Last updated: 6 September 2026
Poshna provides hospital-visit companionship, prescription-guided home nursing and elderly caretaker services in Hyderabad, India. To do that safely we have to handle sensitive things — a person's diagnosis, their medicines, their address, their frailties. We treat that as a responsibility, not a formality.
This policy explains what we collect, why, who sees it, how long we keep it, and what you can ask us to do about it. It is written to meet our obligations under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and under the Information Technology Act, 2000 and its rules on sensitive personal data.
1. Who we are
Poshna is a care services business operating in Hyderabad, Telangana, and is the Data Fiduciary for the information described in this policy. That means we decide why and how it is processed, and we are answerable for it.
- WhatsApp: +91 94946 21929 — our main channel
- Email: care@poshna.in
- Grievance Officer: see section 18
2. Whose information this covers
- The person receiving care — usually an elderly parent. Most of the health information we hold is theirs.
- You, the family member who enquires, books, receives updates and pays.
- People who apply to work with us through our Careers page.
Under the Act, each of these people is a Data Principal and has the rights set out in section 13.
3. What we collect
We collect only what we need. Itemised, that is:
3.1 About you (the family member)
- Name, phone or WhatsApp number, email address.
- Your relationship to the person receiving care, and your authority to arrange care on their behalf.
- Billing details and payment records. We do not store card numbers, CVVs or bank passwords.
- Your messages to us, and our notes of calls with you.
3.2 About the person receiving care
- Name, age, sex, residential address in Hyderabad and access details.
- Identity and address proof, for verification.
- Health information: diagnoses, current medicines and doses, allergies, prescriptions and care plans from the treating doctor, discharge summaries, investigation and diagnostic reports, mobility and continence status, cognitive state, fall history, known infectious conditions, and dietary needs.
- Treating doctor's name and contact details, preferred hospital, and any advance directive you give us.
- Health insurance or TPA policy details, where you ask us to help with claim paperwork.
- Visit records: date and time of each visit, who attended, tasks performed, observations, any refusal of care, and incidents.
- Clinical photographs, such as of a wound, only where you have specifically consented.
- Emergency contacts and the nominated decision-maker.
3.3 About job applicants
See section 16.
We do not require Aadhaar to provide care. If you choose to give an Aadhaar copy as identity proof, we keep it masked, and you may use a passport, driving licence, voter ID or PAN instead.
4. Where we get it
- Directly from you — the website enquiry form, WhatsApp, phone calls, and the onboarding forms you sign.
- From the person receiving care, during visits.
- From documents you hand us, such as prescriptions, discharge summaries and reports.
- From hospitals, doctors and diagnostic laboratories, where our companion collects reports on your written authorisation.
- From our own personnel, in the form of visit notes and observations.
5. Why we use it
Each purpose, and what it enables:
- To answer your enquiry and tell you whether and how we can help, including pricing.
- To assess whether care can be delivered safely at the residence, and to decline where it cannot.
- To match, brief and supervise the companion, nurse or attendant who will attend, so they arrive knowing the allergies, risks and prescription that apply.
- To deliver prescribed nursing care strictly in accordance with the treating doctor's written prescription.
- To accompany the patient to appointments and to present documents, queue, and collect reports on your authorisation.
- To keep you updated with visit summaries and reports.
- To maintain a care record, which is what allows continuity between visits and what protects both the patient and our personnel if a question is later raised about what happened.
- To respond to a medical emergency, including handing over known clinical information to attending medical staff or an ambulance crew.
- To invoice you and keep accounts and tax records.
- To investigate a complaint, incident or safeguarding concern, and to defend or pursue a legal claim.
- To meet legal obligations, including under tax, company, labour and bio-medical waste law.
- To improve safety and quality — for which we use aggregated or de-identified information wherever it will do the job.
We do not sell personal data. We do not use it for advertising, profiling or automated decision-making, and we do not share it with data brokers.
6. Our lawful basis
We rely on your consent, and the consent of the person receiving care, for the care-related purposes above. Before we ask for consent we give a separate, plain-language consent notice listing the data and the purposes, and you can withdraw that consent at any time as described in section 14.
In a small number of situations we rely on the "legitimate uses" the Act itself permits without separate consent, specifically:
- A medical emergency involving a threat to the life or immediate threat to the health of the person in our care, or of anyone else present.
- Compliance with law, or with an order or judgment, including a lawful request from a court, regulator or the police.
- Employment purposes, in relation to our own personnel.
7. Consent where a parent cannot give it themselves
We want to be straightforward with you about a genuine difficulty here, because it affects how we ask for consent.
Where the person receiving care can understand and agree to it, their own consent is what we rely on, and we will ask for it directly and in their own language. Your consent as a family member covers your own information and your instructions to us.
Where a person cannot give informed consent — for example because of advanced dementia — the Act recognises consent given by a lawful guardian, but the Rules define that narrowly: a guardian appointed by a court, or by a designated authority under the Rights of Persons with Disabilities Act, 2016, or by a local level committee under the National Trust Act, 1999. Being an adult son or daughter does not by itself make you a lawful guardian in that sense, and we will not pretend otherwise. Where a court-appointed or statutory guardian exists, we will ask to see the order and verify it.
For this reason we ask, at the very start of our relationship and while your parent is able to give it, for:
- their own written consent to our providing care and handling their health information; and
- a nomination under section 14 of the Act, naming the person who may exercise their data rights if they later become unable to.
Doing this early is far better for everyone than trying to reconstruct authority after capacity has declined. Separately, our Terms of Service set out who may consent to the care itself on a patient's behalf, which is a different question from data rights.
8. Who we share it with
We share on a strict need-to-know basis, and only with:
- The assigned companion, nurse or attendant — limited to what they need to provide care safely. They are bound by a written confidentiality undertaking.
- Our own supervisory and coordination staff, for briefing, escalation and quality review.
- Hospitals, treating doctors, diagnostic laboratories and pharmacies, to the extent needed to accompany or assist the patient, or to hand over information in an emergency.
- Your health insurer or TPA, only if you ask us to support a claim.
- Our service providers, listed in section 9, who process data on our instructions under contract.
- Professional advisers — our accountants, auditors, insurers and lawyers — where genuinely required.
- Courts, regulators, the police or other authorities, where the law requires it, or to protect the safety of the person in our care.
We do not share a patient's health information with other family members unless the patient has agreed, or unless you are the nominated contact and the disclosure is necessary for their care.
9. Service providers and transfers outside India
We keep our operations deliberately simple, but a few technology providers necessarily handle some data:
- Hostinger — hosts this website.
- Web3Forms — delivers submissions from our website enquiry and careers forms to our email inbox. Please do not enter detailed medical information into the website form; tell us on WhatsApp or by phone instead, and share documents only when we ask for them.
- WhatsApp (Meta) — carries our messages with you. Messages are encrypted in transit by WhatsApp, but they are also stored on your device and ours. Please bear that in mind before sending reports through it.
- Google Fonts and a public JavaScript library service — serve fonts and code to your browser when you load this site, and in doing so receive your IP address and browser details. They receive no information you type.
Some of these providers are located outside India and personal data may therefore be transferred outside India. The Act permits this except to countries the Central Government restricts by notification, and we will stop such transfers if a provider's country is restricted. We require our providers by contract to keep data secure and to use it only for the purpose we engaged them for.
Care records themselves — prescriptions, visit notes, reports — are held by us in India and are not uploaded to any consumer cloud service or shared over any personal messaging account by our staff.
10. How long we keep it
We keep information only as long as the purpose needs, then delete or de-identify it. Our current periods are:
- Enquiries that do not become bookings: 12 months from your last contact, then deleted.
- Care records, prescriptions and visit logs: three years from the last service, which reflects the general limitation period for a claim, and longer where a complaint, claim, investigation or regulatory proceeding is pending or reasonably anticipated.
- Invoices, payment records and accounting books: as required by the Companies Act, 2013 and income-tax law, currently eight financial years.
- Personnel records: for the period required by labour, provident fund and tax law after a person leaves us.
- Access and security logs: one year, as the Rules require, so that unauthorised access can be detected and investigated.
- Job applications from candidates we do not engage: 12 months, unless you ask us to delete them sooner.
11. How we protect it
We are a small team, and we would rather tell you exactly what we do than make claims we cannot stand behind. Today, that means:
- Need-to-know access. Care details go only to the person attending your parent and to the coordinator briefing them. We do not circulate patient information more widely than that.
- Confidentiality undertakings and training for every member of our personnel, including a standing instruction never to copy patient information to a personal device, personal email or personal messaging account, and never to discuss or photograph a patient outside the care record.
- Password-protected, screen-locked devices for anyone handling records.
- Masked storage of identity documents, and secure disposal of paper records rather than ordinary waste.
- Backups of care records, so that care can continue if a device is lost or fails.
- Contractual security obligations on the service providers listed in section 9.
The Digital Personal Data Protection Rules, 2025 set out further minimum safeguards — including encryption or masking of stored data, formal role-based access control, and access logging retained for one year — which apply from 13 May 2027. We are working towards those and will update this section as each is in place, rather than claim them before they are.
No system is perfectly secure, and we will not pretend otherwise. What we do commit to is telling you promptly and honestly if something goes wrong.
12. If something goes wrong
If a personal data breach occurs, we will notify each affected person promptly, in plain language, describing what happened, its nature, extent and timing, the likely consequences, what we have done to contain it, what we suggest you do, and who to contact with questions. We will also report the breach to the Data Protection Board of India immediately, and provide the Board with fuller details within 72 hours.
13. Your rights
As a Data Principal, you may:
- Ask what we hold — a summary of the personal data we process about you and what we do with it, and the identities of anyone we have shared it with.
- Correct or complete it — have inaccurate or misleading data corrected, incomplete data completed, and out-of-date data updated. This matters practically: a wrong allergy or a stale medicine list is a safety risk, so please tell us immediately.
- Ask us to erase it — where we no longer need it for the purpose and no law requires us to keep it.
- Have your grievance addressed — see section 18.
- Nominate someone — see section 15.
To exercise any of these, contact our Grievance Officer using the details in section 18. We may need to verify your identity, and your authority where you are asking on behalf of a parent. We will respond within 30 days.
The Act also asks something of you: please give us accurate information, do not impersonate anyone else, do not suppress material information — particularly a known infectious or behavioural risk, which endangers our personnel — and please do not file a knowingly false complaint.
14. Withdrawing consent
You may withdraw your consent at any time, and it must be as easy to withdraw as it was to give. Simply message us on WhatsApp at +91 94946 21929, or email care@poshna.in, saying you withdraw consent.
We will stop processing for the purposes you withdraw, and stop the service that depended on it. Two honest consequences to be aware of: we cannot continue to provide care once consent for handling the patient's health information is withdrawn, because doing so safely is impossible; and withdrawal does not oblige us to delete records we are legally required to keep, such as accounting records or a care record needed to defend a pending claim. Processing already carried out lawfully before withdrawal remains lawful.
15. Nominating someone to act for you
The Act gives every person the right to nominate another individual to exercise their data rights if they die or become unable to act through unsoundness of mind or infirmity of body. Given who we care for, we think this is one of the most useful rights in the Act, and we encourage every patient to use it while they comfortably can. Ask us for a nomination form, or include a nomination in your onboarding paperwork.
16. If you apply to work with us
When you register interest through our Careers page we collect your name, phone or WhatsApp number, the role you are applying for, your experience, your area of Hyderabad, and any note you write.
If we take your application forward, we will ask for a good deal more, including identity and address proof, qualification and nursing council registration details, police verification of character and antecedents, references, medical fitness and immunisation records, and bank and payroll details. We will explain each purpose and ask for your written consent before we verify anything, and we will tell you what we are checking and with whom. We use this information only to assess suitability, to meet our legal obligations as an employer, and to keep the people in our care safe. Where we do not engage you, we delete your application after the period in section 10 unless you ask us to keep it on file.
17. Our website
This website does not use advertising or tracking cookies, and we do not run analytics or advertising pixels on it. The only information it collects is what you type into the enquiry or careers form. As noted in section 9, loading the page causes your browser to fetch fonts and a code library from third-party services, which receive your IP address in the process. Our hosting provider keeps standard server logs.
18. Grievance redressal, and the Data Protection Board
If you have a question or a complaint about how we have handled your information, please contact our Grievance Officer:
- Grievance Officer: the proprietor of Poshna
- WhatsApp: +91 94946 21929
- Email: care@poshna.in
We will acknowledge within 48 hours and aim to resolve within 30 days. Anything touching the safety or dignity of a person in our care is treated as urgent.
If we have not resolved your grievance, you may complain to the Data Protection Board of India. The Act asks you to raise it with us first, so please give us the chance to put it right.
19. Changes to this policy
We will update this policy as our services and the law develop, and the current version will always be on this page with the date of last update at the top. Where a change materially affects how we handle information about you or your parent, we will tell you directly rather than relying on you to notice.
20. Contact us
Questions about this policy? Reach us at care@poshna.in or on WhatsApp.