Legal & GovernanceBack to loginFERTY9 HEALTH PLATFORM
Privacy, Security and Regulatory Compliance
Ferty9’s evidence-based approach to privacy, healthcare and cybersecurity obligations.
- Effective
- 27 September 2026
- Last updated
- 27 September 2026
- Version
- 1.0
- Operator
- Star Fertility Private Limited
Ferty9 manages compliance as an ongoing, evidence-based programme. This page describes applicable obligations and readiness work; it is not a claim of universal certification or legal approval.
1. DPDP Act and Rules
The Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 have staged commencement. Rules 1, 2 and 17–21 commence on publication; Rule 4 commences one year after publication; Rules 3, 5–16, 22 and 23 commence eighteen months after publication. Ferty9 tracks duties as the relevant provisions become operative.
2. Assisted Reproductive Technology
Where the Assisted Reproductive Technology (Regulation) Act, 2021 applies, workflows must support written consent, specific consent for cryopreservation and reproductive material, applicable withdrawal before transfer, recordkeeping for at least ten years and transfer to the National Registry as required. Records connected with legal proceedings may be retained longer. Clinical teams must use the approved clinical forms; a website acknowledgement is not ART treatment consent.
3. CERT-In cybersecurity duties
Covered cybersecurity incidents must be assessed for reporting to CERT-In within six hours of noticing the incident or being informed of it. Applicable ICT logs must be maintained securely for at least 180 days within India. Internal incident procedures govern assessment, evidence preservation, escalation and reporting.
4. Security and governance
- Role-based access and least-privilege administration.
- Authentication, session protection, logging and audit controls.
- Controlled development, change, backup and incident processes.
- Supplier review and contractual controls proportionate to risk.
- Data minimisation and use of masked or synthetic data where appropriate.
5. Conditional frameworks
ABDM participation is not claimed unless a specific integration is verified and approved. GDPR and HIPAA are considered only where their territorial, contractual or activity-specific requirements apply. No reference on this page represents a certification.
6. Contact
- Star Fertility Private Limited, H. No. 10-3-162, 2nd Floor, NCL Pearl, SD Road, Secunderabad, Hyderabad, Telangana – 500026. Privacy and grievance enquiries: admin@ferty9.com. General support: info@ferty9.com. Telephone: 1800 296 0000.