IITK Foundation for Medical Research & Technology ("FMRT", "we", "our", or "us"), an initiative of the Indian Institute of Technology Kanpur, is deeply committed to protecting the privacy and confidentiality of all personal information entrusted to us.
This Privacy Policy governs the collection, use, storage, disclosure, and protection of information gathered through our website www.fmrt.co.in and all interactions with patients, caregivers, researchers, donors, vendors, job applicants, and general visitors.
This policy is compliant with the Information Technology Act, 2000, the IT (Reasonable Security Practices) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDPA).
We collect information necessary to deliver our healthcare, research, and administrative services. Categories of information we may collect:
| Category | Examples | Purpose |
|---|---|---|
| Identity & Contact | Name, date of birth, gender, address, phone, email | Registration, appointments, communication |
| Health & Medical | Medical history, diagnoses, prescriptions, lab reports | Clinical care, research (with consent), compliance |
| Financial | Payment details (via secure gateways), insurance info | Billing, receipts, fund management |
| Technical / Usage | IP address, browser type, pages visited, cookies | Analytics, security, service improvement |
| Research Participation | Survey responses, trial participation records | Approved clinical/academic research (ICMR guidelines) |
| Employment | CV, qualifications, references, background checks | Recruitment and HR administration |
We use your information only for legitimate and stated purposes:
- →Providing medical care, diagnostic services, and treatment at the Yadupati Singhania Hospital and associated facilities on the IIT Kanpur campus.
- →Managing appointments, medical records, test results, and follow-up communications.
- →Processing payments and managing billing or insurance claims.
- →Conducting approved clinical research and academic studies in accordance with ethics committee approvals and ICMR guidelines.
- →Sending service notifications, health advisories, and updates about FMRT initiatives (you may opt out at any time).
- →Ensuring the security and proper functioning of our Website and systems.
- →Complying with applicable laws, court orders, and regulatory requirements.
- →Improving our services through anonymised analytics and internal audit.
Health and medical data is classified as Sensitive Personal Data or Information (SPDI) under Indian law and is accorded the highest level of protection. Additional safeguards we apply:
- ✓Access is strictly limited to authorised clinical and administrative staff on a need-to-know basis.
- ✓Medical records are maintained in compliance with the Clinical Establishments (Registration and Regulation) Act, 2010 and applicable state regulations.
- ✓Patient records are retained for a minimum period as prescribed by National Medical Commission guidelines.
- ✓Health data shared for research purposes is pseudonymised or anonymised wherever feasible, and only used under a valid ethics committee approval.
- ✓Your explicit written or electronic consent is obtained before using your health data for purposes beyond direct clinical care.
We may share your information with the following parties, strictly for the purposes described in this Policy:
All third parties are bound by confidentiality obligations and are prohibited from using your information for any other purpose.
Our Website uses cookies and similar technologies to enhance your browsing experience and gather usage analytics:
You may disable non-essential cookies through your browser settings at any time. We do not use cookies to serve third-party advertisements.
We implement industry-standard technical and organisational measures to protect your information:
- →TLS/SSL encryption for all data transmitted via our Website.
- →Role-based access controls and multi-factor authentication for staff accessing patient data.
- →Regular vulnerability assessments and security audits of our systems.
- →Physical access controls at data storage facilities within the IIT Kanpur campus.
- →Regular staff training on data privacy and confidentiality obligations.
Under the Digital Personal Data Protection Act, 2023 and other applicable laws, you have the following rights with respect to your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Correction
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your data where no longer required, subject to legal retention requirements.
Right to Withdraw Consent
Withdraw consent for processing at any time, without affecting prior lawful processing.
Right to Grievance Redressal
Lodge a complaint with our DPO or with the Data Protection Board of India.
Right to Nominate
Nominate another person to exercise these rights on your behalf in the event of incapacity.
To exercise any of these rights, please contact our Data Protection Officer (Section 12). We will respond within 30 days of receiving a valid request.
We recognise that the health data of children requires heightened protection. For patients under 18 years of age:
- ✓All consent for collection and processing of health data is obtained from a parent or legal guardian.
- ✓We do not collect data from children directly through our Website without verifiable parental consent.
- ✓Data relating to minors is subject to stricter access controls and is not used for research or secondary purposes without explicit guardian consent.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
| Data Type | Retention Period |
|---|---|
| Medical Records | Minimum 7 years from date of last treatment (NMC guidelines), or longer where required |
| Financial Records | 8 years from date of transaction (Indian tax & audit regulations) |
| Recruitment Records (unsuccessful applicants) | 1 year from date of application, then securely deleted |
| Website Usage Data | Up to 26 months in anonymised or aggregated form |
Upon expiry of the applicable retention period, data is securely deleted or anonymised in an irreversible manner.
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or the services we offer. The revised Policy will be posted on this page with an updated effective date.
For material changes, we will provide a prominent notice on our Website or notify you directly. Your continued use of our Website or services after any changes constitutes your acceptance of the updated Policy.
For privacy-related queries, data requests, or to lodge a grievance, please contact our Data Protection Officer:
Also Review Our Terms of Service
Our Terms of Service outline the rules governing your use of this Website, including medical disclaimers, intellectual property, and dispute resolution.
Read Terms of Service →