🔒 Privacy Policy

Version: 1.0  |  Effective Date: 04 Jul 2026
🇮🇳 DPDP Act 2023 🌍 GDPR Ready Last updated: 04 Jul 2026

1. Introduction

At HealthVaultFamily ("Company", "we", "us", or "our"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our software-as-a-service platform, website, and related services (collectively, the "Service").

This policy complies with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and reflects our commitment to global best practices, including the principles of the GDPR. We act as a Data Fiduciary as defined under the DPDP Act.

?? Your Consent: By registering for an account and using the Service, you provide your free, specific, informed, unconditional, and unambiguous consent to the collection and processing of your personal data as described in this policy. You may withdraw your consent at any time, subject to contractual and legal limitations.

2. What Personal Data We Collect

We collect personal data that you provide directly and data generated through your use of the Service.

Category Examples Purpose
Account & Profile Data Name, email address, phone number, company name, job title, username, password. Account creation, authentication, communication, support.
Billing & Payment Data Billing address, payment method details (processed by secure third-party gateways), GSTIN. Subscription management, invoicing, tax compliance.
Usage Data IP address, browser type, device information, pages visited, features used, session logs. Service analytics, performance monitoring, security, product improvement.
User Content Data, documents, reports, configurations, and other content you upload or create via the Service. Providing the Service, data processing as per your instructions.
Communications Emails, support tickets, chat messages, feedback, survey responses. Customer support, service updates, product feedback.
Health Data Health records, family member health information, readings, medical history, and related health data. Providing health management services, analytics, and reporting (with your explicit consent).

3. Legal Basis for Processing

Under the DPDP Act and consistent with global standards, we process personal data on the following legal bases:

  • Consent: You have provided clear and affirmative consent for specific processing activities.
  • Contractual Necessity: Processing is necessary to perform our obligations under the Terms and Conditions, including providing the Service.
  • Legal Obligation: Processing is required to comply with applicable laws, including tax and regulatory requirements.
  • Legitimate Interests: Processing is necessary for our legitimate business interests, such as improving the Service, fraud prevention, and network security, provided such interests are not overridden by your data protection rights.

4. How We Use Your Personal Data

We use your personal data for the following purposes:

  • Provision of Service: To create and manage your account, authenticate your identity, and deliver the Service.
  • Billing and Payments: To process payments, send invoices, and manage subscriptions.
  • Support and Communication: To respond to your inquiries, provide technical support, and send important service-related notifications.
  • Improvement and Analytics: To understand how users interact with the Service, identify trends, and enhance user experience.
  • Security and Compliance: To detect, prevent, and address fraud, security incidents, and technical issues, and to comply with legal obligations.
  • Marketing (with consent): To send you promotional communications about new features, products, or events, where you have opted in.
  • Health Management: To provide health tracking, analysis, and family health management features (with your explicit consent).

5. How We Share Your Personal Data

We do not sell your personal data. We may share your data with:

  • Service Providers: Third-party vendors who assist us with payment processing (e.g., Razorpay, Stripe), cloud infrastructure (e.g., AWS, Azure), customer support platforms, and analytics (e.g., Google Analytics). These providers are contractually bound to process data solely on our instructions and in compliance with this policy.
  • Affiliates and Subsidiaries: Entities under common control with us, for internal business purposes.
  • Law Enforcement and Regulators: Where required by law, court order, or government regulation, including responding to lawful requests from Indian authorities.
  • Business Transfers: In connection with a merger, acquisition, restructuring, or sale of assets, where the recipient agrees to protect your data in a manner consistent with this policy.
  • Healthcare Partners: With your explicit consent, we may share your health data with healthcare providers, laboratories, or other health services you choose to connect.

6. Cross-Border Data Transfers

We may transfer your personal data to servers and service providers located outside India, including in the United States, European Union, and other jurisdictions. Under the DPDP Act, cross-border data transfers are permitted by default, but we ensure that:

  • We maintain appropriate safeguards, such as Standard Contractual Clauses (SCCs) or equivalent measures, to protect your data.
  • We monitor the "negative list" of restricted jurisdictions issued by the Government of India.
  • Any data processing agreements with third parties explicitly reference Indian legal standards and include data protection obligations.

7. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, regulatory, accounting, or reporting requirements. Generally, we retain your data:

  • For the duration of your active subscription plus a reasonable period (typically 30–90 days) after termination to allow for data export.
  • As required by law, such as tax records (8 years under Indian law) or legal proceedings.
  • In anonymized or aggregated form for analytics and research purposes indefinitely.
  • Health data is retained for the duration of your subscription and may be stored longer for historical health tracking, with your continued consent.

8. Your Data Protection Rights

Under the DPDP Act, and consistent with global privacy frameworks, you have the following rights:

  • Right to Access: You may request a copy of the personal data we hold about you.
  • Right to Correction: You may request correction of inaccurate or incomplete data.
  • Right to Erasure: You may request deletion of your personal data, subject to legal and contractual obligations.
  • Right to Withdraw Consent: You may withdraw your consent at any time, but this may affect your ability to use the Service.
  • Right to Object: You may object to processing based on legitimate interests or direct marketing.
  • Right to Data Portability: You may request transfer of your data to another service provider.
  • Right to Grievance Redressal: You may lodge a complaint with our Grievance Officer or with the Data Protection Board of India.

To exercise any of these rights, please contact us using the details in Section 12 below. We will respond within 30 days as required under Indian law.

9. Data Security

We implement industry-standard technical, organisational, and administrative measures to protect your data against unauthorised access, loss, alteration, or destruction. These include:

  • Encryption: Data in transit (TLS 1.2+) and at rest (AES-256).
  • Access Controls: Role-based access, multi-factor authentication, and least-privilege principles.
  • Monitoring: Continuous security monitoring, logging, and incident response protocols.
  • Audits: Regular security assessments and compliance audits.
  • Health Data Protection: Enhanced security measures for health-related data, including separate encryption keys and restricted access.

In the event of a personal data breach, we will notify the Data Protection Board of India and affected users within 72 hours as required by the DPDP Rules, 2025.

10. Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience, analyze usage, and for marketing purposes. You can manage your cookie preferences through your browser settings. For detailed information, please refer to our Cookie Policy.

11. Childrens Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor without verifiable parental consent, we will take steps to delete that information.

As a family health management platform, we may collect health information about family members of all ages. You represent that you have the legal authority to provide such information and that you have obtained appropriate consent.

12. Contact Us / Grievance Redressal

If you have any questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

  • Grievance Officer: [Name of Grievance Officer]
  • Email: grievance@healthvaultfamily.com
  • Address: [Your Registered Office Address, India]
  • Response Time: We will respond to your grievance within 30 days of receipt.

You also have the right to lodge a complaint with the Data Protection Board of India if you are not satisfied with our response.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes through the Service or via email. Your continued use of the Service after such changes constitutes your acceptance of the updated policy.

?? Multi-Language Availability: To comply with the DPDP Act, this Privacy Policy is available in English and [other languages as required]. You may request a copy in your preferred language by contacting us.
← Back to Registration