Privacy Policy

Last updated 7 October 2026. This policy is a functional draft — see the note at the end before relying on it for anything beyond understanding how the product is built today.

Who this covers

This policy covers nmanam.com and pro.nmanam.com: anyone who visits either site, and anyone who creates an account as a Clinician or Clinic Owner. nManam does not yet have individual client/patient accounts — this platform is for mental health professionals and the clinics and organisations around them, not the people they see in session.

What we collect

  • Account and contact details: name, email, phone number, the state and district you practise in, and your 18-or-over declaration at signup.
  • Credential and verification documents: your registration number, qualification documents, and (for a Clinic Owner) establishment registration documents — only what our Platform Admin team needs to verify you, reviewed by a human, never an algorithm.
  • Resume content, if you choose to upload one at signup to pre-fill your application — you can always skip this and type everything by hand instead.
  • Sign-in data: if you sign in with Google, we keep the email and name Google gives us and the account link. If Google also offers us your phone number, we use it once, in your browser session, to pre-fill a form field, and never write it to our database.
  • Account activity:login attempts and basic session data, kept for a bounded period for account security — detailed under “How long we keep things” below.
  • Whatever you publish yourself on your professional profile, in a discussion post, or anywhere else the product lets you write — that content is visible to whoever the feature says it is visible to, by design, not by accident.

What we deliberately do not collect:we never store a client or patient's identity inside a record of one professional referring work to another (GP-5). We have no clinical-record feature at all today — no session notes, no care history, nothing about a specific client's mental health. If we ever build one, it won't ship until a dedicated security design pass and a counsel review of the consent language are both done — not before.

Aadhaar, specifically

Where identity verification uses Aadhaar, we check it offline — a Platform Admin reads your Secure QR code — and we do not keep the 12-digit number, the XML, the QR payload, or an image of the card. We keep only the result: that it was verified, how, when, and by whom. If a verification partner (for example, during payment KYC) runs its own Aadhaar check, we receive only the outcome of that check, never the number itself. We do not accept an uploaded photo or PDF of an Aadhaar card, for the same reason — keeping it would mean keeping the number.

Who we share it with, and why

We share the minimum each of these needs to do its job, never our broader records about you:

  • Groq structures resume content into form fields when you choose to upload one — it receives the extracted text only, never the original file.
  • Razorpay is our payment partner for the features that involve money. We never hold your payment details or your payout ourselves — Razorpay pays a professional or clinic directly, through their own connected account, and we only ever see the outcome. This is not live for any real payment yet.
  • Googlehandles sign-in if you choose that option, and (not yet built) would help auto-fill a clinic's public listing from Google Places if the owner starts that flow themselves.
  • Our email providersends the account emails you'd expect — a welcome message, a password reset, a verification update. Promotional email is different: it only goes to you if you've opted in, and every one has a one-click unsubscribe.

Geminiis reserved for a possible future clinic auto-fill feature and a resume-extraction fallback — it is wired into our code but not yet called by anything live. We don't run any analytics or advertising tracking on either site today.

How we protect it

Every field and document we hold is classified by how sensitive it is, with handling that scales accordingly. Identity and credential documents sit in private storage behind links that expire, and every time one is opened, we log who opened it and when. Standing admin access to your account does not exist — anything beyond the normal review workflow needs an explicit, time-bounded, logged support session, and that session can never reach clinical data (we have none today, and the rule holds for if we ever do).

Right now, uploaded documents are held on our own application server while we build toward encrypted cloud object storage — we say so plainly rather than claiming infrastructure that isn't live yet.

How long we keep things

Most account data is kept for as long as your account is active. A few things have their own stated period: login-security records for six months, with daily summaries kept for twelve; financial records for whatever period tax law requires (exact period pending counsel — we won't guess at it); a signed agreement is kept even after you leave, because it is the other party's legal record too, not only yours.

Your rights

Under the DPDP Act, 2023 you can ask to see what we hold about you, correct it, or ask us to erase it. In practice: your profile page is self-service for access and correction, and you can export your own profile, event history, CPD portfolio, referral and supervision history, signed agreements, and financial records at any time. Ask for account deletion and we'll erase or anonymise your personal data, except where we're required to keep something — a financial record for the statutory period, or a verification trail if your account was the subject of a substantiated concern report, kept for our own legal defensibility. You can also raise a grievance directly — see the contact on our Trust & Compliance page.

If you're under 18, this platform isn't for you yet — we ask for a declaration at signup, and a parental-consent flow for anything involving a minor is designed but not built, since the feature it would gate (client booking) doesn't exist yet either.

If something goes wrong

If we confirm a personal-data breach, we'll tell you what happened, when, and what to do, without delay, through the contact details you've given us. We also report it to the Data Protection Board of India within 72 hours of becoming aware of it, as the DPDP Rules, 2025 require.

Where your data is hosted

Our servers are hosted in India. We don't send your data to a country the Indian government has restricted for this purpose — none has been named as of this writing.

Changes to this policy

We'll update this page as what we actually build changes, and change the date at the top when we do. We won't add a new third-party recipient of your data without updating this page first.

This is a functional draft, written to describe what nManam actually does today — it has not yet been reviewed by external counsel (the legal & compliance register's DPDP Act 2023 compliance-check gate is marked not started). Don't treat it as a final, counsel-approved policy until that review is complete. Questions about your data: see our Trust & Compliance page for the Grievance Officer contact.