← Back to Medieco

Privacy Policy

For Medieco and Medieco Connect

Effective 11 July 2026  |  Last updated 11 July 2026

This Privacy Policy explains how QWIKDOC MEDIECOSYSTEM PRIVATE LIMITED ("Medieco", "we", "us", or "our") collects, uses, shares, stores, and protects personal data when you use the Medieco patient/customer mobile application, the Medieco Connect partner application, our websites, APIs, support channels, and related services (together, the "Services").

By using the Services, you acknowledge the practices described in this Privacy Policy. Where the law requires consent, we will request it through an appropriate notice or permission prompt. You may withdraw consent as described below, although this will not affect processing already carried out lawfully.

1. Who is responsible for your data

Data Fiduciary / Service Operator: QWIKDOC MEDIECOSYSTEM PRIVATE LIMITED

Corporate Identity Number (CIN): U62099GJ2025PTC162040

Permanent Account Number (PAN): AABCQ1076C

Tax Deduction and Collection Account Number (TAN): BRDQ00123E

Registered address: 24 Ram Nagar, Behind Raj Ratna Bhavan, Timbavadi, Junagadh, Junagadh - 362015, Gujarat, India

Privacy and support email: info@rehabmedico.in

Grievance Officer: Grievance Officer, QWIKDOC MEDIECOSYSTEM PRIVATE LIMITED

Healthcare professionals, hospitals, clinics, diagnostic facilities, and service providers using Medieco may separately be responsible for data they collect or maintain for providing care. Their own privacy notices may also apply.

2. Personal data we collect

The data we collect depends on your role, the features you use, and the permissions you grant.

A. Account and identity data

  • Name, profile photo, age or date of birth, gender, and blood group.
  • Mobile number, email address, login credentials, OTP verification status, and account role.
  • Postal address, saved addresses, city, and emergency-contact details.
  • Authentication tokens, session records, and account status.

B. Health and care data

  • Symptoms, allergies, current and previous medications, medical history, treatment progress, and other information you provide.
  • Appointment, consultation, service-booking, prescription, diagnostic, and medical-record information.
  • Files, images, reports, prescriptions, or other documents uploaded by you or an authorised healthcare professional.
  • Reviews, care preferences, and communications relating to services or treatment.

Health information is sensitive. We use it only for the purposes described in this Policy, subject to applicable law and access controls.

C. Partner and professional data

If you use Medieco Connect, we may collect professional qualifications, registration numbers and councils, specialisation, experience, clinic or workplace details, availability, services, fees, identity and address proofs, certificates, police-verification information where applicable, and approval or verification records.

For service providers receiving payouts, we may also collect bank-account holder name, account number, IFSC, bank or branch information, and UPI ID. Access to this information should be limited to authorised operational, verification, finance, and compliance functions.

D. Booking, transaction, and payment data

We collect booking details, prices, discounts, order and transaction identifiers, payment status, refunds, invoices, and billing information. Payments may be processed by Razorpay or another disclosed payment provider. We do not intend to store complete card numbers, CVVs, or net-banking passwords on Medieco systems; payment providers process such credentials under their own terms and privacy policies.

E. Location data

With device permission, we may collect precise or approximate location and map coordinates to select an address, find nearby doctors or services, support service fulfilment, and apply service-area or geofencing rules. You may deny or disable location permission in device settings, but location-dependent features may not work.

F. Photos, video, files, and device storage

When you choose to upload a profile photo, medical document, professional certificate, social post, or other content, the app may request access to your camera, photo library, or files. We access only the content you select or create for the requested feature, subject to the capabilities of your device operating system.

G. Communications and user content

We may process in-app chat messages, support tickets, call or appointment details, reviews, comments, social posts, likes, follows, saved posts, reports, and other content you submit. Content you publish in social or profile areas may be visible to other users according to the feature and your settings. Do not include information about another person unless you are authorised to provide it.

H. Device, notification, security, and diagnostic data

We may collect device and app identifiers, Firebase Cloud Messaging tokens, operating-system and app version, IP address, user-agent information, login/session activity, timestamps, network status, error logs, crash reports, and diagnostic details. We use these to deliver notifications, secure accounts, investigate misuse, and maintain the Services.

3. How we collect data

We collect personal data:

  • Directly from you when you register, complete a profile, make a booking, upload content, communicate, or request support.
  • From healthcare professionals, hospitals, or service providers involved in your booking or care.
  • Automatically from your device and use of the Services.
  • From payment, notification, mapping, communications, and verification providers.
  • From another person acting with appropriate authority, such as a parent, guardian, caregiver, or authorised representative.

4. Why we use personal data

We use personal data to:

  • Create, authenticate, maintain, and secure accounts.
  • Connect patients with doctors, hospitals, and service providers.
  • Schedule, administer, reschedule, cancel, and fulfil appointments and bookings.
  • Create, store, display, and share medical records and prescriptions with authorised participants.
  • Process payments, payouts, refunds, invoices, and transaction verification.
  • Provide location-based search and service availability.
  • Enable chat, notifications, reviews, support, and Medieco Media features.
  • Verify and approve healthcare professionals and service providers.
  • Personalise content and improve usability and service quality.
  • Detect fraud, abuse, security incidents, and technical failures.
  • Comply with legal, regulatory, tax, accounting, medical-record, dispute-resolution, and law-enforcement obligations.
  • Establish, exercise, or defend legal claims and perform other purposes explained when data is collected.

We will not use personal data for a new, incompatible purpose without providing an appropriate notice and obtaining consent where required.

5. Permissions and your choices

Depending on your device and usage, the apps may request permission for location, notifications, photos, media, files, camera, or related device functions. Permissions can be managed in your device settings. Revoking a permission does not delete information already submitted to us, but it stops or limits future access through that permission.

You can manage promotional or non-essential notifications through app or device settings. We may still send essential service, booking, transaction, account, or security communications where permitted by law.

6. How we share personal data

We may share only the data reasonably necessary with:

  • Care and service participants: doctors, hospitals, clinics, appropriately supervised and authorised medical students, service providers, laboratories, and other parties involved in a requested booking or care journey.
  • Other users: when you publish profile information, posts, reviews, comments, or other content intended for social or public-facing features.
  • Payment and payout providers: including Razorpay, banks, and financial partners for processing and reconciling transactions.
  • Technology providers: cloud hosting, storage, database, messaging, Firebase notification, mapping/location, communications, security, analytics, and technical-support providers.
  • Professional advisers and business support: auditors, insurers, accountants, lawyers, and consultants subject to appropriate duties.
  • Authorities and legal recipients: where required by law, valid legal process, regulatory obligation, safety needs, or to protect rights and prevent harm.
  • Corporate transaction recipients: in connection with a merger, acquisition, financing, restructuring, or transfer of all or part of our business, subject to appropriate confidentiality and legal requirements.

We do not sell, rent, or trade personal data. We do not disclose personal data to third parties for their advertising purposes, and we do not process personal data for targeted or behavioural advertising.

We share personal data only for the operational, healthcare, payment, security, legal, and service-delivery purposes described in this Privacy Policy. Service providers may process data only to provide contracted services and according to applicable instructions, agreements, and law. Third-party services may also process data under their own privacy policies.

7. Medical information and emergency limitations

Medieco facilitates healthcare and related services but is not a substitute for emergency medical care. Do not use the Services for a medical emergency; contact local emergency services or visit the nearest appropriate medical facility.

Access to medical information is intended to be limited to the patient, authorised representatives, involved healthcare professionals or providers, and authorised Medieco personnel with a legitimate operational, security, support, or legal need.

8. Data retention

We retain personal data only as long as reasonably necessary for the purposes described in this Policy, including providing the Services and meeting legal, regulatory, tax, accounting, medical-record, fraud-prevention, security, and dispute-resolution requirements.

Retention periods vary by data type and context. When deciding a period, we consider the nature and sensitivity of the data, risks from unauthorised use or disclosure, the purpose of processing, account and booking status, applicable limitation periods, and legal requirements. Some booking, transaction, prescription, and medical-record information may need to be retained after account closure.

When data is no longer required, we will delete or anonymise it, or securely isolate it until deletion is possible. Backup copies may remain for a limited cycle and will not be restored for ordinary use after a valid deletion request.

9. Security

We use reasonable administrative, technical, and organisational safeguards designed to protect personal data, including access restrictions, authentication controls, monitoring, and secure communications where appropriate. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

You are responsible for safeguarding your OTPs, credentials, and device access. Contact us immediately if you believe your account or personal data has been compromised.

10. Your rights and requests

Subject to applicable law, you may have the right to:

  • Obtain information about the personal data we process and the parties with whom it has been shared.
  • Access or request a copy of your personal data.
  • Correct, complete, or update inaccurate or incomplete data.
  • Request erasure of personal data that is no longer necessary or legally required.
  • Withdraw consent for consent-based processing.
  • Nominate another person to exercise rights in the event of death or incapacity.
  • Raise a grievance and receive a response.
  • Use any other right available under applicable law.

You may update certain profile details in the app. To request account deletion, visit rehabmedico.in/delete-account. For another privacy request, contact info@rehabmedico.in. State your account mobile number or email and the request you wish to make. We may verify your identity and authority before acting. We may retain or decline to erase information where retention is required or permitted by law, and will explain this where applicable.

You may also complain to the Data Protection Board of India or another competent authority when that mechanism is legally available to you. We encourage you to contact our Grievance Officer first so we can try to resolve the concern.

11. Account deletion

To request account deletion, visit https://www.rehabmedico.in/delete-account and follow the instructions on that page. Alternatively, email info@rehabmedico.in with the subject "Account Deletion Request." After identity verification, we will delete or anonymise eligible account data and explain any data that must be retained. Deleting the app from a device does not delete your account.

12. Children and persons needing guardianship

The Services are not directed to children under 13, and a person under 13 may not create or use an account. If we learn that we collected personal data from a child under 13, we will take reasonable steps to delete it.

Users aged 13 to 17 may use the Services only with verifiable consent and supervision from a parent or lawful guardian. The parent or guardian is responsible for the minor's use of the Services and may exercise applicable privacy rights on the minor's behalf. We do not engage in behavioural monitoring of children or targeted advertising directed at children. If you believe a minor has used the Services without appropriate authorisation, contact info@rehabmedico.in.

13. International data transfers

Medieco's primary application and database hosting region is India. Some third-party technology providers may process limited data in other locations when providing services such as payments, notifications, mapping, communications, or technical support. Where personal data is transferred across borders, we will take steps required by applicable law, including appropriate contractual and security safeguards and compliance with any transfer restrictions notified by the Government of India.

14. Third-party services and links

The Services may integrate with or link to third-party services, including payment providers, Firebase services, mapping/location providers, app stores, and healthcare or service-provider systems. Their handling of data is governed by their own privacy policies when they act independently. Review those policies before using the relevant feature.

15. Changes to this Policy

We may update this Privacy Policy to reflect changes in the Services, technology, law, or data practices. We will post the updated version with a revised "Last updated" date and provide additional notice or obtain consent where required. Material changes will not apply retroactively where prohibited by law.

16. Contact and grievance redressal

Grievance Officer

QWIKDOC MEDIECOSYSTEM PRIVATE LIMITED

24 Ram Nagar, Behind Raj Ratna Bhavan, Timbavadi, Junagadh, Junagadh - 362015, Gujarat, India

Email: info@rehabmedico.in

Response timeline: We will acknowledge and respond within the period required by applicable law.

We will review and respond in accordance with applicable law. If you are dissatisfied, you may use the escalation or regulatory remedies available to you.

Medieco

The world's most trusted
telehealth company.

All rights reserved © Medieco, 2026

Made with   by ThemeWagon