Rounds Healthcare Technologies · Digital Personal Data Protection (DPDP) Act, 2023
Last updated: 2026-10-08
This policy explains what personal data Rounds collects, why we collect it, who we share it with, and the rights you have over it. Rounds Healthcare Technologies is the Data Fiduciary for that data under the DPDP Act, 2023.
Account and identity data. Your name, email address, phone number and postal address. When you sign in with Google we receive your Google account identifier and email address, never your Google password.
Professional data (doctors). Medical registration number and issuing State Medical Council, specialty and category, and years of experience. We record the registration number only, never a copy of the certificate.
Facility data (hospitals). Facility name, business registration number, GST number, registered address, contact person and facility photographs.
Verification data. Your medical registration number and issuing council, which we check against the official register. The only document we keep is your medical registration certificate or ID, when you upload it to be verified. It is stored securely in India, used only to verify you, shown to hospitals only if you choose, and you can remove it at any time. Nothing else.
Location data. Precise GPS coordinates, captured only at the moment you clock in or out of a shift, to confirm attendance at the facility. We do not track your location in the background or when the app is closed.
Usage and device data. Log data, device type, app version, and crash/diagnostic reports used to keep the service working.
We process your data on the basis of the consent you give at sign-up, and for the legitimate uses permitted by the DPDP Act. Specifically:
We do not sell your personal data, and we do not use your documents or biometric data for advertising.
We share only what is necessary, with processors bound to protect it:
The files we store are: a doctor’s profile photo; a doctor’s registration certificate, licence or ID when they upload it to be verified; and a hospital’s logo, facility photos and clinical establishment certificate. These are held in encrypted S3-compatible object storage in India. Nothing else.
Access is restricted to authorised staff and is audited: every administrative action is recorded against the individual who performed it. Data is transmitted over encrypted connections, and passwords (staff accounts only) are stored as salted hashes, never in plain text.
We keep your data for as long as your account is active. After deletion we retain verification records, the registration number and the outcome of its check, not any document, for up to 3 years to meet medical-credential audit and statutory obligations, and transaction records for the period required by tax law. Everything else is erased.
Under the DPDP Act, 2023 you have the right to:
Exercise any of these by writing to grievance@myrounds.in. We acknowledge within 24 hours and respond within 15 days.
You can delete your account yourself at any time, from Settings → Sign in and security → Delete My Account in the app. It happens immediately. If you have shifts booked that someone is counting on, you will be asked to cancel them first, so the other side is told. Deletion is permanent and removes your profile, photos, uploaded documents, bookings, messages and notifications, subject only to the retention periods in clause 4.
If you cannot access the app, email support@myrounds.in from your registered address and we will complete the deletion for you.
The platform is not intended for anyone under 18, and we do not knowingly collect data from children. If we learn that we have, we will delete it promptly. Contact us if you believe a child has provided us with personal data.
We use a small number of strictly necessary cookies to keep you signed in and to protect sign-in against cross-site request forgery. These are always on.
If you choose “Accept all” on the cookie notice, we also load Google Ads conversion tracking. It tells Google that a visit which started from one of our ads ended in a sign-up, so we can see which ads work. It sends no name, email, phone number or medical details, ad personalisation is switched off, and it never runs on our admin pages. If you choose “Essential only”, it never loads.
If a personal data breach occurs, we will tell every affected user without delay, describing what happened, what data was involved, what we are doing about it and what steps you should take. We will inform the Data Protection Board of India immediately, and give the Board full particulars of the breach within 72 hours, as the Digital Personal Data Protection Rules require.
“Ask Rounds” answers questions about using the platform. Your question is sent to a third-party AI provider, which generates the answer and returns it to us. Only the words you type in that screen are sent. Your name, profile, registration number, bookings, location and contact details are not.
The provider processes the question only to produce that answer. Questions about money, refunds or your own account are never sent to the model at all, they go straight to our support team. Answers are generated by software, can be wrong, and are never medical advice. If you would rather not use it, simply do not open that screen, everything else in Rounds works without it.
Rounds's own team uses YouTube API Services to publish Rounds's marketing videos to the Rounds YouTube channel, and Google Analytics to read this website's visit statistics. Only authorised Rounds staff connect these, with their own Google account, and what we store is the sign-in token for the Rounds channel and the Rounds Analytics property, kept encrypted on our server.
Rounds does not collect, store or share data about YouTube viewers or about users of the Rounds app through YouTube API Services. Google Analytics counts a visit on this website only if you chose “Accept all” on the cookie notice.
By using YouTube features linked from Rounds you agree to be bound by the YouTube Terms of Service. Google's use of data is described in the Google Privacy Policy. Access that a Google account has given to Rounds can be withdrawn at any time at security.google.com/settings/security/permissions.
We may update this policy as the service or the law changes. The “last updated” date above reflects the current version, and we will give in-app notice of any material change before it takes effect.
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the designated officer for privacy complaints is:
Grievance Redressal Officer
Rounds Healthcare Technologies
Email: grievance@myrounds.in
Location: India
Complaints are acknowledged within 24 hours and resolved within 15 days. If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India.