Privacy Policy
Effective date: 10th September 2025
Who we are
MaxPetz Hospitals (“MaxPetz”, “we”, “us”, “our”) is a multi‑specialty veterinary hospital network providing clinical, diagnostic, surgical, and allied services across India, along with digital services through our websites, mobile applications, tele‑consults, and online forms. This policy explains how personal data is collected, used, shared, and protected across our online and offline touchpoints in accordance with India’s Digital Personal Data Protection Act, 2023 (DPDPA).Scope
This policy applies to:
Websites and pages we operate that link to this policy.
Mobile or web apps, tele‑consult platforms, appointment and payment systems.
In‑clinic registrations, consent forms, diagnostics, pharmacy, pet shop, and grooming counters.
Customer support, WhatsApp/SMS communications, and marketing communications.
Personal data we collect
We collect only the data necessary for lawful purposes, with consent or other permitted grounds.
Identity and contact: name, phone, email, address, government ID as required for invoices/compliance.
Pet profile: pet name, species, breed, age, medical history, diagnostics, prescriptions, imaging, procedures.
Transactional: invoices, payment method, UPI/PG reference IDs, insurance/TPA details where applicable.
Technical: device identifiers, IP, cookies, usage logs, and analytics for security and service performance.
Communications: calls, emails, chat/WhatsApp messages, feedback, and grievance submissions.
Recruitment: CVs, qualifications, professional registration and background checks for applicants.
How we use personal data
Provide care: registration, triage, diagnostics, surgery, discharge, rehabilitation, follow‑ups.
Operations: scheduling, reminders, tele‑consults, referrals, second opinions, and medical records.
Payments: billing, refunds, GST compliance, and accounting records retention.
Safety and quality: clinical audits, infection control, adverse event reporting, and training with safeguards.
Communication: service alerts, appointment reminders, vaccination schedules, pet health education.
Improvement: service analytics, security monitoring, error tracking, and product/service enhancement.
Legal and compliance: responding to lawful requests, regulatory filings, and enforcing terms.
Lawful basis and consent
We process data with consent and for other permitted grounds such as medical emergencies, legal obligations, and legitimate uses under DPDPA. Consent is specific, informed, revocable, and recorded. Where required, parental/guardian consent is taken for minors’ data. Consent can be withdrawn anytime using the methods in Section 12.Cookies and analytics
We use essential cookies for security and core functionality, and analytics cookies to improve services. Cookie preferences can be managed via browser settings and our cookie banner. Disabling some cookies may affect site functionality.Sharing and disclosures
We share data only as necessary and with safeguards:
Internal: treating veterinarians, specialists, diagnostics, pharmacy, and operations teams.
External service providers: payment gateways, labs, imaging partners, IT/cloud providers, logistics.
Referral/partner hospitals and consultants with explicit consent or as required for care.
Regulators, law enforcement, courts, or to protect rights, safety, or prevent fraud.
All vendors are bound by confidentiality, security, and data protection obligations.
Cross‑border transfers
If personal data is transferred outside India (e.g., secure cloud infrastructure), we ensure lawful transfer mechanisms and contractual protections, subject to government notifications and restrictions under DPDPA.Data retention
We retain records only for as long as needed for care, operations, legal, tax, and regulatory requirements, and then delete or anonymize them safely in accordance with retention schedules.Security
We implement administrative, technical, and physical safeguards including access controls, encryption in transit and at rest where appropriate, secure backups, vulnerability management, audit logs, and staff training. Despite safeguards, no system is 100% secure; incidents are handled under our breach response plan.Children and sensitive data
We do not knowingly collect personal data from children without guardian consent. Pet medical data is handled with confidentiality, and guardian/owner personal data is protected as personal data under DPDPA. Note: HIPAA does not directly apply in India, but we follow comparable privacy safeguards for client data.Your rights
Subject to applicable law, data principals may:
Access and obtain a copy of personal data we hold.
Correct or update inaccurate or incomplete data.
Withdraw consent for processing that relies on consent.
Request deletion when the purpose is fulfilled or consent withdrawn, subject to legal retention.
Nominate an individual to exercise rights in case of incapacity or death, as per DPDPA.
Requests can be made via the contact details below; we will verify identity before action.
Grievance redressal and contact
Data Protection/Grievance Officer: Ashish Money
Email: info@maxpetz.com
Address: MaxPetz Hospitals, E8 East of Kailash, Delhi, 110043
For unresolved issues, data principals may approach the Data Protection Board of India in accordance with DPDPA procedures.Third‑party sites and services
Our sites may link to third‑party websites, pharmacies, insurance providers, or booking platforms. Their privacy practices are governed by their own policies; review them before providing personal data.Updates to this policy
We may update this policy periodically. The “Effective date” indicates the latest revision. Material changes will be notified via website banners, email, or in‑app notices as applicable.
