Privacy Policy
How Kiwi Consulting Group collects, uses and protects personal data across our website and our consulting engagements.
Effective 26 July 2026 · Last updated 26 July 2026
Kiwi Consulting Group (“Kiwi Consulting”, “we”, “us” or “our”) is a healthcare consulting practice operated by Agastya Healthcare Consulting Pvt. Ltd., a company incorporated under the Companies Act, 2013, with its registered office at TODO(legal): registered office address, Mumbai, Maharashtra, India.
This Privacy Policy explains how we collect, use, disclose, retain and protect personal data when you visit kiwiconsulting.in (the “Website”), contact us, subscribe to our insights, apply for a role with us, or engage us for consulting services.
We are the “Data Fiduciary” in respect of the personal data described in this policy, and you are the “Data Principal”, as those terms are used in the Digital Personal Data Protection Act, 2023 (the “DPDP Act”). We also process personal data in accordance with the Information Technology Act, 2000 and the rules made under it.
Please read this policy together with our Terms of Service.
1. Scope of this policy
This policy applies to personal data we collect through the Website and in the course of our business dealings — enquiries, subscriptions, recruitment, and client engagements.
It does not apply to third-party websites we link to, which have their own privacy practices.
Where we act for a client under a signed engagement letter or master services agreement, that agreement governs our handling of the client’s data. This policy supplements it and does not override it.
2. Personal data we collect
Information you give us directly
- Identity and contact details — your name, email address, telephone number and, where you choose to provide it, the organisation you represent.
- Enquiry details — the category of your enquiry and the contents of any message you send us through the contact form, by email, or by telephone.
- Subscription details — the email address you provide when you subscribe to our insights and updates.
- Recruitment details — where you apply for a role with us, your CV, employment history, qualifications, and any other information you choose to share.
- Engagement correspondence — information shared with us during a consulting engagement, including scheduling details and the contents of meetings, calls and written correspondence.
Information we collect automatically
- Technical data — your IP address, browser type and version, device type, operating system, language preference and the approximate location derived from your IP address.
- Usage data — the pages you view, the links you follow, the date and time of your visit, and the website you arrived from.
- Log data — records generated automatically by our hosting and infrastructure providers for security, diagnostics and abuse prevention.
Information we receive from others
- Referral information — where an existing client, partner or professional contact introduces you to us.
- Publicly available information — professional information from public sources such as company websites and professional networking platforms, used to understand the organisations we work with.
3. How we use your personal data
We use personal data for the following purposes, and no others:
- To respond to enquiries you submit through the Website, by email or by telephone, and to arrange consultations.
- To provide, manage and deliver consulting services under an engagement with your organisation.
- To send you the insights and updates you have subscribed to, and to allow you to unsubscribe at any time.
- To assess applications for employment and to communicate with candidates.
- To operate, maintain, secure and improve the Website, including diagnosing faults and preventing misuse.
- To maintain business records and to meet our legal, regulatory, accounting and tax obligations.
- To establish, exercise or defend legal claims.
We process personal data on the basis of the consent you give when you submit it, or where processing is necessary for a legitimate use permitted under the DPDP Act — including where you have voluntarily provided your personal data for a specified purpose and have not indicated that you object to its use for that purpose, and where processing is required to comply with law.
We do not sell your personal data. We do not share it with advertisers. We do not use it for automated decision-making that produces legal or similarly significant effects.
4. Client engagement data and confidentiality
Our consulting work brings us into contact with the operations of hospitals, clinics, diagnostic centres and individual practitioners. Where an engagement requires us to review data that includes patient information or other sensitive personal data, we act on our client’s instructions and process that data only for the purposes of the engagement.
- We ask clients to provide anonymised or de-identified data wherever the objective of the engagement can be met without identifiable patient information.
- Access is restricted to the consultants assigned to the engagement, on a need-to-know basis.
- Our personnel are bound by written confidentiality obligations that survive the end of the engagement.
- We return or securely destroy engagement data in accordance with the terms of the relevant engagement letter or master services agreement.
Nothing in this policy overrides the confidentiality provisions of a signed engagement agreement. Where the two differ in respect of client data, the engagement agreement prevails.
7. Where your data is stored
Personal data submitted through the Website is stored on servers operated by our infrastructure providers. Some of those providers operate data centres and content-delivery infrastructure outside India, which means your personal data may be transferred to and stored in another country.
Where personal data is transferred outside India, we do so in accordance with the DPDP Act and any restrictions notified by the Central Government, and we require the recipient to apply protections consistent with this policy.
8. How long we keep your data
We keep personal data only for as long as it is needed for the purpose for which it was collected:
- Enquiries that do not lead to an engagement — up to 24 months from the last correspondence, so that we can follow up and keep a record of the enquiry.
- Subscription data — until you unsubscribe, after which your address is removed from our active mailing list.
- Recruitment data — up to 12 months after a hiring decision, unless you ask us to remove it sooner or agree to us keeping it on file for longer.
- Engagement records — for the period specified in the engagement agreement, and otherwise for the period required by applicable accounting, tax and limitation laws.
When personal data is no longer needed and we are not required by law to retain it, we erase it or irreversibly anonymise it.
9. How we protect your data
We maintain reasonable security safeguards appropriate to the nature of the personal data we hold, including:
- Encryption of data in transit using TLS across the Website and our application interfaces.
- Access controls that limit personal data to personnel who need it for their role.
- Segregated, access-controlled storage for client engagement material.
- Written confidentiality undertakings from our personnel and contractors.
- Periodic review of the security practices of the providers we rely on.
No method of transmission or storage is completely secure. While we take reasonable steps to protect personal data, we cannot guarantee absolute security. If a personal data breach occurs, we will notify the Data Protection Board of India and the affected Data Principals as required under the DPDP Act and the rules made under it.
10. Your rights
As a Data Principal under the DPDP Act, you have the following rights:
- Right to access — obtain a summary of the personal data we process about you, the processing we carry out, and the identities of other Data Fiduciaries and processors with whom it has been shared.
- Right to correction and completion — have inaccurate or misleading personal data corrected, incomplete data completed, and outdated data updated.
- Right to erasure — request deletion of personal data that is no longer necessary for the purpose for which it was collected, unless we are required by law to retain it.
- Right to withdraw consent — withdraw your consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
- Right of grievance redressal — raise a grievance with us about our handling of your personal data, and escalate it to the Data Protection Board of India if you are not satisfied with our response.
- Right to nominate — nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
To exercise any of these rights, write to our Grievance Officer using the details at the end of this page. We may ask you for information to verify your identity before acting on a request. We will respond within the timelines prescribed under applicable law, and in any event within 90 days of receiving a grievance.
You are responsible for the accuracy of the information you give us, and for not impersonating another person when exercising these rights.
11. Children’s data
The Website is intended for professional and business audiences and is not directed at children. We do not knowingly collect the personal data of a child under 18 without the verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us with personal data, contact our Grievance Officer and we will delete it.
12. Third-party links
The Website may link to third-party websites, including professional networking platforms and publications referenced in our insights. We do not control those websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of any website you visit through a link on our Website.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, our technology or the law. When we do, we will revise the “Last updated” date shown at the top of this page. Where a change materially affects how we use your personal data, we will take reasonable steps to bring it to your attention. Continuing to use the Website after a change takes effect indicates that you have read the revised policy.
14. Contact us
If you have a question about this policy, wish to exercise your rights, or want to raise a grievance about how we handle your personal data, contact our Grievance Officer using the details below.
We will acknowledge your communication and respond within the timelines set out under applicable law. If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India.
