No system is perfectly secure, and we will not pretend otherwise. What we can promise is that we do not keep data we do not need.

If there is a breach

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person, in the manner and within the time the law prescribes. Our notice to you will say what happened, what data was involved, what we are doing about it, and what you should do.

Complaints

Start with us. Our grievance officer is responsible for answering questions and complaints about how your personal data is handled:

Grievance officer

Email: [grievance officer email — to be confirmed before launch]

On behalf of: [registered legal entity name — to be confirmed before launch]

We acknowledge within seven days and aim to resolve within 30.

If we do not resolve your complaint, or you are unhappy with our answer, you may complain to the Data Protection Board of India, the authority established under the DPDP Act to hear complaints from Data Principals.

The Act also places duties on you as a Data Principal — in particular, not to impersonate someone else and not to file false or frivolous complaints.

Changes to this notice

When we change this notice we update the date at the top of the page. If a change materially affects your rights or how we use your data — a new purpose, a new category of data, a longer retention period, a new processor — we will say so prominently on this page and, where we hold a working email address for you and the change matters, we will email you. We do not apply a materially new purpose to data already collected without asking you again.

Contact

Anything about your data: [grievance officer email — to be confirmed before launch]. Anything else: [general contact email — to be confirmed before launch].

Our terms of use govern your use of this site, and the medical disclaimer explains what the content here is and is not.