Who we are
SuperSlim Healthcare Private Limited, operator of SuperSlim+, is the Data Fiduciary for the personal data described here, under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”). Our registered office is at Bunglow No. A/2, Bhuyang, Dev Society, Opp. Swaminarayan, Ghatlodia, Ahmedabad, Gujarat 380061, India.
This policy covers our marketing site, the patient application, and the consultations, prescriptions and support delivered through them. It should be read alongside our Terms of Service.
What we collect
Information you give us
- Identity and contact — name, date of birth, sex, mobile number, email address, delivery address and pincode.
- Health data — your answers to the eligibility questionnaire, height, weight and BMI, each contraindication flag recorded individually, existing conditions, current medications and allergies, what you tell the doctor during the consultation, the doctor’s structured clinical decision, prescriptions issued to you, dietitian plans, side effects and adherence you report, and progress measurements you log.
- Identity verification and consent — records of the consent you give at registration, before the teleconsultation, before treatment, and at subscription, along with any electronic signature used on a prescription.
- Your messages to us — support tickets, WhatsApp and email conversations with your coordinator, and feedback.
Information we generate or receive
- Payment records — amount, date, order and invoice identifiers, and the result reported by our payment gateway. We never receive or store your full card number, CVV, or UPI PIN — those go directly to the gateway.
- Order and delivery records — what was dispensed, when it shipped, and delivery status from the courier.
- Technical data — IP address, device and browser type, and timestamps of your actions on the platform, including the tamper-evident audit trail described below.
How we use it, and on what basis
| Purpose | Basis |
|---|---|
| Assessing your eligibility and running the consultation | Your explicit consent to process health data |
| Issuing, dispensing and delivering a prescription | Your consent, and performance of our contract with you |
| Coordinator, dietitian and follow-up care | Your consent, and performance of our contract with you |
| Taking payment, invoicing and handling refunds | Performance of our contract; legal obligation |
| Service messages — appointment reminders, dispatch and renewal notices | Performance of our contract |
| Medical record-keeping, clinical audit and the audit log | Legal obligation |
| Safety, fraud prevention, and securing the platform | Legitimate use, and legal obligation |
| Marketing messages about SuperSlim+ | Your consent, which you can withdraw at any time |
We do not sell your personal data. We do not use your health data for advertising, ad targeting, or profiling unrelated to your care, and we do not share it with advertisers, data brokers, insurers or employers.
Your consent
We ask for your consent in clear terms at each gate — registration, teleconsultation, treatment, and subscription — and we record each one separately rather than treating a single tick as blanket permission. Consent notices are available in English, and you may ask for them in any language listed in the Eighth Schedule to the Constitution.
You can withdraw consent at any time, as easily as you gave it, by writing to privacy@superslim.in. Withdrawing consent stops future processing for that purpose. It does not make earlier processing unlawful, and it does not erase records we are legally required to keep — see Retention. If you withdraw consent to health-data processing while on a programme, we cannot continue treating you and will close the programme safely.
Who we share it with
We share the minimum needed, with:
- Your treating doctor — your full clinical record, so they can make a safe decision.
- Your dietitian and patient coordinator — the parts of your record relevant to nutrition guidance and day-to-day support.
- The partner pharmacy — your name, delivery address, contact number, and the prescription, so the medicine can be lawfully dispensed and shipped.
- Logistics providers — your name, address and contact number. They are not told what the package contains beyond what shipping law requires.
- Our payment gateway — the order amount and identifiers needed to process payment.
- Communication providers — WhatsApp business, SMS and email providers, to deliver notifications to you.
- Our electronic signature and cloud hosting providers — as processors acting on our instructions.
- Regulators, courts and law enforcement — where we are legally required to disclose, or to protect someone from serious harm.
- An acquirer — if the business is transferred, subject to the same protections and with notice to you.
Every processor is bound by contract to use your data only for the purpose we specify, to protect it, and to delete or return it when the engagement ends.
How we protect it
- Personal and health data is encrypted at rest, and in transit using TLS 1.2 or above.
- Access is role-based across the six panels — patient, doctor, admin, pharmacy, coordinator and dietitian — and enforced at the database row level, so a staff member sees only the records their role and assignment permit.
- Multi-factor authentication is mandatory for doctors.
- Every clinical action, payment and consent is written to an append-only, hash-chained audit log recording who acted, when, from where, and what changed. Records cannot be silently altered or deleted.
- Prescription PDFs are stored encrypted and served only through short-lived signed links.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person as the DPDP Act requires.
How long we keep it
We keep data only as long as we need it or the law requires. In practice that means:
| Data | Retention | Why |
|---|---|---|
| Medical records — consultation notes, clinical decisions, prescriptions | At least 3 years from the last entry; our systems are built to hold 5+ years | Required of medical records in India; needed for continuity of care and clinical audit |
| Consent records — registration, teleconsultation, treatment, subscription | 7 years | Evidence that lawful consent was obtained for each processing gate |
| Payment and invoice records | As required by tax and company law | Statutory financial record-keeping |
| Account and contact details of an inactive patient | Archived after 12 months of inactivity, then deleted once the periods above lapse | You may return to the programme; after that there is no reason to keep them |
| Health data of a non-serviceable applicant | Purged immediately on pincode rejection | We cannot treat you, so we have no reason to hold your health data. Only the pincode and a waitlist entry are kept |
When you ask us to delete your account, we anonymise the personal identifiers that are not legally required, retain the clinical and consent records for the periods above, and hard delete everything once those periods lapse.
Your rights
Under the DPDP Act you may ask us to:
- Access a summary of the personal data we hold about you, what we do with it, and who we have shared it with.
- Correct or complete data that is wrong or out of date, and update it. Clinical entries made by a doctor are corrected by annotation rather than overwriting, so the medical record stays intact.
- Erase personal data we no longer need and are not required to keep.
- Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
- Withdraw consent, as described above.
- Raise a grievance with us — see below.
Write to privacy@superslim.in. We will verify your identity before acting, and respond within the statutory timeframe.
Children
SuperSlim+ is for adults. We do not knowingly collect data from anyone under 18, and we do not treat under-18s. If you believe a child’s data has reached us, write to privacy@superslim.in and we will delete it.
Cookies and similar technologies
Our marketing site uses only what is needed to serve pages and keep them working. The patient application uses strictly necessary cookies and local browser storage to keep you signed in and to remember where you had reached in the eligibility flow so you do not lose your answers.
Where we use any analytics, it is limited to aggregate usage of the marketing pages and is never joined to your health data. You can block or clear cookies in your browser, though strictly necessary ones cannot be turned off without breaking sign-in.
Where your data is stored
Patient data is hosted in India. If a processor we use stores or accesses data outside India, we transfer it only to countries not restricted by the Government of India, and only under contractual safeguards that hold the processor to this policy.
Changes to this policy
We will update this page as the service and the law evolve. The date at the top shows the current version. Where a change materially affects how we handle your data we will notify you, and where the law requires it we will ask for fresh consent.
Grievance Officer and contact
If you have a question or a complaint about how we handle your data, contact our Grievance Officer. We will acknowledge you and respond within the period the DPDP Act allows.
Grievance Officer — SuperSlim Healthcare Private Limited
Bunglow No. A/2, Bhuyang, Dev Society, Opp. Swaminarayan, Ghatlodia, Ahmedabad, Gujarat 380061, India
grievance@superslim.in ·
+91 98985 87776
If you are not satisfied with our response, you may complain to the Data Protection Board of India.