Privacy Policy
This Privacy Policy is formulated, published, and enforced by Ballderma Clinic (“Ballderma” or “the Clinic”) in compliance with the provisions of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and all other rules, notifications, circulars, and amendments applicable under the laws of India. The Policy is intended to govern the collection, receipt, storage, processing, handling, use, transfer, disclosure, and retention of information, including personal information and sensitive personal data, pertaining to individuals who visit the Clinic, access its website, or otherwise engage with its services (“Users”). By voluntarily providing information to the Clinic, or by continuing to use the website and booking facilities, Users signify their unconditional consent to the terms and conditions contained herein.
Ballderma recognises and affirms that the privacy of its patients and Users is a matter of utmost importance. Accordingly, the Clinic undertakes that it shall, at all times, collect only such information as is necessary for legitimate business and medical purposes, shall process the same in a fair and lawful manner, and shall ensure that the data so collected is secured by implementing reasonable technical, administrative, and organisational measures consistent with Indian law and accepted industry standards.
The Clinic, in the ordinary course of its business, may collect from Users certain basic personal information including but not limited to the full name, email address, and mobile number of the User, which are essential to facilitate the scheduling and confirmation of appointments. Further, in the course of in-clinic consultations, Users may disclose sensitive personal data, including details of medical history, treatment records, dermatological conditions, diagnostic reports, or any other health-related information, all of which shall be received and processed exclusively for the purposes of providing medical consultation and treatment. Ballderma confirms that at present it does not request, solicit, or process online payments through its website, and therefore does not collect banking credentials, credit card details, or other financial information.
The personal information so collected shall be utilised only for purposes that are incidental, ancillary, or reasonably connected with the provision of healthcare services, including confirmation and management of appointments, communication of reminders and updates, addressing queries and grievances, internal record-keeping, improvement of patient care, and compliance with statutory or regulatory requirements. At no stage shall the Clinic sell, rent, disclose, or otherwise exploit personal data for commercial purposes unrelated to the delivery of medical services.
The Clinic may, where strictly necessary, share personal data with carefully selected service providers who assist in appointment scheduling, communication services, or data management. Such third parties shall be contractually bound to maintain confidentiality and adopt reasonable security practices. Additionally, the Clinic may disclose information when required by law, pursuant to directions of regulatory or governmental authorities, in response to lawful requests, or to protect the rights, property, and safety of the Clinic, its staff, or its patients.
Ballderma affirms that it has instituted security measures consistent with Rule 8 of the IT Rules, including the implementation of secure servers, password-protected systems, restricted access protocols, and periodic monitoring of networks to safeguard information from unauthorised access, alteration, destruction, or disclosure. While every effort is made to secure data, the Clinic disclaims liability for any unauthorised access or breach that occurs despite the exercise of reasonable care and due diligence, as no system connected to the internet is entirely immune from risk.
Users are entitled, under law, to seek access to their personal information held by the Clinic, to request rectification of inaccuracies, and to withdraw consent for continued use, storage, or processing of their information. Requests in this regard may be addressed in writing to the designated Grievance Officer of the Clinic at contact@ballderma.com or +91 98199 93433 / +91 98199 97833. Such requests shall be considered and responded to in a manner consistent with applicable legal obligations, provided that withdrawal of consent shall not prejudice the lawfulness of processing carried out prior to such withdrawal and shall not affect data that the Clinic is required to retain under medical and regulatory record-keeping obligations.
Ballderma shall retain personal and sensitive data for such period as is necessary for the fulfilment of the purposes for which it was collected and for compliance with applicable statutory and regulatory requirements. Upon completion of such period, or upon valid withdrawal of consent by the User, the Clinic shall ensure secure deletion or anonymisation of the information, unless retention is otherwise required by law.
Without prejudice to the rights of Users, Ballderma shall not be held responsible or liable for any disclosure, loss, or damage resulting from events beyond its reasonable control, including but not limited to hacking, phishing, cyber-attacks, technical failures, or compelled disclosure pursuant to judicial or governmental directions. Users acknowledge that transmission of data over the internet is inherently subject to risks, and by continuing to use the website, they assume such risks.
Ballderma reserves the right to revise, amend, or update this Privacy Policy at any time without prior notice, to reflect changes in law, technology, or business operations. The revised Policy shall be effective from the date of publication on the Clinic’s website, and continued use of the services shall constitute deemed acceptance of the revised terms. Users are encouraged to review the Policy at regular intervals to remain informed of their rights and the Clinic’s obligations.
This Privacy Policy shall be governed by and construed in accordance with the laws of India, and the courts at Mumbai, Maharashtra shall have exclusive jurisdiction over any disputes or claims arising out of or in connection with this Policy.
By proceeding to book an appointment or otherwise providing information to the Clinic, the User acknowledges that they have read and understood this Privacy Policy, and agree to be bound by its terms and conditions in entirety.
