Legal · India DPDP Act 2023

Data Protection Policy

The principles, safeguards and breach-response steps we follow to protect personal data.

CuraKey·Effective: 10 October 2026·Last updated: 10 October 2026
Written to follow India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, whose duties are coming into force in phases. This is a plain-language policy, not legal advice; we will have it reviewed by a qualified lawyer and update it as the law and our services change.

1. Purpose

This policy sets out how CuraKey, a product of Vermaco Healthcare protects personal data across curakey.in, curakey.co and app.curakey.in, so that every person and partner who works with us follows the same rules.

2. Principles we follow

3. Roles

4. Security safeguards

5. Special care for health data

Health information is among the most sensitive data a person has. CuraKey will store health records only with the explicit consent of the person they belong to, share them only with providers that person approves, let them revoke access at any time, and never sell or advertise with health data.

6. Breach response

  1. Contain — stop the breach and secure systems immediately.
  2. Assess — work out what data, which people and what risk is involved.
  3. Inform — notify affected people and the Data Protection Board of India without delay, in plain language: what happened, likely consequences, what we are doing, and what they can do.
  4. Report — send the Board a detailed report within 72 hours (or longer if the Board allows), with the facts, cause, actions taken and people informed.
  5. Learn — fix the root cause and update this policy.

7. Retention and erasure

Each type of data has a retention period based on its purpose (see the Privacy Policy). When it ends, or consent is withdrawn, data is erased from live systems and removed from backups in their normal cycle, unless the law requires us to keep it.

8. Requests from Data Principals

Requests for access, correction, erasure, nomination or grievances are logged, verified, and answered within the legal time limit (currently no more than 90 days; we aim for 7 working days).

9. Children

No processing of a child’s data without verifiable parental or guardian consent; no tracking, behavioural monitoring or targeted advertising directed at children.

10. Review

This policy is reviewed at least once a year, and whenever our services, providers or the law change.

Grievance Officer & contact

Grievance Officer: Rajesh Kumar, Founder
Email: info@curakey.in
Address: CuraKey, a product of Vermaco Healthcare, Sahibzada Ajit Singh Nagar (Mohali), Punjab, India

We acknowledge requests promptly and resolve them within the time the law allows (currently no more than 90 days) — we aim for 7 working days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.