Privacy Policy
Last updated: June 2026
HealthByte (“we”, “us”) operates the HealthByte pharmacy, consultation and diagnostics platform. This policy explains what personal data we collect and how we handle it, in line with India’s Digital Personal Data Protection Act, 2023 (DPDP).
1. Data we collect
- Account & identity: name, phone number, email, delivery addresses.
- Health data (sensitive): prescriptions you upload, doctor-issued e-prescriptions, consultation notes and chat, and lab test bookings and reports.
- Transaction data: orders, payments (processed by our payment partner — we do not store card details), and order history.
- Device & usage: app/version, and basic diagnostics to keep the service reliable.
2. Why we use it (purpose limitation)
We process your data only to: fulfil medicine orders and verify prescriptions with a registered pharmacist; enable doctor consultations and lab bookings; arrange delivery and sample collection; process payments; and provide customer support. Health data is used only for delivering the care you request.
3. Consent
We process your personal and health data based on your explicit consent, which you give when you create an account and place an order, book a consultation, or book a test. You can withdraw consent at any time (this may stop us from providing the service).
4. Who we share with
We share the minimum necessary data with: the pharmacist who verifies your prescription; the doctor you consult; the partner lab and phlebotomist for tests; the delivery rider (name + address only); and our payment processor. We do not sell your data.
5. Retention & security
Health and order records are retained as required for medical and regulatory record-keeping, then deleted or anonymised. Data is encrypted in transit, access is role-restricted, and prescription and report files are served only to authorised users.
6. Your rights (DPDP)
- Access and correct your personal data.
- Request erasure of your data.
- Withdraw consent and nominate a representative.
- Raise a grievance with our Data Protection Officer.
To exercise these, contact privacy@healthbyte.in.
This template must be reviewed by qualified legal counsel before a public launch, alongside the pharmacy/telemedicine compliance requirements that apply to your business.