Effective date: 16 September 2026
This Privacy Policy explains how Asarfi Hospital Limited (“Asarfi Hospital”, “we”, “us” or “our”) collects, uses, stores, shares and protects personal data in connection with our hospitals, healthcare services, education activities, websites, employee systems, mobile applications and other digital services.
This policy should be read together with any patient consent form, employee notice, app permission notice or service-specific notice shown to you.
1. Digital systems and applications used by Asarfi Hospital
Asarfi Hospital uses digital systems developed, licensed, hosted or supported by SilicoSoft Technologies Private Limited for hospital operations, marketing, HR, ambulance coordination and education management.
Asarfi HRMS may be renamed in the future. This policy will continue to apply to the renamed or successor Human Resources Management product unless replaced by a revised policy.
2. Our role and SilicoSoft's role
Asarfi Hospital generally determines the purposes for which patient, employee, student, attendant, vendor, visitor and operational information is processed in connection with our services.
SilicoSoft Technologies Private Limited acts as a technology/service provider for the above systems and may process personal data on our behalf for hosting, software operation, maintenance, support, authentication, integration, backup, security, troubleshooting and other authorised technical functions.
SilicoSoft is not authorised to independently use Asarfi Hospital patient, employee or student data for unrelated advertising or unrelated commercial purposes.
3. Personal data we may collect or process
| Category | Examples | Typical purpose |
|---|---|---|
| Identity and contact information | Name, age/date of birth, gender, address, mobile number, email, identifiers and emergency contacts. | Registration, identification, communication and service delivery. |
| Health and clinical information | Symptoms, diagnosis, medical history, prescriptions, clinical notes, allergies, vitals, treatment and discharge information. | Healthcare delivery and continuity of care through SilicoMed and hospital systems. |
| Diagnostic and imaging information | Laboratory orders/results, radiology information, reports, samples and related records. | Diagnosis, treatment and clinical workflows. |
| Billing, insurance and payment information | Bills, estimates, deposits, payment status, insurer/TPA details, claims and transaction references. | Billing, settlement, claims and financial administration. |
| Employee and HR information | Employee profile, department, designation, attendance, roster, leave, payroll-related records, performance, work allocation and documents. | Human Resources Management through Asarfi HRMS. |
| Education information | Student profile, admission, attendance, academics, examinations, fees, faculty/staff and related institutional records. | Education Management Software. |
| Marketing and CRM information | Leads, enquiries, campaign/source information, service interests, follow-ups, assignments, feedback and communication history. | Marketing and relationship management through ArogyaVeer. |
| Ambulance and emergency transport information | Patient/contact information, ambulance request, pickup and destination, ambulance/crew assignment, trip status, emergency information and timestamps. | Ambulance coordination through RakshaRath. |
| Location data | Pickup location, destination, vehicle/device location and route information where enabled. | Ambulance dispatch, routing, tracking and hospital coordination. |
| Authentication and audit information | User ID, login events, OTP status, access logs, session details and audit trails. | Secure access, accountability and fraud prevention. |
| Device and technical information | IP address, browser/device type, operating system, app version, crash logs and security logs. | Security, reliability, troubleshooting and system administration. |
| Device permissions and files | Camera, photos/files, notifications and location where a feature requires access. | Only for the specific enabled feature. |
| CCTV and physical-security information | Video footage and access-control records where deployed. | Safety, security and incident investigation. |
4. Product-specific processing
Education Management Software
May process student, applicant, faculty and institutional information for admission, attendance, academics, examination, fee, communication and administrative workflows.
SilicoMed — Hospital Management System
May process patient registration, appointments, clinical and diagnostic data, pharmacy, billing, insurance/TPA, admission/discharge, documents, authentication and hospital operational information.
ArogyaVeer — Marketing CRM Management
May process enquiries, leads, campaign/source information, service interests, contact details, follow-ups, assignments, feedback and communication history for authorised hospital outreach and relationship-management activities.
Asarfi HRMS — Human Resources Management
May process employee profile, department/designation, attendance, roster, leave, payroll-related records, work allocation, performance, documents, authentication and related HR information.
RakshaRath — Ambulance Management
RakshaRath is used to connect patients, ambulances and the hospital. It may process ambulance requests, patient/contact details, pickup and destination information, ambulance/crew assignment, trip status, emergency information, timestamps and location data where necessary for dispatch, routing, tracking and hospital coordination.
5. How we use personal data
- Provide medical, diagnostic, pharmacy, emergency, ambulance and hospital services.
- Maintain medical records and support continuity of care.
- Register and communicate with patients and attendants.
- Manage appointments, enquiries, CRM follow-ups and service communication.
- Manage employees, attendance, rosters, leave, payroll, performance and work allocation.
- Manage education, student and institutional workflows.
- Coordinate ambulance requests, dispatch, routing, tracking and hospital arrival.
- Process billing, insurance and TPA claims.
- Authenticate users, maintain audit trails and protect systems.
- Comply with healthcare, employment, education, tax, legal and regulatory obligations.
We do not sell patient, employee or student personal data.
6. Consent, notices and permissions
Where applicable law requires consent, we will seek consent through an appropriate form, notice, digital interface or other valid mechanism. Device permissions such as camera, files, notifications or location should be requested only where the relevant feature requires them.
For RakshaRath, location access may be required for ambulance pickup, dispatch, vehicle tracking, routing or hospital coordination. The app should explain the purpose when requesting location access.
7. Sharing of personal data
We may share personal data, only as reasonably necessary and subject to applicable law, with authorised doctors, nurses, hospital departments, ambulance teams, educational staff, insurers/TPAs, government health schemes, payment processors, SilicoSoft Technologies Private Limited, hosting and communication providers, authorised integration partners, professional advisers and authorities where legally required.
8. Data retention
We retain information for as long as necessary for healthcare delivery, medical-record obligations, billing, insurance, employment, payroll, education, audit, dispute resolution, security and applicable legal requirements. Different categories of records may have different retention periods.
Deleting an app account does not automatically require deletion of medical, billing, ambulance, employment, payroll or education records that Asarfi Hospital is legally required or permitted to retain.
9. Security safeguards
We use reasonable technical and organisational measures designed to protect personal data, including authentication, role-based access, audit logging, secure communications, backups, network controls, access reviews and security monitoring appropriate to the system and risk.
10. Data breach and incident response
If we become aware of a personal-data breach, we will assess and respond to the incident, take reasonable containment and remediation measures and make notifications to affected persons and/or authorities where required by applicable law.
11. Privacy rights and requests
Subject to applicable law and mandatory record-retention requirements, you may request information about your personal data, correction or updating, erasure where legally permissible, withdrawal of consent where applicable and grievance redressal.
12. Children and minors
Healthcare and education services may involve children and minors. Their information may be processed for healthcare, registration, education, billing, emergency and related purposes through the parent, lawful guardian or other authorised person as required by law.
13. Cookies and website technologies
Our websites may use essential cookies and similar technologies for functionality, security and session management. If non-essential analytics, advertising or tracking technologies are introduced, appropriate notices and consent mechanisms should be provided where required.
14. Digital Personal Data Protection framework
Asarfi Hospital is updating its privacy governance and digital systems in line with the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 as applicable provisions come into force, including purpose-specific notices, consent/withdrawal mechanisms where applicable, reasonable safeguards, grievance handling, applicable rights and oversight of data processors.
15. Changes to this policy
We may update this policy as our services, digital systems, product names, legal obligations or processing practices change. The current version will be published on our website with an updated effective date.
16. Grievance redressal
Asarfi Hospital Limited
Baramuri, B Polytechnic, Dhanbad, Jharkhand 828130
Grievance Officer: Mr. Suraj Hazari, or such successor as may be formally designated by Asarfi Hospital Limited.
Email: info@asarfihospital.com
Publication check: Before publishing, confirm the current Grievance Officer, official grievance/privacy email, actual app permissions, hosting arrangements, third-party SDKs/integrations and formal retention schedule.