1. Overview & Scope
This Privacy Policy describes how Quiet Giant Healthtech Private Limited ("LogCare," "we," "us," or "our") collects, uses, discloses, and protects personal information when you:
- Visit our website at www.logcare.ai (the "Website")
- Use our AI-powered video analytics platform and related services (the "Services")
- Interact with us through email, phone, or other communication channels
We are committed to protecting your privacy and complying with applicable Indian data protection laws, including:
- The Digital Personal Data Protection Act, 2023 ("DPDP Act")
- The Information Technology Act, 2000 and related rules ("IT Act")
IMPORTANT: LogCare's Services use face blur technology at the source to ensure de-identification of individuals in video footage. We do NOT collect, store, or process Protected Health Information (PHI) or personally identifiable health data. The analytics data we process consists of de-identified operational metrics and event data only.
2. Definitions (DPDP Act Compliance)
For purposes of this Privacy Policy and compliance with the DPDP Act:
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
- "Data Principal" means the individual to whom the Personal Data relates.
- "Data Fiduciary" means LogCare, as the entity that alone or in conjunction with others determines the purpose and means of processing Personal Data.
- "Data Processor" means any person who processes Personal Data on behalf of a Data Fiduciary.
- "Consent" means a freely given, specific, informed, and unambiguous agreement by the Data Principal to the processing of their Personal Data.
- "Processing" means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, or erasure.
3. Information We Collect
A. Personal Information from Website Visitors
When you interact with our Website, we may collect the following personal information:
- Contact Forms: Name, email address, phone number, company name, job title, facility type
- Demo Requests: Name, email address, phone number, facility information
- Newsletter Signups: Email address
- Employment Inquiries: Name, email, phone, resume, cover letter, LinkedIn profile
- Event Registrations: Name, email, company name, job title
B. Automatic Information (Cookies & Tracking)
When you visit our Website, we automatically collect certain technical information:
- Device Information: IP address, browser type and version, device type, operating system
- Usage Information: Pages visited, time spent on pages, click behavior, scroll depth, referral source
- Geographic Information: Country, state/region, city (based on IP address)
- Cookie Identifiers: Unique identifiers stored in cookies (see Section 6 for details)
C. Service Usage Data (from Customers)
When you use our Services as a customer, we collect:
- Account Information: Email address, password (hashed), full name, role/title
- Facility Information: Facility name, address, number of cameras, facility type (hospital, clinic, etc.)
- De-Identified Video Analytics Data (NOT PHI):
- Event timestamps and camera identifiers
- Object detection data with blurred faces (no identifiable facial features)
- Operational metrics: fall detection alerts, zone violation alerts, dwell time statistics
- Equipment usage patterns, room occupancy statistics
- Communication Data: Support tickets, chat logs, email correspondence, phone call records
- Billing Information: Billing address, GST number, payment method details (processed by third-party payment processors)
D. Information from Third Parties
We may receive information about you from third-party sources:
- Social Media Platforms: LinkedIn, Twitter/X (when you interact with our profiles or share our content)
- Marketing Partners: Webinar platforms, event organizers, industry associations
- Payment Processors: Razorpay, Stripe (transaction confirmations, payment status)
- Data Enrichment Services: Company information, firmographic data (with consent)
4. How We Use Information
We use the information we collect for the following purposes:
A. Service Delivery
- Provide video analytics, real-time alerts, and dashboard visualizations
- Process de-identified video data to detect falls, zone violations, and operational events
- Generate reports and analytics for healthcare facility operations
- Maintain and improve Service performance and reliability
B. Account Management
- Create and manage user accounts
- Authenticate users and prevent unauthorized access
- Process billing and payments
- Provide customer support and respond to inquiries
- Send Service-related notifications (downtime, updates, security alerts)
C. Product Improvement
- Train and improve machine learning models using anonymized, aggregated data
- Analyze usage patterns to enhance features and user experience
- Conduct research and development for new capabilities
- Test and debug software issues
D. Marketing & Communications (with Consent)
- Send newsletters, product updates, and educational content
- Invite you to webinars, events, and demos
- Conduct market research and surveys
- Display targeted advertising on third-party platforms
E. Legal & Compliance
- Comply with legal obligations (tax, audit, regulatory reporting)
- Enforce our Terms of Use and other agreements
- Respond to legal requests from law enforcement or courts
- Maintain audit trails for compliance purposes
F. Security & Fraud Prevention
- Detect and prevent fraud, abuse, and security incidents
- Monitor system integrity and protect against malicious activity
- Investigate and respond to security breaches
5. Legal Basis for Processing (DPDP Act Compliance)
Under the DPDP Act, we process Personal Data based on the following legal grounds:
- Consent: When you provide explicit consent (e.g., newsletter signups, marketing communications, cookie preferences)
- Contract Performance: To perform our contractual obligations to provide Services to customers
- Legal Obligation: To comply with applicable laws, regulations, and court orders (e.g., tax compliance, regulatory reporting)
- Legitimate Interests: For purposes such as product improvement, security, fraud prevention, and business operations (where not overridden by your rights)
6. Cookies & Tracking Technologies
We use cookies and similar tracking technologies on our Website. Cookies are small text files stored on your device that help us provide and improve our Services.
Types of Cookies We Use:
- Essential Cookies: Required for authentication, session management, and security. These cannot be disabled.
- Analytics Cookies: Google Analytics (with anonymized IP addresses) to understand how visitors use our Website.
- Marketing Cookies: LinkedIn Insight Tag, Google Ads, Meta Pixel to deliver targeted advertising and measure campaign effectiveness.
- Preference Cookies: Remember your settings and preferences (language, region, cookie consent).
Managing Cookies:
You can control cookies through:
- Cookie Consent Banner: Manage your preferences when you first visit our Website
- Browser Settings: Most browsers allow you to block or delete cookies
- Opt-Out Tools: Google Analytics Opt-Out Browser Add-on, NAI opt-out tool
Note: Disabling certain cookies may affect Website functionality.
7. Data Sharing & Disclosure
We share Personal Data with the following categories of recipients:
A. Service Providers (Data Processors)
- Cloud Hosting: Amazon Web Services (AWS) - India (Mumbai/Hyderabad regions)
- Database: Supabase - for account and analytics data storage
- Email Services: Resend - for transactional and marketing emails
- Analytics: Google Analytics, Inspectlet - for Website usage analysis
- Customer Support: Intercom, Zendesk - for support ticket management
B. Payment Processors
- Razorpay (India) - for domestic payment processing
- Stripe (international) - for global payment processing
Payment processors handle credit card and banking information directly; LogCare does not store complete payment card details.
C. Professional Advisors
- Lawyers, accountants, auditors, and consultants (under confidentiality obligations)
D. Legal & Regulatory Authorities
- Law enforcement, courts, regulatory bodies when legally required
- To comply with court orders, subpoenas, or legal processes
- To protect our rights, property, or safety, or that of others
E. Business Transfers
- Acquirers, investors, or successors in the event of a merger, acquisition, or sale of assets (we will notify you and provide choices)
WE DO NOT SELL PERSONAL DATA TO THIRD PARTIES FOR MONETARY CONSIDERATION.
8. Data Retention
We retain Personal Data for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.
Retention Periods:
- Website Visitors: 24 months from last interaction (or until consent is withdrawn)
- Marketing Contacts: Until unsubscribe + 6 months for compliance purposes
- Customer Account Data: Duration of subscription + 60-90 days post-termination
- De-Identified Analytics Data: Duration of subscription + 60-90 days, then permanently deleted (unless anonymized for ML training)
- Legal/Compliance Records: As required by applicable law (e.g., tax records for 7 years, audit trails)
- Anonymized/Aggregated Data: Indefinitely for machine learning model training and product improvement (cannot be re-identified)
After the retention period, Personal Data is permanently deleted or anonymized such that it cannot be re-identified.
9. Data Security
We implement industry-standard technical and organizational measures to protect Personal Data against unauthorized access, loss, destruction, or alteration:
- Encryption: Data in transit is encrypted using TLS 1.2+ (HTTPS). Data at rest is encrypted using AES-256.
- Access Controls: Role-based access controls (RBAC) limit access to Personal Data on a need-to-know basis.
- Authentication: Multi-factor authentication (MFA) for administrative accounts.
- Monitoring: Continuous security monitoring, intrusion detection, and logging.
- Audits: Regular security audits, vulnerability assessments, and penetration testing.
- Incident Response: Documented incident response plan for data breaches.
- Face Blur at Source: Video footage is processed with face blur technology at the edge device before transmission, ensuring no identifiable facial data is stored.
- Employee Training: Regular security and privacy training for all employees with access to Personal Data.
No system is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security. If you become aware of any security vulnerability, please report it to ac@logcare.ai.
10. Your Rights (DPDP Act Compliance)
As a Data Principal under the DPDP Act, you have the following rights regarding your Personal Data:
A. Right to Access
You may request a copy of the Personal Data we hold about you, including details on how we use it and who we share it with.
B. Right to Correction
You may request correction of inaccurate or incomplete Personal Data.
C. Right to Erasure (Right to be Forgotten)
You may request deletion of your Personal Data, subject to:
- Legal retention requirements (e.g., tax, audit, litigation)
- Contractual obligations (e.g., active subscription)
- Legitimate interests (e.g., fraud prevention, security)
D. Right to Data Portability
You may request to receive your Personal Data in a structured, commonly used, and machine-readable format (e.g., JSON, CSV) and have it transmitted to another Data Fiduciary where technically feasible.
E. Right to Withdraw Consent
Where processing is based on consent, you may withdraw consent at any time (e.g., unsubscribe from marketing emails). Withdrawal does not affect the lawfulness of processing before withdrawal.
F. Right to Grievance Redressal
You may file a complaint with our Grievance Officer or the Data Protection Board of India if you believe your rights have been violated.
How to Exercise Your Rights:
To exercise any of these rights, please contact us at:
We will respond to your request within 30 days of receipt. We may request additional information to verify your identity before processing your request.
11. Children's Privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect Personal Data from children under 18 without verifiable parental consent.
If you are a parent or guardian and believe your child has provided us with Personal Data without your consent, please contact us at ac@logcare.ai. We will promptly delete such information from our systems.
12. International Data Transfers
LogCare primarily stores and processes Personal Data in India:
- Primary Storage: AWS Mumbai and Hyderabad regions (India)
- On-Premises Processing: Edge devices (NVIDIA Jetson Orin) at customer facilities in India
However, some third-party service providers (e.g., Google Analytics, Intercom) may process Personal Data outside India. When we transfer Personal Data internationally, we implement appropriate safeguards:
- Standard Contractual Clauses (SCCs): EU-approved model clauses or equivalent mechanisms
- Adequacy Decisions: Transfers to countries deemed to have adequate data protection by the Indian government
- Data Processing Agreements: Binding contracts requiring service providers to protect Personal Data
13. Third-Party Links
Our Website may contain links to third-party websites, social media platforms, or services (e.g., LinkedIn, Twitter/X, partner sites). This Privacy Policy does NOT apply to those third-party sites.
We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party sites you visit before providing Personal Data.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Services.
Notice of Changes:
- Material Changes: We will provide at least 60 days' advance notice via email and a prominent notice on our Website.
- Minor Updates: Updates take effect immediately upon posting to our Website, with the "Last Updated" date revised at the top of this page.
Your continued use of the Services after the effective date of changes constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you must discontinue use of the Services and may request deletion of your Personal Data.
15. Contact & Grievance Redressal
If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:
General Inquiries:
Privacy & Compliance:
Data Protection Officer (DPO):
- Name: Sneha
- Email: ac@logcare.ai
- Address: WeWork Residency Road, Bangalore, Karnataka, India
Grievance Officer (DPDP Act Requirement):
- Name: Sneha
- Email: ac@logcare.ai
- Address: WeWork Residency Road, Bangalore, Karnataka, India
Our Grievance Officer will acknowledge your complaint within 24 hours and resolve it within 30 days of receipt.
Data Protection Board of India:
You have the right to file a complaint with the Data Protection Board of India if you believe we have violated your rights under the DPDP Act. Contact details for the Board will be available at www.meity.gov.in once established.
16. DPDP Act Specific Disclosures
In compliance with the Digital Personal Data Protection Act, 2023, we provide the following disclosures:
A. Data Fiduciary
- Entity Name: Quiet Giant Healthtech Private Limited
- Trading Name: LogCare
- Registered Address: WeWork Residency Road, Bangalore, Karnataka, India
B. Purpose of Processing
As detailed in Section 4 ("How We Use Information"), we process Personal Data for:
- Service delivery and account management
- Product improvement and ML model training
- Marketing and communications (with consent)
- Legal compliance and security
C. Recipients of Personal Data
As detailed in Section 7 ("Data Sharing & Disclosure"), we share Personal Data with:
- Service providers (cloud hosting, analytics, support)
- Payment processors
- Professional advisors
- Legal and regulatory authorities (when required by law)
D. Cross-Border Transfers
As detailed in Section 12 ("International Data Transfers"), Personal Data may be transferred to third-party service providers outside India with appropriate safeguards (SCCs, adequacy decisions).
E. Retention Period
As detailed in Section 8 ("Data Retention"), Personal Data is retained for periods ranging from 24 months (website visitors) to 7 years (tax records), after which it is permanently deleted or anonymized.
F. Rights Available
As detailed in Section 10 ("Your Rights"), Data Principals have rights to:
- Access, correction, and erasure of Personal Data
- Data portability
- Withdrawal of consent
- Grievance redressal
Acknowledgment
By using our Website or Services, you acknowledge that you have read, understood, and agree to this Privacy Policy and the collection, use, and disclosure of your Personal Data as described herein.