01
Why this notice exists
Indian law treats information about your physical or mental health condition and your medical records as sensitive personal data or information under the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Mental Healthcare Act, 2017 gives every person a specific right to confidentiality in respect of their mental health care and treatment. The Digital Personal Data Protection Act, 2023 adds a further layer of obligations on us as a Data Fiduciary.
This notice supplements our Privacy Policy. Where the two documents cover the same ground, they are meant to say the same thing — this one is simply more specific about health data.
Mindcarter
Module No. A, Tejaswini, Technopark, Thiruvananthapuram, Kerala, India
Email: info@mindcarter.com
Phone: +91 75940 71071
02
What counts as health data
In this notice, "health data" means any information that relates to your mental or physical health status, the care you receive, or that could reasonably be used to infer either. For a practice like ours that includes the obvious things — what you tell a clinician — and also less obvious ones, such as the fact that you booked a therapy session at all.
03
Health data we hold
| What | Where it comes from | Sensitivity |
|---|---|---|
| Your stated primary concern and the clinical tags on your record | You, during intake and profile setup; your clinician thereafter | Clinical |
| Wellness journal entries — free text, mood ratings from 1 to 5, your own tags, and the date of each entry | Written by you in the client portal | Clinical |
| Clinician notes on your journal entries | Written by your clinician when reviewing an entry | Clinical |
| Session notes — your clinician's record of each session | Written by your clinician after a session | Clinical, most restricted |
| Assessment information, where you take a psychometric assessment | Recorded by the practitioner who administers it | Clinical |
| Your care team — which clinicians you are assigned to, and which is primary | Set when you are matched with a clinician | Clinical |
| Booking records — dates, times, session type, mode, status and notes | Generated when you book or attend | Health-adjacent: the existence of care, not its content |
| Emergency contact name, number and relationship to you | You, in your profile | Sensitive personal data |
| Date of birth, preferred language | You, in your profile | Personal data |
We do not collect biometric data, genetic data, precise location data, or data from wearables or fitness trackers, and we do not buy health data about you from anyone.
04
How we use it
- To let your clinician prepare for, conduct and document your sessions, and to maintain continuity of care if you see more than one clinician in your care team.
- To let you keep and review your own wellness journal, and to let your clinician respond to entries you submit for review.
- To schedule and run your sessions, including reminders and rescheduling.
- To respond to a medical emergency involving a threat to your life or immediate health — a use the DPDP Act permits without separate consent.
- To meet professional record-keeping and legal obligations.
We do not use your health data to make automated decisions about you, and we do not profile you.
05
Who can see it
| Role | Access to clinical content |
|---|---|
| You | Your own profile, bookings, journal entries and mood history, at any time in the portal. |
| Your clinician | Your profile, bookings, journal entries submitted for review, and the session notes they wrote for you. |
| Other clinicians | Only if they are part of your care team. A clinician who is not on your care team cannot open your record. |
| Your employer, if your access is sponsored | Nothing clinical. Roster membership and session counts only. |
| Our service providers | Only infrastructure-level access (hosting, database, email delivery) under contract, to operate the service. |
Session notes are the most restricted record we keep
Notes your clinician writes about a session are visible to that clinician alone. They are not surfaced in your portal, are not shown to anyone else, and are written once — the system has no edit or delete path for them, so the clinical record cannot be quietly rewritten later.
06
What we never do
- We never sell your health data. Not to anyone, for any price.
- We never share it with advertisers, data brokers or analytics networks, and we run no advertising or behavioural tracking technology on this site.
- We never share it with your employer, including the fact of what you discussed, your mood ratings, your journal, or which psychologist you see.
- We never share it with insurers, prospective employers or background-check services.
- We never use your journal entries or session notes to train machine-learning models.
- We never publish testimonials, case studies or marketing content that identifies you, unless you give separate written consent for that specific use.
The only disclosures we make outside the circle above are the ones the law compels or permits: a serious and imminent risk to your life or safety or to someone else's, a risk of harm to a child or vulnerable person, a medical emergency, or a lawful order from a court or competent authority. If we ever have to make such a disclosure we will tell you, unless the law forbids us from doing so.
07
Consent and withdrawal
We collect health data on the basis of your consent, given when you begin care, complete your profile, or write a journal entry. Consent for one purpose is not consent for another: agreeing to therapy does not mean agreeing to share anything with your employer, and it does not mean agreeing to marketing.
You can withdraw consent at any time by writing to info@mindcarter.com. We will stop processing and erase what we are not legally required to keep. Withdrawal does not undo processing that already happened, and in most cases it will mean we can no longer provide clinical services to you.
08
How it is protected
- Access to clinical records is enforced on the server according to your role and care-team membership — not merely hidden in the interface.
- Passwords are stored only as bcrypt hashes; verification codes and reset tokens are stored as hashes and expire quickly.
- Session tokens are signed, expiring and revocable, so access can be cut off immediately.
- Third-party calendar credentials are encrypted at rest using AES-256-GCM.
- All traffic is encrypted in transit over HTTPS.
These measures are intended to satisfy the reasonable security practices standard under Section 43A of the Information Technology Act, 2000 and our security obligations under the DPDP Act.
09
Retention and deletion
Clinical records are kept for as long as professional and legal record-keeping obligations require, because an incomplete clinical history can itself be a risk to your care. Journal entries, profile information and bookings are kept while your account is active.
When you ask us to erase your data, we erase everything we are not legally required to retain, and we tell you specifically what has been kept and why rather than giving you a vague answer.
10
Your rights
- Know what we hold. Ask for a summary of the health data we process about you and who it has been shared with.
- Access your records. The Mental Healthcare Act, 2017 gives you a right to access your own mental health records, subject to the narrow exceptions in that Act — for instance where access would present a serious risk of harm.
- Correct what is wrong. Have inaccurate or incomplete information corrected or completed.
- Have data erased, where no law requires us to keep it.
- Withdraw consent at any time, as easily as you gave it.
- Nominate someone to exercise these rights for you if you die or become incapacitated.
- Complain — to our Grievance Officer, and then to the Data Protection Board of India if you are not satisfied.
11
Visitors outside India
Mindcarter operates from India and our services are intended for people in India. If you access this website from a jurisdiction with its own consumer health data legislation — such as the State of Washington's My Health My Data Act or Nevada's SB 370 in the United States — we apply the commitments in this notice to you as well: we do not sell your consumer health data, we do not collect or share it beyond what is described here, and you may ask us to confirm what we hold and to delete it by writing to the address below.
This notice does not make Mindcarter a "covered entity" under the United States Health Insurance Portability and Accountability Act (HIPAA), and we are not regulated under it.
12
How to reach us
For any question about your health data, or to exercise any right above, contact our Grievance Officer. Please write from the email address registered on your account so we can verify who you are.
Grievance Officer
Mindcarter
Module No. A, Tejaswini, Technopark, Thiruvananthapuram, Kerala, India
Email: info@mindcarter.com
Phone: +91 75940 71071
If you are in crisis, please do not wait for a reply to an email. Call 112, or Tele-MANAS on 14416.
Related policies
