Compliance & Trust DPDP Act 2023 Compliant Version 2.0

Privacy Policy for Needil

Explaining how LLE Social Media collects, uses, shares, and protects personal and medical health data across the Needil platform, with respect for patient rights and clinical integrity.

Effective Date: March 2026 Operated by: LLE Social Media Grievance: grievance@needil.com
01

Introduction

Welcome to Needil (hereinafter referred to as "Needil", "the App", "we", "us", or "our"), a healthcare technology platform developed and operated by LLE Social Media (hereinafter referred to as "LLE Social Media", "the Company", "we", "us", or "our"). This Privacy Policy explains how LLE Social Media collects, uses, shares, and protects personal data in connection with the Needil platform.

LLE Social Media processes different categories of personal data in different capacities depending on the purpose of processing. Where LLE Social Media determines the purpose and means of processing personal data for its own platform, business, administrative, security, or related purposes, LLE Social Media acts as a Data Fiduciary where applicable under applicable law. Where a Clinic uses Needil to collect, store, manage, or otherwise process patient personal data for the Clinic's healthcare services, the Clinic generally determines the purpose and means of that processing and acts as the Data Fiduciary, while LLE Social Media acts as a Data Processor on behalf of the Clinic.

Scope: This Privacy Policy applies to individuals who access or use Needil, including Clinics, Practitioners, receptionists, administrators, and other authorized users, as well as to personal data processed through Needil where LLE Social Media acts as a Data Fiduciary. Patient personal data processed by LLE Social Media on behalf of a Clinic is primarily governed by the applicable Clinic's privacy notice and the applicable Data Processing Agreement between the Clinic and LLE Social Media.

Key Definitions

Data Fiduciary

The person or entity that determines the purpose and means of processing personal data. For patient personal data processed through Needil for a Clinic's healthcare services, the Clinic generally acts as the Data Fiduciary. LLE Social Media acts as a Data Fiduciary for personal data where it independently determines the purpose and means of processing such data.

Data Principal

The individual to whom the personal data relates. In the context of patient personal data, this is generally the patient.

Practitioner

The licensed Acupuncture Practitioner, a doctor, healthcare professional, or other authorized healthcare provider who pays for and uses the Needil platform to provide healthcare services to you, the patient. The Practitioner acts as a Data Processor on our behalf and/or as a separate Data Fiduciary with independent obligations under the DPDP Act.

Data Processor

Any third-party entity that processes data on our behalf (including the Practitioner, cloud hosting providers, etc.).

Personal Data

Any information that identifies you, including health-related and clinical treatment information.

Important Note for Patients

While the Practitioner is our paying customer and uses our platform to provide you with healthcare services, you, as the patient, are the Data Principal with legal rights under the DPDP Act. This Privacy Policy is designed to inform you, the patient, about how your personal data is handled.

02

Data Fiduciary and Contact Information

LLE Social Media is the Data Fiduciary responsible for the processing of your personal data through the Needil platform.

2.1 Data Fiduciary

LLE Social Media

Registered Address 36/43A, Balakumaran Nagar, Part-A, Kolathur, Chennai - 600 099, Tamil Nadu, India
Corporate Email info@needil.com

2.2 Grievance Officer

Appointed Redressal Authority

Officer Name & Designation S. Ganesh — Grievance Officer, LLE Social Media
Official Email grievance@needil.com
Response Commitment We strive to respond to all grievances within 15 working days and resolve them within 90 days as per the DPDP Act.
Important Note for Patients

Even though you are not the paying customer, you have the right to contact our Grievance Officer directly regarding any concerns about your personal data. The Practitioner does not replace our Grievance Officer.

03

What Personal Data We Collect

We collect personal data that is necessary to provide our healthcare services to you through your Practitioner. An itemised description of the data we collect includes:

3.1 Identity and Demographic Information

Full Name Age / Date of Birth Gender Nationality (if required)

3.2 Contact Information

Email Address Mobile Phone Number Residential / Correspondence Address Emergency Contact Details

3.3 Health and Medical Information (Sensitive Personal Data)

  • Medical Conditions: Ailments, diagnoses, and health concerns (if required).
  • Treatment History: Past treatments, surgeries, and procedures (if required).
  • Medication Information: Current and past medications, dosage, and frequency (if required).
  • Prescription Details: Uploaded prescription documents and medication schedules (if required).
  • Medical Reports: Lab reports, scan reports (X-rays, MRIs, CT scans, ultrasounds), pathology reports, and other diagnostic documents (if required).
  • Clinical Notes: Observations and notes made by your Practitioner during consultations (if required).

3.4 Appointment and Usage Data

  • Appointment history and schedules.
  • All records and notes pertaining to Consultation(s), Treatment Session(s) and Maintenance Session(s).
  • Communication logs with your Practitioner and / or their staff personnel(s).
  • App usage statistics and interaction patterns.

3.5 Device and Technical Information

Device ID & Type Operating System & Version IP Address Browser Type & Version App Version & Installation Details
04

The Purpose of Processing Your Data

We process your data only for specific, legitimate purposes. An itemised description of these purposes includes:

4.1 Primary Healthcare Services

  • To provide healthcare services by enabling Practitioner to access your health information for diagnosis, treatment planning and follow-up care.
  • To maintain a secure, organized, and comprehensive digital health record for you and your Practitioner.

4.2 Appointment and Communication Management

  • To facilitate appointment scheduling, reminders, and cancellations.
  • To enable secure communication between you and your Practitioner.

4.3 Operational and Administrative Purposes

  • To improve our services and perform data analytics in an anonymised or de-identified manner.
  • To manage practitioner accounts, billing, and payment processing (where applicable).
  • To ensure quality assurance and clinical audits.

4.4 Legal and Regulatory Compliance

  • To comply with legal obligations, including clinical establishment rules, healthcare record retention laws, and court orders.
  • To respond to lawful requests from public and government authorities.

4.5 Security and Fraud Prevention

  • To protect against fraud, unauthorized access, and security threats.
  • To investigate and respond to security incidents.
05

Legal Basis for Processing

We process your personal data based on the following legal grounds:

5.1 Consent (Primary Basis)

Your explicit, free, specific, informed, unconditional, and unambiguous consent is the primary basis for processing your data. You will be asked to provide your consent for each specific purpose listed in Section 4. Consent is obtained through:

  • Opt-in Mechanisms: You will be presented with clear, standalone consent toggles for each purpose through the Practitioner's interface.
  • No Bundled Consent: You are not required to consent to purposes unrelated to the core healthcare service.
  • Role of the Practitioner: The Practitioner facilitates the consent process on our behalf, but the consent is your decision as the Data Principal. The Practitioner cannot consent on your behalf unless you explicitly delegate this authority to them through the app.

5.2 Exemptions Under DPDP Act (Without Consent)

In limited situations permitted by law, we may process your data without your consent, such as:

  • Medical Emergency: To respond to a situation involving a threat to your life or health, or that of any other individual.
  • Legal Compliance: To comply with a legal judgment, decree, or order from a court or government authority.
  • Public Health: For public health purposes during epidemics, outbreaks, or other public health emergencies.
06

Your Rights as a Data Principal (Patient)

Under the DPDP Act, you, as the patient, have the following rights, regardless of the fact that you are not the paying customer. We are committed to facilitating these rights through our internal processes.

6.1 Right to Access

You have the right to obtain a copy of the personal data we hold about you, along with information about the processing activities.

6.2 Right to Correction

You have the right to request the correction of inaccurate, incomplete, or outdated personal data.

6.3 Right to Erasure (Right to be Forgotten)

You have the right to request the deletion of your personal data when it is no longer necessary for the purpose for which it was collected, when you withdraw your consent, or when you object to processing with no overriding legitimate grounds.

6.4 Right to Withdraw Consent

You have the right to withdraw your consent for processing at any time. The process for withdrawal is as easy as giving consent. Withdrawal will not affect the lawfulness of processing prior to withdrawal.

6.5 Right to Grievance Redressal

You have the right to lodge a complaint with our Grievance Officer regarding any matter related to the processing of your data. If unsatisfied, you can file a complaint with the Data Protection Board of India.

6.6 Right to Nomination

You have the right to nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

6.7 Right to Information

You have the right to be informed about the processing of your personal data, including the categories of data collected, the purposes of processing, and third parties with whom data is shared.

Unconditional Direct Rights

As a patient, you can exercise these rights directly with us, even if you do not have a direct financial relationship with LLE Social Media. Your Practitioner cannot block or deny you from exercising your rights.

07

How to Exercise Your Rights

You can exercise your rights by contacting our Grievance Officer via the contact details provided in Section 2.2. To ensure the security of your data, we may require you to verify your identity before processing your request.

  • Mode of Request: Requests can be made via email to grievance@needil.com.
  • Response Timeline: We will acknowledge your request within 7 working days and respond to it within 90 days of receiving it, as mandated by the DPDP Act.
  • No Discrimination: Exercising your rights will not result in discrimination or denial of service (except where the processing is essential for the clinical service).
08

Withdrawal of Consent

You can withdraw your consent through the following methods:

8.1 Contacting Grievance Officer

You can withdraw your consent by contacting our Grievance Officer. Please specify which purposes you are withdrawing consent for.

8.2 Impact of Withdrawal

Withdrawing consent will mean we will cease processing your data for the specific purpose(s) you have withdrawn, unless we are legally required to retain it. If you withdraw consent for the core healthcare service, your Practitioner may no longer be able to provide the service to you through the Needil platform.

09

Data Sharing and Third-Party Processors

9.1 How We Share Data

We only share your data with third parties who act as Data Processors on our behalf and are strictly necessary to provide our services. We never sell your personal data to third parties.

9.2 Categories of Third-Party Processors

  • Acupuncture Practitioners: As the primary Data Processor, your Practitioner accesses your data to provide healthcare services. The Practitioner processes your data on our behalf and is bound by a Data Processing Agreement with LLE Social Media.
  • Cloud Hosting Providers: For data storage and infrastructure (e.g., AWS, Google Cloud, Azure). Data is stored on servers that are located within India.
  • Data Analytics Providers: To improve our app's functionality and user experience.
  • Security and Monitoring Vendors: To enhance application security, detect breaches, and monitor threats.
  • Communication Services: For email and SMS notifications (e.g., appointment reminders, OTP verification).
  • Payment Processors: For handling practitioner subscriptions and payments.

9.3 Data Processing Agreements

All our Data Processors, including the Practitioners, are bound by legally binding contracts that:

  • Define them as Data Processors.
  • Require them to adhere to DPDP Act obligations.
  • Implement reasonable security safeguards.
  • Prohibit them from using data for their own purposes (except for providing healthcare services).

9.4 Cross-Border Data Transfers

We may transfer your data to servers located outside India. Such transfers will only take place as permitted by law and in compliance with the Central Government's provisions regarding cross-border data transfers.

10

Data Retention and Deletion

10.1 Retention Period

We will retain your personal data only for as long as necessary to serve the purpose for which it was collected, or as required by other applicable laws (e.g., clinical establishment rules, tax laws, or medical record retention laws).

10.2 Log Retention

We retain logs of processing activities, access logs, and system logs for a minimum of one year from the date of processing, as required by the DPDP Rules.

10.3 Deletion and Erasure

  • Upon Request: When you request erasure, we will delete your data in a secure manner within 90 days of receiving your request.
  • Upon Purpose Completion: When the purpose of processing is complete, or upon the expiry of the retention period, we will delete your data.
  • Prior Notification: We will notify you at least 48 hours prior to the completion of the erasure timeline, giving you an opportunity to engage with us to preserve your data, if applicable.

10.4 Anonymised Data

We may retain anonymised or de-identified data for research, analytics, or statistical purposes without any obligation to delete it, as it no longer identifies you.

11

Reasonable Security Safeguards

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, accidental loss, misuse, or destruction. This includes:

11.1 Technical Safeguards

  • Encryption: We use encryption for data in transit (TLS 1.3+) and at rest (AES-256).
  • Access Controls: We implement role-based access control (RBAC) to ensure only your authorized Practitioner and essential technical staff can access your data.
  • Secure APIs: All API communications are authenticated and encrypted.
  • Network Security: We use firewalls, intrusion detection systems, and DDoS protection.
  • Regular Backups: We maintain offline, immutable backups to mitigate ransomware and ensure data resilience.

11.2 Practitioner's Obligations

Your Practitioner, as a Data Processor, is contractually obligated to:

  • Maintain the confidentiality and security of your data.
  • Access your data only for the purpose of providing healthcare services.
  • Report any data breaches or security incidents to us immediately.

11.3 Organizational Safeguards

  • Employee Training: Our employees undergo mandatory privacy and security training.
  • Non-Disclosure Agreements: All employees and contractors are bound by confidentiality obligations.
  • Data Minimisation: We collect only the data that is strictly necessary for the specified purpose.

11.4 Monitoring and Auditing

  • We maintain secure, immutable logs to track all data access and processing activities.
  • We regularly review our security posture and conduct vulnerability assessments.
12

Personal Data Breach Notification

12.1 Detection and Response

We have systems and processes in place to detect and respond to any personal data breaches in a timely manner.

12.2 Notification to the Data Protection Board

In the event of a personal data breach that is likely to cause harm to you, we will notify the Data Protection Board of India within 72 hours of becoming aware of the breach, as mandated by the DPDP Act, providing details of the breach, its impact, and the mitigation steps taken.

12.3 Notification to Affected Data Principals (Patients)

We will notify you, the affected patient, without undue delay, with:

  • A description of the breach.
  • The potential consequences of the breach.
  • The mitigation and remediation steps we are taking.
  • Contact information for further inquiries.

12.4 Role of the Practitioner

Your Practitioner will also be notified of the breach and may be required to assist in the notification and remediation process.

12.5 Record Keeping

We maintain logs of all breaches, notifications, and remediation actions for audit purposes.

13

Children's Data

13.1 Age Restriction and Verifiable Parental Consent

If you are under the age of 18 years, you are not permitted to use Needil without the consent of your parent or legal guardian. We will require verifiable parental consent in a manner prescribed by the DPDP Rules. Your Practitioner will facilitate this process.

13.2 Healthcare Exemption

If you are receiving healthcare services from a clinical establishment or healthcare professional, there is an exemption from the requirement of verifiable parental consent strictly for the provision of health services. This exemption applies only to the clinical care provided by your Practitioner and does not extend to other purposes (e.g., marketing, analytics).

13.3 Prohibition on Tracking and Targeting

We do not undertake any behavioural tracking, profiling, or targeted advertising directed at children under the age of 18.

14

International Data Transfers

14.1 Transfer of Data

We may transfer your personal data to countries outside India where our service providers are located (e.g., cloud hosting providers). Such transfers will be governed by your explicit consent and compliance with the Central Government's provisions regarding cross-border data transfers.

14.2 Adequacy Decisions

We will only transfer your data to countries or entities that provide an adequate level of protection as determined by the Central Government, or where we have implemented appropriate safeguards (e.g., standard contractual clauses).

15

Cookies and Tracking Technologies

15.1 What We Use

Our web application may use cookies and similar tracking technologies to enhance user experience, remember user preferences, and analyze usage patterns.

15.2 Your Choices

You can control cookies through your browser settings. However, disabling cookies may affect the functionality of the web application.

15.3 No Third-Party Advertising

We do not use third-party advertising cookies or engage in targeted advertising.

16

Automated Decision-Making and Profiling

16.1 Limited Use

We do not currently use automated decision-making or profiling that significantly affects you. In the future, we may use such technologies to analyze health data for treatment suggestions (with your explicit consent) or to identify potential health risks.

16.2 Your Right

You have the right to be informed about automated decision-making, request human intervention, and challenge automated decisions.

17

Links to Third-Party Websites

The Needil platform may contain links to third-party websites (e.g., payment gateways, medical resources). We are not responsible for the privacy practices or content of such websites. We encourage you to review their privacy policies before providing any personal data.

18

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in applicable laws and regulations, our business operations and services, or technology and security practices.

18.1 Notification of Changes

We will notify you of any significant changes through:

  • An in-app notification.
  • An email (if you have provided your email address).
  • A prominent notice on our website.

18.2 Effective Date

The Effective Date at the top of this policy reflects the latest version. Your continued use of the Needil platform after any changes constitutes your acceptance of the updated policy.

19

Compliance with Other Applicable Laws

19.1 Healthcare-Specific Laws

In addition to the DPDP Act, we comply with other applicable laws, including:

  • Clinical Establishments (Registration and Regulation) Act, 2010.
  • Medical Council regulations and equivalent statutory bodies for Acupuncture.
  • Information Technology (IT) Act, 2000 and its applicable Rules.

19.2 Healthcare Record Retention

We retain healthcare records for the period required by applicable clinical establishment rules and regulations.

19.3 Practitioner Responsibilities

Your Practitioner is independently responsible for complying with professional and clinical standards, including maintaining accurate patient records and obtaining appropriate clinical consent.

20

Grievance Redressal Mechanism

20.1 Internal Grievance Process

We have an internal grievance redressal mechanism to handle your complaints and queries. The process includes acknowledgment of your complaint within 7 working days, and investigation and resolution within 90 days.

20.2 You Can Grieve Directly

As a patient, you have the right to lodge a complaint directly with our Grievance Officer, even if you do not have a direct financial relationship with LLE Social Media. Your Practitioner cannot prevent you from exercising this right.

20.3 Escalation to Data Protection Board

If you are not satisfied with the resolution provided by our Grievance Officer, you have the right to file a complaint with the Data Protection Board of India through its online portal.

21

How to Contact Us

If you have any questions, concerns, or complaints regarding this Privacy Policy or your personal data, please reach out through our official channels:

General Inquiries

LLE Social Media

Platform Support Contact Form

Grievance Redressal

Patients & Practitioners

Grievance Officer S. Ganesh

Regulatory Authority

Statutory Oversight

Board Data Protection Board of India
Portal Official Online Grievance Portal
22

Acknowledgment and Consent

By using the Needil platform through your Practitioner, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your personal data as described herein.

You also acknowledge that you have the right to withdraw your consent at any time in accordance with the procedures established in Section 8 of this policy.