Digital Personal Data Protection (DPDP) Rules, 2025
This page explains how Vinmayaa Care India Pvt. Ltd. ("Vinmayaa Care", "we", "us", or "our") aligns its data practices with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, notified by the Ministry of Electronics and Information Technology (MeitY) on 13 November 2025.
About the DPDP Rules, 2025
The Digital Personal Data Protection Rules, 2025 operationalise the Digital Personal Data Protection Act, 2023 — India's first comprehensive law governing digital personal data. Together, the Act and Rules set out a consent-driven, rights-based framework covering how organisations may collect, process, store, and protect personal data, along with obligations around notice, breach reporting, cross-border transfer, and the rights of individuals (referred to as "Data Principals").
The Rules are being rolled out in a phased manner over an 18-month implementation window, and are overseen by the newly constituted Data Protection Board of India.
This page is a plain-language summary of how these rules shape our data practices. It supplements, and should be read alongside, our Privacy Policy.
Our role as a Data Fiduciary
Under the DPDP Rules, Vinmayaa Care acts as a Data Fiduciary — the entity that determines the purpose and means of processing personal data. As a provider of home and facility-based eldercare, we process personal and health-related data belonging to our clients, in order to deliver safe, coordinated care.
Where we engage external partners — such as payment processors or diagnostic labs — to process data on our behalf, those partners act as Data Processors under our instructions, and are bound by written confidentiality and data protection obligations.
Consent and notice
In line with the Rules, before we collect or process personal data, we provide clients and their families with a clear, itemised notice covering:
- What personal data is being collected, in plain and specific terms.
- The specific purpose for which it is being collected (for example, preparing a care plan or processing payment).
- How to withdraw consent, and how to raise a grievance, with a direct communication link or contact.
Consent is collected separately for each distinct purpose, and is never bundled into a single blanket approval. Clients may withdraw consent for non-essential processing (such as promotional communication) at any time, as easily as it was given.
Data retention and erasure
We retain personal and health data only for as long as it is needed for the purpose it was collected, or as required under applicable medical record-keeping and legal obligations. Once the purpose is fulfilled and no legal retention requirement applies, we take steps to erase or anonymise the data within the timelines prescribed under the Rules.
Where a client's account has been inactive for an extended period, we will notify the client or their nominated representative before data is scheduled for erasure, wherever this is required under the Rules.
Data breach notification
In the event of a personal data breach, the Rules require Data Fiduciaries to notify both the affected Data Principals and the Data Protection Board of India, describing the nature of the breach, likely consequences, and mitigation steps taken.
| Step | What we do |
|---|---|
| Detection | Investigate the scope and cause of the incident immediately upon discovery. |
| Containment | Take prompt technical and organisational steps to limit further exposure. |
| Notification | Inform affected clients or families, and the Data Protection Board, within the prescribed timelines. |
| Review | Conduct an internal review to prevent recurrence. |
Cross-border data transfer
The DPDP Rules permit the transfer of personal data outside India, subject to conditions that may be prescribed by the Central Government from time to time. Certain categories of sensitive data may additionally be required to be stored within India, as and when notified.
Vinmayaa Care primarily stores and processes client data within India. Where any service provider processes data outside India (for example, a cloud storage partner), we ensure appropriate contractual safeguards are in place.
Your rights as a Data Principal
As a Data Principal under the DPDP Rules, you (or your authorised representative) have the following rights in relation to your personal data:
Right to access
Obtain a summary of the personal data we hold about you and how it is being processed.
Right to correction
Request correction of inaccurate or incomplete personal data in your records.
Right to erasure
Request deletion of personal data that is no longer necessary for the purpose it was collected.
Right to withdraw consent
Withdraw consent for any processing that is not essential to delivering your care.
Right to grievance redressal
Raise a complaint with our Data Protection Officer, and escalate to the Data Protection Board if unresolved.
Right to nominate
Nominate another individual to exercise these rights on your behalf, including in the event of incapacity.
We aim to respond to all such requests within the timelines prescribed under the Rules.
Children and persons with disabilities
Where a client requires a guardian or lawful representative — including persons with disabilities under a lawful guardianship arrangement — the Rules require verifiable consent from that guardian before processing the individual's personal data. Vinmayaa Care follows this requirement for any client who is unable to provide consent directly, obtaining consent from the nominated next of kin or legal guardian.
Grievance redressal and the Data Protection Board
If you have a concern about how your personal data has been handled, you may first raise it with our Data Protection Officer using the contact details in Section 10. We aim to acknowledge and resolve grievances promptly and in good faith.
If a grievance remains unresolved, you may escalate it to the Data Protection Board of India, the independent body established under the DPDP Act to adjudicate data protection complaints, through its online complaints portal.
Contact our Data Protection Officer
For any questions about this page, or to exercise your rights as a Data Principal, please reach out:
Vinmayaa Care
Email: info@vinmayaacare.com
Phone: +919611519681
+919535657002
Registered office
This page is intended as a general, plain-language summary and does not constitute legal advice. For the full text of the DPDP Act, 2023 and DPDP Rules, 2025, please refer to the official notifications published by the Ministry of Electronics and Information Technology.