Privacy Policy for Healthcare Providers

Wekitsak Platform

Effective Date: November 11, 2025

Version: 1.0

This Privacy Policy describes how Essenzvita Life Sciences Private Limited ("Essenzvita") collects, uses, protects, and discloses personal data of healthcare providers ("Providers") who register for or use the Wekitsak platform. This Policy should be read in conjunction with the Platform Terms of Service and the Data Processing Agreement.

This Policy applies to personal data of Providers themselves. The processing of patient data is governed separately by the Data Processing Agreement, wherein Providers act as Data Fiduciaries and Essenzvita acts as Data Processor.

By registering an account or using the platform, you consent to the practices described in this Policy.

1. INFORMATION COLLECTED

We collect information in three primary ways: information you provide directly, information collected automatically through platform usage, and information obtained from third parties.

Information Provided Directly.

During registration and account management, you provide personal information including full name, email address, mobile number, date of birth, gender, residential and professional addresses, National Medical Commission or State Medical Council registration number, medical qualifications and specializations, years of practice, and clinic or hospital affiliation details. Identity verification requires submission of documents such as medical degree certificates, registration certificates, government-issued identity documents, and professional credentials. Payment processing requires bank account details or UPI information for refunds where applicable, though payment card details are processed by third-party gateways and not stored by Essenzvita. You may optionally provide profile photographs, professional biographies, consultation fees, languages spoken, and working hours. Communications with support, feedback submissions, and grievance filings are also collected and retained.

Automatically Collected Information.

Platform usage generates logs containing IP addresses, device identifiers, browser type and version, operating system, pages accessed, features used, actions performed, timestamps, session duration, and error reports. Location data is inferred from IP addresses and, with your permission, from device geolocation services. Cookies and similar technologies maintain session state and facilitate analytics.

Third-Party Information.

We verify credentials with medical councils using publicly available registration databases. Payment confirmation and transaction status are received from payment processing partners. Where authorized by you, background verification providers may furnish identity confirmation or credential validation.

2. USE OF INFORMATION

Personal data is used for account administration including creation, maintenance, authentication, and credential verification. Service delivery requires this data to provide platform access, process subscription payments, facilitate communications, and enable collaboration features. We send transactional communications regarding account status, password resets, subscription renewals, and platform updates, as well as administrative notices concerning legal compliance and security. Marketing communications are sent only to those who have opted in and may include promotional offers, educational content, and feature announcements; opt-out mechanisms are always provided.

Usage data informs platform improvement through analysis of usage patterns, research and development, feature testing, and bug identification. Security and fraud prevention measures utilize this data to detect unauthorized access, monitor suspicious activity, investigate incidents, and prevent abuse.

Legal compliance requires retention of certain data for tax reporting, responding to lawful requests from courts or regulators, enforcing terms of service, and protecting Essenzvita's rights and interests.

Aggregated and de-identified data derived from usage patterns may be used for analytics, published research, or shared with third parties. Such data cannot be traced to individual Providers.

3. DATA SHARING AND DISCLOSURE

Your professional profile information may be visible to other Providers on the platform and, when directory features are enabled, to patients seeking healthcare providers. Participation in collaborative consultations makes your name and credentials visible to other participating clinicians.

Service providers engaged to operate the platform receive data necessary for their functions. Cloud hosting providers store all platform data. Payment processors handle transaction processing. SMS and email service providers deliver notifications. Analytics tools process usage data for platform improvement. These providers are contractually obligated to protect data and use it only for specified purposes.

Disclosure to legal and regulatory authorities occurs when required by law, court order, or regulatory demand; when necessary to protect life or safety; to investigate fraud or illegal activity; or to enforce our rights. We will provide notice of such disclosures unless prohibited by law.

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. The successor must honor this Privacy Policy. You will be notified of any such transfer.

We may share your information with others only where you have provided explicit consent, such as for participation in research studies or sharing your profile with professional associations.

Your personal data is never sold to third parties, shared with marketers without consent, or publicly disclosed.

4. INTERNATIONAL TRANSFERS

Personal data is primarily stored on servers located in India. However, certain service providers, particularly those providing analytics or support tools, may be located outside India or may store data on international servers. Cross-border transfers are subject to contractual safeguards including standard contractual clauses where applicable and encryption during transmission.

By using the platform, you consent to such international transfers as necessary for platform operation.

5. DATA SECURITY

Technical security measures include encryption of data in transit using TLS 1.2 or higher and encryption of data at rest using AES-256. Access controls limit data access to authorized personnel only, with role-based permissions and multi-factor authentication for sensitive operations. Network security is maintained through firewalls, intrusion detection systems, and regular vulnerability assessments. All access is logged and monitored for anomalous activity.

Organizational measures include confidentiality agreements signed by all personnel, regular security training, documented incident response procedures, and audit logging of data access.

Despite these measures, no system is entirely secure. We cannot guarantee absolute protection against all threats.

You are responsible for maintaining strong passwords, enabling available security features, not sharing credentials, logging out of shared devices, and reporting suspicious activity promptly.

6. DATA RETENTION

Account information is retained for the duration of your active account and for three years following account closure or termination for purposes of legal compliance and dispute resolution. Professional credentials are retained for five years post-termination to address regulatory inquiries. Payment records are retained for seven years pursuant to tax and accounting requirements. Usage logs are retained for five years for security monitoring and compliance purposes. Communications with support are retained for three years. De-identified data may be retained indefinitely as it no longer constitutes personal data.

After retention periods expire, data is securely deleted or anonymized through removal from active databases and deletion from backup systems within the next backup cycle.

7. YOUR RIGHTS

Under the Digital Personal Data Protection Act 2023, you have certain rights with respect to your personal data.

You may request access to confirm what personal data we hold and obtain a copy thereof. Requests should be submitted to the Data Protection Officer contact provided below. We will respond within thirty days. The first request in a twelve-month period is provided at no charge; subsequent requests may be subject to a reasonable fee.

You may request correction of inaccurate or incomplete data. Many profile fields can be updated directly through account settings. For other data, contact support. Corrections will be made within fifteen days of verification.

You may request portability of your data in a structured, machine-readable format such as CSV or JSON. Such requests are fulfilled within thirty days at no charge.

You may request erasure of your personal data subject to legal retention requirements. Deletion requests are processed within thirty days. We may decline requests where retention is required by law, necessary for ongoing legal matters, or necessary to enforce our terms. Refusals will be explained in writing.

You may withdraw consent for data processing at any time, though this may result in inability to provide platform services. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.

You may nominate another person to exercise your rights in the event of death or incapacity. Nomination procedures will be made available when implementing regulations are issued.

If you believe your privacy rights have been violated, you may file a complaint with our Grievance Officer. We will acknowledge complaints within twenty-four hours and resolve within fifteen days. If unsatisfied, you may escalate to the Data Protection Board of India.

8. DATA BREACH NOTIFICATION

In the event of a breach affecting your personal data, we will notify you within seventy-two hours of discovery. Notification will describe the nature and extent of the breach, measures being taken to contain and remediate it, and steps you should take to protect yourself. We will simultaneously notify the Data Protection Board as required by law.

You should promptly change passwords if advised, monitor for suspicious activity, and report concerns to us immediately.

9. COOKIES AND TRACKING

Session cookies maintain your logged-in state. Analytics cookies help us understand platform usage through tools such as Google Analytics. Preference cookies remember your settings. You may block cookies through browser settings, though this may impair platform functionality. Most analytics tools offer opt-out mechanisms.

10. CHILDREN

The platform is intended for licensed medical professionals aged eighteen or older. We do not knowingly collect data from minors. Any data inadvertently collected from minors will be deleted upon discovery.

11. MODIFICATIONS

We may update this Policy from time to time. Material changes will be communicated via email with thirty days' advance notice. The updated Policy will display a revised "Last Updated" date. Continued use after changes constitutes acceptance. If you do not accept changes, you should cease using the platform and may request deletion of your data.

12. GOVERNING LAW

This Policy is governed by Indian law, including the Digital Personal Data Protection Act 2023 and Information Technology Act 2000. Disputes are subject to the jurisdiction of courts in Kolhapur, Maharashtra, or resolution through the dispute mechanisms specified in the Platform Terms of Service.

13. CONTACT INFORMATION

Grievance & Data Protection Officer:

Yogesh Vyas

Email: [email protected]

Essenzvita Life Sciences Private Limited

Registered Office: 383/3A/4B, Pl No. 9, 13th Lane, Rajarampuri,

Kolhapur, Maharashtra 416008

CIN: U86905PN2023PTC218619

This Privacy Policy is effective as of the date stated above. Your use of the platform constitutes acknowledgment of and agreement to this Policy.

END OF PRIVACY POLICY