PRIVACY POLICY & DATA PROTECTION
Last Updated: 01/04/2026
1. STATUTORY FRAMEWORK, OWNERSHIP & SCOPE
This Privacy Policy (“Policy”) is a digital mandate published in accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act (DPDPA), 2023.
Lawcription is a digital platform and brand operated under Healthcription, owned by Mrs. Poulomi Debnath. For the purpose of this Policy, Healthcription (operating as "Lawcription") shall be the "Data Fiduciary" responsible for protecting the privacy of its Users ("Data Principals").
All services, financial transactions, and legal obligations—including the processing of your Personal Data—are undertaken by Healthcription. By accessing the App, you provide Unambiguous, Informed, and Affirmative Consent to the processing of your data as described herein.
2. TAXONOMY OF DATA COLLECTED
We limit data collection to the Principle of Purpose Limitation and Data Minimization:
- Identity & Contact Data: Legal name, mobile number, and email address.
- Professional Credentials: Academic qualifications and professional registration details, essential for verifying status under the NMC Act, 2019.
- Technical & Usage Metadata: IP address, device identifiers, and interaction logs.
- Transaction Data: Details of subscriptions and payments.
- Legal Safe Harbor: We do not store "Sensitive Financial Data" like CVVs or PINs; all payments utilize PCI-DSS compliant, RBI-authorized gateways.
3. LEGAL BASIS & PURPOSE OF PROCESSING
Under Section 4 of the DPDPA, 2023, processing occurs only for "Lawful Purposes":
- Contractual Necessity: Providing access to medico-legal resources.
- Verification: Ensuring use by legitimate healthcare professionals.
- Communication: Service updates and statutory notifications.
- Legitimate Uses: Fraud prevention or responding to judicial mandates.
4. NOTICE AND CONSENT MECHANISM
- Notice: This Policy serves as a notice under Section 5 of the DPDPA.
- Withdrawal of Consent: You may withdraw consent at any time by writing to the Grievance Officer. Withdrawal may result in immediate termination of App services.
5. DATA RETENTION & ERASURE (RIGHT TO BE FORGOTTEN)
- Retention: Data is kept only as long as necessary for the stated purposes or as required by the Prevention of Money Laundering Act (PMLA) and tax laws.
- Erasure: Upon account termination or consent withdrawal, data will be erased within a reasonable timeframe unless retention is legally mandated.
6. DATA SHARING & THIRD-PARTY DISCLOSURES
- Data Processors: We use third-party providers (Cloud hosting, Analytics) under strict Data Processing Agreements complying with Indian Law.
- No Commercial Sale: We strictly prohibit the sale of Data Principal information to third-party marketing entities.
- Law Enforcement: Data will be disclosed if served with a valid warrant or order from a Court or Regulatory Authority.
7. SECURITY ARCHITECTURE
We employ Reasonable Security Practices and Procedures (RSPP) as per ISO/IEC 27001 standards, including end-to-end encryption and Role-Based Access Control (RBAC). Lawcription (Healthcription) is not liable for breaches resulting from User negligence or systemic vulnerabilities beyond its reasonable control.
8. STATUTORY RIGHTS OF THE DATA PRINCIPAL
Pursuant to the DPDPA, 2023, you are entitled to:
- Right to Information: Summaries of data processed.
- Right to Correction/Erasure: Rectifying inaccuracies or requesting deletion.
- Right of Grievance Redressal: Access to a channel for privacy concerns.
- Right to Nominate: Appointing a representative in the event of death or incapacity.
9. GRIEVANCE REDRESSAL MECHANISM
In accordance with Rule 3(11) of the IT Rules, 2021 and Section 13 of the DPDPA, please contact:
- Name: Mrs. Poulomi Debnath
- Designation: Grievance & Data Protection Officer
- Email: lawcriptionadmin@gmail.com
10. PROTECTING MINORS
The App is strictly for individuals above 18 years of age. We do not knowingly process data of "Children" (as defined under DPDPA); such data will be deleted immediately if discovered.
11. CROSS-BORDER TRANSFERS
Data may be processed on servers outside India, provided transfers comply with Central Government "Whitelisting" and maintain adequate safeguards.
12. AMENDMENTS
We reserve the right to amend this Policy. Continued use of the App constitutes "Deemed Acceptance" of the revised Policy.