Privacy Notice
Version 3 · Effective 28 Sep 2026
1. About this notice
This notice explains how your personal data is handled when you use your clinic's booking assistant on Telegram: what is collected, why, who handles it, where it is kept, for how long, how it is protected, what happens if something goes wrong, and the rights you have over it, including how to withdraw consent and how to complain to the Data Protection Board of India.
"Your clinic" means the clinic whose Telegram bot you are using, which is named in the consent message the bot shows you before it does anything else. The clinic's name and its contact for questions about your data are in that consent message. This notice is the same for every clinic that uses the service.
This notice is written to meet the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and other Indian law that applies. The DPDP Rules were notified on 13 November 2025, and most of the duties they place on those who hold personal data begin on 13 May 2027. Until then, section 43A of the Information Technology Act and the SPDI Rules continue to apply. The safeguards this notice describes are already in place.
The patients' Terms of Use, which explain how the booking service works, are a separate document: /terms/v3/
2. Who is responsible for your data
Your clinic is the Data Fiduciary. The clinic decides why your data is collected and how it is used, and it is answerable to you for it. Questions and requests about your data go to the clinic first.
Omvora Media & Automation provides the software, as the clinic's Data Processor. Omvora is a registered partnership firm at Hawal, Srinagar, Jammu & Kashmir 190011, India. It runs the booking, queue, reminder, payment and messaging software for the clinic. Omvora handles your data only on the clinic's instructions and only to provide this service. It does not decide what your data is used for, and it does not use your data for its own purposes.
The assistant tells you this in its first message: it is powered by Omvora and it acts for your clinic.
3. The assistant is automated
The assistant you chat with is software, not a doctor and not a member of clinic staff.
- It handles booking, queue position, reminders and payments only.
- It does not diagnose, prescribe or give medical advice.
- Send /agent at any time to reach a person at the clinic.
- In a medical emergency, do not wait for the chat. Call your local emergency number or go to the nearest hospital.
If a message you send contains words that suggest an emergency, the assistant does not try to handle it. It directs you to emergency help.
4. What personal data is collected
4.1 From you, through the chat
- Your name, as you give it.
- Your Telegram identifier (the number Telegram gives your account) and the name on your Telegram profile. This is how the assistant knows which chat to reply to. Your Telegram username is not collected.
- Your phone number.
- The reason you give for your visit, in your own words.
- Your year of birth and preferred language, where you give them.
- The messages you send to the assistant, and the buttons you tap.
- Your rights requests and complaints, including anything you write in them.
- Your nominee's details, if you name a nominee: their name, phone number and, if you give it, their relationship to you.
4.2 Created as you use the service
- Appointment history: bookings, changes, cancellations, attendance, and the doctor and day of each visit.
- Queue tokens and your position in the queue.
- Payment records: amounts, the status of each payment and refund, and the payment reference. Card and UPI details are not part of these records (see section 11).
- Consent records: which consents you gave or withdrew, when, and which version of the consent text you were shown.
4.3 Recorded by the clinic
- Visit notes: clinic staff and your doctor may record notes and observations about your visit, so that your doctor can see them.
- Documents the clinic adds to your record.
- Prescriptions: each clinic chooses whether to record or upload prescriptions in this system. Some clinics do, and some do not. If your clinic does, your prescriptions are part of your record and are covered by this notice. If it does not, prescriptions stay in the clinic's own paper or other records and are not held in this system.
4.4 Health information is treated as sensitive
The reason for your visit, visit notes, observations, documents and prescriptions are health information. They are handled as sensitive personal data, with the stronger protections set out in section 12.
The only other sensitive personal data involved is payment information, and card and UPI details are entered with Easebuzz, not with the clinic or Omvora (section 11). The service has no passwords: it recognises you by your Telegram account.
4.5 If you choose not to give information
- Your name, your phone number and consent to Care & service (M0) are needed to book: without them the assistant cannot book or manage appointments for you. You can still contact the clinic directly, and your care does not depend on the assistant.
- Your year of birth and preferred language are optional. Without them the assistant still books for you.
- Every consent from M1 to M5 is optional. Saying no changes nothing about your care or your bookings.
4.6 What is not collected
The assistant does not read your Telegram contacts, your location or your other chats, and it does not track you on other apps or websites.
5. Why your data is used
| Purpose | What it covers |
|---|---|
| Booking | Creating, changing and cancelling your appointments |
| Queue | Giving you a token and telling you your position |
| Reminders | Messaging you before your appointment and about changes to it |
| Payment | Taking consultation fees, confirming payment, and handling refunds |
| Your care | Letting your treating doctor and the clinic staff involved in your visit see your record |
| Safety | Recognising a message that suggests an emergency, or that the patient may be a child, and responding to it |
| Your rights | Answering your access, correction, erasure, nomination and complaint requests |
| Security and records the law requires | Protecting the service, keeping an audit trail, and keeping payment and medical records for the periods the law sets |
| Optional purposes | Only the optional purposes you choose in section 6 |
Your data is not sold or rented, and it is not shared with anyone for their own marketing.
Lawful basis. The clinic relies on your consent for each purpose in section 6. Where the law itself requires a record to be kept, such as tax records or medical records, the clinic keeps it because the law requires it, even if you withdraw consent.
The DPDP Act also allows some uses without consent (section 7 of the Act). The clinic relies on them only here:
| Use | Ground under section 7 of the DPDP Act |
|---|---|
| Recognising a message that suggests a medical emergency and directing you to emergency help | Responding to a medical emergency involving a threat to life or health (section 7(f)) |
| Giving information that a law requires to be given to a government authority | Fulfilling a legal obligation to disclose information to the State (section 7(d)) |
| Complying with a court judgment, decree or order | Compliance with a judgment or order (section 7(e)) |
5.1 What each item is used for
| Personal data | Used for |
|---|---|
| Name | Booking, reminders, your record, and letting clinic staff recognise you |
| Telegram identifier and profile name | Replying to you in the right chat, reminders, and identifying you when you use /privacy |
| Phone number | Your record, and contacting you about your appointments |
| Reason for your visit | Booking, and your doctor's care |
| Year of birth and preferred language | Talking to you in your language, and your record |
| Messages and button taps | Understanding what you want, and the safety checks in section 10 |
| Appointment history, queue tokens | Booking, the queue, reminders and your care |
| Payment records | Taking fees, confirming payments and handling refunds; tax records |
| Visit notes, documents, prescriptions | Your care by your doctor |
| Consent records | Proving which consents you gave or withdrew |
| Rights requests, complaints and nominee details | Answering your requests and complaints, and letting your nominee act for you |
6. Consent
6.1 How you give it
Before the assistant books anything, it shows you a consent message that names your clinic, says what is collected and why, and links to this notice. You choose by tapping a button. Nothing is assumed from silence.
Consent is given separately for each purpose. The one consent the service needs is never bundled with the optional ones, and saying no to an optional consent never affects your care.
6.2 The consents you can give
| Code | Name | What it allows | Needed? |
|---|---|---|---|
| M0 | Care & service | Booking, reminders, payment, and your doctor's care | Yes, the service cannot work without it |
| M1 | Improve assistant | Using de-identified information to improve the assistant. Your identifying details are removed first | Optional |
| M2 | Records transfer on referral | If your doctor refers you to another clinic, carrying your details to that receiving clinic only. Your doctor is not paid for referring you | Optional |
| M3 | Over-the-counter product suggestions | Receiving non-prescription skincare and product suggestions. These never replace your doctor's advice | Optional |
| M4 | Tips & offers | Receiving tips and offers from the clinic | Optional |
| M5 | Research / aggregate insights | Using de-identified information in anonymised research and aggregate insights about care. Anything that could identify you is removed first, and results are only shared as totals | Optional |
These six are the only consents offered. If the clinic ever wants to use your data for any other purpose, it will ask you for that separately first, and nothing changes until you say yes.
6.3 How you withdraw it
You can withdraw any consent at any time, as easily as you gave it:
- send /privacy, tap My consents, and tap Withdraw next to the consent; or
- send /stop to stop tips and offers (M4) straight away.
Withdrawing an optional consent (M1 to M5) does not affect your care or your bookings in any way.
Withdrawing M0 (Care & service) ends the booking service for you: the assistant can no longer book, remind or manage appointments for you. Your records are then kept only for the periods the law requires (section 13). You can use the service again later by sending /start and giving consent again.
Withdrawal stops the processing from that point. It does not undo processing that was done lawfully before you withdrew. After you withdraw, the clinic stops the processing within a reasonable time and has Omvora stop it too, unless the law requires or allows it to continue.
No Consent Manager is used. You give, see and withdraw your consents directly in the chat.
6.4 Proof of consent
Each time you give or withdraw a consent, the clinic keeps a record of which consent it was, the time, how you did it, and the exact version of the text you were shown. You can see the current state of your consents at any time under /privacy.
7. AI and automated processing
7.1 What AI is used for
- Understanding your messages. When you write a message in your own words, an AI model may be used to work out what you want, such as to book, to ask about the queue, to ask about opening hours, or to reach a person. This is reception work only. The model is instructed never to diagnose, interpret symptoms, advise on treatment or recommend medicine.
- Recaps for your doctor. An AI model may write a short recap of what is already in your record, to help your doctor recall your previous visits. It only restates what is recorded. It does not diagnose, suggest treatment or make recommendations.
7.2 De-identification before any model
Before any text reaches any AI model, it passes through a de-identification check. Names (in English, Urdu, Kashmiri and Hindi scripts), phone numbers, email addresses, links and identifying numbers are removed and replaced with neutral markers. The service refuses to send text to a model if this check has not been applied. The link between the markers and your real details stays on Omvora's server and is never sent to a model.
7.3 Which models are used
| Model provider | Where it runs | Used for |
|---|---|---|
| OpenAI | United States | Understanding reception messages |
| NVIDIA NIM | NVIDIA's cloud service | Understanding reception messages |
| A model on Omvora's own server | Srinagar, India | Reception and doctor recaps |
Only de-identified text is sent to OpenAI and NVIDIA. Every call to a model is recorded in the audit trail.
7.4 People make the decisions
AI never diagnoses, prescribes or decides anything about your care. Your doctor and the clinic staff make every decision. What the models produce is checked by the software before you see it, and a person is always available: send /agent.
8. Who can see your data, and who receives it
8.1 Inside your clinic
Only clinic staff involved in your care or your appointment can see your record, and each staff member sees only what their role needs. Every time someone opens a patient record, it is recorded in the audit trail.
8.2 Other clinics
Each clinic's data is kept apart from every other clinic's data. A clinic using this software cannot see another clinic's patients. Your details go to another clinic only if you have given consent M2 and your doctor refers you there, and then only to the receiving clinic.
8.3 Omvora
Omvora, as the clinic's Data Processor, handles your data to run, secure, back up and support the service, on the clinic's instructions.
8.4 Service providers
| Provider | What it does | What it receives |
|---|---|---|
| Telegram (Telegram Messenger Inc.) | Carries messages between you and the assistant | Your messages and the assistant's replies. Telegram's servers are outside India, and Telegram's own privacy policy applies to your use of the Telegram app |
| Cloudflare | Network security and delivery in front of Omvora's server | Network information such as IP addresses and request times, to deliver and protect the connection |
| Easebuzz | Payment processing | The details you enter on the payment page to pay, and the payment amount and reference |
| OpenAI | AI model for reception messages | De-identified text only |
| NVIDIA (NIM) | AI model for reception messages | De-identified text only |
| Google (Google Drive) | Storage for one copy of the backups | Backups that are encrypted before they leave Omvora's server |
8.5 When the law requires it
Your data may be disclosed where a law, a court order or a lawful authority requires it: for example to a court or tribunal, the Data Protection Board of India, CERT-In, a law-enforcement or investigating agency, or a tax authority. Only what is required is disclosed, and you will be told unless the law forbids it.
8.6 Who does not receive your data
Your data is not given to advertisers, data brokers or insurers, and it is not sold.
9. Where your data is stored
- Omvora's own server in Srinagar, India holds the database: your records, appointments, payments, consents and audit trail.
- Backups are encrypted before they leave the server. They are kept on local and offline drives in India, and an encrypted copy is kept with Google Drive.
- Telegram carries your messages through its own servers, which are outside India.
- De-identified text may be sent to OpenAI in the United States and to NVIDIA's cloud service, as section 7 explains.
Where Indian law places conditions on processing data outside India, the clinic and Omvora follow them. Your data is not sent to any country to which the Central Government has restricted transfers under section 16 of the DPDP Act, and any requirement the Central Government sets under rule 15 of the DPDP Rules is met. Data processed outside India may also be subject to the laws of the country where it is processed.
10. Safety checks, children and emergencies
10.1 Emergencies
The assistant checks every message for words that suggest an emergency, such as chest pain, difficulty breathing, severe bleeding, loss of consciousness, poisoning or thoughts of self-harm. When it sees them, it stops and tells you to call 112 (India's emergency number) or 108 for an ambulance, or to go to the nearest hospital, and offers you a person at the clinic. This check does not replace calling for help: in an emergency, call 112 straight away.
10.2 Children
The assistant books appointments for adults. If a message suggests that the appointment is for a child, the assistant does not book it by itself: it asks the parent or guardian to arrange the appointment with the clinic's staff, and offers Talk to the clinic. The clinic's staff make the booking with the parent or guardian, who gives consent on the child's behalf.
A child's data is not used for tracking, behavioural monitoring or advertising directed at children.
If you are the lawful guardian of an adult with a disability who cannot consent for themselves, you give consent on their behalf. As with a child, the booking is arranged with the clinic's staff, who may ask to see the order of the court, designated authority or local level committee that appointed you, as the DPDP Rules require.
11. Payments
Easebuzz is the only payment provider used by the service. When you pay, you enter your card or UPI details on Easebuzz's payment page. Easebuzz processes those details. Neither the clinic nor Omvora stores your card number.
Your clinic is the merchant: your payment goes to the clinic, not to Omvora. The clinic and Omvora see the amount, the status of the payment and the payment reference, which are kept as payment records (section 13).
12. How your data is protected
- Encryption at rest. Personal and health information in the database is stored in encrypted columns.
- Encrypted backups. Backups are encrypted before they leave the server, and the keys are kept separately from the backups.
- Role-based access. Each clinic staff member sees only what their role needs.
- Clinic separation. Each clinic's data is walled off from every other clinic's data in the database itself.
- Tamper-evident audit trail. Every access to patient records is logged, and the log is protected so that it cannot be altered unnoticed.
- De-identification before any AI model (section 7).
- Emergency access is reported to you. If clinic staff ever open your records using emergency access, you are told in the chat who opened them, when and why, a person reviews every emergency access within 48 hours, and you can tap This looks wrong to raise a complaint at once.
- Network protection. The server sits behind Cloudflare, which filters attacks before they reach it.
- Encryption in transit. Connections to the service and to these notice pages are encrypted.
- Continuity. Encrypted backups let the service continue if data is lost or damaged.
- Logs kept for detection. Logs of processing are kept for one year (section 13), so that unauthorised access can be detected, investigated and put right.
These are the safeguards the DPDP Rules require as a minimum (rule 6), and they follow a documented security programme with managerial, technical, operational and physical controls, as the SPDI Rules describe (rule 8).
No system connected to the internet can be guaranteed to be completely secure. Section 16 explains what happens if something goes wrong.
13. How long your data is kept
Each kind of data has its own period, and data is not kept just because it might be useful one day. When a period ends, the data is deleted automatically, unless a legal hold applies (for instance, where a dispute or legal case needs it).
| Data | How long it is kept | Why |
|---|---|---|
| Clinical records: visit notes, observations, documents, and prescriptions where the clinic records them | 3 years from your last appointment | Medical record norms, and the period in which a complaint can be brought under the Consumer Protection Act, 2019 |
| Appointments and queue records | 3 years | Matched to the clinical records |
| Audit trail | 3 years | To show who accessed your records and what was done |
| Identifiers: your name, phone number and Telegram identifier | 3 years, matched to the clinical records | So the records above can be linked to you while they are kept |
| Payment, invoice and tax records | For the minimum period Indian GST and income-tax law require. Under section 36 of the Central Goods and Services Tax Act, 2017, this is 72 months from the due date of the annual return for the year concerned | Tax law |
| Processing and traffic logs, and the record used to detect duplicate messages | 1 year | The minimum the DPDP Rules require for logs |
| Rejected calls to the payment gateway | 90 days | Security and fraud checks |
| Consent records | For as long as they are needed to show that consent was given or withdrawn | Proof of consent |
| Your nominee's details | No longer than your own records | They exist only to act for you |
You are told before scheduled deletion. Before records reach the end of their period, the assistant sends you a message listing what is due to be deleted and when. You do not need to do anything. If you want the clinic to keep those records, tap Keep my records and they will not be deleted on that date.
When records are deleted, the copies Omvora holds for the clinic are deleted too. Encrypted backups are replaced on their own schedule, so a deleted record leaves the backups when the backups that contain it expire.
14. Your rights
You have these rights over your personal data. Using them is free.
| Right | What it means |
|---|---|
| Access | A summary of the data held about you, how it is used, and who it has been shared with |
| A copy of your records | A list of your records in the chat, and a complete machine-readable copy from the clinic on request |
| Correction and updating | Fixing details that are wrong, incomplete or out of date |
| Erasure | Deleting your data, except records the law requires the clinic to keep |
| Withdrawing consent | Stopping any consent at any time (section 6.3) |
| Nomination | Naming someone to use these rights for you if you die or become unable to use them |
| Grievance | Complaining about how your data is handled, and getting an answer |
14.1 How to use your rights: /privacy
Send /privacy in the chat. It opens a menu that answers most requests straight away:
| Button | What it does |
|---|---|
| View my data | Shows a summary: your record reference; how many appointments, visits, records, documents and prescriptions are held; the state of each consent; who your data has been shared with; and the date until which medical records are kept |
| My records | Lists the records held about you. A complete machine-readable copy (in the FHIR health-record format) is available from the clinic on request within 30 days |
| Correct details | Lets you correct your name, phone number, year of birth or preferred language. Some changes apply at once; others are checked by the clinic first, and you are told the date by which it will be done and the outcome |
| Erase my data | Explains what erasure does, then asks you to confirm with a one-time code before anything is deleted |
| Raise a complaint | Registers a complaint, gives you a reference, and tells you when it will be acknowledged and resolved |
| My complaints | Shows your complaints, their status and their outcome |
| Nominate someone | Lets you name or remove a nominee |
| My consents | Shows each consent and lets you withdraw it |
You can also contact your clinic directly, using the contact given in the consent message in the chat. For anything about how Omvora handles your data as the clinic's processor, you can write to Omvora's Grievance Officer (section 15).
The clinic may ask for reasonable information to confirm that a request really comes from you or your nominee. It will not ask for more than it needs. In the chat, your Telegram account identifies you. Outside the chat, give your name, your phone number and, if you have it, your record reference, which View my data shows.
How long requests take. Most requests under /privacy are answered at once. A complaint is acknowledged within 2 working days and resolved within 30 days of receipt (section 15). This is within the ninety days the DPDP Rules allow.
14.2 Erasure
When you confirm erasure:
- your name, phone number and identity details are removed;
- pending appointments and waitlist entries are deleted;
- medical records are kept only for the period the law requires (section 13), and then deleted;
- payment and tax records are kept for the period tax law requires; and
- the record that you gave and withdrew consent is kept as proof.
When erasure is done, the assistant tells you exactly which records have been kept and that they are kept for the period the law requires. After erasure, the assistant can no longer serve you at that clinic. If a legal hold applies to your record, erasure waits, and the clinic contacts you about it.
14.3 Nominee
You can name one person to use your rights for you if you die or become unable to use them yourself. Send /privacy, tap Nominate someone, and reply with their name and phone number, and their relationship to you if you wish. Naming someone new replaces the previous nominee, and you can remove your nominee at any time from the same menu.
A nominee can act on all of your rights. The system can also record a nominee who may act only on access, or only on erasure; ask your clinic if you want your nominee limited in either way.
14.4 Your duties
The DPDP Act (section 15) asks you, when you use these rights, to:
- follow the law while using them;
- not pretend to be someone else when you give personal data;
- not hide important information when you give personal data for an official document or proof of identity or address;
- not make a false or frivolous complaint to the clinic, to Omvora or to the Data Protection Board; and
- give only true, checkable information when you ask for a correction or erasure.
15. Complaints
Step 1: your clinic. Raise a complaint through /privacy (Raise a complaint), or contact your clinic using the contact given in the consent message in the chat. Your complaint gets a reference. It is acknowledged within 2 working days and resolved within 30 days of receipt.
Step 2: Omvora's Grievance Officer. If the clinic has not resolved your complaint, or it concerns how Omvora handles your data as the clinic's processor, write to:
Grievance Officer: Mr Mujtaba Mirza Omvora Media & Automation Hawal, Srinagar, Jammu & Kashmir 190011, India Email: privacy@omvoramedia.com Phone: +91 90040 22222 Hours: Monday to Saturday, 10 am to 7 pm IST
Omvora acknowledges a grievance within 2 working days and resolves it within 30 days of receipt, within the one month the SPDI Rules require. Where the matter is the clinic's to decide, Omvora passes it to the clinic without delay and tells you it has done so. A grievance emailed to privacy@omvoramedia.com gets a reference number automatically; quote it, or the reference the chat gave you, to follow up.
Every complaint is handled fairly, courteously and on time, and the answer tells you how to take the matter further if you are not satisfied.
Step 3: the Data Protection Board of India. If your grievance remains unresolved, or you are not satisfied with the answer, you may complain to the Data Protection Board of India, the body the DPDP Act sets up to enforce it, in the manner the Board prescribes. The Act requires a grievance to be raised with the Data Fiduciary (your clinic) first. The Board works as a digital office, so a complaint to it is made online. No consent you give can take away your right to complain to the Board.
16. If there is a data breach
If a personal data breach happens:
- it is recorded, contained and investigated at once;
- Omvora, as processor, informs your clinic without delay;
- you are told without delay, in plain language, in the chat or through another contact you gave: what happened, when and how widely, what data was involved, the likely consequences, what is being done about it, what you can do to protect yourself, and whom to contact;
- the Data Protection Board of India is informed without delay and given a detailed report within 72 hours, or any longer time the Board allows, as the DPDP Act and Rules require; and
- cyber-security incidents that must be reported to CERT-In are reported within 6 hours of being noticed, as CERT-In's directions require.
17. Languages and accessibility
This notice is written in plain English. The chat, including the /privacy menu and the consent message, is plain text that a screen reader can read aloud. If you need this notice in another language listed in the Eighth Schedule to the Constitution of India, or in another format you can use, ask your clinic, or write to privacy@omvoramedia.com.
18. Changes to this notice
This is version 3. Each version is published at its own permanent address and is never edited after it is published, so you can always see the exact notice that applied when you gave consent. A change is published as a new version with a new effective date. Version 3 corrects how the cf_clearance security cookie is described (section 19): Cloudflare adds a small bot-detection script to each page, and this cookie holds its result. Version 2 was published on 28 September 2026.
A new version is published here before it takes effect, and the consent message in the chat always links to the version in force. If a change adds a new purpose, you are asked for consent to it separately, and a consent you gave under an earlier version covers only the purposes that version named.
19. Cookies and these web pages
The booking assistant runs inside Telegram. It sets no cookies and stores nothing in your browser.
This notice and the Terms of Use are published as static web pages served by Cloudflare. The pages themselves store nothing in your browser and use no analytics and no advertising. Cloudflare, which protects them, may set its own security cookies:
| Name | Set by | Type | Category | Purpose | How long | Needs your consent? |
|---|---|---|---|---|---|---|
__cf_bm |
Cloudflare | Cookie | Strictly necessary | Bot management: tells people from automated traffic, to keep the pages available. Set only when Cloudflare needs it | About 30 minutes | No |
cf_clearance |
Cloudflare | Cookie | Strictly necessary | Holds the result of Cloudflare's bot detection: Cloudflare adds a small script to each page it serves, and when that script runs in your browser, this cookie records the outcome. Also set when Cloudflare checks a visitor, and for every visitor while the pages are under attack and its "under attack" protection is on | Set by Cloudflare | No |
Nothing on these pages needs your consent. Your browser's settings let you block or delete cookies; if you block these, Cloudflare may check your browser more often, and while the pages are under attack it may not be able to let you in.
The pages do not track you, so a browser's "Do Not Track" signal changes nothing on them.
20. Links to other services
The chat and these pages link to services run by others, such as Telegram and Easebuzz's payment page. They have their own terms and privacy policies, which apply when you use them. This notice covers only what your clinic and Omvora do with your data.
21. Protect yourself from people pretending to be the clinic
Neither your clinic nor Omvora will ever ask you, in the chat, by message or by telephone, for your card number, CVV, UPI PIN, a one-time password or a bank password. They do not call or message patients offering prizes, free gifts or lucky-draw rewards. Pay only through the Easebuzz link the assistant gives you.
If someone asks you for any of these while claiming to be your clinic, the assistant or Omvora, do not reply or pay. Tell your clinic (send /agent) or write to privacy@omvoramedia.com. If you have lost money, contact your bank and the national cyber-crime helpline 1930 or cybercrime.gov.in straight away.
22. Contact
Your clinic (Data Fiduciary): the name and contact given in the consent message in the chat. In the chat, send /privacy for your data and /agent to reach a person.
Omvora Media & Automation (Data Processor): Hawal, Srinagar, Jammu & Kashmir 190011, India. Privacy and grievances: privacy@omvoramedia.com (Grievance Officer: Mr Mujtaba Mirza). Phone: +91 90040 22222. Hours: Monday to Saturday, 10 am to 7 pm IST.
This notice: /v3/ Terms of Use: /terms/v3/