Skip to content
Astitva

Draft for legal review, not yet in force.

Practitioner privacy policy

Astitva for Practitioners, a product of Velcro Ventures OPC Private Limited
Last updated: [date of publication]

This policy is for practitioners: the clinical psychologists, counsellors and doctors who apply to give sessions through Astitva, and who use the Astitva for Practitioners app. It says what we collect about you, why, where it is kept, who receives it and for how long. It also says what you can ask us to do with it, and how to ask. The people who book you use a separate app, Astitva, which has its own privacy policy.

The short version

  • We collect what we need to check you, list you, run your sessions and pay you: your application and documents, your bank and tax details, your hours, and the records of your sessions and earnings.
  • Patients see your public profile: your name, photograph, qualification, registration and what you write about yourself. They never see your email address, mobile number, documents, PAN or bank details.
  • We pay you ourselves, by bank transfer, so we keep your bank details. Your account number is kept encrypted. Astitva's admins can open it only while a payout to you is being paid, and each time is recorded. The person who looks after our database could also reach it, and must not read it.
  • Your calls run through 100ms. Astitva does not record them.
  • Payment and tax records are kept for 8 years, because the law requires it.
  • We do not sell your data. There are no adverts in the app, and no advertising or analytics trackers.

Who we are

Astitva for Practitioners is a product of Velcro Ventures OPC Private Limited, a company registered in India ("we", "us").

  • Registered address: [registered address]
  • Email: [contact email]

We decide what Astitva collects about you and why. That makes us responsible for your personal data under Indian law, including the Digital Personal Data Protection Act 2023 (the DPDP Act), which calls us the data fiduciary. The practitioner agreement is the contract between us; this policy is part of it.

What we collect, and why

Your account

  • Your email address and password. To make your account, sign you in, send you a 6-digit code if you forget your password, and write to you. Your password is stored only in a scrambled, one-way form. Nobody can read it, including us.
  • Sign-in records. Each sign-up, sign-in, password reset and account deletion, with the email address and the internet address (IP address) it came from. To keep your account safe and to find faults.

Your application

  • What you tell us: your discipline (clinical psychologist, counsellor or doctor), your legal name as it is on your ID, your mobile number, your qualification, your registration number and council (not asked of counsellors), the languages you work in, one line on what you help with, and a short bio.
  • Your agreement: the time you agreed to the practitioner agreement and this policy, and a record of each time you ticked or unticked the box while your application was yours to change, with the time of each.
  • Our review: where your application has got to, our reviewers' notes to you, and who decided and when.
  • Why: to check you before you are listed, as the Telemedicine Practice Guidelines 2020 ask of platforms; to reach you about your application; and to build the profile patients see. Your legal name becomes the name patients see.

Your documents

  • What you send: your government ID and a photograph of you; your registration certificate if you are a clinical psychologist or a doctor; your degree if you are a counsellor; and any certifications or other documents you choose to add.
  • Before they are sent: a document that is a picture (for example, a photo of your ID) is turned the right way up, made smaller if it is very large, never so small that its small print cannot be read, and cleared of what a camera writes into a picture: where and when it was taken, and the phone it was taken with. That data never leaves your phone. A PDF is sent as it is.
  • Where they are kept: in a private store. Only you and our reviewers can open them. Reviewers open them through links that stop working after 10 minutes.
  • Why: to check that you are who you say you are, and that you hold the qualification and registration your profile shows.
  • Removing one: while your application is still yours to change (before you send it, or when we send it back to you), you can remove a document in the app. It leaves your application straight away, and its file is deleted from the store soon after, usually within an hour. Once your application is with us, its documents stay with it.

Your photograph

Before your photograph is sent, the app crops it to a square, makes it smaller, and removes what a camera writes into a picture: where and when it was taken, and the phone it was taken with. That data never leaves your phone. A reviewer checks the photograph against your ID. Once they pass it, it goes into a public store for your profile: patients see it, and anyone with its link can open it. A new photograph you send later waits for a reviewer, and patients see your old one until then.

[for the lawyer: anyone holding the app's public key can list the public store, not only open a photograph whose link they have.]

Your bank and tax details

  • What you give: your PAN, your bank account number, the IFSC and the name on the account. You type the account number twice, so a slip is caught before it is saved.
  • What we keep: all four. Your account number is kept encrypted. The app shows you only its last four digits. We also keep when you saved them.
  • Who can open your account number: Astitva's admins, in our admin console, and only while a payout to you is being paid. Each time is recorded, with who opened it and when. The person who looks after our database could also reach it, outside the console, where no record is made. They must not read it. [for the lawyer: a bank account number is sensitive personal data under the SPDI Rules 2011. Every admin account can open it in the console, for a payout that is being paid, and each reading there is recorded. Whoever holds the database's own login can read it at any time with no record made; only our instruction stops them. Until we switch to live payments, sessions are paid with Razorpay's test keys, and a payout for them moves no money; an admin can still open the practitioner's real account number for it. Each such reading is recorded, but the record is deleted with the test payouts at the switch. Confirm that encrypting it, limiting the console to payouts being paid and recording each reading there is enough, say whether the record of readings for test payouts must be kept, and say what the instruction to the database's keeper must be.]
  • Why: to pay you by bank transfer from our bank account, and to deduct tax at source (TDS) and report it, as income tax law requires.
  • Changing them. Only the bank step in the app, or Your bank in Earnings, can change your PAN and bank details. If your account number or IFSC changes, we tell you in the app, in case it was not you. You cannot change them while a payout to you is being paid.

Your hours and your sessions

  • Your hours: the hours you work each week and your days off. The app makes the times patients can book from them.
  • Your bookings: each session's time, length, price, how the price is split, and what happened to it: paid, cancelled, missed, or the subject of a concern.
  • Concerns: when you or a patient raises one, its reason, what each side wrote, and what we decided.
  • Your earnings: for each session, the price, our commission, the GST on it, any tax deducted at source, what you receive, and the payout it was paid in.
  • Your payouts: for each one, the amount, the sessions it covers, the day it was paid, our bank's reference, and the last four digits, IFSC and name of the account it was paid into.
  • Why: to run your sessions, pay you, decide concerns, and keep the accounts that company and tax law require.

Your calls

Sessions are video calls inside the app, carried by 100ms.

  • Your picture and your voice travel through 100ms's servers while the call is on, to reach the patient, and are not kept. Astitva does not record calls, and our 100ms account has recording switched off. [for the lawyer: "never recorded" rests on the settings of our 100ms account; the app itself records nothing.]
  • What 100ms is told: that someone is joining as the practitioner, never your name, email address or account. While the call is on it also sees what any call service needs: your phone's internet address, details of the phone and the quality of the connection.
  • When you and the patient joined and left the call, which 100ms tells us, kept with the booking. If one of you says the other never came, this is how we can check. You, the patient and the people at Astitva who handle concerns can see it.
  • Your camera and microphone: the app asks for them the first time you join a call. If Bluetooth earbuds or a headset are connected, your phone may also ask whether the app can connect to nearby devices, so the call can play through them.
  • The app blocks screenshots while a call is on.

Notifications

  • From our servers: notes about your application, your photograph, your bookings, cancellations, concerns and payouts. For this, the app gives us a device token: a code that lets Firebase Cloud Messaging, a Google service, reach the app on your phone. Each note is also kept in the app's list of notes. A note may show on your locked screen, depending on your phone's own settings.
  • Made on your phone: reminders of your sessions, of your day, and of earnings that are ready to be paid. Some name the patient and the time. They never show their words on a locked screen. You can turn each kind off under You.

What stays on your phone

The app keeps a few things on your phone, encrypted with a key held in your phone's secure keystore: your sign-in, your reminder settings, and whether the app has asked for your camera and microphone. They are kept for your account, left out of Android's backups, and erased when you delete your account in the app or remove the app.

When you write to us

What you send us and our reply. To answer you, and to keep the record of complaints the law requires.

What patients see about you

  • Your public profile, while you are verified and not paused: your name, photograph (or a drawing, until one is passed), discipline, qualification, registration number and council, languages, what you help with, your bio, and the price and length of your sessions. Your open times. [for the lawyer: anyone signed in to Astitva can read an active practitioner's profile, not only people who have booked her.]
  • On a booking, its receipt and its notes: your name, discipline, qualification and registration.
  • In a concern: what you write in it.
  • In a call: your picture and your voice.

Patients never see your email address, mobile number, documents, PAN, bank details, earnings, or your hours beyond the times they can book.

What you see about patients

About each person who books you, you see the name they give for the session, their age on the day they booked, their gender, what they tell you, and what they write in a concern. You never see their email address, their phone number, their account, or anything they keep in the Astitva app.

What they tell you is theirs. The practitioner agreement asks you to keep it confidential, as the rules of your profession require. Any clinical notes you keep are yours to keep under those rules: Astitva has no place for them and never sees them. [for the lawyer: for her own notes and records the practitioner is her own data fiduciary.]

Who else receives your data

Each receives only what it needs, for the reason given.

  • Our bank, [to confirm: the bank's name], from whose account we pay you. It receives the name on your account, your account number and the IFSC, as any bank transfer needs. Your own bank receives our payment.
  • Razorpay Software Private Limited, which takes the patients' payments for your sessions. It sees your name on each payment, which is described as a session with you. It does not receive your bank details, your PAN, your address or how to reach you.
  • 100ms Inc, which carries the picture and sound of your calls while they are on, as our data processor, and keeps its own record of when each side joined and left. Its servers for Astitva's calls are in India [to confirm: 100ms account set to India].
  • Supabase, Inc., which runs our database, sign-in and file storage for us, as our data processor. Its servers for Astitva are in [region, to confirm].
  • Google. Firebase Cloud Messaging carries notifications. Google Play delivers the app.
  • [email provider, to confirm], which carries our email, including the code for resetting your password.
  • Patients, as "What patients see about you" says.
  • The Income Tax Department, which receives your PAN, your payments and the tax deducted from them, in our TDS returns. [for the lawyer: the quarterly returns and the TDS certificates are prepared outside the app, which does not produce them yet.]
  • Courts and government agencies, when the law requires us to, for example under a court order, or to a professional council asking about your registration.

We do not sell, rent or trade your personal data, and we do not use it for advertising or marketing. If Astitva is ever sold or merged into another company, your data would move only under this policy, and we would tell you first.

Your consent

You agree to this policy and the practitioner agreement when you tick the box before you send your application. We record the time. If you untick the box before you send your application, your application no longer says that you agree, and it cannot be sent until you tick the box again. We keep a record of each tick and untick, with its time, so we can show what you had agreed to and when. That record is deleted when you delete your account. Your phone asks separately for the camera, the microphone and nearby devices, the first time a call needs them.

You can withdraw your consent at any time, as easily as you gave it: take the camera, the microphone or nearby devices away from the app in your phone's settings, turn reminders off under You, or delete your account. Withdrawing does not undo what was done before it, and some things cannot happen without the data they need: you cannot be listed without being checked, or paid without your bank details.

How long we keep things

  • Your application and documents: while you practise on Astitva, and until you delete your account.
  • If your application is rejected: your documents and your bank details (your account number, the IFSC and the name on the account) are deleted 90 days after the decision. If at that point we still owe you for sessions, or paid you less than 30 days before, your bank details are kept until 30 days after we last pay you, in case your bank sends the payment back. Your PAN is kept until you delete your account. [for the lawyer: the application itself and the PAN are kept until the account is deleted, which a rejected applicant can only ask for by writing to us; so are the documents of an application that is sent back to you or never sent.]
  • Your photograph: while you practise on Astitva. Older photographs you replaced stay in the public store until you delete your account. [for the lawyer: confirm this is acceptable, or ask for replaced photographs to be deleted.]
  • Your bank details: until you change them or delete your account. Deleting your account deletes them at once.
  • Your sessions, earnings, payouts and tax deducted: until 8 years after the end of the financial year of the last payment on them, the longest period company and tax law ask us to keep accounts. The record of each payout keeps the last four digits of the account it was paid into, its IFSC and the name on it, and who at Astitva opened your account number for it, and when. [for the lawyer: the nightly job that erases them after that time runs today only for sessions whose patient has deleted her account. Test payouts, made before we switch to live payments, move no money and are deleted at the switch, with the record of who opened her account number for them.]
  • When you and the patient joined and left a call: with the booking, for as long as it is kept.
  • Concerns: with the booking. When you delete your account, what you wrote in them is removed.
  • Notifications from our servers: until you delete your account [proposed: 90 days].
  • Device tokens: until you sign out or delete your account.
  • Sign-in records: 180 days, because India's CERT-In directions ask for logs to be kept that long, then erased.
  • Emails and complaints you send us: [proposed: 3 years after the last message].
  • Backups: Supabase backs up our database, and each backup keeps a copy for [backup period, per our Supabase plan]. Deleted data leaves the backups when that period ends.

When you delete your account

You cannot delete your account while sessions booked with you have not happened yet, while a concern about one of your sessions is still open, or while earnings are waiting to be paid out.

Deleted straight away: your account (you can no longer sign in, and your password is deleted), your application, your documents, your photographs, your hours and open times, the words on your profile, your bank details (your account number, the IFSC and the name on the account), your notifications, your device tokens, what you wrote in concerns, and what the app kept on your phone. Patients can no longer find you or book you.

Kept, locked away, and used only if the law requires it, or to pay you money we owe you:

  • A record that the account existed: your email address, when the account was made and closed, and your application (your name, mobile number, discipline, qualification, registration, where it had got to, when you sent it and when you agreed to the practitioner agreement). Kept for 180 days, because India's IT Rules 2021 require it.
  • If a session was ever booked with you, even one that was cancelled or never paid for: your legal name, discipline, qualification and registration, your PAN, and the records of your sessions, earnings, payouts and tax deducted. The record of each payout keeps the last four digits of the account it was paid into, its IFSC and the name on it. Kept until 8 years after the end of the financial year of the last payment on them, or of the session's own date when nothing was paid, because company and tax law require it. If no session was ever booked with you, your PAN is deleted straight away. [for the lawyer: this keeps the PAN of a practitioner whose only bookings were cancelled or never paid for. The rule could be narrowed to practitioners who were paid for a session.]

If a payout we sent comes back from your bank after you delete your account, we write to you at your email address to pay you another way. [for the lawyer: this uses the email address kept in the 180-day record, and nothing else of it. After 180 days we no longer have it. Say whether this use is allowed, and what we must do with money we cannot pay.]

Your rights

You have the right to:

  • Know what we hold: a summary of your personal data, what we do with it, and who we have shared it with.
  • Correct it or bring it up to date. What you help with, your bio, your languages and your photograph are under You. Your bank details are in Earnings. Your name, discipline, qualification and registration change only through a new review: write to us.
  • Have it erased. Delete your account in the app, whatever stage you are at: under You once you are verified, and until then, or while your account is paused, at the bottom of the screen the app opens on. You can also write to [contact email] from your account's email address and we will delete it. What the law makes us keep is kept, as above.
  • Withdraw your consent, as above.
  • Nominate someone to use these rights for you if you die or become unable to act for yourself. Write to us with their name and how to reach them.
  • Complain, to us first, and then, if you are not satisfied, to the Data Protection Board of India.

To ask, write to [contact email] from the email address of your account, so we can find it. If you write from another address, we will ask you to show the account is yours before we act. We reply within the times on our grievances and contact page.

The law also asks something of you: give us true information, and do not use anyone else's name, documents or details.

How we protect it

  • Everything between the app and our servers is encrypted in transit (HTTPS).
  • Our database checks every request against your account. Your documents, your PAN, and the last four digits, IFSC and name of your bank account can be read only by you and our reviewers; no app can change your PAN or bank details except through the bank step.
  • Your bank account number is kept encrypted. No app can read it, yours included. In our admin console an admin can open it only while a payout to you is being paid, and each time is recorded.
  • Supabase encrypts what is stored on its servers.
  • The people who run Astitva can reach data on our servers through Supabase's own tools, your bank account number included. We use that access only to keep Astitva working, to check applications, to pay you, to decide concerns, to act on a request from you, or when the law requires it. The person who looks after our database must not read your account number that way: to pay you it is opened in the console, where each time is recorded. [for the lawyer: nothing technical stops the holder of the database's own login from reading it, and no record is made if they do. This rests on our instruction to them.]
  • No system is perfectly safe. A screen lock on your phone protects what the app keeps there.
  • If a breach affects your data, we will tell you, the Data Protection Board of India and CERT-In, as the law requires.

Where your data is kept

Our servers are run by Supabase in [region, to confirm]. [If the region is outside India, add: "This means your data is kept outside India."] Razorpay processes payments in India. Video calls run on 100ms's servers in India [to confirm: 100ms account set to India]. Google's services may process data in other countries.

Changes to this policy

When we change this policy, we change the date at the top and tell you before the change takes effect. If a change means using your data in a new way, we ask for your consent first. [for the lawyer: The app records the time you agreed and each tick and untick of the box, with no version of the pages, and has no way yet to ask you to agree again.]

Complaints and contact

Our grievance officer: [grievance officer's name], [designation], Velcro Ventures OPC Private Limited, [registered address]. Email: [grievance email]. Phone: [phone number].

We acknowledge every complaint within 24 hours and resolve it within 7 days. If you are not satisfied with how we handled a complaint about your personal data, you can complain to the Data Protection Board of India.

Astitva is a product of Velcro Ventures OPC Private Limited.

Grievances and contact