Privacy Policy
Version 2.1 · Effective 31 July 2026
This Privacy Policy explains how RAKT INNOVATIONS (OPC) PVT. LTD. (“RAKT”, “we”, “us”), CIN U72900DL2020OPC360414, registered office AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India, collects, uses, shares, protects, and retains personal data in connection with the RAKT blood centre management platform (the “Service”) and the rakt.in website.
It is published under Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and is written to align with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
1. The two roles RAKT plays, and why it matters to you
RAKT handles personal data in two distinct capacities, and your rights differ depending on which applies.
1.1 As a Data Processor, for blood centre records. When a blood centre, hospital, or camp organiser subscribes to RAKT, that organisation is the Data Fiduciary for the records it puts into the Service, and RAKT is its Data Processor. This covers data about donors, recipients and patients, camp organisers, and the organisation’s own staff. We process that data only on the organisation’s instructions and for the purpose of providing the Service. We do not decide what is collected, we do not use it for our own purposes, and we do not sell it.
1.2 As a Data Fiduciary, for our own business data. We are the Data Fiduciary for data we collect in our own right: the details of the people who enquire about, buy, and administer a RAKT subscription, website visitors, and our own personnel.
1.3 If you are a donor, recipient, or patient. Your relationship is with the blood centre that collected your data, not with RAKT. Requests to access, correct, or erase your records should be made to that blood centre, which we will assist. Contact details for reaching us are in Section 11 if you cannot identify the centre.
2. Personal data we handle
2.1 Records entered into the Service by a blood centre. Depending on how the centre configures the Service, this may include name, date of birth or age, sex, address, phone number, email address, government identifier references, blood group, donation and transfusion history, deferral reasons, screening and test results including for transfusion-transmissible infections, vitals, component and inventory records, and camp participation. Health data of this kind is sensitive personal data or information under Rule 3 of the SPDI Rules and is treated accordingly.
2.2 Staff and Authorised User data. Name, role, employee identifiers, email address, phone number, authentication credentials and passkey registrations, and activity logs recording actions taken in the Service.
2.3 Technical and usage data. IP address, device and browser type, pages and URLs visited, approximate location derived from IP, timestamps, session duration, and error diagnostics. We use this to operate and secure the Service, to support users, to investigate incidents, and to detect and block unauthorised access.
2.4 Customer and commercial data. Organisation name and address, licence details, contact names, email addresses and phone numbers, GST details, subscription and usage volumes, invoices and payment references.
2.5 Website and enquiry data. Information you submit through forms on rakt.in, and analytics data described in our Cookie Policy.
3. How we use personal data
- To provide, operate, maintain, and secure the Service.
- To authenticate users and administer access and permissions.
- To provide support, and to investigate and resolve faults and incidents.
- To send operational and transactional messages, including notifications a blood centre configures for its donors, such as donation reminders, camp information, and report links.
- To calculate usage, raise invoices, and collect payment.
- To detect, prevent, and investigate fraud, abuse, and security threats.
- To comply with law, and to respond to lawful requests from courts, regulators, and law enforcement.
- For our own marketing to prospective and existing customer organisations, which you can opt out of at any time.
We do not use donor, recipient, or patient records to train artificial intelligence or machine learning models, and we do not permit our sub-processors to do so.
4. Who we share personal data with
We do not sell personal data. We share it only in the following circumstances.
4.1 Sub-processors. We use a limited number of service providers to run the Service, covering hosting, storage and backup, email, SMS and WhatsApp delivery, payments, error monitoring, customer operations, and the optional artificial intelligence features described in Section 5. Each is bound to confidentiality and security obligations and may process data only to provide its service to us. The current list, with the purpose and processing location of each, is published at rakt.in/subprocessors/.
4.2 On the instruction of a blood centre. Where a centre configures an integration, we transmit data as directed. This includes government systems such as eRaktKosh and the Ayushman Bharat Digital Mission where the centre chooses to use them.
4.3 Where the law requires it. To comply with applicable law and regulation, to respond to a summons, warrant, court order, or other lawful request, to enforce our terms, or to protect the rights, safety, or property of RAKT, our customers, or the public.
4.4 Corporate transactions. In connection with a merger, acquisition, reorganisation, or sale of assets, subject to the recipient being bound by obligations no less protective than this Policy.
5. Optional artificial intelligence features, and what they send
We want to be specific about this rather than leave it inside a general reference to service providers.
5.1 Donor form extraction. Where a blood centre uses the feature that reads a scanned or photographed donor registration form and fills in the record automatically, the image of that form is transmitted to our artificial intelligence provider for text extraction. The image can contain everything written on the form, including name, date of birth, address, contact number, blood group, and recorded vitals.
5.2 RAKT AI assistant. Where staff use the in-product assistant or its WhatsApp interface, the question asked and the records returned by the assistant’s read-only lookups are transmitted to the same provider. Those results can include donor names, blood groups, and contact numbers.
5.3 Location and safeguards. This provider processes data outside India, as recorded in the sub-processor list. It is contractually prohibited from using the data to train its models or for any purpose other than returning a result to us.
5.4 Your control. These features are off by default for every blood centre. They can be switched on only for that centre’s account, on request to support@rakt.in, and can be switched off again the same way. A centre that does not enable them never sends donor data to the AI provider. Because these features involve sensitive personal data, a centre that enables them should ensure its donor consent and notice documentation covers this processing.
6. Transfers outside India
Donor, recipient, patient, and staff records are stored and backed up on infrastructure located in India, in Bengaluru and Mumbai. Certain sub-processors nonetheless process limited data outside India, and we would rather say so plainly than imply otherwise:
- Email delivery processes recipient email addresses and message content.
- WhatsApp messaging processes recipient phone numbers and the contents of template messages, which may include a donor name and donation details.
- Error monitoring processes technical diagnostic data, which may incidentally include limited identifiers present in an error report.
- Artificial intelligence features, where enabled, process the data described in Section 5.
- Marketing and customer operations tools process business contact details of customer and prospect staff, not donor records.
Where the Service is used by a data principal outside India, including in the European Economic Area, the rights and routing in Section 9 apply, and requests should be directed to the blood centre holding the record.
7. How we protect personal data
The measures below are the reasonable security practices and procedures we maintain for the purposes of Section 43A of the Information Technology Act, 2000 and Rule 8 of the SPDI Rules.
- In transit. All access is over HTTPS with HTTP Strict Transport Security enforced, including on subdomains, and plain HTTP is redirected.
- Authentication. Passkeys and WebAuthn are supported, passwords are stored only as salted cryptographic hashes and never in recoverable form, login attempts are rate limited, and sensitive actions require periodic re-authentication.
- Access control. Role-based permissions, and logical separation so each organisation’s records are scoped to that organisation.
- Auditability. Record-level change history and organisation activity logs, so an action can be traced to a user and a time.
- At rest and in backup. Managed database storage with provider-level encryption, object storage encrypted server-side, and system-state backups encrypted with AES-256 before upload. Restores are periodically tested.
- Administrative. Access to production systems is restricted to personnel who require it, over authenticated channels, and administrative interfaces are additionally rate limited and protected by two-factor authentication.
We do not hold an ISO/IEC 27001 certification and we do not claim one. The measures above are the ones we actually operate. No system can be made completely secure, and we cannot guarantee that a determined attack will never succeed.
8. Personal data breaches
If we become aware of a personal data breach affecting a blood centre’s records, we will notify that centre without undue delay and in any event within twenty-four hours of confirming it, with an initial alert as soon as practicable so that the centre can meet its own six-hour reporting obligation to CERT-In. We will provide the information reasonably required for the centre to notify the Data Protection Board of India and affected data principals, and we will report on our own account where the law requires us to. Where we act as Data Fiduciary, we will notify the Board and affected data principals directly, without delay and with detailed particulars within seventy-two hours.
9. Your rights
Subject to applicable law, you have the right to obtain confirmation of and access to your personal data, to have inaccurate or incomplete data corrected or completed, to have data updated, to have data erased where it is no longer required and no legal obligation requires its retention, to nominate another person to exercise your rights in the event of death or incapacity, and to grievance redressal.
How to exercise them. If your data is held by a blood centre using RAKT, contact that centre, which is the Data Fiduciary. It can act on your request directly in the Service, and we will assist it. If you cannot identify or reach the centre, or if RAKT holds your data as Data Fiduciary, write to us using the details in Section 11. We may need to verify your identity before acting, and we may decline a request where the law requires or permits us to retain the data, telling you why.
10. How long we keep personal data
10.1 While a subscription is active. We retain records for as long as the blood centre maintains its subscription, because the centre needs them to operate and to meet its own statutory record-keeping duties.
10.2 After termination. For thirty days after termination, the centre may request an export of its data in a standard machine-readable format at no additional charge. After that window closes, we delete the data from our live systems.
10.3 Backups. Encrypted backups are retained on a defined lifecycle for up to twelve months for disaster recovery, after which they expire and are destroyed. This means a residual copy of deleted data can persist in backup for that period. We do not restore expired customer data from backup except to recover the Service as a whole.
10.4 Logs. Access, traffic, and processing logs are retained for one year, consistent with Rule 8 of the DPDP Rules, 2025 and with CERT-In log retention directions, and are then erased unless a law or an ongoing investigation requires longer.
10.5 Business records. Invoices, tax records, and contractual records are retained for the periods required under tax, company, and limitation law.
10.6 The blood centre’s own obligations. Blood banks must retain certain records for minimum periods under the Drugs and Cosmetics Rules, 1945. Deciding what must be kept and for how long is the centre’s responsibility, not ours, and a deletion request that conflicts with a statutory retention duty cannot be honoured.
11. Grievance redressal
If you have a question, concern, or complaint about how personal data is handled, contact our Grievance Officer:
Grievance Officer
RAKT INNOVATIONS (OPC) PVT. LTD.
AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India
Email: support@rakt.in — please put “Grievance” in the subject line
Phone: +91 70427 21037, +91 99539 94941
We will acknowledge your grievance promptly and resolve it within one month as required by Rule 5(9) of the SPDI Rules, and in any event within ninety days as required by Rule 14 of the DPDP Rules, 2025. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
12. Children
The Service is a business tool used by blood centre staff and is not directed at children. Blood donation in India is restricted to donors aged eighteen and above, so donor records should not contain children’s data. Where a blood centre records data about a patient or recipient who is a child, that centre is responsible for obtaining verifiable consent from a parent or lawful guardian, as required by Section 9 of the Digital Personal Data Protection Act, 2023. We do not carry out tracking, behavioural monitoring, or targeted advertising directed at children.
13. Cookies and similar technologies
We use cookies and similar technologies on the rakt.in website and a small number of strictly necessary cookies in the Service. What they are, what they do, and how to control them is set out in our Cookie Policy.
14. Changes to this Policy
We may update this Policy to reflect changes in our practices, our sub-processors, or the law. Each version carries a version number and effective date at the top of this page. Where a change materially affects how personal data is handled, we will notify affected customer organisations by email or through the Service before it takes effect. Superseded versions are available on request.
15. Contact
RAKT INNOVATIONS (OPC) PVT. LTD.
AN-4D, AN Block, Shalimar Bagh, Delhi 110088, India
CIN: U72900DL2020OPC360414 | GSTIN: 07AAKCR0304B1Z0
Phone: +91 70427 21037, +91 99539 94941
Email: support@rakt.in