As Data Fiduciary under the DPDP Act 2023, OPliveHealth Private Limited shall: process Personal Data only for specified lawful purposes; implement reasonable security safeguards; notify the Data Protection Board of India and affected Data Principals of Personal Data Breaches; ensure Data Processors act only per OPLive's instructions; and erase data upon purpose fulfilment or consent withdrawal, subject to legal retention requirements.
All data transmitted between Users and the Application is protected using industry-standard encryption in transit. HTTPS is enforced for all communications.
Health data and Sensitive Personal Data are encrypted at rest using industry-standard encryption. Encryption key management follows recognised security practices. Backup data is encrypted prior to storage.
Access to Personal Data is restricted on a need-to-know basis using Role-Based Access Controls (RBAC). Multi-factor authentication (MFA) is implemented for personnel with access to production systems. All access events are logged. Third-party vendor access is governed by Data Processing Agreements.
OPLive collects only the minimum Personal Data necessary for each specified purpose. Analytics data is anonymised before processing.
OPLive conducts periodic security reviews, vulnerability assessments, and penetration testing by qualified security professionals. Critical security patches are applied promptly upon release.
Upon becoming aware of a suspected Personal Data Breach, OPLive activates its incident response process as soon as practicable, assesses breach severity, and takes immediate containment steps.
OPLive shall notify the Data Protection Board of India within the prescribed statutory timeline upon confirmation of a breach, including: nature of breach, categories and estimated number of Data Principals affected, likely consequences, and measures taken.
Affected Users will be notified promptly via email, SMS, and in-app notification, in plain language describing what occurred, what data was affected, and what OPLive is doing to address the breach.
A Breach Register is maintained recording all suspected and confirmed breaches, assessment details, notifications, and remedial actions. Retained for a minimum of 5 years.
DPO: Abdul Nayeem | Email: dpo@oplive.app | Phone: +91 7994436622
Data protection considerations are embedded into the design of new features. Data Protection Impact Assessments will be conducted where practicable for high-risk processing activities.
Employees handling Personal Data receive periodic awareness training on data protection obligations and security best practices.
OPLive endeavours to ensure that vendors processing Personal Data on its behalf execute appropriate data processing agreements. Vendor compliance is reviewed periodically.