Privacy Policy
Privacy Policy
This policy explains how Sai Industries Pvt. Ltd. processes, stores, and protects your personal and health data.
Store submission reference
Last updated May 26, 2026
This Privacy Policy is issued by Sai Industries Pvt. Ltd., operating the SwasthaID application for use by patients, caregivers, healthcare providers, hospitals, and clinics.
This Policy describes how we collect, use, disclose, retain, and protect your personal data, including sensitive health data, when you use our Application. This policy reflects internationally accepted best practices for the governance of sensitive healthcare data and complies with Apple App Store privacy guidelines.
By downloading, installing, or using the Application, you acknowledge that you have read, understood, and agree to be bound by the terms of this Policy.
Preamble
SAI INDUSTRIES PVT. LTD. PRIVACY POLICY
SwasthaID Mobile Application
Version 2.0 | Effective Date: 26 May 2026 | Last Updated: 26 May 2026
This Privacy Policy (the "Policy") is issued by Sai Industries Pvt. Ltd., a company incorporated under the laws of Nepal (Registration No. 369506) ("the Company", "we", "us", or "our"), with its registered office at Lalitpur Metropolitan City-3, Lalitpur, Nepal. The Company develops and operates the SwasthaID mobile application (the "Application" or "App") for use by patients, caregivers, healthcare providers, hospitals, and clinics.
1. Definitions
For the purposes of this Policy, the following terms shall have the meanings ascribed to them below:
2. Who We Are
Sai Industries Pvt. Ltd. (Company Registration Number 369506)
Registered Office: Lalitpur Metropolitan City-3, Lalitpur, Nepal
Data Protection Officer (DPO): [DPO NAME — TO BE APPOINTED]
Email: privacy@swastha.id
Support: support@swastha.id
Website: https://swastha.id
3. Scope and Application of This Policy
This Policy applies to:
- All individuals who download, register, or otherwise use the Application, including patients, caregivers, and authorized representatives;
- All personal data and health data collected, stored, processed, or transmitted through the Application;
- All processing activities conducted by the Company, its employees, subcontractors, and third-party service providers acting on its behalf;
- All versions of the Application, whether accessed on iOS or Android.
Third-Party Exclusions
4. What Data We Collect
4.1 Personal Identification Data
- Full legal name
- Date of birth and age
- Gender identity
- Nationality and residential address
- Government-issued identification number (where required by law or healthcare provider)
4.2 Contact Data
- Email address
- Mobile telephone number
- Emergency contact information
4.3 Account and Session Data
Account registration date and time, session tokens, and authentication records.
Note: The Application uses email one-time passcode (OTP) authentication only. No passwords are collected or stored.
4.4 Sensitive Health and Medical Data (Special Category Data)
The following categories of data are classified as Special Category Data and are accorded the highest level of protection:
- Medical records and clinical notes from registered healthcare providers
- Diagnostic reports, pathology results, radiology reports, and laboratory test results
- Prescription history and current medication records
- Health history, including chronic conditions, allergies, surgical history, and immunization records
- Vital health indicators (blood pressure, blood glucose, weight, BMI, and similar metrics) where voluntarily entered
- Mental health records and psychiatric assessments (if applicable)
- Appointment history and consultation notes
- Insurance information linked to health records (where applicable)
4.5 Device and Technical Data
- Device type, model, and operating system version
- Unique device identifiers (subject to user consent under the App Tracking Transparency framework)
- Internet Protocol (IP) address
- Application version and session duration logs
- Error logs and stability diagnostics
- In-app navigation patterns
- Push notification tokens
4.6 Camera Data
The Application requests access to your device camera solely for the purpose of scanning and uploading medical documents, reports, or prescriptions. Camera data is not stored, transmitted, or used for any purpose other than the immediate document upload for which your consent was obtained.
Microphone access: The Application does not currently request or use microphone access. If voice-based features are introduced in a future release, this Policy will be updated and your explicit consent will be sought prior to any microphone use.
4.7 Data We Do Not Collect
The Company does not collect financial payment card data directly. All payment transactions, where applicable, are processed by PCI-DSS-compliant third-party payment processors. The Company does not store full card numbers or bank account details. The Company does not collect location data.
5. How We Collect Your Data
5.1 Direct Collection from the Data Subject
We collect personal data directly from you when you:
- Register and create an account on the Application
- Complete your health profile and input medical information
- Upload medical records, diagnostic reports, or prescriptions
- Communicating with healthcare providers through the Application
- Contact our customer support team
- Respond to surveys, feedback forms, or research requests (with separate consent)
5.2 Automated Collection
- Server logs that record IP addresses, access timestamps, and API requests
- Performance monitoring tools that assess application stability and user interactions
- Session management tokens stored locally on device for authentication purposes
5.3 Third-Party Integrations and Healthcare Providers
Personal data may be received from:
- Registered hospitals and clinics that are formally integrated with the Application and share your medical records with your explicit consent
- Third-party identity verification services used during account creation
- Laboratory information systems or hospital management systems connected to the Application under formal data-sharing agreements
6. How We Use Your Data
The Company processes your personal data only for specified, explicit, and legitimate purposes:
6.1 Provision and Management of Services
- Creating and maintaining your user account
- Enabling you to securely store, access, and manage your medical records and health data
- Facilitating communication and record-sharing between you and your authorized healthcare providers
- Processing appointments and sending appointment reminders
- Generating health summaries and reports for your personal use or for sharing with healthcare professionals
6.2 Application Functionality and Technical Operations
- Authenticating your identity and maintaining the security of your account
- Diagnosing and resolving technical issues, bugs, and service disruptions
- Ensuring compatibility with your device's operating system and hardware
- Sending push notifications relevant to your health records and appointments
6.3 Service Improvement and Research
- Analyzing anonymized and aggregated usage data to improve Application features, user experience, and clinical utility
- Conducting internal research and development to enhance our healthcare data management capabilities
- Where separately consented, contributing to de-identified medical research datasets
6.4 Legal and Regulatory Compliance
- Meeting obligations imposed by applicable Nepalese law, including any regulatory requirements applicable to healthcare software
- Responding to lawful requests from competent governmental, judicial, or regulatory authorities
- Establishing, exercising, or defending legal claims
6.5 Safety and Fraud Prevention
- Detecting and preventing fraudulent activity, unauthorized access, and security incidents
- Monitoring for and responding to threats to the integrity and confidentiality of health data
8. International Data Transfers
The Company may transfer personal data outside Nepal to the extent necessary for cloud storage, technical support, and third-party service provision. In doing so, the Company ensures that an adequate level of protection is maintained through one or more mechanisms such as Standard Contractual Clauses (SCCs).
Special Category Restrictions
9. Data Retention
9.1 Retention Periods
Health and Medical Records
A minimum of ten (10) years from the date of last entry, in accordance with healthcare record retention standards in Nepal.
Account and Session Data
Active duration + six (6) years post account closure to fulfil legal claims or regulatory requirements.
Device and Technical Data
A maximum of thirteen (13) months from the date of collection.
Error and Stability Logs
Ninety (90) days from the date of generation.
9.2 Secure Disposal
Upon expiry of the applicable retention period, personal data is securely deleted or anonymized using industry-standard data destruction methods, including cryptographic erasure for cloud-stored data.
10. Your Rights
You have the following rights under this Policy, subject to applicable exceptions:
Access
Request confirmation of processing and obtain copies of your data.
Rectification
Require the correction of any inaccurate or incomplete personal data.
Erasure (Right to Be Forgotten)
Request the deletion of your personal data under certain conditions.
Restriction
Request restriction of processing under pending verification circumstances.
Data Portability
Receive your personal data in a structured, machine-readable format.
Object
Object to processing based on legitimate interests or direct marketing.
11. Data Deletion and Consent Withdrawal
11.1 In-Application Deletion Request
You may initiate a request to delete your account and associated personal data directly within the Application by navigating to Settings > Account > Privacy & Data > Delete My Account and Data. Upon confirmation, the Company will initiate the deletion process within seventy-two (72) hours.
The public account deletion page is available at: https://swastha.id/account-deletion
11.2 Deletion Request via Email
If you are unable to access the Application, you may submit a deletion request by emailing support@swastha.idwith the subject line "Data Deletion Request", including your full name and registered email address.
11.3 Withdrawal of Consent
You may withdraw consent for any specific category of data processing at any time by accessing Privacy Settings within the Application or by emailing the Data Protection Officer at privacy@swastha.id.
12. Data Security Measures
12.1 Technical Safeguards
- End-to-end encryption of all health data transmitted using a minimum of TLS 1.3
- Encryption at rest of all personal and health data stored on our servers using AES-256
- Role-based access controls and Multi-factor authentication (MFA) for all staff accessing systems
- Regular penetration testing conducted by independent cybersecurity firms
- Secure device storage for mobile tokens and sensitive local cryptographic state
12.2 Personal Data Breach Notification
In the event of a personal data breach affecting your rights and freedoms, the Company will notify you without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach, alongside mandatory regulatory reporting.
13. Apple App Store Compliance
13.1 App Privacy Disclosures
In compliance with Apple App Store privacy disclosures, the following data types are collected and linked to your identity:
- Health and fitness data (linked to identity) — used for health record management
- Contact information (linked to identity) — used for account creation and communication
- Identifiers (linked to identity) — used for account authentication
- Usage data and Diagnostics (not linked to identity) — used for performance monitoring and application stability
13.2 Device Permission Disclosures
Camera Access: The Application requests access to your camera solely to enable you to photograph and upload medical documents, prescriptions, and diagnostic reports to your health record.
Microphone Access: Microphone access is not requested by the Application.
14. Children's Privacy
The Application is not directed at children under the age of sixteen (16) years. We do not knowingly collect personal data from children under sixteen without appropriate consent. Where the Application is used to manage a minor's records, it must be operated by a parent, legal guardian, or authorized adult caregiver.
15. Changes to This Privacy Policy
Material changes will be notified via in-app notification or email no fewer than thirty (30) calendar days prior to the change taking effect. Continued use of the Application constitutes your acknowledgement of the updated Policy.
16. Complaints
If you are not satisfied with our handling of your data, you are entitled to lodge a complaint with our Data Protection Officer at privacy@swastha.id. We commit to responding within thirty (30) calendar days of receipt.
17. Contact Information
For all enquiries, requests, or concerns relating to this Privacy Policy or your personal data, please contact:
Sai Industries Pvt. Ltd.
Attn: Data Protection Officer
Address: Lalitpur Metropolitan City-3, Lalitpur, Nepal