ONICARES AI PRIVATE LIMITED
Privacy Policy
AI-Powered Continuum Pregnancy Care Platform
Version 1.0
Effective date: 2 July 2026
Last updated: 2 July 2026
Applicable to the ONI MOM, ONI DIDI and ONI Clinician Dashboard products, and to future ONI products and services.
1. Introduction and Scope
This Privacy Policy (the “Policy”) explains how ONICARES AI PRIVATE LIMITED (referred to in this Policy as “ONI”, “we”, “us” or “our”), a company incorporated in India and operating under the ONI brand, collects, uses, discloses, stores, protects and otherwise processes personal data when you access or use our platform, mobile applications, web applications, voice services and related services (together, the “Services”).
ONI operates an artificial-intelligence-powered continuum pregnancy care platform that supports pregnant mothers and the clinicians who care for them across the full course of a pregnancy. Because the Services involve health information and clinical workflows, we treat the protection of your data as a core part of the care we help deliver, and we have designed this Policy to be transparent about what we do with your information.
1.1 Products covered by this Policy
This Policy applies to the following ONI products and services, whether accessed through a mobile device, a web browser, an application programming interface, a voice interface or any other channel we make available:
- ONI MOM – a mobile application for pregnant mothers that supports pregnancy monitoring, structured pregnancy records, patient engagement, appointment management, health logging and educational content.
- ONI DIDI – a clinician-facing voice artificial intelligence application that supports voice-assisted interaction, clinical documentation and workflow support.
- ONI Clinician Dashboard – a web application used by clinicians and their authorised staff to manage patients, review structured pregnancy records, generate clinical workflows and coordinate care.
This Policy also applies to any future ONI products, features, models and services that reference or link to this Policy, unless a separate or supplementary privacy notice is provided for a specific product, in which case that notice will govern that product to the extent of any inconsistency.
1.2 Our role under Indian data protection law
For the purposes of the Digital Personal Data Protection Act, 2023 of India (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”), ONI generally acts as a Data Fiduciary in respect of the personal data it determines the purposes and means of processing, and as a Data Processor where we process personal data on behalf and under the instructions of a healthcare provider or other Data Fiduciary. Where we act as a Data Processor, the relevant healthcare provider or organisation remains responsible for the lawful basis of the processing, and this Policy should be read together with that organisation’s own privacy notice.
Where United States law applies – for example, where we process protected health information on behalf of a covered entity or business associate as those terms are used under the U.S. Health Insurance Portability and Accountability Act (“HIPAA”) – we align our handling of that information with HIPAA-consistent safeguards. Nothing in this Policy should be read as a claim that ONI holds any specific certification or formal accreditation; we describe only the practices we actually follow.
1.3 Your acceptance
By creating an account, accessing or using the Services, or otherwise providing personal data to us, you acknowledge that you have read and understood this Policy. Where the law requires your consent for a particular processing activity, we will seek that consent separately and specifically, and this Policy is not a substitute for that consent. If you do not agree with this Policy, please do not use the Services.
2. Definitions
In this Policy, the following terms have the meanings set out below. Terms defined in the DPDP Act and the DPDP Rules carry the meaning given to them in that legislation unless the context requires otherwise.
| Term | Meaning |
|---|---|
| Personal Data | Any data about an individual who is identifiable by or in relation to such data, whether directly or indirectly. |
| Health Data / Clinical Data | Personal data relating to a person’s physical or mental health, pregnancy, medical history, diagnoses, test results, treatment and care. We treat such data with heightened care given its sensitivity. |
| Data Principal | The individual to whom personal data relates. In the case of a child, this includes the parent or lawful guardian; in the case of a person with a disability, it includes the lawful guardian acting on their behalf. |
| Data Fiduciary | The person or entity that, alone or with others, determines the purpose and means of processing personal data. |
| Data Processor | Any person or entity that processes personal data on behalf of a Data Fiduciary. |
| Processing | Any operation performed on personal data, including collection, recording, organisation, storage, use, disclosure, transfer and erasure. |
| Consent Manager | A person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform. |
| De-identified / Anonymised Data | Data that has been processed so that it can no longer reasonably be linked to an identified or identifiable individual. |
| Sub-Processor / Service Provider | A third party engaged by ONI to process personal data or to provide infrastructure or services that support the Services. |
| DPDP Act / DPDP Rules | The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as amended from time to time. |
| Board | The Data Protection Board of India established under the DPDP Act. |
3. Who We Are and How to Reach Us
ONI is the trading brand of the company identified below. This is the entity responsible for the Services and for the processing of personal data described in this Policy.
| Item | Details |
|---|---|
| Legal entity | ONICARES AI PRIVATE LIMITED |
| Brand | ONI |
| Registered address | 6-2A, Krishna Residency, 4th Cross, Amarjyothi Nagar, Vijayanagar (Bangalore), Bangalore North, Bangalore – 560040, Karnataka, India |
| Privacy contact | support@onicares.com |
| Support contact | support@onicares.com |
| Grievance Officer | Office of the Grievance Officer, ONICARES AI PRIVATE LIMITED, at the registered address above – support@onicares.com |
Full contact details, including the mechanisms for exercising your rights and raising complaints, are set out in Section 23 (Grievance Redressal and Contacting Us).
4. Applicability of this Policy
4.1 Who this Policy is for
This Policy is intended for all users of the Services, including:
- Pregnant mothers and patients who use ONI MOM or whose information is recorded in the platform in the course of their care;
- Clinicians and healthcare providers who use ONI DIDI and the ONI Clinician Dashboard, together with their authorised staff;
- Healthcare organisations (such as clinics and hospitals) that deploy ONI to deliver care to their patients; and
- Visitors to our websites and other public interfaces.
4.2 What this Policy does not cover
This Policy does not cover the practices of third parties that we do not own or control, including third-party websites, applications, devices or services that you may connect to or access through the Services. Those third parties operate under their own privacy notices, and we encourage you to review them. Where a healthcare provider uses ONI to deliver care, that provider’s own privacy notice governs the relationship between you and that provider.
5. Categories of Personal Data We Collect
We collect only the categories of personal data that are reasonably necessary to provide, secure and improve the Services. The specific data collected depends on which product you use and how you interact with it. The categories below describe the full range of data that the platform may process; not every category applies to every user.
5.1 Identity and contact information
- Name, date of birth, age, sex and gender where relevant to care;
- Contact details such as mobile number, email address and postal address;
- Emergency contact and next-of-kin details, where provided;
- Government or provider-assigned identifiers strictly where required for care or verification, which we minimise wherever possible.
5.2 Authentication and account information
- Login identifiers, hashed passwords or one-time-password verification records;
- Account role and permissions (for example, patient, clinician or administrator);
- Session tokens, security questions and multi-factor authentication data;
- Records of consent, preferences and settings associated with your account.
5.3 Clinical and pregnancy information
This is the most sensitive information we process and includes, as applicable:
- Pregnancy information such as gestational age, expected delivery date, obstetric history and pregnancy milestones;
- Medical history, allergies, existing conditions and risk factors;
- Consultation notes and AI-assisted clinical documentation;
- Appointments, referrals and follow-up schedules;
- Prescriptions and medication records;
- Vitals such as blood pressure, weight, heart rate and blood glucose;
- Antenatal and laboratory test reports and results;
- Uploaded documents and medical images;
- Structured pregnancy records generated within the platform;
- Health logs, symptoms and self-reported observations.
5.4 Voice and communication data
- Voice conversations processed by our voice AI;
- Voice transcripts generated from those conversations;
- Voice recordings, where retention of the recording is required for clinical, quality, legal or safety purposes;
- Chat messages and in-app communications;
- Support requests, feedback and correspondence with us.
5.5 Device, technical and usage data
- Device information such as device model, operating system and app version;
- Technical metadata, network information and identifiers necessary for the Services to function;
- Usage analytics describing how features are used;
- Crash logs and diagnostic information;
- Security logs and audit logs recording access to and actions within the platform;
- Approximate or precise location, only where a feature requires it and only with any consent required by law.
5.6 Transactional and preference data
- Payment information, where a paid feature applies – typically processed by a third-party payment provider, so that we do not store full card or financial-account numbers;
- Notification and communication preferences, including opt-in and opt-out choices;
- Data collected through cookies and similar technologies, as described in Section 19.
A note on sensitive information
Much of the data described above is health data. We do not ask you to provide health information that is not relevant to your care or to the operation of the Services, and we apply heightened technical and organisational safeguards to it as described in Section 15.
6. How We Collect Your Information
We collect personal data through a combination of information you provide directly, information generated as you use the Services, and information we receive from healthcare providers and trusted third parties.
6.1 Information you provide to us
- Mobile applications. When you register for and use ONI MOM or ONI DIDI, you may enter profile details, pregnancy information, health logs, documents and preferences.
- Web application. Clinicians and authorised staff enter and manage clinical information through the ONI Clinician Dashboard.
- Manual entry. Information you type, upload or dictate, including documents, images and notes.
- Voice AI. Information captured when you speak with our voice AI, including the audio processed and the transcript produced.
- Support interactions. Information you share when you contact support, submit feedback or report a problem.
6.2 Information from healthcare providers
Where a clinic, hospital or clinician uses ONI to deliver care, they may enter or upload clinical information about you, including consultation notes, prescriptions, reports and structured pregnancy records. In these cases the provider is typically the Data Fiduciary and ONI processes the data on their behalf and under their instructions.
6.3 Information collected automatically
- Connected devices. Where you choose to connect a compatible device or sensor, we may receive health measurements from it.
- Automatic analytics. As you use the Services, we automatically collect usage, device and technical data to operate, secure and improve the platform.
- Cookies and similar technologies. On our web interfaces we use cookies and similar technologies as described in Section 19.
- Security and audit logging. We automatically record access and actions within the platform for security, integrity and accountability.
6.4 Information from third-party integrations
The Services rely on third-party providers for infrastructure, communications, analytics, error monitoring and artificial-intelligence processing. Data may be collected or generated through those integrations for the limited purposes described in Section 12. We may also add, change or remove integrations over time as described in that Section.
7. Purposes of Processing
We process personal data only for specified, lawful purposes that are compatible with delivering safe pregnancy care and operating the Services responsibly. The principal purposes are set out below.
| Purpose | What this involves |
|---|---|
| Providing the Services | Creating and managing accounts; delivering pregnancy monitoring, structured records, patient engagement, appointments and care coordination. |
| Clinical workflows | Generating and supporting clinical pathways and documentation to help clinicians deliver continuum care. |
| AI assistance | Providing AI-assisted documentation, report parsing, guidance generation and other AI-supported features described in Section 9. |
| Voice interaction | Enabling voice conversations, transcription and voice-assisted documentation as described in Section 10. |
| Authentication & access | Verifying identity, managing roles and permissions, and protecting accounts. |
| Customer support | Responding to queries, troubleshooting and resolving issues. |
| Security & fraud prevention | Detecting, investigating and preventing unauthorised access, misuse, fraud and other security events. |
| Regulatory compliance | Meeting our obligations under the DPDP Act, health-sector requirements and other applicable law. |
| Analytics & improvement | Understanding how the Services are used so we can improve performance, reliability and usability. |
| Bug fixing & reliability | Diagnosing and resolving errors, crashes and defects. |
| Research & platform improvement | Improving the platform and our AI systems, using de-identified data as described in Section 11. |
| Communication | Sending service messages, appointment reminders, test reminders, health reminders and administrative notifications. |
| Operational purposes | Backups, disaster recovery, capacity planning and general administration of the Services. |
Where we wish to process your personal data for a new purpose that is not compatible with those described above, we will provide a further notice and, where required, seek your consent before doing so.
8. Legal Basis and Consent
Under the DPDP Act, we process personal data on the basis of your consent or for certain legitimate uses permitted by law. Where we rely on consent, that consent will be free, specific, informed, unconditional and unambiguous, and given through a clear affirmative action. We will tell you, in plain language, what data we seek, the purposes for which it will be processed, how you may withdraw consent, and how you may exercise your rights and make a complaint.
8.1 Withdrawing consent
You may withdraw your consent at any time, as easily as it was given, using the contact details or in-app controls described in this Policy. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. Please note that if you withdraw consent for processing that is essential to a feature or to your care, we may no longer be able to provide that feature, and we will explain the consequences to you where relevant. Withdrawal of consent does not require us to erase data that we are required to retain under applicable law, as described in Section 17.
8.2 Consent Managers
Where a Consent Manager registered with the Data Protection Board of India is available, you may choose to give, manage, review and withdraw your consent through that Consent Manager. We will honour valid instructions received through such a mechanism in accordance with the DPDP Rules.
8.3 Consent on behalf of others
If you provide personal data about another person – for example, an emergency contact – you confirm that you are authorised to share that information and to have it processed as described in this Policy. Consent relating to a child or a person with a disability is addressed in Section 20.
9. Use of Artificial Intelligence
Artificial intelligence is central to how ONI supports continuum pregnancy care. This Section explains, in plain terms, how AI is used, what it does and does not do, and which outputs are and are not reviewed by a clinician before they reach you. Please read it carefully.
9.1 AI assists clinicians – it does not replace them
Our AI systems are designed to assist clinicians and support the delivery of care. They are decision-support and productivity tools. AI does not replace the professional judgement of a qualified clinician, and responsibility for clinical decisions relating to diagnosis, treatment and care remains with the treating clinician and the healthcare provider. AI outputs are not a substitute for professional medical advice, diagnosis or treatment, and should not be relied upon as such.
9.2 Clinical decisions remain under clinician oversight
Clinically significant recommendations – those that could materially affect diagnosis, treatment or the management of a pregnancy – remain under clinician oversight. Such recommendations are intended to be reviewed, confirmed or acted upon by a qualified clinician before they influence your care.
9.3 Automatically generated content
Because ONI delivers continuum care across the length of a pregnancy, certain non-diagnostic, supportive and administrative content may be generated and delivered automatically, without individual clinician review of each item before it reaches you. This may include:
- Appointment reminders;
- Test and screening reminders;
- Educational content and general pregnancy information;
- General health tips;
- Follow-up and check-in messages;
- Administrative and operational messages;
- Patient engagement workflows; and
- General pregnancy guidance that is not specific clinical advice.
This content is general and supportive in nature. It is not personalised medical advice, and it is not a substitute for consulting your clinician. If you receive automatically generated content that seems inconsistent with advice from your clinician, or if you have any concern about your health or your pregnancy, you should rely on and contact your clinician.
Important safety information
The Services are not designed for use in a medical emergency. If you believe you are experiencing an emergency, or if you have urgent or worsening symptoms, do not rely on the app or on automatically generated content – contact your clinician or local emergency services immediately.
9.4 How AI processing works
Our AI features may use large language models and other AI technologies to parse antenatal test reports, generate clinical pathways, support documentation and power voice interaction. Clinical pathway generation currently uses leading medical and general-purpose large language models. Future versions of the Services may use models developed by ONI. Where we make a material change to how AI is used in a way that affects your personal data, we will update this Policy and provide notice where required.
10. Voice AI
Some of our Services, including ONI DIDI, use voice artificial intelligence. Voice AI combines speech-to-text (to convert speech into text), a large language model (to understand and generate responses), and text-to-speech (to produce spoken output). This Section explains how we handle voice data.
- Processing of conversations. Your voice conversations with the Services may be processed to understand what is said, to respond, and to support documentation and clinical workflows.
- Transcripts. We may generate and store transcripts of voice conversations so that the content can be used within the platform, for example as part of clinical documentation.
- Recordings. We may store voice recordings where retention of the audio is required for clinical, quality-assurance, safety, legal or regulatory purposes. Where we do not require the recording, we aim to retain only the transcript or to minimise what is kept.
- Consent. Where consent is required for the recording or processing of voice data, we will obtain it. You will be informed when voice features are active.
- Improvement of our systems. Conversation data may be used to improve ONI’s systems only after it has been de-identified, as described in Section 11.
11. De-identified and Anonymised Data
We are committed to improving the safety, accuracy and usefulness of the Services while protecting the privacy of patients. To do this responsibly, we rely on de-identified and anonymised information rather than identifiable patient data wherever possible.
11.1 How we use de-identified data
ONI may use anonymised or de-identified information, including information derived from data across multiple healthcare providers, to:
- Improve our artificial-intelligence systems;
- Improve analytics and reporting;
- Improve clinical and operational workflows;
- Improve our internal systems and infrastructure; and
- Develop and improve future ONI models.
De-identified and anonymised data is processed so that it can no longer reasonably be linked back to an identified or identifiable individual. We apply appropriate technical and organisational measures to reduce the risk of re-identification.
11.2 What we do not do
We do not use identifiable patient data to train our AI models. Improvement of our AI systems is carried out using de-identified or anonymised data, or synthetic and aggregate data, rather than identifiable patient records.
11.3 General-purpose AI providers
Where the Services rely on general-purpose AI providers to process requests, those providers are not intended to use data submitted through their enterprise or developer services to train their own models, based on the service commitments those providers make to their business customers. We select and configure our use of these providers with that expectation. Because those commitments are made and maintained by the providers themselves, we cannot guarantee the internal practices of any third party; we monitor their published terms and act to keep our configuration consistent with the protections described in this Policy.
12. Third-Party Service Providers and Sub-Processors
We work with a limited number of carefully selected third-party providers who help us deliver, secure, analyse and improve the Services. These providers process personal data only as needed to perform their functions, under contractual obligations of confidentiality and security, and are not permitted to use the data for their own unrelated purposes. The current providers are set out below.
| Provider | Function | Categories of data involved |
|---|---|---|
| Google Cloud – Cloud Run | Hosting and running the backend application services. | All categories processed by the backend, including account, clinical and technical data. |
| Google Cloud – Cloud SQL (PostgreSQL) | Managed primary database. | Account, clinical, pregnancy, communication and operational data. |
| Google Cloud – Cloud Storage | Storage of files, documents, images and other objects. | Uploaded documents, medical images and related files. |
| Google Cloud – Memory Store (Redis) | Caching and real-time / session data. | Session, technical and transient operational data. |
| Google Cloud – Vertex AI | Managed AI platform for running AI models and requests. | Data submitted to AI features, which may include clinical and voice-derived content. |
| Google AI Studio | Access to Google AI model services used in development and delivery of AI features. | Data submitted to AI features. |
| Google Gemini (incl. Gemini Live, Gemini 2.5 and Gemini 2.5 Flash Live) | Large-language-model and voice-AI processing. | Text and voice-derived content submitted to AI features. |
| BioMistral | Medical large-language-model used within AI processing. | Clinical and pregnancy-related content submitted to AI features. |
| GLM OCR | Optical character recognition for parsing uploaded reports and documents. | Uploaded documents and images and the text extracted from them. |
| Twilio | Communications, including messaging and voice connectivity. | Contact details and message / voice metadata and content. |
| AppsFlyer | Mobile attribution and marketing / usage analytics. | Device, technical and usage analytics data. |
| Sentry | Application error monitoring and crash reporting. | Crash logs, technical metadata and diagnostic data. |
Some of the AI models listed above, such as BioMistral and GLM OCR, may be operated within our own cloud environment or accessed through third-party infrastructure, depending on how a feature is deployed. In all cases we apply the security and confidentiality safeguards described in this Policy.
12.1 Changes to providers
Our providers and sub-processors may change over time as the Services evolve, as technology improves and as our needs change. We may add, replace or remove providers. Where a change to our providers materially affects how your personal data is processed, we will update this Policy and, where required by law, notify you and seek any consent that is needed. An up-to-date list of significant providers can be made available on request through our privacy contact.
13. International Data Processing and Storage Locations
We aim to store and process personal data within India wherever practical. However, some processing – particularly certain AI processing – may take place outside India.
- Primary hosting. The primary hosting and storage of platform data is located in Mumbai, India.
- AI processing. Certain AI requests may be processed outside India using Google Gemini infrastructure, which may include the “us-central1” region (in the United States) and “global” processing endpoints. This means that data submitted to those AI features may be transmitted to and processed on servers located outside India.
The DPDP Act permits transfers of personal data outside India except to countries or territories that the Central Government may restrict by notification (a “negative list” approach). Where we transfer personal data internationally, we do so in accordance with the DPDP Act and DPDP Rules and any conditions the Government may prescribe, and we require our providers to maintain appropriate safeguards. Certain categories of data may be required to be stored within India as the Government may notify from time to time, and we will comply with any such requirement.
14. Data Ownership
Clarity about who owns what is important in a healthcare platform. Our approach is as follows.
- Patients. Patients own their personal information. Ownership of your personal data does not transfer to ONI by virtue of using the Services.
- Healthcare providers. Healthcare providers own the clinical records generated during the course of treatment they deliver, subject to the rights of the patient and applicable law.
- ONI. ONI owns all rights, title and interest in the platform and its underlying technology, including our software, source code, algorithms, prompts, templates, AI orchestration logic, models, workflows, and all other platform intellectual property. Nothing in this Policy grants you any right in that intellectual property.
These ownership principles operate alongside, and do not limit, the rights that Data Principals have under the DPDP Act as described in Section 18, or the obligations that healthcare providers and ONI owe under applicable law.
15. Data Security
We implement reasonable technical and organisational security safeguards designed to protect personal data against unauthorised or unlawful access, use, alteration, disclosure, loss or destruction. Our security measures include, among others:
- Encryption at rest for stored data;
- Encryption in transit for data moving across networks;
- Role-based access control (RBAC) so that access matches a user’s role;
- Least-privilege principles, granting only the access needed to perform a task;
- Authentication and authorisation controls, including support for multi-factor authentication;
- Audit logging of access to and actions within the platform;
- Restricted access to production systems and personal data on a need-to-know basis;
- Temporary and controlled support access, granted only when necessary and revoked afterwards;
- Monitoring of systems for security and integrity; and
- Backups to support recovery and continuity.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You also play an important part in keeping your account safe – please protect your login credentials, use strong authentication, and notify us promptly if you suspect any unauthorised use of your account.
16. Vendor and Support Access
Access to personal data by ONI personnel and by our vendors is tightly controlled. Such access is:
- Restricted to authorised individuals;
- Approved through appropriate internal controls;
- Temporary, and limited to the duration of the task;
- Logged, so that access can be reviewed and audited; and
- Granted strictly on a need-to-know basis.
16.1 Emergency access
In limited circumstances, authorised access to systems or data may be required on an urgent basis. Such emergency access may occur for:
- Responding to and containing security incidents;
- Disaster recovery;
- System maintenance; and
- Preserving operational continuity of the Services.
Emergency access is subject to the same principles of restriction, approval where feasible, logging and need-to-know, and is reviewed after the fact.
17. Data Retention and Erasure
We retain personal data only for as long as it is necessary for the purposes for which it was collected, or for as long as we are required or permitted to retain it under applicable law.
17.1 Retention of patient records
Patient records are generally retained for the duration of the relationship between the patient and the relevant healthcare provider. Records may continue to be retained after that relationship ends for legitimate purposes, including:
- Legal and medico-legal purposes;
- Operational continuity;
- Compliance with applicable law and health-sector requirements;
- Audit and accountability; and
- Backup and disaster recovery.
We retain such records unless and until deletion is required by law or validly requested and we are not otherwise required to keep the data.
17.2 Erasure
In line with the DPDP Act, we will erase personal data when the purpose for which it was collected is no longer being served and retention is no longer necessary or required by law – for example, following withdrawal of consent where no other lawful basis or retention requirement applies. Certain records, including security and access logs, may be retained for a minimum period required by law. Where we are required to keep data (for example, for medico-legal or statutory reasons), we will retain only what is necessary and continue to protect it.
17.3 De-identified data
De-identified and anonymised data, which can no longer be linked to you, may be retained and used for the purposes described in Section 11 without the time limits that apply to identifiable personal data.
18. Your Rights as a Data Principal
Subject to the conditions and exceptions in the DPDP Act and DPDP Rules, you have the following rights in relation to your personal data. We will not charge you a fee for exercising these rights in the ordinary course, and we will respond within the timeframes required by law.
- Right to access. You may request a summary of the personal data we process about you and information about the processing and the parties with whom it has been shared.
- Right to correction. You may request that we correct inaccurate or misleading data and complete incomplete data. Note that clinical records may be subject to specific correction and amendment rules to preserve the integrity of the medical record; we will handle such requests together with the relevant healthcare provider.
- Right to erasure. You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, subject to legal retention requirements.
- Right to withdraw consent. You may withdraw consent at any time, as described in Section 8.
- Right to nominate. You may nominate another individual to exercise your rights in the event of your death or incapacity, in the manner prescribed under the DPDP Rules.
- Right to grievance redressal. You may raise a grievance with us and have it addressed through the mechanism described in Section 23.
- Right to data portability / export. Where applicable, you may request an export of certain data you have provided, in a commonly used format, subject to technical feasibility and the rights of others.
- Right to complain to the Board. If you are not satisfied with our response, you may complain to the Data Protection Board of India, and appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
18.1 How to exercise your rights
You can exercise your rights using the in-app controls where available, or by contacting us using the details in Section 23. We may need to verify your identity before acting on a request, in order to protect your data. Where you are a patient of a healthcare provider that uses ONI, and that provider is the Data Fiduciary, we may direct or forward your request to that provider and assist them in responding.
19. Cookies and Similar Technologies
Our web interfaces, including the ONI Clinician Dashboard, use cookies and similar technologies (such as local storage and software development kits within our applications) to make the Services work, to keep them secure, and to understand how they are used.
19.1 Types of cookies and technologies we use
- Strictly necessary. Required for the Services to function, including for sign-in, session management and security. These cannot be switched off in our systems.
- Functional. Remember your preferences and settings to improve your experience.
- Analytics and performance. Help us understand usage and improve reliability and performance, including through our analytics providers.
19.2 Managing cookies
You can control cookies through your browser settings and, where we provide one, through an in-product cookie or privacy setting. Blocking some cookies may affect how the Services work. Where the law requires consent for non-essential cookies, we will seek it and default to the more privacy-protective option unless you choose otherwise.
20. Children’s Data
The Services are intended for pregnant women receiving care under the supervision of a healthcare provider, and for clinicians and their authorised staff. The Services are not designed or intended for independent use by children, and we do not knowingly allow children to use the Services on their own.
Where a Data Principal is a child (a person under 18 years of age) or a person with a disability who has a lawful guardian, the DPDP Act and DPDP Rules require verifiable consent of a parent or lawful guardian before processing their personal data. Where the Services are used to deliver care to such a person – for example, care during a pregnancy involving a minor – we, together with the relevant healthcare provider, will obtain verifiable parental or guardian consent as required by law before processing, and will handle that data with additional care.
Consistent with the DPDP Rules, we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If we become aware that we have collected personal data of a child without the required verifiable consent, we will take steps to delete or lawfully address that data. If you believe a child’s data has been provided to us without proper consent, please contact us using the details in Section 23.
21. Marketing and Communications
We send different types of messages, and you have control over many of them.
- Service and care communications. Messages that are necessary to provide the Services or to support your care – such as appointment reminders, test reminders, health reminders and important service or security notices – are part of the Services. Because they are necessary, they are generally not optional while you use the relevant Service.
- Marketing communications. Where we send promotional or marketing messages, we will do so in accordance with applicable law and, where required, only with your consent.
21.1 Your choices
You can manage your communication and notification preferences through the in-app settings where available, or by contacting us. You may opt out of marketing communications at any time, including by using the unsubscribe or opt-out mechanism provided in the message. Opting out of marketing does not stop essential service and care communications.
22. Personal Data Breach Handling
We maintain measures to detect, assess, contain and respond to personal data breaches. In the event of a personal data breach, we will act in accordance with the DPDP Act and DPDP Rules.
- Notification to affected individuals. We will notify each affected Data Principal about the breach without undue delay after becoming aware of it, in plain language, describing the nature and extent of the breach, the likely consequences, the measures we are taking, the steps the individual can take to protect themselves, and how to contact us.
- Notification to the Board. We will notify the Data Protection Board of India of the breach on becoming aware of it, and will provide the Board with the further detailed information required, including updated findings and remediation measures, within the timeframe prescribed under the DPDP Rules (currently 72 hours from awareness, or such longer period as the Board may allow).
- Remediation. We will take reasonable steps to mitigate harm, address the cause of the breach and reduce the likelihood of recurrence.
23. Grievance Redressal and Contacting Us
We take your questions, requests and concerns seriously. Please contact us using the details below, and we will respond within the timeframes required by law.
| Channel | Contact |
|---|---|
| Privacy queries and rights requests | support@onicares.com |
| Product and technical support | support@onicares.com |
| Grievance Officer | The Grievance Officer, ONICARES AI PRIVATE LIMITED – support@onicares.com |
| Postal address | 6-2A, Krishna Residency, 4th Cross, Amarjyothi Nagar, Vijayanagar (Bangalore), Bangalore North, Bangalore – 560040, Karnataka, India |
In accordance with the DPDP Act, we have designated a Grievance Officer who is the point of contact for grievances relating to the processing of your personal data. If you are not satisfied with the resolution provided, you have the right to make a complaint to the Data Protection Board of India. (The name of the currently designated Grievance Officer will be published here and updated from time to time; until then, grievances may be addressed to the Office of the Grievance Officer at the address and email above.)
24. Changes to this Policy
We may update this Policy from time to time to reflect changes in our Services, our providers, technology, or legal and regulatory requirements. When we make changes, we will revise the “Last Updated” date at the top of this Policy and, where the changes are material, we will provide a more prominent notice and, where required by law, seek your consent. We encourage you to review this Policy periodically. Your continued use of the Services after an update takes effect indicates that you have reviewed the updated Policy, to the extent permitted by law.
25. Governing Law and Jurisdiction
This Policy and any matter relating to it are governed by the laws of India. Subject to the jurisdiction of the Data Protection Board of India and the Telecom Disputes Settlement and Appellate Tribunal under the DPDP Act, the courts at Bangalore, Karnataka, India shall have jurisdiction over disputes arising in connection with this Policy, to the extent permitted by law.
26. Interpretation and Precedence
Headings are for convenience only and do not affect interpretation. If any provision of this Policy is found to be unenforceable, the remaining provisions will continue in effect. Where this Policy is made available in more than one language, and there is any conflict, the English version prevails unless the law requires otherwise. This Policy should be read together with any product-specific notice, our terms of service, and any separate consent you provide.
Acknowledgement
By using the Services, you acknowledge that you have read and understood this Privacy Policy of ONICARES AI PRIVATE LIMITED and the way in which your personal data is processed as described here.