Pluro – Best IVF & Fertility Clinic Across India
TREATMENTS
OUR DOCTORS
IVF CENTRES
ACADEMYBLOGSABOUT USCONTACT USFAQ
24x7 Doctor-Supervised Medical HelplineBook Appointment
Pluro – Best IVF & Fertility Clinic Across India
TREATMENTS
OUR DOCTORS
IVF CENTRES
ACADEMYBLOGSABOUT USCONTACT USFAQ
Book Now
Pluro – Best IVF & Fertility Clinic Across India
Book Appointment
  • TREATMENTS
  • OUR DOCTORS
  • IVF CENTRES
  • ACADEMY
  • BLOGS
  • ABOUT US
  • CONTACT US
  • FAQ
Medical HelplineBook Appointment
Follow us

Subscribe to our newsletter

The smartest list on fertility and health. Bi-weekly & worth opening. Join 50,000+ women. No spam (we hate it too).

Pluro – Best IVF & Fertility Clinic Across India

Personalised fertility care from a compassionate, outcomes-focused team. Advanced technology, transparent pricing, and end-to-end support for your parenthood journey.

About

  • Our Story
  • Treatments
  • Our Doctors
  • Find Clinics
  • Academy
  • Contact Us

Reach Out To Us!

Office No. 101-107, 1st Floor, One 45 Business Bay, Vallabh Baug Ln Ext, Railway Police Colony, Ghatkopar East, Mumbai, Maharashtra - 400 075
+917666727272
contact@pluro.in

© 2026 Pluro Fertility and IVF

Privacy PolicyTerms of ServiceRefunds & CancellationsSitemap
Pluro – Best IVF & Fertility Clinic Across India

Personalised fertility care from a compassionate, outcomes-focused team. Advanced technology, transparent pricing, and end-to-end support for your parenthood journey.

Our StoryTreatmentsOur DoctorsFind ClinicsAcademyContact Us

© 2026 Pluro Fertility and IVF

Privacy PolicyTerms of ServiceRefunds & CancellationsSitemap

    Privacy Policy

    We take the privacy and security of your personal and health information seriously. Read our policy to understand how we collect, use and safeguard your data.

    Contact Us
    Digital lock icon representing data privacy and security at Pluro
    Digital lock icon representing data privacy and security at Pluro

    Privacy Policy

    We take the privacy and security of your personal and health information seriously. Read our policy to understand how we collect, use and safeguard your data.

    Contact Us

    This Privacy Policy explains how Esperanza Medical Platform Private Limited (“Pluro”, “we”, “our”, “us”) collects, uses, stores, shares and protects your personal information when you visit our websites, use our applications, book appointments, undergo treatment at our centres, or interact with us via digital and offline channels in India.

    Who we are & scope

    • Entity: Esperanza Medical Platform Private Limited (CIN: U86201MH2025PTC446765), registered office at Units 101, 102, 103, 104, 105 & 107 (1st Floor), One45 Business Bay, Vallabh Baug Extension Lane, Railway Police Colony, Pant Nagar, Ghatkopar East, Mumbai – 400075, operating fertility clinics and digital properties under the Pluro brand in India.
    • Our role: For personal data where we determine the purpose and means of processing, we are a Data Fiduciary under the DPDP Act and a body corporate under Section 43A of the IT Act.
    • Scope: This policy governs our websites, mobile and telemedicine platforms, electronic health-record systems, clinic services, partner networks and customer-support channels.
    • Languages: This policy is provided in English; on request we will make available a copy in any language listed in the Eighth Schedule to the Constitution of India.

    What data we collect

    • Identity & contact information: name, age or date of birth, gender, address, phone number, email.
    • Medical & reproductive health data: health history, fertility investigations, lab results, imaging, prescriptions, vitals, ART/IVF case files, gamete and embryology notes (where applicable), genetic testing (if applicable), and treating-clinician details.
    • Appointment & billing: booking details, payment-method tokens (processed via RBI-regulated gateways), invoices and GST details where applicable.
    • Device & usage information: cookies, IP address, pages viewed, approximate location, device identifiers (for security, analytics and fraud prevention), and location data (where consented).
    • Communication records: messages, forms, call recordings (where permitted by applicable law and with prior disclosure or consent as required, including under the Indian Telegraph Act, 1885), emails and teleconsultation notes.

    An itemised description of the data collected and the purpose of its processing is provided so that you can make an informed choice, as required under DPDP (Section 5, read with Rule 3).

    Purpose of processing

    We may process your personal and health data in accordance with the DPDP Act and Rules as amended from time to time for the following purposes, for which we have either obtained your consent or for certain legitimate uses which include a specified purpose for which you have voluntarily provided your personal data, or a purpose in respect of which you have not indicated to us that you do not consent to the use of your personal data.

    We may also process your personal and health data for the purposes of: (i) complying with any obligation to disclose information to the State or its instrumentalities under applicable law; (ii) complying with any judgment, decree or order issued under applicable law; (iii) responding to a medical emergency involving a threat to the life or immediate health of any individual; (iv) providing medical treatment or health services during an epidemic, disease outbreak or other public health threat; (v) ensuring the safety of, or providing assistance or services to, any individual during a disaster or breakdown of public order; and (vi) purposes relating to employment, including safeguarding the employer against loss or liability, protecting confidentiality of trade secrets, intellectual property or classified information, or providing any service or benefit sought by an employee.

    These purposes include the following:

    • provide fertility care, counselling and ART/IVF services;
    • schedule and manage appointments;
    • maintain clinical records as required by law;
    • run teleconsultations compliantly (identifying patient and Registered Medical Practitioner, documenting consent, issuing e-prescriptions as permitted);
    • process payments, invoices and refunds, prevent fraud, and meet tax and legal obligations;
    • maintain and secure our systems, and carry out analytics to improve our services and patient experience;
    • send service notifications (bookings, reports) and relevant treatment updates;
    • send marketing communications only with your explicit consent, which you may withdraw at any time; and
    • assess and improve service quality, develop new services, and conduct surveys or market analysis for service-improvement purposes.

    Legal basis & consent

    We process personal data on the following bases:

    • Consent (DPDP Section 6) — free, specific, informed, unconditional and unambiguous, given through a clear affirmative action and limited to the data necessary for the stated purpose. Every request for consent shall be presented to you in clear and plain language, giving you the option to access such request in English or any language specified in the Eighth Schedule to the Constitution, and providing the contact details of a Data Protection Officer, where applicable, or of any other person authorised by us to respond to any communication from you for the purpose of exercising your rights under the provisions of the DPDP Act. The consent referred to herein, or any part of it, if it constitutes an infringement of the provisions of the DPDP Act and Rules or any other law for the time being in force, shall be invalid to the extent of such infringement. You may withdraw consent at any time, as easily as it was given, provided that any consequences of such withdrawal shall be borne by you and your withdrawal of consent shall not affect the legality of processing of personal data based on consent before its withdrawal. Upon your withdrawal of consent to the processing of personal data, we shall within a reasonable time cease, and cause our processors to cease, processing your personal data unless such processing without your consent is required or authorised under the provisions of the DPDP Act and Rules or any other law for the time being in force in India.
    • Consent notice — Every request for consent made to you shall be accompanied or preceded by a notice in clear and plain language, presented independently of any other information, setting out: (i) an itemised description of your personal data proposed to be processed; (ii) the specified purpose(s) of such processing and a specific description of the goods or services to be provided or uses to be enabled through such processing; and (iii) the means, including the relevant communication link, through which you may withdraw your consent with ease comparable to that with which consent was given, exercise your rights under applicable data protection law, and make a complaint to the Data Protection Board.
    • Consent manager — You may give, manage, review or withdraw your consent to us through your consent manager. The consent manager so appointed by you shall be accountable to you and shall act on your behalf in such manner and subject to such obligations as may be prescribed under the law. Your consent manager should be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed under the applicable law.
    • Certain legitimate uses (DPDP Section 7) — for example, where you voluntarily provide data for a specified purpose, for compliance with law, and for medical treatment or health services in an emergency or threat to life or public health.

    Where the SPDI Rules apply, consent for sensitive personal data is obtained in writing (including by electronic means). You may give, manage, review and withdraw consent directly with us or through a registered Consent Manager.

    Processing of personal data

    We are responsible for complying with the provisions of the DPDP Act and the rules made thereunder in respect of any processing undertaken by us, or on our behalf by our Data Processors engaged, appointed, used or otherwise involved by us to process personal data for any activity related to offering goods and services to you, only under a valid contract.

    Where the personal data processed by us is likely to be used to make a decision affecting you, or disclosed to another Data Fiduciary, we shall ensure the completeness, accuracy and consistency of such personal data.

    We shall implement appropriate technical and organisational measures to ensure compliance with the DPDP Act and the rules made thereunder, and shall take reasonable security safeguards to prevent personal data breaches, including in respect of processing undertaken by us or on our behalf by our Data Processors. Such safeguards shall include, at minimum and as applicable:

    • appropriate data security measures, including encryption, obfuscation, masking or tokenisation of personal data;
    • appropriate access controls for computer resources used by us or our Data Processors;
    • appropriate logging, monitoring and review of access to personal data to enable detection, investigation and remediation of unauthorised access;
    • reasonable measures, including data backups, to ensure continued processing in the event of compromise of the confidentiality, integrity or availability of personal data;
    • retention of relevant logs and personal data for one year, unless a longer or shorter period is required under applicable law;
    • appropriate contractual provisions requiring our Data Processors, where applicable, to implement reasonable security safeguards; and
    • appropriate technical and organisational measures to ensure effective implementation of such security safeguards.

    No method of internet transmission or electronic storage is completely secure. While we use commercially acceptable means to protect your information, we cannot guarantee absolute security and there is a residual risk of unauthorised access.

    Users under 18, users with disability, and sensitive contexts

    We do not knowingly process the personal data of an individual under eighteen (18) years of age without obtaining verifiable consent of a parent or lawful guardian, as required under applicable data protection law. We shall adopt appropriate technical and organisational measures to obtain such verifiable consent before processing the personal data of a child, and shall exercise due diligence to verify that the individual identifying themselves as the parent has completed eighteen (18) years of age and is identifiable, where required for compliance with applicable law, by reference to: (a) reliable details of the identity and age of such individual available with us; or (b) details of identity and age voluntarily provided by such individual, including through a virtual token mapped to such details and issued by an authorised entity, including where such details or token are made available and verified through a Digital Locker Service Provider. We shall not undertake processing likely to have a detrimental effect on the well-being of a child, and shall not carry out tracking, behavioural monitoring or targeted advertising directed at children.

    Where we process the personal data of a person with disability who has a lawful guardian, we shall obtain verifiable consent of such guardian and exercise due diligence to verify that the guardian has been appointed by a court of law, a designated authority or a local level committee, in accordance with the applicable law relating to guardianship.

    Fertility and ART information is treated with the highest confidentiality. Note: the DPDP Act does not create a separate statutory category of “sensitive personal data”; however, such data qualifies as Sensitive Personal Data or Information (SPDI) under the IT/SPDI Rules while they remain in force, and in all cases we apply heightened safeguards consistent with the ART Act, Surrogacy Act, ICMR guidance and medical-records obligations.

    Health / ART record retention

    Clinical and ART records are retained as mandated by law. Under the ART Act and Rules, ART clinics and banks must preserve records (for example, donor, procedure and outcome data) and, on closure before the mandated period, transfer records to the National Registry. Current guidance indicates preservation for up to 10 years for ART and clinic records (with periodic National Registry updates), or such longer period as prescribed by law or required for ongoing legal proceedings. Where the Surrogacy Act applies to your case, additional record-keeping and retention obligations may apply. Non-clinical website and analytics data is retained for shorter periods consistent with business needs and law.

    In accordance with DPDP (Section 8(7) and Rule 8), we shall erase personal data — and require our processors to erase it — once the purpose is no longer served or consent is withdrawn, whichever is earlier, unless retention is required by law, including the medical-records and ART/Surrogacy obligations above. We maintain logs as required under the Rules. The purpose referred to above shall be deemed to be no longer served if you do not approach us for the performance of the specified purpose for which your personal data was being processed, and you do not exercise any of your rights in relation to such processing, for such time period as may be prescribed.

    Sharing & disclosure

    We may share data with:

    • treating clinicians, labs, radiology partners, healthcare agencies, affiliates and accredited ART banks involved in your care;
    • our agents, contractors and third-party service providers who process information on our behalf, including administrative, professional and support services (for example, legal advisors, accountants, mailing and courier services);
    • technology and cloud providers, appointment and EMR systems, communication tools and security vendors, under contracts with confidentiality and data-protection safeguards;
    • payment gateways and RBI-regulated providers for transactions;
    • regulators and authorities where required by law (for example, National Registry updates); and
    • a third party that acquires, or proposes to acquire, any of our business units or assets (by merger, divestiture, consolidation or purchase), where it is entitled to continue using the information consistent with this policy.

    We require our Data Processors to protect personal data and to process it only on our instructions. Under the SPDI Rules, we will not disclose sensitive personal data to third parties without your prior permission, except under a contract with you or as required by law. We do not sell or rent patient information.

    Cross-border transfer

    We may store or transfer personal data outside India. Under DPDP (Section 16 and Rule 15), such transfers are permitted except to any country or territory that the Central Government restricts by notification (a “negative-list” approach). Under the SPDI Rules (Rule 7), any transfer is made only where necessary or consented, and where the recipient ensures the same level of data protection. Where a sectoral law imposes stricter localisation or transfer conditions, we comply with those requirements, and we apply contractual and legal safeguards as required by Indian law.

    Cookies & tracking

    We use necessary cookies for functionality and, with your explicit consent, analytics and advertising cookies (for example, Google Analytics 4 and Meta Pixel) to improve our services. You can control cookies via your browser settings and our cookie-banner preferences, in accordance with the DPDP Act, 2023.

    Your rights & choices

    Subject to applicable law, you have the right to:

    • access a summary of the personal data we process about you and the processing activities undertaken by us in respect of your personal data;
    • obtain the identities of all other Data Fiduciaries and Data Processors with whom your personal data has been shared by us, along with a description of the personal data so shared;
    • request correction, completion, updation or erasure of your personal data for which you had previously given consent;
    • withdraw consent for processing and marketing at any time;
    • nominate another individual to exercise your rights in the event of your death, or inability to exercise your rights due to unsoundness of mind or infirmity of body; and
    • raise a grievance through the mechanism in Section 13 below.

    Your rights as mentioned above shall not apply to the sharing of your personal data with another Data Fiduciary authorised by law to obtain such personal data, where such sharing is pursuant to a written request for the prevention, detection or investigation of offences or cyber incidents, or prosecution or punishment of offences. You also have duties under DPDP (Section 15), including not to impersonate another person or file false or frivolous grievances.

    Upon receiving a request from you for correction, completion or updation of personal data, we shall correct the inaccurate or misleading personal data, complete the incomplete personal data and update the personal data, as applicable. Upon receipt of such a request, we shall erase your personal data unless retention of the same is necessary for the purpose for which such personal data was processed, in compliance with applicable law.

    At least forty-eight (48) hours before the expiry of any applicable period for erasure, we shall inform you that your personal data will be erased, unless you log into your user account, otherwise contact us for performance of the specified purpose, or exercise your rights in relation to such processing.

    We shall retain, for a minimum period of one (1) year from the date of processing, such personal data, associated traffic data and other processing logs relating to processing undertaken by us or on our behalf by our Data Processors, where required under applicable law. Thereafter, we shall erase such personal data and logs unless further retention is required under applicable law.

    Personal data breach

    On becoming aware of a personal data breach, we act under Section 8(6) of the DPDP Act read with Rule 7 to notify, to the best of our knowledge:

    • the Data Protection Board of India — an initial intimation without delay, followed by a detailed report within 72 hours (or such longer period as the Board permits); and
    • each affected individual — without delay, in clear, concise and plain language, describing the nature, extent and timing of the breach, its likely consequences, the measures we are taking or have already taken, the safeguards you can take, and the business contact information of a person who will be able to respond on our behalf to queries, if any, of the Data Principal.

    There is no materiality threshold — every breach is notifiable to both the Board and affected individuals. Where CERT-In Directions apply, earlier reporting (as short as 6 hours for certain incidents) may also be required, and we operate our breach response to meet the strictest applicable timeline.

    Duties of the Data Principal

    You shall perform the following duties:

    • comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of the Act;
    • ensure not to impersonate another person while providing your personal data for a specified purpose;
    • ensure not to suppress any material information while providing your personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities;
    • ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and
    • furnish only such information as is verifiably authentic while exercising the right to correction or erasure under the provisions of the Act or the rules made thereunder.

    Grievance redressal & contacting us

    We provide a dedicated grievance channel. You may raise a grievance with us in respect of any act or omission by us relating to our obligations concerning your personal data, or the exercise of your rights under the DPDP Act and its Rules. We will acknowledge and respond within the timelines prescribed under DPDP and its Rules.

    • Grievance Officer: Darshit Kothari (VP — Engineering)
    • Email: [ grievance email — add after pasting ]
    • General and privacy queries: [ contact email — add after pasting ]
    • Postal: Units 101–107 (1st Floor), One45 Business Bay, Vallabh Baug Extension Lane, Railway Police Colony, Pant Nagar, Ghatkopar East, Mumbai – 400075
    • Phone: +91 7666 727272

    You are required to first exhaust the grievance redressal mechanism available with us before approaching the Data Protection Board of India. If you are not satisfied with our response, you may complain to the Data Protection Board of India through its digital portal; appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

    Drafting note — remove before publishing. If Pluro is designated a Significant Data Fiduciary, an India-based Data Protection Officer must be appointed and named here, and DPIA and annual independent-audit obligations apply.

    Telemedicine disclaimer & medical information

    All tele consultations are provided by Registered Medical Practitioners (RMPs) in line with the Telemedicine Practice Guidelines, 2020. Online resources and self-assessment tools are informational only and are not a substitute for in-person clinical diagnosis or emergency care. In an emergency, call local emergency services or visit the nearest hospital immediately.

    Changes or updates to this policy

    We may modify, update or add to this policy periodically to reflect legal, regulatory or service changes. The effective date will be revised accordingly, and significant changes will be notified via our website. Your continued use of our services following such changes will signify your acceptance of the updated policy.

  1. Performance of a service you requested and legal obligations — medical record-keeping, responding to lawful authority, and asserting or defending legal rights.