Privacy Policy
DATA PRIVACY POLICY
(DPDP ACT 2023 & CDSCO COMPLIANT)
Effective Date: 1st December 2025
1. PREAMBLE AND REGULATORY STATUS
Bionic Hope Private Limited (“Data Fiduciary”) protects your data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Medical Devices Rules, 2017.
1.1. ABDM Disclaimer:
Currently, Rehabilitation Services are not covered under the Ayushman Bharat Digital Mission (ABDM) ecosystem. Consequently, we do not currently create or link ABHA IDs. However, should future regulatory changes bring Rehabilitation under the purview of ABDM, Bionic Hope Private Limited commits to taking all necessary technical and legal measures to ensure full compliance.
2. DATA COLLECTION AND PROCESSING
We collect the following data based on your Affirmative Consent (via clear affirmative action/checkbox):
- Identity Data: Name, Patient ID (Internal), Contact Details.
-
Biometric & Health Data: Amputation details, stump & physiological measurements, and
MMG (Mechanomyography) signals collected via BrawnBand™.
- Note on MMG: MMG data measures mechanical muscle vibrations. While distinct from electrical EMG, it is treated as Sensitive Personal Data requiring high-level encryption.
- Financial Data: We do not store raw card data. All payments are processed via PCI-DSS compliant gateways (e.g., Razorpay). Robo Bionics is not liable for data breaches occurring at the Payment Gateway level.
3. DATA RETENTION POLICY (CDSCO MANDATE)
3.1. Mandatory Retention Period:
Pursuant to the Medical Devices Rules, 2017 and CDSCO guidelines for Class A/B medical devices, we are legally mandated to retain your technical health data (specifically MMG logs, device usage history, and fitment parameters) for a period of 5 (Five) Years from the date of the last log, usage entry, or profile update.
3.2. Exemption from Erasure:
The “Right to Erasure” under the DPDP Act 2023 is overridden by this statutory obligation. We cannot delete your data before the completion of this 5-year regulatory period.
4. DATA SECURITY AND MINORS
- Security: Data and its Communication are end-to-end encrypted at rest and in transit using TLS 1.3 and SHA-384 standards.
- Minors: For users under the age of 18, Verifiable Parental Consent is mandatory. We strictly prohibit tracking or behavioral monitoring of children for advertising purposes.
- Breach Notification: In the event of a personal data breach, we will notify the Data Protection Board of India and the affected users in compliance with Section 8(6) of the DPDP Act.
5. YOUR RIGHTS (DPDP ACT)
Subject to the retention laws mentioned in Clause 3, you have the right to:
- Access: Request a summary of your personal data processed by us.
- Correction: Request correction of inaccurate or misleading personal data.
- Grievance Redressal: Contact our Grievance Officer (details in Master Terms) for any privacy concerns.
© Bionic Hope Private Limited. All Rights Reserved.