October is Breast Cancer Awareness Month. Book a screening mammogram at a special price. Learn more

Your data, your say.

How Lumi Hospital collects, uses, shares and protects your personal and health information, and how you stay in control of it. Written in plain language under the Digital Personal Data Protection Act, 2023 (DPDP Act).

Last updated · 7 min read
Make a data request
On this page12 sections
  1. 01At a glance
  2. 02Who we are
  3. 03What we collect
  4. 04How we use it
  5. 05Who we share with
  6. 06Cookies & device storage
  7. 07How long we keep it
  8. 08How we protect it
  9. 09Your rights
  10. 10Children & guardians
  11. 11Changes & language
  12. 12Contact & complaints

01At a glance#

This website does not store what you type into its forms. When you send a form, your own WhatsApp or email app opens with the message, and it is sent to us only when you press send in that app. At the hospital itself, we handle your health records under strict medical confidentiality.

  • We collect only what we need to book, treat, bill and follow up with you.
  • We never sell your data, and we never use your health data for advertising.
  • You can ask to see, correct or erase your data, withdraw consent, or nominate someone, using the data request form.
  • Questions go to our Data Protection Officer at privacy@lumihospital.in.

02Who we are#

Lumi Hospital is the Data Fiduciary for the personal data described here. This means we decide why and how it is processed.

Legal entity
[to be provided by the hospital]
Registered address
[to be provided by the hospital]
KPME registration no.
[to be provided by the hospital]
Data Protection Officer
[to be provided by the hospital] · privacy@lumihospital.in
Grievance Officer
[to be provided by the hospital] · grievance@lumihospital.in · [to be provided by the hospital]

03What we collect#

When you use this website

DataWhyBasisKept for
Name, mobile, email and message you type into a formTo reply, book or confirm an appointmentYour consent (tick box on the form)Not stored on the website. Kept in our WhatsApp or email system for as long as needed to handle your request, then for at least 1 year as a record of processing (DPDP Rules, r.8(3))
Speciality, doctor, preferred date, symptoms or reason for visit (may include health information)To route you to the right doctor and prepare your visitYour consentAs above. Moved into your medical record if you become our patient
Display preferences (theme, colours, accessibility settings, list or grid view) and your privacy choiceTo remember how you like the site to lookStrictly necessary. Stored only on your deviceUntil you clear your browser storage
Technical data your browser sends (IP address, device, browser, pages requested)To deliver and secure the websiteLegitimate use / securityServer logs for up to 1 year, kept by our hosting provider: [to be provided by the hospital]

When you are our patient

DataWhyBasisKept for
Identity and contact details, ID document, emergency contactRegistration, identification, safetyConsent; legal obligationAs long as your medical record
Medical history, examinations, test results, images, prescriptions, procedures and discharge summariesDiagnosis, treatment, continuity of careConsent; medical emergency where applicableAs required by law and our records policy: [to be provided by the hospital]
Insurance, TPA and payment detailsBilling, cashless claims, refundsConsent; contractAs required under tax and insurance law
CCTV in public areas of the hospitalSafety and security of patients and staffLegitimate use[to be provided by the hospital]

We do not knowingly collect data we don't need. Please don't send us copies of ID documents or reports over WhatsApp unless a coordinator asks you to.

04How we use it#

We use your data only for the purpose we told you about when we collected it, or for a purpose the law allows:

  • Booking, rescheduling and reminding you about appointments and health check-ups
  • Diagnosis, treatment, nursing and follow-up care by the team treating you
  • Sharing reports with you and with the doctors you are referred to
  • Billing, insurance pre-authorisation and claims
  • Meeting legal duties, for example notifying certain diseases to public health authorities, medico-legal cases, and PC-PNDT records
  • Improving the quality and safety of care, using de-identified data wherever possible

Under section 7 of the DPDP Act we may also process data without fresh consent in certain situations: to respond to a medical emergency that threatens your life or health, to provide treatment during an epidemic or other public-health threat, to comply with a law or court order, or where you have voluntarily given us data for a stated purpose.

We will ask for your consent again, separately, before using your data for anything new, such as research or health newsletters. Saying no will never affect your treatment.

05Who we share with#

  • Your care team: doctors, nurses, lab and imaging staff involved in your care.
  • Insurers and TPAs: only when you ask us to process a claim.
  • Service providers (Data Processors): who handle data for us under contract with security safeguards. These are hospital information system, laboratory system, cloud hosting, and messaging (WhatsApp Business / email). Current list: [to be provided by the hospital].
  • Government and regulators: when the law requires it, for example public health authorities, the police in medico-legal cases, or the PC-PNDT appropriate authority.
  • Someone you authorise: a family member, nominee or legal representative you name.

Some providers, such as WhatsApp and Google Maps, may process data outside India. We transfer data abroad only as section 16 of the DPDP Act allows.

The map on our contact page is embedded from Google Maps. Google may set its own cookies when it loads. WhatsApp messages are also subject to WhatsApp's own privacy policy.

06Cookies & device storage#

This website does not use advertising or analytics cookies. It stores a few small settings in your browser. They never leave your device:

NameTypePurpose
lumi-themeLocal storageYour light/dark mode, colour theme and accessibility settings
lumi-dept-viewLocal storageWhether you prefer the list or grid view of specialities
lumi-consentLocal storageYour privacy choice, so we don't ask again
lumi-plSession storageShows the opening animation only once per visit

If we ever add analytics, we will ask for your consent first and list it here. You can review your choice at any time from Privacy choices in the footer.

07How long we keep it#

We keep personal data only for as long as the purpose needs it, and then erase it, unless a law requires us to keep it longer.

  • Medical records: for the period required by medical regulations (at least 3 years for in-patient records under the IMC Regulations, 2002) and our records policy: [to be provided by the hospital].
  • Pre-natal diagnostic records: at least 2 years, as the PC-PNDT Rules require.
  • Website enquiries that do not become appointments: deleted from our messaging systems once handled, keeping a minimal log for 1 year.
  • Processing logs: at least 1 year, as the DPDP Rules require.

08How we protect it#

We apply reasonable security safeguards, as required by Rule 6 of the DPDP Rules and the IT (Reasonable Security Practices) Rules, 2011:

  • Access to health records only for staff who need it, with individual logins
  • Encryption of data in transit and, where supported, at rest
  • Logging and review of access to detect misuse
  • Backups, so care can continue if a system fails
  • Written contracts requiring our processors to protect your data
  • Staff confidentiality undertakings and regular training

If something goes wrong

If a personal data breach affects you, we will tell you without delay. We will explain what happened, the likely impact, what we are doing about it, and what you can do. We will also inform the Data Protection Board of India, with a detailed report within 72 hours.

09Your rights#

Access
Get a summary of the personal data we hold about you, how we use it, and who we have shared it with (s.11).
Correction & erasure
Have inaccurate or incomplete data corrected, completed or updated, and data we no longer need erased (s.12). We may keep medical records the law requires us to keep.
Withdraw consent
Withdraw consent as easily as you gave it (s.6(4)). Withdrawal does not affect processing already done, or care that the law or a medical emergency requires.
Nominate
Name someone to exercise your rights if you die or become unable to (s.14).
Grievance redressal
Complain to our Grievance Officer, and if you are not satisfied, to the Data Protection Board of India (s.13).

You can exercise these rights through our data request form or by emailing privacy@lumihospital.in. We acknowledge requests within 2 working days and aim to resolve them within 30 days. We will always respond within 90 days, the maximum the DPDP Rules allow. To protect you, we may need to verify your identity first.

Copies of your own medical records are a separate right under the Charter of Patients' Rights: within 24 hours during admission and within 72 hours after discharge. See Patient rights.

Your duties under section 15 of the DPDP Act: give accurate information, don't impersonate anyone, and don't file false or frivolous complaints.

10Children & guardians#

If a patient is under 18, or is a person with a disability who has a lawful guardian, we ask the parent or lawful guardian to give consent on their behalf. We verify the guardian's identity at registration.

Under the Fourth Schedule of the DPDP Rules, a hospital may process a child's data without separate verifiable parental consent only to provide health services to that child, and only as far as needed to protect the child's health. We never track children or target them with advertising.

Website forms for a child must be filled in by a parent or guardian.

11Changes & language#

We will update this notice when our practices or the law change, and show the new date at the top. We will tell you about significant changes before they take effect.

You can ask for this notice in Kannada or another language listed in the Eighth Schedule to the Constitution. [to be provided by the hospital]

The DPDP Rules, 2025 were notified on 13 November 2025. Most of their duties take effect on 13 May 2027, but we already follow them. Until then, the Information Technology Act, 2000 (section 43A) and the SPDI Rules, 2011 also apply to how we handle your sensitive personal data, including health information.

12Contact & complaints#

Data Protection Officer
[to be provided by the hospital] · privacy@lumihospital.in
Grievance Officer
[to be provided by the hospital] · grievance@lumihospital.in · [to be provided by the hospital]
Postal address
[to be provided by the hospital], [to be provided by the hospital]

If we haven't resolved your grievance, you may complain to the Data Protection Board of India through the channels published by the Ministry of Electronics and Information Technology (meity.gov.in).

End of document · Lumi Hospital ·

24 / 7 · 365

Emergency? We're already up.

Emergency room, ICU, ambulance and pharmacy, open day and night.

+91 00000 00001