Privacy Policy
idinsayit is a publication and a private clinical practice. Nothing here is solved in a paragraph.
This page says what we hold, why we hold it, who can see it, and how you get it back or get it deleted. It is written to be understood, not to be impressive. If any part of it is unclear, write to us and we will explain it in plainer words.
Last updated: 16 September 2026
Who is responsible
The site is operated by idinsayit, at Hyderabad, India.
Under India’s Digital Personal Data Protection Act 2023 we are the Data Fiduciary for the personal data described here. Under the UK and EU GDPR, for readers in those places, we are the controller.
We trade as idinsayit. Editorial correspondence is answered by the editors. Anything concerning the practice is answered by the clinician who runs it, Rohit R. Vangimalla, or by a member of the clinical team.
The site and its database are hosted in India.
The short version
- We collect as little as we can, and we say what each piece is for.
- We do not sell personal data. We have never done so and we will not.
- We do not use anything you write to train machine-learning systems, ours or anyone else’s.
- Client written work is the most protected material we hold. It is fenced off from the public site entirely.
- Analytics on this site is cookieless and self-hosted. No reader-level data goes to any third party.
1. Readers
You do not need an account to read. Most readers give us nothing at all.
The letter (newsletter)
What we hold: your email address, the date you subscribed, and a record of that consent. If you tell us your first name we hold that too; it is optional.
Why: to send you the letter. Nothing else.
Lawful basis: your consent (DPDP s.6; GDPR Art 6(1)(a)). You gave it by subscribing. You can take it back at any time using the unsubscribe link at the foot of every letter, or by writing to iam@idinsayit.com.
Who sees it: the editors, and Brevo, which is the service that actually sends our email. Brevo processes it on our instructions and may not use it for anything of its own.
How long: until you unsubscribe. After that we keep only your email address on a suppression list, so that we do not accidentally write to you again. You can ask us to delete that too.
We do not sell, rent, swap or share the subscriber list.
What is free to read
Some pieces are marked free and anyone may read them. The rest need a subscription. Nothing counts how many you have opened and nothing records which ones, because there is no allowance to keep track of.
What we hold: nothing. There is no meter, no counter and no cookie recording what you read, because there is no allowance to enforce. Read one free piece or forty and your browser keeps nothing either way.
Every cookie this site does set is listed, with what it is for, on the Cookie Policy.
Analytics
We use Koko Analytics, installed inside our own WordPress. It is worth being exact about what this means:
- It is cookieless. It does not set an identifier on your device.
- It is self-hosted. The data sits in our database on our server in India. It is not sent to Google, to Meta, or to anyone else.
- It does no cross-site tracking. We cannot see where you go after you leave, and we have no idea what you do on other sites.
- It records page views, referring page, and coarse counts. Not you.
- It is switched off entirely inside the client portal. Practice pages are not measured at all.
Lawful basis for readers in the EU/UK: our legitimate interest in knowing which pieces are read (GDPR Art 6(1)(f)). Because it stores nothing on your device and holds no personal data, there is nothing for you to consent to and nothing for us to give back to you from it.
Server logs and security
Our host keeps standard web server logs (IP address, time, page requested, browser string) for security, abuse prevention and fault-finding. We keep them for 30 days and then they are discarded. Legitimate interest; we do not use them to build a picture of any reader.
Comments and letters to the editors
If you write to us, we keep the correspondence so that we can answer it and so we can find it again if you write later. We keep it for two years unless it concerns the practice, in which case it is treated as a clinical record and follows the retention rule in section 3.
2. Members and subscribers
If you take a paid subscription, or later enrol in a programme, you become a member.
Payment details
Payments are handled by Razorpay. Card numbers, UPI handles, netbanking credentials and bank details are entered on Razorpay’s systems and are held by Razorpay. They never touch our server and we never see them. Razorpay is the controller of that data for its own regulatory and anti-fraud duties and processor for us for the transaction itself. Their own privacy terms apply to it.
What comes back to us from Razorpay is a payment ID, the amount, the currency, the status, the date, and the last four digits and card type where a card was used, and your billing state or country where the payment provider passes it to us. That is what we hold.
The membership record
What we hold: your name as you gave it, your email address, your account username, your membership level, the dates it starts and renews, your invoice history, your billing state or country where the payment provider passes it to us, and the payment references above.
Why: to give you the thing you paid for, to bill you, to issue a valid invoice, and to keep the accounts we are required by law to keep.
Lawful basis: your consent, given at checkout (DPDP s.6), plus our legal obligation to keep tax records. For readers in the EU or UK, performance of a contract with you (GDPR Art 6(1)(b)).
Who sees it: the editors. Razorpay for payment. Brevo for the transactional email that tells you a payment went through or is about to.
How long: for as long as you are a member, and afterwards for as long as accounting and tax law requires us to keep records of a sale, currently eight years from the end of the relevant financial year. When you close an account we cut the record back to that legal minimum and delete the rest.
Email you cannot turn off
Receipts, renewal notices, failed-payment notices and account security messages are transactional. They are part of the service, they are not marketing, and they go out for as long as you hold an account. The letter is separate and is opt-in.
3. Practice clients
This section is about people treated by our clinical practice. It is the part of this policy we most want read.
Everything here is over and above the rest of this document. Where the two differ, this section wins.
What we hold
- Your account. A username, an email address, and a password stored only as a hash. We cannot read your password.
- Intake answers. What you told us when you started: history, substance use, previous treatment, health information relevant to your care, and your contact details.
- Your written work. The worksheets a clinician assigns to you, one at a time, and everything you write in them. Drafts included. Your writing is saved to our database as you work, not left on your device.
- Files you attach. Scans of a worksheet you answered on paper, kept as files on our own server outside the public site, beside the written work they belong to.
- Clinician feedback. What the clinician writes back to you, and the clinical notes made about your care.
- Administrative traces. When a worksheet was assigned, when you submitted it, when it was reviewed.
- Your journal. Whatever you choose to write in it. You write it for yourself and nobody sets you the subject, but it is not sealed: the clinician treating you can read it, because it is of no use in your care if they cannot.
- Messages between you and your clinician. The thread itself, and when each message was read.
- Appointments and the session ledger. The times you asked for, the times that were confirmed, and the account of your prepaid block: what you bought, what has been used, and how each past session was marked.
Who can see it
- You. Everything of yours, through the portal, whenever you are signed in.
- The clinical team members involved in your care. Your own clinician, and anyone covering for them.
- The person who runs the practice. One person, who can reach every client record, because somebody has to be answerable for all of it, for supervision, for a complaint, and for the day your clinician is unreachable. We would rather name that access here than let you find it out.
- The site’s technical administrator, only when maintaining or restoring the system, and never as reading matter.
Nobody else. Specifically:
- Your writing is excluded from search results, from feeds, from the sitemap, from the public REST API, and from analytics. It is not published anywhere on the site and no crawler can reach it.
- Koko Analytics does not run on portal pages at all.
- Editors who do not work clinically do not have access to client material.
- Nothing you write in the portal is used in the publication. If we ever wanted to draw on clinical material for a published piece, we would ask you first, in writing, and a refusal costs you nothing and changes nothing about your care.
What we will never do with it
- We do not use it to train anything. Not a machine-learning model, not an AI system, not a product, not ours and not a third party’s. Your writing is not training data. It is not sent to any external system for processing.
- We do not sell it. Not to anyone, at any price, in any form, aggregated or otherwise.
- We do not share it with insurers, employers, family members, referrers or anyone else without your specific, informed consent, which you can give for one purpose and withdraw afterwards.
The one exception
We may have to disclose clinical information without your consent where the law compels it: a valid order of a court, a lawful demand by a competent authority, a serious and immediate risk to your life or to someone else’s, a child at risk, which the law obliges anyone to report, or, where your care needs it, your nominated representative or another professional treating you, as the Mental Healthcare Act 2017 allows. This is narrow, and it is the same exception any clinician works under. Where we are legally allowed to tell you that a disclosure has been made, we will tell you.
Lawful basis
Health data is sensitive. Under GDPR, where it applies, we rely on your explicit consent (Art 9(2)(a)) and on the provision of health care under Art 9(2)(h), with Art 6(1)(b) for the underlying agreement. Under DPDP we rely on your consent, given at intake, for a purpose we stated plainly at the time.
Consent to treatment can be withdrawn at any point. Withdrawing it ends the treatment; it does not by itself delete records we are required to keep, and section 3’s retention rule then applies.
How long we keep it
- While you are in treatment: for as long as your care continues.
- After your last contact with the practice: three years, so that care can be picked up again and so we can answer a later question about what was done.
- Then it is deleted.
You can ask us to erase your material sooner, and we will unless a specific law requires us to hold it. If part of a record must be kept, we delete the rest and tell you exactly what remains and why.
Getting a copy, or getting it deleted
Write to iam@idinsayit.com from the address on your account, or ask your clinician.
- Export: we will send you everything you have written, together with the feedback written to you and a summary of the clinical notes made about your care, in a readable file. The notes themselves are the clinician’s working record; the summary says what they cover. Free. Within 30 days, usually much sooner. The programme material itself is ours and stays in the portal, so it is not in the file; what you wrote in response to it is yours and all of it is.
- Erasure: we will confirm what will be deleted, and what (if anything) the law makes us keep, before we do it. Deletion is permanent and we cannot undo it.
- Correction: if something in your record is factually wrong, tell us and we will correct it. Clinical opinion is not deleted on request, but your disagreement is recorded alongside it and travels with the record.
We may ask you to confirm your identity first. That is to protect you, not to delay you.
4. Your rights
Under the DPDP Act 2023 (India)
- Access. A summary of the personal data we hold about you, what we are doing with it, and who else has had it.
- Correction, completion, updating and erasure of your personal data.
- Grievance redressal. A route to complain to us, with a real person who has to answer. See the block below.
- Nomination. You may nominate another individual to exercise these rights on your behalf if you die or become incapable of exercising them yourself. How to do that is on the Data Protection & Grievance Redressal page.
You also have duties under the Act: give us information that is true, and do not file a false or frivolous complaint.
Under the GDPR (EU/UK readers)
- Access: a copy of your data.
- Rectification: correction of what is wrong.
- Erasure: deletion, where no law requires us to keep it.
- Restriction: a pause on our use of it while a dispute is resolved.
- Portability: your data in a machine-readable file, or sent to another controller.
- Objection: to any processing we base on legitimate interests, and to direct marketing at any time, absolutely.
You may also withdraw consent at any time, without it affecting what we lawfully did before you withdrew it, and you may complain to your national supervisory authority: in the UK, the Information Commissioner’s Office.
We do not make any decision about you by automated means alone, and we do no profiling.
Transfers
Our servers are in India. If you are in the EU or UK, your data is processed outside your region. Where we send personal data to a processor outside India or the EEA (Brevo for transactional email, Brevo for the newsletter, Razorpay for payment), it moves under that provider’s contractual data protection terms, including standard contractual clauses where they are required. We keep what crosses a border to the minimum: an email address for the letter, a payment reference for a sale. Client clinical material stays on our own server. Three things leave it, and they are all listed elsewhere on this page: a portal invitation or appointment confirmation, which goes by email through Brevo and carries your name and a time but nothing about your treatment; an export you have asked for, which goes to you; and our backups, which sit with our hosting provider, Hostinger, under their own security terms. Hostinger also runs the network in front of the site, which passes every request to the server and keeps ordinary access logs. Nothing else goes anywhere, and nothing at all goes to anyone who has not been named on this page.
5. Children
The publication is written for adults. We do not collect data from anyone under 18 without the verifiable consent of a parent or lawful guardian, and we never use a child’s data for tracking, advertising or profiling. Treatment of a minor is arranged directly with a parent or lawful guardian, whose verifiable consent is taken before any account exists.
6. Security
Access to the portal requires a sign-in. Client material is separated from the public site at the application level. Access is limited to the clinical team involved in a client’s care, the one person who runs the practice, and the site’s technical administrator when maintaining or restoring the system. That is the same list as in section 3, and it is the whole list. Passwords are stored hashed. The site runs over HTTPS. Backups are taken daily and held by our hosting provider under their own security terms. Each is kept for three years and then deleted by hand; a record you ask us to erase leaves the live system at once and leaves the backups as they are deleted.
No system is perfect. If personal data of ours is breached, we will tell the Data Protection Board of India and every affected person. The Act sets no threshold for that and we are not going to invent one: there is no level of breach we would decide was too small to mention to you. We will tell you what happened in plain terms, what was involved, and what to do about it.
7. Changes
If we change this policy we will change the date at the top and, where the change matters, say so on the site. We will not quietly widen what we do with client material.
Grievance Officer
Under section 13 of the DPDP Act 2023, we publish a contact for complaints about how we handle personal data. Write to the Grievance Officer. You do not need a name; the post is what matters.
The Grievance Officer
idinsayit
Hyderabad, India
Email: iam@idinsayit.com
Phone: +91 92700 86548
We acknowledge every complaint within 48 hours and answer it within 30 days. If you are not satisfied with the answer, you may escalate to the Data Protection Board of India. The route is set out on the Data Protection & Grievance Redressal page.
General questions, which are not complaints, go to iam@idinsayit.com.