Privacy Policy
Last updated: 29 July 2026
Health information is the most personal information there is. This policy explains what Zeetac collects, why, who can see it and the choices you have. It applies to the Zeetac website and applications (together, the “platform”). Zeetac is responsible for personal information processed through the platform. It is written to the Digital Personal Data Protection Act 2023, which is the law that governs it in India.
1. What we collect
- Account details - your name, contact details, date of birth and sign-in credentials.
- Health information - the records, readings, prescriptions, appointments and messages created when you and your care team use the platform, including information about dependants you are authorised to manage.
- Technical information - device and browser details, and security logs of access to the platform.
We collect only what the platform needs to work. We do not buy information about you from anyone.
2. How we use it
- to provide your care services - bookings, records, prescriptions and messaging;
- to send you service messages, such as appointment reminders you have chosen to receive;
- to keep the platform secure and to detect misuse;
- to meet legal and professional record-keeping obligations.
The Digital Personal Data Protection Act 2023 allows personal data to be processed on your consent (section 6) or for one of the “certain legitimate uses” the Act itself lists (section 7). We rely on section 7(a) - data you gave us for a stated purpose - to deliver your care and run your appointments, and on a legal obligation for billing and for the records a practitioner must keep. Optional things, such as research participation or marketing, run on your consent and nothing else.
You may withdraw consent for anything optional at any time, from the Privacy screen in the app, and doing so is exactly as easy as giving it. Withdrawing does not affect processing already carried out, and it cannot switch off the record-keeping the law requires of a clinic.
We never sell your personal information, and we do not use your health information for advertising.
3. Who can see your record
Your health record is visible to you and to the members of your care team involved in your care. Access is enforced at the database level, not just on the screen: a request for a record that is not yours returns nothing.
Every time a health record is opened, the platform logs who opened it, when and what was accessed. That audit trail exists to protect you.
We share personal information only with:
- your care team, for your care;
- service providers who help us run the platform (such as hosting and message delivery), under contracts that limit what they may do with it;
- authorities, where the law requires it and to the extent it requires it.
4. How we protect it
- your connection to the platform is encrypted;
- sign-in uses secure, protected cookies that scripts in your browser cannot read, and sessions expire automatically;
- passwords are stored only in strongly hashed form;
- access to records is role-restricted and logged.
No system can promise perfect security, but if an incident ever puts your information at risk, we will inform you and the relevant authority as the law requires.
5. How long we keep it
The periods are set by law, not by us, so we state them rather than saying “as long as necessary”:
- Clinical records - at least three years from the start of treatment, under Regulation 1.3.1 of the Indian Medical Council (Professional Conduct, Etiquette and Ethics) Regulations 2002.
- Billing records - eight financial years, under section 128(5) of the Companies Act 2013.
- Prescription registers for Schedule H1 medicines - three years, under the Drugs and Cosmetics Rules.
- Security and access logs - every read of a health record is logged for five years, and sign-in events for one year. The CERT-In Directions of April 2022 set a rolling 180-day minimum; we keep them longer, because a log has to outlive the incident it is evidence of.
When you close your account, information that no longer has to be kept is removed. Information we must retain is kept only for that purpose, and we tell you which law requires it rather than refusing your request without a reason.
6. Your rights
Under the Digital Personal Data Protection Act 2023 you have the right to:
- access - a summary of the personal data we hold about you and what we do with it (section 11);
- correction and erasure - to have data corrected, completed, updated or erased (section 12);
- grievance redressal - to complain to us and be answered (section 13);
- nomination - to nominate someone to exercise these rights if you die or cannot act for yourself (section 14);
- withdrawal of consent - for anything that runs on consent (section 6(4)).
You can exercise all of these from the Privacy screen inside the app, or by writing to us at support@zeetac.com.au. We answer within 30 days and never charge for a reasonable request. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
7. Children and dependants
In India a child is anyone under 18. A child cannot open an account here: registration asks for a date of birth and refuses one that shows the person is under 18, because section 9(1) of the Act requires verifiable consent from a parent or lawful guardian before a child’s data may be processed at all.
A parent or guardian creates and manages the account instead, and we record who they are and their relationship to the child. Their records receive the same protection as every other record.
Section 9(3) forbids tracking, behavioural monitoring and advertising directed at children, and we do neither for anybody: there is no advertising on this platform and no behavioural tracking of any account, child or adult.
8. Cookies
The platform uses only essential cookies - the secure cookies that keep you signed in and protect your session. There are no advertising or tracking cookies.
9. Changes to this policy
If we change this policy in a way that matters, we will tell you before the change takes effect and update the date at the top of this page.
10. If something goes wrong
If personal data here is ever breached, we notify the Data Protection Board of India and every affected Data Principal as section 8(6) of the Act requires, and we report the incident to CERT-In within six hours of becoming aware of it, as the CERT-In Directions of April 2022 require. We will tell you what happened, what data was involved and what to do about it - not a notice that something occurred.
11. Contact
For any privacy question, to make a data request, or to raise a concern about how your information has been handled, write to support@zeetac.com.au.