Quick read: We only collect the information you actively give us through a booking or contact form (name, phone, email, your medical concern). We use it to schedule and provide your consultation, nothing else. We don't sell your data. You can request access, correction, erasure or nominate someone to act on your behalf at any time — contact details at the bottom of this page.
This Privacy Policy describes how Dr. Anando Sengupta ("we", "our", or "us") handles personal information collected through dranandosengupta.com and its subdomains. Under the DPDP Act 2023, we are a "Data Fiduciary" — the entity that decides why and how your personal information is processed.
Our practice operates from two locations in Delhi:
The DPDP Act requires us to list each type of information we collect and the specific purpose for each. We do not collect more than this:
| Information | Why we collect it | When |
|---|---|---|
| Name | To address you correctly during follow-up call / WhatsApp / email | Booking form, blog comment form |
| Phone number | To call or WhatsApp you to confirm your appointment | Booking form, contact form |
| Email address (optional on booking form, required on contact form) | To send confirmation, instructions and reports | Booking + contact forms |
| Selected medical concern (e.g. GERD, IBS) | So the doctor can prepare for your visit and triage urgency | Booking form |
| Symptom description (optional) | To prepare for your visit; treated as confidential medical information | Booking form "Briefly describe your symptoms" field |
| IP address (technical) | Spam prevention, security, abuse detection — not used for marketing | Every request to the server (standard for any website) |
| Cookies / similar identifiers | Site function, anonymous analytics, ad measurement (each only with your consent — see Section 7) | While you browse the site |
We do not collect: government ID numbers, payment card information (payments happen at the clinic, not online), location/geolocation, biometric data, or any information about people other than the person filling the form.
Under the DPDP Act, your consent is the lawful basis for everything in Section 2. Unlike GDPR, there is no "legitimate interest" shortcut in Indian law — we rely on your free, specific, informed, unconditional and unambiguous consent, given by the affirmative act of submitting our form. We do not use pre-ticked boxes, we do not bundle unrelated purposes together, and we do not condition the consultation on you sharing information that isn't actually needed.
Strictly limited to:
We do not sell, rent or trade your personal information. We do not use your information for unrelated marketing or profiling.
| Recipient | Role | What they see |
|---|---|---|
| Dr. Anando Sengupta | Treating physician | Everything in your submission |
| The clinic team (Ashok Vihar / Fortis Shalimar Bagh) | Appointment scheduling | Name, phone, concern, requested slot |
| Honcho Metrics | Website and email-delivery support (a Data Processor under our instructions) | Same data as the clinic team; bound by an equivalent confidentiality obligation |
| ZeptoMail (Zoho Corporation) | Transactional email delivery to the clinic inbox | The form contents, as the email body |
| Google (Analytics + Tag Manager) | Anonymous website analytics (only if you consented to analytics cookies) | Aggregated, anonymised browsing behaviour — not the contents of your form |
| DigitalOcean | Cloud hosting of the website server | The server processes data in memory; data at rest is the contents of the email account, which lives at Google. |
Each external party listed above is bound by either their own published privacy / processing terms or by a written agreement that requires them to apply the same safeguards we do. We remain responsible to you for how they handle your data.
Form submissions are delivered to a clinic email account hosted by Google (servers may be in multiple regions). The website runs on a DigitalOcean droplet hosted in Asia. ZeptoMail processes the email in India. Anonymous analytics may be processed by Google in regions outside India. None of these locations are countries to which the Government of India has specifically restricted transfers under DPDP §16.
The Act does not use the word "cookies," but cookies that carry identifiers are treated as personal data, so they fall under the consent rules. On first visit, our cookie banner asks you to allow or reject each category:
Non-essential scripts (Google Analytics, Google Tag Manager, ad-platform pixels) do not load until you have explicitly accepted them. You can change your choice anytime via the "Cookie Preferences" link in the footer.
In line with Rule 6 of the DPDP Rules 2025, we apply the following baseline:
You have the following rights with respect to your personal information:
To exercise any of these rights, please visit Data Rights & Grievance → or email us directly using the contact information in Section 12.
Our services are intended for adults. If a person under 18 needs gastroenterology care, the booking form must be filled out by a parent or guardian on their behalf. We do not knowingly process the personal information of a child without verifiable consent from the parent or legal guardian. We do not run behavioural tracking or targeted advertising directed at children.
If you are a person with a disability who cannot act for yourself, your guardian can exercise the rights in Section 10 on your behalf. Please send us proof of guardianship along with the request.
Grievance Officer: Dr. Anando Sengupta
Email: dranandosengupta@gmail.com
Phone / WhatsApp: +91 98714 20105
Postal address: 3, II, Bansal Tower, Ashok Vihar Phase II, New Delhi 110052
Response time: We acknowledge grievances within 7 days and resolve them within 30 days (maximum 90 days, per Rule 13).
You must use this internal grievance mechanism first. If we don't resolve your concern within 90 days, you can escalate to the Data Protection Board of India as constituted under DPDP §18.
This Privacy Policy is published in English. Under DPDP §5(3), you can request the same notice in Hindi or any of the 22 languages listed in the Eighth Schedule of the Constitution of India by writing to dranandosengupta@gmail.com. We will provide a translated copy within 30 days.
If we make a material change to how we handle your data, we will update this page, change the "Last updated" date at the top, and — for substantial changes — re-request your consent through the cookie banner.
If we hold personal information that you provided to us before this Privacy Policy was published, you are receiving this notice now as required by DPDP §5(1)(a). You can withdraw your earlier consent or exercise any of the rights in Section 10 at any time by emailing us.
The information you submit is treated as confidential medical information and is handled with the duty of care a medical practitioner owes a patient. This policy is, however, not a substitute for a doctor-patient consultation. If you are experiencing a medical emergency, please call your local emergency number or go to the nearest emergency room immediately.