Legal & Compliance · oraskinclinics.com

Privacy Policy

How ORA Skin, Hair & Aesthetics collects, uses, protects and respects your personal information — in full compliance with India's Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025.

DPDP Act 2023 & Rules 2025 IT Act 2000 Compliant Google Ads Healthcare Compliant Meta Healthcare Policy Compliant Medical Confidentiality Protected
Last updated: April 2026 Effective from: April 2026 Review frequency: Annually or on regulatory change
01

Who We Are & What This Policy Covers

ORA Skin, Hair & Aesthetics (trading name; hereinafter "ORA", "we", "us", or "our") is a dermatology and aesthetic clinic located at Avalon Court, 3rd Floor, Camelot Layout, Botanical Garden Road, Kondapur, Hyderabad, Telangana — 500084. Our website is accessible at oraskinclinics.com.

As a healthcare provider, we are deeply committed to protecting the privacy, confidentiality and security of all personal information shared with us — including health-related information. We are a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and we process your data in accordance with these laws and all applicable regulations.

This Privacy Policy applies to: (a) visitors and users of oraskinclinics.com; (b) individuals who submit enquiries, book appointments, or contact us through our website, WhatsApp, phone or in person; (c) existing and former clients of ORA Skin, Hair & Aesthetics.

This Privacy Policy should be read alongside our Terms & Conditions. Together, these documents form the complete agreement governing your use of ORA's services and website. For any privacy-related concerns, contact us at dm@oraskinclinics.com.

02

What Personal Data We Collect

We collect only the data that is necessary for the specific purpose for which it is collected (the principle of data minimisation under DPDP Act, 2023 Section 4). We collect data through our website forms, WhatsApp, phone calls, and during in-person visits.

Category Data Collected How Collected
Identity Data Full name, gender (optional) Appointment booking form, in-person registration
Contact Data Mobile number, email address (optional), city / area of residence Website form, WhatsApp, phone, in-person
Health & Treatment Data Nature of skin or hair concern selected at enquiry, treatment history at ORA, medical history relevant to treatment, prescription records, consultation notes Enquiry form (treatment selection), in-clinic consultation, doctor assessments
Communication Data WhatsApp messages, call records (summary only), email correspondence Direct communication with ORA
Usage Data Pages visited on oraskinclinics.com, browser type, IP address (anonymised), session duration Google Analytics 4 (anonymised — no personal data collected)
Marketing Data Whether you opted into promotional communications, source of your referral (e.g., Google, Instagram) Website forms, verbal consent at clinic

What we do NOT collect: We do not collect Aadhaar number, PAN, financial/bank account details, passwords, or any biometric data through our website or as part of standard clinic procedures. We do not collect information from individuals under 18 years of age without explicit parental consent.

03

Why We Use Your Data

Under the DPDP Act, 2023, we must have a lawful purpose for processing your data. We use your personal data only for the following clearly stated purposes:

Appointment Scheduling & Management
To confirm, reschedule, or cancel your appointments. To send reminders via WhatsApp, SMS or phone call. To allocate the appropriate doctor and treatment room.
Providing Medical and Aesthetic Treatment
To enable our dermatologists to review your skin or hair concern prior to and during consultation. To maintain your treatment records, prescriptions, session notes and progress documentation for your ongoing care at ORA.
Communication About Your Enquiry or Treatment
To respond to your questions submitted via the website, WhatsApp or phone. To provide pre- and post-treatment care instructions. To follow up on your treatment progress when clinically appropriate.
Marketing Communications (With Consent Only)
With your explicit consent, to send information about new treatments, offers, and ORA news via WhatsApp, SMS or email. You may withdraw this consent at any time by messaging us at dm@oraskinclinics.com or replying "STOP" to any SMS/WhatsApp. Additionally, by submitting our website form, you authorise ORA to contact you even if your number is registered under DND/DNC/NCPR, solely for the purposes of responding to your enquiry and appointment management.
Website Analytics (Anonymised)
To understand how our website is used and improve our content. We use Google Analytics 4 with IP anonymisation enabled. No personally identifiable data is transmitted to Google Analytics.
Legal and Regulatory Compliance
To comply with legal obligations including the Indian Medical Council Act, Consumer Protection Act 2019, DPDP Act 2023, and any applicable Telangana state health regulations. To respond to lawful requests from government authorities or courts.

We will not use your data for any purpose other than those listed above without notifying you and, where required, seeking your fresh consent.

05

Who We Share Your Data With

We do not sell, rent or trade your personal data to any third party. Ever. Your health information is treated with the same confidentiality as any medical record.

We may share your data in limited circumstances, only as described below:

Internal Team Members
Dermatologists, clinic staff and administrative personnel at ORA Skin, Hair & Aesthetics who need access to provide your treatment. All staff are bound by confidentiality obligations.
Service Providers (Data Processors)
Third-party service providers who help us operate our business — including our website hosting provider (Vercel), appointment management software, and SMS/WhatsApp communication platforms. These providers are bound by data processing agreements and may not use your data for their own purposes. They are classified as Data Processors under DPDP Act, 2023.
Advertising Platforms
We use Google Analytics (anonymised, non-personal), Google Ads conversion tracking (non-sensitive event-level data only), and Meta Pixel (non-health-related event signals only). We configure these tools to ensure no health data or personally identifiable information is transmitted. Meta Pixel is used in Limited Data Use mode.
Legal and Regulatory Authorities
Where required by Indian law, court orders, or lawful requests from government authorities. We will notify you of such disclosure to the extent permitted by law.
Referral Practitioners
If your treatment requires referral to a specialist or hospital, we will share relevant clinical information only with your explicit consent.
06

Health Data & Medical Confidentiality

All health-related information you share with ORA Skin, Hair & Aesthetics — including your skin and hair concerns, treatment preferences, medical history, and consultation notes — is treated as confidential medical information. This is consistent with the ethical obligations of our board-certified dermatologists under the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations, 2002.

Patient Medical Confidentiality Commitment: ORA's doctors and staff will not disclose your health information, treatment history or consultation details to any person outside your direct care team without your explicit written consent — except as required by law (e.g. court order, notifiable disease report, or public health emergency). This commitment applies during and after your treatment relationship with ORA.

Treatment photographs or results, if taken with your consent, are stored securely and will not be shared publicly, used in marketing, or posted on social media without your separate written consent specifically for that purpose.

07

Testimonials & Before/After Photographs

If ORA wishes to use your testimonial, review text, or before/after photographs in marketing materials — on the website, social media, advertisements or any other channel — we will:

Obtain Written Consent
Request and secure your explicit written consent before using any identifiable testimonial or photograph in any marketing context. Consent forms will clearly specify how the content will be used, where it will appear, and the duration of use.
Right to Withdraw
You may withdraw consent for the use of your testimonial or photograph at any time by contacting us at dm@oraskinclinics.com. We will remove the content from all active marketing materials within 30 days of your request. Content already published in print may be phased out as materials are reprinted.
DPDP Act Compliance
Linking your name, neighbourhood or initials to a named treatment type in public content (website, advertisements) may make you identifiable to people who know you. Under DPDP Act 2023, publishing personal health information linked to an identifiable individual requires explicit, specific consent. We will not attribute testimonials to identifiable persons without such consent on file.
08

How Long We Keep Your Data

We retain your personal data only for as long as necessary for the stated purpose. Under the DPDP Act 2023, personal data must not be retained beyond what is required.

Data Type Retention Period Reason
Appointment and enquiry records 3 years from last appointment Ongoing client relationship management
Clinical treatment records, prescriptions, consultation notes 7 years from last treatment Medical record-keeping obligations; Indian Medical Council guidelines recommend minimum 3 years; we retain 7 years to comply with consumer and contract law timelines
Before/after photographs (with consent) Duration of consent or 5 years, whichever is earlier Medical documentation; marketing if consented
Marketing communications consent records Until consent is withdrawn + 1 year Proof of consent compliance
Website analytics data (anonymised) 26 months (Google Analytics default) Website improvement; cannot identify individuals
WhatsApp and email enquiries 2 years from last communication Reference for relationship continuity

When data reaches the end of its retention period or your purpose of processing is no longer valid, we will securely delete or anonymise it.

09

Your Rights as a Data Principal

Under the DPDP Act, 2023 and DPDP Rules, 2025, you have the following rights as a Data Principal (the individual whose data is being processed). These rights are free to exercise. Contact us at dm@oraskinclinics.com to exercise any of these rights. We will respond within 30 days of receiving your request.

Right to Access
Request a summary of the personal data we hold about you and the purposes for which it is processed.
Right to Correction
Request correction of inaccurate, outdated or incomplete personal data we hold about you.
Right to Erasure
Request deletion of your personal data when it is no longer needed for the stated purpose, subject to our legal retention obligations (e.g. medical records).
Right to Withdraw Consent
Withdraw consent for marketing communications, or any other processing based on consent, at any time. Withdrawal does not affect the lawfulness of prior processing.
Right to Grievance Redressal
Lodge a complaint about our data processing practices. We will respond within 30 days. If unresolved, you may approach the Data Protection Board of India.
Right to Nominate
Nominate an individual who may exercise these rights on your behalf in the event of your death or incapacity, in accordance with DPDP Act, 2023.
10

How We Protect Your Data

We implement reasonable technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, or disclosure, as required under the DPDP Act, 2023 and DPDP Rules, 2025 (Rule 6 — Reasonable Safeguards).

Website Security
Our website is served over HTTPS (SSL/TLS encryption). All data transmitted between your browser and our website is encrypted in transit.
Data Access Controls
Access to personal data and clinical records is restricted to authorised personnel only. Staff with access to patient data are bound by confidentiality obligations.
Data Breach Notification
In the event of a personal data breach that is likely to affect you, we will notify affected individuals and the Data Protection Board of India as required under DPDP Act, 2023 and within the prescribed timeline (72-hour notification standard).
Third-Party Processor Safeguards
We require all third-party service providers who process data on our behalf (Data Processors under DPDP Act) to maintain appropriate security standards and process data only on our documented instructions.

While we take all reasonable precautions, no data transmission over the internet or electronic storage system can be guaranteed as completely secure. We strongly advise against sharing sensitive medical information via public platforms.

11

Cookies & Tracking Technologies

Our website uses the following cookies and tracking technologies:

Technology Purpose Personal Data?
Google Analytics 4 Website usage analytics — pages visited, session duration, device type. IP anonymisation is enabled. No — anonymised only
Google Ads Conversion Tag Tracking whether a user submitted an enquiry form after clicking an ad. Non-health event signals only. No health data. Anonymised conversion event only.
Meta Pixel Tracking whether a user submitted a form (Lead event). Configured in Limited Data Use mode. No treatment type or health signals transmitted. No health data. Anonymous Lead event only.
Session / Functional Cookies Essential for website functionality — maintaining your session, form state. Session-only. Deleted when browser is closed.

You may disable non-essential cookies by adjusting your browser settings. This may affect some website functionality. We do not use cookies to target healthcare-related advertisements or to infer health conditions. Our advertising cookies transmit only anonymised, non-health signals to comply with Google and Meta healthcare advertising policies.

12

Children's Privacy

Our website and services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from anyone under 18 through our website.

Where a minor (below 18 years) is brought to ORA for treatment, we require explicit consent from a parent or legal guardian before collecting any personal or health data relating to that minor. The parent or guardian's data is used to manage the relationship. This is consistent with the DPDP Act, 2023 provisions on children's data, which require verifiable parental or guardian consent.

13

Changes to This Privacy Policy

We review and update this Privacy Policy at least annually, or sooner when there are changes in applicable law (including DPDP Act / Rules updates), changes in our data processing practices, or following a data protection review. All updates are effective immediately upon posting to this page.

The "Last updated" date at the top of this page indicates when this policy was most recently revised. We recommend reviewing this page periodically. Material changes will be communicated via a notice on our website or via direct contact with known clients.

14

Contact Us About Privacy

For any privacy-related questions, requests to exercise your rights, or concerns about our data practices, please contact us using the details below. We will respond within 30 days of receiving your request.

Data Fiduciary: ORA Skin, Hair & Aesthetics
Address: Avalon Court, 3rd Floor, Camelot Layout, Botanical Garden Road, Kondapur, Hyderabad, Telangana — 500084
Privacy Contact Email: dm@oraskinclinics.com (Subject: Privacy Request)
Phone: +91 99893 61555 · Monday–Sunday, 9AM–8PM IST
Unsubscribe from Marketing: Reply "STOP" to any WhatsApp/SMS, or email dm@oraskinclinics.com with Subject: Unsubscribe
Data Protection Board of India: If your grievance is not resolved within 30 days, you may lodge a complaint with the Data Protection Board of India once it is constituted and operational under the DPDP Act, 2023.

This Privacy Policy is governed by the laws of India. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts in Hyderabad, Telangana, India.