Skip to main content

Legal · Privacy

Privacy Notice

Last updated: 31 July 2026 · Version 1.1

1. Who we are

Syntropy Sciences Pvt. Ltd ("Kyros", "we", "us", "our") operates Kyros Clinic, a telemedicine platform accessible at kyrosclinic.com and through the Kyros mobile application. We are a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act).

Data Protection Officer: dpo@kyrosclinic.com

2. Data we collect

Identity data

Name, phone number, email address, date of birth, gender, city, and state.

Health data

Medical history, symptoms, consultation notes, prescriptions, laboratory results, and any health information you voluntarily share with your doctor. Health data is sensitive personal data under the DPDP Act and is processed only with your explicit consent.

Data from Apple Health and Android Health Connect

If you choose to connect Apple Health (HealthKit) on iOS or Health Connect on Android, the Kyros app reads only the following categories, and only after you grant permission on your device: steps, sleep, resting heart rate, heart rate variability, body weight, blood pressure, blood glucose, and workout or exercise sessions.

This connection is entirely optional. The app is fully usable without it, you may decline during onboarding, and you can revoke access at any time in Apple Health or Health Connect on your device, or in the Kyros app under Privacy & Security. Revoking access stops all further reads immediately.

We use this data for one purpose only: to show you your own trends in the app and to let the doctor treating you review those trends alongside your lab results during a consultation. We do not use health data obtained from Apple Health or Health Connect for advertising or marketing, we do not sell it, we do not share it with data brokers, and we do not use it for any purpose unrelated to your health, fitness, or medical care. It is never used to make credit, insurance, or employment decisions.

Data read from Apple Health or Health Connect is stored in India (see section 4), is subject to the same deletion rights as all other health data (see sections 6 and 7), and is deleted when you delete your Kyros account.

Device and usage data

IP address, device type, browser, approximate location (city-level), and app usage logs. This data is used for security, fraud prevention, and service improvement.

Payment data

Payment method details processed by Razorpay. Kyros does not store card numbers or CVV codes.

3. How we use your data

  • To provide telemedicine consultations and clinical care.
  • To generate and store prescriptions, lab orders, and consultation notes.
  • To send appointment reminders and care-related communications.
  • To comply with legal obligations under the Telemedicine Practice Guidelines (2020) and DPDP Act (2023).
  • To improve the platform and doctor-patient experience.
  • To detect and prevent fraud and security incidents.

4. Data residency

All personal data and health data is stored in the AWS ap-south-1 (Mumbai, India) region. No data is transferred outside India. Third-party services used by Kyros (payment processing, video consultations, SMS) operate under India data residency agreements.

5. Data sharing

We share your data only as follows:

  • With your doctor: your health data is shared with the doctor assigned to your consultation.
  • With Razorpay: payment data necessary to process transactions.
  • With MSG91: your phone number to deliver OTP verification and appointment reminders.
  • With Google Document AI: uploaded lab reports for OCR processing. Processed in Asia South 1 (Mumbai) region.
  • With authorities: when required by law, court order, or regulatory requirement.

We do not sell patient data. We do not share data with advertisers. Health data read from Apple Health or Android Health Connect is never shared with any third party listed above — it is shared only with the doctor treating you.

6. Your rights (DPDP Act §11–14)

  • Access: request a copy of all personal data we hold about you.
  • Correction: request correction of inaccurate personal data.
  • Erasure: request deletion of your account and associated data (subject to legal retention requirements).
  • Grievance: raise a complaint with our Data Protection Officer.

To exercise these rights: see our data deletion process or email dpo@kyrosclinic.com.

7. Data retention

Medical records are retained for a minimum of 7 years as required under Indian healthcare law. Account data is retained for the duration of your account plus 3 years. Payment records are retained for 7 years as required under the Companies Act.

When you request account deletion, your account is deactivated immediately and permanently deleted within 30 days, subject to legal retention requirements.

8. Security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256 via AWS KMS). Health data in S3 is encrypted with a dedicated KMS key. We conduct quarterly security reviews and maintain an incident response plan aligned with the 72-hour breach notification requirement under the DPDP Act.

9. Cookies

The Kyros website uses strictly necessary cookies for session management and security. We do not use third-party tracking cookies or advertising cookies.

10. Contact

Questions about this notice: dpo@kyrosclinic.com