Privacy Policy - MindOPD
MindOPD ("MindOPD", "we", "our", "us") is committed to protecting your privacy and ensuring the confidentiality of your personal information, especially sensitive mental health records. This Privacy Policy explains how we collect, use, disclose, store, and protect your data when you use our online and offline mental health consultation services, mobile applications, or website.
Effective Date: December 12, 2025
This Privacy Policy applies to:
- Users seeking mental health consultations
- Therapists, psychologists, psychiatrists, counsellors and Lifecoaches and Other holistic therapy providers.
- Visitors accessing our website or app
- Any person interacting with our platform or services
1. Changes to This Privacy Policy
We may update this policy periodically. Changes will be posted with a revised effective date. Continued use of our services constitutes acceptance of the updated policy.
2. Information We Collect
We collect the following categories of personal and sensitive data
2.1 Visitor Data
Includes IP address, device details, pages visited, crash reports, cookies, advertising identifier, browser type, and usage analytics.
2.2 Onboarding Data
User profile, demographic details, emergency contacts, questionnaire responses, onboarding forms, consent forms.
2.3 Account Data
Name, phone number, email, Login ID, age, gender, contact details, consent logs.
2.4 Appointment Data (NEW — required for OPD platforms)
- Booking history
- Consultation type (online/offline)
- Therapist assigned
- Rescheduling logs
- Cancellation logs
- Attendance status
- Time-stamps of interactions
This data enables smooth booking and clinical continuity.
2.5 Clinical Health Records
Includes:
- Mental health history
- Psychologist/psychiatrist notes
- Session summaries
- Uploaded prescriptions, reports, medical files
- Worksheets, journals, therapy-related messages
- Digital prescriptions
- Treatment plans and continuity of care notes
Therapists create and maintain these records as required by law.
2.6 Transaction & Payment Data
Payment IDs, refund requests, invoices, discounts, payment success/failure logs.
2.7 Therapist Data
As provided earlier—including license details, documents, education, identity proofs, bank account details, background check data.
2.8 Location Data
Collected through GPS or IP address for:
- Matching users with licensed therapists in their state
- Emergency response
- Service availability
- Operational compliance
2.9 Communication Data
- Customer support interactions
- Emails and chat communications
- Push notification preferences
- Session reminders
3. How We Use Your Information
We process your information for the following legitimate purposes:
- Providing online/offline mental health consultations
- Appointment scheduling, rescheduling, cancellations
- Therapist matching based on specialty, age group, language
- Generating digital prescriptions (psychiatrists only)
- Maintaining legal medical records
- Emergency escalation
- Payment processing
- Sending reminders and notifications
- Improving app functionality and security
4. Telemedicine Compliance (MANDATORY)
All online consultations follow the Telemedicine Practice Guidelines, 2020 issued by the Medical Council of India.
Therapists must:
- Verify user identity
- Obtain informed consent
- Issue prescriptions only where legally allowed
- Maintain proper records
- Refrain from prescribing prohibited or habit-forming drugs online
5. Emergency & Crisis Disclosure (MANDATORY)
MindOPD is NOT an emergency or suicide prevention platform.
If you experience:
- Suicidal thoughts
- Self-harm urges
- Severe agitation or violence
- Hallucinations or acute psychosis
- Medical emergencies
Please contact:
- Your local emergency number
- Nearest hospital
- Verified suicide helpline
We may inform your emergency contact or authorities if required to preserve safety.
6. Data Sharing
We share data ONLY under these conditions:
- With therapists for clinical purposes
- With payment gateways
- With SMS/WhatsApp OTP vendors
- With platform service providers (hosting, analytics, cloud)
- With emergency responders
- With authorities when required by law
We never sell personal data.
7. Data Security
We implement:
- End-to-end encryption for chats
- Encrypted storage for clinical records
- Role-based access control for therapists
- Regular security audits
- No call or session recording
8. Data Retention
Clinical records are retained per legal and medical record-keeping norms (typically 3-7 years).
General data is retained only as long as necessary.
9. User Rights (DPDP ACT, GDPR)
Full original rights retained:
- Access
- Correction
- Erasure
- Withdraw consent
- Object to processing
- Right to grievance redressal
- Right to nominate
10. Children's Privacy
Not for users below 18.
Parental verification required for minor consultations.
