Legal

Privacy Policy

Last updated: Draft — not yet published

askhelia is operated by Enterstellar Softwares (“we”, “us”). We take the privacy of your mental-health information seriously. This policy explains what we collect, why, how we protect it, and the rights you have under India’s Digital Personal Data Protection Act, 2023 (“DPDP”).

Information we collect

  • Account details — your phone number (for OTP sign-in) and, if you create a profile, your name and date of birth.
  • Health information — assessment answers and scores (e.g. GAD-7, PHQ-9), clinical notes, prescriptions and care plans created by clinicians you see, and messages you exchange with them.
  • Booking & payment — appointments you book and the status and amount of payments. Card/UPI details are handled by our payment processor, not stored by us.
  • Technical data — basic device and usage information needed to run the service securely.

You can use guest mode to take a first assessment without creating an account.

How we use your information

  • To provide the service — assessments, self-help, consults and care plans.
  • To connect you with the clinicians you choose to book.
  • To process payments and pay clinicians.
  • To keep the service safe, prevent abuse, and meet legal obligations.

We do not sell your personal data or use your health information for advertising.

Consent and legal basis

We process your personal data with your consent, which you give when you use the service, and to perform the service you request. You can withdraw consent at any time, though some features may then be unavailable.

Where your data is stored

Your data is stored on servers located in India (Mumbai), in line with DPDP data- residency expectations for health data.

How we protect it

Data is encrypted in transit (TLS) and at rest. Sensitive health records are encrypted with additional protection so access is limited to you and the clinician treating you. We apply least-privilege access controls, log administrative actions, and test the platform for security issues before launch.

Who we share it with

  • Clinicians you book — they see the information needed to care for you.
  • Service providers — e.g. our payment processor and messaging/OTP provider, only for the purpose of running the service.
  • Legal — where required by law or to protect safety.

Your rights

Under DPDP you can:

  • access a copy of the personal data we hold about you;
  • ask us to correct or complete it;
  • ask us to erase it. Note that some clinical and financial records must be retained for a period required by law even after erasure — we anonymise rather than delete those until their retention period ends.
  • withdraw consent and raise a grievance (below).

To exercise any right, contact us at hello@askhelia.com.

How long we keep it

We keep your data for as long as your account is active. Clinical and financial records are retained for the minimum periods required by Indian medical-records and accounting law, then securely deleted.

Children

The service is intended for adults. Where a child uses the service, DPDP requires verifiable parental/guardian consent; we handle children’s data with the additional care the law requires.

Grievances

If you have a concern about how we handle your data, contact our Grievance Officer at hello@askhelia.com. We will acknowledge and respond within the timelines DPDP requires.

Changes

We may update this policy. We will post the new version here and update the date above.