1.Introduction
This Privacy Policy describes how Onsurity Technologies Pvt. Ltd. ("Onsurity", "we", "us", or "our") collects, uses, and shares information about you when you use our mobile application ("Onsurity App") available on iOS (Apple App Store) and Android (Google Play Store).
By downloading or using the Onsurity App, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described here.
This policy covers the Onsurity mobile app only. It does not govern the Onsurity website (onsurity.com) or any third-party services linked from within the app.
2.Information We Collect
Account Information
- Name, email address, phone number, date of birth
- Employee ID (as assigned by your employer)
- KYC details (Aadhaar, PAN) where required for insurance purposes
Insurance Policy Data
- Policy numbers and coverage details
- Sum insured and premium information
- Dependant details (name, relationship, date of birth)
- Network hospital preferences
Health and Claims Data
- Hospitalisation details and claim amounts
- Treatment information and diagnostic reports
- Pre-authorisation requests and discharge summaries
Health and claims data is Sensitive Personal Data. We collect it only for claims processing and policy administration, and we apply heightened security controls to it at all times.
Device Information
- Device type, operating system version, app version
- Device identifier (for push notifications and security)
- Crash reports and diagnostic data (to fix bugs and improve stability)
Usage Data
- Features used, screens visited, interaction patterns
- This data is anonymised and aggregated — it is never linked back to you individually
Location Data
- City and state (to surface nearby network hospitals and wellness partners)
- Precise GPS location is not collected unless you explicitly grant permission — and only while the app is in the foreground for hospital-search features
3.How We Use Your Information
Insurance and Benefits Services
- Policy issuance, renewal, and endorsement processing
- Claims submission, tracking, and settlement
- Cashless hospitalisation at network hospitals
- Digital health card (e-card) generation and storage
Communication
- Policy updates, renewal reminders, and premium due alerts
- Claim status notifications (approval, query, settlement)
- Appointment reminders for teleconsultation
- Benefit expiry alerts for wellness programmes
App Functionality
- Teleconsultation booking (video, audio, or chat with doctors)
- Wellness benefit access (Cult Fit, Fitpass, Amaha, Clove Dental, Sabka Dentist)
- Network hospital search
- HR dashboard (for employer POC users)
Security and Fraud Prevention
- Detecting and preventing fraudulent claims or account access
- Session management and authentication
- Monitoring for unusual activity patterns
Legal Compliance
- IRDAI regulatory reporting and record-keeping obligations
- Digital Personal Data Protection Act 2023 (DPDP Act) compliance
- KYC and anti-money laundering requirements
Analytics
- Anonymised, aggregated usage analytics to improve the app experience
- Crash and performance analytics to maintain app stability
4.Information Sharing
We share your information only where necessary to deliver our services, meet legal obligations, or with your explicit consent.
Insurance Companies
We share policyholder data with IRDAI-licensed insurance companies that underwrite the group health plans on our platform. This is required for policy issuance and servicing — without this, insurance operations cannot function.
Third Party Administrators (TPAs)
For cashless claim processing, we share relevant policy and claim data with authorised TPAs who manage hospital coordination and claim settlement on behalf of the insurer.
Wellness Partners
We share only the minimum data needed to activate your benefit (name, membership status, phone number) with wellness partners — Cult Fit, Fitpass, Amaha, Clove Dental, and Sabka Dentist — and only with your explicit consent at the time of benefit redemption.
Regulatory Authorities
We share data with IRDAI, the Income Tax Department, and other regulatory authorities as required by law.
Service Providers
We use cloud hosting (AWS, Mumbai region), push notification services, and analytics providers under data processing agreements that prohibit them from using your data for their own purposes.
We do not sell your personal data to any third party — ever.
5.Data Retention
We retain your data for as long as your policy is active and for 7 years thereafter, as required by IRDAI regulations and Indian financial record-keeping laws (Income Tax Act, 1961, and GST law).
- Active account data: Retained for the duration of your active policy, plus 12 months after policy expiry or account closure.
- Claims and health data: 7 years from the date of last claim settlement (IRDAI requirement).
- Financial records: 7 years from the end of the relevant financial year.
- Device and usage logs: 12–24 months in identifiable form, then aggregated or deleted.
- Deleted account: Personal identifiers removed or pseudonymised within 30 days, subject to the above retention obligations.
6.Your Rights (DPDP Act 2023)
Under India's Digital Personal Data Protection Act 2023, you have the following rights:
- Right to access: Request a copy of the personal data we hold about you.
- Right to correct: Request correction of inaccurate or incomplete data. Most profile data can be updated directly in the app.
- Right to erasure: Request deletion of your personal data where legally permitted. We will action this within 30 days, subject to retention obligations.
- Right to withdraw consent: Withdraw consent for marketing communications or non-essential data collection at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Right to nominate: Nominate another person to exercise data rights on your behalf in the event of your death or incapacity, as provided under the DPDP Act.
To exercise any of these rights, contact us at privacy@onsurity.com with the subject line "Data Rights Request — Mobile App". We will respond within 30 days.
7.App Permissions We Request
The Onsurity App requests the following device permissions. All permissions are optional unless specifically noted.
Camera
For scanning QR codes at hospitals (cashless check-in) and uploading photos of claim documents. The app never captures images in the background.
Storage / Files
For saving your digital health card (e-card) and downloading policy documents to your device.
Notifications
For claim status updates, renewal reminders, benefit expiry alerts, and appointment confirmations. You can disable these in device settings at any time.
Biometrics (Fingerprint / Face ID)
Optional. Used only for app login security if you choose to enable it. Biometric data never leaves your device — authentication is processed by the OS.
Location
City/state only (coarse location), used to show nearby network hospitals and wellness partners. Precise GPS is only requested if you use the hospital map feature, and only while the app is in the foreground.
8.Children's Privacy
The Onsurity App is not intended for use by individuals under 18 years of age. We do not knowingly collect personal information from children under 18.
If you are a parent or guardian and believe that a child under 18 has provided personal information to us, please contact us at privacy@onsurity.com and we will delete that information promptly.
Note: Dependants under 18 (such as children enrolled as beneficiaries under a group health policy) may have their data processed as part of a policy administered by an adult. In such cases, the adult policyholder is responsible for authorising that processing.
9.Security
We use industry-standard security measures to protect your personal data:
- Encryption in transit: All data between the app and our servers is encrypted using TLS 1.3.
- Encryption at rest: Sensitive data (health records, payment information, identity documents) is encrypted at rest using AES-256.
- Infrastructure: Hosted on AWS (Mumbai region) for India data residency compliance with IRDAI requirements.
- Access controls: Strict role-based access controls (RBAC) limit staff access to personal data on a need-to-know basis.
- App security: Certificate pinning, jailbreak/root detection, and secure local storage (iOS Keychain / Android Keystore) for sensitive on-device data.
- Incident response: Documented breach response plan. In the event of a breach affecting your rights, we will notify the relevant regulator and affected individuals within the timeframe required by law.
To report a suspected security vulnerability, email security@onsurity.com.
10.Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification and email at least 15 days before the changes take effect.
The "Last updated" date at the top of this page indicates when the policy was most recently revised. We encourage you to review this policy periodically.
Your continued use of the Onsurity App after a revised policy takes effect constitutes acceptance of the updated terms.
11.Contact
Onsurity Technologies Pvt. Ltd.
WeWork, 24th Main Rd, Sector 2, HSR Layout
Bengaluru, Karnataka 560102
Privacy enquiries: privacy@onsurity.com
Grievance Officer (DPDP Act): care@onsurity.com
Response time: We aim to acknowledge queries within 2 business days and resolve them within 30 days.
Effective date: 01-Jan-2026. Last updated: 01-Jun-2026. Onsurity Technologies Pvt. Ltd. is registered with the IRDAI as a licensed insurance intermediary. This policy applies to the Onsurity mobile app only. For the website privacy policy, see /v2/privacy-policy.