Transparency

KidsHealth360 Trust Centre

A child's health record is the most sensitive data a family will ever hand to a piece of software. This page explains — without legal jargon — exactly how KidsHealth360 stores that data, who can see it, what our AI does and does not do, and how a parent can take everything back at any time.

Operated by Acquity Growadvice LLP · Last updated 20 August 2026

Data protection at a glance

The three numbers that matter most, before you read a single clause.

100%

Sensitive health fields encrypted at rest (AES-256-GCM)

100%

Child records gated behind verified guardian consent

0%

Data sold, rented or used for advertising — ever

Breach notification clocks

CERT-In reporttarget: within 6 hours
Data Protection Board notificationtarget: within 72 hours

Security

Encryption, hosting and access control.

  • Sensitive health and identity fields are encrypted at rest with AES-256-GCM; everything travels over TLS.
  • Data is hosted on managed infrastructure located in India.
  • Every account is role-scoped — a parent, teacher, principal, doctor and therapist each see a different slice of the platform, enforced at the database layer, not just in the interface.
  • Staff and clinician accounts are subject to multi-factor enrolment checks and cannot elevate their own privileges.
  • Every read, write, export and emergency disclosure is written to an append-only audit log that cannot be edited or deleted by anyone, including us.
  • Backups are encrypted and restore procedures are tested.
No platform can promise absolute security. What we can promise is that safeguards are in place, that access is logged, and that you will be told if something goes wrong — see Compliance below for our breach-notification clocks.

Access — who can see what

Role by role, data category by data category.

DataParentTeacherSchool adminDoctorTherapist
Child identity (name, class, photo)FullOwn classOwn schoolOn grantOn consent
School screening results (vision, dental, RBSK)FullOwn classOwn schoolOn grantNo
Uploaded medical reports & prescriptionsFullNoNoOn grantNo
Emergency card (blood group, allergies)FullEmergency scanEmergency scanEmergency scanNo
Growth, nutrition & digital-wellness logsFullNoAggregate onlyOn grantNo
Therapy & counselling notesAge-tieredNoAggregate onlyNoFull
ABHA number and linkage statusFullNoNoOn grantNo
  • On grant means a doctor sees a child's record only after the guardian explicitly grants access, and only until the guardian revokes it.
  • Emergency scan means the emergency card only — blood group, allergies and guardian contact — reachable by scanning the child's Health Passport, and every scan is logged.
  • Aggregate only means counts and trends across a class or school, never a named child.
  • Age-tiered means older children get a confidentiality tier over counselling notes, in line with clinical practice; safety concerns are always escalated to the guardian.
  • KidsHealth360 staff do not browse child records. Support access is limited, purpose-logged and time-bound.

AI privacy

Exactly what the AI features do, and what they never do.

AI is used in a small number of clearly labelled places:

  • Summarising a child's recent health signals into a plain-language "Today" view for the guardian.
  • Drafting nutrition and vitamin guidance from logged meals and growth data.
  • Suggesting smart reminders and follow-up nudges after screenings.
  • Preparing a doctor-visit brief from records the guardian already holds.

And these are the hard limits:

  • Child health data is never used to train any AI model — ours or a vendor's.
  • AI output is guidance, never a diagnosis. Clinical decisions stay with a registered practitioner.
  • Direct identifiers are minimised before a request leaves the platform; only the fields needed for the specific summary are sent.
  • AI is never used to decide eligibility, to profile a child, or to target advertising — we run no advertising at all.
  • Every AI call is recorded in an inference log for audit, including which feature invoked it.
  • A guardian can ignore or dismiss any AI suggestion, and school staff never see a child's AI summaries.

Sharing

The complete list of who a child's records can reach.

  • The child's school — screening entries the school itself recorded, plus the emergency card.
  • A doctor — only for the duration of a guardian-issued access grant, revocable in one tap.
  • A therapist or counsellor — only after a separate therapy consent.
  • Emergency responders — the emergency card, via a Health Passport scan, logged every time.
  • Government health programmes — RBSK and RPwD submissions where the school is statutorily required to report, through official channels.
  • Processors that run the platform — hosting, SMS, email and payments — contractually bound, no independent use of the data.
We do not sell, rent, barter or share personal or health data for anyone's marketing, advertising or profiling — ever. There is no ad tech in this product.

Export

Download the child's complete record, whenever you want.

  • Account → Settings & privacy → Export my data produces a machine-readable file containing the child's profile, screenings, reports, appointments, consents, payments and audit history.
  • Uploaded documents can be downloaded individually from the Health Vault; the consent forms and Health Passport print as PDFs.
  • Exports are generated on demand and delivered to the signed-in guardian only.

Delete

Withdraw consent, erase the profile, or both.

  • Withdraw consent — processing stops and the portal is locked. The record of the withdrawal itself is kept as legal proof.
  • Delete the account — the guardian and children profiles, reports, screenings, appointments, messages and stored files are erased, along with the sign-in account.
  • Where a record must be retained by law — such as a statutory screening submission or a payment receipt — it is retained for that period only, and everything else is deleted or irreversibly anonymised.
  • An erasure reference number is issued so the guardian has documentary proof of the request and its completion.
  • Automated retention sweeps delete data whose retention period has expired, without waiting for a request.

ABDM / ABHA interoperability

Where we are today, and where we are going.

Available today:

  • A guardian can link a child's existing ABHA number to their KidsHealth360 profile after guardian authorisation.
  • Verified ABHA demographics can pre-fill the Add-a-child form, so the guardian re-types nothing.
  • Every ABHA action — lookup, authorisation, link, unlink — is written to a dedicated, append-only ABHA audit log.

Deliberately not built:

  • We do not create ABHA numbers, and we do not store Aadhaar numbers — only the last four digits, where the guardian chose Aadhaar-based verification.

Roadmap:

  • Consent-manager based record exchange, so a guardian can pull records from, and push records to, other ABDM-linked providers.
  • Health-record linkage with participating hospitals and labs.
  • Alignment with ABDM health data standards as they are finalised for paediatric records.

Compliance

The laws and standards this platform is built around.

  • Digital Personal Data Protection Act, 2023 — verifiable guardian consent for a child's data, purpose limitation, data minimisation, storage limitation, and no tracking, behavioural monitoring or targeted advertising directed at children.
  • Data principal rights — access, correction, erasure, nomination and grievance redressal are all implemented in-product, not just promised on paper.
  • Breach notification — an internal dual-clock runbook targets CERT-In reporting within 6 hours and Data Protection Board notification within 72 hours, with draft reports generated automatically.
  • Statutory school health programmes — RBSK and RPwD Act screening workflows follow the prescribed forms and referral pathways.
  • Grievance OfficerBaldeep Singh, Data Protection Officer & Grievance Officer, info@kidshealth360.com, +91 78145 24624. If you are not satisfied with our response, you may approach the Data Protection Board of India.

Security reports

Independent assessments will be published here as they are completed.

We have not yet published any third-party audit, penetration-test summary or certification. Rather than imply assurances we do not hold, this section stays empty until reports exist — and each one will be listed here with its date and scope when it does.

Security researchers can report a suspected vulnerability to info@kidshealth360.com. Please give us reasonable time to remediate before any public disclosure, and never access or retain another family's data while testing.

Still have a question?

Write to info@kidshealth360.com or call +91 78145 24624. Acquity Growadvice LLP, A-816 Bestech Business Towers, Sector 66, Mohali, Punjab 160062, India. Signed-in parents can see their own consent, access list, sharing log and audit trail under Account → Trust Centre.