1. App & Company Information
App Name: My Health Vault® (Patient App)
Company:
DRCFO MANAGEMENT CONSULTANTS PRIVATE LIMITED
(“Company”, “We”, “Us”, “Our”)
Website: www.drcfo.in
My Health Vault® is a privately developed, patient-facing digital health application that enables users to securely manage personal health records, book appointments, access healthcare services, and make payments where applicable.
This Privacy Policy explains how personal data is collected, processed, stored, shared, and protected in accordance with the Digital Personal Data Protection Act, 2023 (India) and other applicable laws.
2. Relationship Between My Health Vault & DRCFO HMIS
My Health Vault® is the patient-side application of the DRCFO digital health platform.
DRCFO HMIS is the doctor-side clinic and hospital management system, and both applications are integral components of the same private platform, owned, developed, and operated exclusively by DRCFO Management Consultants Private Limited.
3. No Government Affiliation or Authorization (Important Disclaimer)
My Health Vault® is a privately owned and privately operated application.
• The Application does not represent any government entity
• The Application does not provide, facilitate, or deliver any government service
• The Application is not owned, endorsed, authorized, or operated by the Government of India or any government authority
Any references to government programs, platforms, or institutions are made solely for informational transparency regarding technical interoperability and do not imply government ownership, partnership, endorsement, or authorization.
4. References to Government Programs & Public Sources
The DRCFO platform includes technical interoperability with certain nationally recognized digital health ecosystems. These references are included only to explain interoperability and compliance status and are supported by official public sources, including:
• Ayushman Bharat Digital Mission (ABDM)
DRCFO HMIS is listed as an HMIS partner under ABDM (National Health Authority, Government of India).
Official public source: https://abdm.gov.in/our-partners
(Section: HMIS Partners | Registration Date: 15 May 2023)
• AIIMS New Delhi – Clinical Decision Support System (CDSS)
DRCFO HMIS is technically integrated with the AIIMS New Delhi CDSS under the ABDM ecosystem.
Official public source: https://abdm.gov.in/aiims-cdss/partners
These references do not indicate any government service delivery through My Health Vault®.
5. User Consent
By downloading, accessing, or using the Application, you:
• Confirm that you have read and understood this Privacy Policy
• Provide free, specific, informed, and unconditional consent for lawful processing of your personal data
• Acknowledge that withdrawal of consent may restrict access to certain features or services
If you use the Application on behalf of another person, including a minor, you confirm that you are legally authorized to do so.
6. Information We Collect
6.1 Information You Provide
• Name
• Mobile number
• Email address
• Date of birth
• Gender
• Address and PIN code
6.2 Health-Related Data
• Medical records, prescriptions, reports, and test results
• Appointment and consultation history
• Health conditions, diagnoses, and treatment details
• Biometric information, only if explicitly enabled and required
6.3 Payment Information (If Applicable)
• Transaction details and payment confirmations
Payments are processed through secure third-party payment gateways. We do not store card, UPI, or banking credentials.
6.4 Automatically Collected Information
• App usage and interaction logs
• Device information, operating system, and app version
• IP address, timestamps, analytics data, and crash reports
7. Permissions Used by the Application
Permissions are requested strictly on an as-needed basis:
• Location: Nearby clinics and region-based services
• Camera: Uploading medical documents
• Microphone: Teleconsultation features (if enabled)
The Application does NOT access or collect contacts or phonebook data.
8. Purpose of Data Processing
Data is processed only for lawful purposes, including:
• Account creation and management
• Secure health record storage and access
• Appointment and healthcare service facilitation
• Payment processing (where applicable)
• Customer support and technical assistance
• Performance, security, and service improvement
• Compliance with applicable Indian laws
9. ABDM / NHA Alignment (Interoperability Only)
The platform is designed to align with ABDM ecosystem principles such as:
• Consent-based data sharing
• Purpose limitation and data minimization
• Privacy-by-design architecture
Any ABDM or ABHA-related functionality operates only on user consent and does not constitute a government service.
10. Data Sharing & Disclosure
We do not sell or trade personal or health data.
Data may be shared only with:
• Authorized healthcare providers (upon user request)
• Payment gateways for transactions
• Authorized technology partners under confidentiality obligations
• Government authorities where legally required
11. Data Retention
Data is retained only as long as necessary for:
• Active account usage
• Service delivery
• Legal and regulatory requirements
12. Data Processing Location
All personal and health data is processed and stored within India.
Where processing involves systems outside India, it is done only in jurisdictions permitted under the DPDP Act, 2023, with equivalent data protection safeguards.
13. Data Security
We implement administrative, technical, and physical safeguards.
Encryption:
All personal and health data is protected using industry-standard encryption at rest and in transit.
14. Rights of Users (DPDP Act)
Users have the right to:
• Access and correct personal data
• Withdraw consent
• Request erasure (subject to law)
• Nominate another person to exercise rights
15. Children’s Privacy
The Application is not intended for independent use by minors.
Use by minors requires parental or legal guardian authorization.
16. Grievance Redressal & Resolution Timeline
All data-related grievances shall be resolved within 7 (seven) days.
Grievance Officer:
Name: CA Akhil Kumar
Designation: CEO
Company: DRCFO Management Consultants Private Limited
Address:
Flat No. C-5, 2nd Floor, K.K. Apartment,
Opposite Narmada Bhawan (Near Ganna Sansthan),
Dalibagh, Lucknow – 226001, Uttar Pradesh, India
Email: akhil@drcfo.in
Unresolved grievances may be escalated to the Data Protection Board of India.
We prioritize safeguarding your personal information and ensuring your online privacy.
DRCFO MANAGEMENT CONSULTANTS PRIVATE LIMITED (hereinafter the “Company”, “We”, “Us”, and “Our” interchangeably) is the owner of the Website www.drcfo.in and the Mobile Application (hereinafter “Application” which includes the Website, Software program, data and documentation related thereto), and provides services related to health data management, online appointments with healthcare professional, Clinic management, Clinic administration, Patient Management, Accounts & Inventory management along with Legal compliance management and other related services (collectively referred to as “Service/Services”) for integrated health care management for patients and healthcare professionals. This Privacy Policy must be read in conjunction with the Terms of Use. Any capitalized term used but not defined in this Privacy Policy shall have the meaning attributed to it in our Terms of Use. We are committed to Your privacy. This privacy policy (“Privacy Policy”) applies to Your use of and access to the Services and the collection, use, storage, sharing, processing, disclosure, and transfer of Your Information including Your Personal Information when You access and/or use the Services. You are advised to carefully read this Privacy Policy before using or accessing any of Our Services. Our Privacy Policy is applicable to every User who accesses our Application and/or uses Our Services (referred to as “You”, “User” or “Your” as applicable) from any device.
This Privacy Policy states the type of information collected from the Users, the purpose, means, and modes of collection, usage, processing, retention, and destruction of such information; and how and to whom We will disclose such information.
We may require the User to pay with a credit card, wire transfer, debit card, or cheque for Services for which subscription amount(s) is/are payable. We will collect such User’s credit card number and/or other financial institution information such as bank account numbers and will use that information for the billing and payment processes, including but not limited to the use and disclosure of such credit card number and information to third parties as necessary to complete such billing operation. Verification of credit information, however, is accomplished solely by the User through the authentication process. Users’ credit card/debit card details are transacted upon secure sites of approved payment gateways which are digitally under encryption, thereby providing the highest possible degree of care as per current technology. However, We provide you an option not to save your payment details. User is advised, however, that internet technology is not completely safe and User should exercise discretion on using the same.
We strongly encourage parents and guardians to supervise the online activities of their minor children and consider using parental control tools available from online services and software manufacturers to help provide a child-friendly online environment. These tools also can prevent minors from disclosing their name, address, and other Personal Information online without parental permission. Although Our Services are not intended for use by minors, if You are a minor, You may use Our Application and Services only with the involvement of a parent or guardian and through a Parent controlled Account.
If you wish to opt-out of receiving non-essential communications such as promotional and marketing-related information regarding the Services, please send us an email at the email provided below. We reserve the right to continue to keep a copy of any of your Personal Information if required by law. We may use any aggregated/anonymized data derived from your Account, in a matter which shall not infringe upon your privacy.
We maintain a strict “No-Spam” policy, which means that We do not intend to sell, rent, or otherwise give your e-mail address to a third party without your consent.
We use Cookies and similar tracking technologies (For example, Web beacons, Pixels, Software Development Kits (SDKs), etc) to track the activity on Our Service and store certain information. Some of these cookies are essential for Us to provide You with Our Service. We or our third-party service providers may use cookies, mobile app analytics, and similar technologies to track visitor activity and collect data while You use/access Our Service. We may combine this data with other Personal information We have collected from the User. “Cookies” means small pieces of information used to store on web browsers that the Website can retrieve at a later time. Cookies are used to receive and store identifiers and other information on computers, phones, and other devices. Cookies include other technologies, including data that we store on Your web browser or device, identifiers associated with Your device, and other software, which are used for similar purposes. Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on your device when You go offline, while Session Cookies are deleted as soon as You close your web browser. You can change cookie settings in the help section of Your browser. You should be aware that the deactivation of cookies can influence Your experience of Our Service.
Our Service may contain links to other websites that are not operated by Us. If You click on a Third-party link, You will be directed to that third party’s website and/or mobile application or similar service. We strongly advise You to review the Terms and/or Privacy Policy and/or supplementary rules/guidelines of every website/mobile application You visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third party sites or services. You further acknowledge and agree that We shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any such content, goods, or service available on or through any such websites or services.
The Service accessed and used may be regulated by the applicable local laws and regulations on the protection of natural persons with regard to the collection, use, storage and processing of personal data and on the free movement of such data. You may reach out to Us at the email provided in Grievance Redressal Mechanism with the subject line “Data Protection compliance”. We respond to all requests We receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws of India.
We may update Our Privacy Policy from time to time. We will notify You of any updation by posting the new Privacy Policy on this page and update the “Last updated Notice” date at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
To report any grievance with respect to the Application or Our Services, including any discrepancies and grievances with respect to the processing of information, you can contact our Grievance Officer at: Name: CA Akhil Kumar Address: C 5, 2nd Floor K K Apartment Opposite Narmada Bhawan (Near Ganna Sansthan) Dalibagh – Lucknow Pin -226001 Phone: 91-94150-20199 Email: akhil@drcfo.in
If you have any questions concerning the Company, the Application, the Terms, this Agreement, the Services, or anything related to any of the foregoing, or you wish to give your comments/feedback, You can reach us at the following email address mentioned below or using the Contact Us option in the Application. Unless otherwise specified herein, all notices or other communications under or in connection with this Agreement shall be given in writing and may be sent by personal delivery or post acknowledgment due) or courier (with POD) or E- mail as mentioned below. Any such notice or other communication will be deemed to be effective if sent by personal delivery, (when delivered) if sent by registered post (ack due) (on actual receipt), and if sent by courier (on actual receipt), and if sent by E-mail, (on receipt of confirmation to the correct Email id). Name: CA Akhil Kumar Designation: CEO Address: C 5, 2nd Floor K K Apartment Opposite Narmada Bhawan (Near Ganna Sansthan) Dalibagh – Lucknow Pin -226001 Email ID: akhil@drcfo.in
DRCFO MANAGEMENT CONSULTANTS PRIVATE LIMITED (hereinafter the “Company”, “We”, “Us”, and “Our” interchangeably) is the owner of the Website www.drcfo.in and the Mobile Application (hereinafter “Application” which includes the Website, Software program, data and documentation related thereto), and provides services related to health data management and online appointments with healthcare professional and other related services (collectively referred to as “Service/Services”) for integrated health care management for patients. This Privacy Policy must be read in conjunction with the Terms of Use. Any capitalized term used but not defined in this Privacy Policy shall have the meaning attributed to it in our Terms of Use. We are committed to Your privacy. This privacy policy (“Privacy Policy”) applies to Your use of and access to the Services and the collection, use, storage, sharing, processing, disclosure, and transfer of Your Information including Your Personal Information when You access and/or use the Services. You are advised to carefully read this Privacy Policy before using or accessing any of Our Services. Our Privacy Policy is applicable to every User who accesses our Application and/or uses Our Services (referred to as “You”, “User” or “Your” as applicable) from any device.
This Privacy Policy states the type of information collected from the Users, the purpose, means, and modes of collection, usage, processing, retention, and destruction of such information; and how and to whom We will disclose such information.
We may require the User to pay with a credit card, wire transfer, debit card, or cheque for Services for which subscription amount(s) is/are payable. We will collect such User’s credit card number and/or other financial institution information such as bank account numbers and will use that information for the billing and payment processes, including but not limited to the use and disclosure of such credit card number and information to third parties as necessary to complete such billing operation. Verification of credit information, however, is accomplished solely by the User through the authentication process. Users’ credit card/debit card details are transacted upon secure sites of approved payment gateways which are digitally under encryption, thereby providing the highest possible degree of care as per current technology. However, We provide you an option not to save your payment details. User is advised, however, that internet technology is not completely safe and User should exercise discretion on using the same.
We strongly encourage parents and guardians to supervise the online activities of their minor children and consider using parental control tools available from online services and software manufacturers to help provide a child-friendly online environment. These tools also can prevent minors from disclosing their name, address, and other Personal Information online without parental permission. Although Our Services are not intended for use by minors, if You are a minor, You may use Our Application and Services only with the involvement of a parent or guardian and through a Parent controlled Account.
If you wish to opt-out of receiving non-essential communications such as promotional and marketing-related information regarding the Services, please send us an email at the email provided below. We reserve the right to continue to keep a copy of any of your Personal Information if required by law. We may use any aggregated/anonymized data derived from your Account, in a matter which shall not infringe upon your privacy.
We maintain a strict “No-Spam” policy, which means that We do not intend to sell, rent, or otherwise give your e-mail address to a third party without your consent.
We use Cookies and similar tracking technologies (For example, Web beacons, Pixels, Software Development Kits (SDKs), etc) to track the activity on Our Service and store certain information. Some of these cookies are essential for Us to provide You with Our Service. We or our third-party service providers may use cookies, mobile app analytics, and similar technologies to track visitor activity and collect data while You use/access Our Service. We may combine this data with other Personal information We have collected from the User. “Cookies” means small pieces of information used to store on web browsers that the Website can retrieve at a later time. Cookies are used to receive and store identifiers and other information on computers, phones, and other devices. Cookies include other technologies, including data that we store on Your web browser or device, identifiers associated with Your device, and other software, which are used for similar purposes. Cookies can be “Persistent” or “Session” Cookies. Persistent Cookies remain on your device when You go offline, while Session Cookies are deleted as soon as You close your web browser. You can change cookie settings in the help section of Your browser. You should be aware that the deactivation of cookies can influence Your experience of Our Service.
Our Service may contain links to other websites that are not operated by Us. If You click on a Third-party link, You will be directed to that third party’s website and/or mobile application or similar service. We strongly advise You to review the Terms and/or Privacy Policy and/or supplementary rules/guidelines of every website/mobile application You visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third party sites or services. You further acknowledge and agree that We shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with the use of or reliance on any such content, goods, or service available on or through any such websites or services.
The Service accessed and used may be regulated by the applicable local laws and regulations on the protection of natural persons with regard to the collection, use, storage and processing of personal data and on the free movement of such data. You may reach out to Us at the email provided in Grievance Redressal Mechanism with the subject line “Data Protection compliance”. We respond to all requests We receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws of India.
We may update Our Privacy Policy from time to time. We will notify You of any updation by posting the new Privacy Policy on this page and update the “Last updated Notice” date at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
To report any grievance with respect to the Application or Our Services, including any discrepancies and grievances with respect to the processing of information, you can contact our Grievance Officer at: Name: CA Akhil Kumar Address: C 5, 2nd Floor K K Apartment Opposite Narmada Bhawan (Near Ganna Sansthan) Dalibagh – Lucknow Pin -226001 Phone: 91-94150-20199 Email: akhil@drcfo.in
If you have any questions concerning the Company, the Application, the Terms, this Agreement, the Services, or anything related to any of the foregoing, or you wish to give your comments/feedback, You can reach us at the following email address mentioned below or using the Contact Us option in the Application. Unless otherwise specified herein, all notices or other communications under or in connection with this Agreement shall be given in writing and may be sent by personal delivery or post acknowledgment due) or courier (with POD) or E- mail as mentioned below. Any such notice or other communication will be deemed to be effective if sent by personal delivery, (when delivered) if sent by registered post (ack due) (on actual receipt), and if sent by courier (on actual receipt), and if sent by E-mail, (on receipt of confirmation to the correct Email id). Name: CA Akhil Kumar Designation: CEO Address: C 5, 2nd Floor K K Apartment Opposite Narmada Bhawan (Near Ganna Sansthan) Dalibagh – Lucknow Pin -226001 Email ID: akhil@drcfo.in
DRCFO MANAGEMENT CONSULTANTS PRIVATE LIMITED, a company incorporated under the laws of India, is recognized as a start-up by the Department for Promotion of Industry and Internal Trade, Government of India Having Registration no DIPP61037.
India, being one of the largest populated countries, facing a huge gap in the demand and supply of the Healthcare services, and not every individual gets the treatment in time. There are many healthcare professionals who due to ineffective record-keeping, prescription management, and mishandling of emergencies are not able to help their patients despite having the medical acumen and resources to handle such situations. This primarily happens due to a lack of technological up-gradation and skills or unavailability of a cost-effective solution that can smoothen the administrative work of a healthcare professional thereby reallocating time wasted on such work to the needs of the patients.
Copyright © 2025-2026, DRCFO All rights reserved.