Privacy Policy

Call2Physio Privacy Policy

Last Updated: May 9, 2025

1. Introduction

Call2Physio ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform (website, mobile app, and services) in the USA and India.

By accessing or using Call2Physio, you agree to this Privacy Policy. If you disagree, please do not use our services.

2. Information We Collect

A. Personal Data

We may collect:

  • Identity Data: Name, age, gender, profile photo
  • Contact Data: Email, phone number, address
  • Health Data: Medical history, treatment records, prescriptions
  • Financial Data: Payment details (for transactions processed via our platform)
  • Technical Data: IP address, device type, browser, location

B. Sensitive Data

  • Health Information: Shared during consultations
  • Biometric Data: If used for therapy (e.g., motion tracking)

We do not store credit card details. Payments are processed via PCI-DSS compliant gateways.

3. How We Use Your Data

PurposeLegal Basis (USA & India)
Provide physiotherapy servicesContractual necessity
Process paymentsLegal obligation
Improve platform performanceLegitimate interest
Send appointment remindersUser consent
Comply with healthcare lawsRegulatory requirement

4. Data Sharing & Disclosure

We may share data with:

  • Licensed Physiotherapists (only relevant treatment details)
  • Payment Processors (Stripe, Razorpay)
  • Cloud Storage Providers (AWS, HIPAA-compliant servers)
  • Government Authorities (if required by law)

We never sell your data to third parties.

5. Data Security

We implement:

  • Encryption: AES-256 for data transmission & storage
  • Access Controls: Role-based permissions
  • Audit Logs: Track all data access

6. Your Rights

For USA Users (Under HIPAA & CCPA):

  • Request access to your health records
  • Opt out of data sharing for marketing
  • Delete non-essential personal data

For India Users (Under DISHA & IT Act 2000):

  • Request data correction
  • Withdraw consent for data processing
  • File grievances with the Data Protection Officer

To exercise rights, email: privacy@call2physio.com

7. Data Retention

We retain data:

  • Active Users: Until account deletion
  • Inactive Users (3+ years): Anonymized or deleted
  • Medical Records (USA): 6 years (HIPAA requirement)
  • Medical Records (India): 5 years (DISHA guideline)

8. Cookies & Tracking

We use:

  • Essential Cookies: For platform functionality
  • Analytics Cookies: Google Analytics (anonymized data)

You can disable cookies via browser settings.

9. International Data Transfers

  • USA-India Transfers: Protected by Standard Contractual Clauses (SCCs)
  • EU Users: GDPR-compliant safeguards

10. Updates to This Policy

We may update this policy. Changes will be:

  • Posted on this page
  • Emailed to registered users
  • Effective after 30 days

11. Contact Us

For privacy concerns or data requests:

Data Protection Officer:

📧 dpo@call2physio.com

📞 US: +1 (800) XXX-XXXX | India: +91 XXX XXXX XXXX

Address: [Registered Office Location]