REJUVENATE Digital Health is committed to operating in full compliance with all applicable laws and regulations governing digital health services in India. This page outlines the key legislative frameworks under which we operate.
1. Information Technology Act, 2000 (IT Act)
REJUVENATE Digital Health complies with the Information Technology Act, 2000 and its subsequent amendments, including the IT (Amendment) Act, 2008. Our obligations include:
- Maintaining reasonable security practices and procedures as mandated under Section 43A.
- Implementing IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 for handling sensitive personal data, including health records.
- Providing a clear Privacy Policy in compliance with Rule 4 of the SPDI Rules.
- Not disclosing sensitive personal data or information to third parties without prior written consent of the user, except where required by law.
2. Digital Personal Data Protection Act, 2023 (DPDP Act)
We align our data practices with the Digital Personal Data Protection Act, 2023 (DPDP Act), India's landmark personal data protection legislation. Our commitments include:
- Lawful Processing: Personal data is processed only for legitimate purposes with the explicit consent of the Data Principal (user).
- Purpose Limitation: Data collected is used solely for the purpose for which it was obtained and is not retained beyond the required period.
- Data Minimisation: We collect only the minimum personal data necessary for the delivery of our services.
- Rights of Data Principal: Users have the right to access their data, correct inaccuracies, nominate a representative, and withdraw consent at any time.
- Data Fiduciary Obligations: As a Data Fiduciary, we ensure data accuracy, implement appropriate security safeguards, and report any personal data breach to the Data Protection Board of India and affected users without undue delay.
- Children's Data: We do not knowingly process personal data of children under the age of 18 without verifiable parental consent.
3. Telemedicine Practice Guidelines, 2020
All telehealth and online consultation services facilitated through this Portal comply with the Telemedicine Practice Guidelines issued by the Ministry of Health and Family Welfare (MoHFW), Government of India, in March 2020, as appended to the Indian Medical Council Act, 1956.
- Only Registered Medical Practitioners (RMPs) listed with the National Medical Register or State Medical Registers are permitted to provide online consultations through our platform.
- Doctors are responsible for maintaining patient confidentiality and adhering to professional ethical standards during telemedicine consultations.
- Prescriptions issued via telemedicine conform to applicable guidelines regarding drugs that may or may not be prescribed via teleconsultation.
- Patients are informed about the limitations of telemedicine, and emergencies are directed to in-person care.
4. National Medical Commission (NMC) Act, 2019
REJUVENATE Digital Health ensures that all medical professionals associated with our platform are verified against the National Medical Register maintained under the NMC Act, 2019. We do not allow unregistered or de-registered practitioners to offer services through our Portal. Any complaints regarding professional misconduct can be referred to the concerned State Medical Council or the National Medical Commission.
5. Ayushman Bharat Digital Mission (ABDM) & ABHA Compliance
REJUVENATE Digital Health participates in and complies with the Ayushman Bharat Digital Mission (ABDM) framework governed by the National Health Authority (NHA):
- ABHA (Ayushman Bharat Health Account) creation and linkage is facilitated in accordance with NHA-prescribed processes.
- Patient health records shared through ABDM-linked systems adhere to the Health Data Management Policy published by the NHA.
- Consent for sharing health data is obtained electronically and in accordance with the Health Data Management Policy.
- We do not access or share ABDM-linked health records without explicit, informed, and revocable consent of the patient.
6. Clinical Establishments (Registration & Regulation) Act, 2010
Where applicable, REJUVENATE Digital Health ensures that partner clinical establishments are duly registered under the Clinical Establishments Act, 2010 or relevant State-level equivalents. We encourage partner hospitals and clinics to maintain their registrations in good standing and comply with the prescribed standards of services.
7. Consumer Protection Act, 2019
In accordance with the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020, REJUVENATE Digital Health:
- Provides clear, accurate information about all services offered on this Portal.
- Does not engage in unfair or restrictive trade practices.
- Maintains a Grievance Redressal mechanism (see below) to address user complaints promptly.
- Ensures that all charges, fees, and service terms are disclosed transparently before the user commits to any service.
8. School Health Programme Compliance
The School Health Portal module of REJUVENATE Digital Health operates in alignment with:
- National School Health Programme guidelines issued by MoHFW.
- RTE Act, 2009 provisions regarding student privacy and welfare.
- POCSO Act, 2012 — Health data of minors is treated with the highest level of confidentiality and protection.
- Data of students is accessible only to authorised school administrators and healthcare professionals assigned to the school.
9. Data Localisation & Security Standards
All personal data and health records of Indian users are stored on servers located within the territory of India, in compliance with applicable data localisation requirements. We implement the following security standards:
- SSL/TLS encryption for all data in transit.
- Encrypted storage for sensitive health records and personally identifiable information (PII).
- Role-based access controls limiting data access to authorised personnel only.
- Regular security audits and vulnerability assessments.
- Incident response plan for data breaches, with mandatory notification to affected users and authorities.
10. Grievance Redressal Mechanism
In compliance with the IT Act, DPDP Act, and Consumer Protection Act, we have appointed a Grievance Officer to address any complaints or concerns regarding our services or data practices.
Complaints may be submitted via email, phone, or our Contact Us page.
11. Compliance Updates
The legal and regulatory landscape for digital health in India is evolving rapidly. REJUVENATE Digital Health is committed to reviewing and updating its compliance practices as new laws, guidelines, or notifications are issued by relevant authorities including MoHFW, NHA, MeitY, NMC, and the Data Protection Board of India.
This page will be updated whenever there are material changes to our compliance framework. We encourage users to check this page periodically.
Related Legal Documents
Privacy Policy — How we collect, use, and protect your personal data.
Terms & Conditions — Rules governing your use of this Portal.
Disclaimer — Important limitations regarding content on this Portal.