Effective date: August 25, 2026 Last updated: August 25, 2026
This policy is a template accurate to how the app works, with placeholders in
[BRACKETS]you must fill in. Have it reviewed by legal counsel before publishing — especially for India's Digital Personal Data Protection Act, 2023 (DPDP) and any hospital data-processing agreements.
CareLoop ("the App", "we", "us") is a referral-management and hospital field- marketing tool operated by Wormhole ("the Company"), a company registered in India at 87/1103-F-1-A, Revenue Ward No 87, 4th Class Employees Colony, Kurnool, Andhra Pradesh 518003, India. This policy explains what personal data the App processes, why, and your rights.
The App is used by hospital staff and referring practitioners to manage patient referrals. It is not a medical device and does not provide medical advice, diagnosis, or treatment. It records referral and operational information only.
Account & identity - Mobile number (used to sign in via one-time password / OTP) - Name, and for staff optionally an email address - Role and the hospital you belong to
Referral information (includes health data) - Patient name, age, gender, mobile number, village/town, address - Clinical details entered by the practitioner: chief complaint, provisional diagnosis, symptoms, previous treatment, allergies - Whether an ambulance is required - Uploaded documents you attach (prescriptions, scans, reports) - Referral status history (referred → verified → admitted → discharged, etc.)
Field-marketing data (PRO / manager roles only) - Precise device location (GPS), captured only when a PRO taps check-in/check-out for a doctor visit (foreground, while using the App) - Visit notes, doctor/relationship records, medical-camp details
Device & technical - Push-notification token (Firebase Cloud Messaging) - Diagnostic/crash information to keep the App working
On-device cache - A local, on-device copy of searchable patient metadata (name, phone, code) is stored on the device to make search fast and work offline. It is scoped to your hospital and cleared when you sign out.
We do not collect precise background location, we do not read your SMS, and we do not show advertising or sell personal data. No referral commission, payout, or fee is processed — that is prohibited for Indian practitioners (IMC Professional Conduct Regulations, 2002, Clause 6.4).
Legal basis (DPDP): processing is carried out on the basis of consent and/or for the legitimate uses permitted under the Act, and under the instructions of the hospital, which acts as the Data Fiduciary for patient data it enters.
No system is perfectly secure; we work to protect your data but cannot guarantee absolute security.
We retain referral and account data for as long as your hospital account is active and as required to provide the service, plus any period required by applicable medical-records and tax laws. On verified deletion request, data is removed or irreversibly anonymised except where retention is legally required.
You may request access to, correction of, or deletion of your personal data, and withdraw consent, subject to the Act and applicable law.
To delete your account and associated data: - In the App (where available): Profile → Delete account, or - Email support@wormhole.co.in with your registered mobile number.
On a verified request we delete your authentication account and profile, and delete or anonymise data linked to you, within 30 days, except records we must retain by law. Patient records entered under a hospital's account are handled per that hospital's instructions as Data Fiduciary.
The App is intended for hospital staff and practitioners and is not directed to children. We do not knowingly create accounts for children.
We may update this policy; material changes will be notified in-app or by the contact you provided. Continued use after an update means you accept it.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.