Sree Nandaka Advanced Surgery Hospital Plot No. 770, Jayabheri Park, Behind BigBazar, Kompally, Hyderabad, Telangana 500014, India.
Phone: +91 9000861000 Email: sreenandaka@gmail.com Website: www.sreenandaka.com
For privacy-related requests, please contact us using the details mentioned in the “Contact & Grievance” section of this Policy.
This Privacy Policy applies to information collected through:
Website enquiry forms
Appointment booking forms
Phone calls
WhatsApp messages
Email communication
Social media messages
Hospital registration desk
Doctor consultation
Diagnostic reports
Surgical/admission records
Billing and payment records
Insurance/TPA processing
Feedback forms
Patient testimonials, photos or videos, where consent is given
Cookies, analytics and website tracking tools
This Policy applies to online and offline information collected by or on behalf of Sree Nandaka Advanced Surgery Hospital.
We may collect the following categories of information.
Full name
Age/date of birth
Gender
Mobile number
Email address
Address
Location/city
Emergency contact details
Identity proof details, where required for hospital, insurance or legal purposes
Symptoms
Medical history
Surgical history
Current medicines
Allergies
Pregnancy-related information, where relevant
Existing diseases such as diabetes, hypertension, cardiac conditions, thyroid issues or other relevant conditions
Doctor consultation notes
Prescriptions
Investigation reports
Diagnosis
Treatment plan
Consent forms
Operation notes
Anaesthesia notes
Nursing notes
Discharge summaries
Follow-up notes
Medical photographs/videos, only where clinically required or consented
Appointment date and time
Doctor preference
Department/service requested
Reason for visit
Follow-up schedule
Admission/discharge details
Procedure details
Patient feedback and complaints
Billing details
Receipts
Payment mode
Transaction reference number
Insurance policy details
TPA details
Pre-authorisation documents
Claim documents
Reimbursement-related documents
We generally do not store full card details on our website. Payments made through third-party gateways may be processed according to the privacy and security policies of those payment providers.
When you visit our website, we may automatically collect:
IP address
Browser type
Device type
Operating system
Pages visited
Time spent on website
Referring website/source
Approximate location based on browser/device settings
Cookies and similar tracking data
Form submission data
We may collect information directly from you when you:
Submit an enquiry form
Book an appointment
Call the hospital
Send WhatsApp or SMS messages
Email us
Visit the hospital
Register as a patient
Consult a doctor
Share medical reports
Undergo tests/procedures
Make payment
Submit feedback
Give testimonial consent
Communicate through social media
We may also receive information from:
Family members/attendants authorised by you
Referring doctors
Diagnostic centres/labs
Insurance companies
TPAs
Payment gateways
Healthcare partners
Government or legal authorities, where applicable
We use your information for lawful healthcare, administrative, legal and operational purposes.
We may use your information to:
Register you as a patient
Schedule appointments
Provide consultation
Understand symptoms and medical history
Diagnose and plan treatment
Perform investigations/procedures/surgeries
Maintain medical records
Provide follow-up care
Issue prescriptions and discharge summaries
Coordinate with doctors, nurses and clinical teams
Ensure patient safety and continuity of care
We may contact you for:
Appointment confirmation
Doctor availability updates
Follow-up reminders
Report-related communication
Surgery/admission coordination
Billing and insurance updates
Patient support
Feedback collection
Grievance resolution
We may use your information for:
Creating bills and receipts
Processing payments
Insurance pre-authorisation
TPA claim support
Reimbursement documentation
Accounting and audit purposes
We may process data to comply with:
Indian healthcare laws
Medical ethics requirements
Clinical establishment requirements
Medical record retention obligations
Court, police or government directions
Insurance/TPA requirements
NABH/accreditation quality standards
Tax, audit and accounting requirements
Public health or statutory reporting obligations
We may use data for:
Internal quality audits
Infection control monitoring
Patient safety review
Staff training
Complaint analysis
Service improvement
Accreditation readiness
Clinical governance
Where possible, such data may be anonymised or de-identified.
With appropriate consent or lawful basis, we may use your contact details to send:
Health awareness information
Hospital updates
Camp details
Preventive health content
Service-related announcements
You may opt out of non-essential promotional communication at any time.
By submitting your information through our website, WhatsApp, phone, email, social media or hospital registration process, you consent to collection and processing of your information for the purposes described in this Policy.
For specific uses, separate consent may be taken, such as:
Surgery/procedure consent
Anaesthesia consent
Teleconsultation consent
Medical photography/video consent
Testimonial consent
Sharing records with insurance/TPA
Sharing records with another doctor/hospital
Use of anonymised data for education or quality improvement
You may withdraw consent for optional uses, such as promotional communication or testimonials, by contacting us. However, withdrawal of consent may not affect data already processed lawfully, or data that must be retained for medical, legal, billing, regulatory or safety reasons.
We process personal data for lawful purposes including:
Consent given by the patient/user
Provision of healthcare services
Patient registration and appointment support
Medical diagnosis and treatment
Billing and payment
Insurance processing
Legal and regulatory compliance
Protecting patient safety
Responding to emergencies
Record maintenance
Legitimate hospital administration and quality improvement
Under the DPDP Act, digital personal data should be processed for lawful purposes while recognising both individual data protection rights and lawful processing needs. (MeitY)
Medical and health information is highly confidential. We take reasonable care to protect health-related information from unauthorised access, misuse, disclosure, alteration or loss.
Access to medical information is limited to authorised persons who need it for treatment, administration, billing, insurance, legal compliance or patient safety.
We do not sell your personal or medical information.
We may share your information only where necessary and lawful, with:
Treating doctors
Nurses and hospital staff
Anaesthesia team
Diagnostic labs
Imaging centres
Pharmacies
Referral doctors
Insurance companies
TPAs
Payment gateways
IT service providers
Website/CRM vendors
Legal advisors
Auditors
Accreditation or quality assessment teams
Government, court, police or regulatory authorities
Emergency medical providers, where required
Information shared will be limited to what is necessary for the specific purpose.
We may use trusted third-party service providers for:
Website hosting
Form management
Appointment management
CRM systems
Email/SMS/WhatsApp communication
Payment processing
Analytics
Security
Data storage
Billing/administration
Insurance processing
Such providers may process information only for authorised purposes and are expected to maintain confidentiality and security.
Our website may use cookies, analytics tools, pixels and similar technologies to:
Improve website performance
Understand user behaviour
Measure campaign performance
Improve patient experience
Maintain website security
Remember preferences
Support enquiry form functionality
You can disable cookies through your browser settings. However, some website features may not work properly if cookies are disabled.
Third-party platforms such as Google, Meta, YouTube, maps, analytics tools or payment gateways may collect information according to their own privacy policies.
When you contact us through WhatsApp, phone, email or social media, your communication may be stored for service, follow-up, quality, legal or administrative purposes.
Please avoid sharing highly sensitive medical information through public comments or unsecured social media channels.
Medical advice will not be provided through public comments. For proper medical guidance, please book a consultation with a qualified doctor.
We may use patient testimonials, photos, videos, feedback or case stories only after obtaining appropriate consent wherever identifiable patient information is involved.
Testimonials are used for education, awareness or service information. They do not guarantee similar results for other patients.
You may request withdrawal of consent for future use of your testimonial or image. However, content already published, printed, distributed or shared before withdrawal may not always be fully removable from third-party platforms.
For minors, personal and medical data should be provided by the parent or legal guardian.
We may require parent/guardian consent for:
Registration
Consultation
Procedures
Admission
Medical records
Data processing
Communication
The DPDP Rules 2025 include requirements related to children’s personal data and verifiable parental consent under the phased framework. (MeitY)
We use reasonable administrative, technical and physical safeguards to protect personal and medical information.
Security measures may include:
Restricted access to patient records
Staff confidentiality obligations
Password-protected systems
Secure storage of physical records
Limited role-based access
Website security measures
Data backup processes
Vendor confidentiality expectations
Internal monitoring and review
However, no website, internet transmission, digital platform or storage system can be guaranteed to be 100% secure. Users should also take care while sharing information online.
In case of a data breach affecting personal data, we will take reasonable steps to:
Identify the nature of breach
Contain and reduce harm
Review affected systems
Notify relevant persons/authorities where legally required
Take corrective measures
The DPDP Rules 2025 provide implementation requirements connected to data protection obligations, including data breach-related compliance. (MeitY)
We retain personal and medical information only for as long as necessary for:
Patient treatment
Medical record maintenance
Follow-up care
Billing and accounting
Insurance processing
Legal compliance
Regulatory requirements
NABH/accreditation requirements
Dispute resolution
Quality improvement
Medical records may need to be retained for periods required under applicable Indian medical, legal, insurance, clinical establishment, NABH/accreditation or hospital policy requirements.
When data is no longer required, we may securely delete, anonymise or archive it according to hospital policy and applicable law.
Subject to applicable law, you may have the right to:
Know what personal data is collected
Access your personal data
Request correction of inaccurate or incomplete data
Request update of information
Withdraw consent for optional processing
Request deletion of data where legally permissible
Nominate another person to exercise rights, where applicable
Raise grievance regarding data processing
Some requests may be refused or limited where data must be retained for medical records, legal compliance, billing, insurance, patient safety, dispute resolution or statutory obligations.
To access, correct or update your personal information or medical records, you may contact the hospital through official channels.
We may ask for:
Patient name
Registered mobile number
Patient ID, if available
Date of visit/admission
Identity verification
Authorisation letter, if request is made by another person
Relationship proof, where applicable
Medical records may be shared as per hospital policy and applicable law after verification.
You may opt out of non-essential promotional messages by contacting us or replying through available opt-out options.
Even after opting out, we may still send service-related messages such as:
Appointment confirmation
Follow-up reminders
Billing updates
Report communication
Treatment coordination
Legal or safety notices
Some third-party technology tools, hosting providers, analytics platforms or communication tools may process or store data outside India depending on their systems.
Where applicable, such processing will be handled according to Indian data protection law and lawful transfer requirements.
Our website may contain links to:
Google Maps
YouTube
Social media pages
Payment gateways
Insurance/TPA portals
External articles
Third-party platforms
We are not responsible for privacy practices, content, security or policies of third-party websites. Please review their privacy policies before sharing information with them.
Sree Nandaka Advanced Surgery Hospital aims to respect patient dignity, privacy and confidentiality.
NABH patient-rights principles include respect for personal dignity and privacy, confidentiality of patient information, informed decision-making and patient education. (NABH)
We aim to ensure that:
Patient information is handled confidentially
Examination and consultation privacy is respected
Staff are aware of confidentiality expectations
Patient records are protected from unauthorised access
Consent is taken where required
Patient rights and responsibilities are communicated
Complaints related to privacy are addressed through grievance channels
For safety, security and operational purposes, hospital premises may have CCTV surveillance in permitted public/common areas.
CCTV is not intended to be used in areas where patients reasonably expect clinical privacy, except where legally permitted and operationally necessary.
CCTV footage may be accessed only by authorised persons and may be shared with legal authorities if required.
Calls to the hospital may be recorded or monitored for:
Appointment support
Quality improvement
Training
Complaint resolution
Record verification
Legal or safety purposes
By calling the hospital, you acknowledge that call details may be processed for these purposes.
You are responsible for providing accurate, complete and updated information.
Incorrect or incomplete medical information may affect:
Diagnosis
Treatment plan
Surgery planning
Anaesthesia safety
Medicine prescription
Insurance processing
Billing
Follow-up care
Please inform the doctor/hospital immediately if any information changes.
Users, patients and visitors must respect the privacy of other patients.
You must not:
Take photos/videos of other patients
Record doctors, staff or hospital areas without permission
Share another patient’s information
Post hospital incidents online involving identifiable patients
Violate confidentiality inside hospital premises
Unauthorised recording or sharing may result in legal action.
We may update this Privacy Policy from time to time due to changes in law, hospital processes, technology, services or compliance requirements.
Updated policy will be posted on this website with a revised “Last Updated” date.
Continued use of the website or services after updates means you accept the updated Privacy Policy.
For privacy-related questions, data access requests, correction requests, withdrawal of consent, or complaints, please contact:
Privacy/Grievance Officer: G Srinivas Designation: General Manager Phone: +91 9381914136 Email: sreenandakahospitaldigital@gmail.com Address: Sree Nandaka Advanced Surgery Hospital, Plot No. 770, Jayabheri Park, Behind BigBazar, Kompally, Hyderabad, Telangana 500014, India.
We will make reasonable efforts to respond to privacy requests within a reasonable time, subject to verification and applicable law.