Your data, clearly explained
Privacy Policy
This notice explains how ApnaPatho handles personal data while helping you compare and book partner laboratories, arranging home sample collection, transporting samples and delivering laboratory reports.
The short version
- We use health and contact information to provide the services you request.
- We share necessary information with the selected lab, assigned collector and contracted service providers.
- We do not sell personal data or use children's data for targeted advertising.
- You can ask to access, correct or erase data, withdraw consent, or raise a grievance.
1. Who we are and what this policy covers
ApnaPatho is operated by Kanasda Orbix (OPC) Private Limited (“ApnaPatho”, “we”, “us” or “our”). For the personal data processed through our website, mobile application, support channels and collection operations, we act as the Data Fiduciary.
Our registered office is: S/o. Jageshwar Kasyap, Kansada School Ke Samne, Kansda, Seorinarayan, Janjgir-Champa – 495557, Chattisgarh, India.
This policy applies to patients, family-account holders, doctors, collection personnel, laboratory users and other people who interact with ApnaPatho. Partner laboratories may separately act as Data Fiduciaries for laboratory testing, report validation and records they must maintain under applicable healthcare laws.
2. Personal data we process
Depending on how you use ApnaPatho, we process the following categories:
Account and identity data
Name, mobile number, login and verification records, account role, referral code, account creation date and authentication-security information.
Patient and health data
Patient name, date of birth, sex, relationship to the account holder, prescriptions, selected tests, test reports, relevant collection instructions and doctor-consent records.
Booking and collection data
Collection or walk-in preference, address, location coordinates when you choose to provide them, appointment date and time, assigned collector, sample barcode, specimen and tube details, fasting checks, collection and handover timestamps, and rejection or recollection details.
Payment and transaction data
Order value, discounts, credits, payment mode and status, gateway transaction references, refunds and settlement records. Payment-card or bank credentials are handled by the payment provider and are not stored by ApnaPatho in full.
Professional and partner data
Doctor registration and clinic details, laboratory registration and accreditation information, and collection-personnel qualifications, assignments and work records.
Communications and technical data
Support requests, feedback, notification history, device or browser information, IP and request information, session records, and audit and security logs.
We ask you to provide only information that is accurate and that you are authorised to provide, including when you create a profile for a family member.
3. Why we process personal data
We process personal data only for lawful, specified purposes, including to:
- create and secure your account and verify your mobile number;
- compare laboratories, prices, availability and expected report times;
- create bookings, collect payments, apply credits and process refunds;
- schedule a home collection or laboratory visit and coordinate the assigned personnel;
- identify, collect, label, track and safely deliver a sample to the selected laboratory;
- process prescriptions, confirm test selections and resolve low-confidence extraction results;
- deliver reports and enable consent-controlled access for a treating or booking doctor;
- send transactional messages about OTPs, bookings, collections, payments and reports;
- respond to support requests, grievances and privacy-rights requests;
- prevent fraud, secure our systems, investigate incidents and maintain audit trails; and
- meet tax, accounting, payment, clinical-establishment, public-health and other legal obligations.
We generally rely on your consent and on processing information you voluntarily provide to obtain a requested service. We may also process data where another lawful ground or legal duty applies. Optional marketing, if introduced, will use a separate choice and can be stopped at any time.
5. Home sample collection and partner labs
For a home collection, ApnaPatho coordinates the collection personnel, patient and appointment details, collection address, identity checks, specimen labelling, chain of custody and transport to the selected laboratory. The assigned collector receives only the information needed for that job.
The partner laboratory performs the diagnostic testing, quality control and report validation and issues the laboratory report. ApnaPatho does not independently diagnose illness or interpret your results. Please discuss results with a qualified healthcare professional.
Biological samples are handled and disposed of under applicable clinical, laboratory and biomedical-waste requirements. This privacy policy primarily governs digital personal data linked to the sample, such as its barcode, status and chain-of-custody events.
6. Prescription extraction and AI
When prescription extraction is enabled, an uploaded prescription image or PDF may be sent to a contracted AI service provider, such as Anthropic, to suggest the names of prescribed laboratory tests. The suggestion may be reviewed by authorised ApnaPatho personnel and shown for confirmation.
AI output does not diagnose a condition, interpret a report, select a laboratory, take payment or book a test by itself. Where a prescription is unclear, a human review is required. You may instead select tests manually where that option is available.
7. Children and guardian-managed profiles
ApnaPatho login accounts are intended for adults aged 18 or over. A parent or lawful guardian may create and manage a patient profile for a child and book health services on the child's behalf. The account holder must be authorised to provide the child's information and consent to the collection procedure and necessary data sharing with the selected laboratory.
We do not knowingly use children's personal data for behavioural monitoring or targeted advertising. If we learn that a child created an independent account without appropriate guardian involvement, we may restrict the account while we verify the guardian or arrange deletion or transfer to a guardian-managed profile.
8. Retention and erasure
We retain personal data only while it is needed for the stated purpose, an active account or booking, security and dispute resolution, or a legal requirement. Retention depends on the type of record:
- account, patient-profile and saved-address data is kept while the account or profile is active;
- prescriptions and reports are kept so they remain available in the account and are erased when an applicable verified erasure request is completed, unless law requires retention;
- booking, payment, invoice, refund and settlement records may be retained for statutory accounting, tax, fraud-prevention and dispute periods, with identifying fields removed where possible; and
- consent, access, audit and security records are kept for the period required to demonstrate compliance, investigate unauthorised access and meet applicable legal logging requirements.
When erasure applies, we delete or irreversibly anonymise information from active systems and take reasonable steps regarding processors. Limited copies may remain in protected backups until their normal overwrite cycle, or where preservation is legally required.
9. Security and breach communication
We use access controls, role-based permissions, authentication safeguards, encrypted transport, encrypted object storage, audit logs, monitoring, backups and organisational controls appropriate to the nature of health and identity information. Access to reports is limited to the patient or family-account holder, the issuing laboratory, authorised administrators and a doctor with valid recorded consent. Collection personnel cannot view laboratory reports.
No system is completely risk-free. If a personal-data breach affects you, we will communicate the known nature and likely consequences, mitigation measures, steps you can take and a contact for questions without delay, and notify the Data Protection Board of India and other authorities where required.
10. Your privacy rights
Subject to applicable law and identity verification, you may ask us to:
- provide a summary of your personal data and processing activities;
- identify the categories of Data Fiduciaries and processors with whom data has been shared;
- correct inaccurate or misleading data and complete or update incomplete data;
- erase data that is no longer required for a specified purpose or by law;
- withdraw consent as easily as it was given, including consent for doctor access;
- raise a grievance about our handling of personal data; and
- nominate another individual to exercise your rights in the event of death or incapacity.
You can permanently delete an eligible account through Account settings. See our account and data deletion instructions for the app, website and support-request options. Active bookings may need to be completed or cancelled first, and legally required transaction records may be retained in anonymised or minimised form. You can make any other request using the contact details below. We may verify control of your registered mobile number before acting.
Withdrawing consent does not make earlier lawful processing invalid. It may prevent us from offering a future service that cannot be performed without the relevant data, but does not stop processing required to complete an already-requested service or comply with law.
11. Device storage and international processing
The website and application use necessary device storage for authentication, cart and booking state. We do not currently use this storage for targeted advertising. Reports that you intentionally save or share outside ApnaPatho may remain on your device or with the destination you selected and are then subject to your device settings and that recipient's practices.
Some contracted technology providers may process data outside India. Where this occurs, we remain responsible for using lawful providers and contractual safeguards and will comply with restrictions notified by the Government of India. Certain security logs may be retained in India as required by law.
12. Grievances and contact details
Contact the Privacy and Grievance Officer, Kanasda Orbix (OPC) Private Limited to exercise a right, withdraw consent, report a concern or ask a question about processing.
Email: support@spellstudy.com
Phone: +91 77228 85101
Post: S/o. Jageshwar Kasyap, Kansada School Ke Samne, Kansda, Seorinarayan, Janjgir-Champa – 495557, Chattisgarh, India.
Please use “ApnaPatho privacy request” in the subject and provide your registered mobile number and the nature of your request. Do not email a password, OTP, full payment credentials or an unnecessary copy of a medical report. We aim to respond within 30 days, subject to identity verification and law.
If you are dissatisfied after giving us an opportunity to resolve the grievance, you may complain to the Data Protection Board of India using the official mechanism made available by the Government. Information about the Board is available on the Ministry of Electronics and Information Technology website.
We may update this policy when our services, providers or legal obligations change. Material changes will be communicated through the website, application or registered contact channel as appropriate.