Who We Are
InCHES provides digitally enabled medical, underwriting, claims, clinical audit, fraud-risk and related support services to insurance companies. When we process policyholder, insured person, claimant, nominee, medical or claims data on an insurer's instructions, the insurer is ordinarily the Data Fiduciary and InCHES acts as its Data Processor.
For information collected directly for our own purposes — such as website enquiries, recruitment, employment and vendor management — InCHES acts as the Data Fiduciary.
What We May Collect
- Contact details, including name, email address, telephone number, organisation and designation.
- Information included in an enquiry, feedback form, job application, CV or correspondence.
- Technical information such as IP address, device/browser information, access logs and necessary cookie data.
- Insurance, claims, identity, demographic, medical and supporting records, but only where an insurer or authorised client provides or permits access to such data for contracted services.
Why We Use Personal Data
- To respond to enquiries, demonstrate or provide services, manage client and vendor relationships, and process job applications.
- To perform contracted insurance-support services on documented client instructions, including underwriting support, claims review, medical audit, fraud-risk analysis and related quality checks.
- To secure our systems, investigate incidents, maintain audit trails, prevent misuse and meet legal, regulatory and contractual requirements.
- To send service or event communications where you have requested them or where otherwise permitted; you may opt out of optional communications.
Sharing and Retention
We share personal data only on a need-to-know basis with authorised personnel, the relevant insurer/client, approved service providers, professional advisers, regulators or law-enforcement authorities where lawful. We require appropriate confidentiality, security and processing commitments.
We retain data only for the client-approved period, the purpose for which it was collected, or the period required by applicable law, and then securely delete, return or anonymise it.
Security and International Processing
We use reasonable technical and organisational safeguards, including access controls, authentication, logging, encryption where appropriate, secure transfer, backups, vulnerability management and incident response.
If personal data is processed outside India, we follow applicable law, client instructions and contractual safeguards, including any restrictions notified by the Government of India.
Your Choices and Rights
Where InCHES is the Data Fiduciary, you may exercise the following rights. We may need to verify your identity. Where we process data for an insurer/client, please contact that insurer/client first; we will support it in responding to you.
Children's Data
Our website is not directed at children. We do not knowingly collect children's personal data through the website without appropriate authorisation and verifiable parental or lawful guardian consent where required.
Client-provided claims or insurance records involving children are processed only for the contracted purpose and under the client's instructions.
Contact and Grievance
For privacy questions or grievances, please contact our authorised privacy contact using the subject line "Privacy grievance".
9th Floor, Harbhajan Commercial Complex
Plot No. 4954A, B, B1 to B7
Opp. Petrol Pump, CST Road, Kalina
Santacruz (East), Mumbai – 400098
Maharashtra, India
InCHES will acknowledge and address the grievance through its designated privacy owner.