Last updated: 28 May 2026
BlueSting is a doctor-to-doctor patient flagging platform operated in India. This policy explains how we collect, use, and protect personal data in accordance with the Digital Personal Data Protection (DPDP) Act 2023.
| Data | Purpose |
|---|---|
| Name, NMC registration number | Verify medical credentials before granting access |
| Mobile number | Identity verification via OTP; account authentication |
| Email address | Account notifications (approval, rejection) |
| Specialization, city, state | Doctor directory and service quality |
| Patient name, phone, date of birth (masked Aadhaar optional) | Creating patient records for flagging purposes |
| Ratings and clinical flags | Core platform functionality — doctor-to-doctor warnings |
| Audit logs | Security and compliance logging |
We process personal data on the basis of consent obtained at registration (self-declaration checkbox) and for the legitimate purpose of providing the platform service. Patient data is entered by verified doctors in the course of their medical practice.
Doctor account data is retained for as long as the account is active. Deleted accounts are purged within 30 days. Patient records and ratings are retained for the minimum period required to fulfil the platform purpose, currently indefinite pending regulatory guidance. OTP codes are automatically deleted after 24 hours.
We do not sell personal data. Data is shared only with:
As a Data Principal you have the right to:
To exercise any of these rights, contact us at the address below.
We implement reasonable security safeguards including HTTPS encryption in transit, bcrypt password hashing, JWT-based authentication, rate limiting on all endpoints, and audit logging of moderation actions. Data is stored within India (Mumbai region).
In the event of a personal data breach that is likely to result in harm, we will notify affected users and the Data Protection Board of India within the timeframe prescribed under the DPDP Act 2023.
For any data-related complaints or requests, contact our Grievance Officer:
We may update this policy periodically. Material changes will be communicated to registered users by email. Continued use of the platform after updates constitutes acceptance of the revised policy.