← Back to Home🔒 Our Privacy Promise to You
🚫We do NOT store your symptoms, medical concerns, or consultation history. What you tell your doctor stays between you and your doctor.
🚫We NEVER sell your health data to anyone, ever.
🚫We NEVER use your health data for advertising.
✅All traffic to our platform is HTTPS-encrypted in transit.
✅You can delete your account data anytime by email.
✅We are built around India’s DPDP Act 2023.
✅Zero-knowledge GPS — location never sold.
1. Who We Are
BioAgesis (OPC registration in process) ("BioAg€sis," "we," "us") is the data controller for personal data collected through our platform. We operate in India and comply with India's applicable data protection laws.
Privacy Contact: bioagesis.official@gmail.com (a formal Data Protection Officer has not yet been appointed \u2014 write to this address for any privacy request)
Company Address: BioAgesis (OPC registration in process), India (registration pending)
2. What Data We Collect
| Data Type | What We Collect | Why |
|---|
| Account Data | Name, email, phone number, password (hashed) | Account creation and authentication |
| Health Data | Not stored. Symptoms and concerns you share with your doctor are relayed at the time of consultation and never saved on our servers. | — |
| Emergency Data | Emergency contacts, GPS location (during SOS) | SOS notification and emergency response |
| Device Data | Device ID, OS version, app version | Security, anti-misuse enforcement, bug fixing |
| Payment Data | Payment reference IDs only (no card numbers stored). Payments are not yet live — this applies once enabled. | Payment processing via a licensed payment gateway |
| Usage Data | Features used, session timestamps | Platform improvement and security |
We do NOT collect: government ID numbers, financial account details, biometric data beyond what you voluntarily provide, or any data not listed above.
3. How We Use Your Data
- Providing services: Connecting you with doctors for advisory sessions, SOS emergency notifications — your health details are relayed at the time of service, not stored afterward
- Security: Fraud prevention, anti-misuse enforcement, account security
- Legal compliance: IT Act 2000 and India's DPDP Act 2023 are our primary legal frameworks
- Platform improvement: Anonymized, aggregated analytics only
- Communications: Service updates, security alerts, subscription notices
We NEVER use your health data for advertising, marketing profiling, or selling to third parties. This is an absolute rule with no exceptions.
4. Legal Basis for Processing
- Contract: Processing necessary to provide the services you signed up for
- Vital Interests: Emergency SOS data processed to protect life
- Legal Obligation: Compliance with IT Act 2000, DPDP Act 2023
- Legitimate Interests: Platform security and fraud prevention
- Consent: For optional features; you may withdraw consent at any time
5. Data Security
- Encryption: HTTPS/TLS encryption for all traffic in transit
- Data Minimization: We simply don't collect or store your health data in the first place — the strongest protection is having nothing to protect
- Access Control: Role-based access; minimal data exposure principle
- GPS Data: Zero-knowledge GPS — encrypted and never transmitted unencrypted
- Payment Security: Payments are not yet live on our platform. When enabled, payment processing will be handled by a licensed payment gateway under their security standards — no card details will ever be stored by BioAgesis directly
- Breach Response: We commit to notifying affected users promptly, in line with DPDP Act 2023 requirements
6. Data Sharing
We share your data ONLY in these limited circumstances:
- Your emergency contacts: Name and GPS location during active SOS only
- Registered hospitals (Guardian plan): GPS and basic health profile during active SOS — informational relay only
- Advisory doctors: Symptoms and concerns you share are relayed to your doctor at the time of consultation only — we do not keep a copy afterward
- Payment processors: Payments are not yet live. Once enabled, only transaction data will be shared with our licensed payment gateway — never health data
- Legal requirements: When required by court order or applicable law
We NEVER share data with: advertisers, data brokers, marketing companies, insurance companies, employers, government agencies (without court order), or any other third party.
7. Data Retention
| Data Type | Retention Period |
|---|
| Account data | Until account deletion + 30 days |
| Health/consultation data | Not retained — relayed to your doctor at the time of consultation, then discarded |
| SOS/Emergency logs | 90 days (security and anti-misuse), then deleted |
| Payment records | 7 years (legal/tax requirement) |
| Security logs | 12 months |
8. Your Rights
📋
Access
Request a copy of all data we hold about you
✏️
Rectify
Correct inaccurate personal data
🗑️
Delete
Request deletion of your data ("right to be forgotten")
📦
Portability
Receive your data in a machine-readable format
🚫
Object
Object to processing of your personal data
⏸️
Restrict
Restrict how we process your data
To exercise any right: email bioagesis.official@gmail.com. We respond within 30 days. Indian users may also contact the Data Protection Board of India (when operational).
9. Cookies & Tracking
Our website uses minimal, essential cookies only:
- Session cookies: Required for login and security
- Preference cookies: Remember your region and language settings
We do NOT use: advertising cookies, third-party tracking pixels, social media tracking, or behavioral profiling cookies. You may disable non-essential cookies in your browser settings.
10. International Data Transfers
BioAg€sis processes and stores account data primarily in India. We do not transfer health or consultation data internationally, since we do not store it at all. Any account data processed via cloud infrastructure follows DPDP Act 2023 cross-border transfer requirements.
11. Children's Privacy
BioAg€sis is not intended for users under 18. We do not knowingly collect data from minors. If a parent or guardian registers on behalf of a minor, the adult is the account holder and data controller for the minor's use. If you believe we have inadvertently collected a minor's data, contact bioagesis.official@gmail.com immediately.
12. Contact Our Privacy Team