We respect your privacy. This policy explains, in plain English, what personal data we collect, why we collect it, the lawful basis we rely on, who we share it with, where it is stored, how long we keep it, how we protect it, and the rights you have under India's Digital Personal Data Protection Act, 2023 (the 'DPDP Act'). Throughout, 'you' means the person whose data we handle (the Data Principal), and 'we' means BimaHaq (the Data Fiduciary).
Who we are
BimaHaq is an insurance claims review, claim audit, grievance-drafting, and online dispute resolution (ODR) platform. We help you review policies, audit and pursue insurance claims, draft grievances, and resolve disputes through mediation, and we run our Rights Club and Insurance Updates content. We are an independent platform — not an insurance company, broker, or IRDAI-licensed agent — and we do not sell insurance.
BimaHaq is currently run as a sole proprietorship, operating from WeWork Rajeha Woods, 1st to 5th, BLD No. 8, Sr. No. 222/1, Central Avenue, Kalyani Nagar, Pune – 411006.
Under the DPDP Act we are a Data Fiduciary — we decide why and how your personal data is processed. We are not a Significant Data Fiduciary, so we are not required to appoint a Data Protection Officer; instead we have a designated Grievance Officer you can contact for any privacy question or complaint. Reach our Grievance Officer at privacy@bimahaq.com (for general, non-privacy queries, use info@bimahaq.com).
What personal data we collect
We collect only the data we need to run the services you use. Depending on what you do with us, this can include:
Identity and contact details — your name, email address, phone number, and (where relevant) organisation details.
Policy and claim details — your policy type, claim status, the specific monetary figures for your claim (such as the claim amount, sum insured, and the amounts approved, disputed, or received), a description of your issue, and related correspondence with your insurer (such as repudiation letters and settlement communications). We need the exact figures — not just a range — to assess your claim and draft accurate letters and complaints on your behalf.
Documents and evidence — files you upload for your case, which can include medical reports, doctors' communications, identity proof, and bank statements provided for KYC context. Some of this is sensitive personal data, and we treat it with extra care.
Payment information — transaction records and payment metadata for paid services (amounts, order IDs, and payment IDs). We do not store your full card or bank credentials; those are handled by our payment processor.
Messages and case activity — the messages, notes, and updates exchanged as your case progresses.
Device and usage data — information your device and browser send us, such as IP address, pages visited, referral source and campaign (UTM) parameters, plus an anonymous analytics identifier.
Account and security data — session and authentication tokens used to keep you signed in and to secure your account.
Consent records — a record of the consents you give or withdraw, including the categories accepted or rejected, the date, and the consent version.
Eligibility and referral data — the details you enter into our eligibility checker and, if you refer someone, that person's name and email.
We do not build advertising or behavioural profiles of you.
Why we collect it, and our lawful basis
We process your personal data for specific, itemised purposes — not vague goals like 'to improve services'. For each purpose our lawful basis under the DPDP Act is either your consent (Section 6) or a legitimate use permitted by the Act (Section 7), such as processing data you have voluntarily provided or processing needed to perform a service you asked for. The DPDP Act does not recognise a general 'legitimate interest' basis of the GDPR kind, and we do not bundle unrelated purposes into a single consent.
Claims assessment and advocacy — to review, audit, and pursue your claim and advise you. Basis: your consent and performance of the service you engaged us for.
Case management and communication — to run your case, keep records of it, and keep you updated. Basis: performance of the service.
Document management and evidence preservation — to store and protect the documents your case depends on. Basis: performance of the service, and (where a claim or legal right is involved) enforcing a legal claim.
Payment processing — to take payment and issue receipts. Basis: performance of the service, and compliance with tax law for the records we must keep.
Eligibility evaluation — to tell you whether we can help and prioritise our response. Basis: your consent.
Authentication and account security — to sign you in securely and protect your account. Basis: performance of the service.
Dispute resolution and mediation (ODR) — to run mediation and resolution-room sessions where you use them. Basis: performance of the service.
Entitlements and operational notifications — to give you what you paid for and send service messages about your account and cases. Basis: performance of the service.
Analytics — to understand, in aggregate, how our site is used. Basis: your consent, given through the cookie banner. This is optional and you can decline or withdraw at any time.
Audit and compliance — to keep the records the law requires and demonstrate that we handle data lawfully. Basis: compliance with law.
Consent — how you give it and how you withdraw it
When you create an account, we ask for your explicit consent to this Privacy Policy through a tick box that is not pre-ticked, alongside a separate tick box for our Terms. Both are opt-in, and we record which version of the consent you agreed to.
For analytics and other non-essential cookies we show a consent banner. Strictly necessary cookies (needed to sign you in and keep the site working) are always on; analytics cookies are off until you accept them, and you can accept or reject them separately.
You can withdraw consent at any time, as easily as you gave it — from the privacy dashboard in your account, the cookie banner, or by writing to privacy@bimahaq.com. When you withdraw consent for non-essential processing, we stop that processing and erase the analytics events and eligibility/marketing lead data that depended on it. Withdrawal applies going forward and takes effect within a reasonable time; it does not undo processing that was already lawful, and records we are legally required to keep (for example, tax records) are retained as explained below.
Cookies and analytics
We use two kinds of cookies and similar technologies: strictly necessary ones (for sign-in, security, and core functionality) and analytics ones (to measure, in aggregate, how the site is used). We do not use advertising networks and we do not sell your data to advertisers.
Our analytics are first-party and processed on our own servers — analytics events are not sent to any third-party product-analytics vendor. You control analytics cookies through the banner and can change your choice or withdraw at any time. For full detail, see our Cookie Policy.
Who we share it with
We do not sell or trade your personal data. We share it only where it is needed to run the service you asked for, and only with the service providers (processors) we actually use. Every processor is bound by contract to protect your data and to erase its copies when we tell it to; we remain responsible to you for how our processors handle your data.
Processors we currently use: Razorpay (payment processing — we share your user reference, email, payment amounts, and order/payment IDs so a payment can be completed) and Resend (delivery of our transactional emails — we share your email, name, and case/payment details needed for that email, plus any secure link tokens).
We may also share your data with your insurer, or the relevant regulator or ombudsman, where that is necessary to pursue your case — and only with your consent to that specific step.
Providers we support but have NOT switched on: document storage on Cloudinary (documents are stored on our own servers by default), Meta / WhatsApp Cloud API (outbound WhatsApp notifications), Exotel (India-based cloud telephony — for phone calls between our team and you and, later, SMS; where telephony is active a call may be recorded and, if so, you will hear a spoken notice at the start of the call, and the recording is treated as your personal data and erased on request), Jitsi / Google Meet / Zoom / Microsoft Teams (video meetings for the resolution room), Sentry (error monitoring, configured never to receive personal data), and a large-language-model provider used only for the optional AI-assisted analysis of consult documents described below (off by default, and only with your separate, withdrawable consent). We will only route data to any of these if and when we activate it, and this policy and our consent flows will be updated first. We do not use PostHog or any similar third-party product-analytics service.
AI-assisted analysis of your documents (optional)
If you buy a paid consult (the Claim Review or the Claim Review + Expert Call) and upload your claim paperwork, you can optionally allow our AI assistant to read those documents so our specialist can prepare your strategy faster. This is switched off by default and is never a condition of the service — a member of our team reviews your documents personally whether or not you turn it on, and any draft the AI helps prepare is reviewed by a person before it is used.
You give this consent separately — at the point of upload or from your privacy dashboard — and you can withdraw it at any time, just as easily. Once you withdraw it, we stop sending your document text to the AI for any future drafting. When the feature is active, the document text is processed on demand and is not retained by the provider for its own purposes; and before we switch it on, we will put a data-processing agreement in place that binds the provider not to train its models on your data.
When this feature is active, the AI provider we use acts as our processor. We will name the specific provider here and on your consent screen before it is switched on. This choice is independent of your other consents — declining it does not affect your consult in any way.
Where your data is stored, and cross-border transfers
Our database (MongoDB Atlas) and backend (Railway) are configured to host your data in India, in line with IRDAI data-localisation principles, and the documents you upload are, by default, stored on our own servers rather than a third-party service.
The DPDP Act permits transfers of personal data to countries other than those the Central Government specifically restricts. Where any provider processes data outside India, we ensure the transfer is lawful under the DPDP Act (Section 16) and that sector rules — including RBI payment-data and IRDAI requirements — are respected. We will update this section if our hosting or provider locations change.
How long we keep it
We keep each type of record only for as long as we need it or a law requires, then delete or anonymise it. These rules are enforced automatically by our system. The main periods are:
Payment and financial records (and the entitlement records that evidence them) — 6 years from the end of the relevant accounting year, under the Income-tax Rules, 1962 (Rule 6F). Because we are a sole proprietorship that is not GST-registered, we do not apply GST retention; the Companies Act 8-financial-year period would apply only if and after we incorporate as a private limited company.
Case evidence (cases, documents, message threads, messages, and internal notes) — for the life of the case plus 3 years after it closes, under DPDP Act Section 17(1)(a) (data needed to enforce a legal right or claim) and our commitment to preserve the evidence your claim may depend on.
Eligibility checks and marketing leads — up to 18 months, but you can ask us to delete them at any time and we will erase them on request, since no law requires us to keep them (DPDP Act Section 8(7)).
Contact and support messages — up to 18 months, erased earlier on a deletion request.
Analytics and traffic events — up to 1 year, and erasable earlier on a deletion request or consent withdrawal.
Consent records — kept as evidence of your consent history so we can demonstrate compliance; no fixed expiry.
Authentication tokens and sessions — erased when you log out or delete your account. Notifications — erased when you delete your account.
Referral records — the referred person's contact details are stripped when they exercise deletion, while the referral relationship is kept in anonymised form only where needed to reconcile any commission tied to financial records.
When you ask us to delete your data, we erase everything we have no legal basis to keep — and instruct our processors to erase their copies — and retain only what a specific law requires (for example, tax records) under restricted access until its period ends. A deletion cannot complete while a case of yours is still open or under legal hold, because that would destroy evidence you may need; we will tell you if that is why a request is paused.
How we protect it
We take security measures appropriate to the sensitivity of your data. These include: hashing passwords (bcrypt) and never storing them in plain text; short-lived, signed access tokens with separate refresh, magic-link, verification, and password-reset tokens; strict validation and a 10 MB size limit on uploads, with server-side content sniffing and an allow-list of file types; rate limiting to blunt abuse and brute-force attempts; a strict, no-wildcard list of allowed origins with secure, same-site cookies for signed-in sessions; and audit logging of security-relevant actions (sign-in, consent, privacy requests, case changes).
Documents stored with our optional cloud provider are namespaced and served only through short-lived signed links, and our error monitoring is configured never to receive personal data. We also maintain a legal-hold safeguard: while a case is active or an ODR referral is in progress, deletion of the related evidence is blocked so nothing you may need is destroyed.
For our full security framework — including encryption in transit and at rest, access controls and session management, and our alignment with the IRDAI Information and Cyber Security Guidelines 2023 and BIS IS 19493:2025 — see our separate Security page.
No system is perfectly secure, but we work continuously to protect your data and to fix weaknesses quickly.
Your rights under the DPDP Act
The DPDP Act gives you real, enforceable rights over your personal data. You can exercise all of them from the privacy dashboard in your account, or by writing to privacy@bimahaq.com. So we can act safely we may ask you to verify your identity, and when you ask us to correct data you agree to give us accurate information.
Right to access (Section 11) — ask for a summary of the personal data we hold, why we process it, and who we share it with. The 'export' option in your privacy dashboard generates a downloadable bundle of your profile, your cases, document metadata (filename, size, type, and upload date — not the files themselves), message threads, notifications, payment records, and entitlements.
Right to correction and completion (Section 12(1)) — ask us to correct data that is wrong or misleading, or complete data that is incomplete. Update it in your account or email us.
Right to erasure (Section 12(2)) — ask us to delete your data with the 'delete my data' option or by email. Our system runs a retention-aware erasure that deletes everything we are not legally required to keep and anonymises or restricts the rest, as described in 'How long we keep it'.
Right to withdraw consent (Section 6) — withdraw at any time from the privacy dashboard, the cookie banner, or by email, as easily as you gave it.
Right of grievance redressal (Section 13) — raise a complaint with our Grievance Officer, as explained below.
Right to nominate (Section 14) — nominate another person to exercise your rights on your behalf if you are unable to (for example through incapacity) or in the event of your death. Write to privacy@bimahaq.com and we will guide you.
You can also manage your active sessions and sign out of individual devices from your account.
Children's data
Our services are intended for adults. We do not knowingly process the personal data of anyone under 18 without verifiable parental or guardian consent, as the DPDP Act (Section 9) requires. We do not track, behaviourally monitor, or serve targeted advertising to children, and we do not process children's data in ways likely to harm their well-being.
If we ever process the personal data of a minor, we first obtain verifiable consent from a parent or lawful guardian and confirm that they are an identifiable adult — through a reliable method such as a government-issued digital identity (for example DigiLocker or Aadhaar-based verification), as the DPDP Act and its Rules contemplate. A simple tick box or email is not sufficient.
If you believe a child's data has reached us without proper consent, contact privacy@bimahaq.com and we will verify the position and delete the data unless the law requires us to keep it.
Personal data breaches
If a personal data breach occurs, we act without undue delay. We report cyber-security incidents to CERT-In (the Indian Computer Emergency Response Team) within 6 hours of becoming aware of them, as the CERT-In Directions (2022) require. We also notify the affected individuals and the Data Protection Board of India of personal-data breaches as required by the DPDP Act and its Rules — giving details of what happened, the likely consequences, and the steps we are taking to contain and remedy it.
Grievance Officer and escalation to the Data Protection Board
If you have any complaint about how we handle your personal data, contact our Grievance Officer at privacy@bimahaq.com with the subject line 'DPDP Grievance', or by post at WeWork Rajeha Woods, 1st to 5th, BLD No. 8, Sr. No. 222/1, Central Avenue, Kalyani Nagar, Pune – 411006.
Our response times depend on what you ask for: we respond to data-rights requests (access, correction, erasure, and consent withdrawal) within 30 days, and we acknowledge and address privacy grievances within 7 days — in each case within the period the DPDP Act and its Rules require, and without undue delay.
If we do not resolve your complaint or you are not satisfied with our response, you can escalate to the Data Protection Board of India. The Board can inquire into non-compliance and issue binding directions and penalties; you do not need to prove financial harm to complain. We will provide current details for reaching the Board on request and keep this policy updated as the Board's channels are published.
For visitors in the EU or EEA (GDPR)
If you are in the EU or EEA, and to the extent GDPR applies, Articles 6 and 13 set the lawful bases we rely on (principally your consent and the performance of a contract with you), and Articles 15 to 22 give you rights to access, rectify, erase, port, restrict, and object. To exercise these, contact privacy@bimahaq.com. Our primary framework, however, is India's DPDP Act.
For residents of California (CCPA)
If you are a California resident, and to the extent the CCPA (§1798.100 to §1798.130) applies, you have the right to know what personal information we collect, the right to request deletion, and the right to opt out of any sale of personal information. We do not sell personal information. To exercise these rights, contact privacy@bimahaq.com.
Changes to this policy
We may update this policy as our services or the law change. When we make a material change — for example adding a new purpose or a new processor — we will update this page and, where the change affects how we use data you have already given us, tell you and seek fresh consent where required. We will not rely on a quiet, backdated change to justify a new use of your data. The 'last updated' date at the top of this page shows when it last changed.
Contact
For any privacy question, request, or complaint, write to our Grievance Officer at privacy@bimahaq.com; for general queries, use info@bimahaq.com. This policy is written in plain English so you can understand it without a lawyer.
Questions about this page?
Write to info@bimahaq.com. We respond within one working day.