This Privacy Policy explains how Carehorizon Health Private Limited, operating under the brand Diagnex, collects, uses, shares, protects and retains personal information through diagnexhealth.com and related corporate enquiry and payment-support workflows.
Carehorizon Health Private Limited ("Carehorizon", "Diagnex", "we", "us" or "our") is responsible for the personal information processed through the Diagnex corporate website and the enquiry workflows described in this policy. This policy does not replace privacy notices that may apply to a separate patient application, clinical system, doctor portal, partner portal or other Diagnex service where a more specific notice is provided.
Depending on how you use the website, we may collect:
We do not ask for full card numbers, CVV, PINs or OTPs through Diagnex website forms.
Where processing depends on your consent, you may withdraw that consent for future processing, subject to processing that is otherwise permitted or required by law.
The corporate website is primarily an information and enquiry channel, not a clinical record system. If a care pathway requires health information, Diagnex should collect it through the relevant protected clinical or operational workflow and limit access to people who need it for an authorised purpose.
When online payments are enabled, payment processing may be carried out by a bank, card network, payment gateway or other regulated payment service provider. Diagnex may receive transaction status, amount, reference numbers and limited payment metadata needed for reconciliation, refunds and audit.
Diagnex does not intend to store customers' full card number, CVV, card PIN or banking OTP. Payment credentials should be entered only on the payment page or interface provided for that purpose.
We retain information only for as long as reasonably necessary for the purpose for which it was collected, including enquiry follow-up, service operations, transaction reconciliation, audit, fraud prevention, legal claims and statutory accounting or tax requirements. Information that is no longer required should be deleted, anonymised or securely archived according to the relevant system and legal requirement.
Diagnex uses reasonable administrative and technical safeguards appropriate to the information and system involved. These may include HTTPS, access controls, secure sessions, server-side handling of sensitive writes, logging, restricted storage and controlled provider access. No internet service can guarantee absolute security, and users should avoid sending unnecessary sensitive information through ordinary email or website forms.
Subject to applicable law and the context of the request, you may contact us to:
We may need to verify your identity before acting on a request and may retain information where required by law or necessary for legitimate legal, audit, security or transaction purposes.
The corporate website is not designed for children to independently submit healthcare or payment information. A parent, lawful guardian or authorised adult should use Diagnex channels on behalf of a child where appropriate. Child-related clinical information should be handled only through the relevant approved care workflow.
We may update this policy when our website, services, legal obligations or data-handling practices change. The effective date at the top of this page identifies the current published version.
For a privacy question, correction request or grievance, use Email Diagnex, Call Diagnex, or use the Grievance & Escalation page. Please identify the request as a privacy matter and provide only the minimum information needed for us to locate the relevant enquiry or transaction.