Privacy Policy
Last updated: January 2025
Introduction
At Unisoul Health Pvt. Ltd. ("Unisoul", "we", "us", or "our"), we are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use our wellness services, website, mobile applications, and related platforms ("Services").
This Privacy Policy is prepared in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and other applicable Indian privacy and healthcare laws.
By using our Services, you agree to the collection and processing of your personal data as described in this Policy.
1. Information We Collect
We collect only such information that is necessary, lawful, and relevant for providing our Services.
1.1 Personal Information
- Name, age, gender, and contact details (phone number, email address, residential address)
- Identity verification documents such as Aadhaar, PAN, or other government-issued IDs, where legally required
- Emergency contact information
- Profile preferences and communication settings
1.2 Health & Medical Information
- Medical history, allergies, and existing health conditions
- Physiotherapy, wellness, spa, or treatment records
- Prescriptions, diagnostic reports, and therapy notes
- Progress tracking records and wellness goals
- Treatment-related photographs, collected only with explicit consent
All health and medical information is treated as sensitive personal data and handled under strict confidentiality.
1.3 Service Usage Information
- Appointment bookings and service history
- Service preferences and feedback
- Payment and transaction details processed through authorised payment gateways
- Communication records with our staff
1.4 Technical Information
- Device information (device type, operating system, browser type)
- IP address and approximate location data
- Cookies and usage analytics
- Website or application performance and error logs
2. How We Use Your Information
2.1 Service Delivery
- Providing wellness, physiotherapy, spa, and allied healthcare services
- Managing appointments and treatment schedules
- Ensuring safety, suitability, and quality of treatments
- Maintaining continuity of care
2.2 Communication
- Appointment confirmations and reminders
- Post-treatment care instructions and follow-ups
- Customer support and query resolution
- Important service-related updates and notifications
2.3 Business and Legal Operations
- Processing payments and managing accounts
- Internal analysis to improve service quality and user experience
- Compliance with legal, tax, and regulatory requirements
- Prevention of fraud, misuse, and unauthorised access
2.4 Marketing Communications (With Consent)
- Wellness tips, health education, and informational content
- Promotional offers, packages, and membership benefits
- Surveys and feedback requests
You may withdraw your marketing consent at any time.
3. Information Sharing and Disclosure
3.1 Healthcare Professionals
Relevant medical information may be shared with licensed doctors, physiotherapists, and therapists involved in your treatment to ensure safe and effective care.
3.2 Authorised Service Providers
- Payment gateway providers
- Communication and messaging service providers
- IT and technology infrastructure partners
All such parties are bound by confidentiality and data protection obligations.
3.3 Legal and Regulatory Requirements
Personal data may be disclosed where required by applicable laws, court orders, or government and regulatory authorities.
3.4 What We Do Not Share
- We do not sell or trade personal data
- Medical data is never shared for advertising purposes
- Sensitive personal data is not shared without consent, except where legally required
4. Data Security
4.1 Security Measures
- Encryption of sensitive data during transmission
- Secure servers with access controls
- Role-based access to personal data
- Periodic security audits and system updates
- Staff training on confidentiality and data protection
4.2 Data Breach Management
In the event of a personal data breach, we will take prompt corrective action and notify affected individuals and authorities as required under applicable law.
5. Data Retention
5.1 Medical Records
Medical and treatment records are retained for a minimum period of five (5) years from the date of last treatment or longer if required by law.
5.2 Other Personal Data
Other personal information is retained only as long as necessary for active services, legal compliance, and dispute resolution.
5.3 Data Deletion
After the retention period, personal data is securely deleted or anonymised. Requests for early deletion may be considered subject to legal obligations.
6. Your Rights Under DPDP Act, 2023
You have the right to:
- Access your personal data
- Request correction of inaccurate or incomplete data
- Request erasure of personal data, subject to legal requirements
- Withdraw consent for data processing
- Raise grievances related to data processing
7. Cookies and Tracking Technologies
We use cookies to improve website functionality and user experience.
7.1 Types of Cookies
- Essential cookies for core website functionality
- Analytics cookies to understand usage patterns
- Preference cookies to remember user settings
- Marketing cookies, used only with consent
You may manage cookie preferences through your browser settings.
8. Third-Party Services
Our Services may include links to third-party websites or integrations such as payment gateways or social media platforms. We are not responsible for the privacy practices of such third parties.
9. Updates to This Privacy Policy
This Privacy Policy may be updated periodically to reflect changes in legal requirements or business practices. Continued use of our Services after updates constitutes acceptance of the revised Policy.
10. Contact and Grievance Redressal
Data Protection Officer
Email: privacy@unisoulhealth.com
Phone: +91 8817574293
Grievance Officer
Email: grievance@unisoulhealth.com
Phone: +91 8817574293
Response Time: Within 48 working hours
This Privacy Policy is effective as of January 2025 and governs the collection and use of information by Unisoul Health Pvt. Ltd.
For any questions or concerns about this policy, please don't hesitate to contact us using the information provided above.