Skip to main content

Legal · Privacy

Privacy Notice

Last updated: 2 June 2026 · Version 1.0

1. Who we are

Syntropy Sciences Pvt. Ltd ("Kyros", "we", "us", "our") operates Kyros Clinic, a telemedicine platform accessible at kyrosclinic.com and through the Kyros mobile application. We are a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act).

Data Protection Officer: dpo@kyrosclinic.com

2. Data we collect

Identity data

Name, phone number, email address, date of birth, gender, city, and state.

Health data

Medical history, symptoms, consultation notes, prescriptions, laboratory results, and any health information you voluntarily share with your doctor. Health data is sensitive personal data under the DPDP Act and is processed only with your explicit consent.

Device and usage data

IP address, device type, browser, approximate location (city-level), and app usage logs. This data is used for security, fraud prevention, and service improvement.

Payment data

Payment method details processed by Razorpay. Kyros does not store card numbers or CVV codes.

3. How we use your data

  • To provide telemedicine consultations and clinical care.
  • To generate and store prescriptions, lab orders, and consultation notes.
  • To send appointment reminders and care-related communications.
  • To comply with legal obligations under the Telemedicine Practice Guidelines (2020) and DPDP Act (2023).
  • To improve the platform and doctor-patient experience.
  • To detect and prevent fraud and security incidents.

4. Data residency

All personal data and health data is stored in the AWS ap-south-1 (Mumbai, India) region. No data is transferred outside India. Third-party services used by Kyros (payment processing, video consultations, SMS) operate under India data residency agreements.

5. Data sharing

We share your data only as follows:

  • With your doctor: your health data is shared with the doctor assigned to your consultation.
  • With Razorpay: payment data necessary to process transactions.
  • With MSG91: your phone number to deliver OTP verification and appointment reminders.
  • With Google Document AI: uploaded lab reports for OCR processing. Processed in Asia South 1 (Mumbai) region.
  • With authorities: when required by law, court order, or regulatory requirement.

We do not sell patient data. We do not share data with advertisers.

6. Your rights (DPDP Act §11–14)

  • Access: request a copy of all personal data we hold about you.
  • Correction: request correction of inaccurate personal data.
  • Erasure: request deletion of your account and associated data (subject to legal retention requirements).
  • Grievance: raise a complaint with our Data Protection Officer.

To exercise these rights: see our data deletion process or email dpo@kyrosclinic.com.

7. Data retention

Medical records are retained for a minimum of 7 years as required under Indian healthcare law. Account data is retained for the duration of your account plus 3 years. Payment records are retained for 7 years as required under the Companies Act.

When you request account deletion, your account is deactivated immediately and permanently deleted within 30 days, subject to legal retention requirements.

8. Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256 via AWS KMS). Health data in S3 is encrypted with a dedicated KMS key. We conduct quarterly security reviews and maintain an incident response plan aligned with the 72-hour breach notification requirement under the DPDP Act.

9. Cookies

The Kyros website uses strictly necessary cookies for session management and security. We do not use third-party tracking cookies or advertising cookies.

10. Contact

Questions about this notice: dpo@kyrosclinic.com