Trust center

Seven website privacy controls

Aroviah maps cookie consent, data flows, privacy notices, individual rights, breach response, children's data, and security safeguards to specific product and governance controls. This is a transparency statement, not a certification or legal opinion.

Reviewed: 18 September 2026

Control 1 of 7

Cookie and analytics consent

Non-essential analytics stay off until a visitor accepts them. Visitors can reject analytics and reopen Cookie settings from the footer.

Control 2 of 7

Data-flow and processor inventory

Collection points, storage, recipients, international transfers, retention triggers, and external processors are mapped and reviewed when the service changes.

Control 3 of 7

Current plain-language privacy notice

The notice itemises the information collected, its purposes, recipients, retention approach, safeguards, rights, and contact route in concise language.

Control 4 of 7

Access, correction, erasure, and withdrawal

People can submit a trackable privacy request, withdraw consent, request erasure or correction, and download an authenticated account-data export.

Control 5 of 7

Personal-data breach response

A documented escalation and incident register support containment, affected-person notices, Board notification, evidence preservation, and corrective action.

Control 6 of 7

Children and verified guardians

Self-service accounts are restricted to adults. Child cases must remain blocked until a lawful parent or guardian is verified using an approved, proportionate method.

Control 7 of 7

Reasonable security safeguards

Layered controls include role-based access, row-level database policies, staff MFA, audit logging, rate limits, private caching rules, and restricted security headers.

DPDP readiness

India's DPDP Rules, 2025 have staggered commencement dates. Aroviah tracks repository implementation separately from the contracts, approvals, exercises, deployment records, and independent testing needed to demonstrate that a control operates in production.

Whether Curabridge LLP is later notified as a Significant Data Fiduciary is a government determination. The additional SDF obligations are tracked as conditional requirements and are not represented here as currently applicable.

EU AI Act scope

The present website uses deterministic filters and staff-led matching; it does not provide an AI chatbot, diagnose patients, or make solely automated clinical or eligibility decisions. Any future AI system must be entered in the internal inventory and classified before use, including where its output affects people in the EU.

Read the AI transparency notice

Questions, rights, or grievances

Contact the privacy contact at support@aroviah.com or submit a trackable request. Do not send medical records or identity documents by ordinary email.

Submit a privacy request