Legal

Privacy Policy

This policy explains what MedZove collects when you use medzove.com or work with us, why we hold it, and what we will never do with it. It is written to be read, not to be survived.

Last updated
27 August 2026
Applies to
medzove.com and our client work
Written under
DPDP Act 2023 and the IT Act 2000 rules
Part A

What we collect and why

1. Who does this policy cover?

MedZove is a healthcare digital marketing agency based in Jalandhar, Punjab, India. This policy covers three groups of people: visitors to medzove.com, doctors and clinics who enquire about our services, and clients who have engaged us. Where we handle information on behalf of a client clinic, we act on that clinic's instructions and section 5 explains what that means.

2. What information do we collect?

Only what we need to answer you or to do the work. We do not buy contact lists and we do not scrape them.

  • You give us this. Your name, clinic name, speciality, city, email address and phone or WhatsApp number, plus whatever you write in an enquiry, a website audit request or a WhatsApp message.
  • Your browser sends this. IP address, browser and device type, pages viewed, time on page and the site you arrived from. This is standard server and analytics data, collected by our hosting provider and by the analytics tools named in section 6.
  • Client work generates this. Once you are a client, we hold the access credentials, account details and billing information needed to run your website, your Google Business Profile and your campaigns.

We do not ask you for any patient's medical records, and we do not want them.

3. Why do we use it?

Every piece of data we hold maps to a purpose. If a purpose ends, the reason to keep the data ends with it.

What we holdWhy we hold it
Your enquiry detailsTo reply to you, understand your practice and send a proposal
Billing and GST detailsTo raise invoices and keep the accounting records Indian tax law requires
Account credentialsTo run the website, profile and campaigns you have engaged us for
Website analyticsTo see which pages are read and to improve them
Recordings for your AI cloneTo produce the videos you have approved, and nothing else

We do not sell your data, we do not rent it, and we do not pass it to anyone for their own marketing.

4. Do we use cookies?

The site uses cookies that are necessary for it to work, such as caching and security, and analytics cookies that tell us how pages perform. You can block or delete cookies in your browser settings at any time. Blocking the necessary ones may break parts of the site.

Part B

5. How do we handle patient data?

This is the section that matters most, because our clients are doctors. A patient never becomes our customer, and their data is never our asset.

Never
We do not ask for, collect or store patient medical records, reports, scans or prescriptions.
Never
We do not publish patient photographs, before and after images or testimonials about a clinical outcome.
Never
We do not build advertising audiences out of a clinic's patient list, and we do not sell or share patient information with anyone.
Always
Where a website form, a Google Business Profile message or a WhatsApp enquiry brings a patient's details to a clinic, that data belongs to the clinic. We handle it only on the clinic's instructions and only to pass it on.
Always
Enquiry forms we build ask for the minimum a clinic needs to call someone back, because in a speciality like urology or fertility an oversized form is itself a privacy failure.

The wider list of what we refuse to do sits on what we do not do.

Part C

Sharing, keeping and protecting

6. Who do we share information with?

Only the service providers we need to do the work, and only the part of your information that each one needs. We name them rather than hiding behind the phrase trusted partners.

  • Hostinger, which hosts medzove.com and the client websites we build.
  • Google, for Google Business Profile, Google Search Console, Google Analytics and Google Ads where a client has engaged us for campaigns.
  • Meta, for Facebook and Instagram campaigns where a client has engaged us for them.
  • WhatsApp, which carries the messages you send us on our published business number.
  • Our bank and accounting records, for payments, invoicing and statutory filings.

We will also disclose information if a law, a court or a government authority validly requires it. Some of these providers process data outside India, which is how the global internet works, and we rely on their own contractual and security commitments when they do.

7. How long do we keep it?

An enquiry that goes nowhere is kept only as long as it is useful to follow up, and then deleted. Client records, invoices and tax documents are kept for as long as Indian accounting and tax law requires us to keep them. Access credentials are removed when an engagement ends and the handover in our terms is complete.

8. How do we protect it?

Every site we run uses SSL. Access to client accounts is limited to the people doing the work, credentials are not shared over open channels, and websites we manage are backed up and updated as part of the maintenance package. We follow reasonable security practices in line with the Information Technology Act, 2000 and the rules made under it. No system is perfectly secure and we will not pretend otherwise, so if a breach affects your data we will tell you and act on it.

Part D

Your rights and how to reach us

9. What rights do you have?

We handle personal data in line with the Digital Personal Data Protection Act, 2023. You can ask us to do any of the following, and we will not charge you for it.

  • See what we hold about you and what we have done with it.
  • Correct or complete it if something is wrong or out of date.
  • Erase it, unless a law requires us to keep it, such as tax records.
  • Withdraw consent you gave earlier, which stops the use that consent covered.
  • Raise a grievance with us using the contact in section 13, and escalate it if our answer does not satisfy you.

10. Do we deal with children?

No. Our services are sold to doctors and clinics, and this website is not intended for anyone under 18. We do not knowingly collect a child's personal data. If you believe we have, write to us and we will delete it.

11. What about links to other websites?

Our pages link to primary sources, government sites and platform documentation so you can check what we claim. Once you follow a link, that website's own privacy policy applies, not ours.

12. Will this policy change?

It will, as our services and the law both develop. The date at the top always shows the current version. If a change materially affects how we handle your data, we will tell existing clients directly rather than quietly editing this page.

13. How do you contact us?

Write to us about anything in this policy, including a request to see, correct or delete your data, or a grievance about how we have handled it. We answer every message ourselves.

Based in
Jalandhar, Punjab, India