Mon to Sat 5.30 - 7.30pm (Ashok Vihar) | 10.30am - 4.30pm (Fortis Shalimar Bagh)
Mon–Sat · 10:30 AM – 7:30 PM

Last updated: June 2026 · Version 1.0 · Compliant with India's Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025.

Quick read: We only collect the information you actively give us through a booking or contact form (name, phone, email, your medical concern). We use it to schedule and provide your consultation, nothing else. We don't sell your data. You can request access, correction, erasure or nominate someone to act on your behalf at any time — contact details at the bottom of this page.

1. Who we are

This Privacy Policy describes how Dr. Anando Sengupta ("we", "our", or "us") handles personal information collected through dranandosengupta.com and its subdomains. Under the DPDP Act 2023, we are a "Data Fiduciary" — the entity that decides why and how your personal information is processed.

Our practice operates from two locations in Delhi:

2. What information we collect and why (itemised)

The DPDP Act requires us to list each type of information we collect and the specific purpose for each. We do not collect more than this:

InformationWhy we collect itWhen
NameTo address you correctly during follow-up call / WhatsApp / emailBooking form, blog comment form
Phone numberTo call or WhatsApp you to confirm your appointmentBooking form, contact form
Email address (optional on booking form, required on contact form)To send confirmation, instructions and reportsBooking + contact forms
Selected medical concern (e.g. GERD, IBS)So the doctor can prepare for your visit and triage urgencyBooking form
Symptom description (optional)To prepare for your visit; treated as confidential medical informationBooking form "Briefly describe your symptoms" field
IP address (technical)Spam prevention, security, abuse detection — not used for marketingEvery request to the server (standard for any website)
Cookies / similar identifiersSite function, anonymous analytics, ad measurement (each only with your consent — see Section 7)While you browse the site

We do not collect: government ID numbers, payment card information (payments happen at the clinic, not online), location/geolocation, biometric data, or any information about people other than the person filling the form.

3. Lawful basis — your consent

Under the DPDP Act, your consent is the lawful basis for everything in Section 2. Unlike GDPR, there is no "legitimate interest" shortcut in Indian law — we rely on your free, specific, informed, unconditional and unambiguous consent, given by the affirmative act of submitting our form. We do not use pre-ticked boxes, we do not bundle unrelated purposes together, and we do not condition the consultation on you sharing information that isn't actually needed.

4. How we use your information

Strictly limited to:

We do not sell, rent or trade your personal information. We do not use your information for unrelated marketing or profiling.

5. Who has access to your information

RecipientRoleWhat they see
Dr. Anando SenguptaTreating physicianEverything in your submission
The clinic team (Ashok Vihar / Fortis Shalimar Bagh)Appointment schedulingName, phone, concern, requested slot
Honcho MetricsWebsite and email-delivery support (a Data Processor under our instructions)Same data as the clinic team; bound by an equivalent confidentiality obligation
ZeptoMail (Zoho Corporation)Transactional email delivery to the clinic inboxThe form contents, as the email body
Google (Analytics + Tag Manager)Anonymous website analytics (only if you consented to analytics cookies)Aggregated, anonymised browsing behaviour — not the contents of your form
DigitalOceanCloud hosting of the website serverThe server processes data in memory; data at rest is the contents of the email account, which lives at Google.

Each external party listed above is bound by either their own published privacy / processing terms or by a written agreement that requires them to apply the same safeguards we do. We remain responsible to you for how they handle your data.

6. Where your data is stored (cross-border)

Form submissions are delivered to a clinic email account hosted by Google (servers may be in multiple regions). The website runs on a DigitalOcean droplet hosted in Asia. ZeptoMail processes the email in India. Anonymous analytics may be processed by Google in regions outside India. None of these locations are countries to which the Government of India has specifically restricted transfers under DPDP §16.

7. Cookies and tracking

The Act does not use the word "cookies," but cookies that carry identifiers are treated as personal data, so they fall under the consent rules. On first visit, our cookie banner asks you to allow or reject each category:

Non-essential scripts (Google Analytics, Google Tag Manager, ad-platform pixels) do not load until you have explicitly accepted them. You can change your choice anytime via the "Cookie Preferences" link in the footer.

8. Security safeguards

In line with Rule 6 of the DPDP Rules 2025, we apply the following baseline:

9. How long we keep your information (retention)

10. Your rights under the DPDP Act

You have the following rights with respect to your personal information:

  1. Right to access — a summary of what data we hold about you and how it is being used.
  2. Right to correction and erasure — correct inaccurate data; ask us to delete data once the purpose is served or you withdraw consent.
  3. Right to nominate — nominate another person to exercise these rights on your behalf in case of your death or incapacity.
  4. Right to grievance redressal — complain to us first (we respond within 30 days, never more than 90 days); if unresolved, escalate to the Data Protection Board of India.

To exercise any of these rights, please visit Data Rights & Grievance → or email us directly using the contact information in Section 12.

11. Children and persons with disabilities

Our services are intended for adults. If a person under 18 needs gastroenterology care, the booking form must be filled out by a parent or guardian on their behalf. We do not knowingly process the personal information of a child without verifiable consent from the parent or legal guardian. We do not run behavioural tracking or targeted advertising directed at children.

If you are a person with a disability who cannot act for yourself, your guardian can exercise the rights in Section 10 on your behalf. Please send us proof of guardianship along with the request.

12. Grievance Officer and how to contact us

Grievance Officer: Dr. Anando Sengupta
Email: dranandosengupta@gmail.com
Phone / WhatsApp: +91 98714 20105
Postal address: 3, II, Bansal Tower, Ashok Vihar Phase II, New Delhi 110052
Response time: We acknowledge grievances within 7 days and resolve them within 30 days (maximum 90 days, per Rule 13).

You must use this internal grievance mechanism first. If we don't resolve your concern within 90 days, you can escalate to the Data Protection Board of India as constituted under DPDP §18.

13. Multi-language access

This Privacy Policy is published in English. Under DPDP §5(3), you can request the same notice in Hindi or any of the 22 languages listed in the Eighth Schedule of the Constitution of India by writing to dranandosengupta@gmail.com. We will provide a translated copy within 30 days.

14. Changes to this policy

If we make a material change to how we handle your data, we will update this page, change the "Last updated" date at the top, and — for substantial changes — re-request your consent through the cookie banner.

15. Previously collected information

If we hold personal information that you provided to us before this Privacy Policy was published, you are receiving this notice now as required by DPDP §5(1)(a). You can withdraw your earlier consent or exercise any of the rights in Section 10 at any time by emailing us.

16. Legal and disclaimer

The information you submit is treated as confidential medical information and is handled with the duty of care a medical practitioner owes a patient. This policy is, however, not a substitute for a doctor-patient consultation. If you are experiencing a medical emergency, please call your local emergency number or go to the nearest emergency room immediately.

← Back to home