Explain that the policy describes what personal information Shrinivas (G) Educational & Research Institute of Medical Sciences (SGERIMS) collects, why it is collected, and how it is used, stored, and protected.
Applies to patients, students, job applicants, vendors, and website visitors.
Covers all online platforms (main website, admission portal, payment gateway, learning management system, hospital HIS) and offline interactions (registration desks, paper forms).
| Category | Examples | Legal Basis* |
|---|---|---|
| Identity Data | Full name, date of birth, government ID, enrolment number | Contract / Legal obligation |
| Contact Data | Postal address, email, phone, guardian details | Contract / Legitimate interest |
| Health Data | Medical history, prescriptions, lab results, imaging | Vital interest / Healthcare provision |
| Academic Data | NEET score, previous transcripts, faculty evaluations | Contract / Public task |
| Financial Data | Bank details, transaction IDs, insurance policy numbers | Contract / Legal obligation |
| Technical Data | IP address, browser type, cookies, session logs | Legitimate interest / Consent |
Directly from you: admission forms, appointment booking, email, phone calls.
Automatically: cookies, server logs, CCTV recordings.
From third parties: BCECEB, NEET, referring physicians, insurance providers, academic partners.
Process admissions and manage student records.
Deliver clinical care, diagnostics, and tele-medicine.
Schedule appointments and send reminders.
Issue fee invoices and process payments.
Conduct research and publish anonymised findings.
Improve our website, LMS, and hospital information systems.
Comply with statutory reporting to NMC, NABH, and government health authorities.
Types: essential, analytics, preference, advertising.
Opt-in / opt-out mechanisms.
Link to detailed Cookie Notice.
Internal: authorised faculty, clinicians, administrators.
External: labs, referral hospitals, regulatory bodies, payment gateways, academic collaborators—only on a need-to-know basis and under confidentiality agreements.
No sale or rental of personal data to third-party marketers.
State whether servers or cloud backups are located outside India; describe safeguards (Standard Contractual Clauses, encryption, BAA, etc.).
Medical records: [X] years per national health regulations.
Academic records: permanent digital archive.
CCTV footage: auto-delete after [30/90] days unless required for investigation.
Criteria for determining retention periods.
TLS/SSL encryption for all web traffic.
Role-based access control and multi-factor authentication for staff portals.
Regular vulnerability assessments, intrusion detection, and encrypted backups.
Staff training on privacy and cybersecurity.
(Adapt wording to GDPR, Indian PDPB, etc.)
Access, rectification, erasure, data portability, restriction of processing, objection.
How to exercise rights (email, portal, or onsite form).
Timeframe for responses.
Parental consent for patients or students under 18.
Special safeguards for paediatric medical data.
Non-responsibility disclaimer for third-party privacy practices.
Institute may update periodically; new version posted with “Last Updated” date.
Major changes communicated via email or website banner.
Data Protection Officer / Grievance Officer name.
Postal address, email, phone.
Escalation pathway to state or national data-protection authority.
Last Updated: 16-06-2025