Aayuv Technologies Private Limited

Privacy Policy

How Aayuv Technologies Private Limited (“Company”) collects, uses, shares, and protects your personal data – and the rights you have over it.

Critical notice: do not use Company’s products or provide personal data if you disagree with this policy.
Contents
  1. We care about your privacy
  2. What information do we collect?
  3. Why do we process personal data?
  4. Our legal basis for processing
  5. How long do we retain personal data?
  6. Do we share personal data?
  7. Children’s privacy
  8. Data quality
  9. Safeguarding personal data
  10. How do we use cookies?
  11. Your rights
  12. Data security
  13. Controller of your personal data
  14. Grievance redressal mechanism
  15. Changes to this privacy policy

01We care about your privacy

Company and its affiliates are committed to respecting privacy and complying with applicable data-protection laws. This policy describes how personal data is collected and used where Company is the data controller.

If there is a difference between product-specific notices and this Policy, the notices should be considered first.

Software on your device may access your information, and products may contain links to third-party services with their own privacy policies.

Critical notice: do not use Company’s products or provide personal data if you disagree with this policy.

02What information do we collect?

Company collects personal data when you use or register products and services, or interact with the company.

Product and service activations

Electronic activation sends device type, application type, unique identifiers, network information, and subscription details to Company.

Use of products and services

Web servers automatically create visit records including IP addresses, access times, linked sites, pages visited, links used, content viewed, browser type, language, and related information. Applications periodically contact servers to check for updates or send usage information.

Information you provide

When creating accounts or requesting services, Company may request: name, email address, phone number, street address, usernames, passwords, feedback, device information, age, gender, and language preferences. The company maintains records of consents, preferences, and settings regarding location data, marketing, and data sharing.

Your transactions

Company maintains records of downloads, content provided, requests, agreements, products / services delivered, payment details, delivery information, contacts, communications, and other interactions. We may, in accordance with applicable law, record your communication with our customer care.

Positioning and location data

Location-based services use satellite, mobile, Wi-Fi, Bluetooth Low Energy, or network-based positioning. These may involve exchanging location data and unique device identifiers with Company. We do not use this information to identify you personally without your consent.

COVID-19 contact tracing and vaccination status

Per Ministry of Health & Family Welfare guidelines, Company collects vaccination status and COVID-19 infection history. Data is not fetched from government or third-party websites. The aggregated data is shared with your HR / employer only, to help maintain a safe, Covid-free workplace.

Camera and gallery access

Some services require collecting images, audio, video, files, and digital information from your device’s camera and gallery. You won’t be able to share photos of prescriptions or medical reports with the doctor if we don’t have access. Only your doctor has access to them, besides you.

Fitness data usage

Connecting third-party applications or devices to Company’s app allows collection of fitness information including step count, calories burned, and sleep data. Data is collected only when you enable third-party devices or applications. You can withdraw consent anytime through account settings.

We do not share any fitness data collected within Company’s application with external or network partners.

For group challenges and leaderboards, your name and fitness data may be visible to other participants within your corporate group only – no unique identifiers or sensitive details are displayed.

Calendar permission

Employee engagement activities, fitness sessions, and webinars require calendar permissions to store data and provide timely event reminders.

Information provided by partners

Company obtains information from industry partners and public sources like business registries. These sources must comply with applicable laws.

03Why do we process personal data?

04Our legal basis for processing

05How long do we retain personal data?

Company endeavours to collect only necessary personal data and retain it no longer than required. For account management data (name, email, content, preferences) the data is maintained while you retain it. Activity records are typically maintained briefly before anonymisation or pseudonymisation.

Contact aravind@ekincare.com for additional retention information.

06Do we share personal data?

Company does not sell, lease, rent, or disclose personal data to third parties unless stated below.

With your consent and social sharing

Some services allow sharing with other users or services. Consider carefully before disclosing information accessible to other users.

Company and authorised third parties

Company may share personal data with its other subsidiaries or authorised third parties processing data for Company purposes – billing, delivery, customer service, data management, research, and marketing campaigns. Authorised third parties cannot use personal data for other purposes and are contractually bound.

International transfers

Personal data may transfer internationally, including to countries without specific personal-data protection laws. Company ensures legal transfer basis and adequate protection through standard contractual clauses (where necessary) and appropriate technical / organisational security measures.

Mandatory disclosures

Company may be obligated by law to disclose personal data to authorities or third parties like law enforcement in operation countries.

Mergers and acquisitions

Business sales, purchases, mergers, or reorganisations may involve disclosing personal data to prospective or actual purchasers and advisers.

07Children’s privacy

Company products and services are typically intended for general audiences. The company does not knowingly collect children’s information without parental or guardian consent.

08Data quality

Company takes reasonable steps to keep possessed personal data accurate and deletes incorrect or unnecessary data. You are encouraged to access your personal data periodically to ensure it remains current.

09Safeguarding personal data

Privacy and security are key considerations in product creation and delivery. Company assigns specific responsibilities for privacy and security matters and enforces internal policies through proactive and reactive risk management, security and privacy engineering, training, and assessments. Database access is limited to authorised persons with justified need.

10How do we use cookies?

Essential cookies

Necessary to operate and improve offerings, enabling navigation and feature use. Without them, certain services or functionalities like authentication may be unavailable.

Analytics cookies

Company’s website uses analytics cookies, such as Google Analytics, to collect visitor usage information, analyse traffic, track interactions, and identify popular content. The information collected is anonymous and is used for statistical purposes only.

Continuing to use Company constitutes cookie consent. You can control and manage cookies through most web browser settings. Disabling certain cookies may impact website functionality and performance.

11Your rights

You have the right to: know what personal data Company holds about you and access it; have incomplete, incorrect, unnecessary, or outdated personal data updated; request personal data erasure; obtain a machine-readable copy; object to or restrict processing in certain circumstances; unsubscribe from direct marketing.

Critical alerts may still be sent even if you opt-out from marketing and communications.

Requesting data deletion or processing cessation may prevent service continuation. Applicable data-protection law may restrict exercise extent; Company will respond with action explanations as required.

12Data security

You agree information may be stored in third-party cloud service infrastructure. While reasonable safety and security measures are taken, Company is not liable for data breaches by third-party providers beyond its control.

Beyond third-party provider security measures, Company uses physical, managerial, technical, and operational safeguards per industry standards.

We cannot guarantee the security of our database, nor can we guarantee that the information you supply will not be intercepted while being transmitted to us over the internet.

13Controller of your personal data

Company (Skootr Forest, Block C, RMZ Futura Plot No. 14 and 15, Phase 2, HITEC City, Hyderabad 500081) is the personal data controller. The Company affiliate providing the product or service may also be a controller.

For privacy matters, contact the Data Protection Officer at aravind@ekincare.com.

14Grievance redressal mechanism

Grievance Officer · IT Act 2000 & Intermediary Guidelines 2021

Name

Somak Ray

Email

somak@ekincare.com

Address

Skootr Forest, Block C, RMZ Futura Plot No. 14 and 15, Phase 2, HITEC City, Hyderabad 500081

The officer reverts within 24 hours of complaint receipt; best efforts to redress within 15 days. For privacy or data-practice concerns, reach out at aravind@ekincare.com.

15Changes to this privacy policy

Company may change this policy or modify / withdraw service access anytime with or without notice. Material adverse changes require notice at policy beginning and homepage for 30 days. Re-visit this policy periodically to learn of changes.