We take the privacy and security of your personal and health information seriously. Read our policy to understand how we collect, use and safeguard your data.


We take the privacy and security of your personal and health information seriously. Read our policy to understand how we collect, use and safeguard your data.
This Privacy Policy explains how Esperanza Medical Platform Private Limited (“Pluro”, “we”, “our”, “us”) collects, uses, stores, shares and protects your personal information when you visit our websites, use our applications, book appointments, undergo treatment at our centres, or interact with us via digital and offline channels in India.
An itemised description of the data collected and the purpose of its processing is provided so that you can make an informed choice, as required under DPDP (Section 5, read with Rule 3).
We may process your personal and health data in accordance with the DPDP Act and Rules as amended from time to time for the following purposes, for which we have either obtained your consent or for certain legitimate uses which include a specified purpose for which you have voluntarily provided your personal data, or a purpose in respect of which you have not indicated to us that you do not consent to the use of your personal data.
We may also process your personal and health data for the purposes of: (i) complying with any obligation to disclose information to the State or its instrumentalities under applicable law; (ii) complying with any judgment, decree or order issued under applicable law; (iii) responding to a medical emergency involving a threat to the life or immediate health of any individual; (iv) providing medical treatment or health services during an epidemic, disease outbreak or other public health threat; (v) ensuring the safety of, or providing assistance or services to, any individual during a disaster or breakdown of public order; and (vi) purposes relating to employment, including safeguarding the employer against loss or liability, protecting confidentiality of trade secrets, intellectual property or classified information, or providing any service or benefit sought by an employee.
These purposes include the following:
We process personal data on the following bases:
Where the SPDI Rules apply, consent for sensitive personal data is obtained in writing (including by electronic means). You may give, manage, review and withdraw consent directly with us or through a registered Consent Manager.
We are responsible for complying with the provisions of the DPDP Act and the rules made thereunder in respect of any processing undertaken by us, or on our behalf by our Data Processors engaged, appointed, used or otherwise involved by us to process personal data for any activity related to offering goods and services to you, only under a valid contract.
Where the personal data processed by us is likely to be used to make a decision affecting you, or disclosed to another Data Fiduciary, we shall ensure the completeness, accuracy and consistency of such personal data.
We shall implement appropriate technical and organisational measures to ensure compliance with the DPDP Act and the rules made thereunder, and shall take reasonable security safeguards to prevent personal data breaches, including in respect of processing undertaken by us or on our behalf by our Data Processors. Such safeguards shall include, at minimum and as applicable:
No method of internet transmission or electronic storage is completely secure. While we use commercially acceptable means to protect your information, we cannot guarantee absolute security and there is a residual risk of unauthorised access.
We do not knowingly process the personal data of an individual under eighteen (18) years of age without obtaining verifiable consent of a parent or lawful guardian, as required under applicable data protection law. We shall adopt appropriate technical and organisational measures to obtain such verifiable consent before processing the personal data of a child, and shall exercise due diligence to verify that the individual identifying themselves as the parent has completed eighteen (18) years of age and is identifiable, where required for compliance with applicable law, by reference to: (a) reliable details of the identity and age of such individual available with us; or (b) details of identity and age voluntarily provided by such individual, including through a virtual token mapped to such details and issued by an authorised entity, including where such details or token are made available and verified through a Digital Locker Service Provider. We shall not undertake processing likely to have a detrimental effect on the well-being of a child, and shall not carry out tracking, behavioural monitoring or targeted advertising directed at children.
Where we process the personal data of a person with disability who has a lawful guardian, we shall obtain verifiable consent of such guardian and exercise due diligence to verify that the guardian has been appointed by a court of law, a designated authority or a local level committee, in accordance with the applicable law relating to guardianship.
Fertility and ART information is treated with the highest confidentiality. Note: the DPDP Act does not create a separate statutory category of “sensitive personal data”; however, such data qualifies as Sensitive Personal Data or Information (SPDI) under the IT/SPDI Rules while they remain in force, and in all cases we apply heightened safeguards consistent with the ART Act, Surrogacy Act, ICMR guidance and medical-records obligations.
Clinical and ART records are retained as mandated by law. Under the ART Act and Rules, ART clinics and banks must preserve records (for example, donor, procedure and outcome data) and, on closure before the mandated period, transfer records to the National Registry. Current guidance indicates preservation for up to 10 years for ART and clinic records (with periodic National Registry updates), or such longer period as prescribed by law or required for ongoing legal proceedings. Where the Surrogacy Act applies to your case, additional record-keeping and retention obligations may apply. Non-clinical website and analytics data is retained for shorter periods consistent with business needs and law.
In accordance with DPDP (Section 8(7) and Rule 8), we shall erase personal data — and require our processors to erase it — once the purpose is no longer served or consent is withdrawn, whichever is earlier, unless retention is required by law, including the medical-records and ART/Surrogacy obligations above. We maintain logs as required under the Rules. The purpose referred to above shall be deemed to be no longer served if you do not approach us for the performance of the specified purpose for which your personal data was being processed, and you do not exercise any of your rights in relation to such processing, for such time period as may be prescribed.
We may share data with:
We require our Data Processors to protect personal data and to process it only on our instructions. Under the SPDI Rules, we will not disclose sensitive personal data to third parties without your prior permission, except under a contract with you or as required by law. We do not sell or rent patient information.
We may store or transfer personal data outside India. Under DPDP (Section 16 and Rule 15), such transfers are permitted except to any country or territory that the Central Government restricts by notification (a “negative-list” approach). Under the SPDI Rules (Rule 7), any transfer is made only where necessary or consented, and where the recipient ensures the same level of data protection. Where a sectoral law imposes stricter localisation or transfer conditions, we comply with those requirements, and we apply contractual and legal safeguards as required by Indian law.
We use necessary cookies for functionality and, with your explicit consent, analytics and advertising cookies (for example, Google Analytics 4 and Meta Pixel) to improve our services. You can control cookies via your browser settings and our cookie-banner preferences, in accordance with the DPDP Act, 2023.
Subject to applicable law, you have the right to:
Your rights as mentioned above shall not apply to the sharing of your personal data with another Data Fiduciary authorised by law to obtain such personal data, where such sharing is pursuant to a written request for the prevention, detection or investigation of offences or cyber incidents, or prosecution or punishment of offences. You also have duties under DPDP (Section 15), including not to impersonate another person or file false or frivolous grievances.
Upon receiving a request from you for correction, completion or updation of personal data, we shall correct the inaccurate or misleading personal data, complete the incomplete personal data and update the personal data, as applicable. Upon receipt of such a request, we shall erase your personal data unless retention of the same is necessary for the purpose for which such personal data was processed, in compliance with applicable law.
At least forty-eight (48) hours before the expiry of any applicable period for erasure, we shall inform you that your personal data will be erased, unless you log into your user account, otherwise contact us for performance of the specified purpose, or exercise your rights in relation to such processing.
We shall retain, for a minimum period of one (1) year from the date of processing, such personal data, associated traffic data and other processing logs relating to processing undertaken by us or on our behalf by our Data Processors, where required under applicable law. Thereafter, we shall erase such personal data and logs unless further retention is required under applicable law.
On becoming aware of a personal data breach, we act under Section 8(6) of the DPDP Act read with Rule 7 to notify, to the best of our knowledge:
There is no materiality threshold — every breach is notifiable to both the Board and affected individuals. Where CERT-In Directions apply, earlier reporting (as short as 6 hours for certain incidents) may also be required, and we operate our breach response to meet the strictest applicable timeline.
You shall perform the following duties:
We provide a dedicated grievance channel. You may raise a grievance with us in respect of any act or omission by us relating to our obligations concerning your personal data, or the exercise of your rights under the DPDP Act and its Rules. We will acknowledge and respond within the timelines prescribed under DPDP and its Rules.
You are required to first exhaust the grievance redressal mechanism available with us before approaching the Data Protection Board of India. If you are not satisfied with our response, you may complain to the Data Protection Board of India through its digital portal; appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
Drafting note — remove before publishing. If Pluro is designated a Significant Data Fiduciary, an India-based Data Protection Officer must be appointed and named here, and DPIA and annual independent-audit obligations apply.
All tele consultations are provided by Registered Medical Practitioners (RMPs) in line with the Telemedicine Practice Guidelines, 2020. Online resources and self-assessment tools are informational only and are not a substitute for in-person clinical diagnosis or emergency care. In an emergency, call local emergency services or visit the nearest hospital immediately.
We may modify, update or add to this policy periodically to reflect legal, regulatory or service changes. The effective date will be revised accordingly, and significant changes will be notified via our website. Your continued use of our services following such changes will signify your acceptance of the updated policy.