← Back to Rounds

Privacy Policy

Rounds Healthcare Technologies · Digital Personal Data Protection (DPDP) Act, 2023

Last updated: 2026-08-25

This policy explains what personal data Rounds collects, why we collect it, who we share it with, and the rights you have over it. Rounds Healthcare Technologies is the Data Fiduciary for that data under the DPDP Act, 2023.

1. Data we collect

Account and identity data. Your name, email address, phone number and postal address. When you sign in with Google we receive your Google account identifier and email address — never your Google password.

Professional data (doctors). Medical registration number and issuing State Medical Council, specialty and category, and years of experience. We record the registration number only — never a copy of the certificate.

Facility data (hospitals). Facility name, business registration number, GST number, registered address, contact person and facility photographs.

Verification data. Your medical registration number and issuing council, which we check against the official register. We do not collect or store your degree certificate, identity document, selfie, police clearance or any other document. Identity is confirmed by a specialist verification partner: you present your ID to them directly, they return only a pass or fail to us, and the document itself never reaches Rounds.

Location data. Precise GPS coordinates, captured only at the moment you check in or out of a shift, to confirm attendance at the facility. We do not track your location in the background or when the app is closed.

Usage and device data. Log data, device type, app version, and crash/diagnostic reports used to keep the service working.

Payment data. Subscription amount, date, plan and the payment reference issued by our payment gateway. We never see or store your card number, UPI PIN or bank credentials — those go directly to the gateway.

2. Why we use it, and our lawful basis

We process your data on the basis of the consent you give at sign-up, and for the legitimate uses permitted by the DPDP Act. Specifically:

  • To create and operate your account.
  • To verify medical credentials and identity — the core safety purpose of the platform.
  • To match doctors with hospitals and show relevant shifts and roles.
  • To confirm shift attendance via check-in location.
  • To take subscription payments and issue GST receipts.
  • To send service notifications about bookings, verification and support.
  • To investigate grievances, prevent fraud and misuse, and keep the platform safe.
  • To meet legal, tax and regulatory obligations.

We do not sell your personal data, and we do not use your documents or biometric data for advertising.

3. Who we share it with

We share only what is necessary, with processors bound to protect it:

  • Other users.Hospitals see a doctor’s professional profile, verification badge, rating, completed-shift count and cancellation count. Doctors see a hospital’s facility profile and rating. Your identity documents are never shown to another user.
  • Identity verification provider. Your name and contact details, so they can run the identity check. You present your ID document to them directly on their own hosted page; it is never routed through or stored by Rounds, and they return only a pass or fail.
  • Medical Council registers. Registration number and name, to confirm you are validly registered.
  • Payment gateway. Name, contact details and order amount, to take subscription payments.
  • Cloud hosting, database and storage providers. To run the service and store uploaded documents.
  • Email and push notification providers. To deliver service messages.
  • Authorities. Where required by law, court order, or to report a credential fraud to a statutory council.

4. Storage, security and retention

The only files we store are the images you choose to display: a doctor’s profile photo, and a hospital’s logo and facility photos. These are held in encrypted S3-compatible object storage. We hold no identity or credential documents at all, which is a deliberate choice — the safest way to protect a document is not to have it.

Access is restricted to authorised staff and is audited: every administrative action is recorded against the individual who performed it. Data is transmitted over encrypted connections, and passwords (staff accounts only) are stored as salted hashes, never in plain text.

We keep your data for as long as your account is active. After deletion we retain verification records — the registration number and the outcome of its check, not any document — for up to 3 years to meet medical-credential audit and statutory obligations, and transaction records for the period required by tax law. Everything else is erased.

5. Your rights

Under the DPDP Act, 2023 you have the right to:

  • Access a summary of the personal data we hold about you.
  • Correct data that is inaccurate, and complete data that is incomplete.
  • Erase your data, subject to the retention periods in clause 4.
  • Withdraw consent at any time — note this will end your ability to use the platform, since verification is mandatory.
  • Nominate another person to exercise your rights in the event of death or incapacity.
  • Complain to our Grievance Officer, and then to the Data Protection Board of India.

Exercise any of these by writing to grievance@myrounds.in. We respond within 30 days.

6. Deleting your account

You can delete your account yourself, at any time, from Profile → Delete Account in the app. Deletion is permanent and removes your profile, uploaded documents, bookings and notifications, subject only to the retention periods in clause 4. There is no waiting period and you do not need to contact support first.

If you cannot access the app, email support@myrounds.in from your registered address and we will complete the deletion for you.

7. Children

The platform is not intended for anyone under 18, and we do not knowingly collect data from children. If we learn that we have, we will delete it promptly. Contact us if you believe a child has provided us with personal data.

8. Cookies and sessions

We use a small number of strictly necessary cookies to keep you signed in and to protect sign-in against cross-site request forgery. We do not use advertising or cross-site tracking cookies.

9. Data breach notification

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected user without undue delay, as required by the DPDP Act, describing what happened, what data was involved and what steps to take.

10. Changes to this policy

We may update this policy as the service or the law changes. The “last updated” date above reflects the current version, and we will give in-app notice of any material change before it takes effect.

11. Grievance Redressal Officer

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the designated officer for privacy complaints is:

Grievance Redressal Officer

Rounds Healthcare Technologies

Email: grievance@myrounds.in

Location: India

Complaints are acknowledged within 48 hours and resolved within 30 days. If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India.