Privacy Policy

Last updated: January 2024 · Compliant with India DPDP Act 2023

FertilityConnect collects sensitive health information. We are committed to protecting your data with the highest standards of security and transparency. This policy explains exactly what we collect, why, and your rights under India's Digital Personal Data Protection (DPDP) Act 2023.

1. Data We Collect

When you use FertilityConnect, we collect:

Assessment Data: Health information you provide in our fertility assessment, including age, medical diagnoses, menstrual history, semen analysis results, BMI, lifestyle factors, and treatment history. This is classified as Sensitive Personal Data under India's DPDP Act 2023.

Contact Data: Your name, email address, and phone number, collected when you submit an assessment or make a booking.

Usage Data: Pages visited, time on site, referral source, and device information, collected via cookies and analytics tools.

Booking Data: Appointment preferences, clinic selections, and communication records.

2. How We Use Your Data

We use your data to:

· Generate your personalised fertility assessment and clinic matches · Connect you with fertility clinics whose services match your profile · Create a record in our CRM system (Zoho Bigin) to manage your clinic journey · Send you your assessment report and booking confirmations by email · Improve our matching algorithm and platform (in anonymised, aggregated form) · Send educational content if you opted in to marketing communications

3. Data Sharing

We share your data with:

Fertility Clinics: When you book a consultation, we share your name, contact details, recommended treatment, and relevant assessment summary with the selected clinic only.

CRM Provider (Zoho Bigin): To manage clinic bookings and patient journeys. Zoho is ISO 27001 certified.

Email Provider (Resend): To send confirmation and report emails.

Database Provider (Supabase): Your data is stored on Supabase, which is SOC 2 Type II certified and hosted on AWS in the Asia Pacific region.

We do NOT sell your personal data to third parties, advertisers, or data brokers.

4. Your Rights (DPDP Act 2023)

Under India's Digital Personal Data Protection Act 2023, you have the right to:

· Access: Request a copy of all personal data we hold about you · Correction: Request correction of inaccurate personal data · Erasure: Request deletion of your personal data from our systems · Grievance Redressal: Contact our Data Protection Officer for any data-related complaints · Nominate: Nominate a person to exercise your rights in case of incapacity

To exercise any right, email: privacy@fertilityconnect.in

5. Health Data (Sensitive Personal Data)

Your health information is classified as Sensitive Personal Data and receives heightened protection:

· Encrypted at rest (AES-256) and in transit (TLS 1.3) · Access restricted to authorised staff only, on a need-to-know basis · Not used for advertising targeting or profiling purposes · Retained for 3 years from your last interaction, unless you request earlier deletion · Consent is obtained explicitly before collection (assessment consent checkbox)

6. Cookies

We use cookies for:

· Essential cookies: Session management and security (cannot be disabled) · Analytics cookies: Google Analytics to understand platform usage (can be disabled) · Preference cookies: Remembering your filter settings

You can manage cookie preferences in your browser settings or via our Cookie Preferences link in the footer.

7. Data Retention

· Assessment data: 3 years from submission date · Booking records: 5 years (for clinic audit and regulatory compliance) · Email correspondence: 2 years · Analytics data: 26 months (Google Analytics default)

You may request earlier deletion at any time.

8. Contact & Data Protection Officer

Data Protection Officer: FertilityConnect India Email: privacy@fertilityconnect.in Phone: +91 80000 00000

Grievance Officer (as required by DPDP Act 2023): Name: [Grievance Officer Name] Email: grievance@fertilityconnect.in Response time: Within 72 hours