Our approach
nnhans is a healthcare operations platform used by authorized organizations to manage operational workflows. We limit personal information to the purposes described below and design the service around tenant access controls and traceable activity.
Pre-commercial review status
This notice is a pre-commercial draft pending Indian privacy counsel review and confirmation of operating-entity, contact, vendor, region, retention, children, and outbound-channel facts. It is useful for product testing but is not evidence that every described process is operational or that nnhans is certified or fully compliant.
Applicable framework and scope
The Digital Personal Data Protection Act, 2023 and its Rules commence in phases, so counsel must maintain the dated applicability map. The Information Technology Act section 43A, the SPDI Rules, and CERT-In obligations may apply alongside those phased duties. This notice covers visitors, data principals, authorized users, tenants, and connected lead forms; an executed services agreement will govern conflicting customer commercial terms once one exists.
Information we process
nnhans processes account, tenant, patient, referral, appointment, outreach, audit, and support information that authorized organizations and users provide through the service.
When you submit a Meta Instant Form associated with nnhans, we may receive the information you choose to provide, such as your name, email address, and phone number. We may also receive related submission details, including the Facebook Page, form, campaign, ad, and submission time identifiers that Meta makes available.
We also process limited technical and security information needed to authenticate users, protect accounts, diagnose errors, maintain audit records, and remember essential service preferences.
Who is responsible for your data
For patient, referral, appointment, clinical, outreach, and tenant records entered into the service, the hospital, clinic, doctor, or other subscribing organization may determine why and how the information is used, with nnhans processing on documented instructions. The exact fiduciary/processor role depends on each purpose and contract and remains subject to counsel review.
When information is submitted directly to nnhans through a connected Meta Instant Form before being routed to an organization, nnhans may have a separate purpose-specific role. Counsel must confirm that role and the ground before commercial use.
How we use information
We use information only to provide, secure, operate, improve, and administer the service; route inquiries to the appropriate authorized organization; coordinate requested follow-up; support patient, referral, appointment, and outreach workflows; prevent misuse; and comply with applicable legal obligations.
Organizations using nnhans
Hospitals, clinics, and other organizations using nnhans remain responsible for ensuring that personal information is collected and entered with all required notices, permissions, consents, and lawful authority under applicable privacy, healthcare, professional, and confidentiality obligations. If an organization collected your information, that organization is normally the first point of contact for questions about its records or follow-up.
How information is shared
nnhans does not sell personal information. We may disclose information only to authorized users of the relevant organization, contracted service providers that help operate or secure the service, infrastructure and security providers, professional advisers, or government and judicial authorities where legally required. Service providers are permitted to process information only for the services they supply to us.
Retention and deletion
Information is retained only for as long as reasonably necessary to provide the service, support the authorized organization's operational and record-keeping needs, maintain security and audit records, resolve disputes, and meet legal obligations. Retention may vary according to the organization's instructions and the type of record involved. The retention, deletion, anonymization, backup, and legal-hold schedule is still pending approval and operational testing.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, or loss. No online service can guarantee absolute security or uninterrupted availability, so organizations using nnhans must also maintain appropriate access controls, account reviews, backups, and continuity procedures.
Your rights and grievance redressal
You may ask the organization that collected your information to access, correct, restrict, or delete it, subject to applicable law and record-retention requirements. Authorized nnhans account users should contact their tenant administrator for account and organization records.
If your request concerns information submitted through a Meta Instant Form, identify the nnhans Facebook Page and the approximate submission date so the receiving organization can locate the inquiry.
If no organization has received the submission, or the request concerns nnhans's own handling of information, contact the nnhans pre-commercial privacy request route at privacy@nnhans.com. Please describe the request and provide enough information for us to locate the relevant record. The company must assign and verify the statutory grievance role, public entity details, and response workflow before launch. You may use this route to ask about access, correction, restriction, or erasure rights in the meantime.
International processing and safeguards
Enabled vendors, processing regions, remote support access, and transfer safeguards have not yet been fully reconciled. They must be verified against the hosted environment and approved contracts before commercial launch; no transfer assurance is made by this draft.
Personal data breaches
A draft incident plan covers containment, evidence preservation, customer coordination, and CERT-In/DPDP decision paths. It must be approved, staffed, and exercised before launch. Actual notifications and timing will follow counsel's incident-specific legal and contractual assessment.
Data processing agreements
A data processing agreement template is being prepared to cover documented instructions, confidentiality, service providers and subprocessors, security measures, incident notification, deletion or return, and audit rights. Counsel approval and customer execution are required before the template can be treated as an effective agreement.
Changes to this policy
We may update this policy when the service or applicable requirements change. The date at the top of this page identifies the latest version. Material changes should be reviewed by organizations using nnhans before they continue collecting new information through the service.