Legal
Privacy Policy
How NexaMed, operated by Celron Ventures Private Limited, collects, uses, protects and deletes information across every surface of the platform.
This Privacy Policy explains how Celron Ventures Private Limited ("Celron Ventures", "Company", "we", "us" or "our") collects, receives, stores, uses, processes, shares, discloses, protects and deletes information when you access or use NexaMed, including the website available at https://nexamed.pranayjuneja.com, related web applications, mobile applications, dashboards, APIs, integrations, support channels and any other software, tools, products or services offered under the NexaMed brand (collectively, the "Services").
NexaMed is intended to support healthcare and healthcare-operations workflows, including patient registration, appointment and queue workflows, clinical documentation, electronic medical records, prescription/document digitisation, diagnostic workflow support, report management, hospital/clinic operations, healthcare-provider dashboards, integrations with healthcare systems and, where enabled, AI-assisted clinical and administrative tools.
By accessing or using the Services, creating an account, submitting information, uploading documents, integrating NexaMed with an organisation, or authorising a healthcare provider or organisation to use NexaMed in relation to you, you acknowledge that you have read and understood this Privacy Policy. Where consent is required under applicable law, we will seek such consent in the manner required by law.
If you use the Services on behalf of another person, patient, minor, dependent, organisation, hospital, clinic, diagnostic centre or any other entity, you represent that you are authorised to provide information and consent on their behalf, where applicable.
| Item | Details |
|---|---|
| Product / Service Name | NexaMed |
| Website | https://nexamed.pranayjuneja.com |
| Legal Entity | Celron Ventures Private Limited |
| CIN | U35105DL2024PTC437316 |
| Registered Office | House No. 3398 B/1, Plot 16, Ground Floor, Mahindra Park, Rani Bagh, North West Delhi, Delhi, India – 110034 |
| Support Email | pj@pranayjuneja.com |
| Privacy Email | pj@pranayjuneja.com |
| Legal Email | pj@pranayjuneja.com |
| Grievance Officer | Pranay Juneja |
| Grievance Officer Email | pj@pranayjuneja.com |
| Governing Law | Laws of India |
| Jurisdiction | Courts and tribunals at Delhi, India |
This Privacy Policy applies to the following categories of users:
- Patients and end-users who use NexaMed directly or whose information is processed through NexaMed by a healthcare provider or healthcare organisation.
- Doctors, nurses, technicians, radiologists, pathologists, pharmacists, administrators and other healthcare professionals who use NexaMed.
- Hospitals, clinics, diagnostic centres, healthcare networks and institutional customers that deploy, integrate or use NexaMed.
- Visitors to NexaMed websites, landing pages, forms, demos, support channels or related digital properties.
- Authorised staff, vendors, contractors and representatives who interact with NexaMed on behalf of an organisation.
This Privacy Policy does not replace any privacy notice, consent form, patient intake form, hospital policy, medical-record policy, data-processing agreement or institutional agreement that may separately apply between you and your healthcare provider, hospital, clinic, diagnostic centre, employer, insurer, government body or other third party.
Where NexaMed is deployed for a hospital, clinic, diagnostic centre or other healthcare organisation, that organisation may independently determine why and how certain patient or clinical data is processed. In such cases, Celron Ventures may act as a technology provider, data processor, service provider or similar role, depending on the applicable contract, instructions and law.
This Privacy Policy is intended to be read in line with applicable Indian laws, rules and regulations, including, as applicable:
- the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025;
- the Information Technology Act, 2000;
- the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
- the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, where applicable;
- applicable healthcare, medical-record, telemedicine, professional conduct, insurance, payment, consumer-protection and e-commerce requirements; and
- applicable Ayushman Bharat Digital Mission, Health Data Management Policy, Health Information Exchange and Consent Manager framework, or similar digital-health frameworks, where NexaMed is integrated with such systems.
Where any applicable law gives you additional rights or imposes additional obligations on us, our healthcare partners or institutional customers, such law will apply in addition to this Privacy Policy.
For this Privacy Policy:
- Personal Data means any data about an individual who is identifiable by or in relation to such data.
- Sensitive Personal Data or Information includes, where applicable, health information, medical records, financial information, passwords, biometric information and other categories recognised under applicable law.
- Health Data includes information relating to your physical, physiological or mental health, symptoms, diagnoses, prescriptions, investigations, reports, imaging, laboratory results, vitals, allergies, medications, treatment history, clinical notes and related medical records.
- User means any person or organisation using, accessing or interacting with the Services.
- Practitioner means a registered medical practitioner, healthcare professional, diagnostic professional or other authorised healthcare provider using NexaMed.
- Institutional Customer means a hospital, clinic, diagnostic centre, healthcare network, laboratory, pharmacy, insurer, corporate health provider or other organisation that deploys or integrates NexaMed.
- Processing means any operation performed on data, including collection, recording, storage, organisation, structuring, alteration, retrieval, use, disclosure, transmission, restriction, erasure or deletion.
- AI-Assisted Features means automated or semi-automated features used for administrative, documentation, triage-support, summarisation, transcription, OCR, workflow, analytics or diagnostic-support purposes.
We collect information depending on how you use NexaMed, the features enabled, the organisation deploying the Services and the permissions you provide.
5.1 Account, Identity and Contact Information
We may collect:
- name;
- phone number;
- email address;
- age or date of birth;
- gender;
- address, city, state, country, PIN code or similar location details;
- login credentials or authentication identifiers;
- profile photograph, where provided;
- emergency-contact details, where provided;
- identity verification information, where required by the applicable service or organisation.
5.2 Patient and Health Information
Where you use NexaMed as a patient, or where a healthcare provider or organisation uses NexaMed in relation to you, we may process:
- symptoms, complaints, history of present illness and medical history;
- vitals, lifestyle information, activity information and other health parameters;
- prescriptions, medication history, allergies and adverse reactions;
- clinical notes, discharge summaries, referrals and care plans;
- lab reports, diagnostic reports and investigation orders;
- radiology images, pathology data, medical images and related reports, where enabled;
- uploaded files, photographs, scans, prescriptions, documents or images;
- appointment history, consultation details, queue status and visit records;
- insurance details, billing references and payment-related records;
- ABHA number, ABHA address, health IDs, consent artefacts or other ABDM-linked identifiers, where enabled and authorised;
- information shared by doctors, hospitals, clinics, diagnostic centres, laboratories or other healthcare providers in relation to your treatment or healthcare workflow.
5.3 Practitioner and Healthcare Staff Information
For practitioners, healthcare professionals and staff, we may collect:
- name, contact information and professional profile;
- registration number, qualifications, speciality, department and designation;
- organisation, facility and role information;
- work schedule, appointment slots and availability;
- dashboard activity, workflow actions and audit logs;
- access permissions, role-based access details and authentication records;
- documents or credentials uploaded for verification, onboarding or operational use.
5.4 Organisation and Facility Information
For institutional customers, we may collect:
- organisation name, registered details, facility details and authorised representative details;
- department, branch, unit, bed strength, workflow and operational configuration;
- system integration details, APIs, EMR/HIS/LIS/RIS/PACS configuration, FHIR mappings or data schemas;
- billing, subscription, invoice and commercial information;
- staff-user lists, roles, permissions and audit logs;
- support tickets, implementation data and training records.
5.5 Payment and Transaction Information
Where payments are enabled, we may collect or receive:
- billing name, billing contact details and invoice details;
- transaction amount, transaction status, payment reference ID and payment gateway response;
- GST, tax, subscription and commercial records, where applicable;
- refund, cancellation, failed-payment or chargeback-related communication, where applicable.
We do not intend to store full credit-card, debit-card, UPI PIN, net-banking password or similar sensitive payment credentials on NexaMed servers. Such information is generally processed by authorised payment gateways, banks or payment service providers under their own terms and privacy policies.
For clarity, unless expressly provided in a separate written agreement or required under applicable law, all NexaMed fees, subscriptions, implementation fees, service charges and other payments are non-refundable. This Privacy Policy does not create any independent refund, cancellation or return right.
5.6 Device, Usage and Technical Information
When you use the Services, we may automatically collect:
- IP address;
- device identifiers;
- browser type and version;
- operating system;
- app version;
- log data;
- access time and duration;
- pages, screens, features and workflows used;
- crash reports, diagnostics, performance metrics and error logs;
- approximate location derived from IP address;
- cookies, pixels, SDKs and similar technologies, where applicable.
5.7 Communications and Support Information
We may collect information you provide through:
- emails, calls, forms, demos and support tickets;
- chat, messaging or helpdesk channels;
- feedback, surveys and product research;
- sales, onboarding, training and implementation interactions;
- complaints, grievances and legal communications.
5.8 Information from Third Parties and Integrations
Subject to applicable law, contract and consent, we may receive information from:
- hospitals, clinics, diagnostic centres and healthcare providers;
- laboratories, radiology centres, pharmacies or care partners;
- payment gateways and financial service providers;
- authentication providers;
- cloud, hosting, analytics and support-service providers;
- ABDM or other digital-health ecosystem participants, where enabled;
- EMR, HIS, LIS, RIS, PACS, FHIR, HealthKit, Health Connect or similar integrations, where enabled and authorised.
We may collect information:
- directly from you when you create an account, fill forms, upload files, communicate with us or use the Services;
- from practitioners, hospitals, clinics, diagnostic centres, laboratories or other authorised healthcare organisations using NexaMed;
- from institutional customers that configure, deploy or integrate NexaMed;
- automatically through logs, cookies, SDKs, analytics tools and security systems;
- from payment gateways, identity providers, cloud providers, support tools and other service providers;
- from government, digital-health or ABDM-linked systems where enabled and authorised; and
- from publicly available sources, only where lawful and relevant for the Services.
We use information for the following purposes.
7.1 Providing and Operating the Services
- creating and managing accounts;
- enabling patient registration, intake, appointments and queue management;
- enabling clinical documentation and medical-record workflows;
- supporting prescriptions, reports, referrals and care coordination;
- enabling dashboards for doctors, staff and organisations;
- enabling hospital, clinic, diagnostic and administrative workflows;
- providing support, troubleshooting and service communication;
- processing payments, invoices, subscriptions and commercial transactions.
7.2 Healthcare Workflow and Care Support
Subject to permissions, law and the applicable healthcare-provider relationship, we may use information to:
- help healthcare providers access relevant patient records;
- generate summaries, structured notes and workflow prompts;
- assist in investigation ordering, report routing and follow-up workflows;
- support diagnostic-workflow coordination;
- enable continuity of care across authorised users and systems;
- facilitate patient-facing delivery of reports, prescriptions or instructions.
NexaMed does not replace a qualified doctor, radiologist, pathologist, pharmacist, nurse or other licensed healthcare professional. Any clinical decision, diagnosis, prescription, treatment plan or patient-management decision must be made by authorised healthcare professionals.
7.3 AI-Assisted Features
Where AI-Assisted Features are enabled, information may be processed to:
- transcribe or summarise patient inputs, audio, notes or documents;
- extract structured information from prescriptions, reports, images or forms;
- assist with triage-support, clinical summarisation or administrative prioritisation;
- support radiology, pathology, diagnostic or report-generation workflows, where enabled;
- detect inconsistencies, missing data or workflow bottlenecks;
- improve user experience and operational efficiency.
AI-Assisted Features may produce incomplete, inaccurate, outdated or context-limited outputs. They are intended to support authorised users and not to independently provide medical advice, diagnosis or treatment. Healthcare professionals and institutional customers are responsible for reviewing AI-assisted outputs before relying on them for clinical or operational decisions.
7.4 Service Improvement, Security and Analytics
We may use information to:
- maintain, secure, test and improve the Services;
- monitor service uptime, performance and reliability;
- detect, prevent and investigate fraud, abuse, unauthorised access, security incidents or misuse;
- debug errors and resolve support issues;
- understand usage patterns and improve product design;
- develop new features and workflows;
- create aggregated, anonymised or de-identified analytics that do not identify an individual.
7.5 Legal, Compliance and Business Purposes
We may use information to:
- comply with applicable law, court orders, lawful government requests or regulatory requirements;
- maintain records required under medical, tax, corporate, accounting, audit or legal obligations;
- enforce our terms, contracts and policies;
- respond to disputes, claims, notices, complaints and grievances;
- protect the rights, safety and property of users, patients, healthcare providers, institutional customers, Celron Ventures and the public;
- support business transfers, restructuring, merger, acquisition, investment, financing or sale of assets, subject to appropriate confidentiality and legal safeguards.
We may create and use aggregated, anonymised or de-identified data for analytics, research, service improvement, business intelligence, product development, benchmarking, reporting or commercial purposes, provided such data does not identify you personally.
Where we use such data, we will take reasonable steps designed to prevent re-identification, except where permitted or required by law.
We may contact you through email, phone, SMS, WhatsApp, in-app notifications, push notifications or other digital channels for:
- account and authentication messages;
- appointment, queue, report, prescription, care or workflow updates;
- support, security and service-related notices;
- payment, invoice or subscription communication;
- product updates, onboarding and training;
- feedback, research or marketing communication, where permitted by law.
You may opt out of non-essential promotional communications by contacting pj@pranayjuneja.com or using available unsubscribe controls. Transactional, security, legal, healthcare, payment and service-critical messages may continue where necessary.
We retain information for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law, contract, medical-record policies, institutional-customer instructions, audit requirements, tax requirements, dispute-resolution needs, security needs or legitimate business purposes.
Health records and medical workflow records may be retained by or on behalf of healthcare providers, hospitals, clinics, diagnostic centres or institutional customers according to their own legal, medical and operational retention obligations.
When information is no longer required, we may delete, anonymise, de-identify or archive it in accordance with applicable law, contracts and technical feasibility. Backup copies may remain for a limited period due to disaster recovery, security, audit or system-integrity requirements.
We take reasonable technical, organisational, administrative and physical safeguards designed to protect information against unauthorised access, use, disclosure, alteration, loss, destruction or misuse. These safeguards may include, depending on the nature of the system and deployment:
- access controls and role-based permissions;
- authentication and authorisation controls;
- encryption in transit and, where appropriate, encryption at rest;
- audit logs and activity monitoring;
- secure development and testing practices;
- vulnerability management and security reviews;
- backup and recovery procedures;
- staff, vendor and contractor confidentiality controls;
- contractual safeguards with service providers.
No system, server, database, cloud environment, application, internet transmission or electronic storage method is completely secure. Users, practitioners and institutional customers are responsible for protecting their login credentials, devices, access controls and internal user permissions.
Celron Ventures will not be responsible for unauthorised access or data loss arising from user-side device compromise, credential sharing, weak passwords, malware, institutional misconfiguration, unauthorised staff access, third-party systems outside our control or circumstances beyond our reasonable control.
If we become aware of a personal data breach or security incident affecting information under our control, we will take reasonable steps to assess, contain, investigate and remediate the incident.
Where required by applicable law, we will notify affected users, institutional customers, regulators or other authorities in the manner and timeframe required by law. Incident notices may include details of the nature of the incident, likely consequences, steps taken, recommended user actions and contact details for assistance.
NexaMed may process information relating to minors where the Services are used by parents, lawful guardians, healthcare providers, hospitals, clinics, diagnostic centres or other authorised persons for healthcare-related purposes.
Where legally required, consent must be provided by a parent or lawful guardian. Users, practitioners and institutional customers must not submit information of a minor unless they have the authority to do so and the submission is lawful.
We do not knowingly use children's Personal Data for behavioural advertising or profiling in a manner prohibited by applicable law.
Subject to applicable law, identity verification, technical feasibility and any exceptions under law, you may have the right to:
- access information about the Personal Data processed in relation to you;
- request correction, completion or updating of inaccurate or incomplete Personal Data;
- request deletion or erasure of Personal Data where legally permissible;
- withdraw consent where processing is based on consent;
- request grievance redressal;
- nominate another person to exercise certain rights on your behalf, where applicable;
- raise concerns about unauthorised or unlawful processing.
To exercise these rights, contact us at pj@pranayjuneja.com. For grievances, contact the Grievance Officer at pj@pranayjuneja.com.
We may need to verify your identity before acting on a request. We may refuse or limit a request where permitted by law, including where the request conflicts with legal obligations, medical-record retention requirements, contractual obligations, institutional-customer instructions, security needs, audit requirements, dispute-resolution needs or the rights of another person.
Where your information is controlled by a hospital, clinic, diagnostic centre, practitioner or institutional customer, we may direct your request to that organisation or require you to contact that organisation directly.
You may request account deletion or withdrawal of consent by contacting pj@pranayjuneja.com.
Please note:
- deleting your account may prevent you from accessing reports, prescriptions, appointments, records or other Services;
- some information may be retained where required by law, medical-record obligations, institutional-customer instructions, contracts, audit requirements, tax requirements, dispute-resolution needs or security purposes;
- institutional records may remain with the hospital, clinic, diagnostic centre or practitioner that created or controls them;
- deletion from active systems may not immediately delete data from backups or logs maintained for security, audit or recovery purposes.
NexaMed may use cloud, infrastructure, support, security, analytics, communication, AI or technology providers located in India or outside India, subject to applicable law, contract and security safeguards.
Where data is transferred, stored or processed outside India, we will take steps required under applicable law and contractual arrangements. Certain institutional customers may require specific hosting, storage or processing locations; such requirements should be documented in the applicable written agreement.
The Services may contain links to or integrations with third-party websites, payment gateways, hospital systems, diagnostic platforms, government systems, ABDM-linked systems, cloud services or other third-party services.
We are not responsible for the privacy practices, security practices, content, accuracy, availability or policies of third-party services that are not controlled by Celron Ventures. You should review the privacy policies and terms of those third-party services before using them.
Where an institutional customer deploys or uses NexaMed, that institutional customer is responsible for:
- obtaining all required patient, practitioner, staff and organisational consents;
- ensuring users are properly authorised and trained;
- configuring role-based access appropriately;
- maintaining accurate patient and clinical records;
- reviewing and validating AI-assisted outputs before clinical or operational use;
- complying with medical-record, healthcare, privacy, employment, billing and regulatory obligations;
- informing Celron Ventures of any special retention, deletion, hosting, access-control or compliance requirements;
- promptly notifying us of suspected unauthorised access, misuse or security incidents involving NexaMed.
Practitioners and healthcare professionals using NexaMed are responsible for:
- using NexaMed only within the scope of their professional authority and applicable law;
- maintaining confidentiality of patient information;
- verifying clinical information before relying on it;
- independently reviewing prescriptions, reports, summaries, AI-assisted outputs and recommendations;
- complying with applicable medical ethics, professional conduct, telemedicine, prescription and record-keeping rules;
- keeping login credentials confidential and not sharing accounts.
NexaMed is not intended to be an emergency medical service. Users should not rely on NexaMed for emergency diagnosis, emergency treatment, ambulance dispatch or urgent medical intervention. In a medical emergency, users should immediately contact local emergency services or visit the nearest hospital.
NexaMed does not independently provide medical advice, diagnosis or treatment. Healthcare professionals using NexaMed remain responsible for their professional judgement and patient-care decisions.
We may update this Privacy Policy from time to time to reflect changes in law, technology, our Services, security practices, business operations or regulatory requirements.
The updated version will be posted on the website or made available through the Services with a revised "Last Updated" date. Where required by law, we may provide additional notice or seek fresh consent.
Your continued use of the Services after an updated Privacy Policy becomes effective indicates that you have read and understood the updated Privacy Policy, subject to any consent requirements under applicable law.
For support requests, account issues or service-related queries, contact:
Support Email: pj@pranayjuneja.com
For privacy-related requests, data rights, consent withdrawal or deletion requests, contact:
Privacy Email: pj@pranayjuneja.com
For legal notices or legal communication, contact:
Legal Email: pj@pranayjuneja.com
For grievances under applicable privacy, IT or platform laws, contact:
Grievance Officer: Pranay Juneja
Email: pj@pranayjuneja.com
Registered Office: House No. 3398 B/1, Plot 16, Ground Floor, Mahindra Park, Rani Bagh, North West Delhi, Delhi, India – 110034
We will attempt to acknowledge and resolve grievances within the time period required under applicable law.
This Privacy Policy shall be governed by and interpreted in accordance with the laws of India.
Subject to applicable law, the courts and tribunals located at Delhi, India shall have exclusive jurisdiction over disputes arising out of or in relation to this Privacy Policy, the Services or the processing of information by Celron Ventures in connection with NexaMed.
This summary is provided for convenience only. The full Privacy Policy above is the legally relevant version.
- NexaMed is operated by Celron Ventures Private Limited.
- NexaMed may process identity, contact, health, practitioner, organisation, payment, device, usage and support information.
- Health Data may be processed for healthcare workflow support, clinical documentation, diagnostic workflow support, reports, records, prescriptions and related operations.
- AI-Assisted Features are support tools and do not replace qualified healthcare professionals.
- We may share information with authorised healthcare providers, institutional customers, service providers, integrations, legal authorities and others as described in this Privacy Policy.
- We use reasonable security safeguards, but no digital system is completely secure.
- You may contact pj@pranayjuneja.com for privacy requests and grievances.
- Fees and payments are non-refundable unless required by applicable law or expressly agreed in writing.
- This Privacy Policy is governed by Indian law, with jurisdiction at Delhi, India.