Back to SwasthaID

Privacy Policy

Privacy Policy

This policy explains how Sai Industries Pvt. Ltd. processes, stores, and protects your personal and health data.

Store submission reference

Last updated May 26, 2026

Contact

privacy@swastha.id

General support: support@swastha.id

This Privacy Policy is issued by Sai Industries Pvt. Ltd., operating the SwasthaID application for use by patients, caregivers, healthcare providers, hospitals, and clinics.

This Policy describes how we collect, use, disclose, retain, and protect your personal data, including sensitive health data, when you use our Application. This policy reflects internationally accepted best practices for the governance of sensitive healthcare data and complies with Apple App Store privacy guidelines.

By downloading, installing, or using the Application, you acknowledge that you have read, understood, and agree to be bound by the terms of this Policy.

Preamble

SAI INDUSTRIES PVT. LTD. PRIVACY POLICY
SwasthaID Mobile Application
Version 2.0 | Effective Date: 26 May 2026 | Last Updated: 26 May 2026

This Privacy Policy (the "Policy") is issued by Sai Industries Pvt. Ltd., a company incorporated under the laws of Nepal (Registration No. 369506) ("the Company", "we", "us", or "our"), with its registered office at Lalitpur Metropolitan City-3, Lalitpur, Nepal. The Company develops and operates the SwasthaID mobile application (the "Application" or "App") for use by patients, caregivers, healthcare providers, hospitals, and clinics.

1. Definitions

For the purposes of this Policy, the following terms shall have the meanings ascribed to them below:

Personal Data
Any information relating to an identified or identifiable natural person, including name, date of birth, email address, contact number, and account credentials.
Special Category Data / Health Data
Data concerning health, medical records, diagnostic reports, health history, treatments, prescriptions, test results, and any other information pertaining to the physical or mental condition of an individual, which is afforded heightened protection under this Policy.
Processing
Any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, or erasure.
Data Controller
Sai Industries Pvt. Ltd., which determines the purposes and means of processing your personal data.
Data Subject
The identified or identifiable natural person to whom the personal data relates, including patients and application users.
Consent
Any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes by which they agree to the processing of their personal data.

2. Who We Are

Sai Industries Pvt. Ltd. (Company Registration Number 369506)

Registered Office: Lalitpur Metropolitan City-3, Lalitpur, Nepal

Data Protection Officer (DPO): [DPO NAME — TO BE APPOINTED]

Email: privacy@swastha.id

Support: support@swastha.id

Website: https://swastha.id

3. Scope and Application of This Policy

This Policy applies to:

  • All individuals who download, register, or otherwise use the Application, including patients, caregivers, and authorized representatives;
  • All personal data and health data collected, stored, processed, or transmitted through the Application;
  • All processing activities conducted by the Company, its employees, subcontractors, and third-party service providers acting on its behalf;
  • All versions of the Application, whether accessed on iOS or Android.

Third-Party Exclusions

This Policy does not apply to third-party websites, applications, or services that may be linked to or referenced within the Application. The Company bears no responsibility for the privacy practices of third parties.

4. What Data We Collect

4.1 Personal Identification Data

  • Full legal name
  • Date of birth and age
  • Gender identity
  • Nationality and residential address
  • Government-issued identification number (where required by law or healthcare provider)

4.2 Contact Data

  • Email address
  • Mobile telephone number
  • Emergency contact information

4.3 Account and Session Data

Account registration date and time, session tokens, and authentication records.

Note: The Application uses email one-time passcode (OTP) authentication only. No passwords are collected or stored.

4.4 Sensitive Health and Medical Data (Special Category Data)

The following categories of data are classified as Special Category Data and are accorded the highest level of protection:

  • Medical records and clinical notes from registered healthcare providers
  • Diagnostic reports, pathology results, radiology reports, and laboratory test results
  • Prescription history and current medication records
  • Health history, including chronic conditions, allergies, surgical history, and immunization records
  • Vital health indicators (blood pressure, blood glucose, weight, BMI, and similar metrics) where voluntarily entered
  • Mental health records and psychiatric assessments (if applicable)
  • Appointment history and consultation notes
  • Insurance information linked to health records (where applicable)

4.5 Device and Technical Data

  • Device type, model, and operating system version
  • Unique device identifiers (subject to user consent under the App Tracking Transparency framework)
  • Internet Protocol (IP) address
  • Application version and session duration logs
  • Error logs and stability diagnostics
  • In-app navigation patterns
  • Push notification tokens

4.6 Camera Data

The Application requests access to your device camera solely for the purpose of scanning and uploading medical documents, reports, or prescriptions. Camera data is not stored, transmitted, or used for any purpose other than the immediate document upload for which your consent was obtained.

Microphone access: The Application does not currently request or use microphone access. If voice-based features are introduced in a future release, this Policy will be updated and your explicit consent will be sought prior to any microphone use.

4.7 Data We Do Not Collect

The Company does not collect financial payment card data directly. All payment transactions, where applicable, are processed by PCI-DSS-compliant third-party payment processors. The Company does not store full card numbers or bank account details. The Company does not collect location data.

5. How We Collect Your Data

5.1 Direct Collection from the Data Subject

We collect personal data directly from you when you:

  • Register and create an account on the Application
  • Complete your health profile and input medical information
  • Upload medical records, diagnostic reports, or prescriptions
  • Communicating with healthcare providers through the Application
  • Contact our customer support team
  • Respond to surveys, feedback forms, or research requests (with separate consent)

5.2 Automated Collection

  • Server logs that record IP addresses, access timestamps, and API requests
  • Performance monitoring tools that assess application stability and user interactions
  • Session management tokens stored locally on device for authentication purposes

5.3 Third-Party Integrations and Healthcare Providers

Personal data may be received from:

  • Registered hospitals and clinics that are formally integrated with the Application and share your medical records with your explicit consent
  • Third-party identity verification services used during account creation
  • Laboratory information systems or hospital management systems connected to the Application under formal data-sharing agreements

6. How We Use Your Data

The Company processes your personal data only for specified, explicit, and legitimate purposes:

6.1 Provision and Management of Services

  • Creating and maintaining your user account
  • Enabling you to securely store, access, and manage your medical records and health data
  • Facilitating communication and record-sharing between you and your authorized healthcare providers
  • Processing appointments and sending appointment reminders
  • Generating health summaries and reports for your personal use or for sharing with healthcare professionals

6.2 Application Functionality and Technical Operations

  • Authenticating your identity and maintaining the security of your account
  • Diagnosing and resolving technical issues, bugs, and service disruptions
  • Ensuring compatibility with your device's operating system and hardware
  • Sending push notifications relevant to your health records and appointments

6.3 Service Improvement and Research

  • Analyzing anonymized and aggregated usage data to improve Application features, user experience, and clinical utility
  • Conducting internal research and development to enhance our healthcare data management capabilities
  • Where separately consented, contributing to de-identified medical research datasets

6.4 Legal and Regulatory Compliance

  • Meeting obligations imposed by applicable Nepalese law, including any regulatory requirements applicable to healthcare software
  • Responding to lawful requests from competent governmental, judicial, or regulatory authorities
  • Establishing, exercising, or defending legal claims

6.5 Safety and Fraud Prevention

  • Detecting and preventing fraudulent activity, unauthorized access, and security incidents
  • Monitoring for and responding to threats to the integrity and confidentiality of health data

7. Who We Share Your Data With

7.1 Healthcare Providers

With your explicit prior consent, the Company may share your health data with the hospitals, clinics, physicians, or other healthcare professionals designated by you within the Application. Such sharing occurs strictly within the scope of your consent and is governed by formal Data Processing Agreements between the Company and each healthcare provider. Healthcare providers acting as data processors are contractually bound to process your data solely for the purposes you have authorized and to maintain standards of security equivalent to those described in this Policy.

7.2 Technology and Service Providers

The Company engages vetted third-party technology providers to support the delivery of our services. Our current categories of service providers include:

  • Cloud infrastructure and storage providers (hosting servers in jurisdictions with adequate data protection frameworks)
  • Email delivery service (Brevo) — used for OTP delivery only; no health data is transmitted
  • Push notification delivery services (Expo Push Service and Firebase Cloud Messaging)
  • Application performance monitoring and error logging providers
  • Customer support software providers

7.3 Legal and Regulatory Authorities

The Company may disclose personal data to governmental, law enforcement, judicial, or regulatory authorities where required by applicable law, court order, or lawful governmental request. In such cases, the Company will, to the extent permitted by law, notify you of any such disclosure.

7.4 Third-Party SDK Data Practices

SDK / ProviderPurposeData Handled
Firebase Cloud Messaging (Google LLC)Delivery of push notifications to usersPush notification tokens only. No health data.

The Company does not permit any third-party SDK to access, collect, or retain your Special Category Health Data. All SDK integrations are configured to ensure data minimization and to restrict data collection to the minimum necessary for the stated purpose.

8. International Data Transfers

The Company may transfer personal data outside Nepal to the extent necessary for cloud storage, technical support, and third-party service provision. In doing so, the Company ensures that an adequate level of protection is maintained through one or more mechanisms such as Standard Contractual Clauses (SCCs).

Special Category Restrictions

The Company does not transfer Special Category Health Data to jurisdictions that lack equivalent protections without your explicit written consent and without first conducting a Transfer Impact Assessment.

9. Data Retention

9.1 Retention Periods

Health and Medical Records

A minimum of ten (10) years from the date of last entry, in accordance with healthcare record retention standards in Nepal.

Account and Session Data

Active duration + six (6) years post account closure to fulfil legal claims or regulatory requirements.

Device and Technical Data

A maximum of thirteen (13) months from the date of collection.

Error and Stability Logs

Ninety (90) days from the date of generation.

9.2 Secure Disposal

Upon expiry of the applicable retention period, personal data is securely deleted or anonymized using industry-standard data destruction methods, including cryptographic erasure for cloud-stored data.

10. Your Rights

You have the following rights under this Policy, subject to applicable exceptions:

Access

Request confirmation of processing and obtain copies of your data.

Rectification

Require the correction of any inaccurate or incomplete personal data.

Erasure (Right to Be Forgotten)

Request the deletion of your personal data under certain conditions.

Restriction

Request restriction of processing under pending verification circumstances.

Data Portability

Receive your personal data in a structured, machine-readable format.

Object

Object to processing based on legitimate interests or direct marketing.

11. Data Deletion and Consent Withdrawal

11.1 In-Application Deletion Request

You may initiate a request to delete your account and associated personal data directly within the Application by navigating to Settings > Account > Privacy & Data > Delete My Account and Data. Upon confirmation, the Company will initiate the deletion process within seventy-two (72) hours.

The public account deletion page is available at: https://swastha.id/account-deletion

11.2 Deletion Request via Email

If you are unable to access the Application, you may submit a deletion request by emailing support@swastha.idwith the subject line "Data Deletion Request", including your full name and registered email address.

11.3 Withdrawal of Consent

You may withdraw consent for any specific category of data processing at any time by accessing Privacy Settings within the Application or by emailing the Data Protection Officer at privacy@swastha.id.

12. Data Security Measures

12.1 Technical Safeguards

  • End-to-end encryption of all health data transmitted using a minimum of TLS 1.3
  • Encryption at rest of all personal and health data stored on our servers using AES-256
  • Role-based access controls and Multi-factor authentication (MFA) for all staff accessing systems
  • Regular penetration testing conducted by independent cybersecurity firms
  • Secure device storage for mobile tokens and sensitive local cryptographic state

12.2 Personal Data Breach Notification

In the event of a personal data breach affecting your rights and freedoms, the Company will notify you without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach, alongside mandatory regulatory reporting.

13. Apple App Store Compliance

13.1 App Privacy Disclosures

In compliance with Apple App Store privacy disclosures, the following data types are collected and linked to your identity:

  • Health and fitness data (linked to identity) — used for health record management
  • Contact information (linked to identity) — used for account creation and communication
  • Identifiers (linked to identity) — used for account authentication
  • Usage data and Diagnostics (not linked to identity) — used for performance monitoring and application stability

13.2 Device Permission Disclosures

Camera Access: The Application requests access to your camera solely to enable you to photograph and upload medical documents, prescriptions, and diagnostic reports to your health record.

Microphone Access: Microphone access is not requested by the Application.

14. Children's Privacy

The Application is not directed at children under the age of sixteen (16) years. We do not knowingly collect personal data from children under sixteen without appropriate consent. Where the Application is used to manage a minor's records, it must be operated by a parent, legal guardian, or authorized adult caregiver.

15. Changes to This Privacy Policy

Material changes will be notified via in-app notification or email no fewer than thirty (30) calendar days prior to the change taking effect. Continued use of the Application constitutes your acknowledgement of the updated Policy.

16. Complaints

If you are not satisfied with our handling of your data, you are entitled to lodge a complaint with our Data Protection Officer at privacy@swastha.id. We commit to responding within thirty (30) calendar days of receipt.

17. Contact Information

For all enquiries, requests, or concerns relating to this Privacy Policy or your personal data, please contact:

Sai Industries Pvt. Ltd.

Attn: Data Protection Officer

Address: Lalitpur Metropolitan City-3, Lalitpur, Nepal