1. Purpose
This policy sets out how CuraKey, a product of Vermaco Healthcare protects personal data across curakey.in, curakey.co and app.curakey.in, so that every person and partner who works with us follows the same rules.
2. Principles we follow
- Lawful and transparent — we tell people clearly what we collect and why, before we collect it.
- Purpose-limited — data is used only for the purpose it was given for.
- Minimal — we collect the least data needed.
- Accurate — we correct or complete data when asked, and before relying on it for decisions.
- Storage-limited — data is erased when its purpose is served or consent is withdrawn.
- Secure — reasonable security safeguards protect data against breach.
- Accountable — we can show how we meet these principles.
3. Roles
- Data Fiduciary: CuraKey, a product of Vermaco Healthcare.
- Grievance Officer: Rajesh Kumar, Founder — info@curakey.in.
- Data Processors: service providers listed in our Privacy Policy, bound by written terms.
4. Security safeguards
- All traffic is encrypted with HTTPS (TLS). Secrets such as API keys are kept only on the server, never in web pages.
- Access to systems is limited to people who need it, with strong passwords and two-factor sign-in on admin accounts.
- We keep logs of access and important actions for at least one year to detect and investigate misuse.
- Backups and recovery are kept for the systems that hold personal data.
- Providers are chosen for their security practices and contractually required to protect data.
5. Special care for health data
Health information is among the most sensitive data a person has. CuraKey will store health records only with the explicit consent of the person they belong to, share them only with providers that person approves, let them revoke access at any time, and never sell or advertise with health data.
6. Breach response
- Contain — stop the breach and secure systems immediately.
- Assess — work out what data, which people and what risk is involved.
- Inform — notify affected people and the Data Protection Board of India without delay, in plain language: what happened, likely consequences, what we are doing, and what they can do.
- Report — send the Board a detailed report within 72 hours (or longer if the Board allows), with the facts, cause, actions taken and people informed.
- Learn — fix the root cause and update this policy.
7. Retention and erasure
Each type of data has a retention period based on its purpose (see the Privacy Policy). When it ends, or consent is withdrawn, data is erased from live systems and removed from backups in their normal cycle, unless the law requires us to keep it.
8. Requests from Data Principals
Requests for access, correction, erasure, nomination or grievances are logged, verified, and answered within the legal time limit (currently no more than 90 days; we aim for 7 working days).
9. Children
No processing of a child’s data without verifiable parental or guardian consent; no tracking, behavioural monitoring or targeted advertising directed at children.
10. Review
This policy is reviewed at least once a year, and whenever our services, providers or the law change.
Grievance Officer & contact
Grievance Officer: Rajesh Kumar, Founder
Email: info@curakey.in
Address: CuraKey, a product of Vermaco Healthcare, Sahibzada Ajit Singh Nagar (Mohali), Punjab, India
We acknowledge requests promptly and resolve them within the time the law allows (currently no more than 90 days) — we aim for 7 working days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.