Nepal · Legal
Privacy Policy
Last updated: 10 Baishakh 2082 BS (23 April 2025)
Your health information is among the most sensitive data you own. This policy explains exactly what eDawae collects, why, who can see it, and how you control it — under Article 28 of the Constitution of Nepal (right to privacy) and the Individual Privacy Act 2075 BS.
1Who controls your data
eDawae, operating in Nepal, is the data controller for the account and platform data described below. Doctors, hospitals and pharmacies you interact with are separate controllers for the clinical records they create in their own systems and are bound by their own professional confidentiality duties.
2What we collect
- Account data: name, email, mobile number (+977), password hash, chosen role, district and province.
- Health data you upload: lab reports, x-ray and imaging files, prescriptions, notes, vitals, allergies, chronic conditions, current medicines, blood group, date of birth and sex.
- Care activity: appointment requests and status, chat messages with your doctor, prescriptions issued to you, reminders you set.
- Commerce data: medicine orders, delivery address, courier handoff notes and photos, wallet top-up references, wallet transactions.
- Professional data (for doctors, hospitals, pharmacies, couriers): licence and registration numbers, clinic or firm address, service areas, fees, vehicle and licence-plate details.
- Technical data: device and browser type, IP address, error logs and basic usage events needed to run and secure the service.
We do not collect biometric identifiers, and we do not ask for your citizenship number or national ID unless a regulator requires it for professional verification.
3Why we use it (lawful basis)
- To perform the service you asked for: store your records, book appointments, run consults, place medicine orders, dispatch couriers, move wallet money.
- With your explicit consent: showing a specific record to a specific doctor, generating an AI summary of your own records, sending email reminders.
- To comply with Nepali law: tax records, drug and prescription record-keeping, anti-money-laundering checks, lawful requests from a competent authority.
- For legitimate operation of the platform: fraud prevention, abuse investigation, security monitoring, service quality.
4Who can see your health records
By default, only you. Nobody else — including our staff — browses your records in the ordinary course of business. Access is opened only in these cases:
- A doctor you book with, limited to the records or summary you attach to that appointment, or a share link you create.
- A pharmacy, limited to the order items, your contact name and phone, and the delivery address you provide.
- A courier, limited to pickup and drop-off address, your name and phone, and the package reference. Couriers never see diagnoses or record contents.
- Our authorised technical staff, only when strictly necessary to fix a fault or investigate abuse, under confidentiality obligations and with access logged.
- A competent Nepali authority, court, or regulator acting under lawful process.
Share links you create expire on the date you set and can be revoked at any time from the Shares screen. Revoking stops all further access immediately.
5AI processing
When you ask for an AI summary or next-steps checklist, the relevant text and images from your own records are sent to our AI processing provider to generate that output. This happens only when you trigger it. Your data is not used to train third-party foundation models, and it is not shared with advertisers. AI output is stored in your account so you can see it again, and you can delete it.
6Payment data
We never see or store your eSewa, Khalti, IME Pay, ConnectIPS, card or bank credentials. For a wallet top-up we store only the amount, method, the reference number you type, the depositor name if you give one, and any receipt image you attach — enough to verify the deposit and to satisfy accounting and anti-money-laundering obligations.
7Where data is stored and transfers
Records, files and wallet data are held on managed cloud infrastructure with encryption in transit (TLS) and encryption at rest. Some infrastructure and AI processing servers are located outside Nepal. Where that happens, we transfer only what is needed for the feature you invoked, under contractual confidentiality and security terms. By using the AI and hosting features you consent to that transfer.
8How long we keep it
- Health records: kept while your account is open. Deleted within 30 days of account closure, unless you ask us to keep them.
- Prescriptions and medicine order records: retained for the period required of the pharmacy under the Drug Act 2035 BS and its rules.
- Wallet transactions, top-up references and invoices: retained for at least 5 years for tax and anti-money-laundering compliance.
- Security and access logs: up to 12 months.
- Support correspondence: up to 2 years.
9Your rights
- Access — download your records and a copy of your account data at any time.
- Correct — edit your profile, health details and uploaded record metadata.
- Delete — delete individual records, revoke shares, or close your account and have the rest erased subject to legal retention.
- Withdraw consent — turn off email reminders or stop using AI features without losing access to your records.
- Object and complain — write to privacy@edawae.com. If you are not satisfied, you may complain to the relevant Nepali authority, and you retain your remedies under the Individual Privacy Act 2075 BS.
We respond to rights requests within 15 days.
10Security measures
- Row-level database rules so each account can read only its own data.
- Private file storage: record and receipt files are never publicly addressable, and are served through short-lived signed links.
- Encrypted transport (HTTPS) and encryption at rest.
- Leaked-password protection on sign-up and password change; anonymous sign-in disabled.
- Least-privilege internal access with logging.
No system is perfectly secure. If a breach affects your data we will notify you and the relevant authority without undue delay, describing what happened and what to do.
11Children
Accounts are for adults. A parent or guardian may manage a child's records under their own account and is responsible for that content. If we learn a child has created an account independently, we will close it and delete the data.
12Cookies and similar technology
We use only essential storage: a session token to keep you signed in and local preferences. We do not run third-party advertising or cross-site tracking cookies.
13Changes and contact
We will notify you in-app or by email before material changes take effect. For any privacy question or request, write to privacy@edawae.com.