This Privacy Policy describes how MRI Guwahati ("we", "us", or "our") collects, uses, and safeguards information about users of our website mriguwahati.in and our digital booking services. We comply with the Digital Personal Data Protection Act 2023 (DPDP Act) and applicable Indian regulations on data protection.
1. Who we are
MRI Guwahati is a digital booking platform operated from Christian Basti, Guwahati, Assam 781005, India. We help patients discover and book MRI scans at partner diagnostic centres in Guwahati. We are an aggregator; we do not perform scans or issue radiology reports ourselves.
2. Information we collect
We collect the following categories of information:
- Account information: name, mobile number, email address, password (stored as a one-way hash), and account preferences.
- Booking information: scan type, partner centre, date and time slot, patient name, age, gender, and any notes you add.
- Health information: documents you upload, including doctor prescriptions, previous reports, and any clinical notes you add. Health information is processed only for the purpose of completing your booking and is shared with the partner centre that performs the scan.
- Payment information: payment is processed by Razorpay. We receive tokenised confirmation, transaction IDs, and amounts. We do not store card numbers, UPI IDs, or bank account numbers.
- Technical information: IP address, device type, browser type, language, referring URL, and pages visited. We use this to operate, secure, and improve the service.
- Usage information: bookings made, reports downloaded, and support interactions.
3. How we use information
We use the information to:
- Create and manage your account.
- Process bookings, payments, refunds, and rescheduling.
- Share necessary booking and clinical information with the partner centre performing your scan.
- Deliver SMS, email, and WhatsApp notifications about your booking and reports.
- Provide customer support and respond to queries.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with applicable Indian laws.
4. Who we share information with
- Partner diagnostic centres: the centre you book with receives the information needed to perform the scan, including patient details, prescription, and any clinical notes you provide.
- Payment processor: Razorpay processes online payments on our behalf.
- Communication providers: MSG91 sends SMS notifications and Resend handles email delivery.
- Cloud and hosting providers: our servers are hosted on managed services in India.
- Government authorities: when required by law, including responses to lawful requests from courts or regulators.
We do not sell your personal information to advertisers or data brokers. We do not allow partner centres to use your information for marketing.
5. Data retention
We retain account information as long as your account is active. Booking and report records are retained as long as you have a registered account, so you can access them in the future. You may request deletion of your account at any time. Some records may be retained for the period required by accounting and tax laws, typically 8 years.
6. Your rights under the DPDP Act
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or outdated information.
- Request deletion of your personal data, subject to legal retention requirements.
- Withdraw consent for processing where consent is the legal basis.
- Lodge a grievance with our Grievance Officer or the Data Protection Board of India.
To exercise these rights, write to privacy@mriguwahati.in. We respond within 7 working days.
7. Cookies and analytics
We use essential cookies to keep you logged in and to remember your preferences. We use Google Analytics 4 to understand site usage in aggregate. Analytics is loaded only after you accept the cookie banner. See our Cookie Policy for the full list of categories.
8. Security
We use HTTPS across the site, encrypted database connections, hashed passwords, and signed URLs for report downloads. Health documents are stored in a non-public location and only accessible via authenticated requests with short-lived signed URLs. We follow industry standard practices to detect and respond to security incidents.
9. Children
Our service is not intended for children under 18. Parents or guardians may book scans on behalf of minors using their own accounts.
10. Changes to this policy
We may update this policy from time to time. We will notify you of material changes via email or via a banner on the site. The "Last updated" date at the top reflects the latest revision.
11. Grievance Officer
For complaints or concerns related to your personal data, contact our Grievance Officer at privacy@mriguwahati.in. Postal address: Grievance Officer, MRI Guwahati, Christian Basti, Guwahati, Assam 781005, India.