Privacy Policy

Version 1.0 · Last updated 28 July 2026 · Effective 28 July 2026

In short

Anmaya Connect exists to make people and organisations in the AYUSH professions findable. Much of what you put on your profile is deliberately public and indexed by search engines — that is the service, not a side effect. Your contact details, résumé, applications, identity and licence documents, and the enquiries you send or receive are not public.

You choose what to share, and you can change or delete it at any time — whether or not you hold an account.

This policy covers Anmaya Connect. Anmaya HMS is a separate product with its own policy.

1. Who we are

Anmaya Health Technologies Private Limited
Pavithram Towers, 13/77, Nehru Nagar West, Kalapatti Road, Coimbatore 641014, Tamil Nadu, India

We are the Data Fiduciary for personal data processed on Anmaya Connect, under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.

Our Grievance Officer handles complaints under both that Act and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. Contact details are in section 16 and in the footer of every page. You do not need an account to contact us.

2. What this policy covers

This policy applies to everyone who uses Anmaya Connect — whether you hold an account, use the platform on behalf of an organisation, contact someone through it, or simply browse.

Where something applies only in a particular situation, we say so.

3. What we do not do

We do not hold clinical records. Anmaya Connect is a professional network, not a clinical system. We do not operate an electronic health record, receive patient records from any hospital, or process ABHA numbers or ABDM health data. We do not offer patient appointment booking.

We ask you not to send us health information. Note fields on request and enquiry forms are short courtesy messages, not a place for symptoms, diagnoses or medical history. Health content submitted there may be removed.

We handle no money. We do not process payments, hold funds or take commissions. Any fee or price shown is stated by the user who published it and is paid directly between the parties, off the platform. We hold no card or bank details.

We do not sell personal data, and we do not use your content to train artificial intelligence models. If either ever changes, we will ask for your consent first.

4. Information we collect

WhatDetails
Who you areName, photograph, date of birth, gender, email, mobile number, city and State
Your professional backgroundQualifications, institution, year of qualification, council and registration number, specialities, experience, current and past roles, languages
Verification recordsWhich register we checked, when, the outcome, reviewer notes, and who vouched for you
What you publishProfile details, articles, case studies, images, course and event listings, catalogue items, job listings
Organisation detailsWhere you use Connect for an organisation: its name, type, address, registration identifiers, and the details of the person representing it
Licence and compliance documentsWhere you list products: GST, manufacturing, food safety or certification documents and their expiry dates. Held privately and never published
Job-seeking informationYour résumé, preferences, applications and their status
Requests and enquiriesYour name, mobile number, and optionally email, quantity and a short note, when you contact someone through the platform
Consent recordsWhich notice you were shown, what you agreed to, and when
How you use the platformIP address, device and browser, approximate location from IP, sign-in times, pages viewed, and cookies
What you send usSupport messages, complaints and appeals

We do not collect Aadhaar numbers, biometrics, caste, religion or political affiliation, and we do not buy personal data from brokers.

5. Why we use it

  • To create, display and verify your profile, organisation page, listings or catalogue
  • To make your profile publicly discoverable, including by search engines
  • To connect you with roles, courses, suppliers and other users
  • To pass your request to the person or organisation you contacted, so they can respond
  • To verify your mobile number when you make a request
  • To send you service messages — verification outcomes, one-time passwords, request updates, security alerts, complaint responses and changes to our terms
  • To send optional updates and alerts you have chosen
  • To prevent fraud, fake profiles, spam and abuse, and to keep the platform secure and working
  • To produce aggregated statistics about the AYUSH sector, which do not identify anyone
  • To comply with the law, court orders and lawful requests from authorities

6. Your consent

Most of what we do rests on your consent, given by a clear affirmative action — ticking a box at sign-up, or on a request form, after being shown a plain-language notice.

Consent is specific rather than bundled. Declining something optional does not stop you using the rest of the service.

You can withdraw consent at any time, as easily as you gave it. If you hold an account, use Settings → Privacy. If you made a request without an account, use the private link we sent you by SMS. Or email privacy@anmayahealth.com. Withdrawal does not affect what we lawfully did beforehand. If you withdraw consent that the core service depends on, we will tell you before you confirm, because we will no longer be able to maintain your account.

Some processing continues without consent where the law allows it: complying with a legal obligation or court order, responding to a lawful request from a government agency, preventing fraud and abuse, and protecting information security.

7. What is public, and what is not

Public and indexed by search engines: your name, photograph, qualifications, specialities, city and State, verification badges and the dates we checked them, organisation affiliations, and anything you publish — articles, case studies, listings and catalogue items.

Your council registration number appears masked publicly, for example TN-AYUSH-…204, and in full only to signed-in users. You may choose to show it in full; we recommend against it, because your full name, photograph and full registration number together are what someone would need to impersonate you elsewhere.

Never public: your email, phone, date of birth, gender, résumé, job applications, identity and licence documents, reviewer notes, who vouched for you, the details of people who contact you, and anything you send our support team.

Your controls. You can hide non-essential fields, or set your profile to members-only, which removes it from public view and from search results. A public verified profile must show at least your name, qualifications and verification status.

Search engines are not ours to control.When you hide or delete something we remove it from search on our side promptly. Copies already held in a search engine's index, cache or a third-party archive disappear on that provider's timetable, not ours. We will help you request removal, but we cannot promise a date.

8. Verification badges and compliance marks

A badge or mark means we reviewed a register entry or a document on the date shown. It does not mean the registration or licence is currently valid or in good standing — authorities may suspend or cancel one at any time without telling us. Marks lapse at their recorded expiry date. We publish the mark and its review date, never the underlying documents.

9. Published clinical content

Anyone publishing content describing a patient's assessment, treatment or outcome must have that patient's informed written consent and must remove anything that could identify them — no name, no identifiable photograph, no registration or hospital number, no exact dates, age given as a band, no locality below district level.

We may review such content before or after publication and will unpublish anything that falls short.

If you believe published content on this platform describes you, write to grievance@anmayahealth.com. We will remove it from public view while we investigate. You do not need an account, and you do not need to identify the author.

10. When we share your information

With other users. When you apply for a role, your résumé and contact details go to that employer. When you contact a course organiser or a supplier, your name and phone number go to that recipient — named on the form before you submit — so they can reply. Nobody else sees them: not other users, not search engines, not any export.

This is not consent to marketing. Our Terms require recipients to use your details only to answer that request, never to build a list. Once they have your details, they are independently responsible for them under the law. When you withdraw or ask for erasure, we tell them and they must act; we cannot delete data from their own records for them.

With service providers. We use third parties to host the platform, deliver email and SMS, and keep the service secure and working. They act on our instructions only, under written contracts meeting the requirements of the DPDP Rules, and may use your data for nothing else. A current list is available on request.

With authorities. We disclose personal data to courts, regulators and law enforcement only where lawfully required, and only what is required.

We never sell your personal data.

11. Where your data is stored

Your personal data is stored and processed in India.

12. Cookies

We use cookies that are strictly necessary — signing you in, keeping your session, security, and remembering your privacy choices. These cannot be switched off.

We also use optional cookies for convenience features and for pseudonymised analytics that tell us which features are used and what breaks. These stay off until you accept them, and you can change your mind at any time from the cookie settings link in the footer.

We use no advertising or cross-site tracking cookies and run no advertising pixels. We honour Global Privacy Control and Do Not Track signals for optional cookies.

13. How long we keep things

We keep personal data only as long as we need it for the purpose you gave it for, and then delete it or make it permanently anonymous.

In practice:

  • While your account is open, we keep your profile and content. After you deactivate, we hold it for 12 months so you can return without re-verifying, then delete it.
  • When you ask us to delete, we remove it from the platform immediately and from backups within 35 days.
  • Requests and enquiries are deleted 30 days after they are sent if nobody acts on them, and 90 days after they are closed otherwise. Course and event lists are deleted 90 days after the event ends.
  • Verification and licence records are kept for 3 years after a badge or mark expires, as our audit trail for its integrity.
  • Complaint records are kept for 3 years.
  • Consent records are kept for 3 years and cannot be used to contact you.
  • If you opt out of contact, we keep a one-way encoded form of your number indefinitely so we can honour that. It cannot be reversed or used to reach you.
  • Security logs are kept for one year, and system logs for at least 180 days in India, as the law requires.
  • Financial and statutory records are kept for 8 years under company and tax law.

Where we let an organiser or supplier export their own list of enquiries, our retention periods no longer reach that copy. They are bound by our Terms to the same limits, but the data sits with them.

14. Keeping it safe

We encrypt data in transit and at rest, limit access to those who need it, require multi-factor authentication for administrative access, mask contact details in system logs, hold licence documents in private storage separate from published content, monitor access, review permissions periodically, keep development separate from live systems, and require confidentiality of everyone who works with us.

No system is perfectly secure. If you find a vulnerability, tell us at grievance@anmayahealth.com — we will not pursue anyone who reports responsibly and does not misuse what they find.

If something goes wrong, we report qualifying security incidents to CERT-In within 6 hours, notify the Data Protection Board of India without delay and file a full report within 72 hours, and tell you directly — in plain language, covering what happened, what was involved and what to do. There is no severity threshold and no requirement that you hold an account.

15. Your rights

You can:

  • See what personal data we hold about you, how we use it, and who we have shared it with
  • Correct or complete anything inaccurate or out of date
  • Delete data we no longer need
  • Withdraw consent for anything you agreed to
  • Nominate someone to exercise these rights if you die or become incapacitated
  • Download your data and take it elsewhere
  • Complain, to us and beyond us

These rights belong to everyone, including people with no account.

If you hold an account, most of this is self-service in Settings → Privacy. If you made a request without an account, use the private link we texted you. If you have lost it, or want something else, email privacy@anmayahealth.com.

We acknowledge within 24 hours and complete requests within 15 days, telling you if something genuinely needs longer. The law allows up to 90 days for grievances; we do not intend to use it.

We will verify who you are using information we already hold. We will not ask you for new identity documents to answer a question about data we already have.

16. Complaints

Write to our Grievance Officer at grievance@anmayahealth.com. No account needed. We acknowledge within 24 hours and respond within 15 days with our reasons.

If you are unhappy with how we handled a complaint about content or another user's conduct, you may appeal to the Grievance Appellate Committee at gac.gov.in within 30 days.

If you are unhappy with how we handled your personal data, you may complain to the Data Protection Board of India through its digital portal.

None of this affects your rights under consumer law, or your right to go to court.

17. Children

Anmaya Connect is for adults.You must be 18 or over to hold an account or send a request. We do not knowingly process the personal data of anyone under 18, and we do not track children's behaviour or direct advertising at them.

If you believe someone under 18 holds an account, tell us at privacy@anmayahealth.com and we will suspend it and delete the data.

18. Language

This policy is published in English. We will provide it, and any notice, in any language listed in the Eighth Schedule to the Constitution of India on request to privacy@anmayahealth.com.

19. Changes to this policy

We may update this policy. For material changes we will give at least 15 days' notice by email and in the app before they take effect, and publish the new version. Where a change requires it, we will ask for your consent again rather than assume it.

20. Contact us

Anmaya Health Technologies Private Limited
Pavithram Towers, 13/77, Nehru Nagar West, Kalapatti Road, Coimbatore 641014, Tamil Nadu, India

Privacy: privacy@anmayahealth.com
Grievance Officer: grievance@anmayahealth.com


See also: Terms of Service