🛡️ Privacy Policy
"Your privacy matters to us. Here's exactly how we collect, use, and protect your information."
🔒 We NEVER sell your personal information to third parties. | 🛡️ HIPAA Compliant | 🇪🇺 GDPR Compliant | ♿ WCAG 2.1 AA
🛡️ Quick Summary — What This Policy Means For You
- 📦We collect only the data necessary to run this platform — nothing more
- 🚫We never sell your personal information to third parties, ever
- 🗑️You can request deletion of your data at any time
- 🍪We use cookies to improve your experience — you can opt out of non-essential ones
- ⚕️We take medical data privacy extremely seriously with HIPAA & GDPR protections
- 🩺This site is not a substitute for professional medical advice
DrInsight is a medical education and health information website. We publish content written and reviewed by qualified healthcare professionals. We do not provide medical diagnosis, treatment, or prescriptions.
Company: DrInsight | Registration: #NY-2018-MED-4471
Registered Office: DrInsight, Badin, Sindh Pakistan
Data Controller: DrInsight
Data Protection Officer (DPO): Dr. Javed Kumbhar — contact@drinsight.org
You Provide Directly
- Name & email (registration)
- Password (encrypted)
- Contact form messages
- Newsletter sign-up
- Comment submissions
- Topic suggestion forms
- Author/reviewer applications
Collected Automatically
- IP address
- Browser type & version
- Device type (mobile/desktop)
- Operating system
- Pages visited & time spent
- Referring URL
- Click & scroll depth data
Cookie & Tracking Data
- Session cookies
- Analytics cookies
- Preference cookies
- Marketing pixels (if enabled)
- See full details in Section 5
Third-Party Login
- Google OAuth: name, email, photo
- Facebook Login: name, email, photo
- Only if you choose to use social login
Email Interaction Data
- Newsletter open rates
- Click-through rates
- Unsubscribe actions
- Aggregated only — not individual profiles
| Purpose | Data Used |
|---|---|
| Providing and improving the platform | Usage data, device info |
| Sending newsletters and health updates | Email address, preferences |
| Responding to contact form inquiries | Name, email, message |
| Personalising content recommendations | Reading history, specialty preferences |
| Moderating comments | Name, email, comment content |
| Analytics and performance monitoring | IP address, usage data (anonymised) |
| Legal compliance | All data as required by applicable law |
| Fraud prevention and security | IP address, login activity |
Consent
Newsletter sign-up, non-essential cookies, marketing communications
Contractual Necessity
Account creation, author agreements, service delivery
Legitimate Interests
Platform security, analytics, fraud prevention, content improvement
Legal Obligation
Compliance with applicable laws, court orders, regulatory requirements
Even if GDPR does not apply to you directly, we apply these same data protection standards globally to all users of DrInsight.
Cookies are small text files stored on your device that help us remember your preferences and understand how you use our platform. We use the following categories:
Performance / Analytics
Functional
Marketing / Targeting
You can manage your cookie preferences at any time via our Cookie Settings panel. Changing preferences will not affect your ability to read content on this platform.
We never sell, rent, or trade your personal information to third parties for their marketing purposes. This is an absolute, non-negotiable commitment.
Circumstances where data may be shared:
- Service providers: Hosting (AWS), email delivery (Mailchimp), analytics (Google Analytics) — under strict data processing agreements
- Legal requirements: Court orders, law enforcement requests — only as legally required
- Business transfers: In case of merger or acquisition — users will be notified in advance
- Medical reviewers/authors: Limited to content they directly contribute to
Google Analytics
Google AdSense
Mailchimp
Hotjar
Meta Pixel
Cloudflare
- This platform is informational only and does not collect or store personal medical records
- Any health topics discussed in comments or contact forms are treated with heightened confidentiality
- We do not share any health-related communications with third parties
- No health condition profiling — we do not build profiles of your medical interests
- Google Analytics is configured with IP anonymisation enabled
- HIPAA — For US users, where applicable, we follow HIPAA guidance on tracking technologies
- GDPR Article 9 — Special category health data protections for EU users
- PDPA / Local Regulations — We respect applicable local health data laws
Do not submit personal medical information through our contact forms. For medical concerns, always consult a licensed healthcare professional. Our platform does not provide medical consultations through contact forms.
Account data
Newsletter data
Contact form submissions
Comment data
Analytics data (Google)
Legal / compliance records
Security / fraud logs
Access
Request a copy of all data we hold about you
Rectification
Correct any inaccurate personal data
Erasure
"Right to be forgotten" — request full data deletion
Restrict Processing
Limit how we use your data in certain situations
Portability
Export your data in a machine-readable format
Object
Object to processing based on legitimate interests
Withdraw Consent
Unsubscribe or change cookie settings anytime
Lodge a Complaint
Complain to your local data protection authority
- Email: contact@drinsight.org
- Response time: Within 30 days
- Identity verification required before processing requests
- No fee charged for rights requests (unless manifestly unfounded or excessive)
- This platform is intended for users 18 years and older
- We do not knowingly collect data from children under 13 (COPPA) or under 16 (GDPR)
- If a child's data is discovered, it will be deleted immediately without notice
- Parents or guardians may contact us at contact@drinsight.org
- Medical content is written for adult healthcare professionals and informed adult readers
Our primary servers are located in the United States. Data may be transferred internationally via third-party services. We ensure adequate safeguards are in place for all international transfers.
- EU Standard Contractual Clauses (SCCs) — for transfers from the EU to third countries
- Adequacy decisions — where recognised by applicable data protection authorities
- Data Processing Agreements (DPAs) — signed with all third-party service providers
- Privacy Shield successor frameworks — where applicable
TLS 1.2 / 1.3
Encryption in transit (HTTPS)
AES-256
Encryption at rest
Role-Based Access
Least privilege principle
Security Audits
Regular penetration testing
Staff Training
Data protection training for all staff
Incident Response
Breach response plan in place
In the event of a confirmed data breach affecting your personal information, we will notify affected users within 72 hours of discovering the breach, as required by GDPR and applicable laws.
No method of transmission over the internet is 100% secure. We strive for best-in-class security but cannot guarantee absolute security of data transmitted to or stored on our platform.
We reserve the right to update this Privacy Policy at any time. Continued use of the platform after changes constitutes acceptance of the updated policy.
- Email notification to all registered users
- Prominent banner notice on website homepage
- Updated "Last Modified" date and version number at top of this page
| v2.1 | June 2026 | Added cookie categories table, updated third-party service list, updated retention periods |
| v2.0 | January 2025 | Full rewrite for GDPR compliance, added DPA references, updated breach notification procedures |
| v1.0 | March 2023 | Initial Privacy Policy published |
📍 Mailing Address
DrInsight Inc.
Badin
Pakistan
We aim to respond to all privacy-related requests within 5–7 business days. Data subject rights requests will be fulfilled within 30 days as required by GDPR.