Rounds Healthcare Technologies · Digital Personal Data Protection (DPDP) Act, 2023
Last updated: 2026-08-25
This policy explains what personal data Rounds collects, why we collect it, who we share it with, and the rights you have over it. Rounds Healthcare Technologies is the Data Fiduciary for that data under the DPDP Act, 2023.
Account and identity data. Your name, email address, phone number and postal address. When you sign in with Google we receive your Google account identifier and email address — never your Google password.
Professional data (doctors). Medical registration number and issuing State Medical Council, specialty and category, and years of experience. We record the registration number only — never a copy of the certificate.
Facility data (hospitals). Facility name, business registration number, GST number, registered address, contact person and facility photographs.
Verification data. Your medical registration number and issuing council, which we check against the official register. We do not collect or store your degree certificate, identity document, selfie, police clearance or any other document. Identity is confirmed by a specialist verification partner: you present your ID to them directly, they return only a pass or fail to us, and the document itself never reaches Rounds.
Location data. Precise GPS coordinates, captured only at the moment you check in or out of a shift, to confirm attendance at the facility. We do not track your location in the background or when the app is closed.
Usage and device data. Log data, device type, app version, and crash/diagnostic reports used to keep the service working.
Payment data. Subscription amount, date, plan and the payment reference issued by our payment gateway. We never see or store your card number, UPI PIN or bank credentials — those go directly to the gateway.
We process your data on the basis of the consent you give at sign-up, and for the legitimate uses permitted by the DPDP Act. Specifically:
We do not sell your personal data, and we do not use your documents or biometric data for advertising.
We share only what is necessary, with processors bound to protect it:
The only files we store are the images you choose to display: a doctor’s profile photo, and a hospital’s logo and facility photos. These are held in encrypted S3-compatible object storage. We hold no identity or credential documents at all, which is a deliberate choice — the safest way to protect a document is not to have it.
Access is restricted to authorised staff and is audited: every administrative action is recorded against the individual who performed it. Data is transmitted over encrypted connections, and passwords (staff accounts only) are stored as salted hashes, never in plain text.
We keep your data for as long as your account is active. After deletion we retain verification records — the registration number and the outcome of its check, not any document — for up to 3 years to meet medical-credential audit and statutory obligations, and transaction records for the period required by tax law. Everything else is erased.
Under the DPDP Act, 2023 you have the right to:
Exercise any of these by writing to grievance@myrounds.in. We respond within 30 days.
You can delete your account yourself, at any time, from Profile → Delete Account in the app. Deletion is permanent and removes your profile, uploaded documents, bookings and notifications, subject only to the retention periods in clause 4. There is no waiting period and you do not need to contact support first.
If you cannot access the app, email support@myrounds.in from your registered address and we will complete the deletion for you.
The platform is not intended for anyone under 18, and we do not knowingly collect data from children. If we learn that we have, we will delete it promptly. Contact us if you believe a child has provided us with personal data.
We use a small number of strictly necessary cookies to keep you signed in and to protect sign-in against cross-site request forgery. We do not use advertising or cross-site tracking cookies.
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected user without undue delay, as required by the DPDP Act, describing what happened, what data was involved and what steps to take.
We may update this policy as the service or the law changes. The “last updated” date above reflects the current version, and we will give in-app notice of any material change before it takes effect.
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the designated officer for privacy complaints is:
Grievance Redressal Officer
Rounds Healthcare Technologies
Email: grievance@myrounds.in
Location: India
Complaints are acknowledged within 48 hours and resolved within 30 days. If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India.