Our Policies
Privacy Policy
Effective Date: 20 August 2026 | Last Updated: 20 August 2026
1. Introduction
These Terms of Use ("Terms") govern access to and use of Wellnine (the "App" or "Service"), provided by Wellfront Technologies Private Limited ("Company", "we", "us", or "our"). By registering your hospital/organization for Wellnine, or by creating a personal account, accepting a join request, or otherwise using the App as an Manager or Staff user, you agree to be bound by these Terms and by our Privacy Policy, which is incorporated by reference. If you are agreeing to these Terms on behalf of a hospital or other organization ("Organization"), you represent that you have the authority to bind that Organization, and "you" refers to both you individually and the Organization. If you do not agree to these Terms, do not access or use Wellnine.
2. Scope and Applicability
This Policy applies to:
Manager users - hospital staff who manage schedules, approve requests, and administer teams within Wellnine.
Staff users - hospital employees who view schedules, submit swap/leave requests, and use Wellnine day-to-day.
Hospital administrators who onboard their organization via the Wellnine web application.
Wellnine is a business-to-business (B2B) tool provisioned by a hospital or healthcare facility (the "Organization") to its employees. Your Organization determines who is invited to use Wellnine, what department/role data is attached to your account, and retains certain administrative rights over your account within the platform (see Section 7).
Key Definitions
"Personal Data" means any data about an individual who is identifiable by or in relation to such data.
"Data Principal" means the individual to whom the personal data relates i.e., you, the Wellnine user.
"Data Fiduciary" means the entity that determines the purpose and means of processing personal data in most respects, this is Wellfront Technologies Private Limited as the provider of Wellnine. In relation to schedule, role, and department data, your Organization (the hospital) may also act as a Data Fiduciary or joint controller for that data.
"Processing" means any operation performed on personal data, including collection, storage, use, sharing, and deletion.
Information We Collect
4.1 Information You Provide Directly
Account & authentication data: mobile number and/or email address, and one-time password (OTP) verification records.
Profile data: first name, last name, gender, date of birth (if provided), profile photo (if provided).
Employment data: Employee ID, department, role/designation (Incharge or Staff), hospital/organization code, join date.
Emergency contact information (if you choose to provide it).
Two-factor authentication data: your selected 2FA method (SMS/text, authenticator app, or email) and associated verification data.
Notes content: any text, reminders, or handoff notes you create within the Notes feature.
Request data: swap request and leave/time-off request details, including dates, shift types, reasons provided, and colleague selections.
Communications with Riva, our in-app AI assistant, including questions you ask and the context Riva uses to respond (e.g., your own schedule and overtime data). Riva is designed to assist with non-medical, operational, work-related queries only, and you will be asked to provide consent before your first use.
Support and grievance communications you send to us.
4.2 Information Collected Automatically
Device information: device type, operating system, unique device identifiers, mobile network information.
Usage data: app interactions, feature usage, session duration, crash logs, and diagnostic data.
Push notification tokens, used to deliver schedule, request, and shift-related alerts.
Approximate location data, only if and to the extent required for a specific feature (if applicable).
4.3 Information From Your Organization
Your Organization (the hospital) provides or confirms certain data when onboarding you, including your assigned department, role, reporting Incharge, and scheduling rules that apply to you (e.g., maximum shifts, rest-hour requirements). Your Organization also creates, publishes, and modifies schedules that are then visible to you within the App.
4.4 Information We Do Not Intentionally Collect
Your Organization (the Wellnine is a workforce-scheduling tool. It is not designed to collect patient health information, medical records, or any protected health information (PHI) belonging to third parties. Please do not enter patient-identifiable information into any field of the App, including Notes or Riva conversations.) provides or confirms certain data when onboarding you, including your assigned department, role, reporting Incharge, and scheduling rules that apply to you (e.g., maximum shifts, rest-hour requirements). Your Organization also creates, publishes, and modifies schedules that are then visible to you within the App.
How We Use Your Information
To create and manage your Wellnine account and verify your identity (OTP, 2FA).
To connect you to your Organization and reflect your assigned role and department.
To generate, display, and update work schedules, and to apply your Organization's scheduling rules.
To process and route swap requests, leave requests, and their approvals/rejections between you, your colleagues, and your Incharge.
To send notifications relevant to your role (schedule publication, shift changes, request status updates, reminders), based on your notification settings.
To provide Riva's assistant features, strictly for non-medical, operational scheduling support, and only after you provide consent.
To maintain security, detect fraud or misuse, and enforce our Terms of Use.
To analyze aggregated, de-identified usage patterns to improve the App.
To comply with legal obligations and respond to lawful requests from authorities.
Legal Basis for Processing (Consent)
Under the DPDP Act, we process your personal data on the basis of your consent, given through clear affirmative action (e.g., completing signup, accepting the Riva consent screen). Where required, we provide a notice describing what data is collected and why, in or before the relevant consent request.
You may withdraw consent at any time by contacting us or your Organization's administrator, subject to Section 10. Withdrawing consent may limit or prevent your ability to use certain features (for example, Riva) or the App as a whole, since core scheduling functionality depends on processing your employment and schedule data.
Certain limited processing (e.g., security logging, fraud prevention, compliance with law) may continue on grounds permitted under the DPDP Act even after consent is withdrawn, as legally permitted.
How We Share Your Information
7.1 Within Your Organization
Your Incharge can view your schedule, shift history, submitted requests, and basic profile/employment data as needed to manage staffing.
Colleagues within your department can see your name, role, and shift assignment where relevant to coverage and swap requests (e.g., "Colleagues on shift").
Notes you create are private to you and are not visible to your Incharge or colleagues, unless a future version of the App introduces shared notes (in which case this Policy will be updated).
Your Organization's designated administrators may access account and role data for administrative purposes (e.g., approving join requests, managing departments).
7.2 Service Providers
We share data with third-party service providers who help us operate Wellnine, under contractual confidentiality and data-protection obligations, including (as applicable):
Cloud hosting and infrastructure providers: [Insert provider, e.g., AWS/GCP/Azure region]
SMS/OTP and communication gateway providers: [Insert provider]
Push notification services: [Insert provider, e.g., Firebase Cloud Messaging/APNs]
AI/processing infrastructure used to power Riva: [Insert provider/model information]
Analytics and crash-reporting tools: [Insert provider, if any]
7.3 Legal and Safety Disclosures
We may disclose personal data if required by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect the rights, property, or safety of Wellnine, our users, your Organization, or the public.
7.4 Business Transfers
If Wellnine or Wellfront Technologies Private limited is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or a successor policy of no lesser protection.
7.5 What We Do Not Do
We do not sell your personal data.
We do not share your data with advertisers or use it for third-party advertising purposes.
Data Retention
We retain personal data for as long as your account is active with your Organization, and thereafter for a period necessary to fulfil the purposes described in this Policy, resolve disputes, and comply with legal or contractual obligations. Indicative retention periods:
Account and profile data: for the duration of your employment with the Organization plus 90 days after account deactivation.
Schedule, shift, and request history: 3 years for record-keeping and dispute-resolution purposes, or as required by applicable labor/employment law.
Notes: retained until you delete them, or until account deletion.
Riva conversation logs: [Insert Retention Period].
OTP and authentication logs: retained for a short period strictly for security purposes, per .
On request, and where not otherwise required by law or legitimate business need, we will delete or anonymize your personal data. See Section 10 for how to exercise this right.
Data Retention
We implement reasonable technical and organizational security measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:
Encryption of data in transit (e.g., TLS/HTTPS).
[Confirm: encryption of data at rest]
OTP-based authentication and optional multi-factor authentication (SMS, authenticator app, email).
Role-based access controls, so data is visible only to appropriately authorized users within your Organization.
Audit trails and access logs for administrative actions (e.g., schedule publication, overrides, and request approvals), so changes can be traced to the user who made them.
Regular security review of our infrastructure and access logs.
No method of transmission or storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.
Your Rights as a Data Principal
Under the DPDP Act, subject to applicable exceptions, you have the right to:
Access: request a summary of the personal data we hold about you and the processing activities carried out.
Correction and updating: request correction of inaccurate or incomplete personal data, and updating of personal data relevant to the purposes of processing.
Erasure: request erasure of personal data that is no longer necessary for the purpose it was collected, subject to legal retention requirements.
Grievance redressal: raise a complaint about how your personal data has been processed (see Section 11).
Nominate: nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
Withdraw consent: withdraw previously given consent at any time (see Section 6).
To exercise these rights, contact us using the details in Section 17, or reach out to your Organization's administrator for data that is jointly managed with your employer (such as schedule records). We will respond within the timeframe required under applicable law.
Grievance Redressal Mechanism
In accordance with the DPDP Act, we have designated a Grievance Officer to address any concerns or complaints regarding the processing of your personal data:
Grievance Officer- Milan Ghoghari
Email- info@getwellnine.com
Address- 22 SHIV NAGAR 1SOC KATARGAM SURAT Surat City Gujarat 395004 Katargam Surat India
Response time- We aim to acknowledge grievances within 7 days and resolve them within 30 days.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India, once constituted and operational under the DPDP Act, or to any other applicable regulatory authority.
Children's Privacy
Wellnine is intended for use by working adults employed by or affiliated with a hospital/healthcare Organization. It is not directed at, and we do not knowingly collect personal data from, individuals under the age of 18. If we become aware that we have inadvertently collected data from a minor, we will take steps to delete it.
Cross-Border Data Transfer
Your personal data may be stored and processed in [Insert Data Storage Location(s), e.g., "data centers located in India" or "India and [Country]"]. Where personal data is transferred outside India, we will do so in accordance with the DPDP Act and any restrictions notified by the Central Government from time to time.
Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act, including a description of the breach, likely consequences, and measures taken to mitigate harm.
Third-Party Links and Services
Wellnine may contain links to third-party resources not operated by us. This Policy does not apply to those third-party resources, and we encourage you to review their respective privacy policies.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal requirements. Material changes will be notified to you via in-app notification and/or email prior to taking effect. Continued use of Wellnine after changes take effect constitutes acceptance of the updated Policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Wellfront Technologies Private Limited
22 SHIV NAGAR 1SOC KATARGAM SURAT Surat City Gujarat 395004 Katargam Surat India
Email: info@getwellnine.com