Privacy Policy

Last updated: January 2026

1. Introduction

This Privacy Policy describes how The 5 Lotus ("we," "us," "our," or the "Facility") collects, uses, processes, protects, and discloses your personal and sensitive health information when you visit our website, use our services, or visit our physical premises. We are committed to protecting your privacy and ensuring the security of your data in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and applicable healthcare regulations in India. By accessing our services, you consent to the data practices described in this policy.

2. Information We Collect

We collect several types of information to provide superior care and improve our services:

  • Personal Identity Information: Name, age, gender, date of birth, next-of-kin details, and government-issued ID proof (Aadhaar, PAN, etc.) as required for patient admission and verification.
  • Contact Information: Phone numbers, email addresses, and residential addresses.
  • Sensitive Personal Data or Information (SPDI):
    • Physical and mental health records, including medical history, symptoms, diagnoses, and treatment plans.
    • Psychological assessment results and therapy notes.
    • Biometric information (if used for security/patient safety).
    • Financial information (bank account or credit card details) for payment processing.
  • Technical Data: IP address, browser type, device information, and usage patterns when accessing our digital platforms.

3. Purpose of Data Collection

We use your data strictly for legitimate medical and operational purposes, including:

  • Clinical Care: To diagnose medical/psychiatric conditions, prescribe treatments, and monitor progress.
  • Communication: To send appointment reminders, health updates, and administrative notices.
  • Safety & Security: To maintain the safety of our premises (e.g., CCTV surveillance) and prevent harm to patients or staff.
  • Legal Compliance: To comply with court orders, medico-legal requirements, public health regulations, and government audits.
  • Research & Improvement: De-identified (anonymized) data may be used for internal quality audits and authorized medical research to improve treatment outcomes.

4. Data Disclosure and Sharing

We do not sell your personal data. We may share your information only under the following specific circumstances:

  • Medical Necessity: With other healthcare providers, specialists, labs, or hospitals involved in your direct care (referrals/transfers).
  • Legal Obligations: When required by Indian law, court order, or law enforcement agency (e.g., in cases of self-harm risk or threat to public safety).
  • Authorized Representatives: With family members or legal guardians, strictly as per the consent provided by the patient or where the patient lacks decision-making capacity due to medical reasons, in accordance with the Mental Healthcare Act, 2017.
  • Service Providers: With trusted third-party vendors (e.g., IT support, cloud storage, payment processors) who are legally bound by confidentiality agreements.

5. Data Security Measures

We implement robust physical, technical, and administrative security safeguards to protect your data from unauthorized access, loss, or misuse. This includes secure electronic medical record (EMR) systems, access controls, encryption where applicable, and strict staff confidentiality agreements. While we strive to use commercially acceptable means to protect your data, no method of transmission over the internet or electronic storage is 100% secure.

6. Retention of Data

We retain medical records and personal data for the duration required by applicable Indian laws (typically 3-10 years post-treatment depending on the nature of the record) or as long as necessary to fulfill the purposes outlined in this policy. After the retention period, data is securely disposed of or anonymized.

7. Your Rights

Subject to applicable laws, you have the right to request access to your medical records, correct inaccuracies, or withdraw consent for specific data uses (prospective only). Requests regarding your data must be submitted in writing to our Grievance Officer. Note that withdrawal of consent may limit our ability to provide medical services.

8. Grievance Officer

In accordance with the Information Technology Act, 2000, and SPDI Rules, contact details of the Grievance Officer are provided below:

Name: Dr. Raghvendra Singh Ranvaria
Designation: Director & Data Privacy Officer
Email: contact@the5lotus.com
Address: Shop No. 8, Gol Chakkar, Krishna Milestone, B 1, Shastripuram, Agra, Uttar Pradesh 282007

9. Changes to This Policy

We reserve the right to update this Privacy Policy at any time to reflect changes in our practices or legal requirements. Updated policies will be posted on our website. Continued use of our services constitutes acceptance of the revised terms.