1. Who we are
This policy explains how CuraKey, a product of Vermaco Healthcare (“we”, “us”) handles personal data through curakey.in, curakey.co and app.curakey.in. Under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary for the data described here, and you are the Data Principal.
2. Where we stand today
CuraKey is a consent-based digital health record service that is still in development. The public website and the demonstration app at app.curakey.in run in your browser with sample data — they do not yet collect or store real patient health records. This policy covers what we handle today and the rules we will follow when real health records are added.
3. What we collect, why, and on what basis
We collect only what we need for the purposes below. Each purpose is listed separately so you can see exactly what you are agreeing to.
| Data | What exactly | Why | Legal basis |
|---|---|---|---|
| Contact and early-access requests | Name, email address and anything you choose to write when you email us or use the “Request early access” link. | To reply to you and manage the waitlist. | Consent |
| Technical data | IP address, browser type, pages requested and timestamps, logged automatically by our hosting provider (Netlify). | To run the website securely and stop abuse. | Legitimate use (security) |
| Cookie preference | Whether you accepted or declined optional cookies. | To remember your choice. | Strictly necessary |
| Demo app data | Anything you type into the demonstration app stays in your own browser and is not sent to us. | Demonstration only. | Not collected by us |
| Future health records (at launch) | Health records, reports, prescriptions and IDs that you choose to add, and who you share them with. | To keep your records and share them only with the providers you approve. | Your explicit consent, per item and per provider |
4. What we never do
- We never sell your personal data or use it for advertising.
- We never act on your accounts, devices or messages without your permission.
- We never track, profile or target advertising at children.
5. Who we share data with
We use a small number of service providers (“Data Processors”) who process data only on our instructions, under written terms that require them to protect it: Netlify (website hosting, United States/European Union). At launch we will list every additional provider here before using it.
We may also disclose data where the law requires it, for example to a court or government authority acting under law.
6. Transfers outside India
Some providers above process data outside India. The DPDP Act permits such transfers except to countries the Government of India restricts by notification; we will stop any transfer to a restricted country.
7. How long we keep data
We keep personal data only as long as needed for the purpose you gave it for, or as the law requires, and then erase it. If you withdraw consent, we stop processing and erase the data unless we must keep it by law. Security logs are kept for one year, as the DPDP Rules require.
8. Your rights
- Access — a summary of the personal data we hold about you and how we use it, and who we have shared it with.
- Correction, completion, updating and erasure of your data.
- Withdraw consent at any time — as easily as you gave it. Withdrawal does not affect processing already done.
- Grievance redressal — a response from our Grievance Officer.
- Nominate someone to exercise your rights if you die or become incapable.
At launch you will be able to export your full record and revoke a provider’s access with one tap. To use any right, email info@curakey.in. We may ask you to confirm your identity first.
9. Your duties
The DPDP Act asks Data Principals to give authentic information, not to impersonate anyone, and not to file false or frivolous complaints.
10. Children
Our services are for adults. We do not knowingly collect data from anyone under 18 without verifiable consent from a parent or lawful guardian, and we never track, monitor the behaviour of, or target advertising at children. If you believe a child has given us data without such consent, contact us and we will delete it.
11. Security and breaches
We protect data with encryption in transit (HTTPS), access controls, least-privilege access and activity logs — see our Data Protection Policy. If a personal data breach happens, we will inform affected people and the Data Protection Board of India without delay, and send the Board a detailed report within 72 hours.
12. Cookies and consent
See our Cookie Policy and our Consent & Permission Policy.
Grievance Officer & contact
Grievance Officer: Rajesh Kumar, Founder
Email: info@curakey.in
Address: CuraKey, a product of Vermaco Healthcare, Sahibzada Ajit Singh Nagar (Mohali), Punjab, India
We acknowledge requests promptly and resolve them within the time the law allows (currently no more than 90 days) — we aim for 7 working days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Changes
We will post updates here with a new date, and tell you directly about important changes before they apply.