Niro

Privacy Policy

Xtramile Consultancy Services (Pvt) Ltd of Town Mosque Road, Akkaraipattu 02, 32400, Sri Lanka ("we", "us", "our") values your privacy and is committed to protecting personal and health information. This Privacy Policy explains how we collect, use, store, share and protect information when you use Niro (the "Service"), including our mobile application and web portals.

This Policy is prepared in accordance with the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025 (together, the "PDPA"). We act as the "controller" of personal data processed through the Service.

By creating an account and giving your consent in the app, you agree to the practices described below. Health information is a "special category of personal data" under the PDPA and we ask for your explicit consent before processing it.

Last updated: 2 September 2026

About Niro

Niro is a patient-held personal health record. Patients create and control their own record and choose who sees it. The Service includes:

Except as described under "Appointment booking" below, nothing in your record is visible to a doctor, dentist, allied health professional, pharmacy, laboratory or radiology centre unless you present your Niro code or QR code to them.

Information We Collect

Patients

Healthcare professionals and facilities

Home carers

Name, telephone number, gender, the languages they speak, identity document, the qualification claimed and its certificate or registration number, police or character certificate and its expiry date, the location travelled from and the distance travelled, the services offered (their hourly prices are set by Niro and are the same for every companion), availability and on-duty state, the institutions they work for, ratings received, a reliability record (on-time rate, lateness, unproven check-ins, no-shows and strikes) built from their visit records, and, for payouts, bank account details with a passbook page or statement header in their name.

Technical information

Purposes and Legal Bases

We process personal data for specified, explicit and legitimate purposes only (PDPA section 6):

We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not use your health data for advertising.

Patient-Controlled Sharing

Your record is shared only when you act:

We never sell personal data, and we do not share it with advertisers.

What each kind of access opens

Sharing your record is not all-or-nothing. A doctor or dentist treating you sees the whole record; everyone else receives access shaped to the job they are doing, and nothing wider:

Previously, allowing access gave the whole record to whoever asked, which meant a pharmacist dispensing an inhaler received every consultation note you had ever had. That is no longer how it works, except where you deliberately grant it: showing a one-time consent code from the app opens your full record to the clinician who scans it, for the working day only. Like every other kind of access it lapses on its own, is written to your access log, and can be withdrawn from Record access.

Emergency access

There is one exception to sharing happening only when you act. A registered clinician can open your record in a medical emergency — when you are unable to consent, such as being brought in unconscious — without your action. This is never silent: the clinician must record a reason, you are notified the moment it happens, the access lasts two hours and then lapses, and it is written to your access log under their name like any other grant. Legal basis: protecting your vital interests where you are physically or legally incapable of giving consent (Schedule I(d) / II(c)).

Access ends by itself

Access is time-limited. A consultation's access lapses a few days afterwards, a home care visit's two days after the visit, and a returned test result's after a few weeks. Only your own access, and a delegate you have named, do not expire.

Withdrawing access

You can see everyone who currently holds access to your record, what kind of access it is, and when it lapses — and you can withdraw any of it at any time, from Record access in the app. Consent that cannot be taken back is not consent.

Your access log

We keep a log of every time access to your record was granted, to whom, and why, and you can read it. It records authorisations rather than every page view: once someone has been let in, they read your record directly from their device, so we do not see each screen they open — and we would rather tell you exactly what we know than imply a surveillance we do not have.

Appointment booking

When you book an appointment, you share your name and telephone number with the institution and with the practitioner you have booked, so that they can manage the queue and contact you. Your health record is not part of a booking.

Booking an appointment is also your consent for that practitioner to open your health record for that consultation, in the same way as if you had shown them your code at the desk. This lets them prepare before you arrive. If you do not wish to share your record, you may cancel the booking, or ask the practitioner not to open it.

The institution's channelling staff see your visit, not your history. Specifically, staff of the institution's channelling department can see your name, telephone number and queue position; any observations the clinic took before your consultation; and, after the consultation, what it asked you to do next — the plan, the investigations ordered, the medicines prescribed and any referral raised — so that the desk can direct you to their pharmacy, their laboratory or your next appointment.

They cannot see your medical history, your past consultations, or the diagnosis made at this one. This access is limited to staff the institution has placed in that department, and it ends a few days after the appointment.

Managing a Record for Someone Else

A person can be named as a delegate on someone's record — most often an adult child managing an elderly parent's care, sometimes from abroad. A delegate sees the record as the patient does and can book on their behalf. Everything they do is recorded under their own name as well as the patient's, because "who is this for" and "who did this" are different questions.

A delegate is appointed only by the patient allowing it, and the patient can withdraw it at any time from Record access.

Where a person cannot hold an account themselves — an elderly parent without a phone — an identity-verified relative can create a record for them. Such a record is marked as managed, and who created it is stored, so that any clinician relying on it can see that the patient has never verified anything themselves. It stops being managed when the patient signs in on their own number and claims it. We cap how many records one person may create this way.

Proving Who You Are

Some things — managing another person's record, creating one for a relative — act on somebody other than yourself, so they require identity verification. An email address proves someone reads an inbox and a telephone number proves someone holds a SIM; neither says who a person is.

To verify, you send us a photograph of an identity document (a National Identity Card, or a passport for people signing up from overseas). A person reviews it. We store the images and the outcome; the trust level that results is stored where you cannot edit it, because a trust level its own subject can write means nothing.

People outside Sri Lanka can sign up with an email address instead of a Sri Lankan mobile number, and sign in afterwards with their device's fingerprint or face (a passkey). We hold the email address, the passkey's public key — never a fingerprint or face image, which never leave your device — and the verification codes we sent, which expire.

Home Care

Niro introduces families to home care from independent companions and from institutions with a Home care department. It is not a care agency and does not employ carers. This means personal data flows in both directions, and both directions are worth stating.

From a carer, we collect and hold: their name and contact details, their gender (which a family may filter on, since personal care is often chosen on it), the qualification they claim and the certificate or registration number behind it, a police or character certificate, where they travel from and how far, the services they offer and their hourly prices. Verification documents are reviewed by a person, who also records when the police certificate and any registration expire; we send reminders before expiry and pause the profile when a document has expired. The level they are approved at is written by that reviewer and not by the carer.

From an institution with a Home care department, we hold the services and prices it offers, the area it covers, its desk telephone number, its insurance declaration — insurer, policy number and expiry — which is shown to families once we have verified it, as "Covered by [institution]", and the list of Niro-verified staff it has invited and who have accepted. Whether a staff member is on duty, and whether they work exclusively for that institution, is set at the institution's desk and seen by the institutions they work for.

From a family booking a visit, the carer is shown: the patient's name and telephone number, the address of the visit, what has been asked for, and whatever the family chose to write in the notes — which we ask them to make honest, because a carer arriving without knowing that a patient cannot stand is how both of them get hurt. An institution's desk sees the same booking details in order to accept, assign and dispatch; the patient's record itself is opened only to the assigned carer, and only for that visit.

A visit record holds when the carer said they were on their way and the arrival time they gave; how they checked in — by scanning the patient's QR code, by entering the six-digit arrival code shown only to the family, or without proof — and the location and distance from the address recorded at check-in; when they checked in and out; the visit note; how late the arrival was against the booked start and against that estimate; extra hours requested and approved; incident reports (a fall, an injury, damage, care refused) with any photographs; any emergency raised from the visit, which also notifies the family, the institution's desk and Niro; what was asked for, what it cost, and whether it was paid. Where a problem is reported, the report, our review notes and the outcome are kept with it. This is kept as a record of what happened: it is what a complaint, an insurance claim or a dispute is settled from.

From these records we keep a reliability record for each carer — on-time rate, lateness, unproven check-ins, no-shows and strikes — and for each institution, and use them to decide who continues to be offered to families. The family and the carer see each other's part of a visit only as the app shows it; an institution sees the reliability record of its own staff; review notes are seen by Niro's administrators. All of it is retained with the visit record.

To pay carers and institutions we hold a payout account: bank, branch, account number and the name on the account, with a photograph of a passbook page, a statement header or a bank letter showing that name. A person at Niro checks the name against the verified identity or the institution's registration before the first payout and after any change; the document is seen only by that reviewer. The account, each visit's gross, commission and net, and every payout with its bank reference are kept with the payout history for as long as the account exists and for the period the tax and accounting laws require afterwards.

After a visit both sides may rate the other. A family's rating and review appear publicly on the carer's profile, showing the family's first name only. Reviews that name a medical condition or otherwise identify a patient are removed. A carer's rating of a household is not published.

The obligations on each side are set out in the Home Care Provider Agreement, the Institution Home Care Provider Terms and the Home Care Booking Terms.

Payments

Payments are handled by PayHere, a licensed Sri Lankan payment gateway. Your card details are never sent to Niro and never stored by us — they are entered inside PayHere's own checkout.

We hold a record of each transaction: what it was for, the amount, its status, and the reference PayHere gives us. We keep this because a payment that did not result in the consultation or visit it was for is a refund we owe you, and that is only provable from a ledger.

Data Processing, Cloud Providers and AI

Each provider acts as our "processor" under PDPA section 21 and is bound by contract to process personal data only on our instructions, with confidentiality and appropriate technical and organisational measures. AI-extracted text is always shown to you for confirmation before it is saved; it is your responsibility to check its accuracy, and the original document is always kept alongside it.

Cross-Border Data Transfers

Our cloud infrastructure is located outside Sri Lanka (as described above). Under section 26 of the PDPA (as amended), we engage in cross-border data flows on the basis that: (a) we ensure compliance with Parts I and II and sections 20 to 25 of the PDPA and adopt the instruments specified by the Data Protection Authority; and (b) you give your explicit consent to this transfer when you create your account, after being informed of the possible risks. You may withdraw this consent at any time, though the Service cannot operate without cloud storage.

Referrals

Where a practitioner refers you to a specialist or an allied health professional, the referral records who it is addressed to, the question being asked, and a brief summary of your history written by the referring practitioner for that purpose. It is part of your record, you can read it in full, and you can print it to carry with you.

Verification of Healthcare Professionals

A doctor, dentist, allied health professional or institution may ask us to verify their registration. Verification is optional and does not restrict use of the Service: an unverified professional can use Niro fully, but their entries and listings are marked as unverified so that patients can see the difference.

Data Storage and Security

Under PDPA section 10, we apply appropriate technical and organisational measures, including:

See our Trust Centre for a fuller description of our security architecture.

Data Retention and Deletion

We keep your record for as long as your account is active, so that it can serve as your lifelong health record. You may delete individual entries at any time in the app.

You may also delete your entire account from Settings. Because a health record can take years to rebuild, deletion is not immediate: your account is scheduled for deletion and can be restored by signing in again within 30 days. After that period your personal data is erased from production systems, and from backups on a rolling basis within 30 days, except where we are required to retain it under Sri Lankan law or a court order. Before deleting, you can download a copy of your record as a PDF.

A bank receipt you upload for Niro Premium is kept only until your payment is confirmed and is deleted within 90 days. It is stored where only our administrator can open it, and is never shown to any healthcare professional or other user.

When your account is erased:

Children

Under the PDPA, a child is a person below 16 years of age, and a child's personal data is a special category of personal data. A Niro account for a child must be created and operated by a parent or legal guardian, whose consent we require. Rights in respect of a child's data are exercised by the parent or guardian (PDPA section 17(5)).

Messages and Marketing

We send service messages (verification codes, security alerts, critical service notices) as part of operating the Service. We will send promotional or marketing messages only with your prior consent (PDPA section 27), we will identify ourselves in every such message, and every message will tell you how to opt out free of charge.

Your Rights

Under Part II of the PDPA you have the right to:

We will respond in writing within one month of your request, free of charge. Where an extension is genuinely necessary we may extend by up to two further months (never more than three months in total) and will tell you before the first month ends. If we refuse a request we will give reasons and inform you of your right to appeal to the Data Protection Authority of Sri Lanka, and thereafter to the Court of Appeal. Rights may be exercised on behalf of a child or an incapable person by a parent, guardian or court-appointed administrator, by a person you authorise in writing, or by an heir within ten years of a data subject's death.

Personal Data Breaches

If a personal data breach occurs, we will notify the Data Protection Authority of Sri Lanka in the form, manner and time period specified in its rules (PDPA section 23), and we will notify you where the rules so require or where we consider you are at risk of harm.

Complaints and Contact

You also have the right to lodge a complaint with the Data Protection Authority of Sri Lanka.

Updates to this Policy

We may update this Policy from time to time. We will notify you in the app of material changes and, where required by the PDPA, seek fresh consent. This Policy is provided in Sinhala, Tamil and English; in the event of an inconsistency, the English text prevails.