Privacy Policy
This policy describes what AYRIVA actually does with information about you and your child. It is written against the system as built, not against a template. Where something is not yet true — an app that has not launched, a deletion schedule that does not yet run automatically — this policy says so plainly rather than describing an intention as a fact.
On this page
- 1. Who we are, and how to reach us
- 2. What this policy covers
- 3. The short version
- 4. What we collect, why, and on what basis
- 5. What we deliberately do not collect
- 6. Cookies, analytics and browser storage
- 7. Who else processes your information
- 8. Where your information is stored
- 9. How long we keep it
- 10. Your rights, and how to use them
- 11. Children, and who gives consent
- 12. Security
- 13. The Ayriva Kids app (not yet released)
- 14. Automated decisions and profiling
- 15. Changes to this policy
1. Who we are, and how to reach us
AYRIVA is a preventive child healthcare service for children aged 0–16, operated by AYRIVA Healthcare Pvt. Ltd. in Kathmandu, Nepal. For everything described in this policy, AYRIVA Healthcare Pvt. Ltd. is the party that decides what is collected and why, and is responsible for it.
For any privacy question or request — a copy of your information, a correction, a deletion, or a complaint — write to [email protected]. A person reads every message. You can also use the contact form, but for a request about your own information email is better, because it lets us reply to an address we can check against our records.
AYRIVA operates in Nepal and this policy is written to be read under Nepali law, including Nepal’s privacy legislation. Where you have rights under the law of another country, we will honour them rather than argue about jurisdiction.
2. What this policy covers
It covers this website, ayriva.asia — every page on it, the six forms it offers, the doctor directory, guest appointment booking, and the private administration console used by AYRIVA staff.
It also describes the Ayriva Kids mobile app, in section 13. That app is not released — it is not published on Google Play or the App Store, and nobody can install it. Section 13 is marked accordingly so you are not left thinking it describes something already collecting your child’s data.
It does not cover what a doctor does with information inside their own clinic. Once you attend an appointment, the doctor is keeping their own medical record under their own professional obligations, and that record is theirs, not ours.
3. The short version
- We ask for the least we can. The booking form takes a name and a phone number; everything else on it is optional.
- No health records are collected by this website. No measurements, no test results, no history, no attachments. There is no field for them.
- No payment details, anywhere. You pay the doctor at the visit.
- We do not sell your information and we run no advertising network, no marketing pixel and no profiling tracker. One analytics tool counts page views.
- We do not send you anything automatically. This service has no SMS and no email sending. After you book, a reference code appears on screen and the clinic telephones you.
- Your information is stored on our own server, in Germany, and reaches it over an encrypted connection.
- Email us and we will give you a copy of what we hold, correct it, or delete it — within 30 days.
4. What we collect, why, and on what basis
Below is every category of information this website collects. Nothing else is gathered — if a field is not named here, no page on this site asks for it.
4a. The six forms on this site
All six send what you type to our own application. Each asks only for what its purpose needs:
- Interest sign-up — your name, email address, the role you choose (parent, doctor, school, investor or other), and a phone number if you choose to give one.
- Newsletter — your email address, and nothing else at all.
- Registration — your name, email address and role; optionally a phone number, an organisation, a city and a message.
- Contact — your name, email address and message; optionally a role and a subject line.
- School demonstration request — the school’s name, a contact name and an email address; optionally a phone number, a city, an approximate number of students and a message.
- Care Network application — your full name, email address, the type of provider you are, your institution and its location; optionally a phone number, a specialty, a professional registration number and a message. This form also asks you to tick a box confirming the details are accurate and that we may contact you.
Why: to reply to you, to keep you on the list you asked to be on, and — for the Care Network — to check whether an applicant is who they say they are before anything is published about them.
Basis: your consent, given by choosing to submit the form. You can withdraw it at any time by emailing us, and withdrawing it does not affect anything done before you did.
A note on duplicates. Every submission receives the same response, whether or not we already held your address. That is deliberate: a form that says “you are already on the list” can be used by anyone to test whether a particular email address belongs to one of our families, one submission at a time. We refuse to build that.
4b. Reserving an appointment as a guest
You can reserve a time with a doctor without an account. When you do, we collect:
- Your name and a mobile number — both required, because a telephone call is the only way the clinic can reach you.
- Your child’s first name — optional.
- Your child’s age in months — optional.
- One line about why you are coming — optional, and limited in length. Please keep clinical detail out of it.
- The doctor and the time slot you chose, and a reference code we generate for you.
Why: to hold that slot so nobody else takes it, to put the request in the doctor’s queue, and to let the clinic telephone you to confirm.
Basis: taking a step you asked for, in order to arrange the appointment you requested.
The phone number is not verified. We do not send a code to it and we do not check that it is yours. If you mistype it, the clinic will call the wrong number — so please check it before you submit.
The reference code is not a password. There is deliberately no page anywhere on this site for looking up an appointment by its code. If such a page existed, anyone typing codes could read a stranger’s name, phone number and reason for visiting. Because it does not exist, your reservation cannot be read by someone who guesses a code — and equally, you cannot view or cancel it online yourself. Email us and we will pass a change or cancellation to the doctor.
4c. Technical information about your visit
- Your IP address. Our application writes a short operational log of the requests it serves, and that log includes the IP address a request came from. It is used to detect and stop abuse and to enforce rate limits, and it is not stored in our database alongside your name — none of the tables holding form submissions has an IP address column at all.
- Rate-limit counters. To stop a script emptying a doctor’s calendar, we count recent requests per IP address, and for bookings also per phone number in a one-way scrambled form. These counters live in memory only and are gone when the service restarts.
- Standard connection information seen by the services that deliver this site — see section 7.
Basis: our legitimate interest in keeping the service available, secure and usable by real families.
4d. Bot protection
Every public form is protected by Cloudflare Turnstile, a bot check that inspects your browser instead of asking you to solve a puzzle. The check runs when you submit a form, not when you merely read a page. Cloudflare receives your IP address as part of performing it.
Basis: our legitimate interest in preventing automated abuse of open forms.
4e. Measurement
We use Firebase Analytics, a Google service, to count page views across the site. See section 6.
4f. AYRIVA staff and doctor accounts
Staff and verified doctors sign in with Firebase Authentication, a Google service. For those accounts we hold an email address, the account identifier Firebase issues, and the role the account holds. Actions taken in the administration console — approvals, status changes — are written to an internal audit record showing who did what and when. This applies to AYRIVA staff and to doctors, not to members of the public, who have no account.
Basis: performing our contract with those users, and our legal and legitimate interest in being able to show who changed what.
5. What we deliberately do not collect
These are not oversights. Each is a decision, and each is enforced by the design of the system rather than by a promise:
- No clinical data through this website. No growth measurements, no immunisation history, no diagnoses, no test results, no documents or images. The booking form has no field for any of it and no way to attach a file.
- No payment or card details. Online payment is switched off. You pay the doctor at the visit.
- No IP addresses or browser fingerprints stored beside your form submission. The only extra thing recorded with a submission is the time it arrived.
- No advertising identifiers, no ad network, no marketing pixel, no cross-site tracking, no session recording and no heatmaps.
- No passwords on any public form. There is no public account to create.
- No database credentials in your browser. Your browser talks to our application, which decides what it is allowed to do. It has no direct access to the database.
- No third-party analytics beyond the one named in section 6.
6. Cookies, analytics and browser storage
There is no cookie banner on this site. Not because we are cutting a corner, but because there is no advertising network, no marketing pixel and no profiling tracker to ask you about. We would rather remove the trackers than ask you to dismiss a box about them.
What does run:
- Firebase Analytics (Google) — loads on every page and records a page-view event. It sets its own identifiers in your browser and Google receives the usual measurement information, including your approximate location derived from your IP address, your device type and your browser. This is the only measurement tool on the site.
- Cloudflare Turnstile — its script loads only at the moment you submit a form, and only on pages that have one.
What the public pages themselves store on your device: nothing. No page on the public site writes to local or session storage. The one exception is the private administration and doctor console, which keeps a sign-in session for the lifetime of the browser tab and signs the user out after 30 minutes of inactivity. That session dies when the tab closes and is never written to long-term browser storage — a deliberately stricter choice than the default, so an administrator’s session cannot be left alive indefinitely on a shared computer.
You can block or clear analytics cookies in your browser settings, or use a tracker-blocking extension. Nothing on this site will stop working if you do.
7. Who else processes your information
We use a small number of suppliers to run the service. They process information on our instructions, for the purposes below and nothing else. This list is complete.
- Google (Firebase Hosting) — serves the pages of this website. Sees the standard information any web server sees, including your IP address.
- Google (Firebase Authentication) — signs in AYRIVA staff and verified doctors. Not used by members of the public.
- Google (Firebase Analytics) — counts page views, as described in section 6.
- Cloudflare — sits in front of this website and our application as a content delivery network and security layer, and provides the Turnstile bot check. Sees your IP address and the requests you make.
- Oracle Cloud Infrastructure — provides the rented server that runs our application and its database, and the storage that holds our encrypted database backups.
- The doctor you book with — sees the reservations made for their own calendar: the name and phone number you gave, your child’s first name and age if you supplied them, and your one-line reason. A doctor cannot see another doctor’s reservations, and cannot see any of the six forms in section 4a.
We do not sell your information, and we do not share it with advertisers or data brokers. We would disclose information only where the law of Nepal requires it, or to protect someone from serious harm — and we would give you as much notice as the law permits.
8. Where your information is stored
Our application and its database run on a rented server in Frankfurt, Germany. Encrypted nightly backups of that database are held in Oracle Cloud object storage. This website’s pages are served by Google’s hosting network and reach you through Cloudflare, both of which operate globally.
This means information you give us leaves Nepal and is processed abroad. It travels over an encrypted connection, our server refuses connections that do not arrive through Cloudflare, and the suppliers above are bound by their own contractual and legal obligations for the data they handle on our behalf. By using this site you accept that your information is processed outside Nepal in this way.
9. How long we keep it
We will be straight with you here, because this is the section policies usually fill with numbers nobody enforces.
Today there is no automatic timetable that deletes old records. No scheduled job removes form submissions, appointment reservations or the administration audit record when they reach a certain age. What we hold is kept until it is no longer needed for the purpose you gave it for, or until you ask us to remove it — and removal is a deliberate action taken by a person, not a background process. We would rather write that sentence than invent a retention period we do not run.
What that means in practice, category by category:
- Form submissions (section 4a) — kept until you ask us to remove them, or until we close the list they belong to. The system holds no permission to delete these records automatically or in bulk: a submission is the record of a real person asking to be contacted, and removing one is a manual step performed by a named administrator so that it cannot happen silently.
- Appointment reservations (section 4b) — kept as the record of the booking, including after the appointment has happened or been declined. There is currently no automatic expiry on a guest reservation. Ask us and we will remove yours.
- Database backups — taken nightly. The ten most recent copies are kept and older ones are deleted automatically. This is the one genuinely automatic retention limit in the system. It also means that if you ask us to delete something, a copy can persist in a backup for roughly ten more days before it ages out.
- The administration audit record — kept indefinitely, and deliberately impossible to edit or delete. It records which staff account performed which action on which record, and exists so that a change to someone’s data can always be traced to a person. It is not a record of your browsing.
- Operational request logs (including IP addresses) — short-lived server logs kept only as long as they are useful for security and diagnosing faults, and not linked to your form submission.
- Rate-limit counters — held in memory only and discarded when the service restarts.
- Firebase Analytics data — retained by Google according to the retention setting on our analytics property, and governed by Google’s own terms.
What we are working towards. A documented schedule that removes inactive records automatically, and an archive step that lets an administrator retire a record without destroying the evidence of who retired it. Until that runs, this section will keep saying so. When it does, this section will state the periods and the date it started.
10. Your rights, and how to use them
You can ask us to:
- Tell you what we hold about you and your child.
- Give you a copy of it, in a form you can read and take elsewhere.
- Correct anything that is wrong or out of date.
- Delete it.
- Stop using it for a particular purpose, or withdraw a consent you gave — for example, to come off the newsletter list.
- Object to how we are using it.
How: email [email protected] and say which of the above you want. Writing from the address you gave us makes it faster.
How long: we complete requests within 30 days. There is no self-service button for this on the website — these requests are handled by a person, and that is why we commit to a timeframe rather than an instant.
We may ask you to confirm the request came from you before we act on it, particularly for deletion. This is not an obstacle: it is what stops somebody else deleting your records by claiming to be you.
Exercising these rights costs nothing and we will not treat you differently for it. If you are unhappy with how we have handled a request, say so in reply and we will escalate it internally; you also retain any right you have to complain to a regulator in your country.
For account deletion specifically, see Delete Your Account.
11. Children, and who gives consent
AYRIVA is a service for children, used by adults. It is designed to be operated by a parent or legal guardian on a child’s behalf. It is not designed for children to use themselves, and we do not knowingly collect information directly from a child. You should be 18 or over to submit anything on this site.
On this website, information about a child is limited to three optional fields on the booking form: a first name, an age in months, and your one-line reason for the visit. You can complete a booking without any of them. Nothing else about a child is collected here.
Consent is given by the adult, and it is recorded. When you submit a booking for a child you are confirming that you are that child’s parent or legal guardian and that you agree to the handling described in this policy. In the Ayriva Kids app, consent is a stronger and more formal thing: the account holder’s agreement is stored against their account with a version and a timestamp, and the database itself refuses to store any child health record until that consent exists. That check runs on every write, not once at sign-up.
Sharing a child’s record with a doctor is always a separate, explicit and revocable act — never a default, never automatic, and never a consequence of having booked an appointment.
If you believe a child has given us information directly, email us and we will remove it.
12. Security
The measures below are in place today:
- Everything travels encrypted. The site and our application are served only over HTTPS, with strict transport security enforced.
- The database enforces permissions itself. Access rules are applied inside the database on every statement, so a mistake in the application cannot open a record the database says you may not read.
- Staff permission is checked twice and the database wins. A sign-in token proves who you are; the database is then asked what role that person actually holds, and if the two disagree the request is refused and the disagreement is recorded. A claim in a token can therefore only ever cause a refusal, never a grant.
- Booking is the only public write that touches a doctor’s calendar, and it runs through a single guarded routine that validates every field before a record exists. There is no general-purpose write path from the public internet.
- Our server refuses connections that do not arrive through Cloudflare, so it cannot be reached by going around the security layer.
- Public forms are behind a bot check and rate limits.
- Backups are taken nightly, verified before they are trusted, and stored off the machine they came from.
- Administration sessions are tab-scoped and time out after 30 minutes of inactivity.
No system is completely secure, and we will not claim otherwise. If you find a security problem in AYRIVA, please tell us at [email protected] before disclosing it publicly, and we will work with you.
13. The Ayriva Kids app (not yet released)
The Ayriva Kids app is not published. It is not on Google Play or the App Store and cannot be installed. This section describes how it is built to handle information, so that it is not a surprise when it launches — but nothing in this section is collecting anything from you today.
When it launches, the app is designed to hold:
- Your account — your name, email address, and optionally a phone number.
- Your child’s record — first name, date of birth, sex, and the growth measurements, developmental milestones and immunisations you choose to enter.
- Consultations you book and hold through the app, and messages exchanged with a doctor during them.
Two design decisions are already fixed. Nothing about a child is stored until the account holder has given consent — the database refuses the write otherwise. And a doctor sees a child’s record only while you have granted them access, which you grant explicitly and can revoke.
When the app is released this policy will be updated to describe it in the present tense, with the same specificity as the rest of this page.
14. Automated decisions and profiling
We make no automated decisions that have a legal or similarly significant effect on you, and we build no behavioural profile of you or your child. Nothing here scores you, ranks you, or decides anything about your care. The only automated judgements in the system are a bot check on form submissions and rate limits on abuse — neither of which produces a decision about you as a person, and both of which you can get past by emailing us if they ever get in your way.
15. Changes to this policy
We update this policy when what we do changes — in the same change, not afterwards. The effective date at the top always reflects the current version.
If we make a change that materially affects how we handle information we already hold about you, we will say so prominently on this site before it takes effect. Because this service currently has no automated email, we cannot promise to notify you individually; we would rather tell you that than promise a message our systems cannot send.
Contact
Privacy questions, access requests, corrections, deletions and complaints: [email protected]
AYRIVA Healthcare Pvt. Ltd., Kathmandu, Nepal.
Related pages: Frequently asked questions · Terms of Use · Delete Your Account