Signaasat Healthcare Private Limited ("Signaasat," "we," "our," or "us") is committed to protecting the privacy of every individual who interacts with our website, services, and communications. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, how long we keep it, and the rights you have over it.
This policy is published in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 ("IT Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and other applicable laws of India.
1. Who we are
Signaasat Healthcare Private Limited is a healthcare-focused digital marketing agency registered in India.
| Field | Detail |
|---|---|
| Registered office | 4, Luv Kush Apartments, Seasons Mall Road, Sanewadi, Aundh, Pune 411007, Maharashtra, India |
| Corporate Identification Number (CIN) | U62099PN2024PTC233782 |
| GSTIN | 27ABOCS1745A1ZE |
| General enquiries | hello@signaasat.com |
| Data Protection Officer | dpo@signaasat.com |
| Grievance Officer | grievance@signaasat.com |
Our role under the DPDP Act. For personal data we collect directly through our website, marketing channels, and business communications, Signaasat is the Data Fiduciary. For patient lead data collected on behalf of our hospital and clinic clients, Signaasat acts as a Data Processor, and the respective healthcare provider is the Data Fiduciary. The terms of that processing are governed by our written service agreement with the relevant client.
2. What personal data we collect
We collect only the personal data we need to provide our services, respond to your enquiries, meet our legal obligations, and — with your consent — send you communications.
A. When you visit our website. Technical data (IP address, browser type, device type, operating system, referrer URL), usage data (pages visited, time spent, click and navigation behaviour), and cookie data as described in Section 10 and in our Cookie Policy.
B. When you contact us, book a call, or submit an enquiry. Name, designation, organisation, email address, phone or WhatsApp number, hospital or clinic name and location, and the content of your message.
C. When you subscribe to our communications. Email address, name and organisation (if provided), and communication preferences.
D. When you engage us as a client. Authorised signatory details, billing information (GST, PAN), bank details for invoicing, KYC documentation where required, and engagement communication records.
E. When we process patient lead data on behalf of our hospital and clinic clients. This data is collected on behalf of, and under the documented instructions of, the relevant healthcare provider (the Data Fiduciary). Signaasat acts as a Data Processor for such data, does not use it outside the scope of that engagement, and does not retain it beyond the retention period defined in the applicable client agreement. The healthcare provider's own privacy policy governs the use of such data.
Sensitive Personal Data or Information (SPDI). Under the SPDI Rules, categories such as financial information, health condition, medical records, biometric information, and sexual orientation are treated as sensitive. In our own operations we do not knowingly collect SPDI directly from website visitors. To the extent SPDI may reach us as part of the patient lead data we process on behalf of a healthcare client, it is handled under the client's written consent framework, with enhanced access controls, and is never used for our own marketing.
Children's data. We do not knowingly collect personal data from children (persons under 18) without verifiable parental consent, in accordance with Section 9 of the DPDP Act.
3. Why we collect personal data
| Category | Purpose |
|---|---|
| Website analytics | Understand how visitors use our website; improve experience and content |
| Enquiry response | Respond to business enquiries, schedule discovery calls, share proposals |
| Client engagement | Deliver contracted services, raise invoices, project communications |
| Marketing communications | Send service updates, insights, and case studies — only with your consent |
| Legal compliance | Comply with law, respond to lawful requests, defend legal claims |
| Service improvement | Improve our offerings using aggregated, non-identifiable usage patterns |
| Security & fraud prevention | Detect and prevent unauthorised access, abuse, and fraud |
We do not use personal data for purposes outside this list. We do not sell personal data to any party. We do not share your personal data with third parties for their independent marketing.
4. Legal basis for processing
Under the DPDP Act, we process personal data on one or more of the following bases: your consent (Section 6), certain legitimate uses as defined in Section 7 (including where you have voluntarily provided the data for a specified purpose and not indicated that you do not consent to its use), compliance with a legal obligation, and performance of a contract to which you are party.
For marketing communications, we rely on your explicit and specific consent. You can withdraw this consent at any time by writing to dpo@signaasat.com or by using the unsubscribe link in any email we send. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
5. Who we share your data with
We share personal data only with the categories of recipients listed below, and only to the extent necessary.
Service providers who help us operate our business. These include:
- Website hosting and infrastructure — Hostinger and successor providers
- Website analytics — Google Analytics (or equivalent)
- Email and productivity — Google Workspace and equivalent providers
- Customer relationship management (CRM) — [CRM PROVIDER NAME, if used]
- Advertising platforms — Meta, Google Ads, LinkedIn, and programmatic partners including Limelight PPL and Bidscube (for campaigns on behalf of clients; not for our own marketing on this website)
- Payment and invoicing — [PROVIDER, if applicable]
All service providers are bound by written contracts requiring confidentiality and data protection standards consistent with the DPDP Act and the IT Act.
Hospital and clinic clients for whom we process patient lead data on their behalf, in accordance with our service agreement.
Professional advisors — auditors, lawyers, accountants, and consultants — under confidentiality obligations.
Regulatory authorities and law enforcement when required by law, court order, or legally binding request.
Successors in the event of a business reorganisation, merger, or acquisition, in which case the acquirer will be bound by this Privacy Policy or an equivalent standard.
We do not share, rent, sell, or disclose your personal data to third parties for their independent commercial or marketing purposes.
6. How long we retain your data
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law.
| Data category | Retention period |
|---|---|
| Website analytics | Up to 26 months |
| Business enquiries (not converted to engagement) | 24 months from last interaction |
| Client engagement records | Duration of contract + 7 years |
| Marketing subscription data | Until consent withdrawn + 30 days |
| Tax, accounting, and statutory records | 8 years from end of relevant financial year |
| Patient lead data (as Processor) | As defined in the applicable client agreement; typically deleted or returned within 90 days of engagement end |
Once the retention period expires, we securely delete or anonymise the data.
7. How we protect your data
We implement reasonable security practices and procedures aligned with Section 43A of the IT Act, the SPDI Rules, and DPDP Act requirements. These include:
- Encryption in transit (TLS 1.2 or higher) for all data exchanged over the internet
- Encryption at rest in our primary data stores
- Role-based access controls and the principle of least privilege
- Regular security reviews and vulnerability assessments
- Written confidentiality and data protection obligations on all employees, contractors, and sub-processors
- Documented incident-response procedures
No method of transmission over the internet or method of electronic storage is 100% secure. While we use commercially reasonable means to protect personal data, absolute security cannot be guaranteed.
8. Personal data breach notification
In the event of a personal data breach, we will notify the affected Data Principals and the Data Protection Board of India in accordance with the DPDP Act and its rules. Where the DPDP Rules prescribe a specific timeline for breach notification (currently 72 hours under the draft rules), we will comply with that timeline. Notifications will include the nature of the breach, the categories and approximate number of Data Principals affected, the likely consequences, and the measures we have taken or will take to address the breach.
9. Your rights under the DPDP Act
As a Data Principal, you have the following rights in respect of the personal data we hold about you as Data Fiduciary:
- Right to information — a summary of the personal data we hold about you and the processing activities undertaken
- Right to correction and erasure — to request correction of inaccurate or misleading data, completion of incomplete data, updating of data, and erasure of data no longer necessary for the purpose for which it was collected (subject to legal retention obligations)
- Right of grievance redressal — to raise concerns about our handling of your data through the mechanism described in Section 12
- Right to nominate — to nominate any other individual to exercise your rights in the event of your death or incapacity
- Right to withdraw consent — to withdraw consent that you have previously given, at any time
Where the data has been processed on your behalf by us as Data Processor for one of our healthcare clients, you should exercise these rights with the client (the Data Fiduciary). We will assist the client in responding to any such request as required by our agreement with them.
10. Cookies and tracking technologies
Our website uses cookies and similar technologies for essential site functionality, analytics, and (where you have consented) marketing purposes. Non-essential cookies are set only after you have provided consent through our cookie banner. For a full list of cookies used, their purposes, retention periods, and how to manage them, please see our Cookie Policy.
Advertising and remarketing pixels. Where applicable, we use the Meta Pixel, Google Ads tag, and LinkedIn Insight Tag on this website to measure the effectiveness of our own marketing and, with your consent, to show you relevant content. You can withdraw this consent at any time through the cookie preference centre.
11. Third-party links
Our website may link to third-party sites, including our clients' hospital websites, social media platforms, and industry resources. We are not responsible for the privacy practices of those third parties and encourage you to review their policies before providing personal data to them.
12. Data Protection Officer and Grievance Officer
We have designated a Data Protection Officer ("DPO") who is responsible for our data-protection practices and acts as the point of contact for Data Principals and regulatory authorities under the DPDP Act.
We have also designated a Grievance Officer under the IT Act to handle complaints about our handling of personal data.
| Role | Contact |
|---|---|
| Data Protection Officer | [DPO NAME] · dpo@signaasat.com |
| Grievance Officer | [GRIEVANCE OFFICER NAME] · grievance@signaasat.com |
| Postal address (for both) | Data Protection Officer / Grievance Officer, Signaasat Healthcare Private Limited, 4 Luv Kush Apartments, Seasons Mall Road, Sanewadi, Aundh, Pune 411007, Maharashtra, India |
How to reach us and what to expect. You may contact the DPO or the Grievance Officer at the addresses above. We will acknowledge receipt of your request within 3 business days and respond substantively within the timelines prescribed under the DPDP Act and its rules, and in any case no later than 30 days from receipt. If you are not satisfied with our response, you may approach the Data Protection Board of India.
13. Cross-border data transfers
We primarily store personal data on servers located in India. In limited cases, our service providers may store, back up, or process data outside India — for example, where analytics or hosting infrastructure is operated by a global provider. Under Section 16 of the DPDP Act, we may transfer personal data outside India except to countries specifically restricted by notification of the Central Government. Where required, we put in place appropriate contractual and technical safeguards to protect data transferred internationally.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our services, applicable law, or regulatory guidance. The updated policy will be published on this page with a revised "Last updated" date. Material changes will be communicated to active clients and consenting subscribers by email at least 15 days before they take effect.
15. Contact us
For any questions about this Privacy Policy or how we handle personal data:
- Data Protection Officer: dpo@signaasat.com
- Grievance Officer: grievance@signaasat.com
- General enquiries: hello@signaasat.com
- Postal address: Signaasat Healthcare Private Limited, 4 Luv Kush Apartments, Seasons Mall Road, Sanewadi, Aundh, Pune 411007, Maharashtra, India
If you are not satisfied with our response to a grievance, you may approach the Data Protection Board of India through the mechanisms notified under the DPDP Act.
This Privacy Policy governs how Signaasat Healthcare Private Limited collects and processes personal data. Please read it together with our Terms of Use, Cookie Policy, and Disclaimer.