The Homecare Association of India ("HCAI", "we", "our" or "us") respects the privacy of its members, applicants, committee members, website visitors and other individuals who interact with HCAI.
This Privacy Policy explains what personal data HCAI may collect, why we use it, how we protect it, and the choices available to you.
1. Information We May Collect
Depending on your relationship with HCAI, we may collect information such as:
- Name and professional designation
- Organisation and role
- Email address and mobile number
- City, State and other membership information
- Membership category and status
- Membership ID and credentials
- Committee or working-group participation
- Profile photograph and professional information provided by you
- Membership payment and transaction references
- Communications with HCAI
- Portal activity, login and security information
- Device, browser and technical information required for security and website operation
We aim to collect only information reasonably required for the relevant HCAI purpose.
2. Why HCAI Uses Your Information
HCAI may process personal data to:
- Receive and assess membership applications
- Administer memberships
- Provide access to the HCAI Member Portal
- Issue and verify membership credentials
- Maintain HCAI member records
- Manage committees, working groups and HCAI initiatives
- Communicate membership notices, events and relevant HCAI updates
- Process membership payments and maintain appropriate records
- Protect HCAI accounts, systems and members from misuse
- Maintain appropriate security and audit records
- Respond to member requests and grievances
- Meet applicable legal or regulatory requirements
HCAI will not use personal data for an unrelated purpose merely because it is available to us.
3. Member Portal and Account Security
Each authorised member may receive individual credentials for accessing relevant areas of the HCAI Member Portal.
Members are responsible for keeping their login credentials confidential and should not share passwords or OTPs with another person.
Members should create a unique password for HCAI and should not reuse passwords used for email, banking or other important accounts.
HCAI does not intend to store passwords in readable form. Passwords should be protected using appropriate cryptographic password-hashing practices.
HCAI administrators should not be able to retrieve or view a member's actual password.
If a password is forgotten, HCAI will provide a secure password-reset mechanism rather than disclose the previous password.
HCAI will never ask a member to send their password or OTP by email, WhatsApp or telephone.
4. Access Within HCAI
Access to personal information will be limited according to role and operational need.
Committee membership or HCAI membership does not automatically give an individual access to other members' private information.
Administrative access should be restricted to authorised personnel who require such access for legitimate HCAI functions.
5. Sharing of Personal Data
HCAI does not sell member personal data.
HCAI may use carefully selected service providers where required to operate its website, member portal, communications, payments, hosting, security or other association functions.
Where third parties process personal data on HCAI's behalf, HCAI will seek appropriate contractual and security safeguards.
Information may also be disclosed where required under applicable law or a lawful government or regulatory requirement.
6. Member Directory
Certain professional information may be displayed in an HCAI member directory or verification system where appropriate.
HCAI should clearly distinguish information intended to be public from information maintained privately for membership administration.
Sensitive account information, passwords, OTPs, private contact information and internal administrative information will not be displayed publicly.
Where appropriate, members will be given control over optional directory information.
7. Data Retention
HCAI will retain personal data only for as long as reasonably required for the purpose for which it was collected, HCAI's legitimate administrative requirements, dispute or security requirements, or applicable legal obligations.
When information is no longer required, HCAI will take appropriate steps to delete, anonymise or securely archive it where applicable.
Termination or expiry of membership does not necessarily require immediate deletion of every record where HCAI is required or reasonably needs to retain particular records.
8. Membership Expiry, Resignation or Removal
When membership expires, is resigned, suspended, terminated or otherwise made inactive, HCAI may restrict or deactivate access to member-only systems.
Records that are no longer required will be handled according to HCAI's retention requirements and applicable law.
9. Security
HCAI will take reasonable technical and organisational measures appropriate to the nature of the information it processes.
These may include:
- Secure password hashing
- Encryption where appropriate
- Role-based access controls
- Secure password-reset procedures
- Authentication controls
- Security and access logging
- Backups
- Software and dependency updates
- Restricted administrative privileges
- Incident response procedures
No internet-based service can guarantee absolute security. HCAI will nevertheless take reasonable measures to protect personal data under its control.
10. Personal Data Breaches
HCAI will maintain procedures for identifying, assessing, containing and responding to personal data breaches.
Where notification is required under applicable law, HCAI will follow the applicable requirements for notifying affected individuals and relevant authorities.
11. Your Choices and Requests
Subject to applicable law and the circumstances of the request, individuals may contact HCAI regarding their personal data, including requests relating to correction, updating, access, consent or deletion where applicable.
HCAI may need to verify the identity of the requester before acting on a request.
12. Cookies and Website Technologies
HCAI's website may use cookies or similar technologies required for login, security, preferences, analytics and website functionality.
Where appropriate, HCAI will provide further information and choices through its Cookie Policy or consent interface.
13. Communications
HCAI may contact members regarding their membership, governance matters, security, events, programmes and other association activities.
Where consent or an opt-out is appropriate for optional communications, HCAI will provide the relevant choice.
Essential membership, security and administrative communications may need to continue while an individual remains an HCAI member.
14. Children's Data
HCAI's membership portal is intended for professional and organisational use and is not designed as a service for children.
HCAI does not intentionally seek children's personal data through the member portal.
15. Changes to This Policy
HCAI may update this Privacy Policy as its services, technology or legal obligations change.
The current version and its effective date will be published on the HCAI website.
Material changes may also be communicated to members where appropriate.
16. Privacy and Grievance Contact
Questions, privacy requests or concerns regarding personal data may be sent to:
Homecare Association of IndiaEmail: homecareassociationofindia@gmail.com
Website: https://homecareassociationofindia.org
HCAI will review privacy requests and grievances in accordance with applicable requirements.
Our Principle
HCAI believes that membership should create trust, not require members to surrender unnecessary personal information.
We will seek to collect what we need, explain why we need it, protect it appropriately, and stop retaining it when there is no longer a legitimate reason to keep it.