This Privacy Policy is an electronic record under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), and the rules made under them. It is generated by a computer system and does not require a physical or digital signature.
Centiva Healthcare Private Limited (“Centiva Health”, “we”, “us” or “our”) operates the website www.centiva.health and the related assessments, programmes, applications and services (together, the “Services”). Your health information is among the most personal data you can share, and we treat it that way. This policy explains, as plainly as we can, what we collect, why we collect it, who we share it with and the choices you have.
By using the Services you agree to the collection and use of your information as described here. If you do not agree with any part of this policy, please stop using the Services.
Scope and applicable law
This policy covers information collected through our website, our assessments and programmes, and any related sales, marketing or events. We process personal data in line with the laws of India, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the DPDP Act, as amended from time to time.
Information we collect
Information you give us
Depending on how you use the Services, this may include:
- Identity and contact details — name, date of birth, gender, phone number, email and address.
- Health information — symptoms, medical and family history, medications, lifestyle questionnaires, lab and biomarker results, body composition, imaging reports and physician notes.
- Transaction details — services purchased, invoices and payment status. We do not store full card numbers.
- Communications — messages, feedback and support requests you send us.
Please make sure the information you give us is accurate and complete, and let us know when it changes. Centiva Health is not responsible for decisions made on information you supply that is inaccurate.
Information collected automatically
When you visit the website we automatically collect limited technical data such as IP address, browser and device type, operating system, referring pages, approximate location and how you move through the site. This does not identify you by name; we use it to keep the website secure, fix problems and understand what is useful.
How we use your information
We process your information to provide the Services you ask for, with your consent, for our legitimate business purposes, and to meet our legal obligations. Specifically, to:
- book and deliver assessments, sample collections, consultations and programmes;
- let our physicians and care team review your results and build your personalised protocol;
- send reminders, reports, progress updates and other service communications;
- process payments, issue invoices and handle refunds;
- ask for feedback and improve the quality and safety of our Services;
- analyse aggregated, de-identified data to understand trends and develop new services; and
- comply with law, including medical record-keeping requirements.
We will only send you marketing messages with your consent, and you can opt out at any time using the link in the message or by writing to us.
When we share information
We do not sell your personal data. We share it only in these circumstances:
- Care partners — accredited diagnostic laboratories, imaging centres, sample-collection partners and physicians who need it to deliver your Services, under confidentiality obligations.
- Service providers — hosting, payment, communication and analytics providers who process data on our instructions and for no other purpose.
- Aggregated insights — statistics that cannot identify you.
- Legal requirements — where required by law, court order or a lawful request from a government authority, or to protect the safety of any person or investigate fraud.
- Business transfers — as part of a merger, acquisition, financing or sale of assets, in which case the recipient will be bound by this policy.
How we protect your information
We use reasonable technical and organisational safeguards, including encryption in transit, access controls limited to people who need the data, and regular review of our practices. No system connected to the internet is completely secure, however, and we cannot guarantee absolute security. Please access the Services only from devices and networks you trust.
How long we keep your information
We keep personal data only as long as needed for the purposes in this policy, or longer where the law requires it — for example, applicable medical record retention rules. When we no longer need it we delete or anonymise it. Where that is not immediately possible (such as data in backups), we store it securely and isolate it until it can be deleted.
Your rights
Subject to applicable law, including the DPDP Act, you can:
- ask for a summary of the personal data we hold about you and how it is processed;
- ask us to correct, complete or update your data;
- ask us to erase your data, unless we are required to keep it by law;
- withdraw your consent at any time — this does not affect processing already carried out; and
- raise a grievance with us, and escalate it to the Data Protection Board of India if unresolved.
To use any of these rights, contact us using the details below.
Cookies and third-party services
We use cookies and similar technologies to keep the website working, remember preferences and measure usage. Most browsers accept cookies by default; you can change this in your browser settings, though some features may not work as intended. We do not store personally identifiable information in cookies.
The website may link to or embed third-party services such as social media platforms. Those services may collect data under their own privacy policies, which we encourage you to read. We are not responsible for their practices.
Children
The Services are intended for people aged 18 and over. We do not knowingly collect data from children without verifiable consent from a parent or lawful guardian.
Changes to this policy
We may update this policy from time to time. The latest version will always be on this page with its effective date, and continued use of the Services after an update means you accept the revised policy. Where changes are significant we will make reasonable efforts to notify you.
Grievance Officer and contact
If you have questions, requests or complaints about this policy or how we handle your data, please contact our Grievance Officer. We aim to acknowledge complaints within 48 hours and resolve them within 30 days.