MeeAayu
Return Home

Privacy Policy

Last Updated: July 10, 2026

This Privacy Policy explains how MeeAayu collects, uses, stores, shares, and protects personal data in connection with the MeeAayu website, waitlist, conversational interfaces, patient-facing tools, hospital-linked services, optional ABHA or ABDM features, and related digital services.

This Privacy Policy is intended to support transparent notice under applicable Indian law, including the Digital Personal Data Protection Act, 2023, and to align, where relevant, with the privacy and consent principles used in the digital health ecosystem, including ABDM-related flows.

1. Scope

This Privacy Policy applies to personal data collected directly from users, hospitals, healthcare providers, integration partners, and authorized representatives through the MeeAayu website, waitlist forms, communication channels, application interfaces, hospital-linked systems, optional ABDM or ABHA workflows, and related service interactions.

This Privacy Policy does not replace any separate contractual privacy or data processing terms agreed with hospitals, clinics, enterprise customers, or regulated healthcare partners. Where a separate written agreement applies, that agreement may supplement this Privacy Policy for the relevant service relationship.

2. Who this Policy covers

This Privacy Policy may apply to different categories of individuals depending on how MeeAayu is used, including:

  • website visitors and waitlist sign-ups;
  • patients and caregivers;
  • doctors and clinical staff;
  • hospital administrators and operations users;
  • support users and authorized representatives; and
  • integration or pilot participants.

Different users may see different notices, consent requests, or product flows depending on the service used, the applicable deployment model, and legal requirements.

3. Personal data collected

MeeAayu may collect different categories of personal data depending on the feature, relationship, and use case. These may include:

  • identity and profile data: such as name, email address, mobile number, login details, age band, and account identifiers;
  • health-related data: such as uploaded documents, prescriptions, lab reports, vitals, wellness summaries, health history, consultation-related information, or hospital-linked records where the service supports such functionality;
  • ABHA or ABDM-related data: such as ABHA number, ABHA address, verification status, consent-related metadata, or linked health information exchange details where such features are used;
  • communication data: such as support messages, chat inputs, onboarding responses, survey responses, and waitlist interactions;
  • technical and usage data: such as IP address, browser type, device information, session logs, timestamps, crash reports, and interaction data; and
  • administrative or transaction-related data: where relevant to onboarding, pilots, enterprise use, or support.

MeeAayu does not intentionally seek more personal data than is reasonably necessary for the relevant disclosed purpose, subject to legal obligations, hospital workflows, user choices, and feature design.

4. Sources of personal data

Personal data may be collected from one or more of the following sources:

  • directly from the user;
  • from a parent, guardian, caregiver, or authorized representative;
  • from hospitals, clinics, labs, or doctors using the service;
  • from integrated systems or platforms enabled by the user or an enterprise customer;
  • from ABDM or ABHA-linked flows where the user has chosen to use those features; and
  • automatically through the user’s interaction with the website or application.

Where required by law, MeeAayu will rely on valid notice, consent, another lawful basis, or enterprise-authorized processing arrangements before processing such data.

5. Purposes of processing

MeeAayu may collect and process personal data for one or more of the following purposes, depending on the service used:

  • managing the waitlist and communicating with interested users;
  • providing website, app, and account functionality;
  • authenticating users and securing access;
  • enabling hospital-linked, doctor-linked, patient-facing, or caregiver-facing features;
  • organizing, displaying, extracting, summarizing, or supporting interpretation of health-related information;
  • enabling optional ABHA verification, ABHA linking, ABDM-related consent flows, or interoperability services where applicable;
  • responding to support requests, grievances, and legal requests;
  • performing analytics, debugging, quality assurance, service improvement, and feature testing;
  • complying with applicable law, contracts, fraud prevention, security obligations, and dispute handling; and
  • supporting permitted AI-assisted or automated product features, subject to the limitations stated in this Privacy Policy and the Terms of Service.

MeeAayu will not use personal data for a materially different purpose without appropriate notice, additional consent where required, or another lawful basis under applicable law.

6. Consent and user choice

Where consent is required, MeeAayu will seek consent through an affirmative mechanism such as a checkbox, form submission, OTP-based confirmation, consent screen, or another clear action. Consent requests are intended to be free, specific, informed, unconditional, and unambiguous, consistent with applicable law and, where relevant, ABDM-aligned consent expectations.

A user may withdraw consent for future processing to the extent the processing is based on consent and the service or applicable law allows such withdrawal. Withdrawal of consent does not automatically require deletion of data where retention is necessary for legal compliance, security, dispute resolution, fraud prevention, backup integrity, or other legally permitted purposes.

Where ABDM-linked services are used, personal data sharing across the digital health ecosystem should occur in line with the applicable consent framework and only for the purposes communicated to the user.

7. ABHA and ABDM-related privacy

ABHA and ABDM-related features are optional unless a specific service flow, pilot, or healthcare deployment expressly requires them. If a user chooses to use such features, MeeAayu may process ABHA-related identifiers, verification details, consent metadata, and record-sharing information as necessary to support those flows.

ABHA participation is voluntary in the ABDM ecosystem, and the absence of ABHA or ABDM participation does not by itself prevent hospital-side storage of records in native hospital systems.

Where MeeAayu supports ABDM-linked flows, health data may be processed and shared only within the scope of valid permissions, applicable consent, contractual arrangements, and relevant ecosystem requirements.

8. AI-assisted and automated processing

MeeAayu may use AI-assisted, machine learning, rule-based, or automated tools to classify, organize, extract, summarize, surface, or support understanding of health-related information, operational information, or user-provided content. Such tools may rely on user inputs, uploaded documents, metadata, and system context to produce outputs.

AI-assisted outputs may be incomplete, inaccurate, or context-dependent and should not be relied on as a substitute for professional medical advice, diagnosis, or treatment. Human review, hospital workflows, product restrictions, or additional controls may apply to sensitive or high-risk use cases.

Where feasible and appropriate, MeeAayu may use de-identification, masking, tokenization, access restrictions, or other technical controls to reduce privacy risk in AI and analytics workflows.

MeeAayu does not represent that every AI-assisted feature is suitable for every medical, legal, or operational use case.

9. Sharing of personal data

MeeAayu may share personal data only as reasonably necessary for the purposes described in this Privacy Policy, subject to applicable law, user choices, and contractual controls. Sharing may occur with:

  • hospitals, clinics, labs, doctors, and healthcare providers connected to the relevant user journey;
  • caregivers, nominees, guardians, or authorized representatives where permitted;
  • service providers, processors, hosting providers, communication vendors, analytics providers, and support vendors acting under appropriate obligations;
  • ABDM ecosystem participants, consent managers, or interoperability partners where the user has chosen to use those features and the applicable conditions are met;
  • legal, regulatory, law enforcement, or governmental authorities where required by law or reasonably necessary to protect rights, safety, or the integrity of the service; and
  • potential acquirers, investors, or restructuring counterparties in connection with a business transfer, subject to applicable confidentiality and legal obligations.

MeeAayu does not sell personal health data in exchange for money. If any future feature materially changes the way personal data is shared or commercialized, additional notice and compliance steps would be required.

10. Data retention

MeeAayu retains personal data only for as long as necessary for the relevant disclosed purpose, contractual commitment, legal obligation, operational need, security purpose, dispute handling need, or other legally permitted reason.

Retention periods may vary depending on whether the data relates to a waitlist interaction, account activity, support request, audit log, hospital deployment, health record workflow, consent history, or enterprise contract. In health-record or hospital-linked contexts, retention may also be influenced by healthcare recordkeeping standards, hospital instructions, legal requirements, and applicable retention policies.

Where deletion is requested, MeeAayu may delete, anonymize, de-identify, suppress, archive, or restrict further processing of data, depending on the applicable legal, technical, and contractual context.

11. Security practices

MeeAayu uses reasonable technical, administrative, and organizational measures designed to protect personal data. Depending on the system and context, such measures may include encryption in transit and at rest, role-based access controls, authentication controls, audit trails, logging, secure development practices, environment segregation, vendor review, and incident response procedures.

No system is completely secure, and MeeAayu cannot guarantee that unauthorized access, cyber incidents, or security failures will never occur. Users should also take reasonable precautions, including protecting credentials and using trusted devices and networks.

12. Data residency and cross-border processing

MeeAayu may process data using infrastructure, vendors, and service providers located in India or, where legally and operationally appropriate, in other jurisdictions. For health-record, hospital, or identifiable patient-data deployments, India-based hosting and processing may be offered or preferred as a stronger governance posture.

Where cross-border access, processing, storage, support, or transfer is used, MeeAayu will seek to apply appropriate contractual, technical, and organizational safeguards consistent with applicable law and the sensitivity of the data involved.

13. Children and guardian data

MeeAayu does not knowingly permit unlawful direct use by children where consent from a parent or legal guardian is required. Where a child’s data is processed in a permitted context, such processing may be based on parent, guardian, hospital, or other authorized representative involvement, subject to applicable law and service design.

Guardian, nominee, or caregiver data may also be processed where required to support family-linked health use cases, authorized care support, emergency handling, or hospital-linked workflows.

14. User rights and requests (DPDPA Act 2023 Compliance & Grievance Officer Details)

Subject to applicable law and the nature of the service, users may have rights relating to notice, access, correction, consent withdrawal, grievance submission, and other privacy-related requests. MeeAayu may provide web forms, in-product mechanisms, support channels, or grievance contacts to facilitate such requests.

MeeAayu may need to verify identity, clarify the request scope, or retain certain information where deletion or unrestricted action is not legally or operationally possible.

DPDPA Act 2023 Compliance & Grievance Officer Details:

Under the Digital Personal Data Protection Act, 2023 (DPDPA) of India, you act as the Data Principal, and MeeAayu acts as the Data Fiduciary. If you have queries regarding consent withdrawal, data corrections, or general compliance questions, you may contact our designated Grievance Officer:

Grievance & Data Protection Officer

MeeAayu Technologies Private Limited

Email: grievances@meeaayu.com

15. Cookies, analytics, and similar technologies

MeeAayu may use cookies, SDKs, pixels, local device identifiers, logs, analytics tools, and similar technologies to operate the website or application, remember preferences, maintain sessions, improve performance, detect abuse, and understand usage trends.

Where required, consent or appropriate controls may be provided for non-essential tracking or analytics technologies. Browser-level settings or device controls may also affect how certain tracking technologies function.

16. Third-party websites and integrations

The service may link to, embed, or interoperate with third-party websites, hospital systems, ABDM systems, communication tools, payment services, labs, or other external services. MeeAayu is not responsible for the privacy practices of independent third parties, except to the extent required by law or contract.

Users should review the privacy notices and terms of relevant third-party services before using them.

17. Business transfers and restructuring

If MeeAayu undergoes a merger, acquisition, asset sale, financing, reorganization, or similar transaction, personal data may be disclosed or transferred as part of that process, subject to applicable law, confidentiality obligations, and reasonable continuity of privacy protections.

18. Updates to this Privacy Policy

MeeAayu may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We will notify waitlist members of any material changes via the email address provided.

Where required by law or where the change materially affects how personal data is processed, additional notice, refreshed consent, or other appropriate steps may be taken.