Emergency: 1122  |  Helpline: +92 335 3545545Helpline +92 335 3545545

🛡️ Privacy Policy

"Your privacy matters to us. Here's exactly how we collect, use, and protect your information."

📅 Effective: January 1, 2025🔄 Last Updated: June 1, 2026📋 Version 2.1
📖 Plain English Summary Available Below

🔒 We NEVER sell your personal information to third parties. |  🛡️ HIPAA Compliant  |  🇪🇺 GDPR Compliant  |  ♿ WCAG 2.1 AA

🛡️ Quick Summary — What This Policy Means For You

  • 📦We collect only the data necessary to run this platform — nothing more
  • 🚫We never sell your personal information to third parties, ever
  • 🗑️You can request deletion of your data at any time
  • 🍪We use cookies to improve your experience — you can opt out of non-essential ones
  • ⚕️We take medical data privacy extremely seriously with HIPAA & GDPR protections
  • 🩺This site is not a substitute for professional medical advice
📑 Contents
1
Who We Are
🏥 About DrInsight

DrInsight is a medical education and health information website. We publish content written and reviewed by qualified healthcare professionals. We do not provide medical diagnosis, treatment, or prescriptions.

Company: DrInsight  |  Registration: #NY-2018-MED-4471

Registered Office: DrInsight, Badin, Sindh Pakistan

Data Controller: DrInsight

Data Protection Officer (DPO): Dr. Javed Kumbhar — contact@drinsight.org

2
Information We Collect
📋

You Provide Directly

  • Name & email (registration)
  • Password (encrypted)
  • Contact form messages
  • Newsletter sign-up
  • Comment submissions
  • Topic suggestion forms
  • Author/reviewer applications
🤖

Collected Automatically

  • IP address
  • Browser type & version
  • Device type (mobile/desktop)
  • Operating system
  • Pages visited & time spent
  • Referring URL
  • Click & scroll depth data
🍪

Cookie & Tracking Data

  • Session cookies
  • Analytics cookies
  • Preference cookies
  • Marketing pixels (if enabled)
  • See full details in Section 5
🔗

Third-Party Login

  • Google OAuth: name, email, photo
  • Facebook Login: name, email, photo
  • Only if you choose to use social login
📧

Email Interaction Data

  • Newsletter open rates
  • Click-through rates
  • Unsubscribe actions
  • Aggregated only — not individual profiles
3
How We Use Your Information
PurposeData Used
Providing and improving the platformUsage data, device info
Sending newsletters and health updatesEmail address, preferences
Responding to contact form inquiriesName, email, message
Personalising content recommendationsReading history, specialty preferences
Moderating commentsName, email, comment content
Analytics and performance monitoringIP address, usage data (anonymised)
Legal complianceAll data as required by applicable law
Fraud prevention and securityIP address, login activity
4
Legal Basis for Processing (GDPR)
🌍 Note for Non-EU Users

Even if GDPR does not apply to you directly, we apply these same data protection standards globally to all users of DrInsight.

5
Cookies & Tracking Technologies

Cookies are small text files stored on your device that help us remember your preferences and understand how you use our platform. We use the following categories:

Strictly Necessary

Purpose
Site functionality, login sessions
Duration
Session
Can Opt Out?
❌ No

Performance / Analytics

Purpose
Google Analytics, page speed
Duration
2 years
Can Opt Out?
✅ Yes

Functional

Purpose
Saved preferences, font size
Duration
1 year
Can Opt Out?
✅ Yes

Marketing / Targeting

Purpose
Ad retargeting (if applicable)
Duration
90 days
Can Opt Out?
✅ Yes
🍪 Manage Your Cookie Preferences

You can manage your cookie preferences at any time via our Cookie Settings panel. Changing preferences will not affect your ability to read content on this platform.

🍪 Manage Cookie Preferences
6
Third-Party Services & Sharing
🚫 We DO NOT Sell Your Data

We never sell, rent, or trade your personal information to third parties for their marketing purposes. This is an absolute, non-negotiable commitment.

Circumstances where data may be shared:

📋 Limited Sharing With
  • Service providers: Hosting (AWS), email delivery (Mailchimp), analytics (Google Analytics) — under strict data processing agreements
  • Legal requirements: Court orders, law enforcement requests — only as legally required
  • Business transfers: In case of merger or acquisition — users will be notified in advance
  • Medical reviewers/authors: Limited to content they directly contribute to

Google Analytics

Purpose
Usage analytics
Data Shared
Anonymised usage data
Privacy Policy
View →

Google AdSense

Purpose
Ad display
Data Shared
Anonymised browsing data
Privacy Policy
View →

Mailchimp

Purpose
Newsletter delivery
Data Shared
Email, name
Privacy Policy
View →

Hotjar

Purpose
Heatmaps & UX
Data Shared
Anonymised interaction data
Privacy Policy
View →

Meta Pixel

Purpose
Ad conversion tracking
Data Shared
Page visit data (if enabled)
Privacy Policy
View →

Cloudflare

Purpose
Security & CDN
Data Shared
IP address (security only)
Privacy Policy
View →
7
Medical Information & Sensitive Data
⚕️ Special Notice Regarding Health Information
  • This platform is informational only and does not collect or store personal medical records
  • Any health topics discussed in comments or contact forms are treated with heightened confidentiality
  • We do not share any health-related communications with third parties
  • No health condition profiling — we do not build profiles of your medical interests
  • Google Analytics is configured with IP anonymisation enabled
🛡️ Health Data Compliance
  • HIPAA — For US users, where applicable, we follow HIPAA guidance on tracking technologies
  • GDPR Article 9 — Special category health data protections for EU users
  • PDPA / Local Regulations — We respect applicable local health data laws
⚠️ Important Reminder

Do not submit personal medical information through our contact forms. For medical concerns, always consult a licensed healthcare professional. Our platform does not provide medical consultations through contact forms.

8
Data Retention

Account data

Retention Period
While active + 90 days after deletion request
Basis
Contractual

Newsletter data

Retention Period
Until unsubscribe + 30 days
Basis
Consent

Contact form submissions

Retention Period
12 months
Basis
Legitimate interest

Comment data

Retention Period
Indefinitely unless deletion requested
Basis
Legitimate interest

Analytics data (Google)

Retention Period
26 months (GA default)
Basis
Legitimate interest

Legal / compliance records

Retention Period
7 years (as required by law)
Basis
Legal obligation

Security / fraud logs

Retention Period
12 months
Basis
Legitimate interest
9
Your Rights & Choices
👁️

Access

Request a copy of all data we hold about you

✏️

Rectification

Correct any inaccurate personal data

🗑️

Erasure

"Right to be forgotten" — request full data deletion

⏸️

Restrict Processing

Limit how we use your data in certain situations

📦

Portability

Export your data in a machine-readable format

🚫

Object

Object to processing based on legitimate interests

🍪

Withdraw Consent

Unsubscribe or change cookie settings anytime

📣

Lodge a Complaint

Complain to your local data protection authority

📬 How to Exercise Your Rights
  • Email: contact@drinsight.org
  • Response time: Within 30 days
  • Identity verification required before processing requests
  • No fee charged for rights requests (unless manifestly unfounded or excessive)
10
Children's Privacy
🔞 Children's Privacy Notice
  • This platform is intended for users 18 years and older
  • We do not knowingly collect data from children under 13 (COPPA) or under 16 (GDPR)
  • If a child's data is discovered, it will be deleted immediately without notice
  • Parents or guardians may contact us at contact@drinsight.org
  • Medical content is written for adult healthcare professionals and informed adult readers
11
International Data Transfers

Our primary servers are located in the United States. Data may be transferred internationally via third-party services. We ensure adequate safeguards are in place for all international transfers.

🌍 Transfer Safeguards
  • EU Standard Contractual Clauses (SCCs) — for transfers from the EU to third countries
  • Adequacy decisions — where recognised by applicable data protection authorities
  • Data Processing Agreements (DPAs) — signed with all third-party service providers
  • Privacy Shield successor frameworks — where applicable
12
Data Security
🔒

TLS 1.2 / 1.3

Encryption in transit (HTTPS)

🗄️

AES-256

Encryption at rest

👥

Role-Based Access

Least privilege principle

🔍

Security Audits

Regular penetration testing

📚

Staff Training

Data protection training for all staff

🚨

Incident Response

Breach response plan in place

🚨 Data Breach Notification

In the event of a confirmed data breach affecting your personal information, we will notify affected users within 72 hours of discovering the breach, as required by GDPR and applicable laws.

📋 Security Disclaimer

No method of transmission over the internet is 100% secure. We strive for best-in-class security but cannot guarantee absolute security of data transmitted to or stored on our platform.

13
Changes to This Policy

We reserve the right to update this Privacy Policy at any time. Continued use of the platform after changes constitutes acceptance of the updated policy.

📬 How We Notify You
  • Email notification to all registered users
  • Prominent banner notice on website homepage
  • Updated "Last Modified" date and version number at top of this page
v2.1June 2026Added cookie categories table, updated third-party service list, updated retention periods
v2.0January 2025Full rewrite for GDPR compliance, added DPA references, updated breach notification procedures
v1.0March 2023Initial Privacy Policy published
14
Contact Us

🛡️ Data Protection Officer

privacy@drinsight.org

All privacy & data requests

✉️ General Inquiries

contact@drinsight.org

All general enquiries

⚖️ Legal Department

legal@drinsight.org

Legal and compliance matters

📍 Mailing Address

DrInsight Inc.
Badin
Pakistan

⏱️ Response Time Commitment

We aim to respond to all privacy-related requests within 5–7 business days. Data subject rights requests will be fulfilled within 30 days as required by GDPR.