PRIVACY POLICY
TRANSFORM HOSPITALS
PRIVACY POLICY
The CLOCK Strategy® · Transform Hospitals Website, WhatsApp Channel & Mobile App
Effective Date: [INSERT DATE] | Last Updated: [INSERT DATE]
This document is a comprehensive working draft prepared to align with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000 and associated rules, and general international privacy norms. It contains placeholders marked in red — these must be completed, and the final draft reviewed by a licensed Indian advocate, before publishing on any live platform. This document does not constitute legal advice.
1. Introduction & Scope
This Privacy Policy ("Policy") describes how
This Privacy Policy ("Policy") describes how [TRANSFORM HOSPITALS — LEGAL ENTITY NAME], operating under the brand "Transform Hospitals" and offering "The CLOCK Strategy®" hospital transformation programme ("Transform Hospitals", "we", "us", "our"), collects, uses, stores, discloses, and protects personal data of individuals who interact with us through our website, WhatsApp Business channel, mobile application (available on the Google Play Store and Apple App Store), social media pages, Clarity Calls, CLOCK Position Audits, and any other touchpoint where this Policy is linked or referenced (collectively, the "Services").
This Policy applies to hospital owners, promoters, CEOs, administrators, doctors, staff members, and any other individual ("you", "User", "Data Principal") who provides personal data to us, whether as a prospective client, an enrolled client under The CLOCK Strategy programme, a website visitor, or a WhatsApp/social media user.
This Policy is drafted with primary reference to Indian law, being:
• The Digital Personal Data Protection Act, 2023 ("DPDPA") and rules framed thereunder, which is the principal law governing personal data processing in India;
• The Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), to the extent they continue to apply to sensitive personal data and reasonable security practices;
• The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, to the extent applicable to our website and app;
• The Consumer Protection (E-Commerce) Rules, 2020, where relevant to any online transactions.
Where Transform Hospitals engages with hospitals, users, or website visitors located outside India, we additionally have regard to internationally recognised privacy principles, including those under the EU General Data Protection Regulation ("GDPR") where applicable, on a best-efforts basis, without representing that we are otherwise subject to such foreign law.
2. Key Definitions
"Personal Data"
Any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDPA.
"Sensitive Personal Data or Information" (SPDI)
Under the SPDI Rules, this includes financial information (such as bank account or payment card details), health data, biometric information, and passwords. We treat any hospital financial/audit data, payment details, and any incidentally shared health-adjacent information with this heightened standard of care.
"Data Fiduciary"
Transform Hospitals, which determines the purpose and means of processing your personal data, and is accountable for such processing under the DPDPA.
"Data Processor"
Any third party that processes personal data on our behalf and under our instructions (e.g., cloud hosting providers, WhatsApp Business Solution Providers, payment gateways).
"Data Principal"
The individual to whom the personal data relates — i.e., you.
"Consent Manager"
A person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review, or withdraw consent through an accessible, transparent, and interoperable platform, where applicable.
3. What Personal Data We Collect
We collect personal data directly from you, automatically through your use of our Services, and, in limited circumstances, from third parties such as Meta (Facebook/Instagram) advertising platforms when you respond to our ads.
Category | Examples | Why We Collect It |
Identity & Contact Data | Full name, designation, hospital name, mobile number, WhatsApp number, email address, city/location | To identify you, respond to enquiries, and schedule your free Clarity Call |
Hospital / Business Data | Hospital size, bed count, ownership structure, current accreditation status (e.g., NABH), existing SOPs, financial and operational information shared during the CLOCK Position Audit | To assess your hospital's Clock Position and prepare the Audit, 180-day plan, and proposal |
Payment Data | Billing name, GST details, payment confirmation/transaction reference for the ₹20,000 + GST Audit fee or Programme fee (payment processed by our third-party payment gateway; we do not store full card/UPI credentials) | To process fees and issue invoices/receipts |
Communication Data | Messages, voice notes, and shared documents exchanged over WhatsApp, email, or phone during the chatbot flow, Clarity Call, or ongoing engagement | To respond to you, maintain a record of commitments made, and improve our chatbot and service quality |
Technical & Usage Data | IP address, device type, browser type, app version, log-in timestamps, pages viewed, in-app actions, crash logs | To operate, secure, and improve the website and Transform Hospitals app |
Marketing & Advertising Data | Interaction with our Facebook/Instagram ads, form submissions on landing pages, campaign source/UTM data, cookie identifiers | To measure ad performance, retarget interested prospects, and avoid duplicate outreach |
Diagnostic / Course Data | Responses submitted through the interactive HTML diagnostic form, intake workbook, or course/community materials | To generate your Clock Position score and tailor your ADOPT/ADAPT pathway recommendation |
4. Sources of Data Collection
• Directly from you — via our website contact/landing page forms, the WhatsApp chatbot flow, phone calls, the Clarity Call, the CLOCK Position Audit, and the Transform Hospitals app.
• Automatically — via cookies, SDKs, and similar technologies on our website and app (see Section 10).
• From third parties — Meta Platforms, Inc. (when you click or engage with our Facebook/Instagram ads and are redirected to us), WhatsApp Business Solution Providers, and, where you consent, referrals from existing client hospitals or peer doctors invited to our sessions.
5. Purpose of Processing
Consistent with the purpose limitation principle under the DPDPA, we process your personal data strictly for the purposes for which it was collected, including to:
• Respond to enquiries and book your free Clarity Call;
• Conduct the CLOCK Position Audit and generate your hospital's diagnostic report;
• Prepare and deliver ADOPT/ADAPT 180-day execution plans and related proposals;
• Onboard you as a client under a signed legal agreement and deliver the CLOCK Strategy programme, including coordination with the Titans of 12 delivery team;
• Process payments, issue invoices, and maintain financial and statutory records as required under Indian law;
• Operate, maintain, and improve our website, WhatsApp channel, and mobile app;
• Send you service-related communication, reminders, and — where you have separately consented — promotional/marketing communication;
• Comply with applicable law, respond to lawful requests from government or regulatory authorities, and enforce our agreements;
• Maintain records for grievance redressal, dispute resolution, and audit trail purposes.
We do not use your personal data for any purpose beyond what is disclosed in this Policy or at the point of collection, without seeking fresh consent where required.
6. Legal Basis & Consent
Under the DPDPA, we process personal data primarily on the basis of your free, specific, informed, unconditional, and unambiguous consent, given through a clear affirmative action (e.g., submitting a form, replying to our WhatsApp chatbot, or signing the client agreement).
Where applicable, we also rely on the following grounds recognised under the DPDPA without requiring separate consent:
• Performance of a contract you have entered into with us (e.g., the signed CLOCK Strategy engagement agreement);
• Compliance with a legal obligation (e.g., statutory record-keeping, tax, and invoicing requirements);
• "Legitimate uses" as recognised under Section 7 of the DPDPA, such as where you have voluntarily provided your data for a specific purpose and have not indicated that you do not consent to its use (e.g., a prospect who voluntarily shares their number for a callback).
You have the right to withdraw consent at any time, with the same ease with which it was given. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, and will not affect obligations you have already undertaken under a signed agreement.
7. Children's Data
Our Services are intended exclusively for hospital owners, administrators, doctors, and other business decision-makers, and are not directed at or intended for use by children (individuals below the age of 18, as defined under the DPDPA). We do not knowingly collect personal data of children. If we become aware that we have inadvertently collected personal data of a child without verifiable parental/guardian consent, we will delete such data promptly. As required under the DPDPA, we do not undertake tracking, behavioural monitoring of children, or targeted advertising directed at children.
8. WhatsApp, Meta, and Other Third-Party Platforms
Our chatbot flow and ongoing client communication operate over the WhatsApp Business Platform, provided by WhatsApp/Meta Platforms, Inc. and, where used, a WhatsApp Business Solution Provider ("BSP"). When you message us on WhatsApp:
• Your messages are transmitted and stored in accordance with WhatsApp's own Privacy Policy and Business Terms of Service, in addition to this Policy;
• We access your WhatsApp number, message content, and message metadata for the purposes described in Section 5;
• Meta Platforms, Inc. may process certain data as an independent data controller/fiduciary for its own platform-safety and analytics purposes, as disclosed in Meta's own privacy policy.
Similarly, when you engage with our Facebook or Instagram advertisements, Meta may share aggregated or pseudonymised campaign performance data with us (such as click-through rates and conversion events), and may use cookies or pixels on our landing pages, subject to Meta's own terms. We encourage you to review Meta's Privacy Policy at facebook.com/privacy/policy and WhatsApp's Privacy Policy at whatsapp.com/legal/privacy-policy.
We are a Data Fiduciary in relation to the data we collect through these channels for our own purposes; WhatsApp/Meta acts as a Data Processor for message transmission and, separately, as an independent fiduciary for its own platform operations.
9. Data Sharing & Disclosure
We do not sell your personal data. We may share your personal data with the following categories of recipients, strictly on a need-to-know basis:
• The Titans of 12 delivery team and internal Transform Hospitals personnel directly involved in delivering your engagement;
• Data Processors engaged by us, such as cloud/website hosting providers, WhatsApp Business Solution Providers, payment gateways, email service providers, and IT support vendors, each bound by contractual confidentiality and data-processing obligations;
• Professional advisors, including our auditors, accountants, and legal counsel, where necessary;
• Government authorities, regulators, or law enforcement agencies, where required under applicable law, a valid legal process, or to protect our rights, property, or safety, or that of others;
• A successor entity, in the event of a merger, acquisition, or sale of all or substantially all of our business assets, subject to that entity being bound by materially equivalent privacy protections.
We do not share hospital-specific Audit findings, financial data, or operational data with any other client hospital or third party without your explicit consent, except as aggregated and anonymised case-study data where you have separately agreed to such use (e.g., for testimonials or marketing case studies).
10. Cookies & Tracking Technologies
Our website and landing pages use cookies, web beacons, and similar technologies to:
• Remember your preferences and improve site functionality;
• Measure the performance of our Facebook/Instagram advertising campaigns (via the Meta Pixel or Conversions API);
• Understand aggregate visitor behaviour through analytics tools.
You can control or disable cookies through your browser settings; however, doing so may affect the functionality of our website. Where required by applicable law, we will display a cookie consent banner allowing you to accept or reject non-essential cookies before they are set.
11. Cross-Border Data Transfer
Some of our Data Processors (such as cloud hosting providers, WhatsApp/Meta, and analytics tools) may store or process data on servers located outside India. Under Section 16 of the DPDPA, the Central Government may notify countries to which personal data may be transferred; as of the effective date of this Policy, no such restriction list has materially limited our processing arrangements. Where we transfer personal data outside India, we require our Data Processors to maintain security safeguards that are consistent with the standards required under this Policy and applicable law.
12. Data Storage, Security & Retention
We implement reasonable security practices and procedures, in line with the SPDI Rules and the DPDPA, including:
• Access controls limiting personal data access to authorised personnel only;
• Encryption of data in transit (e.g., HTTPS/TLS) and, where applicable, at rest;
• Secure storage of documents (Audit reports, agreements, financial records) with restricted access;
• Periodic review of our security practices and vendor agreements.
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required under applicable law (for example, financial and invoicing records required under Indian tax law are typically retained for the statutory period applicable at the time). Where you do not proceed beyond the free Clarity Call stage, we retain your enquiry data for a limited period to permit reasonable follow-up, after which it is deleted or anonymised, unless you request earlier deletion.
13. Your Rights as a Data Principal
Under the DPDPA, you have the following rights in relation to your personal data, which you may exercise by writing to our Grievance Officer/Data Protection Officer (Section 16 below):
• Right to Access — to obtain a summary of the personal data we hold about you and the processing activities undertaken;
• Right to Correction and Completion — to request correction of inaccurate or incomplete personal data;
• Right to Erasure — to request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations;
• Right to Grievance Redressal — to have any grievance regarding processing of your personal data addressed by us within a reasonable time;
• Right to Nominate — to nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity;
• Right to Withdraw Consent — as described in Section 6.
If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India, constituted under the DPDPA.
14. Data Breach Notification
In the event of a personal data breach that is likely to affect you, we will take prompt steps to contain and remediate the breach, and will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDPA and applicable rules.
15. Third-Party Links
Our website, app, or WhatsApp communications may contain links to third-party websites or services (such as payment gateways or social media pages) that are not operated by us. We are not responsible for the privacy practices of such third parties, and we encourage you to review their respective privacy policies.
16. Grievance Officer / Data Protection Contact
Fill in before publishing — the DPDPA and IT Rules require a named, reachable Grievance Officer.
In accordance with the DPDPA and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the details of our Grievance Officer are as follows:
Name: [Dr Mangesh Virkar]
Designation: [Fonder & CEO]
Email: [improvehospital@transformhospitals.com]
Phone: [+91-9962416077]
Registered Address: [Gagan Utopia, Keshavnagar, Mundhwa, Pune, Maharashtra, India]
We will acknowledge grievances promptly and endeavour to resolve them within the timelines prescribed under applicable law.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, our Services, or applicable law. The "Last Updated" date at the top of this Policy indicates when it was last revised. Material changes will be notified to you through the website, app, or WhatsApp, as appropriate. Continued use of our Services after such changes constitutes acceptance of the updated Policy.
18. Governing Law & Jurisdiction
This Policy is governed by the laws of India. Subject to the DPDPA's grievance redressal and Data Protection Board mechanisms, any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at
This Policy is governed by the laws of India. Subject to the DPDPA's grievance redressal and Data Protection Board mechanisms, any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at [Pune, Maharashtra].
19. Contact Us
For any questions about this Privacy Policy or our data practices, please contact us at:
Transform Hospitals
Email: [improvehospita@transformhospitals.com]
WhatsApp/Phone: [+91-9962416077]
Address: [Gagan Utopia, Keshavnagar, Mundhwa, Pune, Maharashtra, India]
Legal note: This Policy has been drafted as a comprehensive, India-first template and is not a substitute for advice from a licensed advocate. Before publishing, please: (1) fill in every placeholder in red; (2) confirm the legal entity name and registration details under which Transform Hospitals operates (proprietorship/LLP/private limited); (3) have the final draft reviewed against the DPDPA Rules once notified in final form, and against sector guidance if you begin handling patient-level health data directly on behalf of client hospitals.





