Legal
Privacy Policy
Last updated: 4 July 2026
Who we are
Hesto Health Care (“Hesto”, “we”) operates a mediated healthcare staffing platform that connects hospitals, clinics and families with verified nurses, general duty assistants and home workers. This policy explains what personal data we collect and how we handle it, in line with India’s Digital Personal Data Protection Act, 2023 (DPDP Act).
What we collect
Staff members: name, photo, contact details, professional qualifications, work history, identity and certificate documents you upload for verification, blood group, expected salary, and your responses to opportunities.
Companies & families: organisation/contact name, email, callback phone number, and the details of your hiring requirements (including care needs you describe).
Everyone: account credentials (passwords are stored only as salted hashes) and messages you exchange with the Hesto team on the platform.
Companies & families: organisation/contact name, email, callback phone number, and the details of your hiring requirements (including care needs you describe).
Everyone: account credentials (passwords are stored only as salted hashes) and messages you exchange with the Hesto team on the platform.
How we use it
Solely to operate the staffing service: verifying staff profiles, matching requirements to candidates, mediating all communication between the two sides, coordinating placements, and sending transactional SMS (opportunity alerts, verification codes). We do not sell personal data or use it for third-party advertising.
The mediation principle
By design, staff and hirers never see each other’s contact information on the platform. Staff identities shown publicly are partially masked; contact details, salaries and documents are visible only to you and to Hesto’s team. Full details are shared between the parties only by Hesto, at the point of a confirmed placement.
Where it lives
Data is stored with our infrastructure providers: MongoDB Atlas (database), Cloudinary (photos and verification documents) and Amazon Web Services (hosting and encrypted backups). Transactional SMS is delivered via a DLT-registered provider as required by TRAI regulations.
Your rights
You may access and correct your data at any time from your dashboard. You may request a copy of your data or the deletion of your account and associated personal data by writing to [email protected] — we act on verified requests within 30 days, subject to records we must retain by law.
Retention & security
We keep personal data only while your account is active or as needed for legal and accounting records. Access is restricted to Hesto’s operations team; traffic is encrypted in transit (TLS via Cloudflare) and credentials are hashed. Report any concern to the email above.
Changes
We will post updates to this policy here and note the date above. Continued use of the platform after an update constitutes acceptance.