DPDP-Ready Privacy-by-Design Architecture

Privacy Policy & Notice

Last updated: April 2026 · Aligned with India's Digital Personal Data Protection (DPDP) Framework

Data Principal Rights Portal

Exercise your statutory rights for access, correction, erasure, or grievance redressal.

Submit Rights Request

Communication Preferences

Manage your notification choices or withdraw consent for optional product updates.

Manage Preferences

1. Data Fiduciary Identity

This website and the Swachh Hospital platform are developed and operated by:

Navidad Infotech Private Limited

Bengaluru, Karnataka, India

Corporate Privacy Inquiries: privacy@navidad.co.in

Where Navidad Infotech Private Limited determines the purposes and means of processing personal data (such as website inquiries, pilot requests, and direct customer interactions), it acts as the Data Fiduciary under India's Digital Personal Data Protection framework. Where our platform is deployed within a hospital or healthcare network to process operational hygiene inspections on behalf of that institution, that institution acts as the primary Data Fiduciary and Swachh Hospital operates as a Data Processor under a written agreement.

2. Personal Data We Collect & Minimization

We adhere strictly to data minimization: we collect only personal data that is genuinely necessary for the specified purpose.

A. Website Inquiries & Pilot Requests

Required: Full name, professional work email, healthcare organization name, and inquiry message.
Optional: Designation, contact phone number, city, state, and approximate bed count.

B. Facility Feedback & Public Hygiene Concerns

Data: Complainant name, email, optional phone, selected participating facility, and observation description.
Notice: Submissions are routed directly to the selected participating facility for operational review.

C. System Technical & Security Logs

IP address, user agent, timestamps, and API response status codes recorded strictly for security monitoring, unauthorized access investigation, and DDoS prevention.

Strict Prohibition Against Patient Health Data:Swachh Hospital is an environmental hygiene inspection, corrective-action, and facility governance platform. We do not collect, request, or store patient medical records, diagnostic histories, Aadhaar numbers, or clinical documentation. All demonstrations, screenshots, and sample reports across this website utilize strictly synthetic demonstration data (e.g., "Apex Memorial Hospital").

3. Purpose Specification & Consent

Personal data is processed only for explicit, non-bundled purposes communicated at the time of collection:

  • To evaluate, coordinate, and schedule requested platform demonstrations and pilot deployments.
  • To transmit facility feedback directly to the operational team of the designated healthcare facility.
  • To investigate and remediate security events and unauthorized platform access attempts.
  • To send optional product feature updates only where you have provided explicit, un-ticked affirmative consent.

Marketing consent is never bundled with pilot requests, feedback submissions, or service contracts. You may withdraw consent at any time without penalty via our Communication Preferences page.

4. Data Principal Rights

Under the DPDP framework, you possess specific enforceable rights as a Data Principal:

  • Right to Access: Request a concise summary of the personal data held about you and the processing activities undertaken.
  • Right to Correction & Updating: Request the correction, completion, or updating of inaccurate or misleading personal data.
  • Right to Erasure: Request the deletion of your personal data when the purpose of collection has been fulfilled, subject to statutory retention obligations.
  • Right to Grievance Redressal: Submit a complaint regarding data processing to our designated Grievance Redressal Officer.
  • Right to Nominate: Nominate an individual to exercise rights on your behalf in the event of death or incapacity.

5. Reasonable Security Safeguards

In compliance with statutory security requirements under the notified DPDP Rules, Navidad Infotech implements layered technical and organizational safeguards:

  • Encryption in Transit: Mandatory TLS 1.3/1.2 encryption for all network traffic with HSTS enabled.
  • Encryption at Rest: AES-256 encryption across databases, object storage volumes, and backups.
  • Role-Based Access Control (RBAC): Strict principle of least privilege, preventing unauthorized inter-tenant or cross-department data exposure.
  • Sanitized Audit Logging: Security logs record actor IDs, timestamps, and resource actions without storing passwords, tokens, or raw personal data payloads.
  • Opaque Reference Tracking: Public tracking identifiers and verification tokens use random, unpredictable identifiers (e.g., SH-XXXX-XXXX) rather than incremental sequential numbers to prevent enumeration.

6. Data Retention & Automated Erasure

We do not retain personal data indefinitely. Personal data is systematically removed or anonymized according to configuration-driven schedules:

Data CategoryRetention PeriodRationale
Contact & Pilot Inquiries180 daysPurpose completion and demonstration follow-up
Security & Access Audit Logs365 days (1 year)Statutory investigation window under notified DPDP rules
Incomplete Form Drafts14 daysSession cleanup and minimization
Data Principal Rights Records1095 days (3 years)Statutory compliance verification and defense

7. Data Processors & Service Providers

We do not sell personal data to third parties. We engage carefully vetted Data Processors under written data processing contracts that require equivalent security safeguards:

  • Cloud infrastructure and database hosting providers located within India.
  • Transactional email delivery services for responding to inquiries and rights verifications.

8. Grievance Redressal Officer

In compliance with the DPDP framework, Navidad Infotech has designated a Grievance Redressal Officer to address queries, complaints, or escalations:

Grievance Redressal Officer — Privacy & Data Protection

Navidad Infotech Private Limited

Navidad Infotech Private Limited, Bengaluru, Karnataka, India

Email: grievance@navidad.co.in

Response timeline: Grievances are acknowledged within 48 hours and resolved within 30 calendar days.

Compliance & Implementation Principle:

Swachh Hospital is architected and built to be DPDP-ready by design. In accordance with responsible governance, we do not make unverifiable claims such as "DPDP Certified" or claim government endorsement. Full organizational compliance requires coordinated institutional contracts, data protection agreements, operational policies, and ongoing compliance reviews.