Effective and last updated:13 August 2026
This policy is intended to operate consistently with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and notified rules as their provisions come into force, the Information Technology Act, 2000, and other applicable privacy and consumer laws.
1. Scope, operator, and key roles
HomoeoRx is a health-education and practitioner-support platform operated by Chhayarani Technologies Pvt. Ltd. In this policy, "HomoeoRx", "we", "us", and "our" refer to that legal entity. This policy applies when you visit homoeorx.com, use a HomoeoRx application, create an account, purchase a subscription, contact support, or use a learning or practitioner feature.
Data fiduciary and legal entity:Chhayarani Technologies Pvt. Ltd.
Business address:C/236/301, Spandan, Kadampukur, North 24 Pargana 700135
For account, learning, subscription, website, and support data, we generally determine why and how data is processed. For patient or case information entered by a practitioner, the practitioner may independently determine the clinical purpose and remain responsible for authority, consent, accuracy, confidentiality, and lawful use. We process that information to provide the practitioner-requested service and for limited security and legal purposes.
2. Personal data we collect
Depending on the features you choose, we may collect the following categories:
- Account and profile data: name, email address, mobile number, account type, login identifiers, profile settings, preferred language, and authentication records.
- Practitioner registration data: professional category, registration details, qualifications, verification documents, practice details, and verification status where professional access is requested.
- Learning data: searches, learning history, bookmarks, notes, flashcards, quiz responses, progress, saved comparisons, and feature preferences.
- Practitioner and case data: case narratives, symptoms, clinical notes, follow-up entries, attachments, reports, images, repertorisation selections, remedy comparisons, and patient identifiers entered by an authorised practitioner.
- Voice and media data: microphone input, voice recordings, transcripts, images, files, and related metadata when you actively use voice, upload, scan, or attachment features.
- Support and grievance data: name, contact details, account reference, request topic, message, complaint evidence, correspondence, and resolution records. Public support forms instruct users not to submit patient data, Aadhaar numbers, passwords, OTPs, or complete payment-card details.
- Transaction data: subscription plan, purchase channel, transaction reference, price, tax and invoice details, entitlement status, refund status, and limited payment metadata. Card, UPI, bank, and wallet credentials are handled by the relevant payment provider and are not intended to be stored by HomoeoRx.
- Technical and usage data: IP address, device and browser type, operating system, app version, language, time zone, referral page, session and event data, crash diagnostics, performance records, and security logs.
- Communications and preferences: service notices, consent choices, notification preferences, survey responses, and records of privacy or account-deletion requests.
3. How we receive personal data
- Directly from you when you register, use features, upload content, purchase, or contact us.
- From a practitioner or institution that is authorised to create or administer an account or record.
- Automatically from your device, application, browser, cookies, SDKs, logs, and security systems.
- From authentication, app-store, payment, analytics, messaging, and support providers involved in a transaction or requested feature.
- From public or official professional registers where practitioner credentials are lawfully verified.
If you provide personal data about another person, you represent that you are authorised to do so, have given any required notice, and have obtained any required consent.
4. Purposes and legal grounds for processing
We process personal data only for specified, lawful purposes, including to:
- Create and secure accounts, authenticate users, verify practitioners, and manage access.
- Provide learning, search, note, record, voice, transcription, repertorisation, export, follow-up, and clinical decision-support features selected by the user.
- Process purchases, verify subscription entitlements, issue invoices, prevent duplicate billing, and administer cancellations or refunds.
- Respond to support, privacy, grievance, safety, and account-deletion requests.
- Maintain service reliability, diagnose errors, monitor performance, prevent fraud or abuse, investigate security incidents, and enforce our terms.
- Improve features using aggregated, de-identified, or appropriately controlled data and user feedback.
- Comply with applicable law, lawful government or court requests, accounting obligations, and regulatory directions.
Under applicable Indian data-protection law, processing may be based on your consent, your voluntary provision of data for a specified purpose, certain legitimate uses recognised by law, compliance with a legal obligation, or another lawful ground. Where consent is the basis, you may withdraw it as easily as it was given. Withdrawal does not invalidate prior lawful processing, and a feature may stop working where its required data can no longer be processed.
5. Health, patient, and case information
Practitioner workflows can contain highly private health and case information. A practitioner must collect and upload only what is necessary, use suitable identifiers, obtain all required patient or authorised-person consent, restrict access, and comply with professional recordkeeping and confidentiality duties. HomoeoRx must not be used as the only copy of a record that a practitioner is legally or professionally required to keep.
Do not upload Aadhaar numbers, payment credentials, passwords, OTPs, or unrelated identity documents. Where an image, voice file, report, or narrative contains third-party data, the uploading user is responsible for confirming that its collection and use are authorised. We do not sell patient or case records and do not use them for targeted advertising.
6. AI-assisted processing and automated output
Prompts, selected learning context, voice transcripts, case narratives, symptoms, and related content may be processed by automated systems to generate explanations, extract or organise information, suggest follow-up questions, support search, compare remedies, or provide decision-support output. Only information reasonably needed for the requested feature should be submitted.
AI output can be incomplete, outdated, biased, or incorrect. It is not an autonomous diagnosis or prescription and is not used by HomoeoRx to make a final clinical decision. Students may use it only for education. Qualified practitioners must independently review every output and remain responsible for examination, diagnosis, prescription, potency, dose, repetition, monitoring, referral, and emergency action.
7. App permissions, cookies, and analytics
A mobile application may request microphone, camera, photo, file, storage, or notification permission only when needed for a user-selected feature. Device settings can be used to withdraw a permission, although the related feature may then be unavailable.
The website and application may use essential storage, cookies, analytics, crash-reporting, and similar technologies to maintain sessions, remember preferences, measure reliability, and understand feature use. Where law requires consent for a non-essential technology, we will request it. Browser controls can restrict cookies, but doing so may affect account or preference features.
9. Processing and transfers outside India
Some cloud, app-store, analytics, support, or payment providers may process data in India or other countries. Where a cross-border transfer occurs, we apply applicable contractual and technical safeguards and comply with restrictions notified under Indian law. Certain records may be retained in India where a legal direction requires localisation.
10. Security and incident response
We use reasonable and proportionate safeguards such as encrypted network transport, identity and access controls, restricted administrative privileges, logging, secure development practices, backups, provider reviews, and incident-response procedures. Security measures are reviewed according to risk and applicable legal requirements.
No online service can guarantee absolute security. Users must use a strong, unique password, protect devices and OTPs, sign out of shared devices, and promptly report suspected misuse. Where a personal-data breach requires notification, we will notify the affected person and competent authority in the form and time required by applicable law.
11. Retention, account closure, and deletion
We retain each category only for its service, security, dispute, or legal purpose:
- Account, profile, and learning data are generally kept while the account is active and through the verified deletion process.
- Practitioner case records remain available according to account controls until deleted by an authorised user or the account is closed, subject to backup cycles and lawful retention.
- Voice files are retained only as required to complete the requested feature or when the user intentionally saves them as part of a record; associated transcripts may follow the retention of that record.
- Support, consent, grievance, and deletion records are retained for a reasonable audit and dispute period after closure.
- Invoices, transaction references, refunds, and accounting records are retained for the period required by tax, company, payment, and financial-record laws.
- Security and access logs are retained under our security schedule and for any minimum period required by applicable cyber-security directions.
Deletion from active systems may not immediately remove encrypted backup copies. Backups are isolated, expire through scheduled cycles, and are not restored except for continuity or security recovery. Data subject to a legal hold, fraud investigation, dispute, or mandatory recordkeeping obligation may be restricted and retained until that purpose ends.
Request account deletion without signing in12. Your choices, rights, and duties
Subject to applicable law and identity verification, you may ask us to:
- Provide a summary of personal data being processed and the processing activities.
- Correct inaccurate or misleading data, complete incomplete data, or update changed data.
- Erase personal data that is no longer required or must be erased by law.
- Withdraw consent and manage available communication, permission, and analytics choices.
- Receive information about the grievance process and nominate another person to exercise rights where applicable law permits.
A request may be limited where retention or processing is required by law, needed to establish or defend a legal claim, protects another person, or falls within a lawful exception. Users must not impersonate another person, suppress material information, or submit a false or frivolous grievance.
13. Children and student accounts
Practitioner accounts are for adults who are appropriately qualified and legally permitted to use professional features. A student under 18 may use eligible educational features only with verifiable consent from a parent or lawful guardian where required. We do not knowingly use a child's personal data for targeted advertising or behavioural monitoring. A parent or guardian may contact us to review, correct, or delete a child's account data.
14. Third-party links and services
HomoeoRx may link to app stores, payment providers, research sources, or other independent services. Their privacy notices govern processing they control. Review those notices before providing data. We are not responsible for an independent service's privacy practices.
15. Changes to this policy
We may update this policy when features, providers, or law change. The revised page will show its effective date. Where a change materially affects the purpose of processing or requires fresh consent, we will provide an appropriate in-product or account notice before applying it as required by law.
16. Privacy and grievance contact
Submit a privacy request through the public support page and choose "Privacy", or use the public email below. We may verify identity before disclosing, correcting, or deleting data. The on-screen submission receipt provides a reference number that should be retained for follow-up.
Grievance Officer:GRIEVANCE_OFFICER_NAME_PLACEHOLDERRequired before launch
Designation:Grievance Officer - HomoeoRx
Privacy and grievance email:SUPPORT_EMAIL_PLACEHOLDERRequired before launch
Customer-care phone:SUPPORT_PHONE_PLACEHOLDERRequired before launch
Postal address:C/236/301, Spandan, Kadampukur, North 24 Pargana 700135
We aim to acknowledge consumer complaints within 48 hours and resolve them within one month, subject to the nature of the complaint and any information required from the user. This does not restrict any right to approach a competent statutory authority, consumer commission, court, or the Data Protection Board of India when its jurisdiction and the relevant provisions apply.
Open the secure support and grievance form17. Indian legal framework
This policy should be read with applicable Indian law. Official materials are available from the following Government of India sources: