Privacy & Security

Privacy Policy

Momivara — Clinic Management for Gynaecology & Paediatrics. Plainly stated, and accurate to what the app actually does.

Last Updated: 19 July 2026
Version 2.0
Data stored in India (asia-south1)
DPDP Act 2023 Data Residency: India No AI Training on Your Data Not a Medical Device

1Introduction & Who We Are

Momivara is a clinic management application for gynaecology, obstetric and paediatric practices in India. It is operated by Trivartha, based in Vadodara, Gujarat, India ("Trivartha", "we", "our", "us").

This Privacy Policy explains what information the Momivara mobile application and associated services (together, the "App" or "Services") collect, why we collect it, who it is shared with, how long it is kept, and what you can do about it.

Our commitment in this document: every statement below describes what the App actually does today. We have deliberately removed compliance claims we cannot substantiate. We would rather publish a narrower policy that is true than a broader one that is not.

1.1 Who Uses the App

  • Moms / Patients — pregnant women, new mothers and parents attending a clinic that uses Momivara.
  • Doctors — registered medical practitioners running a gynaecology or paediatric clinic on the platform.
  • Clinic Staff — receptionists, nurses and administrative staff added by a doctor.
  • Clinic Owners / Administrators — the account that owns a clinic workspace.

1.2 Scope of This Policy

The Services are offered to clinics and patients in India. This Policy is written primarily against India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 with its rules, together with the Google Play User Data Policy.

We do not currently target, market to, or knowingly onboard clinics or patients in the European Economic Area, the United Kingdom, or the United States. If you access the App from outside India, you do so on your own initiative, and you are responsible for compliance with your local law. Section 19 explains where your data is stored.

What this Policy is not. This Policy is not medical advice, and it does not create a doctor–patient relationship between you and Trivartha. Trivartha does not practise medicine. See Sections 26 to 29.

1.3 Acceptance

By downloading, installing, registering for, or using the App, you confirm that you have read and understood this Policy. If you do not agree with it, please do not use the App and, if you already have an account, delete it as described in Section 21.

2Who Controls Your Data

This is the most important section in this Policy, because it determines who is answerable to you for what. Momivara is software supplied to clinics. Most of the medical information in the App is created, owned and controlled by your clinic, not by us.

2.1 Two Different Roles

Category of dataData Fiduciary (decides why & how)Our role
Clinical records, prescriptions, vitals, diagnoses, lab reports, scan reports, visit history, invoices, vaccination records, growth measurementsYour clinic (the treating doctor / clinic entity)Data Processor acting on the clinic's instructions
Your account, login credentials, profile, and app-level settingsTrivarthaData Fiduciary
Personal wellness data you create for yourself — contraction timer, personal gallery, medicine reminders, personal notes, emergency contactsTrivartha (on your instruction)Data Fiduciary
Messages you send in chat and community groupsShared — you author it, the clinic administers its groupsData Fiduciary for delivery and storage

2.2 What This Means in Practice

  • If you want a clinical record corrected or erased — a wrong diagnosis, an incorrect vital, a note attributed to the wrong patient — that request goes to your clinic. The clinic decides, because the clinic is the treating provider and the keeper of the medical record. We will facilitate and pass on such requests, and we will act on the clinic's lawful instruction.
  • If you want your account deleted, that request comes to us, and we handle it directly (Section 21).
  • We do not read, review, verify, correct, second-guess, or clinically validate anything a doctor or staff member enters. We have no clinical staff and we make no clinical judgements.
  • We do not decide who your doctor is, what treatment you receive, what you are charged, or what is written in your file.
Plainly: Trivartha builds and runs the software. Your clinic practises the medicine and owns the medical record. Claims about diagnosis, treatment, clinical accuracy, fees, or professional conduct are matters between you and your clinic.

2.3 Processing on Clinic Instruction

When acting as a processor for a clinic, we process personal data only to provide the Services, keep them secure and reliable, comply with law, and follow the clinic's lawful documented instructions. We do not use clinic-controlled clinical data for our own purposes, and we never use it to train machine learning models (Section 16).

3Information We Collect

3.1 Account & Identity Information

  • Name, mobile number, email address
  • Password (handled by Firebase Authentication — see Section 18.2; we never see or store your password)
  • Google account identifier and basic profile, if you choose Google Sign-In
  • Profile photograph, if you upload one
  • Role (Mom, Doctor, Staff, Owner) and clinic association
  • Date of birth and address, where provided

3.2 Health & Clinical Information

Health data is sensitive personal information and we treat it accordingly. Depending on your role and your clinic's use of the App, this may include:

  • Maternity & gynaecology: last menstrual period, expected date of delivery, gestational week, obstetric history (gravida/para), blood group, weight, blood pressure, blood sugar, SpO₂, temperature, pulse, antenatal visit notes, prescriptions, scan and lab reports, delivery and postnatal details
  • Paediatrics: the child's name, date of birth, sex, birth weight, growth measurements (weight, height, head circumference), vaccination schedule and administered doses, paediatric clinical notes and prescriptions
  • Self-tracked wellness data: contraction timings, medicine reminders, kick counts, personal symptom notes and similar entries you record for yourself
  • Documents you or your clinic upload: lab reports, ultrasound images and reports, discharge summaries, and similar files

3.3 Clinic & Operational Information

  • Clinic name, code, address, logo, branding and clinic type (gynaecology or paediatric)
  • Doctor profile, qualifications and specialisation as self-declared by the doctor
  • Appointments, queue tokens, consultation slots, shifts, leave and staff attendance
  • Invoices raised by the clinic, amounts, line items and payment status

3.4 Content You Create

  • Chat messages between you and your clinic
  • Community group messages, polls, reactions and voice notes
  • Photographs and videos you add to your personal gallery
  • Notes, feedback and support requests

3.5 Device & Technical Information

  • Device model, operating system version, app version and language
  • Firebase Cloud Messaging token, used to deliver push notifications to your device
  • Anonymous installation identifier used by Firebase Analytics
  • Crash reports, stack traces and diagnostic logs (Firebase Crashlytics)
  • Approximate region inferred from network address by our infrastructure provider

3.6 Permissions the App Requests

Android will ask you before granting any of these. You may refuse or later revoke any of them in system settings; only the specific feature stops working.

PermissionWhy we askIf you decline
CameraScanning clinic QR codes, capturing report photographs, and the Baby Position Monitor (Section 7)QR check-in, photo capture and the monitor are unavailable
Photos & MediaAttaching existing reports, images and profile photographsYou cannot attach files from your device
MicrophoneRecording voice notes in community groups onlyYou can still send text; voice notes are unavailable
Precise LocationAttaching your location to an Emergency SOS alert (Section 8)SOS still sends, without location
NotificationsAppointment reminders, queue updates, messages, medicine remindersYou receive no push notifications
Phone (call)Dialling your clinic or an emergency contact when you tap a call buttonNumbers open in your dialler instead
Exact alarmsFiring medicine and appointment reminders at the correct timeReminders may be delayed by the operating system
BiometricOptional fingerprint or face unlock for the AppPassword login only
We do not collect: your contacts list, your SMS or call logs, your browsing history, your keystrokes, your device advertising identifier for ad targeting, or continuous background location. The App does not track your location when it is closed or in the background.

4How We Use Information

4.1 To Deliver the Service

  • Create and authenticate your account, and keep you signed in
  • Connect you to your clinic and show you the right workspace for your role
  • Book, reschedule and cancel appointments; manage the live consultation queue and tokens
  • Record and display clinical visits, prescriptions, vitals, reports, growth charts and vaccination schedules
  • Raise and display invoices, and record the payment status your clinic or you mark
  • Deliver messages between you and your clinic and within community groups
  • Send reminders for appointments, medicines and vaccination due dates

4.2 To Keep the Service Working & Safe

  • Diagnose crashes and errors, and fix defects
  • Detect and prevent misuse, fraud, unauthorised access and abuse
  • Enforce clinic isolation and role-based access rules
  • Maintain backups and restore data after a failure
  • Understand which features are used, in aggregate, to decide what to build next

4.3 To Communicate With You

  • Service messages: appointment confirmations, queue status, invoices, security notices, policy changes
  • Support responses when you contact us

4.4 To Comply With Law

  • Respond to lawful requests from courts, regulators and law enforcement
  • Retain records where a statute or the clinic's professional obligations require it
  • Establish, exercise or defend legal claims
What we never do with your information: we do not sell it, we do not rent it, we do not share it with data brokers, we do not use it for behavioural advertising, and we do not use it to train artificial intelligence or machine learning models. See Section 16.

5Legal Basis & Consent

5.1 Consent Under the DPDP Act

Under the DPDP Act, we process your personal data on the basis of your consent, which must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. You give that consent when you register and when you enable a specific feature.

5.2 Granular Consent

Consent is requested feature by feature, not as one blanket approval:

  • Registration and clinic linkage — required to use the App at all
  • Camera, microphone, location and notifications — each requested separately, at the moment the feature is first used
  • Baby Position Monitor — requires a distinct acknowledgement of its limits (Section 7)
  • Emergency SOS — requires you to nominate contacts and accept that location will be shared
  • Community participation — optional; you may use the App without joining any group

5.3 Certain Legitimate Uses

The DPDP Act permits processing without separate consent for certain legitimate uses. We rely on these in narrow circumstances: where you voluntarily provide data for a purpose you have asked us to fulfil; for compliance with law or a court order; and to respond to a medical emergency threatening your life or health, or to provide medical treatment during an epidemic or threat to public health.

5.4 Withdrawing Consent

You may withdraw consent at any time, with the same ease with which you gave it — by revoking a permission in system settings, disabling a feature in the App, or deleting your account. Withdrawal is not retroactive: it does not affect processing already lawfully carried out.

Consequence of withdrawal. If you withdraw consent to processing that is essential to the Service, we may not be able to continue providing it to you. Separately, your clinic may still lawfully retain your medical record where professional or statutory record-keeping obligations require it — see Section 17.

5.5 Consent Given by Your Clinic

Where a clinic enters your data into the App, the clinic is responsible for having obtained your consent, or for having another lawful basis, before doing so. That responsibility sits with the clinic as the treating provider (Section 28).

6Children's & Infant Data

Read this if you use the paediatric features. Momivara's paediatric module exists specifically to record health information about babies and children. This section explains exactly how that works and who is responsible.

6.1 Children Do Not Hold Accounts

Account holders must be 18 years or older. Children cannot register, log in, or use the App independently. There is no interface through which a child interacts with Momivara.

6.2 Data About Children, Provided by Adults

Where the App holds information about a child, that information is entered by an adult — the child's parent or lawful guardian, or a treating clinician at the clinic. Such information may include the child's name, date of birth, sex, birth weight, growth measurements (weight, height, head circumference), vaccination schedule and doses administered, clinical notes, prescriptions and reports.

6.3 Parental & Guardian Consent

Section 9 of the DPDP Act requires verifiable consent from a parent or lawful guardian before processing the personal data of a child. When you add a child in the App, you confirm that you are that child's parent or lawful guardian and that you consent, on the child's behalf, to the processing described in this Policy. Where a clinic enters child data, the clinic is responsible for having obtained guardian consent.

6.4 Protections Specific to Children's Data

Consistent with Section 9(3) of the DPDP Act, in respect of children's data we do not:

  • Undertake tracking or behavioural monitoring of children
  • Direct any advertising at children — the App carries no advertising at all
  • Profile children, or use their data for any purpose beyond the clinical and record-keeping purposes described here
  • Use children's data to train any model (Section 16)

6.5 Access to a Child's Record

A child's record is visible to: the parent or guardian account linked to that child; the treating paediatric clinic and its authorised staff; and no one else. A mother linked to both a gynaecology clinic and a paediatric clinic will see each record only within the corresponding clinic workspace — the two do not merge.

6.6 Withdrawing Consent or Deleting a Child's Data

A parent or guardian may withdraw consent and request deletion of a child's data at any time, using the contact details in Section 33. Deletion of the data we hold on your instruction is subject to the clinic's independent medical record-retention obligations (Section 17.3).

6.7 If a Child Registered Without Authorisation

If we learn that someone under 18 has created an account, we will disable it and delete the associated personal data promptly. If you believe this has happened, contact us at once (Section 33).

7Baby Position Monitor — Camera Feature

CRITICAL SAFETY NOTICE — READ IN FULL BEFORE USE. The Baby Position Monitor is a convenience aid only. It is NOT a medical device. It is NOT a breathing, apnea, respiration, heart-rate, oxygen or SIDS-prevention monitor. It cannot detect whether a baby is breathing and it cannot prevent Sudden Infant Death Syndrome or any other harm. It is not a substitute for adult supervision.

7.1 What the Feature Does

When you open the Baby Position Monitor and grant camera access, the App uses your device's camera to look at the sleeping area and applies on-device Google ML Kit face detection and pose detection to estimate whether the baby appears to have rolled into a face-down position. If it estimates that, it sounds an alarm on your device to draw your attention so that you can check on your baby.

7.2 Everything Stays on Your Device

No video leaves your phone. Camera frames are analysed in memory on your device and discarded immediately. The feature does not record video, does not save images, does not upload frames, does not stream anything, and does not transmit any camera data to Trivartha, to your clinic, to Google, or to anyone else. No recording is created and nothing is retained. When you close the monitor, the camera stops and no trace of what it saw remains.

The ML Kit models run entirely offline on your device. They do not learn from your baby, do not adapt, and send nothing anywhere.

7.3 It Will Sometimes Be Wrong

Computer vision on a consumer phone camera is inherently unreliable. The monitor may fail to detect a genuine face-down position, and may raise an alarm when nothing is wrong. Circumstances in which it will not work correctly include, without limitation:

  • Poor, changing, or very low light; darkness
  • The baby being covered by a blanket, swaddle, toy or bedding
  • Camera angle, distance, obstruction, or a moved or knocked phone
  • Phone battery depletion, overheating, or the operating system suspending or killing the App
  • The camera being claimed by another app, an incoming call, or a system interruption
  • Silent mode, muted volume, connected headphones, or Do Not Disturb suppressing the alarm
  • Device crash, restart, or storage or memory pressure

7.4 Your Responsibilities When Using It

  • Continue to follow safe-sleep guidance from your paediatrician and from recognised bodies such as the Indian Academy of Paediatrics — place babies on their back to sleep, on a firm flat surface, clear of soft bedding.
  • Never leave an infant unattended in reliance on this feature.
  • Never treat the absence of an alarm as confirmation that your baby is safe, breathing, or in a safe position.
  • Ensure the device is placed safely, cannot fall into the cot, and that cords are out of reach.
  • Seek immediate medical help for any concern about your baby's breathing or condition. Call your doctor or emergency services — do not consult this App.
Assumption of risk. You use the Baby Position Monitor entirely at your own risk. To the maximum extent permitted by law, Trivartha accepts no liability for any injury, harm, loss or damage arising from use of, reliance on, failure of, delay in, or absence of an alert from this feature. If you are not comfortable with these limitations, do not use it.

8Emergency SOS & Location

MOMIVARA IS NOT AN EMERGENCY SERVICE. The SOS feature does not contact ambulances, police, fire services, 108, 112, or any government emergency response system. It sends an in-app alert and message to your clinic and your nominated contacts. In a real emergency, call 108 or 112 immediately.

8.1 What SOS Collects and Sends

When you trigger an SOS alert, and only then, the App:

  • Requests a precise GPS location fix from your device
  • Converts those coordinates into a readable street address using your device's platform geocoding service (provided by Google Play Services on Android)
  • Sends an alert containing your name, your message if any, the timestamp, your coordinates, the resolved address and a map link to your linked clinic and to the emergency contacts you have nominated

8.2 Location Is Not Collected Otherwise

The App does not collect location in the background, does not track your movements, does not build a location history, and does not access location when the App is closed. Location is requested only at the moment you press SOS. If you decline the permission or no fix is available within roughly fifteen seconds, the alert is still sent — without location.

8.3 Third-Party Geocoding

Converting coordinates into an address requires sending those coordinates to the device's geocoding provider (Google). That transfer is governed by Google's privacy policy. If you prefer this not to happen, decline the location permission; SOS will still function without an address.

8.4 Delivery Is Not Guaranteed

An SOS alert depends on your network connectivity, your device, notification permissions, battery state, the recipient's device and connectivity, and the availability of third-party infrastructure. Alerts may be delayed, undelivered, unseen or unanswered. Your clinic is under no obligation to us, and may be under no obligation to you, to monitor alerts at any particular time, including outside clinic hours.

Do not rely on SOS as your emergency plan. To the maximum extent permitted by law, Trivartha is not liable for any harm arising from a delayed, failed, undelivered, unseen or unanswered SOS alert, or from reliance on this feature in place of contacting emergency services.

8.5 Retention of Alerts

SOS alerts, including the location attached, are retained in the clinic's records so that the clinic has a history of what was raised and how it was handled. You may request deletion under Section 20.

9Payments, Invoices & UPI

Trivartha never touches your money for clinic services. We are not a payment gateway, a payment aggregator, a payment system operator, or a merchant of record for any clinic. We do not hold, route, collect, escrow or settle funds between you and your clinic.

9.1 Clinic Invoices and UPI

Clinics may raise invoices in the App for consultations and services. Payment happens outside the App, directly between you and the clinic, typically by UPI to the clinic's own UPI ID or by cash at the counter.

  • We store the clinic's UPI identifier as the clinic has entered it, and display it to you.
  • We store invoice line items, amounts and a payment status flag.
  • Marking an invoice "paid" is a record-keeping action taken by you or by clinic staff. It is an honour-system marker. The App does not verify with any bank or payment network that money actually moved, and marking an invoice paid is not proof of payment.
  • We never collect, see or store your UPI PIN, bank credentials, card numbers, CVV, or any payment instrument details. They are never entered into the App.

9.2 Billing Disputes Are Between You and Your Clinic

Fees, refunds, receipts, tax invoices, GST treatment and any dispute about an amount charged are matters between you and your clinic. We have no visibility into your bank or UPI account, cannot reverse a transaction, cannot confirm or deny that a payment occurred, and cannot adjudicate a billing dispute. Please raise these with your clinic directly.

9.3 Momivara Subscriptions (Clinics)

Where a clinic subscribes to Momivara, that subscription is processed through Google Play Billing. Google collects and processes the payment; we receive only the subscription status, product identifier, purchase token and validity dates needed to activate the plan. We never receive card or bank details. Refunds for Play Store purchases follow Google Play's refund policy.

9.4 Records

Invoice and subscription records are retained as described in Section 17, including where retention is required for tax or accounting purposes.

10Messaging, Community & Your Content

10.1 Direct Chat With Your Clinic

Messages between you and your clinic are stored on our infrastructure so that both sides can see the conversation history and so it survives a device change. They are visible to you and to authorised personnel at your clinic, which may include clinic staff and not only the doctor (Section 24).

Chat is not a consultation and not an emergency channel. Do not use chat to report an emergency or an urgent clinical deterioration. There is no guaranteed response time. Messages are not end-to-end encrypted — they are encrypted in transit and at rest, but they are readable by the platform in the sense that they are not cryptographically opaque to us.

10.2 Community Groups

Clinics may run community groups for their patients. Content you post in a group — text, images, polls, reactions and voice notes — is visible to every other member of that group and to the group's administrators. Voice notes are recorded on your device and uploaded to our storage for playback by group members.

Anything you post in a group is disclosed to other patients. Please do not post information about your own health, your child's health, or anyone else's health that you would not want other members to see, save, screenshot or repeat. We cannot retrieve or unshare what another member has already seen or copied.

10.3 Your Responsibilities for Content

You must not post content that is unlawful, defamatory, obscene, harassing, infringing, misleading as to medical fact, or that discloses another person's personal or health data without their consent. You are responsible for what you post.

10.4 Moderation

Group administrators at your clinic may remove content, mute or remove members, and delete groups. We may also remove content or suspend accounts where we believe, in our reasonable judgement, that content is unlawful or violates this Policy or our terms. We are not obliged to pre-screen or monitor content, and we do not do so systematically. We are an intermediary in respect of user content and claim the protections available to intermediaries under Indian law.

10.5 Licence to Operate the Service

You retain ownership of the content you create. You grant Trivartha a limited, non-exclusive, royalty-free licence to host, store, back up, transmit and display that content solely for the purpose of operating the Services for you and the people you have shared it with. This licence ends when the content is deleted, except for copies in backups pending their expiry. We do not use your content for marketing, promotion or model training.

11Notifications

11.1 What We Send

  • Appointments: confirmations, reminders, reschedules, cancellations, queue and token updates
  • Clinical: vaccination doses due, follow-up reminders, report availability
  • Personal reminders: medicine reminders you have set for yourself
  • Messages: new chat and community activity
  • Billing: new invoices and payment confirmations
  • Emergency: SOS alerts to clinics and nominated contacts
  • Service: security notices, policy changes, mandatory update notices

11.2 How They Work

Push notifications are delivered through Firebase Cloud Messaging. To do this we store a device messaging token against your account; it is deleted when you sign out or delete your account. Some reminders are scheduled locally on your device and are not sent over the network at all.

11.3 Content of Notifications

Notification payloads are kept minimal and are designed to avoid exposing clinical detail on a lock screen. However, a notification may reveal that you have an appointment or a message from a named clinic. If your lock screen is visible to others, consider hiding notification content in your device's system settings.

11.4 Delivery Is Not Guaranteed

Notification delivery depends on network connectivity, device settings, battery optimisation, Do Not Disturb, and Google's messaging infrastructure. Notifications may be delayed, suppressed by the operating system, or not delivered at all. Do not rely on a notification as your only reminder of a medical appointment, medication dose or vaccination. Trivartha is not liable for a missed appointment, missed dose, or any consequence of a notification that was delayed or not delivered.

11.5 Turning Them Off

You can disable notifications by category in the App's settings, or entirely in your device's system settings. Service and security notices may still be shown inside the App.

12Reports, Media & Documents

12.1 What Gets Uploaded

You and your clinic may upload lab reports, scan reports, discharge summaries, prescriptions, photographs and similar documents. These are stored in Firebase Cloud Storage under access rules that restrict them to your account and your clinic.

12.2 Image Handling

Images are resized and compressed on your device before upload to reduce data usage and storage cost. We do not strip or analyse image metadata for any purpose beyond what is needed to display the file, and we do not extract location metadata from your photographs for our own use.

12.3 Personal Gallery

Your personal pregnancy and baby gallery is yours. It is not shared with your clinic unless you explicitly share an item.

12.4 Accuracy of Documents

We store documents as supplied. We do not verify, interpret, transcribe or clinically validate their contents. If a report in the App looks wrong, incomplete or attributed to the wrong person, contact your clinic immediately — and rely on the original issued by the diagnostic centre or laboratory, not on the copy in the App.

13Sharing & Disclosure

13.1 Within Your Clinic

Your information is shared with the clinic you are linked to: your treating doctor, other doctors within that same clinic where the clinic has enabled shared access, and clinic staff whose role requires it (reception, billing, nursing). Section 24 sets out what each role can see.

13.2 Across Clinics

Clinic workspaces are isolated by default (Section 23). Your data crosses a clinic boundary only when:

  • You link yourself to a second clinic — for example, a mother linked to both a gynaecology clinic and a paediatric clinic. Each clinic sees only its own records.
  • Your record is formally transferred to another clinic through the App's transfer function, which is an explicit, logged action.

13.3 Service Providers

We share data with the infrastructure providers listed in Section 14, strictly to run the Service. They act on our instructions and are bound by their own contractual and security obligations.

13.4 Legal and Regulatory Disclosure

We may disclose information where we are required to by law, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, a court order, or a lawful request from a government or law enforcement authority; to enforce our terms; to detect or prevent fraud or a security incident; or to protect the rights, safety or property of you, us, our users or the public. Where we are lawfully permitted to notify you of such a request, we will endeavour to do so.

13.5 Business Transfer

If Trivartha is involved in a merger, acquisition, restructuring, financing or sale of assets, personal data may be transferred as part of that transaction. Any acquirer will remain bound by this Policy in respect of data transferred, or you will be notified and given a choice before any materially different treatment applies.

13.6 We Do Not Sell Your Data

Trivartha does not sell, rent, licence, trade or otherwise disclose personal or health data to advertisers, data brokers, insurers, pharmaceutical companies, marketing agencies, or any third party for their own purposes. We have never done so and this Policy would have to change before we could.

14Third Parties & Subprocessors

14.1 Our Subprocessors

ProviderServiceWhat it handlesLocation
Google — Firebase AuthenticationLogin & identityEmail, phone, password hashes, session tokensIndia / Google global
Google — Cloud FirestorePrimary databaseAccounts, clinical records, appointments, messages, invoicesasia-south1 (Mumbai)
Google — Cloud StorageFile storageReports, images, voice notes, documentsasia-south1 (Mumbai)
Google — Cloud FunctionsServer-side logicNotifications, invoice triggers, background jobsasia-south1 (Mumbai)
Google — Cloud MessagingPush notificationsDevice tokens, notification payloadsGoogle global
Google — Analytics for FirebaseUsage analyticsAnonymous events and installation identifierGoogle global
Google — CrashlyticsCrash reportingStack traces, device model, OS versionGoogle global
Google — Remote ConfigFeature flagsApp version, configuration fetchesGoogle global
Google — Play BillingSubscriptionsPurchase tokens and subscription statusGoogle global
Google — ML KitBaby Position MonitorNothing — runs entirely on your device, transmits nothingOn device only
Google — Play Services geocodingSOS address lookupCoordinates, only when SOS is triggeredGoogle global

14.2 Their Terms

These providers process data under Google's privacy terms and their own security commitments. Their handling of data is governed by their policies, available at policies.google.com/privacy and firebase.google.com/support/privacy.

Note on our reliance on Google. Momivara is built on Google Cloud and Firebase. We do not control Google's infrastructure, availability or security. We are not liable for outages, defects, data loss or security incidents originating with a third-party provider, beyond our obligation to select reputable providers, configure them responsibly and respond promptly when something goes wrong.

14.3 Changes to Subprocessors

We may add or change subprocessors as the Service evolves. Material changes will be reflected in an updated version of this Policy.

14.4 External Links

The App may link to external sites and resources. We do not control them and are not responsible for their content or privacy practices.

15Analytics & Crash Reporting

15.1 What We Measure

We use Firebase Analytics to understand, in aggregate, which features are used and where users get stuck. Events are things like booking started, booking succeeded, booking failed with a generic reason code, or branding saved.

15.2 What We Deliberately Exclude

We do not attach names, phone numbers, email addresses, medical details, diagnoses, prescriptions, report contents, message contents, or precise locations to analytics events. Analytics tells us that a booking failed and broadly why; it does not tell us who booked, with whom, or for what condition.

15.3 Crash Reporting

Firebase Crashlytics collects stack traces, device model, operating system version and app version when the App crashes or hits an error. Crash reports may incidentally contain technical identifiers. We do not deliberately send personal or health data into crash reports, and we treat any such data as confidential and delete it when identified.

15.4 No Advertising

The App contains no advertising of any kind. We do not use advertising SDKs, we do not build advertising profiles, we do not use your device advertising identifier for targeting, and we do not share data with ad networks.

15.5 Retention

Analytics data is retained according to Firebase's configured retention period, and crash data is retained for up to 90 days, after which it is deleted or aggregated.

16No AI Training, No Data Sale

We do not use your data to train artificial intelligence. Trivartha does not use your personal data, your health data, your child's data, your messages, your reports, your images or your clinical records to train, fine-tune, evaluate or improve any artificial intelligence or machine learning model — ours or anyone else's. We do not send your data to any third-party AI service, large language model, or generative AI provider.

16.1 The Only Machine Learning in the App

The single machine learning component in Momivara is Google ML Kit face and pose detection, used by the Baby Position Monitor. It runs entirely on your device, using pre-trained models shipped with the App. It does not learn, does not adapt to your baby, does not store anything and transmits nothing (Section 7.2).

16.2 No Automated Clinical Decisions

Momivara does not generate diagnoses, does not summarise or interpret medical reports, does not suggest treatment, and does not make any automated decision that produces a legal or similarly significant effect on you. Every clinical entry in the App was typed by a human clinician. Every clinical decision is made by your doctor.

16.3 If This Ever Changes

We would have to publish a revised Policy, describe the processing plainly, and obtain fresh consent before using your data in any such way. It will not happen silently.

17Data Retention

17.1 Principle

We keep personal data only as long as necessary for the purpose it was collected for, or as long as a law or a clinic's professional obligation requires.

17.2 Indicative Periods

DataRetention
Account and profileWhile the account is active; deleted on account deletion
Clinical records, prescriptions, vitals, reportsRetained by the clinic per its record-keeping obligations — see 17.3
Paediatric records, growth and immunisation historyRetained by the clinic; immunisation history has long-term clinical value
Appointments and queue historyDuration of the clinic relationship
Invoices and payment recordsUp to 8 years, where required for tax and accounting
Chat and community messagesUntil deleted by you, your clinic, or on account deletion
Uploaded reports and mediaUntil deleted, subject to clinical retention
Emergency SOS alertsRetained in clinic records for incident history
Notification device tokensDeleted on sign-out or account deletion
Crash reportsUp to 90 days
BackupsRolling, overwritten in the ordinary cycle
Security and audit logsUp to 12 months

17.3 Medical Records Survive Your Account Deletion

Please understand this before requesting deletion. A medical record created by your clinic is the clinic's record of the care it provided. Registered medical practitioners in India are required to maintain patient records for a prescribed period, and longer where a complaint, claim or proceeding exists or is anticipated. Deleting your Momivara account removes your access and your account, but it does not compel your clinic to destroy its medical record of your treatment, and we will not destroy clinic records where the clinic instructs us that a retention obligation applies. If you want the clinic's record itself erased, that request must go to the clinic, and the clinic decides in line with its legal obligations.

17.4 Anonymised Data

We may retain data that has been irreversibly anonymised, and can no longer identify you or be re-linked to you, for statistical and product purposes. Anonymised data is not personal data.

18Security Measures

The following describes what we actually do. We have avoided listing controls we do not operate.

18.1 Encryption

  • In transit: all communication between the App and our infrastructure uses TLS 1.2 or higher.
  • At rest on the server: Firestore and Cloud Storage encrypt stored data using Google-managed AES-256 encryption.
  • On your device: authentication tokens and encryption keys are held in Android Keystore-backed secure storage. Selected sensitive fields in the local database — your emergency contacts and your medicine reminders — are additionally encrypted with AES-256-GCM before being written to disk.
An honest limitation. The local on-device database as a whole is not encrypted file-wide in the current build; the protections that apply on-device are the field-level encryption described above, together with Android's own application sandboxing and, where you have enabled it, device-level encryption. We state this plainly rather than claim otherwise. Keep a screen lock enabled on your device.

18.2 Credentials

Passwords are handled entirely by Firebase Authentication. We never see, receive, store or have any means of recovering your password. We cannot tell you what your password is, and any message purporting to be from us that asks for your password is fraudulent.

18.3 Access Control

  • Server-enforced Firestore and Storage security rules — access is denied at the database, not merely hidden in the interface
  • Clinic-level data isolation (Section 23) and role-based access (Section 24)
  • Least privilege: each role is granted only what its function requires
  • Re-authentication for sensitive operations such as changing credentials or deleting an account
  • Optional biometric lock on the App

18.4 Operational Security

  • Infrastructure hosted on Google Cloud, inheriting its physical, network and platform security controls
  • Automated crash and error monitoring
  • Dependency and platform updates applied as part of ongoing maintenance
  • Security rules exercised by an automated test suite before deployment

18.5 What You Should Do

  • Use a strong, unique password and do not reuse it elsewhere
  • Keep a screen lock on your device and keep the operating system updated
  • Do not share your login, and do not hand an unlocked, signed-in device to someone else
  • Sign out on shared or borrowed devices
  • Tell us immediately if you suspect unauthorised access
No absolute guarantee. No system, and no organisation, can guarantee perfect security. We implement reasonable safeguards proportionate to the sensitivity of the data and the scale of our operations, but we cannot and do not warrant that the Services will never be compromised. You accept this residual risk in using the Services.

19Where Your Data Lives

19.1 Primary Storage in India

Our database, file storage and server-side functions are provisioned in Google Cloud's asia-south1 (Mumbai, India) region. Your clinical records, appointments, messages, invoices and uploaded documents are stored in India.

19.2 Services That Operate Globally

Some ancillary Google services are not region-pinned and may process limited data outside India: Cloud Messaging (notification tokens and payloads), Analytics (anonymous usage events), Crashlytics (crash diagnostics), Authentication (identity records), Remote Config and Play Billing. These handle operational metadata, not your clinical records.

19.3 Transfers

The DPDP Act permits transfer of personal data outside India except to countries restricted by the Central Government. We do not transfer data to any restricted territory. Where data is processed outside India by the services above, it remains subject to Google's contractual and security commitments.

19.4 Government Access

Data stored in India is subject to Indian law, including lawful access requests. We disclose data only where legally compelled, and we do not provide any government or third party with bulk, direct or unfettered access to our systems.

20Your Rights

20.1 Rights Under the DPDP Act

  • Right to access information — a summary of the personal data we process about you, the processing activities, and the identities of others with whom it has been shared.
  • Right to correction and erasure — to have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased where it is no longer needed for the purpose it was collected for.
  • Right of grievance redressal — to a readily available means of raising a grievance with us, which we must respond to (Section 33).
  • Right to nominate — to nominate another individual who may exercise your rights in the event of your death or incapacity.
  • Right to withdraw consent — as easily as you gave it (Section 5.4).

20.2 How to Exercise Them

Most rights can be exercised directly in the App: edit your profile, delete your content, revoke a permission, change notification settings, or delete your account. For anything else, contact our Grievance Officer (Section 33). We will verify your identity before acting, because acting on an unverified request would itself be a privacy failure.

20.3 Timelines

  • Acknowledgement of a request: within 7 days
  • Substantive response: within 30 days, extendable where a request is complex, with reasons given
  • Account deletion: within 30 days of a verified request

20.4 Requests We May Decline

We may decline or limit a request where: we cannot verify your identity; the request is manifestly unfounded, excessive or repetitive; complying would infringe another person's rights or privacy; the data is subject to a clinic's medical record-retention obligation (Section 17.3); or a law requires us to retain it. We will always tell you why.

20.5 Your Duties Under the DPDP Act

The DPDP Act also places duties on you: not to impersonate another person when providing data, not to suppress material information, not to register a false or frivolous grievance or complaint, and to furnish only authentic information when seeking correction or erasure.

20.6 Complaints

If you are not satisfied with our response, you may complain to the Data Protection Board of India once it is constituted and operational. We would appreciate the chance to resolve it with you first.

21Account Deletion

21.1 How to Delete Your Account

You can request deletion from within the App under Settings → Account → Delete Account, or through the web form at momivara.trivartha.com/delete-account.html, or by writing to our Grievance Officer (Section 33).

21.2 What Gets Deleted

  • Your login credentials and authentication record
  • Your profile, personal details and preferences
  • Your personal wellness data — gallery, contraction logs, medicine reminders, emergency contacts, personal notes
  • Your chat and community messages, subject to 21.4
  • Your device notification tokens
  • Your clinic linkage

21.3 What May Be Retained, and Why

  • Clinic medical records — retained by the treating clinic under its professional and statutory obligations (Section 17.3)
  • Invoices and financial records — retained where tax or accounting law requires
  • Data under legal hold — where a claim, complaint, investigation or proceeding exists or is reasonably anticipated
  • Backups — residual copies persist until the ordinary backup cycle overwrites them
  • Anonymised aggregates — which can no longer identify you

21.4 Group Content

Messages you posted in community groups may remain visible to other members after your account is deleted, because they form part of a shared conversation. Ask a group administrator to remove specific posts before deleting your account if this matters to you. We cannot recall content that others have already seen, saved or copied.

21.5 Irreversibility

Account deletion is permanent and cannot be undone. We cannot restore a deleted account or its data. Export anything you want to keep first (Section 22).

21.6 Deletion by a Clinic

If a clinic closes its Momivara workspace, patient access to that clinic's records through the App ends. Custody of the underlying medical record remains the clinic's responsibility and is a matter between you and the clinic.

22Data Export

22.1 What You Can Export

You can obtain a copy of your profile, appointment history, clinical records visible to you, growth and immunisation records for your children, uploaded reports, invoices and personal wellness data.

22.2 How

Individual reports and records can be downloaded or shared directly from the App. For a consolidated export, write to our Grievance Officer (Section 33) and we will provide it within 30 days of verifying your identity, in a structured, commonly used, machine-readable format such as JSON or CSV, with attached documents in their original formats.

22.3 Limits

Exports contain your own data. They do not include another person's data, a clinic's internal operational or commercial information, other members' community messages, or our proprietary system data.

23Multi-Tenant Isolation

23.1 The Model

Every clinic operates in its own logical workspace. A clinic can see only its own patients, appointments, records, invoices, staff and messages. This is enforced server-side by security rules, not merely by hiding things in the interface — a request for data outside your clinic scope is refused by the database itself.

23.2 How Isolation Works

  • Every record carries a clinic identifier, validated on every read and write
  • Access tokens carry role and clinic claims that the server checks
  • Cross-clinic queries are structurally denied
  • File storage paths are namespaced per clinic and enforced by storage rules

23.3 Dual-Clinic Patients

A mother may be linked to a gynaecology clinic and a paediatric clinic simultaneously. The two remain isolated: the paediatric clinic does not see her obstetric records, and the gynaecology clinic does not see the child's paediatric records, unless she is a patient of both for those specific records.

23.4 Transfers

Records move between clinics only through the App's explicit transfer function, initiated deliberately using the destination clinic's code, and logged.

24Role-Based Access

Something patients should know: clinic staff — receptionists and administrative personnel, not only your doctor — can see your name, contact details, appointments, invoices and, depending on their duties, clinical information needed to run the clinic. This is normal for any clinic, digital or paper-based, but we would rather you heard it from us plainly.

24.1 Who Sees What

RoleTypical access
Mom / PatientOwn records, own children's records, own appointments, invoices and messages
DoctorFull clinical access to patients of their clinic; can create and amend records, prescriptions, invoices; can manage staff and clinic settings
Clinic StaffPatient demographics, appointments, queue, check-in, billing and invoicing, and clinical data entry where their duties require; cannot alter clinic ownership or subscription
Clinic Owner / AdminEverything a doctor can do, plus staff management, subscription and clinic-level configuration

24.2 The Clinic Controls Its Staff

Your clinic decides who works there, what role each person holds, and when access is revoked. Trivartha does not vet clinic staff, does not conduct background checks, and does not supervise how a clinic manages its personnel. A clinic must revoke access promptly when a staff member leaves (Section 28.2).

24.3 Auditability

Record creation and amendment are attributed to the user who performed them, with timestamps, so a clinic can see who entered or changed what.

24.4 Re-Authentication

Sensitive actions — changing your email or password, deleting your account, altering clinic ownership — require you to re-authenticate.

25Data Breach Response

25.1 If a Breach Occurs

On becoming aware of a personal data breach, we will contain it, investigate its cause and scope, assess the risk to affected individuals, remediate the vulnerability, and notify as required by law.

25.2 Notification

  • Data Protection Board of India — notified as required under the DPDP Act, without undue delay
  • CERT-In — reportable cyber security incidents notified within 6 hours of becoming aware, as required by the CERT-In Directions of 28 April 2022
  • Affected users — notified without undue delay, in plain language, describing what happened, what data was involved, what we have done, and what you should do
  • Affected clinics — notified so they can meet their own obligations as data fiduciaries

25.3 Reporting a Vulnerability

If you discover a security vulnerability, please report it to us privately using the contact details in Section 33 rather than disclosing it publicly. We will acknowledge your report and will not pursue action against good-faith security research that does not access, alter or exfiltrate other users' data, does not degrade the Service, and gives us reasonable time to fix the issue.

26Not a Medical Device, Not Medical Advice

Momivara is a record-keeping and clinic administration tool. It is not a medical device, it does not diagnose, and it does not treat.

26.1 No Medical Advice

Nothing in the App — no chart, no reminder, no vaccination schedule, no growth curve, no gestational week counter, no educational content — constitutes medical advice, diagnosis, prognosis, or treatment recommendation from Trivartha. Trivartha does not practise medicine and employs no clinicians in connection with the Services. Always consult a qualified registered medical practitioner.

26.2 Not a Regulated Medical Device

Momivara is not registered, approved, cleared or certified as a medical device under the Medical Devices Rules, 2017, by the Central Drugs Standard Control Organisation, or by any other regulator in any jurisdiction. It is not intended for diagnosis, prevention, monitoring, treatment or alleviation of disease within the meaning of those rules. Do not use it as if it were.

26.3 No Clinical Decision Support

The App performs no clinical reasoning. Vaccination schedules and gestational calculations are simple calendar arithmetic applied to dates entered by a human, presented for convenience. They are not tailored to a patient's clinical circumstances, and they may be wrong if the underlying dates are wrong. Your doctor's judgement governs, always.

26.4 Accuracy of Data

All health data in the App is entered manually by patients, doctors or staff. We do not verify it. Values may be mistyped, misattributed, out of date, incomplete or entered against the wrong patient. Do not make any medical decision on the basis of what the App displays without confirming it with your doctor and with the original source documents.

26.5 In an Emergency

If you or your child has a medical emergency — bleeding, severe pain, reduced foetal movement, breathing difficulty, unresponsiveness, or any acute concern — call 108 or 112, or go to the nearest hospital immediately. Do not open this App, do not send a chat message, and do not wait for an SOS alert to be acknowledged.

27No Telemedicine

27.1 The App Does Not Provide Consultations

Momivara does not offer telemedicine. There is no video consultation, no audio consultation, no remote examination and no online prescribing feature in the App. It is a record-keeping, scheduling and communication tool supporting in-person care at a physical clinic.

27.2 Text Messaging Is Not a Consultation

The chat feature allows administrative and follow-up communication with your clinic. It is not a consultation channel, and a message from clinic personnel is not a teleconsultation, a diagnosis or a prescription.

27.3 If a Practitioner Uses It Otherwise

If a registered medical practitioner chooses to give clinical guidance through the App's messaging feature, that practitioner is solely responsible for complying with the Telemedicine Practice Guidelines and all applicable professional and regulatory obligations. Trivartha does not hold itself out as a telemedicine platform, does not facilitate teleconsultation, and accepts no responsibility for advice given by a practitioner through any channel.

28Clinic & Practitioner Responsibilities

This section applies to doctors, clinic owners and clinic staff using Momivara. It is a condition of your use of the Services.

28.1 Your Warranties

By using Momivara as a clinic or practitioner, you represent and warrant on a continuing basis that:

  • You are a validly registered medical practitioner or a lawfully constituted clinic entity, holding all registrations, licences and permissions required to provide the services you provide, including under the Clinical Establishments Act and applicable State legislation.
  • You have a lawful basis, including any patient consent required, for every item of personal and health data you enter, upload, store or process using the Services.
  • You have obtained verifiable guardian consent before entering any child's data (Section 6.3).
  • You will comply with the DPDP Act as a data fiduciary in respect of the data you control, with the National Medical Commission's professional conduct regulations, with medical record-keeping and retention requirements, and with all applicable rules on prescriptions and drugs.
  • You will use the Services only for lawful clinical and administrative purposes, and not for marketing to patients without their consent.

28.2 Your Operational Duties

  • Grant staff only the access their duties require, and revoke access immediately when a staff member leaves or changes role.
  • Keep credentials confidential; do not share logins between people.
  • Ensure the accuracy of what you and your staff enter, and correct errors promptly.
  • Respond to your patients' access, correction and erasure requests as their data fiduciary.
  • Notify us immediately of any suspected unauthorised access.
  • Maintain your own independent records as your professional obligations require. Do not rely on Momivara as your only copy of a medical record.

28.3 What Trivartha Does Not Do

  • We do not verify a practitioner's registration, qualifications, credentials or fitness to practise.
  • We do not supervise, review or audit clinical practice, record quality, or fee levels.
  • We do not vet, employ or supervise clinic staff.
  • We do not act as your compliance function, your medical records officer, or your data protection officer.
  • We make no representation to any patient about any clinic or practitioner on the platform.

28.4 Indemnity

You (the clinic, practitioner or clinic owner) agree to indemnify, defend and hold harmless Trivartha, its proprietors, employees and agents from and against any claim, demand, proceeding, loss, liability, damage, penalty, cost or expense (including reasonable legal fees) arising out of or relating to: your clinical practice, decisions, diagnoses, prescriptions or treatment; your fees, billing or refunds; your failure to obtain a lawful basis or consent for data you process; your breach of the DPDP Act, medical council regulations, or any other law; your failure to manage staff access; your loss or misuse of credentials; the inaccuracy of data you enter; or your breach of this Policy or our terms.

28.5 Patients Contract With Their Clinic

Nothing in this Policy creates a doctor–patient relationship, a contract for medical services, or any duty of care in respect of clinical matters between a patient and Trivartha. The provision of healthcare is a matter between the patient and the clinic.

29Disclaimers & Limitation of Liability

29.1 Service Provided "As Is"

To the maximum extent permitted by applicable law, the Services are provided "as is" and "as available", without warranty of any kind, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, accuracy, or non-infringement. We do not warrant that the Services will be uninterrupted, timely, secure, error-free, or that defects will be corrected.

29.2 Specific Exclusions

Without limiting the above, and to the maximum extent permitted by law, Trivartha is not liable for:

  • Any clinical decision, diagnosis, prescription, treatment, omission or outcome — these are the practitioner's responsibility
  • The accuracy, completeness, timeliness or clinical appropriateness of any data entered by any user
  • Any failure, delay, false alarm, missed alarm or non-detection by the Baby Position Monitor (Section 7)
  • Any delayed, undelivered, unseen or unanswered Emergency SOS alert (Section 8)
  • Any missed, delayed or suppressed notification or reminder, including for appointments, medication and vaccinations (Section 11.4)
  • Any payment dispute, non-payment, over-payment or billing error between a patient and a clinic (Section 9.2)
  • Content posted by users in chat or community groups, or its consequences
  • Unauthorised access resulting from your loss, sharing or weak protection of credentials, or from an unlocked device
  • Outage, defect, data loss or security incident originating with a third-party provider, including Google, Firebase or the Play Store
  • Loss of data where you have not maintained independent records
  • Any event beyond our reasonable control, including network failure, power failure, natural disaster, epidemic, war, civil disturbance, government action, cyber attack or platform outage

29.3 No Indirect Loss

To the maximum extent permitted by law, Trivartha shall not be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, nor for any loss of profit, revenue, goodwill, business, opportunity, anticipated saving, or data, however arising, whether in contract, tort (including negligence), statute or otherwise, even if advised of the possibility.

29.4 Aggregate Cap

To the maximum extent permitted by law, Trivartha's total aggregate liability arising out of or relating to the Services and this Policy, across all claims combined, shall not exceed the total subscription fees actually paid by you to Trivartha in the twelve (12) months immediately preceding the event giving rise to the claim, or INR 5,000, whichever is greater. Where you have paid nothing — as is the case for patients, who are not charged by Trivartha — the cap is INR 5,000.

29.5 What We Do Not Exclude

Nothing in this Policy excludes or limits liability that cannot lawfully be excluded or limited, including liability for fraud or fraudulent misrepresentation, for death or personal injury caused by our own gross negligence, or any liability that Indian law does not permit us to exclude. Where a limitation in this section is held unenforceable, it applies to the maximum extent that is enforceable, and the remainder of this Policy is unaffected.

29.6 Your Acknowledgement

You acknowledge that the allocation of risk in this section is a fundamental basis on which the Services are made available, that the fees charged (or the absence of fees) reflect that allocation, and that the Services would not be offered on different terms.

30Accessibility

We aim to make Momivara usable by as many people as possible, including support for system font scaling, sufficient colour contrast, and compatibility with Android screen readers such as TalkBack. The App is currently available in English only.

If you encounter an accessibility barrier, or need this Policy or your data in an alternative format, contact us (Section 33) and we will assist. We will not require you to disclose a disability in order to exercise a privacy right.

31Changes to This Policy

31.1 Updates

We may update this Policy as the App changes or the law changes. The version number and "Last Updated" date at the top of this page always reflect the current version.

31.2 Material Changes

Where a change materially affects how we handle your personal data, we will give notice through the App, and by email where we hold your address, before the change takes effect. Where the DPDP Act requires fresh consent, we will ask for it rather than assume it.

31.3 Continued Use

Continued use of the App after a change takes effect indicates acceptance of the revised Policy. If you do not accept it, stop using the App and delete your account.

31.4 Version History

  • v2.0 — 19 July 2026: Comprehensive revision. Added paediatric and child data, Baby Position Monitor, Emergency SOS, UPI and invoicing, community and voice notes, and no-AI-training commitment. Clarified the clinic-as-fiduciary / Trivartha-as-processor split. Corrected security claims to match the shipped build. Removed HIPAA, COPPA, GDPR and CCPA compliance assertions and telemedicine provisions that did not reflect the Service as operated; re-based the Policy on India's DPDP Act 2023. Added grievance officer, governing law and liability provisions.
  • v1.0 — 9 June 2026: Initial publication.

32Governing Law & Dispute Resolution

32.1 Governing Law

This Policy and any dispute or claim arising out of or in connection with it, its subject matter or formation (including non-contractual disputes or claims) are governed by and construed in accordance with the laws of India, without regard to conflict of law principles.

32.2 Jurisdiction

Subject to Section 32.3, the courts at Vadodara, Gujarat, India shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy or the Services, and you consent to that jurisdiction and venue.

32.3 Resolve It With Us First

Before commencing any proceeding, please contact our Grievance Officer (Section 33) and give us a genuine opportunity to resolve the matter. Most issues are resolved this way. We ask that you allow us 30 days from a written notice describing the issue and the outcome you seek.

32.4 Arbitration

Any dispute not resolved under Section 32.3 may, at either party's election, be referred to arbitration by a sole arbitrator under the Arbitration and Conciliation Act, 1996. The seat and venue of arbitration shall be Vadodara, Gujarat, and the language shall be English. This does not prevent either party from seeking urgent interim relief from a court.

32.5 Regulatory Recourse

Nothing here prevents you from complaining to the Data Protection Board of India or any other competent authority (Section 20.6).

32.6 Severability

If any provision of this Policy is held invalid, illegal or unenforceable, it shall be severed or read down to the minimum extent necessary, and the remaining provisions shall continue in full force.

32.7 No Waiver

Our failure to enforce any provision is not a waiver of it, and no waiver on one occasion operates as a waiver on any other.

32.8 Entire Agreement

This Policy, together with our Terms of Service and any clinic subscription agreement, constitutes the entire agreement between you and Trivartha regarding the processing of personal data, and supersedes all prior understandings on that subject, including version 1.0 of this Policy.

33Grievance Officer & Contact

33.1 Data Fiduciary

Trivartha

Vadodara, Gujarat, India

A 33 —Usha Kiran society Tarsali Vadodara Gujarat

Application: Momivara — Clinic Management for Gynaecology & Paediatrics

Website: momivara.trivartha.com

33.2 Grievance Officer

In accordance with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines) Rules, 2021, the Grievance Officer for Momivara is:

Meena Devi — Partner

Designation: Grievance Officer, Trivartha

Email: info@trivartha.com

Address: as at Section 33.1

Hours: Monday to Saturday, 10:00 to 18:00 IST, excluding public holidays

33.3 What to Contact Us About

  • Exercising your rights of access, correction, erasure or nomination
  • Withdrawing consent
  • Requesting a data export
  • Reporting a security vulnerability or suspected unauthorised access
  • Raising a grievance about how we have handled your data
  • Any question about this Policy

33.4 What to Take to Your Clinic Instead

Correction or erasure of a clinical record, a question about a diagnosis or prescription, a billing dispute, or a complaint about care or conduct — these are matters for your clinic, which is the data fiduciary for those records and the provider of your care (Section 2.2).

33.5 Response Times

  • Acknowledgement: within 7 days
  • Grievance resolution: within 30 days
  • Security incident reports: acknowledged within 48 hours

34Definitions

  • Personal Data — any data about an individual who is identifiable by or in relation to such data.
  • Data Principal — the individual to whom the personal data relates. Where the individual is a child, this includes their parent or lawful guardian.
  • Data Fiduciary — the person who, alone or with others, determines the purpose and means of processing personal data.
  • Data Processor — a person who processes personal data on behalf of a Data Fiduciary.
  • Child — an individual under the age of 18 years.
  • Processing — any operation on personal data, including collection, storage, use, sharing, alteration, retention and erasure.
  • Health Data — personal data relating to physical or mental health, medical history, clinical findings, treatment and care.
  • Clinic — the medical practice, practitioner or clinical establishment operating a workspace on Momivara.
  • Services — the Momivara mobile application and associated backend, website and support.
  • DPDP Act — the Digital Personal Data Protection Act, 2023 (India).
  • Consent Manager — a registered entity through which a Data Principal may give, manage and withdraw consent, as contemplated by the DPDP Act. Momivara does not currently operate through a Consent Manager.
Acknowledgement. By downloading, installing, registering for or using Momivara, you confirm that you have read and understood this Privacy Policy, including the safety notices for the Baby Position Monitor (Section 7) and Emergency SOS (Section 8), the medical disclaimers (Section 26), and the limitation of liability (Section 29). If you do not agree, do not use the App.