01At a glance#
This website does not store what you type into its forms. When you send a form, your own WhatsApp or email app opens with the message, and it is sent to us only when you press send in that app. At the hospital itself, we handle your health records under strict medical confidentiality.
- We collect only what we need to book, treat, bill and follow up with you.
- We never sell your data, and we never use your health data for advertising.
- You can ask to see, correct or erase your data, withdraw consent, or nominate someone, using the data request form.
- Questions go to our Data Protection Officer at privacy@lumihospital.in.
02Who we are#
Lumi Hospital is the Data Fiduciary for the personal data described here. This means we decide why and how it is processed.
- Legal entity
- [to be provided by the hospital]
- Registered address
- [to be provided by the hospital]
- KPME registration no.
- [to be provided by the hospital]
- Data Protection Officer
- [to be provided by the hospital] · privacy@lumihospital.in
- Grievance Officer
- [to be provided by the hospital] · grievance@lumihospital.in · [to be provided by the hospital]
03What we collect#
When you use this website
| Data | Why | Basis | Kept for |
|---|---|---|---|
| Name, mobile, email and message you type into a form | To reply, book or confirm an appointment | Your consent (tick box on the form) | Not stored on the website. Kept in our WhatsApp or email system for as long as needed to handle your request, then for at least 1 year as a record of processing (DPDP Rules, r.8(3)) |
| Speciality, doctor, preferred date, symptoms or reason for visit (may include health information) | To route you to the right doctor and prepare your visit | Your consent | As above. Moved into your medical record if you become our patient |
| Display preferences (theme, colours, accessibility settings, list or grid view) and your privacy choice | To remember how you like the site to look | Strictly necessary. Stored only on your device | Until you clear your browser storage |
| Technical data your browser sends (IP address, device, browser, pages requested) | To deliver and secure the website | Legitimate use / security | Server logs for up to 1 year, kept by our hosting provider: [to be provided by the hospital] |
When you are our patient
| Data | Why | Basis | Kept for |
|---|---|---|---|
| Identity and contact details, ID document, emergency contact | Registration, identification, safety | Consent; legal obligation | As long as your medical record |
| Medical history, examinations, test results, images, prescriptions, procedures and discharge summaries | Diagnosis, treatment, continuity of care | Consent; medical emergency where applicable | As required by law and our records policy: [to be provided by the hospital] |
| Insurance, TPA and payment details | Billing, cashless claims, refunds | Consent; contract | As required under tax and insurance law |
| CCTV in public areas of the hospital | Safety and security of patients and staff | Legitimate use | [to be provided by the hospital] |
We do not knowingly collect data we don't need. Please don't send us copies of ID documents or reports over WhatsApp unless a coordinator asks you to.
04How we use it#
We use your data only for the purpose we told you about when we collected it, or for a purpose the law allows:
- Booking, rescheduling and reminding you about appointments and health check-ups
- Diagnosis, treatment, nursing and follow-up care by the team treating you
- Sharing reports with you and with the doctors you are referred to
- Billing, insurance pre-authorisation and claims
- Meeting legal duties, for example notifying certain diseases to public health authorities, medico-legal cases, and PC-PNDT records
- Improving the quality and safety of care, using de-identified data wherever possible
Under section 7 of the DPDP Act we may also process data without fresh consent in certain situations: to respond to a medical emergency that threatens your life or health, to provide treatment during an epidemic or other public-health threat, to comply with a law or court order, or where you have voluntarily given us data for a stated purpose.
We will ask for your consent again, separately, before using your data for anything new, such as research or health newsletters. Saying no will never affect your treatment.
06Cookies & device storage#
This website does not use advertising or analytics cookies. It stores a few small settings in your browser. They never leave your device:
| Name | Type | Purpose |
|---|---|---|
| lumi-theme | Local storage | Your light/dark mode, colour theme and accessibility settings |
| lumi-dept-view | Local storage | Whether you prefer the list or grid view of specialities |
| lumi-consent | Local storage | Your privacy choice, so we don't ask again |
| lumi-pl | Session storage | Shows the opening animation only once per visit |
If we ever add analytics, we will ask for your consent first and list it here. You can review your choice at any time from Privacy choices in the footer.
07How long we keep it#
We keep personal data only for as long as the purpose needs it, and then erase it, unless a law requires us to keep it longer.
- Medical records: for the period required by medical regulations (at least 3 years for in-patient records under the IMC Regulations, 2002) and our records policy: [to be provided by the hospital].
- Pre-natal diagnostic records: at least 2 years, as the PC-PNDT Rules require.
- Website enquiries that do not become appointments: deleted from our messaging systems once handled, keeping a minimal log for 1 year.
- Processing logs: at least 1 year, as the DPDP Rules require.
08How we protect it#
We apply reasonable security safeguards, as required by Rule 6 of the DPDP Rules and the IT (Reasonable Security Practices) Rules, 2011:
- Access to health records only for staff who need it, with individual logins
- Encryption of data in transit and, where supported, at rest
- Logging and review of access to detect misuse
- Backups, so care can continue if a system fails
- Written contracts requiring our processors to protect your data
- Staff confidentiality undertakings and regular training
If something goes wrong
If a personal data breach affects you, we will tell you without delay. We will explain what happened, the likely impact, what we are doing about it, and what you can do. We will also inform the Data Protection Board of India, with a detailed report within 72 hours.
09Your rights#
- Access
- Get a summary of the personal data we hold about you, how we use it, and who we have shared it with (s.11).
- Correction & erasure
- Have inaccurate or incomplete data corrected, completed or updated, and data we no longer need erased (s.12). We may keep medical records the law requires us to keep.
- Withdraw consent
- Withdraw consent as easily as you gave it (s.6(4)). Withdrawal does not affect processing already done, or care that the law or a medical emergency requires.
- Nominate
- Name someone to exercise your rights if you die or become unable to (s.14).
- Grievance redressal
- Complain to our Grievance Officer, and if you are not satisfied, to the Data Protection Board of India (s.13).
You can exercise these rights through our data request form or by emailing privacy@lumihospital.in. We acknowledge requests within 2 working days and aim to resolve them within 30 days. We will always respond within 90 days, the maximum the DPDP Rules allow. To protect you, we may need to verify your identity first.
Copies of your own medical records are a separate right under the Charter of Patients' Rights: within 24 hours during admission and within 72 hours after discharge. See Patient rights.
Your duties under section 15 of the DPDP Act: give accurate information, don't impersonate anyone, and don't file false or frivolous complaints.
10Children & guardians#
If a patient is under 18, or is a person with a disability who has a lawful guardian, we ask the parent or lawful guardian to give consent on their behalf. We verify the guardian's identity at registration.
Under the Fourth Schedule of the DPDP Rules, a hospital may process a child's data without separate verifiable parental consent only to provide health services to that child, and only as far as needed to protect the child's health. We never track children or target them with advertising.
Website forms for a child must be filled in by a parent or guardian.
11Changes & language#
We will update this notice when our practices or the law change, and show the new date at the top. We will tell you about significant changes before they take effect.
You can ask for this notice in Kannada or another language listed in the Eighth Schedule to the Constitution. [to be provided by the hospital]
The DPDP Rules, 2025 were notified on 13 November 2025. Most of their duties take effect on 13 May 2027, but we already follow them. Until then, the Information Technology Act, 2000 (section 43A) and the SPDI Rules, 2011 also apply to how we handle your sensitive personal data, including health information.
12Contact & complaints#
- Data Protection Officer
- [to be provided by the hospital] · privacy@lumihospital.in
- Grievance Officer
- [to be provided by the hospital] · grievance@lumihospital.in · [to be provided by the hospital]
- Postal address
- [to be provided by the hospital], [to be provided by the hospital]
If we haven't resolved your grievance, you may complain to the Data Protection Board of India through the channels published by the Ministry of Electronics and Information Technology (meity.gov.in).
End of document · Lumi Hospital ·