1. Overview
Fertiva Pro is built around the requirements of the Digital Personal Data Protection (DPDP) Act 2023. This page sets out how we approach our obligations as a Data Fiduciary and how we support the rights of Data Principals — patients, clinic staff and administrators — whose data is processed on the platform.
2. Our role under the Act
HumanITech, operating Fertiva Pro, acts as a Data Fiduciary in respect of clinic user and billing data. Fertility clinics using Fertiva Pro act as Data Fiduciaries in respect of their patients, with HumanITech acting as a Data Processor on their behalf.
3. Consent architecture
- Dual consent model: patient consent is collected as a V1 consent covering demographic intake and a V2 consent covering clinical ART data processing.
- Couple-aware consent: where a procedure involves two partners, each individual provides separate explicit consent before shared clinical data is processed.
- Consent tokens: each consent event is recorded with a timestamped, uniquely identified token retained in the audit log.
- Withdrawal: patients may withdraw consent at any time. Fertiva Pro supports withdrawal workflows that restrict further processing of that patient's data.
4. Data Principal rights
Under the Act, Data Principals have the right to access the personal data held about them, request correction of inaccurate data, request erasure of data no longer necessary (subject to the retention periods mandated by the ICMR ART Act 2021), and raise grievances. To exercise these rights, write to hello@fertiva.pro.
5. Data localisation
All personal data — patient clinical records, embryology lab data and consultation notes — is stored on infrastructure physically located within India. No personal data is processed or stored on servers outside India. Voice transcription is India-hosted.
6. Security safeguards
- Role-based access control across governed API endpoints.
- TLS 1.3 encryption for all data in transit.
- Full-disk encryption at rest, being deployed ahead of first clinic go-live.
- Audit logging of data access and modification events.
- Automated daily encrypted backups stored in India.
7. Data breach notification
In the event of a personal data breach we will notify the Data Protection Board of India within the period required by law, notify affected clinics and patients as required, take immediate remediation steps, and publish a post-incident report.
8. Children's data
Fertiva Pro processes birth records of children born through ART where the ICMR ART Act 2021 requires it. These records are handled with heightened access restrictions and are accessible only to clinically authorised personnel. Children's data is not used for any secondary purpose.
9. Grievance Officer
Grievances may be submitted to hello@fertiva.pro. We aim to acknowledge within 48 hours and resolve within 15 business days. Unresolved disputes may be escalated to the Data Protection Board of India.
10. Policy review
We review this page quarterly and update it to reflect changes in applicable law or in our data processing activities.