- Introduction and Commitment
- Scope of Policy
- All individuals using the Heartiest Website, Heartiest App, or Heartiest Store.
- Participants in our assessments, courses, challenges, events, corporate programs, and wellness initiatives.
- All offline and online data collected through forms, communications, feedback, or transactions.
- Information We Collect
- Full name, contact number, and email address
- Date of birth, gender, and demographic details
- Billing and shipping address (for product deliveries)
- Health-related information (only if voluntarily shared during assessments or programs)
- Corporate/Institutional details (for B2B clients)
- Login credentials, profile photo, and preferences
- Communications and messages sent through support, chat, or social channels.
- Is used only to generate personalized reports, recommendations, and progress tracking.
- Is never shared externally without explicit written consent.
- Is stored securely and anonymized for analytical or educational insights.
- Device type, browser, IP address, and operating system
- Pages visited, duration of visit, and referring URLs
- Cookies and session identifiers
- Mobile device identifiers, app version, and crash logs
- How We Use Your Information
- To create and manage your user account
- To process orders, subscriptions, and program enrollments
- To generate personalized reports or wellness recommendations
- To deliver purchased digital or physical products
- To communicate transactional and service-related information
- To provide customer support and respond to queries
- To send educational newsletters, updates, or promotional messages (only if opted-in)
- To improve app/website performance through analytics
- To understand usage patterns and content engagement
- To develop new programs, features, and services
- To ensure compliance with applicable laws and regulatory requirements
- Consent and Legal Basis for Processing
- Your explicit consent (e.g., when signing up or submitting assessments).
- Performance of a contract (e.g., program enrollment, purchase fulfillment).
- Legitimate interest (e.g., improving user experience, analytics).
- Compliance with legal obligations (e.g., tax or audit purposes).
- Data Retention Policy
- Heartiest retains user data only as long as necessary for legitimate business, legal, or operational purposes.
- Health assessment data is retained securely for up to 5 years to allow users to track progress over time.
- Inactive accounts may be anonymized after 24 months of inactivity.
- Transaction and invoice data are stored per accounting requirements.
- Data Sharing and Disclosure
- Law, regulation, or court order
- Government or enforcement agencies under due legal process
- Cookies and Tracking Technologies
- Improve website performance and load speed
- Remember user preferences
- Measure campaign effectiveness
- Deliver personalized content
- Data Security and Protection
- Secure Socket Layer (SSL) encryption across all web sessions
- Multi-layered firewalls and intrusion detection systems
- Encrypted data storage and restricted access protocols
- Regular security audits and vulnerability testing
- Limited employee access to personal data on a need-to-know basis
- Notify affected users within 72 hours (as per legal requirements)
- Take immediate remedial measures to contain and rectify the incident
- Data Subject Rights (as per Indian DPDPA & Global GDPR Standards)
- Right to Access: Request a copy of your personal data held by Heartiest.
- Right to Rectification: Correct or update inaccurate information.
- Right to Erasure (“Right to be Forgotten”): Request deletion of data (subject to retention laws).
- Right to Restrict Processing: Limit certain uses of your data.
- Right to Data Portability: Request export of your data in a structured format.
- Right to Withdraw Consent: Stop communications or data processing anytime.
- Right to Lodge Complaint: File grievances with regulatory authorities if dissatisfied with our handling.
- International Data Transfers
- Minors’ Privacy
- Parents/guardians must provide consent before data collection.
- Children’s data, if collected, is anonymized and used only for educational insight.
- Corporate and Institutional Clients
- Individual participant data remains confidential.
- Only aggregate health trends are shared with the organization, never individual results.
- Corporate administrators must ensure lawful consent collection from their employees or members.
- Communication Preferences
- Unsubscribe from newsletters via footer link
- Opt out of promotional SMS or WhatsApp by replying “STOP”
- Modify notification settings in the app or website profile
- Third-Party Links and External Services
- Data Storage Duration and Deletion Requests
- Customer account data: retained as long as the account is active
- Assessment data: retained for 5 years (anonymized after expiry)
- Billing & transaction data: 8 years (per Indian accounting norms)
- Marketing consent data: until user opts out
- Grievance Redressal Mechanism
- Level 1 – Data Support Team: Email: info@heartiest.org Response: within 7 business days
- Level 2 – Grievance Officer: Name: Data Protection Officer (DPO), Heartiest Wellness Pvt. Ltd. Address: P-45, Mayur Vihar Phase I, Near Ahlcon Public School, Delhi – 110091 Email: privacy@heartiest.org Response: within 15 business days
- Level 3 – Escalation (Regulatory Complaint): If unsatisfied, you may escalate to the Data Protection Board of India (DPBI) under the Digital Personal Data Protection Act, 2023.
- Policy Updates and Notifications
- Posted on Heartiest.org/privacy-policy
- Communicated via email to registered users (where material changes occur)
- Effective 7 days after publication
- Limitation of Liability
- You share data voluntarily and understand inherent internet risks.
- Heartiest is not liable for breaches caused by third-party service providers, cyberattacks, or force majeure events beyond its reasonable control.
- Our liability in any proven breach is limited to the amount paid by the affected user within the preceding 6 months or as otherwise required by law.
- Contact Details
- User Acknowledgement
- Have read, understood, and agreed to this Privacy Policy
- Voluntarily provide data to receive health, wellness, or educational services
- Understand their rights under Indian law and international best practices
- Consent to data collection and use as outlined herein