SaathWell Privacy Policy
Effective / Last updated: July 30, 2026
SaathWell is a service operated by Wonksknow Technologies India Pvt. Ltd. This Privacy Policy explains how Wonksknow Technologies India Pvt. Ltd (doing business through SaathWell, and referred to as "SaathWell," "we," "us," or "our") collects, uses, shares, stores, and protects personal data when people use the SaathWell website, applications, care-management services, teleconsultations, home services, and related communications (collectively, the "Services").
1. Scope and who this Policy covers
This Policy applies to patients and elders receiving care ("Patients"), people who purchase or arrange a plan ("Subscribers"), family members and caregivers authorized to access information ("Authorized Family Members"), prospective customers, website visitors, and other people who communicate with us.
SaathWell is generally the data fiduciary or controller for account, subscription, care-coordination, platform, and customer-support data. A doctor, diagnostic laboratory, physiotherapist, dietitian, specialist, payment provider, or other professional may also act as an independent data fiduciary or controller for records created under that professional's legal and ethical duties. Their notices may also apply.
This Policy does not replace a clinician's professional confidentiality obligations, a laboratory's privacy notice, or any consent or authorization signed by a Patient.
2. Important roles and consent
The Patient is the primary decision-maker regarding the Patient's health information. Paying for a plan or being related to a Patient does not automatically authorize access to the Patient's medical records.
We share Patient information with a Subscriber, relative, friend, or caregiver only to the extent authorized by the Patient or by a legally valid representative. The Patient may change or revoke that authorization, subject to legal retention duties and actions already taken.
Where a Patient may lack decision-making capacity, we may request documentation establishing the authority of a lawful guardian, nominee, attorney, or other legally authorized representative.
3. Personal data we collect
Identity, contact, and relationship information
- Names, date of birth, age, gender where clinically relevant, phone numbers, email addresses, residential and service addresses, PIN code, preferred language, and identity-verification details.
- The Subscriber's relationship to the Patient and documents or confirmations showing authority to arrange care or receive information.
- Emergency contacts, caregivers, nominees, and Authorized Family Members.
Health and care information
- Medical history, symptoms, diagnoses, allergies, medications, prescriptions, immunizations, family history, past procedures, functional status, and care preferences.
- Vital signs, home-monitoring readings, laboratory and imaging results, reports, trend charts, clinical notes, care plans, referrals, specialist information, and treatment follow-up.
- Geriatric and wellness screening information, including mood, memory, cognition, nutrition, frailty, fall risk, gait, activities of daily living, sleep, loneliness, hearing, vision, pain, and mobility information.
- Information supplied in calls, chats, messages, forms, questionnaires, uploaded documents, photographs, audio, video, or consultations.
Service, payment, and device information
- Plan selection, order history, appointment and home-visit details, service completion, cancellations, feedback, and support requests.
- Billing address, payment status, transaction identifiers, currency, and limited payment metadata. Full card or bank credentials are ordinarily handled by payment processors, not stored by SaathWell.
- IP address, device and browser type, operating system, app version, login and security events, cookie identifiers, diagnostic logs, and how features are used.
- Approximate or precise location only when needed and enabled for a home visit, service coverage, fraud prevention, or a feature the user requests.
Recordings and quality review
We may record a call or consultation, or permit a trained quality reviewer to observe it, only after giving appropriate notice and obtaining any consent required by law. Refusing optional recording or observation will not by itself prevent access to core care services.
4. How we obtain personal data
We collect data directly from Patients, Subscribers, Authorized Family Members, caregivers, website visitors, and applicants. We may also receive data from doctors, laboratories, phlebotomists, diagnostic centers, physiotherapists, dietitians, specialists, hospitals, pharmacies, payment processors, communications providers, referral partners, and devices or services connected at the user's request.
A person who gives us another individual's personal data must have a lawful basis and appropriate authority to do so and must not misrepresent the scope of that authority.
5. Why we use personal data
- To determine service eligibility and coverage, enroll Patients, create accounts, verify identity and authority, and administer subscriptions.
- To arrange home sample collection, consultations, home visits, screenings, care-manager check-ins, referrals, specialist coordination, and other included services.
- To create and maintain longitudinal health records, review trends, communicate results, prepare care plans, support medication adherence, and coordinate appropriate follow-up.
- To provide authorized access to reports, visit notes, messages, and trend information.
- To communicate about appointments, test preparation, service updates, care reminders, security, billing, and support.
- To process payments, prevent fraud, maintain accounting and tax records, and enforce agreements.
- To protect Patients, personnel, systems, and the public; investigate incidents; comply with law; and establish or defend legal claims.
- To improve safety, usability, accessibility, service quality, clinical workflows, and staff training using appropriately limited, aggregated, or de-identified information where feasible.
- To send marketing communications only where permitted and subject to available opt-outs. We do not use identifiable Patient health data for targeted advertising.
6. Consent and other lawful grounds
Where consent is required, we seek consent that is specific to the stated purpose and limited to data reasonably necessary for that purpose. Consent to care, consent to process personal data, authorization to share records with family, consent to recording, and consent to marketing are separate choices where appropriate.
Depending on the context and applicable law, we may also process data to perform a contract, respond to a request voluntarily made by an individual, comply with legal and professional obligations, protect vital interests in an emergency, prevent fraud or security incidents, or establish and defend legal claims.
A person may withdraw consent through the app or by contacting us. Withdrawal does not invalidate earlier lawful processing and may limit or prevent our ability to continue a Service that requires the data.
7. How we share personal data
We disclose only the information reasonably needed for the relevant purpose. Recipients may include:
- SaathWell doctors, nurses or allied professionals where engaged, care managers, authorized operations and support personnel, and quality personnel subject to confidentiality obligations.
- Diagnostic laboratories, phlebotomy providers, imaging centers, physiotherapists, dietitians, specialists, hospitals, pharmacies, ambulance or emergency providers, and other care partners involved in the Patient's care.
- Authorized Family Members and caregivers within the permissions granted by the Patient or lawful representative.
- Cloud hosting, electronic health record, communications, identity verification, security, analytics, customer-support, and document-management vendors that process data under contractual restrictions.
- Payment processors, banks, tax and accounting providers, and fraud-prevention services.
- Government, regulatory, judicial, law-enforcement, accreditation, or professional bodies when disclosure is legally required or reasonably necessary to protect rights, safety, or public health.
- A successor or transaction counterparty in a merger, financing, reorganization, or sale, subject to confidentiality and applicable legal safeguards.
8. Family access and confidentiality
The app may permit different access levels. A Patient may authorize a person to view all records or only selected categories, receive alerts, participate in consultations, communicate with the care team, or manage appointments and payment.
We may withhold or limit information where required by law, professional ethics, Patient safety, third-party privacy, or the Patient's instructions. A Subscriber's payment rights do not override the Patient's confidentiality rights.
Users must not forward, download, screenshot, or disclose another person's health information except as authorized and lawful. SaathWell is not responsible for a recipient's misuse after an authorized disclosure, but may suspend access and assist with investigation.
9. No sale of health data and limits on advertising
SaathWell does not sell identifiable personal data or Patient health information. We do not provide identifiable health data to data brokers or use it to target advertisements based on a Patient's medical condition.
We do not currently use advertising cookies or advertising pixels. If we later introduce analytics, advertising measurement, or similar non-essential technologies, we will update this Policy and provide any notice or consent controls required by applicable law. Such technologies will not be permitted to receive health-record content, consultation content, or authenticated Patient-portal activity.
10. International processing and transfers
Subscribers and Authorized Family Members may reside outside India, and some technology or support providers may process data in other countries. Where personal data is transferred or accessed internationally, we use contractual, technical, and organizational safeguards required by applicable law and consider any country-specific transfer restrictions.
Patient-care services are intended to be delivered in India unless SaathWell expressly states otherwise.
11. Data retention
We retain personal data only as long as reasonably necessary for the purposes described in this Policy, continuity of care, the Patient's instructions, contractual obligations, professional recordkeeping, tax and accounting, dispute resolution, security, and applicable law.
Health records may be retained for a longer period than general account data because longitudinal comparison is a core part of SaathWell and because clinicians may have independent recordkeeping duties. When retention is no longer required, we delete, anonymize, or securely isolate the data, subject to technically necessary backup cycles.
Our current retention schedule is:
- Health and care records: eight years from the later of the Patient's last clinical interaction or the end of the applicable SaathWell plan. Records may be kept longer where required by a clinician's professional duties, a legal hold, a complaint, litigation, an investigation, or another applicable law.
- Call and consultation recordings: 180 days from recording, unless the recording is incorporated into a clinical record or is needed for a complaint, quality investigation, safety event, fraud review, or legal claim. In those cases, it may be retained with the related record or until the matter is finally resolved.
- Prospective-customer inquiries and leads: 12 months after the last meaningful interaction. A minimal suppression record may be retained longer to honor an unsubscribe or do-not-contact request.
- Security, access, and audit logs: one year from creation. Logs associated with a confirmed or suspected security incident may be retained for three years after the incident is closed, or longer where required for an investigation or legal proceeding.
- Financial, billing, tax, and transaction records: eight financial years, or longer where an audit, assessment, investigation, dispute, or proceeding is pending.
- Inactive general account and support data: three years after the last account activity or closure, unless the data forms part of a health record or another category above.
- Backups: deleted or overwritten through ordinary backup rotation, generally within 90 days after deletion from active systems, unless technically isolated for disaster recovery or subject to a legal hold.
These periods are operational retention periods for an India-based service and are not based on HIPAA or other United States healthcare-retention rules. We may shorten a period where the purpose has ended and no legal or operational need remains, or extend it where applicable law, professional duties, safety, fraud prevention, or a pending matter requires longer retention.
12. Security
We use administrative, physical, and technical safeguards designed for the sensitivity of health data, including role-based access, authentication, encryption in transit and where appropriate at rest, logging, backups, vendor review, confidentiality obligations, and incident-response procedures.
No system is completely secure. Users must protect passwords, devices, one-time codes, and downloaded records and must promptly report suspected unauthorized access to suchin.ravi@wonksknow.com.
13. Your choices and rights
Subject to applicable law and appropriate identity verification, a person may request access to a summary of personal data and processing, correction or updating, completion of incomplete data, deletion where retention is not required, withdrawal of consent, restriction or objection in certain jurisdictions, a copy or portability where available, and grievance redressal.
Patients may review and change family-access permissions. Marketing emails may be stopped through the unsubscribe link; transactional and care-related communications may still be sent.
We may decline or limit a request where required for another person's privacy, legal claims, fraud prevention, professional recordkeeping, public interest, or another lawful reason. We will explain the reason where permitted.
14. Cookies and similar technologies
At this time, SaathWell uses only cookies or similar technologies reasonably necessary for website and app operation, security, session management, preferences requested by the user, and core functionality. We do not currently use advertising cookies. Browser controls may block these technologies, but some features may then not function correctly.
15. Children and other individuals
SaathWell is designed primarily for adults, especially elders. It is not directed to children. Do not create a Patient profile for a child unless SaathWell has expressly agreed to provide a relevant service and the legally required guardian consent is obtained.
Medical records may incidentally mention relatives. Users should provide only information reasonably relevant to care.
16. Emergency and legally required disclosures
SaathWell is not an emergency service. In an urgent or life-threatening situation, contact the local emergency number or go to the nearest emergency facility.
Where law permits or requires, we may disclose limited information to protect the life or safety of a Patient or another person, support emergency care, report certain public-health matters, or comply with a lawful order.
17. Third-party services and integrations
Links, payment pages, video services, laboratory portals, ABHA/ABDM features, connected devices, or other third-party services may have separate privacy terms. We access or share data through an optional integration only as disclosed and authorized.
SaathWell is not responsible for an independent third party's privacy practices, although we seek appropriate contractual protections for vendors processing data on our behalf.
18. Changes to this Policy
We may update this Policy as the Services, law, or technology changes. We will post the revised version and update the date. Where a change materially affects rights or how sensitive data is used, we will provide additional notice and obtain consent where required.
19. Grievance redressal and contact
Privacy questions, rights requests, complaints, and security concerns may be sent to:
Email: suchin.ravi@wonksknow.com
Postal address: Wolfpack Workspaces, #39, 8th Main Road, Vasanth Nagar, Bengaluru - 560052
Telephone: +91-7899217483
We will acknowledge and address requests within the period required by applicable law. A person may also use any complaint or appeal mechanism available under applicable data-protection, consumer, or healthcare law.