Privacy Policy
Uber Diagnostics Private Limited, operating as Cardiotrack
Effective 10 August 2026
1. Who we are
Cardiotrack is a brand of Uber Diagnostics Private Limited, a company incorporated in India with its registered office in Bengaluru, Karnataka. In this policy, "Cardiotrack", "we", "us" and "our" refer to Uber Diagnostics Private Limited.
We operate a health screening platform. Through it, insurers, diagnostic centres, hospitals and clinicians order and receive medical examinations, electrocardiograms, treadmill tests, medical examination reports and related health assessments, many of which are carried out at the individual's home.
This policy explains what personal data we collect, why we process it, who we share it with, how long we keep it and what rights you have. It is written to meet our obligations under the Digital Personal Data Protection Act 2023 and the Information Technology Act 2000 and the rules made under them.
2. Two different roles, and why it matters to you
Our role changes depending on how your data reached us, and this affects who you should approach about it.
When an insurer, employer, hospital or diagnostic centre instructs us, for example when a life insurer orders a pre policy medical examination on an applicant, that organisation decides why and how your data is processed. Under the Digital Personal Data Protection Act 2023 they are the Data Fiduciary and we act as a Data Processor on their behalf. We process your data only on their documented instructions. Requests to access, correct or erase that data are best directed to them, and we will support them in answering you.
When you deal with us directly, for example through our consumer application, our website, or when you contact us, we are the Data Fiduciary and this policy governs that processing in full.
3. Personal data we collect
Identity and contact data. Name, date of birth, gender, postal address, telephone number, email address, and where required by the organisation instructing the examination, a government identifier for verification.
Health data. This is the core of what we handle and we treat it accordingly. It includes electrocardiogram traces and their interpretation, cardiac risk assessment scores, treadmill test results, vital signs, height, weight and other measurements, medical history and declarations you give during an examination, images and documents captured during an examination, and any report generated from these.
Examination and appointment data. Appointment times, the location of the examination, the identity of the technician or physician involved, consent records, and the audit trail of who accessed a record and when.
Technical data. When you use our website or application we collect device type, operating system, browser type, IP address, and usage information through cookies and similar technologies.
We do not knowingly collect data from anyone under 18 except where an examination has been lawfully ordered and consent has been given by a parent or lawful guardian.
4. How we collect it
Directly from you during an examination or through our application. From the insurer, employer, hospital, diagnostic centre or clinician who ordered the examination. From the connected medical devices used during the examination, which upload readings into the platform. And automatically from your device when you use our website or application.
5. Why we process it, and on what basis
We process personal data to schedule and carry out the examination you or a third party has requested, to generate and deliver the resulting report to the organisation entitled to receive it, to apply artificial intelligence models that interpret readings and produce risk scores, to verify the identity of the person examined and the integrity of the record, to maintain an audit trail for regulatory and contractual purposes, to provide customer support, to detect and prevent fraud and misuse, and to meet legal, regulatory and tax obligations.
Where we act as a Data Fiduciary we rely on your consent, given at or before the point of collection, and on the legitimate uses permitted under the Digital Personal Data Protection Act 2023. Where we act as a Data Processor, the organisation instructing us is responsible for obtaining your consent.
We do not sell personal data. We do not use your health data for advertising.
6. Artificial intelligence
Our platform uses machine learning models to interpret readings such as electrocardiograms and to produce structured findings and risk scores. These outputs are clinical support tools. Where a reading is abnormal or borderline it is escalated for review by a qualified clinician. An automated output is not by itself a diagnosis and is not by itself a decision about you.
7. Who we share it with
The organisation that ordered the examination, which receives the report and the structured data associated with it. Clinicians and technicians involved in carrying out or reviewing the examination. Service providers who host, secure or support the platform, under written contracts that restrict them to processing on our instructions. Professional advisers where necessary. And regulators, courts or law enforcement where we are required to disclose by law.
We do not share personal data with any other party without a lawful basis for doing so.
8. Where your data is stored
Personal data collected through the platform is stored on infrastructure located in India. Where any transfer outside India is necessary, we carry it out only as permitted under applicable Indian law and under contractual protections.
9. How long we keep it
We retain personal data for as long as necessary for the purpose it was collected for, and thereafter for as long as required by law, by regulatory expectations applying to insurance and healthcare records, or for the establishment or defence of legal claims. Where we act as a Data Processor, retention follows the instructions of the organisation that engaged us. When data is no longer required it is deleted or irreversibly anonymised.
10. How we protect it
We hold ISO/IEC 27001 certification for our information security management system. Data is encrypted in transit and at rest. Access is role based, granted on a need to know basis and logged, and the platform is designed so that one client organisation cannot see another's data. Reports are delivered through the platform, by application programming interface or by tokenised link rather than as loose attachments. We maintain an incident response process and will notify the Data Protection Board of India and affected individuals of a personal data breach as required by law.
11. Your rights
Subject to the conditions in the Digital Personal Data Protection Act 2023, you have the right to obtain confirmation of and access to your personal data, to have inaccurate or misleading data corrected and incomplete data completed, to have your data erased where it is no longer needed and no legal obligation requires us to keep it, to nominate another individual to exercise your rights in the event of your death or incapacity, and to a readily available means of grievance redressal.
Where we act as a Data Processor, please direct these requests to the organisation that ordered your examination. We will assist them in responding.
You may withdraw consent at any time where our processing rests on consent. Withdrawal does not affect processing already carried out, and it may mean we can no longer provide a service to you.
12. Cookies
Our website uses cookies and similar technologies for functionality, security and analytics. You can control cookies through your browser settings. Blocking some cookies may affect how parts of the site work.
13. Grievance redressal
If you have a question or a complaint about how we handle your personal data, contact our Grievance Officer.
Grievance Officer
Uber Diagnostics Private Limited, operating as Cardiotrack
Email: sales@cardiotrack.io
Address: 1443, 4th Floor, 80 Feet Road, Nagarbhavi 1st Stage, Chandra Layout, Bengaluru 560072, Karnataka, India
Telephone: +91 80 6916 5400
We will acknowledge your complaint and respond within the period required under applicable law. If you are not satisfied with our response you may complain to the Data Protection Board of India.
14. Changes to this policy
We may update this policy. The current version is always published at this address, and the effective date at the top shows when it last changed. Where a change is significant we will take reasonable steps to bring it to your attention.