1. Data We Collect
1.1Careseekers. To register, we collect your mobile number, which is verified via OTP.
1.2Health Professionals. We collect:
(a)Stage A: mobile number, verified via OTP, and basic profile details (name, professional category).
(b)Stage B: professional registration details submitted for lookup against the applicable professional council registry (via a third-party verification provider), and identity information retrieved via Aadhaar through DigiLocker, provided with your explicit consent through the DigiLocker consent flow. We do not collect facial images, selfies, or other biometric data as part of this verification process.
1.3We also collect Content you post, and standard usage data (such as app interactions) for the purposes described in Section 3.
2. Sensitive Personal Data
2.1Aadhaar-linked identity information is retrieved only through DigiLocker’s consent-based document-sharing mechanism, meaning you separately authorize the release of that information to us through DigiLocker at the time of verification; we do not independently store your Aadhaar number.
2.2Professional registration numbers submitted for Stage B verification are treated as sensitive data and used solely for the verification purpose described in Section 3.
2.3We apply appropriate technical and organizational safeguards to this category of data, consistent with Section 10.
3. Purpose of Processing
3.1We process personal data to: (a) create and maintain your account; (b) verify HP professional credentials and identity as described in Section 1.2(b); (c) personalize Content and community recommendations; (d) operate analytics for product improvement (see Section 4); and (e) comply with applicable legal obligations.
4. Third-Party Processors
4.1We engage the following categories of third-party processors:
(a)A verification services provider, to perform the professional-registry lookup and to facilitate the DigiLocker-based Aadhaar retrieval described in Section 1.2(b).
(b)An analytics and application-monitoring provider, to understand product usage and diagnose issues.
(c)Content-discovery data sources (such as public APIs of video- and discussion-platforms), used solely to identify publicly available content for potential embedding; these sources do not receive or process any User personal data from us.
4.2Each processor is contractually bound to use data only for the purpose we specify and consistent with this Policy.
5. Data Sharing
5.1We do not sell personal data to any third party.
5.2We do not currently offer any brand, sponsor, or advertiser account type on the Platform, and there is accordingly no sharing of User data with brand or commercial accounts at this stage.
5.3Embedded Content Note. Where the Platform displays embedded content from third-party platforms (such as YouTube or Instagram), viewing that content may cause your device to communicate directly with the source platform, which may then receive technical information such as your IP address, governed by that source platform’s own privacy policy. Ninto does not receive or share any personal data through this display; it is a content-display feature only.
6. Retention and Deletion
6.1We retain account data for as long as your account remains active on the Platform.
6.2Pending-status HP data (submitted for Stage B but not yet approved) is retained pending completion of manual review, and may be deleted upon request or after a defined inactivity period.
6.3Where an account is Blocked under the Terms, we retain the minimum data necessary to enforce that status and comply with legal obligations, and delete other data in line with our retention schedule.
6.4You may request deletion of your account and associated data at any time, subject to Section 7.
7. Your Rights
7.1Under the Digital Personal Data Protection Act, 2023, you have the right to: (a) access the personal data we hold about you; (b) request correction or completion of inaccurate or incomplete data; (c) request erasure of your data, subject to legal retention requirements; (d) withdraw consent at any time, without affecting the lawfulness of processing before withdrawal; (e) nominate another individual to exercise these rights on your behalf in the event of death or incapacity; and (f) lodge a grievance as described in Section 8.
8. Grievance Redressal
8.1For any privacy-related query, request, or grievance, you can write to contact@ninto.in.
We will acknowledge and address grievances within the timelines prescribed under applicable law.
9. Cross-Border Data Transfer
9.1Some of our processors (see Section 4) may process data outside India as part of standard analytics or infrastructure operations. Where this occurs, we take steps to ensure data is handled consistent with applicable Indian data protection law.
10. Security Measures
10.1We apply reasonable technical and organizational safeguards, including access controls and encryption in transit, to protect personal data against unauthorized access, loss, or misuse. No system is completely secure, and we cannot guarantee absolute security.
11. Changes to This Policy
11.1We may update this Policy as the Platform evolves beyond the Beta phase. Material changes will be notified through the Platform or your registered mobile number. Continued use after such notice constitutes acceptance of the updated Policy.