Privacy Policy
Xtramile Consultancy Services (Pvt) Ltd of Town Mosque Road, Akkaraipattu 02, 32400, Sri Lanka ("we", "us", "our") values your privacy and is committed to protecting personal and health information. This Privacy Policy explains how we collect, use, store, share and protect information when you use Niro (the "Service"), including our mobile application and web portals.
This Policy is prepared in accordance with the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025 (together, the "PDPA"). We act as the "controller" of personal data processed through the Service.
By creating an account and giving your consent in the app, you agree to the practices described below. Health information is a "special category of personal data" under the PDPA and we ask for your explicit consent before processing it.
About Niro
Niro is a patient-held personal health record. Patients create and control their own record and choose who sees it. The Service includes:
- A patient app (iOS, Android and web) for recording current medications, medical conditions, doctor visits and investigation results, and for booking appointments, available in Sinhala, Tamil and English.
- A doctor portal and a dentist portal, where a practitioner you share your code with — or whose appointment you have booked — can view your record and record a consultation (an "episode"), including diagnoses, notes, investigation orders and prescriptions.
- An allied health portal for other registered health professionals (for example nursing officers, physiotherapists and dieticians), who can view a record you share and add visit notes, but cannot prescribe.
- A pharmacy portal for dispensing prescriptions you present.
- Laboratory and radiology portals for receiving investigation requests you present and returning results.
- An institution portal for hospitals, clinics and channelling centres, which lets an owner run departments, invite staff, and operate a channelling desk that lists consultants, sessions and appointment queues, records pre-consultation observations, and sees what each consultation asked the patient to do next.
- A referral system, which lets a practitioner refer you to a specialist or an allied health professional, and lets that person reply.
- An internal administration console, used by our named administrator to review professional verification submissions and to monitor service usage. It does not provide access to patient health records.
Except as described under "Appointment booking" below, nothing in your record is visible to a doctor, dentist, allied health professional, pharmacy, laboratory or radiology centre unless you present your Niro code or QR code to them.
Information We Collect
Patients
- Account and identity: full name (as on your NIC), an optional calling name, mobile phone number, date of birth, gender, blood group, known allergies, and your Niro patient code.
- Health information (special category): medical conditions, medications, doctor visits and consultation episodes, prescriptions, laboratory results and imaging reports that you enter, or that a healthcare professional enters when you share your record.
- Documents and photographs: images you capture or upload of laboratory reports, prescriptions, clinic notes, scan reports and similar records. These are stored with your record and are retained even where their contents have also been transcribed into structured entries.
- Location: the city or town you select for your address, and the geographic coordinates associated with that town, used to show appointments near you. If you use the "near me" option when searching for appointments, your device's approximate location is used at that moment to sort results; we do not store a location history and we do not track your location in the background.
- Appointment bookings: the consultant, institution, date, session, queue number and estimated time of appointments you book, together with the contact details described under "Appointment booking".
- Pre-consultation observations: where a clinic takes readings before you see the practitioner — blood pressure, pulse, oxygen saturation, temperature, blood sugar, weight and height — these are recorded against that appointment. They belong to that visit; they become part of your record only if the practitioner includes them in their consultation notes.
- Referrals: where a practitioner refers you on, the referral records who it is addressed to, what is being asked, and the summary of your history the referring practitioner writes for that purpose, together with any reply.
- Authentication: your phone number is used for one-time SMS verification codes. If you enable biometric unlock, your fingerprint or face data is processed only on your device by its operating system — it is never transmitted to, collected or stored by us. Your backup PIN is stored in protected form.
- Subscription and payment: your plan (free or Niro Premium) and its dates. If you subscribe to Premium by bank transfer, the photograph or PDF of the bank receipt you upload — which shows your name, the paying bank and account, the amount, the date and the reference — is collected to confirm your payment. Card payments are handled by PayHere; we receive a record that a payment succeeded, and never your card number.
Healthcare professionals and facilities
- Doctors and dentists: name, Sri Lanka Medical Council (SLMC) registration number, whether the registration is on the medical or dental register, and qualifications, which are attached to the episodes and prescriptions they create; and, where they offer telehealth, the consultation languages and the short introduction they choose to show to patients.
- Allied health professionals: name, profession, council registration number where held, and qualifications, which are attached to the visit notes they create.
- Verification documents (special category where they contain health-profession or identity data): where a professional or an institution asks to be verified, we collect images or PDF documents of registration certificates, professional identity cards, National Identity Cards, and institutional registrations such as PHSRC or NMRA licences and business registrations. These are reviewed by our named administrator and are not shown to patients.
- Professional directory: for doctors and dentists we maintain a directory that records the practitioner's name against their SLMC registration number, and whether Niro has verified that registration. SLMC registration is public information in Sri Lanka. This directory is readable within the Service so that a hospital clerk adding a consultant, and a patient choosing an appointment, can see whose registration number they are dealing with.
- Institutions: business name, city or town, telephone number, the map location the owner pins, the departments they operate, and the staff memberships and invitations they create.
- Institution billing: for an institution on the channelling plan, the plan's dates and the bank receipt its administrator uploads to pay — showing the payer's name, the paying bank and account, the amount, the date and the reference. The receipt is read by the same Google Cloud Vertex AI (Gemini) service that reads Premium receipts, only to check the amount, date and reference, and is reviewed by a person at Niro where it cannot be matched automatically. It is kept as the record of that payment with the institution's billing history, which only the institution's owner and administrators can see; patients and other staff never see it.
Home carers
Name, telephone number, gender, the languages they speak, identity document, the qualification claimed and its certificate or registration number, police or character certificate and its expiry date, the location travelled from and the distance travelled, the services offered (their hourly prices are set by Niro and are the same for every companion), availability and on-duty state, the institutions they work for, ratings received, a reliability record (on-time rate, lateness, unproven check-ins, no-shows and strikes) built from their visit records, and, for payouts, bank account details with a passbook page or statement header in their name.
Technical information
- Device and usage information (device type, app version, interaction logs) used to operate, secure and improve the Service. We do not include health information in analytics or crash reports.
- Service usage records for document reading, which record who made the request, the document type, the number of pages and the processing cost. They do not contain the contents of the document.
Purposes and Legal Bases
We process personal data for specified, explicit and legitimate purposes only (PDPA section 6):
- To provide the Service — creating your record, displaying it to those you authorise, booking appointments, generating prescriptions and investigation requests. Legal basis: your consent (Schedule I(a) and Schedule II(a)) and performance of our contract with you (Schedule I(b)).
- Where a licensed healthcare professional records information for your care, processing is additionally supported by Schedule II(g) of the PDPA (medical diagnosis, provision of care or treatment, and management of health-care services by a licensed health professional).
- To arrange appointments you request, including passing your name and telephone number to the institution and practitioner you book, recording observations taken before the consultation, and letting the institution act on what the consultation asked you to do next. Legal basis: performance of our contract with you (Schedule I(b)) and your consent.
- To refer you to another practitioner where your treating practitioner considers it necessary, and to carry their reply back. Legal basis: Schedule II(g) (provision of care by a licensed health professional) and your consent.
- To read documents you choose to photograph, so that their details can be offered to you for confirmation. Legal basis: your consent, given each time you choose to use the feature.
- To verify the registration of healthcare professionals and institutions, so that patients can tell whose care they are in. Legal basis: our legitimate interests, and those of patients, in preventing impersonation in a clinical setting (Schedule I(f)), and the consent of the professional who submits the documents.
- To verify your identity and secure your account (SMS one-time codes, sign-in protection). Legal basis: contract performance and our legitimate interests in preventing fraud and ensuring network and information security (Schedule I(f) and (h)).
- To respond to a medical emergency threatening life, health or safety (Schedule I(d) / II(c)).
- To comply with legal obligations under Sri Lankan law (Schedule I(c)).
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not use your health data for advertising.
Patient-Controlled Sharing
Your record is shared only when you act:
- Showing your QR code or patient code to a doctor, dentist or allied health professional lets that practitioner view your conditions, medications and investigation results, and add to your record.
- Prescriptions you present can be viewed and dispensed by a pharmacy; the dispensing pharmacy's name is recorded.
- Investigation requests you present can be viewed and marked as received by a laboratory or radiology centre, which can return the result into your record.
- A healthcare professional cannot open their own record through a professional portal. Where a practitioner is also a patient, they use their patient account for their own care.
We never sell personal data, and we do not share it with advertisers.
What each kind of access opens
Sharing your record is not all-or-nothing. A doctor or dentist treating you sees the whole record; everyone else receives access shaped to the job they are doing, and nothing wider:
- A doctor or dentist you consult — whether you booked them or showed them your QR code — sees your whole record: your allergies and current medicines, your conditions, your past consultations and results, and other clinicians' notes. A doctor treating you is not shown a partial record, because a decision made on half a history is the risk a shared record exists to remove.
- A pharmacy sees what you take and what you react to, and the prescription it is dispensing. Nothing else.
- A laboratory or radiology centre sees the test it has been asked to do, and returns the result. It does not see your history of results.
- A home carer coming to your house sees your allergies, your current medicines, your current conditions, and the prescription behind anything a nurse has been asked to give. They see no consultation notes and no history, and they cannot write anything into your record. An institution's home care desk sees the booking — who, where, when, what was asked for — so that it can assign and dispatch, but not your record.
- A family member you have named as a delegate, and a clinician you have kept on your standing patient list, see the whole record for as long as that relationship lasts.
Previously, allowing access gave the whole record to whoever asked, which meant a pharmacist dispensing an inhaler received every consultation note you had ever had. That is no longer how it works, except where you deliberately grant it: showing a one-time consent code from the app opens your full record to the clinician who scans it, for the working day only. Like every other kind of access it lapses on its own, is written to your access log, and can be withdrawn from Record access.
Emergency access
There is one exception to sharing happening only when you act. A registered clinician can open your record in a medical emergency — when you are unable to consent, such as being brought in unconscious — without your action. This is never silent: the clinician must record a reason, you are notified the moment it happens, the access lasts two hours and then lapses, and it is written to your access log under their name like any other grant. Legal basis: protecting your vital interests where you are physically or legally incapable of giving consent (Schedule I(d) / II(c)).
Access ends by itself
Access is time-limited. A consultation's access lapses a few days afterwards, a home care visit's two days after the visit, and a returned test result's after a few weeks. Only your own access, and a delegate you have named, do not expire.
Withdrawing access
You can see everyone who currently holds access to your record, what kind of access it is, and when it lapses — and you can withdraw any of it at any time, from Record access in the app. Consent that cannot be taken back is not consent.
Your access log
We keep a log of every time access to your record was granted, to whom, and why, and you can read it. It records authorisations rather than every page view: once someone has been let in, they read your record directly from their device, so we do not see each screen they open — and we would rather tell you exactly what we know than imply a surveillance we do not have.
Appointment booking
When you book an appointment, you share your name and telephone number with the institution and with the practitioner you have booked, so that they can manage the queue and contact you. Your health record is not part of a booking.
Booking an appointment is also your consent for that practitioner to open your health record for that consultation, in the same way as if you had shown them your code at the desk. This lets them prepare before you arrive. If you do not wish to share your record, you may cancel the booking, or ask the practitioner not to open it.
The institution's channelling staff see your visit, not your history. Specifically, staff of the institution's channelling department can see your name, telephone number and queue position; any observations the clinic took before your consultation; and, after the consultation, what it asked you to do next — the plan, the investigations ordered, the medicines prescribed and any referral raised — so that the desk can direct you to their pharmacy, their laboratory or your next appointment.
They cannot see your medical history, your past consultations, or the diagnosis made at this one. This access is limited to staff the institution has placed in that department, and it ends a few days after the appointment.
Managing a Record for Someone Else
A person can be named as a delegate on someone's record — most often an adult child managing an elderly parent's care, sometimes from abroad. A delegate sees the record as the patient does and can book on their behalf. Everything they do is recorded under their own name as well as the patient's, because "who is this for" and "who did this" are different questions.
A delegate is appointed only by the patient allowing it, and the patient can withdraw it at any time from Record access.
Where a person cannot hold an account themselves — an elderly parent without a phone — an identity-verified relative can create a record for them. Such a record is marked as managed, and who created it is stored, so that any clinician relying on it can see that the patient has never verified anything themselves. It stops being managed when the patient signs in on their own number and claims it. We cap how many records one person may create this way.
Proving Who You Are
Some things — managing another person's record, creating one for a relative — act on somebody other than yourself, so they require identity verification. An email address proves someone reads an inbox and a telephone number proves someone holds a SIM; neither says who a person is.
To verify, you send us a photograph of an identity document (a National Identity Card, or a passport for people signing up from overseas). A person reviews it. We store the images and the outcome; the trust level that results is stored where you cannot edit it, because a trust level its own subject can write means nothing.
People outside Sri Lanka can sign up with an email address instead of a Sri Lankan mobile number, and sign in afterwards with their device's fingerprint or face (a passkey). We hold the email address, the passkey's public key — never a fingerprint or face image, which never leave your device — and the verification codes we sent, which expire.
Home Care
Niro introduces families to home care from independent companions and from institutions with a Home care department. It is not a care agency and does not employ carers. This means personal data flows in both directions, and both directions are worth stating.
From a carer, we collect and hold: their name and contact details, their gender (which a family may filter on, since personal care is often chosen on it), the qualification they claim and the certificate or registration number behind it, a police or character certificate, where they travel from and how far, the services they offer and their hourly prices. Verification documents are reviewed by a person, who also records when the police certificate and any registration expire; we send reminders before expiry and pause the profile when a document has expired. The level they are approved at is written by that reviewer and not by the carer.
From an institution with a Home care department, we hold the services and prices it offers, the area it covers, its desk telephone number, its insurance declaration — insurer, policy number and expiry — which is shown to families once we have verified it, as "Covered by [institution]", and the list of Niro-verified staff it has invited and who have accepted. Whether a staff member is on duty, and whether they work exclusively for that institution, is set at the institution's desk and seen by the institutions they work for.
From a family booking a visit, the carer is shown: the patient's name and telephone number, the address of the visit, what has been asked for, and whatever the family chose to write in the notes — which we ask them to make honest, because a carer arriving without knowing that a patient cannot stand is how both of them get hurt. An institution's desk sees the same booking details in order to accept, assign and dispatch; the patient's record itself is opened only to the assigned carer, and only for that visit.
A visit record holds when the carer said they were on their way and the arrival time they gave; how they checked in — by scanning the patient's QR code, by entering the six-digit arrival code shown only to the family, or without proof — and the location and distance from the address recorded at check-in; when they checked in and out; the visit note; how late the arrival was against the booked start and against that estimate; extra hours requested and approved; incident reports (a fall, an injury, damage, care refused) with any photographs; any emergency raised from the visit, which also notifies the family, the institution's desk and Niro; what was asked for, what it cost, and whether it was paid. Where a problem is reported, the report, our review notes and the outcome are kept with it. This is kept as a record of what happened: it is what a complaint, an insurance claim or a dispute is settled from.
From these records we keep a reliability record for each carer — on-time rate, lateness, unproven check-ins, no-shows and strikes — and for each institution, and use them to decide who continues to be offered to families. The family and the carer see each other's part of a visit only as the app shows it; an institution sees the reliability record of its own staff; review notes are seen by Niro's administrators. All of it is retained with the visit record.
To pay carers and institutions we hold a payout account: bank, branch, account number and the name on the account, with a photograph of a passbook page, a statement header or a bank letter showing that name. A person at Niro checks the name against the verified identity or the institution's registration before the first payout and after any change; the document is seen only by that reviewer. The account, each visit's gross, commission and net, and every payout with its bank reference are kept with the payout history for as long as the account exists and for the period the tax and accounting laws require afterwards.
After a visit both sides may rate the other. A family's rating and review appear publicly on the carer's profile, showing the family's first name only. Reviews that name a medical condition or otherwise identify a patient are removed. A carer's rating of a household is not published.
The obligations on each side are set out in the Home Care Provider Agreement, the Institution Home Care Provider Terms and the Home Care Booking Terms.
Payments
Payments are handled by PayHere, a licensed Sri Lankan payment gateway. Your card details are never sent to Niro and never stored by us — they are entered inside PayHere's own checkout.
We hold a record of each transaction: what it was for, the amount, its status, and the reference PayHere gives us. We keep this because a payment that did not result in the consultation or visit it was for is a refund we owe you, and that is only provable from a ledger.
Data Processing, Cloud Providers and AI
- Hosting and database: Google Cloud / Firebase (Google Identity Platform for authentication, Cloud Firestore for data, and Cloud Storage for documents and photographs), hosted in Mumbai, India (asia-south1).
- Document reading: if you choose to photograph a laboratory report, prescription or clinic note for Niro to read, the image is processed by Google Cloud Vertex AI (Gemini) in the Mumbai (asia-south1) region, under the same Google Cloud terms as the rest of our infrastructure, and is not used to train AI models. The feature is optional, and during early access it is available at no charge.
- The document reader transcribes printed text only. It does not interpret X-rays, scans, ECGs or any other image of the body, and it is instructed to return nothing for such images; imaging findings come from a radiologist, never from software.
- Bank receipts for Niro Premium: a receipt you upload to pay by bank transfer is read by the same Google Cloud Vertex AI (Gemini) service, in the Mumbai (asia-south1) region, for the single purpose of reading the amount, date, payer and reference so your payment can be confirmed and matched against our bank records. It is not used for any other purpose and not used to train AI models.
- SMS delivery: one-time codes are delivered through Text.lk, a Sri Lankan SMS gateway. Only your telephone number and the verification code are shared with them.
- Video consultations (telehealth) and in-app home care calls: when you join a video consultation — or an in-app call between a family and a carer, which is audio only — your live video and audio are carried by Agora, our real-time communications provider, over encrypted connections, through relay servers located outside Sri Lanka (typically Singapore). Calls are not recorded — by us or by Agora — and no video or audio is stored anywhere. What remains afterwards is the same as for any consultation: the clinical record your practitioner writes, the details of the consultation itself (who, when, and how long) — and, on a home care visit, a short log of call attempts (who called, when, and whether it was answered, missed or declined), kept on the visit as part of its record.
Each provider acts as our "processor" under PDPA section 21 and is bound by contract to process personal data only on our instructions, with confidentiality and appropriate technical and organisational measures. AI-extracted text is always shown to you for confirmation before it is saved; it is your responsibility to check its accuracy, and the original document is always kept alongside it.
Cross-Border Data Transfers
Our cloud infrastructure is located outside Sri Lanka (as described above). Under section 26 of the PDPA (as amended), we engage in cross-border data flows on the basis that: (a) we ensure compliance with Parts I and II and sections 20 to 25 of the PDPA and adopt the instruments specified by the Data Protection Authority; and (b) you give your explicit consent to this transfer when you create your account, after being informed of the possible risks. You may withdraw this consent at any time, though the Service cannot operate without cloud storage.
Referrals
Where a practitioner refers you to a specialist or an allied health professional, the referral records who it is addressed to, the question being asked, and a brief summary of your history written by the referring practitioner for that purpose. It is part of your record, you can read it in full, and you can print it to carry with you.
- Where the person you are referred to holds a Niro account, the referral is delivered to them, and their reply is recorded in your record as well as returned to the practitioner who referred you.
- Where they do not, the referral is a document you carry. Nothing is sent anywhere.
- Being referred to someone does not give them your health record. They see the referral and what the referring practitioner chose to put in it. Your record is shared with them the same way as with anyone else — when you present your code, or book an appointment with them.
Verification of Healthcare Professionals
A doctor, dentist, allied health professional or institution may ask us to verify their registration. Verification is optional and does not restrict use of the Service: an unverified professional can use Niro fully, but their entries and listings are marked as unverified so that patients can see the difference.
- The documents submitted are reviewed by our named administrator, who checks them against the relevant public register — the SLMC medical or dental register, the applicable professional council, or PHSRC and NMRA registration for institutions.
- Documents are retained while the account exists so that a verification decision can be re-examined, and are deleted when the account is deleted.
- The outcome — verified or not — is shown alongside the professional's name within the Service. The documents themselves are never shown to patients.
Data Storage and Security
Under PDPA section 10, we apply appropriate technical and organisational measures, including:
- Encryption of data in transit (TLS) and at rest (AES-256 provided by our cloud providers).
- Per-record access rules so that a record is only accessible to its patient and to those the patient authorises.
- Sign-in protection: SMS verification at registration and at least every 30 days; on-device biometric or PIN unlock in between.
- Restricted internal access: our named administrator can view verification submissions, service usage and support reports. Our staff do not browse patient health records, and administrative access is limited to the accounts that require it.
- Access logging and internal controls maintained under our Data Protection Management Programme (PDPA section 12).
See our Trust Centre for a fuller description of our security architecture.
Data Retention and Deletion
We keep your record for as long as your account is active, so that it can serve as your lifelong health record. You may delete individual entries at any time in the app.
You may also delete your entire account from Settings. Because a health record can take years to rebuild, deletion is not immediate: your account is scheduled for deletion and can be restored by signing in again within 30 days. After that period your personal data is erased from production systems, and from backups on a rolling basis within 30 days, except where we are required to retain it under Sri Lankan law or a court order. Before deleting, you can download a copy of your record as a PDF.
A bank receipt you upload for Niro Premium is kept only until your payment is confirmed and is deleted within 90 days. It is stored where only our administrator can open it, and is never shown to any healthcare professional or other user.
When your account is erased:
- Your health record, uploaded documents and photographs are deleted.
- Upcoming appointments are cancelled and your contact details are removed from past bookings.
- Your staff memberships are removed, and any consultant listing created for you by a hospital is unlinked from your account but remains that hospital's own record.
- Entries a healthcare professional made in another person's record remain part of that person's record. A professional's account being deleted does not remove clinical entries from the records of the patients they treated.
Children
Under the PDPA, a child is a person below 16 years of age, and a child's personal data is a special category of personal data. A Niro account for a child must be created and operated by a parent or legal guardian, whose consent we require. Rights in respect of a child's data are exercised by the parent or guardian (PDPA section 17(5)).
Messages and Marketing
We send service messages (verification codes, security alerts, critical service notices) as part of operating the Service. We will send promotional or marketing messages only with your prior consent (PDPA section 27), we will identify ourselves in every such message, and every message will tell you how to opt out free of charge.
Your Rights
Under Part II of the PDPA you have the right to:
- Access — confirm whether we process your personal data and receive the information in Schedule V (section 13).
- Withdraw consent at any time, and object to processing (section 14). Withdrawal does not affect processing already carried out.
- Rectify or complete inaccurate or incomplete data (section 15) — you can edit most of your record directly in the app.
- Erasure of your personal data (section 16).
- Request review of any decision based solely on automated processing (section 18).
We will respond in writing within one month of your request, free of charge. Where an extension is genuinely necessary we may extend by up to two further months (never more than three months in total) and will tell you before the first month ends. If we refuse a request we will give reasons and inform you of your right to appeal to the Data Protection Authority of Sri Lanka, and thereafter to the Court of Appeal. Rights may be exercised on behalf of a child or an incapable person by a parent, guardian or court-appointed administrator, by a person you authorise in writing, or by an heir within ten years of a data subject's death.
Personal Data Breaches
If a personal data breach occurs, we will notify the Data Protection Authority of Sri Lanka in the form, manner and time period specified in its rules (PDPA section 23), and we will notify you where the rules so require or where we consider you are at risk of harm.
Complaints and Contact
- Data Protection Officer: privacy@niro.lk
- General support: support@niro.lk
- Postal: Xtramile Consultancy Services (Pvt) Ltd, Town Mosque Road, Akkaraipattu 02, 32400, Sri Lanka.
You also have the right to lodge a complaint with the Data Protection Authority of Sri Lanka.
Updates to this Policy
We may update this Policy from time to time. We will notify you in the app of material changes and, where required by the PDPA, seek fresh consent. This Policy is provided in Sinhala, Tamil and English; in the event of an inconsistency, the English text prevails.
Niro