Version 2.0.0
Elderkonnect Privacy Policy
Effective 11 Jun 2026
ELDERKONNECT
Trusted Care For The Ones Who Cared For You
A brand of Alumnik India Private Limited
INFO POLICY
Digital Personal Data Protection Act, 2023 — Compliant
Version 2.0 | Effective Date: 26 May 2026 | Jurisdiction: India
Supersedes: Info Policy v1.0
This Info Policy describes how Alumnik India Private Limited, operating the ElderKonnect platform ("ElderKonnect", "we", "us", or "our"), collects, uses, stores, shares, and protects personal data. It is prepared in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, the IT (Amendment) Act, 2008, and all applicable rules. By using the Platform, you consent to the practices described herein.
IMPORTANT — ELDER DATA: This platform handles data of elderly individuals across 23 provider categories including health, diagnostic, pharmacy, medical equipment, and monitoring services. Such data is classified as Sensitive Personal Data. Please read Sections 5 and 6 carefully.
1. Definitions
The following terms apply throughout this Policy:
"DPDP Act" — the Digital Personal Data Protection Act, 2023 and all rules, regulations, and guidelines issued thereunder.
"Data Fiduciary" — Alumnik India Private Limited, operating the ElderKonnect brand, being the entity that determines the purpose and means of processing Personal Data.
"Data Principal" — the individual to whom Personal Data relates — including Family Users, Providers (all 23 categories), and Elders.
"Data Processor" — any entity that processes Personal Data on behalf of the Data Fiduciary under a written contract.
"Personal Data" — data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDP Act.
"Sensitive Personal Data (SPD)" — Personal Data relating to health, medical condition, physical or mental condition, care needs, diagnostic information, medications, monitoring data, or any data revealing health status.
"Consent" — a free, specific, informed, unconditional, and unambiguous indication of agreement to data processing, as required by Section 6 of the DPDP Act.
"Platform" — the ElderKonnect website, mobile application, Requirements Board, Provider Directory, Family Dashboard, and Education Portal operated by Alumnik India Private Limited.
"Family User" — an individual who registers to find, book, or manage elder care services for an Elder.
"Elder" — the elderly individual for whom care is being sought or coordinated.
"Provider" — any individual or organisation registered across any of the 23 Provider Categories on the Platform.
"Care Companion File" — a physical file of health and medical documents maintained by the Family User or Elder — not uploaded to or stored on the Platform.
2. Identity and Contact Details of the Data Fiduciary
| Detail | Information |
|---|---|
| Legal Entity Name | Alumnik India Private Limited |
| Platform Brand | ElderKonnect |
| Role under DPDP Act | Data Fiduciary |
| Registered Office | Gopal Bhavan, Baguipara, Raghunathpur, North 24 Parganas, West Bengal, India (PIN: 700059) |
| Info Contact | info@elderkonnect.com |
| Grievance Officer | Abhijit Adhya — info@elderkonnect.com |
| Data Protection Officer | Abhijit Adhya — info@elderkonnect.com |
| Grievance Response SLA | Acknowledgement within 72 hours; Resolution within 15 business days |
3. Scope and Application
This Policy applies to:
-
All Family Users registered on any plan (Basic, Care+, Care Pro);
-
All Providers registered across any of the 23+ Provider Categories (Individual, Company, and Education Providers);
-
Elders whose Personal Data or Sensitive Personal Data is disclosed on the Platform by Family Users;
-
Visitors who browse the Platform without registering;
-
Anyone who contacts Alumnik India Private Limited regarding the ElderKonnect brand.
This Policy does not govern the independent data practices of Providers who collect data from Family Users or Elders outside the Platform.
4. Categories of Personal Data Collected
4.1 Data Collected from Family Users
| Category | Data Elements | How Collected |
|---|---|---|
| Identity | Full name, date of birth, gender, nationality | Registration form |
| Contact | Email, mobile/WhatsApp number, country of residence ( status if applicable) | Registration form |
| Family Plan | Subscribed plan (Basic / Care+ / Care Pro), billing currency (INR/USD/GBP/AED) | Plan selection |
| Location | City/district of Elder's residence, PIN code | Care posting form |
| Care requirements | Care category, preferred schedule, budget range, duration, care complexity | Requirements Board |
| Payment metadata | Payment method type, transaction IDs, billing address (not card numbers) | Payment gateway |
| Usage data | Pages visited, search queries, time on Platform, device type, IP address | Automatic / cookies |
| Communications | In-Platform messages, support queries, feedback, Care AI WhatsApp summary delivery logs | In-app / Twilio/MSG91 |
4.2 Data Collected from Providers — by Registration Type
Individual Providers (Categories 1–6: Nurses, Caregivers, Physiotherapists, Dementia Specialists, Home Visit Doctors, Therapists)
| Category | Data Elements | How Collected |
|---|---|---|
| Identity | Full name, date of birth, gender, photograph | Enrolment form |
| Professional credentials | RNM registration, nursing/medical/therapy licence, certificate numbers | Document upload |
| Contact | Mobile, WhatsApp number, email | Enrolment form |
| Service details | Care categories, specialisations, availability, pricing, geography | Profile/listing form |
| Background check | Police verification certificate, background check result (where submitted) | Document upload |
| Bank / payout | Bank account number, IFSC, account holder name | Payout setup |
| Usage data | Bid activity, listing views, Platform engagement, IP address | Automatic |
Company Providers (Categories 7–21: Agencies, Hospitals, Diagnostic Centres, Allied Services, etc.)
| Category | Data Elements | How Collected |
|---|---|---|
| Entity identity | Company name, CIN, GST, PAN, registered address, entity type, category (e.g., diagnostic centre, hospital, pharmacy, assisted living) | Enrolment form |
| Regulatory licences | Category-specific registrations: NABL accreditation (diagnostics), AYUSH/MCI licence (hospitals), drug licence (pharmacy), AERB approval (medical equipment), state-level facility registration (assisted living) | Document upload |
| Staff accounts | Named staff users on Featured tier — name, email, role designation | Enrolment / admin panel |
| Service packages | Active service packages — descriptions, pricing, geography | Profile/listing form |
| Bank / payout | Bank account number, IFSC, account holder name | Payout setup |
| Usage data | Bid activity, listing views, analytics (Featured tier), IP address | Automatic |
Education Providers (Categories 22–23: Nursing Colleges, Caregiver Training Institutes)
| Category | Data Elements | How Collected |
|---|---|---|
| Institution identity | Institution name, registration/accreditation number, affiliation body, address | Education Portal enrolment |
| Programme details | Courses offered, duration, eligibility, intake, fees, placement record | Education Portal form |
| Contact | Designated contact name, email, phone | Enrolment form |
4.3 Elder Data — Special Considerations
Elder data is the most sensitive category on the Platform. It spans 23+ provider categories — from personal care and nursing to diagnostic reports, pharmacy records, remote monitoring streams, and medical equipment needs. Family Users must have lawful authority to disclose all Elder data. ElderKonnect follows strict data minimisation across all categories.
| Category | Data Elements that may be collected | How Collected |
|---|---|---|
| Identity | First name, last name and age | Care posting form or App/Website |
| Location | City/district and PIN code — specific home address NOT collected on Platform | Care posting form or App/Website |
| Care needs metadata | Type of care required across any of the 23+ provider categories (e.g., dementia care, physiotherapy, diagnostic home visit, medical equipment rental, emergency alert subscription) — descriptive, not clinical records | Care posting form or App/Website |
| Monitoring data (metadata only) | Where Remote Monitoring or Emergency Alert Providers are engaged: device type, service name, subscription status — NOT the vital readings or alert logs themselves | Provider engagement record |
| Health documents (NOT stored) | Medical records, diagnostic reports, prescriptions, discharge summaries — MAINTAINED PHYSICALLY in the Care Companion File; NOT uploaded to or stored on the Platform | Not collected digitally |
5. Legal Basis for Processing Under the DPDP Act
| Lawful Basis | DPDP Act Reference | Data Processed Under This Basis |
|---|---|---|
| Consent | Section 6 — free, specific, informed, unconditional, unambiguous | All personal data at registration; Elder SPD; Care WhatsApp summary delivery; marketing communications |
| Contract performance | Section 7(a) | Account creation, Requirements Board, bid processing, payment, Provider verification across all 23 categories, Care+ / Pro plan delivery |
| Legal obligation | Section 7(b) | GST/TCS records, tax compliance, court orders, KYC obligations, regulatory compliance |
| Medical emergency | Section 7(d) | Elder health data disclosed in genuine life-threatening emergency — particularly relevant for Emergency Alert (Category 17) and Remote Monitoring (Category 16) Provider categories |
| Safety | Section 7(e) | Safeguarding Elders from fraudulent Providers; platform integrity; fraud prevention |
5.1 How Consent Is Obtained
-
Affirmative opt-in checkboxes at registration — not pre-ticked;
-
Granular consent notices at each material data collection event (e.g., first Elder data posting, Care WhatsApp summary activation);
-
Separate consent for marketing, analytics, and optional communications;
-
Standalone Elder Data Consent Form for disclosure of Elder Sensitive Personal Data.
5.2 Consent for Elder Sensitive Personal Data
Where a Family User discloses Elder SPD — regardless of which of the 23 Provider Categories the care requirement is directed to — the Family User warrants they have the Elder's knowledge and, where the Elder has legal capacity, explicit consent; or lawful authority by POA, guardianship, or other legal authorisation. The Company relies on this representation.
6. Purposes of Processing
| Purpose | Data Categories Used | Lawful Basis |
|---|---|---|
| Registration and account management | Identity, contact, credentials | Consent / Contract |
| Matching Family Users with Providers across 23 categories | Care requirements, location, Elder care needs metadata, provider category | Contract |
| Requirements Board operation | Family User postings, Provider bids | Contract |
| Provider verification (all 23 categories, category-specific docs) | Credentials, licences, background check data, accreditation docs | Contract / Legal |
| Payment processing and invoicing | Payment metadata, bank details, transaction records | Contract / Legal |
| Care+ WhatsApp daily summary delivery | Care update logs from engaged Providers; WhatsApp number; plan subscription status | Contract / Consent |
| Care Pro emergency coordination | Emergency contact details; Elder location (city level); engaged Provider details | Contract / Emergency |
| Education Portal operations | Institution identity, programme details, contact data | Contract |
| Platform safety and fraud prevention | Usage data, IP addresses, communication logs | Legitimate use — safety |
| Customer support and grievance resolution | Communications, account data, transaction data | Contract / Legal |
| Legal and regulatory compliance (GST, TCS, KYC) | Identity, payment records, communications | Legal obligation |
| Platform analytics and improvement (anonymised only) | Anonymised / aggregated usage data | Consent |
| Marketing and service communications (opt-in only) | Email, phone number | Consent (separate) |
ElderKonnect does not process Elder Sensitive Personal Data for marketing, analytics, profiling, or any purpose other than facilitating care coordination. We do not sell, rent, or licence any Personal Data to third parties for commercial purposes.
7. Sharing of Personal Data
7.1 Sharing Within the Platform
As a marketplace, certain data is shared between Family Users and Providers to enable the core service:
-
Family User care requirements (excluding the Elder's full name, specific address, or clinical records) are visible to relevant verified Providers on the Requirements Board;
-
Provider profiles, credentials, service listings, listing tier, and ratings are visible to Family Users in the Provider Directory;
-
Contact details are shared between matched parties only after a booking or connection is confirmed through the Platform;
-
For Care+ and Care Pro subscribers, care update summaries compiled from engaged Provider activity logs are shared with the Family User via Email/Message/WhatsApp.
7.2 Sharing with Third-Party Data Processors
| Processor | Purpose | Data Shared |
|---|---|---|
| Supabase (Mumbai — AWS ap-south-1) | Backend database, authentication, real-time data — hosted in India | All Platform data at rest and in transit |
| Third Party | India payment processing and Provider payouts | Payment metadata, bank details |
| Third Party | WhatsApp OTP authentication, SMS alerts, Care AI summary delivery | Phone/WhatsApp number, summary content (anonymised care update) |
| Third Party | Transactional email (bookings, payments, verification, alerts) | Email address, transactional content |
| Vercel | Frontend application hosting and delivery | Usage logs, IP addresses (anonymised) |
| Background verification partners | Service Provider background and credential verification | Identity documents, credentials |
| Analytics tools (anonymised only) | Platform performance analytics — no personal data | Anonymised / aggregated usage data only |
| Legal / regulatory authorities | Compliance with court orders, statutory obligations | As required by law |
7.3 Cross-Border Data Transfers
Primary database infrastructure is in India (Supabase, Mumbai — AWS ap-south-1). Where data is processed outside India — specifically through a third party for payment processing and Vercel's CDN edge network — the Company ensures compliance with Section 16 of the DPDP Act and applicable country allow lists once notified by MeitY. Appropriate contractual safeguards are maintained with all overseas processors.
7.4 What We Never Share
Alumnik India Private Limited / ElderKonnect NEVER: (a) sells Personal Data; (b) shares Elder clinical records, diagnostic reports, or prescriptions (these are never on the Platform); (c) uses Personal Data for targeted advertising; (d) discloses data to foreign governments except as required by Indian law; (e) shares Care WhatsApp summary content with any party other than the subscribing Family User.
8. Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Account registration data | Account active + 3 years post-closure | Legal obligation, dispute resolution |
| Payment and transaction records | 8 years | GST Act; Income Tax Act |
| Individual Provider credential documents | Active listing + 5 years | Regulatory compliance, indemnity |
| Company Provider entity documents | Active listing + 5 years | Regulatory compliance |
| Care requirement postings | 2 years from posting date | Platform operations, dispute resolution |
| Care WhatsApp summary logs | 12 months (rolling) | Plan delivery, dispute resolution |
| In-platform communications | 3 years | Dispute resolution, safety |
| Grievance and support records | 5 years | Consumer Protection Act 2019; IT Rules |
| Usage and analytics data | 13 months (rolling) | Analytics; security |
| Consent audit logs | 3 years from last consent event | DPDP Act compliance demonstration |
| Elder care needs metadata (Platform) | 2 years from posting or care completion | Minimum necessary retention |
9. Rights of Data Principals Under the DPDP Act
| Right | What It Means | How to Exercise |
|---|---|---|
| Right to Access (S.11) | Request a summary of Personal Data held and how it is processed | Email info@elderkonnect.com — response within 15 business days |
| Right to Correction (S.12) | Request correction of inaccurate or incomplete data | In-app profile update or email request |
| Right to Erasure (S.12) | Request deletion where data is no longer necessary, subject to legal retention obligations | Account deletion request — processed within 30 days |
| Right to Withdraw Consent (S.6(4)) | Withdraw consent at any time; does not affect prior lawful processing | Platform consent settings or email request |
| Right to Grievance Redressal (S.13) | Raise a complaint about data practices and receive a response within prescribed timelines | grievance@elderkonnect.com or in-app grievance module |
| Right to Nominate (S.14) | Nominate another individual to exercise your rights in case of death or incapacity | Nomination form available on request |
| Right to approach the Board | Approach the Data Protection Board of India if your complaint is unresolved | Via the Board's prescribed process |
10. Data Security
Technical Measures
-
TLS 1.2+ encryption for all data in transit;
-
AES-256 encryption for sensitive data at rest on Supabase (Mumbai);
-
Row-Level Security (RLS) on Supabase ensuring strict data isolation between User accounts and across all 23 Provider categories;
-
Multi-factor authentication via WhatsApp OTP (Third party) for all registered Users;
-
Access controls and role-based permissions — Company Provider Featured-tier staff access is scoped per-user;
-
All infrastructure within India (Supabase ap-south-1) for data localisation compliance;
-
Automated backup and disaster recovery with defined RPO and RTO.
Organisational Measures
-
Internal data protection policy binding all employees and contractors of Alumnik India Private Limited;
-
Written Data Processing Agreements (DPAs) with all processors listed in Section 7.2;
-
Regular staff training on DPDP Act obligations;
-
Incident response plan with escalation and notification procedures.
10.1 Data Breach Notification
In the event of a Personal Data breach likely to cause harm to Data Principals, the Company will: (a) notify the Data Protection Board of India within prescribed timeframes; (b) notify affected Data Principals as soon as practicable; (c) maintain a breach log and conduct root cause analysis.
11. Cookies and Tracking Technologies
ElderKonnect uses a minimal-cookie architecture. Full details are set out in the Cookie and Consent Policy. In summary: strictly necessary cookies (session, CSRF, auth state, consent preference, locale); functional cookies (UI preferences, last search filter, notification preferences); first-party anonymised analytics cookies (no third-party analytics, no advertising cookies, no social tracking pixels). All analytics are self-hosted and anonymised.
12. Minors
The Platform is not directed at individuals under 18. ElderKonnect does not knowingly collect Personal Data from minors. If such collection is discovered, it will be deleted promptly. Contact: info@elderkonnect.com.
13. Grievance Redressal
Grievance Officer: Abhijit Adhya, Alumnik India Private Limited (ElderKonnect) Email: info@elderkonnect.com Acknowledgement: Within 72 hours | Resolution: Within 15 business days
If unsatisfied with the Grievance Officer's response, you may approach the Data Protection Board of India through its prescribed process.
14. Updates to This Policy
Material changes will be communicated to registered Users via Resend email and in-app notification at least 14 days before taking effect. The version number and effective date will be updated. Where a change requires fresh DPDP Act consent, an affirmative opt-in will be sought before the changed processing begins.
15. Contact Us
Alumnik India Private Limited (ElderKonnect) Gopal Bhavan, Baguipara, Raghunathpur, North 24 Parganas, West Bengal, India (PIN: 700059) Info queries: info@elderkonnect.com Grievance Officer: info@elderkonnect.com Website: www.elderkonnect.com
Draft for legal review only. Must be reviewed by qualified counsel familiar with the DPDP Act, 2023 before publication. Entity placeholders must be completed upon incorporation.