Last updated: 6 September 2026

Poshna provides hospital-visit companionship, prescription-guided home nursing and elderly caretaker services in Hyderabad, India. To do that safely we have to handle sensitive things — a person's diagnosis, their medicines, their address, their frailties. We treat that as a responsibility, not a formality.

This policy explains what we collect, why, who sees it, how long we keep it, and what you can ask us to do about it. It is written to meet our obligations under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and under the Information Technology Act, 2000 and its rules on sensitive personal data.

1. Who we are

Poshna is a care services business operating in Hyderabad, Telangana, and is the Data Fiduciary for the information described in this policy. That means we decide why and how it is processed, and we are answerable for it.

2. Whose information this covers

Under the Act, each of these people is a Data Principal and has the rights set out in section 13.

3. What we collect

We collect only what we need. Itemised, that is:

3.1 About you (the family member)

3.2 About the person receiving care

3.3 About job applicants

See section 16.

We do not require Aadhaar to provide care. If you choose to give an Aadhaar copy as identity proof, we keep it masked, and you may use a passport, driving licence, voter ID or PAN instead.

4. Where we get it

5. Why we use it

Each purpose, and what it enables:

We do not sell personal data. We do not use it for advertising, profiling or automated decision-making, and we do not share it with data brokers.

6. Our lawful basis

We rely on your consent, and the consent of the person receiving care, for the care-related purposes above. Before we ask for consent we give a separate, plain-language consent notice listing the data and the purposes, and you can withdraw that consent at any time as described in section 14.

In a small number of situations we rely on the "legitimate uses" the Act itself permits without separate consent, specifically:

7. Consent where a parent cannot give it themselves

We want to be straightforward with you about a genuine difficulty here, because it affects how we ask for consent.

Where the person receiving care can understand and agree to it, their own consent is what we rely on, and we will ask for it directly and in their own language. Your consent as a family member covers your own information and your instructions to us.

Where a person cannot give informed consent — for example because of advanced dementia — the Act recognises consent given by a lawful guardian, but the Rules define that narrowly: a guardian appointed by a court, or by a designated authority under the Rights of Persons with Disabilities Act, 2016, or by a local level committee under the National Trust Act, 1999. Being an adult son or daughter does not by itself make you a lawful guardian in that sense, and we will not pretend otherwise. Where a court-appointed or statutory guardian exists, we will ask to see the order and verify it.

For this reason we ask, at the very start of our relationship and while your parent is able to give it, for:

Doing this early is far better for everyone than trying to reconstruct authority after capacity has declined. Separately, our Terms of Service set out who may consent to the care itself on a patient's behalf, which is a different question from data rights.

8. Who we share it with

We share on a strict need-to-know basis, and only with:

We do not share a patient's health information with other family members unless the patient has agreed, or unless you are the nominated contact and the disclosure is necessary for their care.

9. Service providers and transfers outside India

We keep our operations deliberately simple, but a few technology providers necessarily handle some data:

Some of these providers are located outside India and personal data may therefore be transferred outside India. The Act permits this except to countries the Central Government restricts by notification, and we will stop such transfers if a provider's country is restricted. We require our providers by contract to keep data secure and to use it only for the purpose we engaged them for.

Care records themselves — prescriptions, visit notes, reports — are held by us in India and are not uploaded to any consumer cloud service or shared over any personal messaging account by our staff.

10. How long we keep it

We keep information only as long as the purpose needs, then delete or de-identify it. Our current periods are:

11. How we protect it

We are a small team, and we would rather tell you exactly what we do than make claims we cannot stand behind. Today, that means:

The Digital Personal Data Protection Rules, 2025 set out further minimum safeguards — including encryption or masking of stored data, formal role-based access control, and access logging retained for one year — which apply from 13 May 2027. We are working towards those and will update this section as each is in place, rather than claim them before they are.

No system is perfectly secure, and we will not pretend otherwise. What we do commit to is telling you promptly and honestly if something goes wrong.

12. If something goes wrong

If a personal data breach occurs, we will notify each affected person promptly, in plain language, describing what happened, its nature, extent and timing, the likely consequences, what we have done to contain it, what we suggest you do, and who to contact with questions. We will also report the breach to the Data Protection Board of India immediately, and provide the Board with fuller details within 72 hours.

13. Your rights

As a Data Principal, you may:

To exercise any of these, contact our Grievance Officer using the details in section 18. We may need to verify your identity, and your authority where you are asking on behalf of a parent. We will respond within 30 days.

The Act also asks something of you: please give us accurate information, do not impersonate anyone else, do not suppress material information — particularly a known infectious or behavioural risk, which endangers our personnel — and please do not file a knowingly false complaint.

14. Withdrawing consent

You may withdraw your consent at any time, and it must be as easy to withdraw as it was to give. Simply message us on WhatsApp at +91 94946 21929, or email care@poshna.in, saying you withdraw consent.

We will stop processing for the purposes you withdraw, and stop the service that depended on it. Two honest consequences to be aware of: we cannot continue to provide care once consent for handling the patient's health information is withdrawn, because doing so safely is impossible; and withdrawal does not oblige us to delete records we are legally required to keep, such as accounting records or a care record needed to defend a pending claim. Processing already carried out lawfully before withdrawal remains lawful.

15. Nominating someone to act for you

The Act gives every person the right to nominate another individual to exercise their data rights if they die or become unable to act through unsoundness of mind or infirmity of body. Given who we care for, we think this is one of the most useful rights in the Act, and we encourage every patient to use it while they comfortably can. Ask us for a nomination form, or include a nomination in your onboarding paperwork.

16. If you apply to work with us

When you register interest through our Careers page we collect your name, phone or WhatsApp number, the role you are applying for, your experience, your area of Hyderabad, and any note you write.

If we take your application forward, we will ask for a good deal more, including identity and address proof, qualification and nursing council registration details, police verification of character and antecedents, references, medical fitness and immunisation records, and bank and payroll details. We will explain each purpose and ask for your written consent before we verify anything, and we will tell you what we are checking and with whom. We use this information only to assess suitability, to meet our legal obligations as an employer, and to keep the people in our care safe. Where we do not engage you, we delete your application after the period in section 10 unless you ask us to keep it on file.

17. Our website

This website does not use advertising or tracking cookies, and we do not run analytics or advertising pixels on it. The only information it collects is what you type into the enquiry or careers form. As noted in section 9, loading the page causes your browser to fetch fonts and a code library from third-party services, which receive your IP address in the process. Our hosting provider keeps standard server logs.

18. Grievance redressal, and the Data Protection Board

If you have a question or a complaint about how we have handled your information, please contact our Grievance Officer:

We will acknowledge within 48 hours and aim to resolve within 30 days. Anything touching the safety or dignity of a person in our care is treated as urgent.

If we have not resolved your grievance, you may complain to the Data Protection Board of India. The Act asks you to raise it with us first, so please give us the chance to put it right.

19. Changes to this policy

We will update this policy as our services and the law develop, and the current version will always be on this page with the date of last update at the top. Where a change materially affects how we handle information about you or your parent, we will tell you directly rather than relying on you to notice.

20. Contact us

Questions about this policy? Reach us at care@poshna.in or on WhatsApp.

Read our Terms of Service →