PRIVACY POLICY
Introduction
Star Health & Allied Insurance Co. Ltd. ("Star Health", "we", "us" or "our") respects your privacy and values the trust you place in us when you share your Personal Data. We are committed to Processing Personal Data lawfully, fairly, and transparently.
This Privacy Policy explains:
- the Personal Data we collect;
- how and why, we process Personal Data; and
- the rights available to Data Principals in relation to their Personal Data.
Definitions
In this Privacy Policy, unless the context requires otherwise:
"Applicable Law" means the laws, rules, regulations, notifications, circulars, guidelines, directions, and orders applicable to Star Health or to the relevant Processing of Personal Data, as amended from time to time. This includes the Digital Personal Data Protection Act, 2023 and the rules made under it, applicable insurance laws and regulations, and directions issued by the Insurance Regulatory and Development Authority of India (IRDAI).
"Child" means an individual who has not completed 18 years of age.
"Consent" means a freely given, specific, informed, unconditional and unambiguous indication of a Data Principal’s wishes, provided through clear affirmative action, agreeing to the Processing of Personal Data for a specified purpose.
"Cookies" means small text files or similar technologies placed on or accessed through a device when a person visits a website or uses a digital service. Cookies may support essential functions, security, preferences, performance, and analytics.
"Data Fiduciary" means a person who, alone or jointly with others, determines the purpose and means of Processing Personal Data. For the Processing described in this Privacy Policy, Star Health acts as the Data Fiduciary unless stated otherwise.
"Data Principal" means the individual to whom Personal Data relates. Where the individual is a Child, the term includes the Child’s parent or lawful guardian; where the individual is a person with a disability who is unable to act independently under Applicable Law, it includes the lawful guardian acting on that individual’s behalf.
"Personal Data" means any data about an individual who is identifiable by or in relation to that data.
"Process", “Processed” and “Processing” mean any wholly or partly automated operation performed on Personal Data, including collection, recording, organization, storage, use, sharing, disclosure, retrieval, alignment, combination, restriction, erasure, or destruction.
"Website" means Star Health’s official website at www.starhealth.in and, where the context requires, its associated webpages and digital services.
"Act" means the Digital Personal Data Protection Act 2023 and the rules made under it, as amended from time to time.
"Data Processor" means any person who processes Personal Data on behalf of a Data Fiduciary.
"Personal Data Breach" means any unauthorized Processing of Personal Data, or any accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to Personal Data, that compromises its confidentiality, integrity, or availability.
Scope
This Privacy Policy applies where Star Health acts as a Data Fiduciary and determines the purposes and means of Processing Personal Data.
It covers Processing carried out in connection with Star Health’s websites, mobile applications, software platforms, insurance products and Services, and related business activities, including events, medical camps, marketing, business partner engagement, and vendor management. It applies to individuals who interact with Star Health, including customers, prospects, policyholders, insured persons, claimants, nominees, employees, intermediaries, vendors, business partners, and their authorized representatives, as relevant to the interaction.
Categories of Data Principals
The categories of Data Principals covered by this Privacy Policy include:
- Insurance prospects, including visitors to our publicly accessible websites and digital platforms;
- Insurance policyholders and proposers;
- Insured persons, including dependents and members covered under individual, family floater, student, travel, and group insurance policies;
- Claimants;
- Nominees; and
- Representatives of policyholders and insured groups, including designated contacts, human resources representatives, administrators, authorized signatories, guardians, legal heirs, and other authorized representatives.
Children's Personal Data
Our websites and digital platforms are not intended to be used independently by persons under 18 years of age. If a parent or lawful guardian has reason to believe that we are Processing a child’s Personal Data without an appropriate legal basis, the parent or lawful guardian may contact us through the mechanism specified in this Privacy Policy and request appropriate action, including deletion where applicable.
Processing Personal Data of Children and Persons with Disabilities
Where we process the Personal Data of a child under 18 years of age, or of a person with a disability who is unable to provide legally valid Consent even after being provided adequate and appropriate support, in connection with our insurance services, we will obtain the prior Consent of the parent or lawful guardian and comply with applicable data protection laws.
Collection of Personal Data
Personal Data Collected Directly from the Data Principal:
Prospect Insurance Journey
During your interactions with us as an insurance prospect, we may collect Personal Data that you voluntarily provide, including when you:
- Visit our website or use our digital services;
- Request an insurance quotation;
- Submit an enquiry or callback request;
- Complete forms requesting assistance or information; or
- Submit any other request for services, support, or assistance.
During this stage, as an insurance prospect, we collect only a limited amount of Personal Data that is necessary to fulfil the specific request you have made. For example, we may collect limited health-related information where it is necessary to generate an initial insurance quotation.
Core Insurance Purpose
This is the next stage of the insurance journey, where you become an insurance applicant after completing and submitting a proposal form, along with the requested supporting documentation, for the purpose of assessing your profile for underwriting.
For the provision, administration, and management of our insurance services (collectively referred to and described as "Insurance Lifecycle Management"), as well as to comply with Applicable Laws, we may collect more detailed Personal Data during this stage.
This may include financial information, health information, and other Personal Data necessary to underwrite risks, provide our products and services, administer policies, provide related services and comply with the requirements under Applicable Laws. More detailed health-related information may also be collected to enable us to accurately assess and underwrite the risks associated with your application.
Personal Data Received from Third Parties:
For Prospect Insurance Journey and Core Insurance Purposes, your Personal Data may be shared, transferred, or made available to us from the following third parties:
Regulated Insurance Distribution and Servicing Partners:
These are IRDAI regulated third parties whose business predominantly involves distributing, arranging, facilitating or servicing insurance products and services, such as:
- insurance brokers;
- insurance intermediaries;
- insurance agents;
- corporate agents;
- insurance marketing firms; and
- other insurers.
Business and Affinity Partners
These are third parties whose primary business activities may not be insurance, but who are authorized to distribute or ease the sale of our insurance products, such as:
- non-banking financial companies (NBFCs);
- bancassurance partners;
- other authorized distribution partners.
For example, a travel agency may offer travel insurance as part of a travel package and share the Personal Data necessary for us to issue or administer the relevant policy. For further information about recipient categories, please refer to the “Disclosure of Personal Data” section of this Privacy Policy.
Group Insurance Policies
Where insurance coverage is provided under a group insurance policy, we may receive Personal Data from the group policyholder to extend coverage to eligible members. For example, where health insurance is provided as an employee benefit, an employer may share its employees’ Personal Data with us to ease coverage under the group policy.
Personal Data Received and Processed Through Insurable Interests
Depending on the insurance product, we may receive and Process Personal Data from a proposer, policyholder, family member, guardian, employer, or another authorized person who obtains and pays for an insurance policy for the benefit of another individual.
Personal Data Obtained Pursuant to Legal and Regulatory Requirements
To comply with Applicable Laws, regulatory requirements, and fraud-prevention obligations, we may obtain or access Personal Data from authorized fraud-detection repositories, government authorized databases, insurance industry repositories, and other lawful sources. These may include the Insurance Information Bureau of India (IIB) and other authorized agencies involved in fraud detection, risk assessment, regulatory compliance or claims verification.
Personal Data Collected Through Cookies and Similar Technologies
When you visit our websites, mobile applications, or other digital platforms, we may collect information through cookies and similar technologies, including:
- online identifiers;
- device and browser information;
- usage and interaction data; and
- technical information relating to your access to and use of our services.
Where this information relates to an identifiable individual, we treat it as Personal Data. We use it to enable essential functionality, enhance security, improve performance and user experience, conduct analytics and service improvement, and remember user preferences. Please refer to our Cookie Policy for information about cookie categories, functions, and preference controls.
Why We Process Your Personal Data
We collect and process Personal Data for lawful purposes, taking account of our relationship with you, the context in which the Personal Data was obtained, and the purposes for which it was provided or otherwise made available.
Insurance Lifecycle Management
As an insurance service provider, we process Personal Data to provide, administer, and manage insurance products and services, including:
- receive and respond to enquiries;
- provide insurance quotations;
- process proposal forms and policy applications;
- conduct underwriting and risk assessment;
- issue insurance policies;
- administer and service policies throughout their lifecycle;
- process endorsements, renewals, and modifications;
- manage claims, investigations, and settlements;
- prevent and detect fraud and protect the security of our services;
- comply with legal and regulatory obligations; and
- Provide customer support and related services.
When you submit an enquiry, request a quotation, complete a proposal form, or otherwise share, make available your Personal Data to us, we process such Personal Data to evaluate your request and take the steps necessary to provide the requested insurance service. During the insurance lifecycle, we may obtain or access additional information needed for underwriting, policy administration, claims administration, settlement, and dispute resolution.
Insurance Risk Management, Fraud Prevention and Security
As part of Insurance Lifecycle Management, we take proportionate measures to protect our customers and business, manage insurance risk, prevent fraud, comply with know-your-customer requirements and applicable anti-money-laundering obligations, and address identity theft and other unlawful activities.
These activities may include verifying whether information or documents submitted to us are false, misleading, inaccurate, or incomplete; verifying identity and eligibility; identifying suspicious transactions or claims; and conducting additional checks where allowed or required by Applicable Law.
For these purposes, we may process government-issued identifiers, including Permanent Account Number (PAN) and Aadhaar information, strictly in accordance with Applicable Law. We may also disclose relevant Personal Data to authorized insurance fraud management databases and industry repositories, including databases maintained by the IIB, where permitted or required by Applicable Law.
Actuarial Research and Analysis:
As required under Applicable Laws, we are mandated to appoint an actuary who is skilled in determining the present financial effects of future contingent events and in conducting financial modelling and risk analysis relating to insurance risks. This includes the design and pricing of insurance products, assessment of benefits, recommendation of insurance rates, and related analyses based on empirical data and statistical methods, including analyses performed with the assistance of statisticians.
For such actuarial research and analysis, we will use your relevant Personal Data to determine and apply appropriate actuarial parameters for assessing risks and uncertainties, particularly those relating to Star Health’s financial sustainability and its ability to manage future claim payouts. This assessment will actively assist us in shaping the design of insurance products and determining the costs of such products in a manner that is financially sustainable for us and affordable for our customers.
Marketing, Business Development and Relationship Management
Subject to applicable Consent, preference, and legal requirements, we may process Personal Data to:
- provide personalized marketing communications in accordance with your selected preferences;
- administer health camps, events, prize draws, competitions, and similar promotional activities conducted by Star Health or its authorized partners;
- generate leads and identify prospective customers;
- provide customer benefits and relevant product information; and
- Manage and develop relationships with customers, prospects, and business partners.
Promotional activities may be governed by additional terms and conditions. We conduct direct marketing in accordance with applicable data protection, telecommunications, anti-spam, and direct marketing requirements. Where Consent is relied upon to conduct such activities, you may withdraw it through the channels described in this Privacy Policy or in the relevant communication channel prescribed to such activity.
Business Operations and Quality Assurance
We process Personal Data to operate our business and improve the quality, consistency, and security of our services. These activities may include:
- managing workflows and allocating work to authorized employees and service providers;
- monitoring and evaluating customer service channels and business processes;
- conducting audits, quality reviews, risk assessments, and compliance checks;
- identifying operational inefficiencies and recurring service issues;
- classifying and routing enquiries to the appropriate service teams;
- training personnel and improving scripts, processes, and service delivery; and
- Test controlled pilot, beta, or automation solutions to improve operational effectiveness and customer experience.
Where permitted by law, we may record communications, including telephone calls, for quality assurance, training, evidentiary, fraud prevention and dispute-resolution purposes. Where required, an appropriate notice will be provided before or at the start of the recording. Access to recordings will be restricted to authorized persons, and such recordings will be retained in accordance with applicable retention requirements.
Service Improvement, Research and Business Intelligence
We may process Personal Data to assess service quality and customer satisfaction, improve products and services, conduct market research, perform analytics, and develop business insights. This may include surveys conducted by us or by appropriately engaged research service providers.
Unless a survey or research notice expressly states otherwise, we generally use survey and research results in aggregated or de-identified form or both to understand trends and service performance rather than to make decisions solely about a particular individual. Where identifiable Personal Data is used, we will apply a suitable legal basis and relevant safeguards.
Protection of Legal Rights and Dispute Resolution
Where necessary, we may process and retain Personal Data to establish, exercise or defend legal rights and claims; participate in litigation, investigations or other legal proceedings; manage legal risk; and respond to actual or reasonably anticipated disputes, complaints, claims or regulatory matters. We will retain relevant information only to the extent necessary for those purposes.
Legal, Regulatory and Compliance Requirements
We may process, retain, use, and disclose Personal Data and related records where necessary to comply with applicable legal, regulatory, supervisory, tax, accounting, audit, anti-money-laundering and other compliance obligations. We may retain and process such information for the periods and in the manner prescribed by Applicable Law, regulatory guidance, or lawful directions of competent authorities, including to demonstrate compliance.
We collect and process only Personal Data that is relevant and necessary for the applicable purposes, subject to legal and regulatory requirements.
Legal Basis for Processing Personal Data
We process Personal Data using an appropriate legal basis under the Act. Depending on the relevant Processing activity, the legal basis may include Consent or a recognized legitimate use.
Consent
Where we rely on Consent, we will request it at the relevant time and provide information about the relevant Processing purpose. If you do not provide Consent where it is necessary to provide a product or service, we may be unable to provide that product or service. You may withdraw Consent for the relevant purpose through the applicable mechanism, subject to legal and regulatory requirements, and the consequences communicated to you at the time of withdrawal.
Where you provide Personal Data relating to another Data Principal, you confirm that you are authorized to provide that information and, where required, to provide Consent on that person’s behalf.
Certain Legitimate Uses
Applicable data protection laws may permit us to process Personal Data for certain legitimate uses without obtaining separate Consent. For example, where you voluntarily provide Personal Data and request a specified service, Processing pursuant to fulfilling a legal/ regulatory obligation etc., we may process the information necessary to fulfil that particular purpose. We will rely on legitimate use only where the conditions and limitations prescribed by Applicable Law are satisfied.
Disclosure of Personal Data
To provide and administer insurance services, operate our business and comply with legal and regulatory requirements, we may disclose Personal Data to authorized recipients. We disclose only the Personal Data necessary for the relevant purpose and require confidentiality, privacy, and security safeguards where applicable.
Disclosure during Insurance Lifecycle Management
Authorized Service Providers and Other Recipients:
Depending on the relevant service or Processing purpose, recipient categories may include network hospitals, medical diagnostic laboratories, financial institutions, communication service providers, claims-Processing partners, risk-management partners, verification and KYC agencies, wellness partners, the IIB, professional advisers, technology providers and cloud service providers, as well as regulators and other competent authorities.
Medical Diagnostic Laboratories
For underwriting, policy issuance or claims assessment, we may refer a proposer, insured person, or claimant to an authorized medical diagnostic laboratory. The laboratory may collect biological samples, conduct tests, prepare diagnostic reports, and share relevant results with us to assess health status, eligibility, policy terms, or claim admissibility, and to prevent fraud or abuse.
A laboratory may be independently required by law or professional standards to retain medical records, test reports, samples, or related information. Where the laboratory acts independently, its Processing is governed by its own legal obligations and privacy practices. You may contact the relevant laboratory for further information about those practices.
Network Hospitals and Healthcare Providers
We may disclose Personal Data to, and receive Personal Data from, network hospitals and other healthcare providers for cashless authorization, treatment coordination, medical review, policy administration, claims Processing, settlement, fraud prevention, and related insurance services. Healthcare providers may also process Personal Data independently to provide medical care and comply with their legal and professional obligations.
Network Hospitals may be independently required by law or professional standards that are directly applicable to them to retain medical records, test reports, samples, or related information. Where the Network Hospital acts independently, its Processing is governed by its own legal obligations and privacy practices. You may contact the relevant Network Hospitals for further information about those practices.
KYC Verification Agencies
Before policy issuance and, where required, during the insurance relationship, we may engage authorized KYC verification agencies to verify identity, address, and other prescribed information. Available verification methods may vary depending on applicable regulatory requirements, the circumstances of the customer, and the availability of appropriate records. KYC Processing may include checks intended to prevent money laundering, terrorist financing, impersonation, and the use of insurance services by anonymous, fictitious, or otherwise unauthorized persons.
Risk Management Partners
For claims, grievances, high-value personal accident policies, pre-inception checks, or other risk-based reviews, we may engage authorized verification or investigation partners. We may disclose the information necessary for them to verify documents, conduct field or in-person checks where appropriate, collect relevant intelligence, and assess the authenticity of information or claims. Such activities will be conducted in accordance with Applicable Law and our instructions.
Professional Advisers
We may disclose relevant Personal Data to external professional advisers, including auditors, lawyers, consultants, and accountants, where necessary for them to provide professional services, protect our legal interests or assist us in complying with applicable obligations.
Wellness Partners
If you participate in a wellness program or use a wellness benefit, we may facilitate your sharing of Personal Data to authorized wellness partners to enroll you, provide the requested service, administer benefits, validate eligibility and measure program performance. The concerned wellness partner is solely responsible for such Processing activity, and we suggest that you refer to the concerned wellness partner’s privacy policies to understand their privacy posture.
Payment Service Providers:
To facilitate the payment and collection of insurance premiums, claims, refunds, and other related financial transactions, we engage payment providers, payment gateways, payment aggregators, banks, card networks, and other payment service providers involved in Processing or facilitating such transactions.
For payment facilitation services, such payment service providers collect your payment-related information directly through their own interfaces or platforms. We do not directly collect or process your payment credentials, including card-related information. We only receive payment confirmations and other information necessary to verify, administer, and reconcile the transaction.
Such payment service providers shall be independently responsible for the collection, use, disclosure, storage, and other Processing of your Personal Data including the payment related information. We encourage you to refer to the privacy policies of the relevant payment service providers to understand their privacy practices.
Communication Service Providers
We may engage communication service providers to communicate with you via SMS, telephone, email, WhatsApp, or other communication channels. These providers facilitate such services by assisting us in delivering communications, responding to enquiries, sending notifications, and supporting other communications where there is an appropriate legal basis for doing so.
Such providers may process Personal Data for the purpose of providing and facilitating communication services. However, where required under Applicable Laws, regulations, licensing conditions, or compliance obligations applicable to them, including requirements imposed by the Telecom Regulatory Authority of India (TRAI), they may retain communications and related Personal Data for their own legal and regulatory purposes. To the extent that such providers process Personal Data to comply with their own legal, regulatory, or compliance obligations, they shall be independently responsible for such Processing activities.
Other Insurers:
In accordance with the requirements and guidelines issued by IRDAI, if you choose to port your existing insurance policy from us to another insurer, we may transfer your insurance-related information through the IRDAI-approved portability platform and to the insurer selected by you for the purpose of facilitating the portability process. Following the completion of the portability process, the receiving insurer shall be independently responsible for any Processing activities undertaken for its own client relationships, regulatory obligations, and business purposes.
Insurance Information Bureau of India (IIB):
The IIB operates insurance industry data repositories and provides services that support cross-insurer risk intelligence, fraud detection and prevention, risk management, and the fulfilment of regulatory objectives. As required by IIB pursuant to the requirements under Applicable Laws, we shall be required to submit your Personal Data to IIB. Based on the Consent obtained from you; we will submit your Personal Data to the IIB.
Any such Personal Data submitted to IIB will be Processed by IIB for its own purposes, and IIB shall remain independently responsible for such Processing activities.
Information obtained through IIB services may be used to identify inconsistencies, early warning indicators, or suspicious patterns, and to support proportionate verification activities before underwriting, policy administration, claims Processing, or other insurance policies and claim related decisions. Such information will not be treated as conclusive and will be subject to appropriate review before any decision is made.
Cloud and Technology Service Providers
We may use authorized cloud, hosting, software, platform, and technology service providers to store, secure, process, transmit or otherwise support Personal Data within our digital environment. Such providers may host systems on their infrastructure or provide tools accessed through controlled authentication and access management mechanisms. We require relevant providers to process Personal Data only for authorized purposes solely based on our instructions and to implement appropriate contractual, technical, and organizational safeguards.
Business and Affinity Partners:
Affinity partners and other authorized distribution partners may offer our insurance products to their members, customers, employees, or other eligible groups based on an existing relationship with those individuals. Example: E-Seva Partners. We may exchange limited Personal Data with such partners to verify eligibility, provide quotations, facilitate enrolment, issue, or service policies, administer benefits and support claims, subject to an appropriate legal basis and applicable insurance-distribution requirements. In Particular,
Bancassurance Partners
Banks may distribute insurance products under authorized bancassurance by obtaining Corporate Agent licenses or other applicable licensing requirements. Where you obtain or enquire about an insurance product through a bank, the bank may share relevant Personal Data with us to facilitate quotations, applications, policy issuance, servicing, and claims support. We may share limited Personal Data with the bank where necessary for the services it provides or to comply with applicable requirements. The bank remains independently responsible for Processing undertaken for its own banking, customer relationship, or regulatory purposes.
Non-Banking Financial Companies
An NBFC may offer our insurance products alongside its financial product or service. In Such case the NBFC may collect and share Personal Data necessary to assess eligibility, provide quotations and assist us to, process premiums communicate with customers and comply with applicable requirements. The NBFC remains independently responsible for Processing undertaken for its own banking, customer relationship, or regulatory purposes.
Collection and Disclosure of Personal Data to Insurance Distribution Partners:
We may receive Personal Data from, disclose Personal Data to, and otherwise exchange Personal Data with regulated insurance intermediaries, distribution partners, and servicing partners to facilitate insurance enquiries, quotations, applications, underwriting, policy issuance, policy administration, servicing, claims, renewal handling, and other insurance related services. These entities are regulated by the Insurance Regulatory and Development Authority of India (IRDAI). Their roles, licenses, and obligations depend on the category of those services and the services they provide.
Insurance Agents
Insurance agents are individuals appointed by an insurer, such as us, to solicit or procure insurance business, including business relating to the continuance, renewal, or revival of insurance policies.
We may receive Personal Data from, disclose Personal Data to, and otherwise exchange Personal Data with authorized insurance agents in connection with insurance quotations, applications, underwriting, policy servicing, renewals, claims, and other insurance related services.
Where insurance agents process Personal Data solely in accordance with our instructions and for purposes related to the provision of our products and services, they will act as our Data Processors. However, where they process Personal Data in connection with their own client relationships, legal obligations, or regulatory requirements, they shall be independently responsible for such Processing activities.
Corporate Agents
Corporate agents are entities holding a valid registration or certificate issued under the IRDAI (Registration of Corporate Agents) Regulations, 2015, and any subsequent amendments thereto, to solicit and service insurance products within the permitted categories.
Where you are referred, onboarded, or serviced through a Corporate Agent, we may receive Personal Data from, disclose Personal Data to, and otherwise exchange Personal Data with corporate agents for the purposes of quotations, applications, underwriting, policy administration, servicing, renewals, claims handling, and related insurance activities.
Corporate agents remain independently responsible for Processing undertaken for their own customer relationships, legal obligations, and regulatory purposes.
Insurance Brokers
Insurance brokers are registered entities that solicit and arrange insurance for clients and may provide claims consultancy, risk management, or related services as defined under the IRDAI (Insurance Brokers) Regulations, 2018, and any subsequent amendments thereto.
Where you are referred, onboarded, or serviced through an Insurance Broker, we will receive Personal Data from, disclose Personal Data to, and otherwise exchange Personal Data with insurance brokers to facilitate quotations, underwriting, policy placement, policy servicing, renewals, claims handling, and other requested insurance-related services.
To the extent that insurance brokers process Personal Data for their own client relationships, advisory activities, legal obligations, or regulatory purposes, they shall remain independently responsible for such Processing activities.
Insurance Marketing Firms
Insurance Marketing Firms (IMFs) are entities registered under the IRDAI (Registration of Insurance Marketing Firms) Regulations, 2015, and any subsequent amendments thereto. They are authorized to solicit or procure insurance products and provide insurance-related services.
Where you are referred, onboarded, or serviced through an IMF, we may receive Personal Data from, disclose Personal Data to, and otherwise exchange Personal Data with IMFs in connection with insurance enquiries, quotations, applications, underwriting, policy servicing, renewals, claims handling, and other insurance-related activities.
IMFs may recommend insurance products, including comparisons of products offered by different insurers, based on their clients' needs. Accordingly, IMFs remain independently responsible for any Processing activities undertaken for their own client relationships, regulatory obligations, and business purposes.
Insurance Web Aggregator:
Insurance Web Aggregators are entities registered under the IRDAI (Insurance Web Aggregators) Regulations, 2017, and any subsequent amendments thereto. They act as intermediaries that facilitate the purchase and comparison of insurance products offered by multiple insurers through their websites or web portals.
Where you are referred, onboarded, or serviced through an Insurance Web Aggregator, we may receive Personal Data from, disclose Personal Data to, and otherwise exchange Personal Data with such Insurance Web Aggregator in connection with insurance enquiries, quotations, applications, underwriting, policy issuance, policy servicing, renewals, claims handling, and other insurance-related activities.
As Insurance Web Aggregators primarily facilitate the distribution and comparison of insurance products for their clients, they remain independently responsible for any Processing activities undertaken for their own client relationships, regulatory obligations, and business purposes.
Employees and Approved External Workforce Providers:
Personal Data may be Processed by authorized Star Health employees and, where required, personnel supplied by approved workforce providers who perform comparable operational roles (collectively, “authorized personnel”). Access is granted on a need-to-know and least privilege basis, taking account of each person’s responsibilities and the Processing activity assigned to them.
For example, authorized underwriting personnel may review information submitted with a proposal form and contact the proposer through approved channels to verify or update information necessary to assess the relevant insurance risk.
Personal Data is Processed primarily within managed and controlled systems and environments. Where approved third-party systems or providers are used, we require appropriate contractual, security, and privacy controls. Safeguards may include role-based access controls, data-loss-prevention measures, monitoring and logging, authorized-device and approved-channel requirements, confidentiality obligations, and periodic privacy and information-security training and assessments.
Change in Control and Business Transfers
If Star Health undergoes a reorganization, merger, acquisition, financing, restructuring, insolvency, liquidation, divestiture or transfer of all or part of its business or assets, Personal Data may be disclosed or transferred to advisers, counterparties, competent authorities or a successor entity, subject to Applicable Law, confidentiality requirements and appropriate safeguards. Where legally required and practical, we will provide notice through appropriate public announcement or direct communication.
Use of Artificial Intelligence
We may use artificial intelligence, machine learning, and other automated or autonomous technologies with varying levels of autonomy in providing our services and conducting our internal business operations. Such technologies may process information to provide assistance, generate recommendations, or support certain decisions.
Where you provide Personal Data while interacting with an AI enabled service deployed by us, such as a conversational chatbot, we may process the information you provide to deliver the assistance or service requested by you through that AI enabled service.
We may use anonymised, aggregated data or both that does not relate to an identified or identifiable Data Principal and, therefore, does not qualify as Personal Data under Applicable Laws, for the training, development, testing, and improvement of AI systems or models. We may also use Personal Data in a masked form, with the identifiers maintained separately, so that the Data Principal is not identifiable to the AI system or model.
Retention of Personal Data
Star Health retains Personal Data only for as long as reasonably necessary to fulfil the purposes for which it was collected and Processed and to comply with applicable legal, regulatory, tax, accounting, contractual, fraud-prevention, security, and legitimate business requirements.
Factors used to determine retention periods include:
- the duration and nature of our relationship with you;
- the period for which a policy, claim, service request, or other transaction remains active;
- applicable record-keeping requirements prescribed by IRDAI or other competent authorities;
- the need to establish, exercise or defend legal rights and claims;
- ongoing or anticipated complaints, disputes, litigation, investigations, or audits;
- fraud-prevention, security, and risk-management requirements; and
- The sensitivity, volume and nature of the Personal Data, and the potential impact of unauthorized use or disclosure.
We may retain relevant records after a policy, account or other relationship ends, or after a deletion request, where continued retention is required or permitted for a specified legal, regulatory, claims, dispute, investigation, investigation, audit, fraud-prevention, or other lawful purpose. Personal Data retained for such a purpose will not be used for an unrelated purpose unless we establish a separate legal basis.
At the end of the applicable retention period, Personal Data will be securely deleted, destroyed, purged, or anonymized, unless continued retention is required or permitted by Applicable Law. Anonymized, aggregated data or both that no longer identifies a Data Principal may be retained and used for analytics, statistical modelling, product development, risk assessment, and service improvement.
Transfer of Personal Data Outside India
Star Health may transfer Personal Data outside India only as permitted under Applicable Law. Any cross-border transfer will be subject to restrictions or requirements prescribed by the Central Government or another competent authority, including any restriction relating to the transfer of Personal Data to a specified country, territory, entity, or class of entities.
Where a permitted cross border transfer takes place, Star Health will implement appropriate contractual, technical, and organizational safeguards, having regard to the nature of the Personal Data, the purpose of the transfer and the requirements of Applicable Law.
Security of Personal Data and Privacy Governance
Security Safeguards
Star Health implements reasonable security safeguards to protect Personal Data in its possession or under its control, including Personal Data Processed on its behalf by Data Processors, in accordance with Applicable Law. Star Health maintains information security and privacy-governance frameworks aligned with recognized standards and practices. Star Health is certified to ISO/IEC 27001, reflecting its commitment to maintaining appropriate controls for the protection of information and Personal Data.
Star Health has adopted technical and organizational measures designed to prevent unauthorized access, disclosure, alteration, misuse, loss, or destruction of Personal Data and to reduce the risk and impact of a Personal Data Breach. Depending on the nature of the Processing, these measures may include:
- encryption or other appropriate protection mechanisms for Personal Data;
- role-based access controls that restrict access to authorized personnel and service providers on a need-to-know basis;
- logging, monitoring, and periodic review of access to support detection, investigation, and remediation of unauthorized activity;
- backup, recovery, and business-continuity measures designed to support the continued availability and restoration of Personal Data following a security incident; and
- periodic assessment and improvement of relevant security and privacy controls.
Privacy Governance
Star Health maintains an internal privacy-governance framework that provides oversight, accountability, and operational control over data protection practices. The framework includes a designated Data Protection Officer, a Privacy and Compliance Team responsible for monitoring compliance with data-protection and regulatory requirements, an Information Security Team responsible for implementing and maintaining security controls, and departmental privacy champions who support privacy-by-design and compliance within business functions.
Data Principal Rights and Responsibilities
Rights of Data Principals
Subject to the Act, the rules made under it and other Applicable Law, Data Principals may have the following rights:
- the right to obtain a summary of the Personal Data being Processed by Star Health and information relating to such Processing, in the manner prescribed under the Act;
- the right to request correction, completion or updating of inaccurate, misleading, or incomplete Personal Data;
- the right to request erasure of Personal Data where applicable, subject to any requirement to retain the data for a specified purpose or under Applicable Law;
- the right to raise grievance concerning the Processing of Personal Data or the exercise of rights under Applicable Law through Star Health’s grievance-redressal mechanism; and
- the right to nominate another individual to exercise the Data Principal’s rights in the event of death or incapacity, in the manner prescribed under Applicable Law.
Data Principals may exercise these rights or raise grievance through Star Health’s designated customer-care channels or privacy contact details. Requests and grievances will be reviewed and addressed in accordance with Applicable Law and relevant regulatory requirements. Where required under Applicable Law, a Data Principal must first exhaust Star Health’s internal grievance redressal mechanism (including the final resolution provided under grievances@starhealth.in) before approaching the Data Protection Board of India or another competent authority.
If you withdraw your Consent for the Core Insurance Purposes that is necessary for us to the provision of our insurance services, we will not be able to use your Personal Data for providing our insurance services, and therefore we will have to discontinue our services to you.
Please note that we will honor and serve the above-mentioned rights in accordance with the enforcement timelines and requirements specified under Applicable Laws.
Data Protection Officer:
In accordance with the requirements of the Act, Star Health has appointed a Data Protection Officer (“DPO”) to oversee its data protection obligations and compliance framework. The DPO represents Star Health before the Data Protection Board of India and other competent data protection authorities, as applicable.
The DPO is the designated point of contact for grievances, complaints, concerns, and queries relating to the Processing of Personal Data, including the Processing activities described in this Privacy Policy.
For any grievances or complaints, you may contact the Office of the DPO by email at privacy@starhealth.in.
For complete contact details and information about the available communication channels and grievance procedure, please refer to the “Contact Information” section of this Privacy Policy.
Responsibilities of Data Principals
When providing Personal Data or exercising rights under Applicable Law, Data Principals are expected to:
- comply with Applicable Law;
- not impersonate another person or suppress material information while providing Personal Data for a document, identifier or proof of identity or address;
- provide information that is authentic and capable of verification where required; and
- not register a false or frivolous grievance or complaint.
Personal Data Breach Management
If a Personal Data Breach occurs, Star Health will respond appropriately in accordance with Applicable Law. Depending on the circumstances, these measures may include:
- promptly assessing, containing and mitigating the breach to prevent or reduce further unauthorized access, disclosure, alteration, loss, or other harm;
- investigating the nature, scope and root cause of the incident and implementing appropriate corrective and preventive measures;
- maintaining records of the breach, its effects and the actions taken, in accordance with applicable legal and regulatory requirements;
- notifying the Data Protection Board of India, other competent authorities and affected Data Principals in the form, manner and within the timelines prescribed under Applicable Law;
- Based on the requirements of the Applicable Laws, providing affected Data Principals with information necessary to understand the breach and take appropriate protective measures;
- coordinating with Data Processors and other service providers/ partners involved in the Processing to support containment, investigation, remediation, and compliance with notification obligations; and
- issuing other breach related communications/updates in accordance with Applicable Law and regulatory guidance.
Contact Information:
For any concerns, queries, or grievances relating to the Processing of Personal Data, or to exercise rights available under the Act, Data Principals may contact Star Health through the channels set out below. You may exercise your rights as a data principal under the Act, including the right to correction, completion, updating of shared Personal Data, Consent management, and other related rights, by writing to privacy@starhealth.in. Your request will be handled in accordance with Star Health’s’ established internal processes and shall be resolved within the timelines and in accordance with the procedures prescribed under Applicable Laws. If our final resolution (including the final resolution provided under grievances@starhealth.in) does not adequately address your concern, you have the right to lodge a complaint with the Data Protection Board of India in the manner prescribed under Applicable Laws.
Links to Other Websites
Star Health’s services may contain links to third-party websites or services that are not operated or controlled by Star Health. Star Health is not responsible for the privacy practices or content of such third-party websites, and Data Principals are advised to review the respective privacy policies of those websites independently.
Changes to This Privacy Policy
Star Health reserves the right to update or modify this Privacy Policy from time to time. Any updates will be published on Star Health’s website, and Data Principals are encouraged to review this Privacy Policy periodically for the latest information.