← Back to HomePrivacy Policy
Last updated: February 13, 2026
1. Introduction
RAKSHAK HealthTech Pvt. Ltd. ("RAKSHAK", "we", "us", or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our blood bank network platform, mobile applications, and related services (collectively, the "Services").
This policy is compliant with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian data protection regulations.
2. Information We Collect
We collect the following categories of information:
- Personal Identification: Full name, email address, phone number, date of birth, gender, government-issued ID (for KYC verification)
- Health Information: Blood type, weight, medical history relevant to donation eligibility, donation records, and test results
- Location Data: Address, PIN code, GPS coordinates (with consent) for donor matching and camp discovery
- Usage Data: Device information, IP address, browser type, pages visited, and interaction patterns
- Transaction Data: Donation history, reward redemptions, and gamification activity
3. How We Use Your Information
- To facilitate blood donation matching and emergency requests
- To verify donor eligibility and maintain donation records
- To send notifications about donation camps, emergencies, and appointment reminders
- To operate our gamification and rewards system
- To generate anonymized analytics for blood supply forecasting (AI-powered predictions)
- To comply with regulatory requirements (NABH, CDSCO, State Blood Transfusion Councils)
- To improve our Services and user experience
4. Data Sharing & Disclosure
We do not sell your personal data. We may share information with:
- Registered Blood Banks & Hospitals: To fulfill blood requests and coordinate donations
- Government Authorities: When required by law or for public health emergencies
- Service Providers: Cloud hosting (AWS), notification services, and analytics — all bound by data processing agreements
All data shared with third parties is encrypted in transit (TLS 1.3) and at rest (AES-256).
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide Services. Donation records are retained for a minimum of 5 years as required by Indian blood banking regulations. You may request deletion of non-regulatory data at any time.
6. Your Rights (DPDPA 2023)
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access and obtain a copy of your personal data
- Correct inaccurate or incomplete data
- Erase your data (subject to regulatory retention requirements)
- Withdraw consent at any time
- Lodge a grievance with the Data Protection Board of India
7. Security Measures
- End-to-end encryption for all data in transit and at rest
- Role-based access control (RBAC) for all platform users
- Regular security audits and penetration testing
- ISO 27001-aligned information security management
- Blockchain-based immutable audit trails for blood chain-of-custody