Privacy Policy

Effective Date: October 5, 2026

Entity: Shalom Institute of Mental Health and Research ("SIMHAR", "Institute", "We", "Us", or "Our")

Website: https://simhar.com

Contact / Nodal Officer: Privacy & Data Protection Officer (hello@simhar.com)

1. Introduction & Overview

At Shalom Institute of Mental Health and Research (SIMHAR), we understand that mental healthcare, clinical treatment, and academic research involve exceptionally sensitive information. We are committed to protecting the privacy, dignity, and personal data of our patients, clinical research participants, facility visitors, online users, and staff.

This Privacy Policy governs the collection, use, processing, storage, disclosure, and protection of personal data and Sensitive Personal Data or Information (SPDI) collected through our inpatient and outpatient facilities, digital health platforms, research activities, and official website.

This policy has been framed to comply comprehensively with applicable domestic Indian statutory laws and international global data protection standards:

2. Information We Collect

We categorize the data collected into non-sensitive personal data and sensitive medical/health data:

A. Patient & Clinical Information (Sensitive Health Data)

B. Research Data

C. Website & Digital Platform Data

3. Legal Grounds & Statutory Compliance for Data Processing

We collect and process data under clear, lawful bases recognized under Indian and global frameworks:

  1. Explicit Consent (Section 6, DPDP Act 2023 / Art. 6 & 9, GDPR): Free, specific, informed, unconditional, and unambiguous consent obtained via written or digital consent forms before treatment, research enrolment, or website data collection.
  2. Medical Emergency / Provision of Healthcare (Section 7, DPDP Act / Art. 9(2)(h), GDPR): Necessary for medical diagnosis, provision of emergency mental health treatment, or medical care when a patient is temporarily incapable of giving explicit consent.
  3. Legal Obligations & Statutory Mandates: Compliance with court orders, regulatory reporting under the Mental Healthcare Act 2017, or child protection statutes (e.g., POCSO Act in India).

4. Special Mental Health Confidentiality Clauses (Indian & Global Laws)

Due to the sensitive nature of psychiatric and psychological care, SIMHAR enforces heightened confidentiality protocols. Our core confidentiality protections rest on three pillars:

Section 23, MHCA 2017 DPDP Act / GDPR Media Protection (Section 24, MHCA)
Statutory right to confidentiality for mental health records. Heightened protection for Sensitive Personal Data or Information (SPDI). Strict prohibition of patient identifiers and photos.

Clause 4.1: Statutory Confidentiality (Section 23, Mental Healthcare Act, 2017)

All health professionals at SIMHAR have a strict legal duty to keep all information obtained during care or treatment confidential. Information will NOT be released to third parties unless one of the following legal exceptions applies:

Clause 4.2: Protection from Media and Public Exposure (Section 24, MHCA)

In compliance with Section 24 of the Mental Healthcare Act, 2017:

Clause 4.3: Right to Access Records & Medical Restrictions (Section 25, MHCA / Article 15 GDPR)

Patients have the right to access their basic medical records. However, under Section 25(2) of the MHCA, the treating mental health professional in charge may temporarily withhold specific parts of the record if disclosing it would cause serious harm to the mental health, physical health, or safety of the patient or others.

5. How We Use Your Information

SIMHAR processes personal and health data strictly for specified, lawful purposes:

6. Data Sharing, Disclosures, and International Transfers

SIMHAR does not sell, rent, or commercially exploit any patient or user data under any circumstances.

A. Third-Party Service Providers (Data Processors)

We may share minimal required data with trusted third-party providers (e.g., cloud EHR platforms, secure payment gateways, diagnostic laboratories). All such processors are bound by strict Non-Disclosure Agreements (NDAs) and Data Processing Agreements (DPAs) requiring equivalent security standards.

B. Cross-Border Data Transfers (GDPR / DPDP Act)

For international tele-consultations, foreign research collaborations, or international cloud storage:

7. Data Security & Storage Standards

We employ administrative, physical, and technical safeguards to prevent unauthorized access, loss, or leakage:

Security DomainImplemented Controls & Protocols
EncryptionEnd-to-end encryption for tele-health calls; AES-256 for data at rest; TLS 1.3 for data in transit.
Access ControlRole-Based Access Control (RBAC); multi-factor authentication (MFA) for electronic health records (EHR).
Physical SecurityRestricted physical access to medical records archive rooms; 24/7 CCTV monitoring of administrative premises.
Audits & LoggingImmutable access logs detailing who viewed, modified, or downloaded patient records, audited periodically.

8. Data Retention and Destruction

9. Your Data Rights

Depending on your jurisdiction (under DPDP Act 2023, MHCA 2017, or GDPR), you hold the following rights regarding your personal data:

  1. Right to Information & Summary: Request a summary of personal data processed and processing activities.
  2. Right to Rectification & Erasure: Request correction of inaccurate data or deletion of personal data (subject to statutory clinical retention mandates).
  3. Right to Withdraw Consent: Revoke consent for processing at any time (does not affect lawful processing conducted prior to revocation).
  4. Right to Nominate (DPDP Act): Nominate an individual to exercise data rights in the event of death or incapacity.
  5. Right to Grievance Redressal: Access swift, transparent mechanisms to resolve data privacy concerns.

10. Grievance Officer & Contact Information

In compliance with the Digital Personal Data Protection Act, 2023, and the IT (Reasonable Security Practices) Rules, 2011, SIMHAR has appointed a dedicated Data Protection & Grievance Officer.

For privacy complaints, access requests, or rights enforcement, please contact:

Data Protection & Grievance Officer
Shalom Institute of Mental Health and Research (SIMHAR)
Address: Vazhukkapara, Kinavallur P.O., Parali, Palakkad – 678612, Kerala, India
Email: hello@simhar.com
Phone: (+91) 811 308 7028
Working Hours: Monday to Saturday, 9:00 AM – 5:00 PM IST

We will acknowledge receipt of any privacy complaint within 24 to 48 hours and aim to resolve all grievances within 15 business days.

11. Updates to This Privacy Policy

SIMHAR reserves the right to update or modify this Privacy Policy to reflect changes in legal requirements, operational practices, or technological advancements. Material changes will be published on our official website with an updated "Effective Date." Continued use of our services or website constitutes acceptance of the revised policy.