Achievements: 8182 Kidney Transplantation; 786 Liver Transplantation; 691 Robotic Kidney Transplantation; 493 Swap Transplants

Photo Gallery

  • 6 - State gets 3 Awards at NOTTO Best SOTTO, Best Hospital and Best Coordinator, New Delhi-2019
  • 8 - IKDRC-ITS gets best ROTTO Award of Hospitals for Organ Donation day - 2021
  • 4 - Best Speciality Hospital in Urology - 2016
  • 9 - Appreciation Certificate of the PMJAY - 2022
  • 2 - Best Speciality Hospital in Nephrology - 2013
  • 3 - Padmashree Dr H L Trivedi - 2015
  • 7- Certificate of Appreciation at Civil Hospital -2020
  • 12 - Best Government Hospital in Organ Transplantation award - 2025
  • 5 - FICCI Healthcare Award For Service Excellence -2019
  • 10 - Felicitation of Team Working for Organ Procurement - 2022

Privacy Policy

Smt. G.R. Doshi and Smt. K.M. Mehta Institute of Kidney Diseases and Research Centre, Dr. H.L. Trivedi Institute of Transplantation Sciences (IKDRC-ITS)

Ahmedabad, Gujarat, India

1. Introduction

The Smt. G.R. Doshi and Smt. K.M. Mehta Institute of Kidney Diseases and Research Centre, Dr. H.L. Trivedi Institute of Transplantation Sciences (IKDRC-ITS) is committed to protecting the privacy and security of personal and sensitive information of patients, users, employees, students, healthcare professionals, and other individuals who use IKDRC's websites, mobile applications, portals, and digital services.

This Privacy Policy explains how IKDRC-ITS collects, accesses, uses, stores, shares, protects, retains, and deletes personal and sensitive information through its digital services.

This Privacy Policy applies to the IKDRC-ITS mobile application(s) and associated online services operated or authorized by the Institute.

By accessing or using an IKDRC-ITS application or digital service, you acknowledge that you have read and understood this Privacy Policy.

Where a particular service requires additional consent, terms, notices, or privacy disclosures, those requirements shall apply in addition to this Privacy Policy.

2. Information We Collect

IKDRC-ITS collects and processes only such information as is reasonably necessary for providing healthcare, administrative, academic, research, authentication, communication, and other authorized institutional services.

Depending upon the particular application and services used, the information collected may include the following.

2.1 Personal Information

This may include:

  • Name.
  • Date of birth or age.
  • Gender, where required for the relevant service.
  • Mobile number.
  • Telephone number.
  • Email address.
  • Residential or correspondence address.
  • Identification or registration details.
  • Patient or beneficiary identification information.
  • Employment, academic, or professional information.
  • Information submitted through applications, registrations, feedback, complaints, or other forms.

2.2 Healthcare and Medical Information

Where applicable to the services provided through the application, IKDRC may collect or access health-related information, including:

  • Patient registration information.
  • Appointment information.
  • Medical history.
  • Diagnosis and clinical information.
  • Treatment and procedure information.
  • Laboratory and diagnostic information.
  • Prescriptions and medication information.
  • Medical reports and records.
  • Information relating to kidney disease, transplantation, dialysis, or other healthcare services.
  • Other information necessary for providing or administering healthcare services.

Health and medical information is considered sensitive information and is handled with appropriate safeguards.

2.3 Authentication and Account Information

Where the application provides authenticated access, IKDRC may collect:

  • Username or user ID.
  • Mobile number or email used for authentication.
  • Authentication tokens or session information.
  • Password-related information, where applicable.
  • One-time passwords (OTP), where applicable.
  • Account and access-control information.

IKDRC does not intentionally collect passwords in plain text.

2.4 Device and Technical Information

When the application is used, certain technical information may be automatically collected or generated, including:

  • IP address.
  • Device type and model.
  • Operating system and version.
  • Application version.
  • Device identifiers or installation identifiers, where technically necessary.
  • Network information.
  • Date and time of access.
  • Crash reports and diagnostic information.
  • Security and audit logs.

This information may be used to maintain application security, troubleshoot technical problems, prevent misuse, and improve application performance.

2.5 Camera, Microphone, Files and Other Device Permissions

Depending on the functionality of a particular IKDRC application, the application may request access to device features such as:

  • Camera.
  • Microphone.
  • Photos or files.
  • Notifications.
  • Location.
  • Bluetooth or other device connectivity features.
  • Other Android permissions necessary for specific application functionality.

Such permissions will be requested only where required for a legitimate feature of the application.

IKDRC does not use device permissions for unrelated purposes.

2.6 Aadhaar and Face Authentication

Where an IKDRC-ITS application integrates with an authorized Aadhaar authentication or Face Authentication service, the application may facilitate authentication through the relevant authorized service provider.

Aadhaar-related information and authentication/face-related information shall be processed only for the authorized purpose for which the service is provided and in accordance with applicable laws, regulations, UIDAI requirements, contractual requirements, and security controls.

IKDRC does not use Aadhaar or authentication information for advertising or unrelated commercial purposes.

3. How We Collect Information

Information may be collected through:

  • IKDRC-ITS mobile applications.
  • IKDRC-ITS websites and web portals.
  • Online registration forms.
  • Appointment and healthcare services.
  • Authentication services.
  • Admission, recruitment, academic, or training services.
  • Feedback and grievance forms.
  • Communication with IKDRC-ITS.
  • Authorized third-party services integrated with IKDRC-ITS systems.

Information may also be generated automatically through application and server logs for security and operational purposes.

4. Purpose of Collection and Use

IKDRC may use collected information for legitimate institutional purposes, including:

  • Providing healthcare and patient-related services.
  • Patient registration and appointment management.
  • Authentication and identity verification.
  • Providing access to authorized application features.
  • Managing academic, administrative, research, and institutional activities.
  • Processing applications, registrations, and requests.
  • Communicating appointments, notifications, alerts, and institutional information.
  • Providing customer/user support.
  • Maintaining application and information-system security.
  • Detecting and preventing unauthorized access, fraud, misuse, or security incidents.
  • Maintaining records required by law or institutional policy.
  • Conducting authorized research, statistical analysis, and service improvement.
  • Improving application functionality and performance.
  • Complying with applicable laws, regulations, court orders, government directions, and statutory requirements.

IKDRC will not use personal or sensitive information for purposes unrelated to the purpose for which it was collected unless such use is permitted by applicable law or the user has provided appropriate consent.

5. Sharing and Disclosure of Information

IKDRC-ITS does not sell or rent personal or sensitive information to third parties.

Information may be shared only where necessary for legitimate institutional, healthcare, legal, regulatory, or operational purposes.

Information may be shared with:

5.1 Authorized IKDRC-ITS Personnel

Information may be made available to authorized healthcare professionals, employees, administrators, technical personnel, or other authorized persons who require access for legitimate institutional purposes.

5.2 Authorized Service Providers

IKDRC-ITS may engage authorized technology service providers, cloud service providers, application service providers, security providers, SMS/email providers, or other contractors for operating and maintaining digital services.

Such service providers may process information only to the extent necessary to provide the contracted service and subject to appropriate confidentiality and security obligations.

5.3 Government and Regulatory Authorities

Information may be disclosed where required or permitted by:

  • Applicable law.
  • Court order.
  • Government direction.
  • Regulatory requirements.
  • Law-enforcement requirements.
  • Statutory authorities.

5.4 Healthcare and Institutional Services

Where necessary for patient care, treatment, referral, diagnostics, insurance, government healthcare schemes, or other authorized healthcare activities, relevant information may be shared with appropriate parties as permitted by law and institutional policy.

5.5 Research and Academic Activities

Information may be used for legitimate academic, clinical, scientific, statistical, or research purposes where permitted by applicable law, ethics requirements, and institutional policies.

Where appropriate, information may be anonymized, de-identified, or aggregated before being used for such purposes.

6. No Sale of Personal or Health Data

IKDRC-ITS does not sell personal information, health information, medical records, authentication information, or other sensitive user information to advertisers, data brokers, or other entities for commercial purposes.

IKDRC-ITS does not use sensitive healthcare information for targeted advertising.

7. Data Security

IKDRC-ITS implements reasonable administrative, technical, and organizational safeguards to protect personal and sensitive information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.

Security measures may include:

  • Authentication and access controls.
  • Role-based access.
  • Encryption or secure transmission.
  • HTTPS/TLS-secured communications.
  • Server and application security controls.
  • Security monitoring and logging.
  • Backup and recovery mechanisms.
  • Vulnerability management and security updates.
  • Restricted access to sensitive information.
  • Confidentiality obligations for authorized personnel and service providers.

Despite these measures, no electronic transmission or storage system can be guaranteed to be completely secure.

8. Data Retention

IKDRC-ITS retains personal and sensitive information only for as long as reasonably necessary for the purposes for which it was collected or as required by applicable law, regulations, healthcare requirements, institutional policies, research requirements, or legitimate legal and administrative purposes.

Healthcare and medical records may be retained for the period required under applicable laws, regulations, professional requirements, government directions, or institutional record-retention policies.

Certain information may therefore be retained even after a user requests deletion where retention is legally required or necessary for legitimate purposes such as:

  • Legal compliance.
  • Healthcare record-keeping.
  • Regulatory requirements.
  • Fraud or security investigations.
  • Financial or audit requirements.
  • Protection of legal rights.

Where information is required to be retained, IKDRC-ITS will restrict its use to the applicable legitimate purpose.

9. Account Deletion and Data Deletion

Where an IKDRC-ITS application allows users to create an account, users may request deletion of their account and associated personal information.

The application shall provide an accessible mechanism for initiating account deletion.

Where required, users may also request account deletion through an external web-based mechanism or by contacting IKDRC-ITS using the contact details provided in this Privacy Policy.

Upon receiving a valid deletion request, IKDRC-ITS will process the request in accordance with applicable law and institutional requirements.

Where deletion is legally permissible, IKDRC-ITS will delete or anonymize information associated with the account within a reasonable period.

Certain information may need to be retained where required by law, healthcare record-retention requirements, regulatory obligations, security requirements, or legitimate legal purposes.

Retention of such information will not be used to circumvent the user's deletion request.

10. User Consent and Permissions

Where an application requires access to personal or sensitive information or device permissions, IKDRC-ITS will request the relevant permission or consent as required by applicable law, Android platform requirements, and Google Play policies.

Users may deny or withdraw certain permissions through the device or application settings where technically supported.

Certain application features may not function if the permissions necessary for those features are denied.

Where personal or sensitive information is collected through a specific feature, users will be provided with appropriate information about the purpose of collection and use.

11. Prominent Disclosure for Sensitive Information

For features that require access to personal or sensitive information, IKDRC-ITS may provide an in-app disclosure explaining:

  1. What information is being accessed or collected;
  2. Why the information is required;
  3. How the information will be used; and
  4. Whether the information will be shared with any third party.

Where required, the application will obtain affirmative user consent before requesting the relevant permission or collecting the information.

12. Third-Party Services and Integrations

IKDRC-ITS applications may integrate with authorized third-party services, APIs, platforms, or infrastructure providers.

Examples may include services for:

  • Authentication.
  • Aadhaar/Face Authentication.
  • SMS and OTP delivery.
  • Email communication.
  • Cloud infrastructure.
  • Application monitoring.
  • Security services.
  • Payment services, where applicable.
  • Government or statutory platforms.

Third-party services may have their own privacy policies and terms of service.

IKDRC-ITS will take reasonable steps to ensure that third-party service providers handling IKDRC-ITS user information maintain appropriate security and confidentiality safeguards.

13. Cookies and Similar Technologies

IKDRC-ITS websites and web-based services may use cookies and similar technologies for:

  • Essential website functionality.
  • Session management.
  • Security.
  • Performance monitoring.
  • Website analytics.
  • Improving user experience.

Users may configure their browser to restrict or disable cookies. Certain website functions may not work correctly if essential cookies are disabled.

14. Notifications

Where users provide permission for notifications, IKDRC-ITS may send:

  • Appointment notifications.
  • Healthcare-related notifications.
  • Service alerts.
  • Application notifications.
  • Important institutional communications.
  • Security-related notifications.

Users may manage notification permissions through their device settings, subject to the functionality of the application.

15. Children's Privacy

IKDRC-ITS healthcare services may involve patients who are minors.

Where information relating to a child or minor is collected as part of healthcare, registration, academic, or other legitimate institutional services, such information will be handled in accordance with applicable laws, regulations, professional obligations, and institutional policies.

IKDRC-ITS does not knowingly use children's personal information for advertising or unrelated commercial purposes.

16. External Websites and Services

The IKDRC-ITS website or application may contain links to websites, applications, portals, or services operated by other organizations, government agencies, institutions, or third parties.

IKDRC-ITS is not responsible for the privacy practices, content, security, availability, or data-handling practices of external services.

Users should review the privacy policy of an external service before submitting personal or sensitive information to that service.

17. User Rights and Privacy Requests

Subject to applicable laws and institutional requirements, users may contact IKDRC-ITS regarding:

  • Access to information.
  • Correction of inaccurate information.
  • Questions regarding use of personal information.
  • Withdrawal of consent where applicable.
  • Account deletion.
  • Data deletion requests.
  • Privacy-related complaints or concerns.

Requests may be subject to verification to protect the privacy and security of the concerned individual.

18. Grievance and Privacy Contact

For privacy-related questions, requests, complaints, or concerns, users may contact:

The Director
Smt. G.R. Doshi and Smt. K.M. Mehta Institute of Kidney Diseases and Research Centre,
Dr. H.L. Trivedi Institute of Transplantation Sciences (IKDRC-ITS),
Ahmedabad, Gujarat, India

Email: [email protected]

Website: https://ikdrc-its.org

Users may also submit their request through the official Contact Us section of the IKDRC-ITS website.

19. Changes to this Privacy Policy

IKDRC-ITS may update or modify this Privacy Policy from time to time to reflect:

  • Changes in applicable laws and regulations.
  • Changes in institutional practices.
  • Changes in application functionality.
  • Changes in technology.
  • Changes in third-party services.
  • Changes in Google Play or Android requirements.

The updated Privacy Policy will be published on the official IKDRC-ITS website.

Users are encouraged to periodically review this Privacy Policy.

20. Definitions

"Personal Information"

Information relating to an identified or identifiable individual or information through which an individual's identity can reasonably be established.

"Sensitive Information"

Information requiring enhanced protection because of its nature, including health and medical information, authentication information, financial information, biometric or face-related information, and other information classified as sensitive under applicable law.

"User"

Any individual who accesses or uses an IKDRC-ITS website, mobile application, portal, or digital service.

"Application"

Any mobile application developed, operated, maintained, or authorized by IKDRC-ITS.

"Third Party"

Any person, organization, company, service provider, government body, or other entity other than IKDRC-ITS and the concerned user.

21. Compliance with Applicable Laws and Platform Requirements

IKDRC-ITS will handle personal and sensitive information in accordance with applicable Indian laws, regulations, government directions, healthcare requirements, institutional policies, and applicable technology-platform requirements.

For applications distributed through Google Play, IKDRC-ITS will maintain the application's privacy disclosures and Google Play Data Safety information consistently with the application's actual data collection, access, use, sharing, security, retention, and deletion practices.

Health-related applications will also comply with applicable Google Play Health Content and Services requirements and any applicable declaration or disclosure requirements.

22. Acceptance

By accessing or using an IKDRC-ITS application or digital service, the user acknowledges that they have read and understood this Privacy Policy.

Where additional consent is legally or technically required, the relevant consent will be obtained separately through the applicable application or service.

Smt. G.R. Doshi and Smt. K.M. Mehta Institute of Kidney Diseases and Research Centre, Dr. H.L. Trivedi Institute of Transplantation Sciences (IKDRC-ITS)

Ahmedabad, Gujarat, India

© 2025 ikdrc.visioninformatics.in | Designed & Developed by : Vision Informatics
Privacy Policy