Legal

Privacy Policy

Signaasat Healthcare Private Limited ("Signaasat," "we," "our," or "us") is committed to protecting the privacy of every individual who interacts with our website, services, and communications. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, how long we keep it, and the rights you have over it.

This policy is published in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 ("IT Act") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and other applicable laws of India.


1. Who we are

Signaasat Healthcare Private Limited is a healthcare-focused digital marketing agency registered in India.

FieldDetail
Registered office4, Luv Kush Apartments, Seasons Mall Road, Sanewadi, Aundh, Pune 411007, Maharashtra, India
Corporate Identification Number (CIN)U62099PN2024PTC233782
GSTIN27ABOCS1745A1ZE
General enquirieshello@signaasat.com
Data Protection Officerdpo@signaasat.com
Grievance Officergrievance@signaasat.com

Our role under the DPDP Act. For personal data we collect directly through our website, marketing channels, and business communications, Signaasat is the Data Fiduciary. For patient lead data collected on behalf of our hospital and clinic clients, Signaasat acts as a Data Processor, and the respective healthcare provider is the Data Fiduciary. The terms of that processing are governed by our written service agreement with the relevant client.


2. What personal data we collect

We collect only the personal data we need to provide our services, respond to your enquiries, meet our legal obligations, and — with your consent — send you communications.

A. When you visit our website. Technical data (IP address, browser type, device type, operating system, referrer URL), usage data (pages visited, time spent, click and navigation behaviour), and cookie data as described in Section 10 and in our Cookie Policy.

B. When you contact us, book a call, or submit an enquiry. Name, designation, organisation, email address, phone or WhatsApp number, hospital or clinic name and location, and the content of your message.

C. When you subscribe to our communications. Email address, name and organisation (if provided), and communication preferences.

D. When you engage us as a client. Authorised signatory details, billing information (GST, PAN), bank details for invoicing, KYC documentation where required, and engagement communication records.

E. When we process patient lead data on behalf of our hospital and clinic clients. This data is collected on behalf of, and under the documented instructions of, the relevant healthcare provider (the Data Fiduciary). Signaasat acts as a Data Processor for such data, does not use it outside the scope of that engagement, and does not retain it beyond the retention period defined in the applicable client agreement. The healthcare provider's own privacy policy governs the use of such data.

Sensitive Personal Data or Information (SPDI). Under the SPDI Rules, categories such as financial information, health condition, medical records, biometric information, and sexual orientation are treated as sensitive. In our own operations we do not knowingly collect SPDI directly from website visitors. To the extent SPDI may reach us as part of the patient lead data we process on behalf of a healthcare client, it is handled under the client's written consent framework, with enhanced access controls, and is never used for our own marketing.

Children's data. We do not knowingly collect personal data from children (persons under 18) without verifiable parental consent, in accordance with Section 9 of the DPDP Act.


3. Why we collect personal data

CategoryPurpose
Website analyticsUnderstand how visitors use our website; improve experience and content
Enquiry responseRespond to business enquiries, schedule discovery calls, share proposals
Client engagementDeliver contracted services, raise invoices, project communications
Marketing communicationsSend service updates, insights, and case studies — only with your consent
Legal complianceComply with law, respond to lawful requests, defend legal claims
Service improvementImprove our offerings using aggregated, non-identifiable usage patterns
Security & fraud preventionDetect and prevent unauthorised access, abuse, and fraud

We do not use personal data for purposes outside this list. We do not sell personal data to any party. We do not share your personal data with third parties for their independent marketing.


4. Legal basis for processing

Under the DPDP Act, we process personal data on one or more of the following bases: your consent (Section 6), certain legitimate uses as defined in Section 7 (including where you have voluntarily provided the data for a specified purpose and not indicated that you do not consent to its use), compliance with a legal obligation, and performance of a contract to which you are party.

For marketing communications, we rely on your explicit and specific consent. You can withdraw this consent at any time by writing to dpo@signaasat.com or by using the unsubscribe link in any email we send. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.


5. Who we share your data with

We share personal data only with the categories of recipients listed below, and only to the extent necessary.

Service providers who help us operate our business. These include:

  • Website hosting and infrastructure — Hostinger and successor providers
  • Website analytics — Google Analytics (or equivalent)
  • Email and productivity — Google Workspace and equivalent providers
  • Customer relationship management (CRM) — [CRM PROVIDER NAME, if used]
  • Advertising platforms — Meta, Google Ads, LinkedIn, and programmatic partners including Limelight PPL and Bidscube (for campaigns on behalf of clients; not for our own marketing on this website)
  • Payment and invoicing — [PROVIDER, if applicable]

All service providers are bound by written contracts requiring confidentiality and data protection standards consistent with the DPDP Act and the IT Act.

Hospital and clinic clients for whom we process patient lead data on their behalf, in accordance with our service agreement.

Professional advisors — auditors, lawyers, accountants, and consultants — under confidentiality obligations.

Regulatory authorities and law enforcement when required by law, court order, or legally binding request.

Successors in the event of a business reorganisation, merger, or acquisition, in which case the acquirer will be bound by this Privacy Policy or an equivalent standard.

We do not share, rent, sell, or disclose your personal data to third parties for their independent commercial or marketing purposes.


6. How long we retain your data

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law.

Data categoryRetention period
Website analyticsUp to 26 months
Business enquiries (not converted to engagement)24 months from last interaction
Client engagement recordsDuration of contract + 7 years
Marketing subscription dataUntil consent withdrawn + 30 days
Tax, accounting, and statutory records8 years from end of relevant financial year
Patient lead data (as Processor)As defined in the applicable client agreement; typically deleted or returned within 90 days of engagement end

Once the retention period expires, we securely delete or anonymise the data.


7. How we protect your data

We implement reasonable security practices and procedures aligned with Section 43A of the IT Act, the SPDI Rules, and DPDP Act requirements. These include:

  • Encryption in transit (TLS 1.2 or higher) for all data exchanged over the internet
  • Encryption at rest in our primary data stores
  • Role-based access controls and the principle of least privilege
  • Regular security reviews and vulnerability assessments
  • Written confidentiality and data protection obligations on all employees, contractors, and sub-processors
  • Documented incident-response procedures

No method of transmission over the internet or method of electronic storage is 100% secure. While we use commercially reasonable means to protect personal data, absolute security cannot be guaranteed.


8. Personal data breach notification

In the event of a personal data breach, we will notify the affected Data Principals and the Data Protection Board of India in accordance with the DPDP Act and its rules. Where the DPDP Rules prescribe a specific timeline for breach notification (currently 72 hours under the draft rules), we will comply with that timeline. Notifications will include the nature of the breach, the categories and approximate number of Data Principals affected, the likely consequences, and the measures we have taken or will take to address the breach.


9. Your rights under the DPDP Act

As a Data Principal, you have the following rights in respect of the personal data we hold about you as Data Fiduciary:

  • Right to information — a summary of the personal data we hold about you and the processing activities undertaken
  • Right to correction and erasure — to request correction of inaccurate or misleading data, completion of incomplete data, updating of data, and erasure of data no longer necessary for the purpose for which it was collected (subject to legal retention obligations)
  • Right of grievance redressal — to raise concerns about our handling of your data through the mechanism described in Section 12
  • Right to nominate — to nominate any other individual to exercise your rights in the event of your death or incapacity
  • Right to withdraw consent — to withdraw consent that you have previously given, at any time

Where the data has been processed on your behalf by us as Data Processor for one of our healthcare clients, you should exercise these rights with the client (the Data Fiduciary). We will assist the client in responding to any such request as required by our agreement with them.


10. Cookies and tracking technologies

Our website uses cookies and similar technologies for essential site functionality, analytics, and (where you have consented) marketing purposes. Non-essential cookies are set only after you have provided consent through our cookie banner. For a full list of cookies used, their purposes, retention periods, and how to manage them, please see our Cookie Policy.

Advertising and remarketing pixels. Where applicable, we use the Meta Pixel, Google Ads tag, and LinkedIn Insight Tag on this website to measure the effectiveness of our own marketing and, with your consent, to show you relevant content. You can withdraw this consent at any time through the cookie preference centre.


11. Third-party links

Our website may link to third-party sites, including our clients' hospital websites, social media platforms, and industry resources. We are not responsible for the privacy practices of those third parties and encourage you to review their policies before providing personal data to them.


12. Data Protection Officer and Grievance Officer

We have designated a Data Protection Officer ("DPO") who is responsible for our data-protection practices and acts as the point of contact for Data Principals and regulatory authorities under the DPDP Act.

We have also designated a Grievance Officer under the IT Act to handle complaints about our handling of personal data.

RoleContact
Data Protection Officer[DPO NAME] · dpo@signaasat.com
Grievance Officer[GRIEVANCE OFFICER NAME] · grievance@signaasat.com
Postal address (for both)Data Protection Officer / Grievance Officer, Signaasat Healthcare Private Limited, 4 Luv Kush Apartments, Seasons Mall Road, Sanewadi, Aundh, Pune 411007, Maharashtra, India

How to reach us and what to expect. You may contact the DPO or the Grievance Officer at the addresses above. We will acknowledge receipt of your request within 3 business days and respond substantively within the timelines prescribed under the DPDP Act and its rules, and in any case no later than 30 days from receipt. If you are not satisfied with our response, you may approach the Data Protection Board of India.


13. Cross-border data transfers

We primarily store personal data on servers located in India. In limited cases, our service providers may store, back up, or process data outside India — for example, where analytics or hosting infrastructure is operated by a global provider. Under Section 16 of the DPDP Act, we may transfer personal data outside India except to countries specifically restricted by notification of the Central Government. Where required, we put in place appropriate contractual and technical safeguards to protect data transferred internationally.


14. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our services, applicable law, or regulatory guidance. The updated policy will be published on this page with a revised "Last updated" date. Material changes will be communicated to active clients and consenting subscribers by email at least 15 days before they take effect.


15. Contact us

For any questions about this Privacy Policy or how we handle personal data:

  • Data Protection Officer: dpo@signaasat.com
  • Grievance Officer: grievance@signaasat.com
  • General enquiries: hello@signaasat.com
  • Postal address: Signaasat Healthcare Private Limited, 4 Luv Kush Apartments, Seasons Mall Road, Sanewadi, Aundh, Pune 411007, Maharashtra, India

If you are not satisfied with our response to a grievance, you may approach the Data Protection Board of India through the mechanisms notified under the DPDP Act.


This Privacy Policy governs how Signaasat Healthcare Private Limited collects and processes personal data. Please read it together with our Terms of Use, Cookie Policy, and Disclaimer.