NEIMHAANS

Privacy Policy

Privacy Policy How NEIMHAANS collects, uses & protects your data GDPR  ·  DPDP Act 2023 & DPDP Rules 2025  ·  neimhaans.in

Effective date: 16 August 2026  |  Last updated: 16 August 2026  |  Version: 2.0

In short: NEIMHAANS is a non-clinical medical-travel navigation service. We collect only the information you choose to share — chiefly through our contact form and WhatsApp — and use it solely to help your family plan hospital care in South India. We do not sell your data or use it for third-party advertising. You can ask us to access, correct, or delete your information at any time by writing to care@neimhaans.in. This policy is written to meet India’s Digital Personal Data Protection (DPDP) Act 2023 and DPDP Rules 2025, the EU/UK GDPR, and Google’s trust and transparency expectations for health-related (YMYL) websites.

1. Who we are (the Data Fiduciary)

NEIMHAANS — Healthcare Navigation & Medical Travel Support (“NEIMHAANS”, “we”, “us”, “our”) operates the website neimhaans.in. We are a non-clinical service that helps families — particularly from Northeast India — coordinate hospital selection, travel, stay, and on-ground support for treatment in South India.

For the purposes of the DPDP Act 2023 we act as the Data Fiduciary (equivalent to a “data controller” under the GDPR) for the personal data you share with us. You, the individual whose data we process, are the Data Principal (“data subject” under the GDPR).

Contact & Grievance Officer
NEIMHAANS — Healthcare Navigation & Medical Travel Support
Email: care@neimhaans.in
Phone / WhatsApp: +91 70907 77372
Website: neimhaans.in  ·  Contact page

All privacy questions, consent withdrawals, and grievances may be addressed to the Grievance Officer at the email above. We aim to acknowledge requests within 72 hours and resolve them within the timelines required by applicable law.

2. Important medical & service disclaimer

NEIMHAANS is not a hospital, clinic, doctor, or healthcare provider. We do not provide medical advice, diagnosis, or treatment, and nothing on this website should be treated as a substitute for professional medical care. Information on neimhaans.in is for general guidance only. Always consult a qualified doctor or accredited hospital for any medical decision. We help you navigate care — the clinical relationship is always between you and the hospital or physician you choose.

3. Scope of this policy

This policy explains what personal data we collect through neimhaans.in and our communication channels (email, phone, and WhatsApp), why we collect it, the legal grounds we rely on, who we share it with, how long we keep it, and the rights you have. It applies to visitors and enquirers wherever they are located, including individuals in India, the European Economic Area (EEA), and the United Kingdom.

4. Key definitions

  • Personal data / personal information — any information about an identifiable individual, such as your name, email, phone number, or the details you share in a message.
  • Processing — any operation performed on personal data (collecting, storing, using, sharing, or deleting it).
  • Data Fiduciary / Data Controller — the entity that decides why and how personal data is processed. That is NEIMHAANS.
  • Data Principal / Data Subject — the individual the personal data relates to. That is you.
  • Data Processor — a third party that processes data on our behalf and under our instructions (for example, our website host or analytics provider).
  • Consent Manager — under the DPDP framework, a registered platform through which a Data Principal may give, manage, review, and withdraw consent. Where such services become available and applicable, you may use them to manage your consent with us.

5. Information we collect

5.1 Information you give us directly

When you complete our contact form (“Contact NEIMHAANS”) we collect the fields you submit:

  • Full name
  • Email address
  • Phone / WhatsApp number
  • Your city & state (optional)
  • Type of support needed (optional)
  • Your free-text message describing how we can help your family

If you contact us on WhatsApp, by phone, or by email, we receive your number or email address and the content of that conversation. If you leave a comment on a blog post, we collect the name, email address, and website you provide, together with your IP address and browser (user-agent) string, which are used for spam detection.

5.2 Information we collect automatically

When you visit neimhaans.in, we and our service providers may automatically collect limited technical data:

  • Usage & analytics data via Google Analytics / Google Site Kit — pages viewed, approximate (city/country-level) location derived from your IP address, device and browser type, referring source, and on-site behaviour. This is collected using cookies and similar technologies.
  • Server & security logs — IP address, date and time of access, and pages requested, kept by our hosting and caching layer (LiteSpeed) to operate the site securely and diagnose problems.

We do not knowingly collect payment-card details through this website. Any payments for treatment or services are made directly to the hospital or provider concerned.

6. Sensitive & health-related information

Please share only what is necessary. The “How can we help your family?” field is free text, and families sometimes describe a health condition so we can understand the situation. Health data is treated as sensitive / special-category personal data under both the GDPR and Indian law. We process it only with your explicit consent and use it solely to route you to appropriate hospitals and coordinate your support. We recommend describing your need in general terms here — detailed medical records, scans, and reports are best shared directly with the hospital once we have connected you, not through this website.

7. Children’s data

Our website and services are directed at adults arranging care for themselves or their family. Under the DPDP Act 2023, a child is anyone under 18 years of age; under the GDPR the threshold for consent is generally 16 (or as set by the relevant member state). We do not knowingly collect personal data directly from a child without the verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Where a family enquiry concerns a minor patient, we rely on the parent or guardian who contacts us providing that information on the child’s behalf. If you believe a child has provided us data without appropriate consent, contact us and we will delete it.

8. How we use your information & our legal grounds

We use your personal data only for clearly specified purposes. The table below maps what we collect to why we use it and the legal grounds we rely on under the GDPR and the DPDP Act 2023.

DataPurposeLegal ground
Name, email, phone/WhatsApp, city/state, support type, messageRespond to your enquiry and coordinate hospital selection, travel, and stay supportYour consent; and steps taken at your request prior to any engagement (GDPR Art. 6(1)(a)/(b); DPDP — consent for a specified purpose)
Health-related details you voluntarily provideUnderstand your need and route you to suitable, accredited hospitalsYour explicit consent (GDPR Art. 9(2)(a); DPDP — consent)
WhatsApp / phone / email conversationCommunicate with you about your requestConsent and our legitimate interest in responding to you
Blog comment data (name, email, site, IP)Publish your comment and prevent spamConsent; legitimate interest in site security
Analytics & cookie dataUnderstand and improve how the site is usedConsent (for non-essential cookies); legitimate interest in improving our service
Server & security logsOperate, secure, and troubleshoot the websiteLegitimate interest / legitimate use in running a safe service
Any dataComply with legal, regulatory, and record-keeping obligationsLegal obligation

We do not sell your personal information, and we do not use it for third-party advertising or profiling.

Where we rely on consent, we ask for it through a clear, specific request — for example, when you tick the consent box and submit our contact form. In line with the DPDP Act 2023 and DPDP Rules 2025, our consent request is (or is accompanied by a notice that is) presented in plain language, itemises the personal data collected and the specified purpose, and tells you how to withdraw consent and how to complain.

Withdrawing consent is as easy as giving it. You may withdraw your consent at any time by emailing care@neimhaans.in. Withdrawal does not affect the lawfulness of processing carried out before you withdrew, and we may retain limited information where the law requires it. After withdrawal, we will stop the relevant processing and delete or anonymise the data unless we are legally required to keep it.

10. Who we share information with

We share personal data only where necessary, and never for sale. Recipients include:

  • Hospitals and care providers — we share your contact details and the relevant particulars of your request with a specific hospital or provider only when you have asked us to coordinate with them.
  • Meta / WhatsApp — messages you send us are handled through the WhatsApp Business platform and are subject to WhatsApp’s own privacy policy.
  • Technology service providers (our Data Processors) — our website host and caching provider, and Google (Analytics / Site Kit), process data on our behalf to keep the site running and help us understand traffic. They are permitted to use the data only for these purposes.
  • Legal and regulatory bodies — where we are required to disclose information by law, court order, or a lawful request from a public authority.

We put appropriate contractual and technical safeguards in place with our processors and require them to protect your data to a standard consistent with this policy.

11. International data transfers

Some of our service providers (for example, Google and Meta/WhatsApp) may process data on servers located outside your country, including outside India and the EEA. Where personal data is transferred internationally, we rely on lawful transfer mechanisms — such as the transfer safeguards permitted under the DPDP Act 2023 and, for EEA/UK data, appropriate safeguards under the GDPR (for example, adequacy decisions or Standard Contractual Clauses). We take reasonable steps to ensure your data continues to receive a comparable level of protection wherever it is processed.

12. Cookies & tracking technologies

Cookies are small files stored on your device. We use:

  • Strictly necessary cookies — required for the site and its security/caching to function.
  • Analytics cookies — set by Google Analytics / Site Kit to measure and improve site usage.
  • Comment cookies — if you leave a comment and opt in, your name, email, and website may be saved in a cookie for your convenience on future comments; these expire after about one year.

You can control or delete cookies through your browser settings, and refuse non-essential cookies. Blocking some cookies may affect how parts of the site work. Where required by law, we will seek your consent before setting non-essential cookies.

13. How long we keep your data (data lifecycle)

Consistent with the data-minimisation and storage-limitation principles of the GDPR and the DPDP framework, we keep personal data only for as long as needed for the purpose it was collected, and then delete or anonymise it:

Type of dataRetention period
Contact-form enquiries & related correspondenceFor as long as needed to provide support, and a reasonable period afterwards for our records — then deleted, or sooner on request.
WhatsApp / phone / email conversationsFor the duration of your engagement plus a reasonable follow-up period, unless deletion is requested.
Blog commentsRetained so we can recognise returning commenters, until you ask us to remove them.
Analytics dataRetained per Google Analytics settings (typically up to 14 months in aggregate form).
Server / security logsShort-term, on a rolling basis, for security and diagnostics.

When the specified purpose is served and no legal requirement to retain remains, we erase the personal data.

14. How we protect your data

We use reasonable technical and organisational safeguards to protect your information, including HTTPS/TLS encryption in transit, access controls, a maintained and updated WordPress environment, and security/caching measures at the hosting layer. No method of transmission or storage is completely secure, so while we work hard to protect your data we cannot guarantee absolute security.

15. Data breach notification

16. Your rights

Subject to applicable law, you have the following rights over your personal data. To exercise any of them, contact us at care@neimhaans.in; we may need to verify your identity first.

16.1 Under the DPDP Act 2023 (India)

  • Right to access a summary of the personal data we process about you and the processing activities.
  • Right to correction and erasure of your personal data.
  • Right to grievance redressal — a readily available means to raise a complaint with us (see below).
  • Right to nominate another individual to exercise your rights in the event of death or incapacity.
  • Right to withdraw consent at any time.

16.2 Under the GDPR (EEA / UK)

  • Right of access to your data and a copy of it.
  • Right to rectification of inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”).
  • Right to restrict or object to processing.
  • Right to data portability.
  • Right to withdraw consent and to lodge a complaint with a supervisory authority.

If you have a user account on this site, you can also see, edit, download, or request deletion of your information directly.

17. Grievance redressal & complaints

If you have a concern about how we handle your data, please contact our Grievance Officer at care@neimhaans.in first — we will acknowledge and work to resolve it. If you are not satisfied, you may escalate to the Data Protection Board of India under the DPDP Act 2023, or, if you are in the EEA/UK, to your local data-protection supervisory authority (in the UK, the Information Commissioner’s Office).

18. Automated decisions & profiling

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, and we do not carry out profiling for advertising. Our recommendations are prepared with human involvement.

Our site links to hospitals, government portals, and other external organisations for your reference. These sites have their own privacy policies, and we are not responsible for their practices. Pages may include embedded content (for example, maps or media) from other websites, which behaves as if you had visited that website directly and may collect data about you under their own terms.

20. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or in the law — including the phased implementation of the DPDP Rules 2025, which is being rolled out in stages through to 2027. When we make material changes, we will revise the “Last updated” date above and, where appropriate, notify you. Please review this page periodically.

21. Contact us

For any question about this policy, to exercise your rights, or to withdraw consent, contact:

NEIMHAANS — Grievance Officer
Email: care@neimhaans.in
Phone / WhatsApp: +91 70907 77372
Website: neimhaans.in/contact

This Privacy Policy is provided for transparency and general information. It reflects our good-faith implementation of the DPDP Act 2023, the DPDP Rules 2025, and the GDPR, and does not constitute legal advice. NEIMHAANS is a non-clinical medical-travel navigation service and is not a hospital or healthcare provider.
Scroll to Top