01Introduction
VRX Healthcare Pvt. Ltd. (“VRX”, “we”, “our”, or “us”) operates the website at vrxhealthcare.in and three patient-care centres across Mumbai. We are part of the Rajan Modi & Sons Healthcare Group and work in clinical partnership with Kapadia Multispeciality Hospital.
This Privacy Policy explains what personal information we collect when you visit our website, book an appointment, undergo a diagnostic test, take part in a physiotherapy programme, or otherwise interact with VRX — and how we use, share, and safeguard that information.
By using our website or any VRX service you agree to the practices described here. If you do not agree, please do not use the website or our services.
02Information We Collect
2.1 Information you give us
- Identity & contact details — name, age, gender, mobile number, email address, residential address.
- Appointment details — preferred centre, date and time, the service or test you are booking, the referring doctor (if any).
- Health information — clinical history, symptoms, prescriptions, prior reports you share with us, allergies, current medication, family medical history where relevant.
- Payment information — the amount and the transaction reference. Card or UPI credentials are handled by our PCI-DSS-compliant payment processors and are never stored on VRX servers.
- Communications — messages you send us by email, WhatsApp, contact form, or phone.
2.2 Information collected automatically
- Device & usage data — IP address, browser type, device model, operating system, pages visited, referring URL, and approximate location derived from your IP.
- Cookies & similar technologies — small text files used for session management, analytics, and remembering preferences. See section 7.
2.3 Information from third parties
We may receive information from referring physicians, partner hospitals (including Kapadia Multispeciality Hospital), insurance providers, and corporate wellness clients where you are a beneficiary of their plan.
03How We Use Your Information
We use the information we collect to:
- Schedule, confirm, and deliver the diagnostic, physiotherapy, wound-care, or home-service appointment you have requested.
- Generate, store, and deliver your test reports and treatment notes.
- Send appointment reminders, report-ready notifications, follow-up instructions, and aftercare guidance via SMS, WhatsApp, email, or phone.
- Process payments, raise invoices, and address billing queries.
- Improve the website, our clinical protocols, and our service quality through aggregate, de-identified analytics.
- Comply with applicable laws, court orders, and the lawful directions of medical, regulatory, and tax authorities.
- Respond to your questions, feedback, and grievances.
Marketing communications. We will only send promotional offers and health-awareness content when you have explicitly opted in. You can withdraw consent at any time by replying STOP to any SMS / WhatsApp, clicking the unsubscribe link in an email, or writing to
care@vrxhealthcare.in.
04How We Share Your Information
We do not sell your personal or health information. We share it only in the following limited circumstances:
- Treating clinicians and laboratories — pathologists, radiologists, physiotherapists, podiatrists, and partner laboratories that perform tests or interpret reports on our behalf.
- Referring doctors and hospitals — with your consent, we share reports with the doctor or hospital who referred you.
- Service providers — appointment-management software, secure cloud hosting, SMS/WhatsApp gateways, payment processors, and courier partners (for home sample collection), all bound by confidentiality and data-protection obligations.
- Insurance & corporate partners — where you are a member of a panel or wellness programme and have authorised us to coordinate billing or send reports.
- Legal & regulatory authorities — where required by law, court order, or to protect the rights, safety, or property of VRX, our patients, or the public.
05Data Security
We use a combination of administrative, technical, and physical safeguards to protect your information:
- HTTPS / TLS encryption for all data transmitted to and from the website.
- Role-based access controls — staff can only see the patient records relevant to their role.
- Encrypted, password-protected storage for digital reports and electronic medical records.
- Periodic security reviews, employee training, and confidentiality agreements with every team member and vendor.
No method of transmission or storage is completely secure. While we take strong precautions, we cannot guarantee absolute security and you share information with us at your own risk.
06Data Retention
We retain medical records and test reports for the period mandated by Indian medical record-keeping norms — typically a minimum of three (3) years for outpatient records and longer where specific tests, imaging studies, or regulations require it. Financial records are retained for the period required by tax and accounting laws. Marketing-consent records are retained for as long as your consent remains valid.
07Cookies & Tracking
Our website uses cookies and similar technologies for three purposes:
- Strictly necessary — session, security, and load-balancing. These cannot be disabled.
- Analytics — we use privacy-respecting analytics to understand which pages, tests, and services are most useful.
- Preferences — remembering your nearest centre and accessibility choices.
You can control cookies through your browser settings. Disabling cookies may affect parts of the booking flow.
08Your Rights
Under India’s Digital Personal Data Protection Act, 2023, you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Correction & updating — ask us to correct inaccurate or incomplete information.
- Erasure — request deletion of data that is no longer needed and is not subject to a retention requirement.
- Withdrawal of consent — withdraw any consent you have previously given. Withdrawal does not affect processing carried out before the withdrawal.
- Grievance redressal — raise a complaint with our Grievance Officer (see section 11) and, if unresolved, with the Data Protection Board of India.
- Nomination — nominate an individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, write to care@vrxhealthcare.in from the email address registered with us, or visit any VRX centre with valid photo identification.
09Children’s Privacy
For paediatric services we collect health information about the child only with the verifiable consent of a parent or legal guardian. The child’s record is maintained under the parent’s account until the child turns eighteen, after which the child can transition the record to themselves.
10Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, law, or industry practice. The “Last updated” date at the top of this page shows the effective version. Significant changes will be highlighted on the website and, where appropriate, communicated to you directly.
11Contact Us
For any privacy questions, requests, or grievances, please reach out to: