DATA RETENTION & DATA LIFECYCLE POLICY
Version 1.0 · Effective Date: 14.09.2026 · Last Updated: 14.09.2026
1. INTRODUCTION
This Data Retention & Data Lifecycle Policy ("Policy") describes how [INSERT LEGAL ENTITY NAME], a company incorporated under the Companies Act, 2013, operating under the brand "Aarog Health Records" ("Aarog", "Company", "we", "our", "us") manages the retention, archival, deletion, and destruction of Personal Data and Health Data processed through the Services.
This Policy forms part of Aarog's legal framework and should be read together with the:
- Privacy Policy;
- Terms & Conditions;
- End User License Agreement (EULA);
- Consent for Processing Health Data;
- Family Member Consent & Authorization Policy;
- Account Deletion Policy; and
- other applicable policies.
2. PURPOSE
The objectives of this Policy are to:
- retain data only for as long as reasonably necessary;
- comply with Applicable Law;
- protect user privacy;
- maintain business continuity;
- support disaster recovery;
- reduce unnecessary data storage;
- securely dispose of data that is no longer required.
3. SCOPE
This Policy applies to:
- Personal Data;
- Health Data;
- Family Member profiles;
- account information;
- uploaded medical records;
- system logs;
- security logs;
- audit logs;
- customer support records;
- communication records; and
- backup copies,
processed by Aarog in connection with the Services.
4. DATA LIFECYCLE
The lifecycle of information within Aarog generally consists of:
- Collection;
- Verification (where applicable);
- Secure Storage;
- Processing;
- Authorized Access;
- Sharing upon User instruction or legal requirement;
- Archival where necessary;
- Deletion or Secure Destruction.
Aarog aims to manage each stage in a manner consistent with applicable legal requirements and industry security practices.
5. GENERAL RETENTION PRINCIPLES
Aarog retains Personal Data and Health Data only:
- for as long as required to provide the Services;
- to comply with Applicable Law;
- to resolve disputes;
- to enforce contractual rights;
- to prevent fraud;
- to maintain security;
- to support legitimate business operations.
Information that is no longer required for these purposes will be securely deleted or anonymized, where reasonably practicable.
6. RETENTION OF ACCOUNT INFORMATION
Basic account information (such as name, registered mobile number, email address, and account identifiers) is retained while the User's account remains active.
Following account deletion, certain account-related information may be retained for a limited period where necessary for:
- legal compliance;
- fraud prevention;
- security investigations;
- dispute resolution; or
- enforcement of contractual obligations.
7. RETENTION OF HEALTH DATA
Health Data uploaded by Users is retained while the User maintains an active account or until the User deletes the information, subject to:
- legal obligations;
- regulatory requirements;
- preservation of system integrity;
- backup retention;
- ongoing investigations; or
- lawful requests from competent authorities.
Aarog does not retain Health Data indefinitely without a legitimate purpose.
8. RETENTION OF FAMILY MEMBER DATA
Health Data relating to Family Members is retained under the same principles as the primary User's Health Data.
Where the User's authority to manage a Family Member profile ends, Aarog may restrict access, transfer control where appropriate, or delete information in accordance with applicable law and the relevant policies.
9. RETENTION OF CUSTOMER SUPPORT RECORDS
Communications with customer support, including emails, chat messages, complaint records, and support tickets, may be retained for a reasonable period to:
- improve customer service;
- investigate complaints;
- resolve disputes;
- demonstrate compliance with legal obligations.
10. RETENTION OF SECURITY AND AUDIT LOGS
To protect the security and integrity of the Services, Aarog may retain:
- authentication logs;
- login history;
- device information;
- IP address logs;
- access logs;
- audit trails;
- security incident records.
These records may be retained for longer periods where necessary for cybersecurity, fraud prevention, or legal compliance.
11. BACKUPS
Aarog may maintain encrypted backups of data for:
- disaster recovery;
- service restoration;
- operational continuity;
- security resilience.
Backup copies are not intended for routine user access.
Where technically feasible, deleted data will age out of backup systems in accordance with Aarog's operational schedules.
12. LEGAL HOLD
If Aarog becomes aware of:
- pending litigation;
- regulatory investigations;
- law enforcement requests;
- court orders; or
- legal preservation obligations,
relevant information may be retained for longer than the standard retention period until the matter is resolved or the legal obligation ends.
13. DELETION OF DATA
Users may request deletion of:
- their account;
- specific Health Data;
- uploaded documents; or
- other Personal Data,
subject to identity verification and any applicable legal exceptions.
Deletion requests will be handled in accordance with Aarog's Account Deletion Policy.
14. ANONYMIZATION
Where appropriate and permitted by Applicable Law, Aarog may convert certain information into anonymized or aggregated form.
Once information has been anonymized so that it can no longer reasonably identify an individual, it may be used for legitimate purposes such as:
- platform improvement;
- security analysis;
- performance monitoring;
- statistical reporting.
Anonymized information is not intended to identify any individual.
15. SECURE DESTRUCTION
When data reaches the end of its retention period and is no longer required, Aarog aims to securely destroy or irreversibly delete it using methods appropriate to the storage medium and technical environment.
16. USER RESPONSIBILITIES
Users are encouraged to:
- download copies of important records before requesting deletion;
- maintain independent copies of critical medical documents where appropriate;
- review their uploaded information periodically for accuracy and relevance.
17. CHANGES TO THIS POLICY
Aarog may amend this Policy to reflect:
- changes in Applicable Law;
- technological developments;
- operational requirements;
- security enhancements; or
- new Services.
Material changes will be communicated where required.
18. CONTACT INFORMATION
Questions regarding this Policy may be directed to Aarog through the official support channels.
Grievance Officer
- Name: Arpan Gupta
- Email: support@aaroghealthrecords.com
- Registered Office: 206, Millenium Garden, Peer Muchalla, Zirakpur, Punjab
19. USER ACKNOWLEDGEMENT
By using Aarog, you acknowledge that:
- You have read and understood this Data Retention & Data Lifecycle Policy.
- You understand that certain information may be retained after account deletion where required by law or for legitimate purposes such as fraud prevention, dispute resolution, security, or disaster recovery.
- You understand that Aarog will make reasonable efforts to securely delete or anonymize data when it is no longer required.
- You understand that you should retain your own copies of important medical records before requesting deletion.
Questions about this policy? Contact us.