Privacy Policy

Version 1.0  |  Effective Date: 1 July 2026


1. Who We Are and Why This Policy Exists

Hospital Infection Society – India (HISI) is India’s premier professional society dedicated to the prevention and control of healthcare-associated infections. Founded over three decades ago and recognised as a resource partner by the World Health Organization and the Government of India, HISI brings together physicians, nurses, infection control practitioners, microbiologists, and allied healthcare professionals from across the country. The Society’s peer-reviewed journal (JPSIC), published by Wolters Kluwer, is indexed in Scopus, EMBASE, and DOAJ.

This Privacy Policy explains how HISI collects, uses, stores, and protects the personal data of individuals who interact with our website (hisindia.org), apply for or hold HISI membership, register for our events and educational programmes, or otherwise engage with us digitally.

As a Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules), HISI is required by law to be transparent about how it handles your personal data. This document is that transparency notice.

The full compliance deadline under the DPDP Rules is 13 May 2027. HISI has chosen to implement all substantive obligations — consent, breach reporting, data rights, and security safeguards — from the date this website goes live, well ahead of the statutory deadline.

2. Scope of This Policy

This policy applies to all digital personal data processed by HISI, including data collected through:

  • The HISI website at hisindia.org and any subdomains
  • The member registration, login, and dashboard portal
  • Event and conference registration forms (HISICON, CMEs, webinars)
  • The contact and enquiry forms on the website
  • Email correspondence and newsletter subscription
  • Payment processing for membership fees and event registrations

It applies to all categories of individuals whose data we handle: current and prospective members, event attendees, journal contributors, chapter coordinators, and website visitors. It does not apply to data processed solely in physical, offline formats that have not been digitised.

3. Personal Data We Collect

HISI collects only the data necessary for the specific purpose for which it is collected. The categories of personal data we process are described below.

3.1 Membership Registration Data

When you apply for or renew HISI membership, we collect:

  • Full name, professional designation (e.g., Dr., Prof., RN), and specialisation
  • Medical Council or Nursing Council registration number (where applicable for membership tier)
  • Institutional affiliation, department, and city
  • Contact details: email address, mobile number, and mailing address
  • Membership tier applied for (currently Life Member; additional membership types such as Regular, Associate, Fellow, Institutional, Student etc. will apply as and when decided by the Executive Committee of HISI and published on hisindia.org)
  • Supporting documents uploaded for verification, if any
  • Date of membership registration and renewal history, if any

3.2 Payment Data

Membership fees and event registration payments are processed through Razorpay, a PCI-DSS compliant payment gateway. HISI does not store, view, or have access to card numbers, UPI PINs, or net banking credentials. The only payment data retained by HISI is the transaction reference number, amount, date, and payment status, which are necessary for membership management and financial record-keeping.

3.3 Event and Programme Registration Data

When you register for HISICON, a CME, webinar, or chapter event, we collect your name, professional designation, institution, contact email, mobile number, and dietary or accessibility preferences where relevant.

3.4 Member Dashboard and Activity Data

Once you are a logged-in member, we retain records of your membership status, dashboard activity, downloaded resources, course or CPD module completions (as and when they are made available on hisindia.org), and certificate awards. This data is necessary to provide member services and is accessible to you at all times through your member dashboard.

3.5 Communication and Correspondence Data

When you contact HISI through the website contact form, by email, or via the chapter enquiry route, we retain the content of that communication and your contact details to respond to and resolve your query.

3.6 Website Usage Data (Cookies and Analytics)

We use Google Analytics 4 to understand how visitors use the HISI website — which pages are visited, how long visitors spend on the site, and what links they follow. This helps us improve the website and its content. Google Analytics data is collected only after you provide consent through our cookie consent banner (CookieYes). No analytics tracking occurs before consent is given.

The cookies used on this website fall into three categories:

  • Strictly necessary cookies: Required for the website to function (login sessions, shopping cart, security). These are always active and do not require consent.
  • Analytics cookies: Google Analytics 4, activated only after consent.
  • Functional cookies: Preferences settings, activated only after consent.

You may withdraw cookie consent at any time by clicking the “Manage Cookies” link in the website footer.

4. Legal Basis for Processing

Under the DPDP Act, 2023, personal data may be processed on the basis of consent or on certain legitimate uses defined in the Act. HISI processes your data on the following bases:

  • Consent: For newsletter subscriptions, analytics cookies, and functional cookies. You provide this consent through the cookie banner or newsletter sign-up form. You may withdraw consent at any time (see Section 7).
  • Contractual necessity: For processing membership registrations, collecting membership fees, issuing digital membership cards, and providing member services. This processing is necessary to deliver the membership you have applied for and paid for.
  • Legitimate organisational purposes: For maintaining accurate membership records, managing HISI events, issuing CPD certificates, maintaining the integrity of the member database, and fulfilling HISI’s governance and Society administration obligations.
  • Legal obligation: Where applicable, to retain financial records as required under Indian tax and applicable law.

HISI does not sell your personal data to third parties. HISI does not use your data for automated decision-making that has significant effects on you, and does not use your data for purposes unrelated to the management of the Society and delivery of member services.

5. How We Use Your Personal Data

HISI uses your personal data for the following specific purposes:

  • To process your membership application, issue your digital membership card, and manage your membership account
  • To process payments and generate invoices for membership fees and event registrations
  • To communicate with you about your membership status, renewal reminders, and account updates
  • To send you HISI publications, announcements, event invitations, and the Society newsletter (only if you have subscribed or consented to receive communications)
  • To manage event registrations, issue entry confirmations, and generate delegate lists for HISICON and other HISI programmes
  • To award and record CPD credits, issue completion certificates, and maintain your continuing professional development record (as and when they are made available on hisindia.org)
  • To operate and improve the HISI website, using anonymised, aggregated analytics
  • To respond to your queries and correspondence
  • To maintain the HISI member directory, which is accessible only to logged-in members and displays only the information you have chosen to make visible
  • To fulfil HISI’s legal, regulatory, and governance obligations as a registered professional society

6. Who We Share Your Data With

HISI does not sell, rent, or trade your personal data. We share data with third-party service providers only to the extent necessary to deliver HISI’s services, under contractual obligations that require them to protect your data and use it only for the specific purpose for which it has been shared.

6.1 Third-Party Service Providers

The service providers who may process your data on our behalf include:

  • Hostinger India (website hosting): All HISI data is hosted on Hostinger’s Mumbai data centre. Your data does not leave Indian territory. This satisfies the data localisation expectation under the DPDP Act and DPDP Rules.
  • Razorpay (payment processing): Processes membership fee and event registration payments. Razorpay is PCI-DSS Level 1 certified. Card and UPI transaction data is processed entirely within Razorpay’s secure infrastructure and is never stored on HISI’s server.
  • Brevo (email communications and newsletters): Used to send HISI newsletters and membership communications. Only members and subscribers who have opted in receive these communications.
  • MSG91 (SMS and WhatsApp notifications): Used for membership OTP verification and critical account notifications.
  • Google (Analytics): Anonymised website usage data is processed through Google Analytics 4, only after visitor consent.

6.2 Data Shared Within HISI

HISI’s Executive Committee, the Hon. Secretary, and designated chapter coordinators have access to member data on a need-to-know basis for Society administration purposes. All HISI personnel and volunteers handling member data are required to respect the confidentiality of that data.

6.3 Disclosure Required by Law

HISI may disclose your personal data when required to do so by a court order, statutory authority, or any other legitimate legal obligation under Indian law.

6.4 Cross-Border Data Transfer

HISI’s primary data storage is on Hostinger’s Mumbai server and remains within India. Certain third-party tools (Google Analytics, Brevo) may involve servers outside India as part of their global infrastructure. Where such transfers occur, HISI relies on the service providers’ standard contractual clauses and certifications to ensure appropriate protection of your data.

7. Your Rights as a Data Principal

The Digital Personal Data Protection Act, 2023 gives you, as the individual whose data is being processed (referred to in the Act as the “Data Principal”), the following enforceable rights:

7.1 Right to Access Information

You have the right to know what personal data HISI holds about you, the purposes for which it is being processed, and to whom it has been shared or disclosed. You may exercise this right by writing to the Grievance Officer at the contact address in Section 10.

7.2 Right to Correction and Erasure

You have the right to correct inaccurate or outdated personal data and to erase personal data that is no longer necessary for the purpose for which it was collected. Active members may update their name, contact details, and institutional affiliation directly through the member dashboard. For other corrections or erasure requests, please contact the Grievance Officer.

Please note that some data — particularly financial and membership records — must be retained for a minimum period under Indian tax and professional society law, and cannot be erased during that retention period even on request.

7.3 Right to Grievance Redressal

If you believe that your personal data has been processed in a manner that is inconsistent with this policy or with the DPDP Act, you have the right to file a grievance with HISI’s Grievance Officer (see Section 10). HISI will acknowledge your grievance within 72 hours and resolve it within 30 days. If you are unsatisfied with HISI’s resolution, you may approach the Data Protection Board of India, once the Board is fully constituted under the Act.

7.4 Right to Withdraw Consent

Where processing is based on your consent (newsletter subscriptions, analytics cookies), you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. To unsubscribe from newsletters, use the unsubscribe link in any HISI email. To withdraw cookie consent, use the “Manage Cookies” link in the website footer. All withdrawal requests will be acted upon within 30 days of receipt at HISI Secretariat.

7.5 Right to Nominate

Under the DPDP Act, you may nominate a trusted individual to exercise your data rights on your behalf should you be unable to do so at any time. However, the nominee’s data rights do not include participation in voting and elections to the HISI Executive Board/Council, forums, committees, and sub-committees. To register a nominee, please contact the Grievance Officer.

8. How Long We Retain Your Data

HISI retains personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. The following retention guidelines apply:

  • Active membership records: Retained for the duration of active membership and for 7 years after membership expires, to meet professional society governance and Indian tax law requirements.
  • Payment and invoice records: Retained for 8 years from the transaction date, as required under the Income Tax Act, 2025 (and any successor legislation) and the applicable GST Rules.
  • Event registration records: Retained for 3 years after the event date, for CPD accreditation and certificate verification purposes.
  • Contact form and correspondence data: Retained for 2 years after the query is resolved.
  • Website analytics data: Retained in Google Analytics for 14 months (the minimum configurable retention period), after which it is automatically deleted.
  • Data of individuals who enquired but did not register: Retained for 1 year from the date of enquiry.

When data is no longer required and has reached the end of its retention period, HISI securely deletes or anonymises it. We also instruct our data processors to delete data within a reasonable time after it is no longer required.

9. Security of Your Personal Data

HISI implements reasonable security safeguards to protect member data against unauthorised access, alteration, disclosure, or destruction. The technical measures built into the platform include:

  • Data hosting on Hostinger’s Mumbai server infrastructure, with physical and network-layer security
  • Cloudflare CDN and Web Application Firewall (WAF), which shields the website from DDoS attacks, bots, and common web exploits before requests reach the server
  • Wordfence security plugin, which monitors for malware, blocks brute-force login attacks, and scans WordPress files for integrity
  • SSL/TLS encryption for all data in transit between visitors and the server
  • Encrypted HTTPS enforced on all pages; HTTP access automatically redirected
  • Daily automated backups to cloud storage, enabling full site restoration within hours if required
  • Razorpay’s PCI-DSS Level 1 certified infrastructure for all payment data
  • Access to member data within HISI restricted to authorised personnel on a need-to-know basis

In the event of a personal data breach that is likely to result in harm to you, HISI will notify the Data Protection Board of India within 72 hours of becoming aware of the breach, as required under the DPDP Rules, 2025. Where the breach is likely to cause significant harm to you personally, HISI will also notify you directly and promptly.

9A. Limitation of Liability

Notwithstanding the security safeguards described in Section 9, HISI, its Executive Committee, Office Bearers, members, employees, vendors, functionaries, and representatives shall not be liable for any loss, harm, or damage of any nature — whether personal, financial, reputational, or otherwise — arising from an inadvertent breach or unauthorised disclosure of personal data that occurs despite reasonable security measures being in place and beyond HISI’s reasonable control.

This limitation applies to all categories of harm including but not limited to personal, property, commercial, financial, reputational, or material harm. HISI’s liability in all cases shall be limited to taking prompt remedial action, notifying affected individuals as required by law, and cooperating fully with regulatory authorities.

10. Contact Us and Grievance Redressal

HISI has designated the following contact point for all data privacy queries, access requests, correction and erasure requests, and grievances:

Grievance Officer (Data Privacy)
Hospital Infection Society – India
Apollo Hospitals, Sarita Vihar, New Delhi
Email: privacy@hisindia.org
Website: hisindia.org/contact

HISI will acknowledge your request or grievance within 72 hours and will endeavour to resolve it within 30 days. Requests received through the member dashboard (for data access and correction) will typically be addressed within 15 working days.

10.1 Role and Responsibilities of the Grievance Officer

The Grievance Officer is a designated role within HISI, assigned to the Hon. Secretary or a nominated member of the Executive Committee. The responsibilities of the Grievance Officer include:

  • Receiving, acknowledging, and logging all privacy-related queries, data access requests, correction and erasure requests, and formal grievances from members and website visitors
  • Coordinating with HISI’s website administrator and Executive Committee to fulfil data access, correction, and erasure requests within the timelines specified in this policy
  • Acting as the primary point of contact with the Data Protection Board of India in the event of a data breach or regulatory inquiry
  • Coordinating breach notification to affected members and to the Data Protection Board of India within the timelines required under the DPDP Rules, 2025
  • Maintaining a confidential register of grievances received, actions taken, and resolutions achieved, for Society governance and regulatory compliance purposes
  • Periodically reviewing this Privacy Policy and recommending updates to the Executive Committee to reflect changes in law, technology, or HISI’s data practices

If you are not satisfied with HISI’s response, or if your grievance remains unresolved, you may approach the Data Protection Board of India at the address and through the online mechanism published by MeitY at the time the Board is constituted.

11. Children’s Data

The HISI website and membership programmes are directed at healthcare professionals and are not intended for children under the age of 18. HISI does not knowingly collect personal data from anyone under 18. Under the DPDP Act, any processing of data of a person under 18 requires verifiable parental or guardian consent. If we become aware that we have inadvertently collected data from a minor without the required consent, we will delete it promptly.

12. Changes to This Policy

HISI may update this Privacy Policy periodically to reflect changes in our practices, the services we offer, or the applicable law. When we make material changes, we will post the revised policy on this page with a new effective date and, where appropriate, notify members directly by email.

The date this policy was last updated is shown at the top of this document. Continued use of the HISI website or membership portal after any changes constitutes acceptance of the revised policy.

13. Applicable Law and Jurisdiction

This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the Income Tax Act, 2025, and to the extent still applicable, the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. Any disputes arising from this policy shall be subject to the jurisdiction of the courts at New Delhi.


Hospital Infection Society – India  |  Apollo Hospitals, Sarita Vihar, New Delhi
hisindia.org  |  privacy@hisindia.org  |  Version 1.0  |  Effective 1 July 2026