PRIVACY POLICY
This Privacy Policy ("Privacy Policy" or "Policy") explains how “NSD – Nursing Services at Doorstep” is a brand name, trade name and digital healthcare platform that is owned, operated and controlled by Trisha Helping Hands LLP, a limited liability partnership incorporated under the laws of India and having its registered office at 93 Shiv Shakti Nagar, Behind Anup Cinema, CGO Complex, MIG Thana, Indore – 452001, Madhya Pradesh, India ("NSD", "we", "us" or "our"), collects, receives, stores, uses, processes, shares and protects information relating to users of the mobile application and website branded as NSD – Nursing Services at Doorstep (collectively, the "Platform").
All services made available through the mobile application, website, digital interfaces and related technology infrastructure branded as NSD – Nursing Services at Doorstep (collectively, the “Platform”) are provided by or through Trisha Helping Hands LLP, either directly or through empaneled and authorized third-party service providers.
For the purposes of applicable data protection, information technology and consumer protection laws, Trisha Helping Hands LLP shall be the “Data Fiduciary” / “Body Corporate” / “Platform Operator”, as applicable, in respect of all personal data, sensitive personal data and information collected, processed, stored or otherwise handled through the Platform, and shall be responsible for compliance with applicable legal and regulatory requirements.
This Privacy Policy is drafted in line with detailed healthcare technology platforms operating in India and governs the collection and use of Personal Information and Sensitive Personal Data or Information of all users of the Platform.
1. Legal Compliance and Scope of this Privacy Policy
This Privacy Policy is published in accordance with the applicable provisions of Indian law, including, inter alia, Section 43A of the Information Technology Act, 2000, which mandates the implementation of reasonable security practices and procedures for the protection of personal data; the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPI Rules”), which regulate the collection, use, storage, disclosure and transfer of sensitive personal data or information; and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which prescribe due diligence requirements for intermediaries operating digital platforms. This Privacy Policy is further guided by applicable principles under Indian healthcare laws, consumer protection legislation and emerging data protection frameworks, to the extent relevant to the nature of services provided through the Platform.
This Privacy Policy sets out in detail the categories and nature of information collected from Users, including Personal Information and Sensitive Personal Data or Information; the purposes for which such information is collected; the lawful means and methods adopted for collection; and the manner in which such information is used, processed, stored, retained and secured. The Policy further explains the circumstances under which such information may be shared or disclosed, including disclosures made for the purpose of service delivery, legal compliance, operational requirements, or pursuant to lawful requests from governmental or regulatory authorities. This Privacy Policy is intended to ensure transparency, safeguard user privacy, and demonstrate the Platform’s commitment to responsible data handling practices in accordance with applicable law.
2. Applicability and Consent
By accessing, browsing, registering on, or using the Platform or any Services, or by otherwise providing your information to NSD, you shall be deemed to have read, understood and agreed to the practices and policies outlined in this Privacy Policy and to be bound by the same. You hereby expressly consent to the collection, use, processing, storage, retention and disclosure of your Personal Information and Sensitive Personal Data or Information for the purposes and in the manner described under this Privacy Policy and in accordance with applicable law.
This Privacy Policy forms an integral part of the Terms of Use of the Platform. If you do not agree with this Privacy Policy at any time, you must immediately discontinue access to and use of the Platform and Services and refrain from providing any information to NSD.
In accordance with the Digital Personal Data Protection Act, 2023, you acknowledge that you are the Data Principal in respect of the personal data provided by you and that such data is being processed by NSD for lawful purposes connected with the provision of nursing, caregiving and allied healthcare services. You further acknowledge that you are providing your consent freely, specifically, informed and unambiguous, through clear affirmative action, including but not limited to clicking ‘I Agree’, registering on, or otherwise using the Platform, for the processing of your personal data in accordance with this Privacy Policy and applicable law. You may withdraw your consent at any time by providing written notice to NSD; however, you acknowledge that withdrawal of consent may result in NSD being unable to provide some or all Services and may require termination of any ongoing service relationship.
Where you use the Platform or Services on behalf of another individual, including but not limited to a patient, elderly person, minor or dependent, you represent and warrant that you are duly authorized to act on behalf of such individual as their legal guardian, authorized representative or caregiver, and that you have obtained all necessary consents required under applicable law to provide their personal data and sensitive personal data. You further consent, on behalf of such individual, to the collection, use, processing and disclosure of such data in accordance with this Privacy Policy, and agree to indemnify NSD against any claims arising from lack of valid authorization or consent.
3. Definitions
For the purposes of this Privacy Policy, unless the context otherwise requires, the following terms shall have the meanings ascribed to them below:
“Personal Information” shall mean any information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available with a body corporate, is capable of identifying such person.
“Sensitive Personal Data or Information” or “SPDI” shall mean such personal information of a person as is classified as sensitive under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and shall include, without limitation, passwords, financial information such as bank account, credit card or debit card details, physical, physiological or mental health condition, medical records and history, biometric information, and any information received by NSD under a lawful contract or otherwise.
“Users” shall collectively refer to and include all persons who access, browse, register on or use the Platform or Services, including but not limited to patients, service recipients, family members or authorized representatives, nurses, caregivers, attendants, healthcare professionals, registered users and casual visitors to the Platform.
“Service Providers” shall mean nurses, caregivers, attendants and other healthcare professionals who are empaneled, on boarded or otherwise engaged through the Platform for the purpose of providing nursing, caregiving or allied healthcare services to Users.
4. Collection of Information
4.1 Information Collected from Users
In order to enable NSD to provide its Services effectively and in accordance with applicable law, NSD may require Users to voluntarily provide certain information that personally identifies them or could be used to identify them. Such information may be collected at the time of registration, booking of services, communication with NSD, or during the course of service delivery. The information collected from Users may include, without limitation, their name, gender, age and date of birth; mobile number, email address and residential address; details relating to the patient’s medical condition, diagnosis, prescriptions, medical history, care requirements and clinical notes; emergency contact details; identity and address proof where required for verification or compliance purposes; payment, billing and transaction details; and any feedback, reviews, grievances or other communications shared by the User with NSD.
The information so collected may constitute Personal Information or Sensitive Personal Data or Information under applicable law. Provision of such information by Users is voluntary; however, failure to provide certain information may result in NSD being unable to provide some or all of the Services.
4.2 Information Collected Automatically
Due to the communications standards on the internet and the nature of digital platforms, when a User accesses or uses the Platform, NSD may automatically receive and collect certain technical and usage-related information. Such information may include the Internet Protocol (IP) address of the User’s device, device identifiers, browser type, operating system, approximate or precise location data (subject to the permissions granted by the User), usage logs, access times, interaction patterns, and other diagnostic data. NSD may also use cookies and similar tracking technologies for the purposes of technical administration of the Platform, analysis of usage trends, enhancement of user experience and improvement of Services. This information is generally used in aggregated or anonymized form and is not ordinarily used to personally identify individual Users.
4.3 Information Collected from Service Providers
As part of the onboarding, empanelment and continued engagement of Service Providers on the Platform, NSD may collect certain information from nurses, caregivers, attendants and other healthcare professionals. Such information may include professional qualifications, registrations, licenses and certifications; work experience, background verification details and identity information; and performance-related data including service history, ratings, feedback and compliance metrics. This information is collected for the purposes of verification, quality assurance, regulatory compliance, service delivery and improvement of the Platform’s offerings.
5. Sensitive Personal Data or Information
The information collected by NSD from Users may, in certain circumstances, constitute Sensitive Personal Data or Information as defined under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Such Sensitive Personal Data or Information may include, without limitation, medical records and treatment history; information relating to the physical, physiological or mental health condition of a patient; biometric or identification data where required for verification or compliance purposes; financial information including bank account details, credit or debit card details or other payment instruments; and any information received by NSD under a lawful contract or otherwise in connection with the provision of Services.
NSD collects such Sensitive Personal Data or Information only with the explicit consent of the User or the User’s authorized representative and solely for the purposes necessary to provide the Services, comply with applicable laws, and perform its contractual and operational obligations. Such data is accessed, used, processed, stored and disclosed strictly in accordance with this Privacy Policy and applicable law, and is subject to enhanced security and confidentiality measures commensurate with the sensitive nature of the information.
6. Purpose of Collection and Use
NSD collects, receives, uses, processes and stores User information, including Personal Information and Sensitive Personal Data or Information, for purposes that are necessary, lawful and directly connected with the provision of Services through the Platform. Such information may be used for identifying Users; enabling access to and use of the Platform; and facilitating the provision of nursing, caregiving and attendant services at the User’s doorstep.
NSD may use User information to match Users with appropriate Service Providers based on the nature of the care required, to schedule, coordinate and manage service appointments, and to ensure effective fulfilment of Services. Information may also be used to communicate with Users through calls, messages, emails or other electronic means for the purposes of service confirmations, updates, alerts, reminders, feedback collection and resolution of service-related queries or issues.
User information may further be used for processing payments, issuing invoices, facilitating refunds where applicable, and coordinating with third-party payment gateways, banks or financial institutions in connection with financial transactions. NSD may also use such information for internal operations including quality control, audits, performance monitoring of Service Providers, internal training, compliance verification and improvement of service standards.
NSD reserves the right to use User information to comply with applicable legal and regulatory obligations, respond to lawful requests from governmental or judicial authorities, maintain records as required under law, and protect its legal rights or the rights of Users, Service Providers and third parties. User information may also be used for analytics, research, statistical analysis and business intelligence purposes in an aggregated or anonymized form that does not identify individual Users, for the purpose of improving the Platform, developing new features and enhancing service delivery.
Healthcare Data Disclaimer and Limited Role of NSD
A Platform Facilitation Role
NSD – Nursing Services at Doorstep operates as a technology-enabled facilitation platform that enables Users to connect with independent nurses, caregivers, attendants and allied healthcare professionals (“Service Providers”) for the provision of healthcare and caregiving services at the User’s location. NSD does not itself provide medical, nursing or clinical services and does not practice medicine or healthcare in any manner.
B Independent Professional Judgment
All medical, nursing, caregiving and clinical decisions, including but not limited to diagnosis, treatment, care plans, procedures, medication administration and monitoring of patient condition, are made solely and independently by the Service Providers based on their professional judgment, qualifications, experience and applicable standards of care. NSD does not influence, supervise or control the clinical decision-making of Service Providers.
C Use of Healthcare Data
Any medical records, health information, clinical notes or other healthcare-related data collected through the Platform are processed by NSD solely for the limited purposes of facilitating service requests, enabling coordination between Users and Service Providers, ensuring continuity of care, maintaining records as required under applicable law, and improving the operational effectiveness of the Platform. NSD does not use such healthcare data to provide medical advice or make clinical determinations.
D Limitation of Responsibility for Clinical Outcomes
NSD shall not be responsible or liable for:
- the accuracy, completeness or appropriateness of any medical advice, diagnosis or treatment provided by Service Providers;
- any act, omission, negligence or misconduct of Service Providers in the course of rendering services;
- any injury, harm, deterioration of health, adverse event or clinical outcome suffered by a User arising from services provided by Service Providers.
Users acknowledge and agree that engagement of Service Providers through the Platform is undertaken at their own discretion and risk, subject to applicable law.
E No Substitution for Medical Consultation
Information exchanged through the Platform, including health-related data, communications or service descriptions, is not intended to substitute professional medical consultation, diagnosis or treatment by a qualified healthcare professional. Users are advised to seek immediate medical attention from appropriate healthcare facilities in case of medical emergencies.
F Consumer Protection and Legal Compliance
Nothing in this Clause shall be construed as excluding liability to the extent such exclusion is prohibited under applicable law. This Clause is intended to clarify the limited facilitative role of NSD and allocate responsibility appropriately between Users and Service Providers in accordance with applicable healthcare, consumer protection and information technology laws.
7. Disclosure and Sharing of Information
NSD may disclose, share or transfer User information, including Personal Information and Sensitive Personal Data or Information, strictly on a need-to-know basis and only to the extent necessary for the purposes set out in this Privacy Policy. Such disclosure may be made to Service Providers empaneled on the Platform solely for the purpose of enabling the provision of nursing, caregiving and attendant services requested by the User, and for no other purpose.
NSD may also disclose User information to third-party service providers, vendors and contractors who work on behalf of or in association with NSD to facilitate the operation of the Platform and the delivery of Services. This includes, without limitation, payment gateways, banks and financial institutions for the purpose of processing payments and refunds; technology service providers for hosting, data storage, analytics, customer support and communication services; and professional advisors such as auditors or legal consultants. Such third parties shall have access only to such information as is reasonably necessary to perform their functions and are contractually obligated to maintain confidentiality and implement reasonable security practices.
NSD reserves the right to disclose User information where such disclosure is required to comply with applicable laws, rules, regulations, legal processes, court orders or lawful requests from governmental, regulatory or law enforcement authorities, or where NSD, in its sole discretion, considers such disclosure necessary to protect its rights or the rights of Users, Service Providers or the public, to prevent fraud, address security or technical issues, or enforce the Terms of Use and other agreements.
In the event of any merger, acquisition, reorganization, restructuring, sale of assets or transfer of business, NSD may disclose or transfer User information to the relevant third party, subject to such third party agreeing to handle such information in a manner consistent with this Privacy Policy and applicable law.
NSD does not sell, rent, trade or otherwise commercially exploit the personal or health-related data of Users. Any use of User information for analytics, research or business intelligence purposes shall be undertaken only in an aggregated or anonymized form that does not identify individual Users.
8. Cookies and Tracking Technologies
The Platform uses cookies and similar tracking technologies to collect and store certain information that does not, by itself, constitute Sensitive Personal Data or Information. Cookies are small data files placed on a User’s device and are used by NSD and its authorized service providers for the technical administration of the Platform, enabling core functionality, facilitating user authentication, enhancing security, and improving overall performance and user experience.
In the course of providing and optimizing the Services, NSD may use cookies to analyses usage patterns, track navigation behavior, understand preferences of Users and improve the design, functionality and effectiveness of the Platform. NSD may also permit authorized third-party service providers, such as analytics or technology partners, to place or recognize cookies on a User’s device for the limited purposes of supporting Platform operations, performance monitoring and service improvement. Such cookies do not ordinarily store Personal Information or Sensitive Personal Data or Information.
The Platform uses cookies and similar tracking technologies to collect and store certain technical and usage-related information for purposes including platform functionality, security, performance optimization and improvement of user experience. Cookies do not, by themselves, ordinarily contain Personal Information or Sensitive Personal Data or Information.
Users may manage, restrict or disable cookies through the privacy or security settings of their internet browser, mobile device or application, and, where made available, through cookie preference controls on the Platform. Users acknowledge that disabling or restricting cookies may limit access to certain features or functionalities of the Platform and may affect the quality of Services.
Where required under applicable law, User consent for the use of cookies and similar tracking technologies shall be obtained through clear affirmative action, including through a cookie banner, pop-up, or preference management tool, and shall be capable of being withdrawn by the User at any time using the same or equivalent means.
Continued access to or use of the Platform after providing such affirmative consent shall be deemed to constitute acceptance of the use of cookies in accordance with this Privacy Policy.
9. Data Retention
NSD retains Personal Information and Sensitive Personal Data or Information of Users only for such period as is necessary to fulfil the purposes for which the information was collected, including the provision of Services through the Platform, or as required to comply with applicable laws, rules or regulations. NSD may also retain such information for legitimate business purposes, including audits, internal reviews, dispute resolution, enforcement of legal rights, and compliance with contractual or regulatory obligations.
Where retention of Personal Information or Sensitive Personal Data or Information is no longer required for the purposes stated above, NSD shall take reasonable steps to securely delete, destroy or anonymize such information in accordance with its internal data retention policies and applicable law. In certain circumstances, data may be anonymized and aggregated and retained for analytical, research, statistical or business intelligence purposes, in which case such data shall no longer be capable of identifying individual Users.
Users acknowledge that withdrawal of consent or deletion of data may result in NSD being unable to provide certain Services or to continue any existing service relationship. Notwithstanding the foregoing, NSD may retain such information as is necessary to comply with legal obligations, resolve disputes, or enforce its agreements, even after deletion or deactivation of a User account.
9A. Data Storage and Cross-Border Transfer
9A.1 Location of Data Storage
Personal Information and Sensitive Personal Data or Information collected through the Platform may be stored and processed on servers located within India or in other jurisdictions, as may be necessary for the provision of Services, operational efficiency or technical requirements, subject at all times to the Digital Personal Data Protection Act, 2023 and other applicable Indian laws, rules and governmental notifications.
9A.2 Compliance with Applicable Transfer Restrictions
Where personal data is stored or processed outside India, NSD shall ensure that such storage or transfer:
- is permitted under applicable law;
- is carried out in accordance with prescribed safeguards, if any;
- does not violate any restrictions or conditions notified by the Government of India or the Data Protection Board of India from time to time.
9A.3 Security and Confidentiality Safeguards
NSD shall take reasonable steps to ensure that personal data stored or processed outside India is subject to standards of data protection, confidentiality and security that are at least equivalent to those required under applicable Indian law.
9A.4 User Acknowledgement
By using the Platform and providing personal data, Users acknowledge and consent to the storage and processing of their personal data in India or such other jurisdictions as may be permitted under applicable law, in accordance with this Privacy Policy.
10. A. Rights of Data Principals under the DPDP Act, 2023
10.1 Status of Data Principal
In accordance with the provisions of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), every User whose personal data is collected, stored, processed or otherwise handled by NSD through the Platform shall be regarded as a “Data Principal”, and Trisha Helping Hands LLP shall act as the “Data Fiduciary” in respect of such personal data.
10.2 Right to Confirmation and Access
A Data Principal shall have the right to obtain from NSD confirmation as to whether their personal data is being processed and, where such processing is taking place, access to such personal data and information relating to:
- the categories of personal data being processed;
- the purposes for which such personal data is being processed;
- the identities or categories of recipients with whom such personal data has been shared; and
- any other information as may be prescribed under applicable law.
10.3 Right to Correction, Completion and Erasure
A Data Principal shall have the right to:
- request correction of inaccurate or misleading personal data;
- request completion of incomplete personal data; and
- request erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to NSD’s legal, regulatory, contractual and record-retention obligations under applicable law.
NSD shall take reasonable steps to give effect to such requests within the timelines prescribed under the DPDP Act, after due verification of the identity of the Data Principal.
10.4 Right to Withdraw Consent
A Data Principal shall have the right to withdraw their consent for the processing of their personal data at any time.
Consent may be withdrawn:
- through the account or privacy settings available on the Platform; or
- by submitting a written request via email to the Grievance Officer or designated data protection contact.
Withdrawal of consent shall be as easy as the manner in which consent was originally provided. The Data Principal acknowledges that withdrawal of consent may result in NSD being unable to provide certain or all Services and may require suspension or termination of the User’s account or ongoing services.
10.5 Right to Nominate
A Data Principal shall have the right to nominate another individual, who shall, in the event of the death or incapacity of the Data Principal, exercise the rights of the Data Principal under the DPDP Act on their behalf.
The manner and procedure for making such nomination shall be as prescribed under applicable law or communicated by NSD through the Platform from time to time.
10.6 Right to Grievance Redressal
A Data Principal shall have the right to register grievances or complaints with NSD in relation to:
- the processing of their personal data;
- any breach of obligations by NSD under the DPDP Act; or
- denial or delay in exercising their rights under this Privacy Policy or applicable law.
NSD shall endeavor to resolve such grievances within the timelines prescribed under the DPDP Act and applicable rules.
10.7 Right to File Complaint with the Data Protection Board of India
Where a Data Principal does not receive a satisfactory response from NSD in respect of any grievance, or where such grievance remains unresolved within the prescribed time, the Data Principal shall have the right to file a complaint with the Data Protection Board of India, in accordance with the provisions of the DPDP Act and rules made thereunder.
10.8 Right to Be Informed of Personal Data Breach
In the event of a personal data breach that is likely to cause harm to a Data Principal, NSD shall, in accordance with applicable law:
- notify the Data Protection Board of India; and
- inform the affected Data Principal(s) of such breach, including the nature of the breach, potential consequences, and remedial measures undertaken or proposed.
10.9 Exercise of Rights
All requests for exercise of rights under this Clause may be submitted by the Data Principal using the contact details provided under the “Grievance Redressal and Contact Details” section of this Privacy Policy. NSD may require verification of identity prior to acting on any such request.
B. Rights and Data Processing of Service Providers
10B.1 Status of Service Providers
For the purposes of this Privacy Policy, nurses, caregivers, attendants and allied healthcare professionals empaneled or engaged through the Platform (“Service Providers”) are independent professionals and not employees of NSD, unless expressly stated otherwise in a separate written agreement. This Clause governs the collection and processing of personal data of Service Providers in their capacity as independent service providers.
10B.2 Categories of Data Collected from Service Providers
NSD may collect and process personal data of Service Providers including, without limitation:
- identity and contact information;
- professional qualifications, licenses, registrations and certifications;
- background verification details;
- service history, availability and engagement records;
- ratings, reviews, feedback and performance metrics; and
- compliance, audit and quality-control related information.
Such data is collected for verification, onboarding, service facilitation, quality assurance, regulatory compliance and platform integrity purposes.
10B.3 Rights of Service Providers
Subject to applicable law, Service Providers shall have the right to:
- access and review their personal data maintained by NSD;
- request correction or updating of inaccurate or outdated information;
- raise objections or submit explanations in respect of disputed data, including ratings or feedback, where permitted by Platform policies;
- withdraw consent for processing of personal data, subject to legal and contractual obligations.
NSD shall act on such requests within reasonable timelines and in accordance with applicable data protection laws.
10B.4 Retention of Service Provider Data Post De-boarding
Upon suspension, de-boarding or cessation of engagement of a Service Provider, NSD may retain personal data of such Service Provider for such period as may be necessary:
- to comply with applicable laws, regulatory requirements or professional standards;
- to resolve disputes, complaints or legal proceedings;
- to maintain audit trails, quality control records and fraud prevention mechanisms; and
- to enforce contractual rights and obligations.
Thereafter, such data shall be securely deleted, anonymized or archived in accordance with NSD’s data retention policies and applicable law.
10B.5 Use of Ratings, Reviews and Feedback
Ratings, reviews, feedback and performance-related data relating to Service Providers:
- may be generated by Users or through internal quality assessment mechanisms;
- may be used by NSD for service quality monitoring, training, performance evaluation, dispute resolution and platform integrity;
- may be displayed in aggregated or summarized form on the Platform for user decision-making, subject to Platform policies.
NSD shall not manipulate, falsify or misuse such data and shall take reasonable steps to ensure fairness, relevance and proportionality in its use. Service Providers acknowledge that ratings and feedback are subjective in nature and may vary based on individual user experience.
10B.6 Limitation of Liability in Relation to Performance Data
NSD shall not be liable for any loss, reputational harm or adverse consequences alleged by a Service Provider arising solely from:
- bona fide user feedback;
- algorithmic or objective performance metrics;
- lawful internal assessments carried out for platform integrity and service improvement purposes.
Nothing in this Clause shall prevent Service Providers from exercising rights available under applicable law in cases of demonstrable data inaccuracy or unlawful processing.
11. User Rights
Subject to applicable law, Users are entitled to access, review and, where appropriate, seek correction or updating of their Personal Information and Sensitive Personal Data or Information maintained by NSD. Users may review and update certain information through the account settings available on the Platform or by contacting NSD using the contact details provided in this Privacy Policy. NSD shall make reasonable efforts to ensure that such information is accurate and up to date, and to give effect to requests for correction or updation within a reasonable time, subject to verification and applicable legal requirements.
Users may withdraw their consent to the collection, use or processing of their Personal Information or Sensitive Personal Data or Information at any time by providing written notice to NSD. Users acknowledge and agree that withdrawal of consent may result in NSD being unable to provide certain or all Services, and may require suspension or termination of any existing service relationship. Notwithstanding such withdrawal, NSD may retain and continue to process such information to the extent required under applicable law, for dispute resolution, audits, enforcement of legal rights, or compliance with statutory or regulatory obligations.
Users may also request deletion or erasure of their Personal Information and Sensitive Personal Data or Information, subject to applicable law and NSD’s data retention obligations. NSD shall assess such requests in accordance with legal requirements and may decline or partially comply with a request where retention of information is required by law, where the information forms part of records related to an ongoing or completed legal proceeding, or where deletion would adversely affect NSD’s ability to comply with its legal or contractual obligations. All requests relating to access, correction, withdrawal of consent or deletion of data may be submitted using the contact details provided in this Privacy Policy, and NSD shall endeavor to respond to such requests within the timelines prescribed under applicable law.
A. Data Breach and Incident Response
11A.1 Definition of Personal Data Breach
For the purposes of this Privacy Policy, a “Personal Data Breach” shall mean any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Information or Sensitive Personal Data or Information that compromises the confidentiality, integrity or availability of such data.
11A.2 Incident Detection and Assessment
NSD shall maintain reasonable technical and organizational measures to detect, investigate and assess suspected or actual Personal Data Breaches. Upon becoming aware of a breach, NSD shall take prompt steps to contain the incident, assess its scope and severity, and determine the potential impact on affected Data Principals.
11A.3 Notification to Authorities
Where a Personal Data Breach is required to be reported under applicable law, NSD shall notify the Data Protection Board of India and any other relevant regulatory or governmental authority, in such form and within such timelines as may be prescribed under the Digital Personal Data Protection Act, 2023 and rules made thereunder.
11A.4 Notification to Affected Users
Where a Personal Data Breach is likely to cause harm to a Data Principal, NSD shall, in accordance with applicable law, notify the affected User(s) without undue delay. Such notification shall, to the extent reasonably practicable, include:
- the nature of the Personal Data Breach;
- the categories of personal data affected;
- the likely consequences or risks arising from the breach; and
- the remedial measures taken or proposed to mitigate the impact of the breach, including steps that Users may take to protect themselves.
11A.5 Remedial and Preventive Measures
NSD shall take reasonable and appropriate remedial actions to mitigate the effects of a Personal Data Breach, including technical fixes, system upgrades, process improvements, and employee or Service Provider training, as may be necessary to prevent recurrence of similar incidents.
11A.6 Record-Keeping and Cooperation
NSD shall maintain records of Personal Data Breaches in accordance with applicable law and shall cooperate with regulatory authorities, law enforcement agencies and affected Users, as required, in connection with investigation, mitigation and resolution of such breaches.
11A.7 Limitation of Liability
Nothing in this Clause shall be construed as an admission of fault or liability on the part of NSD. NSD’s obligations under this Clause shall be subject to applicable law and shall not extend to breaches resulting from factors beyond its reasonable control, including force majeure events or security failures attributable to third-party systems or User devices.
12. Confidentiality and Security
NSD maintains appropriate administrative, technical, operational and physical security measures to protect the Personal Information and Sensitive Personal Data or Information under its control from unauthorized access, improper use or disclosure, unauthorized modification, and unlawful destruction or accidental loss. Such measures are commensurate with the nature of the information collected and the risks associated with the provision of nursing, caregiving and allied healthcare services through the Platform.
Access to User information is restricted on a role-based basis and limited only to authorized employees, agents and Service Providers who require such access for the purposes of performing their duties in connection with the Services. NSD implements reasonable security practices including, without limitation, encryption of sensitive data, use of secure servers, firewalls, intrusion detection systems, access monitoring and periodic security reviews. All employees, contractors and Service Providers who have access to Personal Information or Sensitive Personal Data or Information are bound by confidentiality obligations and are required to adhere to NSD’s information security policies and procedures.
No administrator or employee of NSD shall have access to User passwords in plain text. Users are responsible for maintaining the confidentiality of their account credentials and for preventing unauthorized access to their accounts and devices. NSD shall not be responsible for any unauthorized use of a User’s account resulting from failure to safeguard login credentials or devices, and Users agree to promptly notify NSD of any suspected unauthorized access or security breach.
Notwithstanding the foregoing, Users acknowledge that no method of transmission over the internet or method of electronic storage is completely secure. While NSD adopts industry-standard safeguards and reasonable security practices, NSD does not guarantee absolute security of information and shall not be held liable for any loss or unauthorized access arising from events beyond its reasonable control, including but not limited to cyber-attacks, hacking incidents, system failures, acts of government, or deficiencies in the User’s internet service or devices.
13. Third-Party Links
The Platform may contain links to third-party websites, applications or services that are not owned, operated or controlled by NSD. Such links are provided solely for the convenience of Users, and the inclusion of any link does not imply any endorsement by NSD of the content, policies or practices of such third parties.
NSD does not exercise control over, and shall not be responsible or liable for, the privacy practices, terms of use, content, accuracy, integrity or security of any third-party websites or services accessed through such links. Any Personal Information or other data that a User provides to such third-party websites or services shall be governed by the privacy policies and terms of such third parties, and NSD shall have no responsibility or liability in respect thereof.
Users acknowledge and agree that access to and use of third-party websites or services is undertaken entirely at their own risk. NSD encourages Users to review the privacy policies and terms of use of such third-party websites or services prior to providing any information or engaging with them.
14. Children and Dependant Care
NSD strongly encourages parents, legal guardians and authorized representatives to supervise the use of the Platform and Services by minors and dependents. The Services provided through the Platform are not intended to be accessed or used independently by minors. Services for minors or dependents may be booked only by parents, legal guardians or duly authorized representatives who are competent to provide consent and information on their behalf.
NSD does not knowingly collect Personal Information or Sensitive Personal Data or Information directly from minors without the consent of a parent, guardian or authorized representative. Where information relating to a minor or dependent is provided through the Platform, such information is deemed to have been provided with the valid consent of the parent, guardian or authorized representative, who assumes responsibility for the accuracy and legality of such information.
If NSD becomes aware that Personal Information or Sensitive Personal Data or Information of a minor has been collected without appropriate consent, NSD shall take reasonable steps to delete or restrict processing of such information in accordance with applicable law. Parents, guardians or authorized representatives may contact NSD using the contact details provided in this Privacy Policy to review, update or request deletion of information relating to a minor or dependent.
15. Changes to this Privacy Policy
NSD reserves the right to update, modify, amend or revise this Privacy Policy at any time, with or without prior notice, to reflect changes in legal, regulatory, operational or business requirements, or changes in the manner in which NSD collects, uses or processes information. Any such changes shall be effective immediately upon being posted on the Platform, unless otherwise stated.
In the event of material changes to this Privacy Policy that affect the manner in which Personal Information or Sensitive Personal Data or Information is collected, used or disclosed, NSD may, at its discretion, provide additional notice to Users through the Platform or by electronic communication. Users are encouraged to periodically review this Privacy Policy to stay informed of any updates.
Continued access to or use of the Platform or Services after any changes to this Privacy Policy shall be deemed to constitute acceptance of the revised Privacy Policy. If a User does not agree with the modified terms of this Privacy Policy, the User must discontinue use of the Platform and Services and may request deactivation of their account in accordance with applicable law.
16. Grievance Redressal and Contact Details
In accordance with the provisions of the Information Technology Act, 2000 and the rules made thereunder, NSD has appointed a Grievance Officer to address any grievances, complaints or concerns relating to the collection, use, processing, storage or disclosure of Personal Information and Sensitive Personal Data or Information under this Privacy Policy.
Users may contact the Grievance Officer with any questions, concerns, complaints or requests relating to privacy, data protection or information security, including requests for access, correction, withdrawal of consent or deletion of data. NSD shall make reasonable efforts to acknowledge and resolve such grievances in a timely manner and within the timelines prescribed under applicable law.
The contact details of the Grievance Officer are as follows:
- Name: [To be appointed]
- Designation: Grievance Officer / Data Protection Officer
- Entity: Trisha Helping Hands LLP
- Email: [privacy@nsd.in]
- Address: [Registered Office Address]
Users are requested to provide sufficient details to enable effective resolution of their grievance. NSD shall not be responsible for delays caused due to incomplete or inaccurate information provided by the User.
17. Consent to this Privacy Policy
You acknowledge and agree that this Privacy Policy forms an integral part of the Terms of Use of the Platform and governs your access to and use of the Platform and Services. By accessing, browsing, registering on or using the Platform or Services, or by otherwise providing your information to NSD, you expressly signify your consent to the collection, use, processing, storage, retention and disclosure of your Personal Information and Sensitive Personal Data or Information in the manner and for the purposes set out in this Privacy Policy.
Your continued use of the Platform or Services shall constitute your ongoing acceptance of this Privacy Policy and any amendments made thereto from time to time. Your access to and use of the Platform and Services is subject to this Privacy Policy and the Terms of Use. If you do not agree with this Privacy Policy or any part thereof, you must immediately discontinue use of the Platform and Services and refrain from providing any information to NSD.
Last Updated: 31/01/2026