Plain-language summary
Super Vitals is a health records and clinical workflow platform. We collect personal and health data to provide the service. We never sell, rent, or use your health data for advertising. You can request deletion of your data at any time. This policy is governed by India's Digital Personal Data Protection Act, 2023.
1. Information We Collect
We collect the following categories of information when you use Super Vitals:
| Category | Data collected | Purpose |
|---|---|---|
| Identity & Contact | Full name, phone number, date of birth, gender | Account creation & verification |
| Profile | Profile photo (optional) | Personalisation |
| Health Documents | Lab reports, prescriptions, pharmacy bills, audiometry, pathology, vision prescriptions, PFT reports, and other medical documents you upload | Document storage & retrieval |
| Health Vitals | Blood pressure, blood glucose, SpO₂, weight, heart rate, and other vitals you record | Health tracking & monitoring |
| Medications & Reminders | Medication names, dosages, schedules, and reminder times | Medication management |
| Hydration Data | Daily water and fluid intake logs, drink types, quantities, and hydration goals | Hydration tracking |
| Women's Health Data | Menstrual cycle data, symptoms, and related health information you choose to record | Women's health tracking |
| IPD / Admission Records | Hospital admission details, ward information, nursing notes, MAR records, and in-patient vitals | In-patient care management |
| Appointment Data | Consultation records, doctor visit history, appointment scheduling data | Appointment management |
| Device & App Data | Push notification token, app version, operating system type | Notification delivery |
| Camera / Storage | Photos or scanned images of documents (only when you choose to capture or upload) | Document scanning & upload |
2. Sensitive Health Data
Important
Super Vitals collects sensitive personal data as defined under India's Digital Personal Data Protection Act, 2023 — specifically health and medical information, women's health data, and clinical records. We apply the highest standard of protection to this data.
- Sensitive health data is stored in encrypted form and is never shared with third parties for advertising, profiling, or commercial purposes.
- Women's health data (menstrual cycle, symptoms) is treated as strictly confidential and is accessible only to you.
- IPD and clinical records are accessible only to authorised healthcare professionals within your registered organisation.
- We do not use your health data to train machine learning models or for any purpose beyond delivering the Service to you.
- We collect only the data necessary to provide the features you use. You can choose not to use certain features (e.g., women's health tracking) and no related data will be collected.
3. How We Use Your Information
4. Data Sharing & Third Parties
We do not sell, rent, trade, or share your personal or health data with any third party for commercial purposes. To operate the platform, we work with the following categories of service providers who act solely as data processors on our behalf:
| Provider type | Purpose | Data shared |
|---|---|---|
| Cloud database & file storage | Stores account data, health records, and uploaded documents | All user data |
| Push notification service | Delivers medication and health reminders to your device | Device token, notification content |
| Cloud hosting provider | Hosts the Super Vitals web application and API | Processed request data |
All third-party providers are contractually bound to process your data only as instructed by us, apply appropriate security measures, and comply with applicable data protection law. We also disclose data when required to do so by law, court order, or governmental authority.
5. Data Retention & Deletion
We retain your personal and health data for as long as your account is active and as necessary to provide the Service.
How to delete your account and data
Send a deletion request to info@humanmindlabs.com with the subject line “Account Deletion Request” and the phone number registered to your account. We will permanently and irreversibly delete all your personal and health data within 30 days of receiving the request.
We may retain certain data for a longer period where required by law (e.g., for tax, legal, or regulatory compliance). In such cases, we retain only the minimum data required and will notify you if applicable.
6. Your Rights under the DPDP Act 2023
Under India's Digital Personal Data Protection Act, 2023, you have the following rights regarding your personal data:
Right to access
Request a copy of the personal data we hold about you.
Right to correction
Request correction of inaccurate or incomplete data.
Right to erasure
Request permanent deletion of all your personal data.
Right to withdraw consent
Withdraw consent for processing at any time (may affect Service availability).
Right to grievance redressal
Raise a complaint with our Data Protection Officer within the platform or by email.
Right to nominate
Nominate another individual to exercise your rights in the event of death or incapacity.
To exercise any right, email info@humanmindlabs.com. We respond within 30 days.
7. Security
We implement industry-standard security controls to protect your data:
Row-level security
Database-enforced isolation ensures you can only access your own data.
Encrypted transit & storage
All data is encrypted in transit (TLS 1.2+) and at rest.
Role-based access
Healthcare staff access is limited to patients within their organisation only.
No electronic transmission or storage method is 100% secure. While we use commercially reasonable measures, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
8. Children's Privacy
Super Vitals is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. Patients under 18 may only use the platform with the consent and supervision of a parent or legal guardian who accepts this Privacy Policy on their behalf.
If you believe a child has provided us with personal data without parental consent, please contact us at info@humanmindlabs.com and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via push notification or email at least 7 days before changes take effect, and update the “Last updated” date at the top of this page. Continued use of Super Vitals after changes take effect constitutes acceptance of the updated policy.
We encourage you to review this policy periodically. Previous versions are available upon request.
10. Contact Us
For any questions, concerns, or data rights requests regarding this Privacy Policy, contact our Data Protection Officer:
Company
Human Mind Labs Private Limited
CIN: U72900GJ2024PTC000000
Address
Mehsana, Gujarat — 384315, India
General enquiries
info@humanmindlabs.com