Last Updated [29/06/2026]
This privacy notice (“Privacy Notice”) outlines how M/s. DM Med City Hospitals (India) Private Limited, a unit of Aster DM Quality Care Limited (Formerly known as Aster DM Healthcare Limited) (hereinafter referred to as “Organisation”, "we," "us," or "our") collects, uses, discloses, transfers, and otherwise processes personal data collected from patients and other users of the Aster Health application/website (“Aster Health”), as well as such other persons whose personal data is shared with us on their behalf (hereinafter referred to as “you” and “your”). This Privacy Notice explains how we process personal data collected from you in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, the Telemedicine Practice Guidelines, 2020 and the corresponding rules thereof, and other applicable laws, to the extent applicable.
Where required by applicable law, your consent will be free, specific, informed, unconditional and unambiguous, and signified by a clear affirmative action. You may withdraw your consent as easily as it was given, in the manner made available by us, and such withdrawal shall not affect the lawfulness of processing already undertaken based on consent before its withdrawal.
The Nature and Purposes of Personal Data Collected
-
(i) We will require the following personal information (information about you or identifiable in relation to you) for the following specified purposes:
-
(ii) Contact Information: We collect your name, email address, phone number, address, and other identifiable information provided during sign-up or added to your account profile, for the following purposes:
-
(a) To create and maintain your account.
-
(b) To communicate with you regarding services, updates, and notifications.
-
(c) To provide customer support and manage service requests.
-
(d) To improve and customize your user experience on the application.
-
-
(iii) Health and Demographic Information: We collect information related to age, gender, health conditions, medications, allergies, vaccinations, history of surgeries or procedures, health goals, health journal entries, medical reports, and health tracking data (entered manually, synced from a device, or authorized by third-party sources), for the following purposes:
-
(a) To provide and maintain the Personal Health Record functionality for patients.
-
(b) To facilitate the accurate management of your medical history and health monitoring.
-
(c) To enable healthcare services, such as health tracking, reporting, and the delivery of personalized health insights or recommendations.
-
(d) To support healthcare professionals in delivering care or advice.
-
(e) To create and maintain a unified patient profile across Organisation (OneHealth ID), including merging of multiple profiles belonging to the same individual based on system logic or user/admin request.
-
(f) To enable continuity of care by allowing access to consolidated health records, including consultation notes, prescriptions, lab reports, radiology reports, and other medical records across Organisation.
-
(g) To facilitate creation of new registrations, booking of appointments, and provision of healthcare services across Organisation using a unified patient profile.
-
-
(iv) Other Technical Information: We collect cookie related information, server logs, session settings, usage data including but not limited to location, device type, operating system, browser, date-time, and context usage and other technical data related to the usage of Aster Health for the following purposes:
-
(a) To enhance user experience and functionality.
-
(b) To save and apply user preferences (e.g., language, display settings).
-
(c) To facilitate seamless access to services via auto-authentication, where enabled.
-
(d) To monitor service usage and improve the application’s performance.
-
Device Permissions
We ask for the following device permissions while onboarding:
-
(i) SMS: We require access to your SMS messages to provide the following features: (a) Receive and Read SMS: To automatically detect and process OTPs for secure logins; and (b) Send SMS: To send appointment reminders and other important notifications to your contacts.
-
(ii) Microphone and Camera: We require access to your microphone and camera to provide the following features: (a) Voice Commands: To allow you to interact with the app using voice commands for a hands-free experience; (b) Audio/Video Calls: To facilitate audio and video consultations with healthcare professionals; and (c) Video Consultations: Enable video calls with healthcare professionals.
-
(iii) Notification: We may request permission to send notifications for service-related communications such as appointment reminders, health alerts, medication reminders, and important updates relating to Aster Health. Where we send promotional or marketing communications, we will do so only in accordance with applicable law and any choices made available to you.
-
(iv) Files and Images: We require access to files and images to facilitate upload of documents or images for sharing them on Aster Health.
-
(v) SSID/BSSID: We may request access to network-related information only where reasonably necessary to support connectivity, troubleshooting, or service quality for relevant features of Aster Health.
-
(vi) GPS location: We may request access to your location only where enabled by you and reasonably necessary to help identify nearby healthcare facilities, support location-based services, or personalise service availability.
Sources of Collection of Personal Data
We collect personal data from the following sources:
-
(i) From records maintained by our hospitals and healthcare facilities, where such personal data has been collected in connection with healthcare services and is processed for lawful purposes, including to enable services offered through Aster Health, in accordance with applicable law;
-
(ii) Directly from patients who are admitted to, visit, or otherwise receive services from our hospitals and healthcare facilities; and
-
(iii) From users who register on Aster Health.
-
(iv) From existing records across Organisation, which may be linked or merged to create a unified patient profile (OneHealth ID) to ensure accurate identification of the patient and continuity of care.
Transactional Data
Your payment details are processed through authorised payment gateways using secure and encrypted transaction mechanisms. We do not store complete payment card details unless required by law or necessary for a lawful purpose and supported by appropriate safeguards. Please note that while we implement reasonable security measures, online transactions may still carry inherent risks. Verification of payment credentials is carried out through the applicable authentication process made available by the payment service provider.
Your Responsibilities
You represent that the personal data provided during the registration process is true, accurate, current, and complete. You are required to periodically review and update your registration data to ensure that it is always accurate and correct. We will rely on the last updated version of the personal data as updated by you. While providing your personal data, you agree to ensure not to impersonate another person, and to furnish only such information as is authentic.
The accuracy, integrity and completeness of the personal health information you enter or allow to enter on your behalf is your responsibility, and we do not assume any liability for it.
Sharing of Personal Data with Third Parties
-
(i) We may disclose any information to government or law enforcement officials if we believe doing so is required to comply with law enforcement and legal process; to prevent or stop any illegal, unethical, or legally prohibited activity; and to protect your, our or others’ rights and safety.
-
(ii) We may disclose your personal data on your own request.
-
(iii) We may share personal data with third-party service providers, contractors, and technology vendors who process such data on our behalf and under appropriate contractual and security safeguards, only to the extent necessary to provide, support, secure, maintain, or improve Aster Health, communicate with you, process payments, or enable healthcare-related services requested by you or otherwise lawfully undertaken.
-
(iv) We may share anonymised and aggregated information, which does not identify you, for analytics, research, service improvement, or other lawful business purposes.
-
(v) We may share and make accessible your personal and health data across Organisation, healthcare facilities, and authorized personnel (including doctors and administrative staff), for the purposes of creating and maintaining a unified patient profile (OneHealth ID), enabling continuity of care, facilitating registrations, consultations, and providing healthcare services.
Use of Unified Patient Profile (OneHealth ID)
Aster Health may create and maintain a unified patient profile for you across its group entities and healthcare facilities, referred to as the Master Patient Index (OneHealth ID).
This may involve linking or merging multiple patient profiles that belong to you, based on identifiers such as name, date of birth, gender, contact details, or through requests raised by you or by authorized personnel acting on your behalf.
The unified profile enables:
-
Access to consolidated health records across Aster facilities;
-
Seamless booking of appointments and creation of registrations across units;
-
Improved coordination and continuity of care across different healthcare providers within Aster.
In certain cases, authorized personnel may assist in creating or linking profiles on your behalf, based on your request or confirmation provided at the facility.
You retain the right to request correction, unlinking, or restriction of such merged profiles, subject to applicable laws and internal processes.
Minors and Persons under Guardianship
Aster Health is intended for individuals who are 18 years of age or older, except where a parent or lawful guardian uses Aster Health on behalf of a child or a person with disability who has a lawful guardian. Before processing personal data of a child, or of a person with disability who has a lawful guardian, we will obtain verifiable consent of the parent or lawful guardian, as applicable, in accordance with the Digital Personal Data Protection Act, 2023 and applicable rules. We do not knowingly undertake processing of children’s personal data that is likely to cause any detrimental effect on the well-being of a child, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children except to the extent permitted by applicable law.
Security Practices and Procedures
We implement reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, loss, or misuse. Personal data processed under this Privacy Notice may be stored and processed on systems operated by our technology vendors or service providers, subject to appropriate contractual and security safeguards. Your personal data may be processed in India and, where permitted under applicable law, outside India. While we take steps to protect personal data, no method of transmission over the internet or electronic storage is completely secure, and a residual risk of compromise remains.
Your Rights
-
(i) Right to Withdraw Consent: Where we rely on your consent to process personal data, you have the right to withdraw your consent at any time in the manner made available by us. We will make withdrawal of consent as easy as giving consent. Please note that withdrawal of consent may affect our ability to provide certain services, and we may continue to retain or process personal data to the extent required or permitted by applicable law.
-
(ii) Right to Access: Subject to certain conditions, and where we have relied on consent to process your personal data, or where you have voluntarily provided your personal data for a specified purpose, you have the right to obtain information from us as below, as well as such information as may be further prescribed under applicable law:
-
(a) Summary of personal data and processing activities: You have the right to receive a summary of the personal data that is being processed by us, along with details regarding the processing activities undertaken by us with respect to such personal data.
-
(b) Identities of other data fiduciaries and data processors: You have the right to know the identities of all other entities with whom your personal data has been shared by us. This includes a description of the personal data shared with these entities.
-
-
(iii) Right to Correction, Completion and Updation: Subject to certain conditions, you have the right to correction, completion, and updating of your personal data for which you have previously given consent, or voluntarily provided your personal data for a specified purpose, in accordance with any requirement or procedure under any law for the time being in force. This includes the right to:
-
(a) Correct any inaccurate or misleading personal data.
-
(b) Complete the incomplete personal data.
-
(c) Update your personal data.
-
-
(iv) Right to Erasure: Subject to certain conditions, you have the right to request the deletion of your personal data under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected or when you withdraw your consent.
-
(v) Right to nominate an individual for exercising rights: You have the right to nominate any other person to exercise the rights mentioned above in case of your death or incapacity.
We will respond to your requests in the manner and within the timelines prescribed by applicable law.
Retention of Your Data
We will not retain your personal data for longer than is required for the purposes for which the information may lawfully be used or is otherwise required under any other law for the time being in force. We may process anonymized and aggregated data/ information collected through Aster Health, for purposes of evaluating healthcare outcomes, healthcare requirement patterns and to measure the effectiveness of services and content.
Grievance Redressal / Contact Us
Towards exercising your rights mentioned under the ‘Your Rights’ section and for grievance redressal/inquiries regarding this Privacy Notice, please reach out to our grievance officer as below:
Name: Syed Mohamed Baqar
Email Address: [email protected]
If you are not satisfied with our response to your grievance, you may have the right to seek recourse with the Data Protection Board of India or any other authority, forum, or mechanism available under applicable law.
Changes/ Updates to the Privacy Notice
Please note that this Privacy Notice may change from time to time as we continue to offer and improve our services. In the event of any change to this Privacy Notice, the updated version will be posted here and will take effect from the date of posting, unless otherwise stated.
If there are any changes to the purposes for which you have provided your consent under this Privacy Notice, we will seek your consent for such change in the purposes of processing personal data under this Privacy Notice.

