Privacy Notice & Privacy Policy – PingMeDoc Labs

Last updated: 23 December 2025

This Privacy Notice & Privacy Policy (“Policy”) explains how PingMeDoc Labs collects, uses, shares, stores, and protects personal data when you use our website and laboratory services (“Services”). We follow privacy-by-design principles and process personal data for specific, clear purposes with appropriate safeguards.

1) Who we are

Brand/Unit: M/s. PingMeDoc Multispeciality Clinic & Labs – A Unit of PINGMEDOC HEALTHTECH PVT LTD

Corporate entity: PINGMEDOC HEALTHTECH PRIVATE LIMITED

CIN: U86201TN2024PTC173127

GSTIN: 33AAPCP0361D1ZP   |   Drug Licence No.: TN/CPU/20/01132

Primary service city: Chennai, Tamil Nadu (India)

Clinic/Lab address (lab visit location)

Survey No. 3/A7, North Facing, Shop No – 2 from East to West, Ground Floor, Vandalur to Kelambakkam Main Road, Nallampakkam, Kandigai-600048, Vandalur Taluk, Chengalpattu District, Tamil Nadu

Contact

  • Phone: +91 90434 09465, 044-27470015
  • Email: care@pingmedoc.com, labs@pingmedoc.com

Grievance / Privacy Officer

Designation: Grievance & Privacy Officer, PingMeDoc Labs
Email: care@pingmedoc.com
Phone: +91 90434 09465, 044-27470015
Address: Survey No. 3/A7, North Facing, Shop No – 2 from East to West, Ground Floor, Vandalur to Kelambakkam Main Road, Nallampakkam, Kandigai-600048, Vandalur Taluk, Chengalpattu District, Tamil Nadu

We aim to acknowledge and resolve grievances promptly and, in any case, within 30 days of receipt where applicable.

2) What information we collect

  • Account & contact data: name, mobile number, email address, login credentials (if you create an account).
  • Booking & service data: selected tests/packages, collection type (home or lab visit), preferred slot, service address for home collection, and notes you provide.
  • Patient data: age, sex, and information you voluntarily provide for accurate service delivery.
  • Health-related documents & results: prescription uploads (if provided) and your lab reports/results (treated as sensitive/confidential).
  • Payment data: payment status and transaction references received from the payment gateway (we do not store your full card/UPI credentials on our servers).
  • Technical data: device/browser information, IP address, logs, cookies (for security and service performance).

3) Why we collect and how we use information (purpose limitation)

  • To process bookings, schedule appointments, and deliver home collection/lab visit services.
  • To correctly identify samples, maintain chain-of-custody, and generate reports.
  • To communicate important service updates (confirmation, reschedule, report-ready).
  • To provide customer support, manage complaints, and process refunds where applicable.
  • To maintain accounting records, receipts, and reconcile payments.
  • To improve service quality and website performance (security monitoring and analytics).
  • To comply with applicable Indian laws, regulations, and lawful requests.

4) Consent and choices

We collect and use data needed to deliver your booking and provide reports. Where required, we take your consent through affirmative action (for example, selecting checkboxes at checkout). Optional communications (such as marketing) will be separated and can be declined without affecting your core service.

5) Sharing and disclosures (minimum necessary)

We do not sell personal data. We share only what is necessary for the stated purposes with:

  • Authorized staff/phlebotomists/logistics: to perform home collection and service delivery.
  • Outsourced LIS provider (Laboratory Information System): reports are stored and delivered via an outsourced LIS used for diagnostic operations. The LIS acts as a service provider processing data on our behalf under confidentiality and security controls.
  • Payment providers: for payment processing and reconciliation.
  • Legal/regulatory authorities: when required by law or valid legal process.

6) Report access, confidentiality, and patient responsibility

Reports are provided through your PingMeDoc dashboard (My Reports). You are responsible for keeping your login details confidential. If you use a shared device, please log out after viewing your reports.

7) Data security safeguards

We implement reasonable security safeguards, including HTTPS encryption, role-based access controls, audit logging for report access, secure credential handling, and vendor controls for outsourced systems. No system is 100% secure; however, we continuously improve our security posture.

8) Data retention

We retain personal data only as long as necessary for service delivery, report access, legal compliance, dispute resolution, and audit requirements. Standard retention: 5 years from the report date (unless a longer period is required by law or a shorter period is permitted and requested where applicable).

9) Your rights and requests

You may request access/correction of your account information and raise privacy grievances using the contact details above. Certain records may need to be retained for legal/compliance purposes even if you request deletion.

10) Personal data incidents

We maintain internal procedures to identify, respond to, and document personal data security incidents, and we will take steps consistent with applicable legal requirements.

11) Children’s privacy

Bookings for minors should be made by a parent/guardian. We minimize collection of children’s data and use it only for service delivery and compliance needs.

12) Important note on global privacy standards

Our controls are designed to be consistent with Indian privacy requirements and aligned with globally recognized healthcare privacy principles such as confidentiality, role-based access, and “minimum necessary” use. HIPAA is a U.S. law; we use its core privacy/security concepts as best-practice benchmarks where appropriate.

13) Changes to this Policy

We may update this Policy periodically. The latest version will be posted on this page with an updated date.