Privacy Policy

Privacy Policy
Last updated: April 22, 2024
Thank you for shopping at ilumina Health.
If, for any reason, You are not completely satisfied with a purchase We invite You to review
our policy on privacy. This Privacy Policy has been created with the
help of the Privacy Policy Generator.
The following terms are applicable for any products that You purchased with Us.

With effect from 01 April 2024

Welcome to Ilumina (“App/Platform”). This App/Platform and its suite of products and services is owned and operated by Ilumina Health Private Limited (“Company”/“We”/ “Us”),and ‘https://ilumina.health/’ (“Website”) having its registered office at <Insert Address> (hereinafter referred to as the “Company” or “us” or “we”, which expression shall mean and include its officers, successors and permitted assigns). The Company is engaged in the business providing a variety of services, through health coaches in the context of health and lifestyle modifications including human coaching support, structured content support, chatbot coaching support, medication reminders and other related services which may be specified by the Company from time to time (“Services”). The Services may be provided by the Company through the Platform, and its suite of products and services, as may be identified by the Company from time to time. This Privacy Policy (“Privacy Policy”) sets out the privacy practices of the Company with respect to the entire scope of Services provided by the Company.

This document is published in accordance with the provisions of Digital Personal Data Protection Act, 2023, Information Technology Act, 2000 and the rules made thereunder that require publishing the rules2011 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 made regulations, privacy policy and terms of use on an online portal of the Company. We request you to go through this Privacy Policy and the Terms of Use carefully before you decide to access this Platform.

For the purposes of this Privacy Policy, the words “us”, “we”, and “our” refer to the Company and all references to “you”, “your” or “user”, as applicable mean the person who accesses, uses and/or participates in the Platform in any manner or capacity.

The Company is strongly committed to protecting the privacy of its users and has taken all necessary and reasonable measures to protect the confidentiality of the user information and its transmission through the internet. The Company will not be held liable for disclosure of any information if such disclosure is in accordance with this Privacy Policy, the Terms of Use and/or applicable law. If you object to your information being transferred or used in accordance with this Privacy Policy, please do not use the Platform.

All capitalized terms used but not defined herein shall have the meaning ascribed to in the Terms of Use.

1. Information Collection

  1. You (i.e. the User) are the sole owner of your (i.e. User’s) information. The Company just collects your information through the Platform for providing the products and services you have signed up for. We will not sell, share, transfer or rent any personalOffice no 1001, 10th floor, Wave Silver Tower, Sector 18, Noida 201301 5 information to others in ways different from what is disclosed in this privacy policy and the Terms of Use.
  2. Purpose Limitation: We collect your personal data for specific, explicit, and legitimate purposes. We do not use your information for purposes beyond those stated without obtaining your consent.
  3. Relevance: We limit the collection of personal data to what is directly relevant and necessary for the intended purpose. We avoid collecting excessive or irrelevant information.
  4. The Company collects information from you on the Register/Log-in page of the Platform. In the sign-up page, you are required to give your personally identifiable contact information (such as name, mobile number, and email ID etc.). A verification process is used to confirm your identity through the contact information that you provide. When the Platform requests your identity, the Platform will clearly indicate the purpose of the inquiry before the information is requested.
  5. Once a registered participant, you have the option of providing additional personally identifiable, health and other information including but not limited to age, height, weight, occupation, name of your doctor, hospital or other healthcare provider, location, data relating to your diet, activity levels, exercise, medical reports (if any), medical history, mobile number, email ID, name of a primary caregiver, contact details of the primary caregiver and other personal information to avail of the Services provided through the Platform. Providing additional information beyond what is required at registration is entirely optional and can be altered or removed by you at any time. We assume that any information provided by you relating to a primary caregiver has been provided after obtaining due consent of such primary caregiver.
  6. Every computer/mobile device connected to the Internet is given a domain name and a set of numbers that serve as that computer&#39;s Internet Protocol or &quot;IP&quot; address. When you request a page from any page within the Company platform, our web servers automatically recognize your domain name and IP address. The domain name and IP address reveal nothing personal about you other than the IP address from which you have accessed the Platform.

2.Children's and Minor's Privacy

The Company strongly encourages parents and guardians to supervise the online activities of their minor children and consider using parental control tools available from online services and software manufacturers to help provide a child-friendly online environment. These tools also can prevent minors from disclosing their name, address, and other personally identifiable information online without parental permission. Although the Platform is not intended for use by minors, the Company respects the privacy of minors who may inadvertently use the internet or the Platform.

3. Data Retention

We establish clear retention periods for personal data. Once the data is no longer needed for the specified purpose, it is securely deleted or anonymized. Subject to the other terms contained in this Privacy Policy and the Terms of Use, your information will be retained with the Company until you specifically request the Company to destroy such information by way of a written request. The Company shall, upon receipt of such request from you, proceed to delete such information after carrying on internal verification procedures. Notwithstanding the foregoing, the Company will retain and use your information as necessary to comply with its legal obligations, resolve disputes, carry on audits, and enforce its agreements or for other business purposes. The data is stored on cloud servers (AWS) in India.

4. Opt-Out Procedures

Upon initial communication from the Company, you may opt-out of receiving further communications from the Company. To be completely removed from the Company subscription list, you may contact us at helpdesk@iiumina.health . If you are using an e-mail forwarding service or other similar service, please make sure to include the correct e-mail address or addresses.

5. Company as a Pass-Through Facilitator

The Company may be a pass-through facilitator for data under a contract with a client or partner (“Enterprise Client”). In such cases, the Company shall not be deemed to be the owner of such information. The Company may, as part of the agreement with such Enterprise Clients, use the information collected from such Enterprise Client to provide the relevant services to the user. The Company may continue to use the data for the purposes identified in this statement and the Terms of Use.

Please note however, that in respect of any information received by the Company under certain specific patient support program: (a) the Company shall retain identified data for a period of 5 (Five) years from the date of termination of such agreement, for performance of its contractual obligations, audits, diligence thereunder; and (b) the Company shall thereafter be permitted to retain only de-identified data for such period of time as may be necessary. The de-identified data at any point of time will be used for the purpose of compliance with applicable law, carrying on its contractual obligations, for carrying on audits and for improvement of its technology All personal identification data will be deleted after a period of 5 years from the date of termination of agreement.

Company may retain additional time point data related to you if there is a legal obligation to retain the data, if required to comply with any statutory or regulatory retention requirement by law.

6. Use of The Information Collected

6.1. Use Of the Information for Services

The primary goal of the Company in collecting the information is to provide you the Services as defined in the Terms of Use. The Company may use the personal and non-personal information provided by you, including but not limited to, the following ways:

a. Identify and reach you. b. Resolve technical issues of access to the Platform via telephone or email.
c. Provide you with further information, products, and services.
d. Better understand users’ needs and interests.
e. Personalize your experience and customizing experience.
f. Diagnosing and assisting you in your clinical, health and general wellbeing progress.
g. Run statistical research and undertake scientific publications.
h. Improving the product and services offered to current and future users and partners by improving parts of the Platform, including but not limited to the algorithms, logic systems, content, decision support, engineering.
i. Providing access to your information to healthcare practitioners and partners.
j. Providing data to clients or partners under the terms of agreement with them.
k. Providing access to your “User Profile” to other users of the Platform, Company administrators, Company moderators, Health Coaches and Primary Caregivers.
l. For carrying on audits, due diligence for effecting investments in the company.
m. Detect and protect us against error, fraud, and other criminal activity.
n. Make disclosures as may be required under applicable law.
o. Improve our Platform to better serve the user.
p. Allow us to better service the user in responding to customer service requests.
q. Administer a contest, promotion, survey, or other site feature; and
r. Provide access to other users as part of a social feed, to provide motivation or assistance to such other users.
s. Google Fit Data: When you connect your Google Fit account to the " Ilumina “App, we may access and collect the following data:
  • Health and fitness data, including activity, blood glucose, heart rate, sleep, and nutrition information.
  • Permissions you grant to access specific data types within Google Fit.

6.2 Disclosure to primary caregiver

a. Information collected from you may be transferred to your primary caregiver (as identified by you), as part of the Services.

b. The Company may, at its sole discretion, be entitled to contact the primary caregiver (as identified by you) at scheduled intervals and at unscheduled times and provide any information relating to you, as may be deemed beneficial or essential by the Company. The Company shall periodically update the primary caregiver relating to your health and progress based on the statistics available in the Platform, and any other relevant information that the Company believes is relevant to improve your health, clinical and Office no 1001, 10th floor, Wave Silver Tower, Sector 18, Noida 201301 8 general wellbeing outcomes. The Company may also reach out to the primary caregivers at unscheduled times upon occurrence of an Adverse Event, emergency event, or if you have not engaged with the Platform or your Health Coach for a long duration.

For the purposes of this Privacy Policy, the term “Adverse Event” shall refer to any adverse health consequences, or adverse medical events, that occur consequent to, or resulting out usage of any drug, medical device or as part of any therapy or consultation that the user is currently on or has been on.

6.3. Sale of Assets, Merger, Acquisition

The Company may share your information, including your information with our parent, subsidiaries, and affiliates for internal purposes. The Company also reserves the right to disclose and transfer all such information: (i) to a subsequent owner, co-owner or operator of the Platform, Website, or applicable database; or (ii) in connection with a corporate merger, consolidation, restructuring, the sale of substantially all our membership interests and/or assets or other corporate change, including, during any due diligence process. You will be notified via email and/or a prominent notice on our Platform and/ or Website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.

6.4. Cookies

Cookies are small pieces of information saved by your browser onto your computer/mobile. Cookies are used to record various aspects of your visit and assist the Company to provide you with uninterrupted Service. The Company does not use cookies to save personal information for unauthorized uses.

6.5. Ownership of work products

Any information provided by you through the Platform may be utilized by the Company for carrying on data analytics, derivatives, and other work products. The Company shall be deemed to be the sole owner of all such data analytics, derivatives, and work products, and may use all such data analytics, derivatives, and work products for each of the purposes identified in this Privacy Policy and the Terms of Use.

6.6. Non-disclosure of Information

Subject to the provisions of this Privacy Policy and the Terms of Use, the Company pledges that it will not sell or rent your personal details to anyone, and your personal information will be protected and maintained strictly confidential by the Company except in the following cases:

a. The Company may disclose your personal information in the event it is required to do so by law, rule, regulation, law, enforcement, governmental official, legal, or regulatory authorities and, or, to such other statutory bodies who have appropriate authorisation to access the same for any specific legal purposes.

b. The Company may disclose your information to provide you the Services, enforce or apply the Terms of Use, or to protect the rights, property or safety of the Company, its users, or others. This includes exchanging information with other companies / agencies that work for fraud prevention.

c. The Company may disclose your information to such third parties to whom it transfers its rights and duties under any agreement entered with such third parties; and

d. The Company may disclose your information to any of its affiliates or related entity.

6.7 Data Subject Rights

Ilumina Health Private Limited respects the data subject rights of our users and customers. We are committed to facilitating the exercise of these rights in accordance with applicable data protection laws. Below are the key data subject rights you may have and how you can exercise them:

Right to Access: You have the right to request access to the personal data we have collected about you.

Right to Rectification: If you believe that the personal data, we hold about you is inaccurate or incomplete, you may request corrections. To request rectifications, please contact our data protection officer.

Right to Erasure (Right to Be Forgotten): You have the right to request the deletion of your personal data, subject to legal exceptions. To request erasure, please contact our data protection officer.

Right to Data Portability: You may request a copy of your data in a commonly used, machine-readable format. To request a data copy, please contact our data protection officer. Right to Object: If you wish to object to the processing of your data for certain purposes, such as marketing, you can do so by contacting us at dpo@iiumina.health

Right to Restriction of Processing: You have the right to request the temporary suspension of processing your data under certain conditions. To request processing restrictions, please contact our data protection officer.

Right to Withdraw Consent: If we rely on your consent for data processing, you can withdraw your consent at any time. The withdrawal of consent will not affect the lawfulness of data processing before consent was withdrawn. To withdraw consent, please contact us at dpo@iiumina.health

Automated Decision-Making and Profiling: If we engage in automated decision-making processes or user profiling, you have the right to request human intervention or express your point of view. Please contact our data protection officer to exercise this right.

Right to Lodge a Complaint: If you believe your data rights have been violated, you have the right to lodge a complaint with a supervisory authority. Please contact grievance.redressal@iiumina.health

7. Sharing of Information

7.1 Sharing

The Company may share aggregated personal information with the Company's partners / clients as per the terms of any agreement with such partner / client. The data shared may be on an identified or deidentified basis, based on the terms agreed by the Company with such partner / client. Information available with the Company may be shared by the Company even after completion of the Services. The Company shall not be liable for the transfer of any personal identification information resulting from loss or distribution of data, the delineation or corruption of storage media, power failures, natural phenomena, riots, acts of vandalism, sabotage, terrorism, or any other event beyond the Company's control.

7.2. Consulting and Sub-Contracting

The Company may sub-contract all or part of the Services to a third-party sub-contractor, partner with another party to provide specific services. When you sign up for these services, the Company will share names, or other contact information that is necessary for the third party to provide these services. Per the Company's contractual arrangements with parties, these parties are not allowed to use personally identifiable information except for the explicit purpose of providing these services.

7.3. With Whom (Third Party) We are sharing your Personal Information

Third party services are not owned or controlled by Ilumina Health Private Limited, and third parties may have their own policies and practices for collection, use and sharing of information. Third parties include vendors and service providers we rely on for the provision of the Services. We share your Personal Information with selected third parties, including:
  • Cloud service providers who we rely on for compute and data storage, including Amazon Web Services, based in India. ‍
  • Platform support providers who help us manage and monitor the Services.
  • Data labelling service providers who provide annotation services and use the data we share to create training and evaluation data for Ilumina Health Private Limited product features.
  • Mobile advertising tracking providers who help us measure our advertising effectiveness.
  • Analytics providers who provide analytics, segmentation and mobile measurement services and help us understand our user base. We work with several analytics providers, including Google LLC, which is based in the U.S. You can learn about Google’s practices by going to https://www.google.com/policies/privacy/partners/, and opt-out of them by downloading the Google Analytics opt-out browser add-on, available at https://tools.google.com/dlpage/gaoptout.‍
  • Advertising Partners: We work with third party advertising partners to show you ads that we think may interest you. If you do not wish to receive personalized ads, please contact helpdesk@iiumina.health to learn about how you may opt out of receiving web-based personalized ads from member companies. You can access any settings offered by your mobile operating system to limit ad tracking, or you can install the AppChoices mobile app to learn more about how you may opt out of personalized ads in mobile apps.‍
  • Providers of integrated third-party programs, apps, or platforms, such as Google Calendar and Google fit. When you connect third party platforms to our Services, you authorize us to share designated information and data created and/or uploaded by you to our servers with these third-party programs on your behalf.
  • ‍Payment processors, these payment processors are responsible for the processing of your Personal Information and may use your Personal Information for their own purposes in accordance with their privacy policies.
If you choose to engage in public activities on the Sites, you should be aware that any information you share there can be read, collected, or used by other users of these areas. You should use caution in disclosing personal information while participating in these areas. We are not responsible for the information you choose to submit in these public areas. Note: Our Ilumina App not sharing any user data with any other third-party tools or AI models.

7.4. Ilumina App limited use policy for the integration with Google services

We have integrated the Ilumina App with services provided by Google to enhance your experience and provide valuable functionalities. Specifically:

(a) Sign-In with Gmail ID: You can conveniently sign in to the Ilumina App using your existing Gmail ID.

(b) Health Insights and Analysis: We use Google services to provide you with insights and in- depth analysis of your health data, delivering a comprehensive health and wellness experience.

In connection with this integration, it's essential to highlight our commitment to data protection and compliance:

Google APIs: Any data collected, stored, used, or transferred from Google APIs will consistently adhere to Google API Services User Data Policy, including its limited use requirements, ensuring that your information is handled responsibly and securely.

Google Health Connect: For data received through Google Health Connect/Google Fit, we remain dedicated to following the Health Connect Permissions Policy, which includes strict limited use requirements to safeguard your data and privacy.

8. Spam

The Company maintains a strict "No-Spam" policy, which means that the Company does not intend to sell, rent, or otherwise give your e-mail address to a third party without your consent.

9. Exclusion

The Company maintains a strict “No-Spam” policy, which means that the Company does not intend to sell, rent, or otherwise give your e-mail address to a third party without your consent.
  1. This Privacy Policy does not apply to any information other than information collected by the Company via any means, including the Platform, including such information collected in accordance with the clause on “Use of the Information Collected” above. This Privacy Policy will not apply to any unsolicited information provided by you through this Platform or through any other means. This includes, but is not limited to, information posted on any public areas of the Platform. All such unsolicited information shall be deemed to be non-confidential, and the Company will be free to use, disclose such unsolicited information without limitation.
  2. The Company also protects your personal information off-line other than as specifically mentioned in this Privacy Policy. Access to your personal information is limited to employees, agents, consultants, or partners and third parties, who the Company reasonably believes will need that information to enable the Company to provide Services to you. The Company will make best efforts to ensure that your personal contact information is protected. However, the Company is not responsible for the confidentiality, security, or distribution of your personal information by our partners and third parties outside the scope of our agreement with such partners and third parties.

10. The Company Forums

When you interact with our Platform or avail the Services, your comments, your name, your mobile number, and IP address may be recorded for purposes of maintaining your own account within the Platform. This information is not used to personally identify you outside the Company Platform and Services. To diffuse the information in the Company forum to a wider audience, the Company may, from time to time, collect some of your comments to use in a specific publication, print, electronic mailing, or other public dissemination. At no point however will your name, your mobile number or IP address be revealed without your consent. In addition, when your comments are used in this fashion, they may be edited to fit with the general content of the publication being prepared.

11. Protection of Information

11.1 Security of Information

The Company takes the security of your information very seriously. The Company protects your information from loss, misuse and unauthorized access, disclosure, alteration, and destruction by using microservices architecture. It is an architectural style that structures an application as a collection of loosely coupled services, which implement business capabilities. for e.g. having separate services for user profile related operations and user’s health details related operations, these services reside on different servers having their own databases. Data is encrypted using the SHA-256 algorithm on both the server and the device The Company has put in place appropriate methods and managerial procedures to safeguard and secure such information. It only processes personal information in a way that is compatible with and relevant for the purpose for which it was collected or authorized by the individual. The Platform allows users access to their personal information and allows them to correct, amend or delete inaccurate information.

a. The Company uses commercially reasonable precautions to preserve the integrity and security of your information against loss, theft, unauthorized access, disclosure, reproduction, use or amendment.

b. The information that is collected from you may be transferred to, stored, and processed at any destination within and / or outside India. By submitting information on the Platform, you agree to this transfer, storing and / or processing. The Company will take such steps as it considers reasonably necessary to ensure that your information is treated securely and in accordance with this Privacy Policy.

c. In using the Platform, you accept the inherent security implications of data transmission over the internet. Therefore, the use of the Platform will be at your own risk and the Company assumes no liability for any disclosure of information due to errors in transmission, unauthorized third-party access, or other acts of third parties, or acts or omissions beyond its reasonable control and you agree not to hold the Company responsible for any breach of security.

d. In the event the Company becomes aware of any breach of the security of your personal information, it will promptly notify you and take appropriate action to the best of its ability to remedy such a breach.

12. Confidentiality

The Company takes all necessary precautions to protect your personal information both online and off-line. No administrator at the Company will have knowledge of your password.

Other Links

The Platform may contain links to other sites, products, platforms, and services. These are not necessarily under the control of the Company. Please be aware that the Company is not responsible for the privacy practices of such other sites. The Company encourages you to read the privacy policies of each web site that collects personally identifiable information. If you decide to access any of the third-party sites linked to Platform, you do this entirely at your own risk. Any links to any partner of the Platform should be the responsibility of the linking party, and the Company shall not be responsible for notification of any change in name or location of any information on the Platform.

13. Notification of Changes

The Privacy Policy shall be subject to changes based on the Applicable laws as well as in case of changes in the Internal Policies of Ilumina. We may update this Privacy Policy at any time, with or without advance notice. In the event there are significant changes in the way we treat your personally identifiable information, or in the Privacy Policy document itself, we will display a notice on the on the Company website or send you a notification or update of the same through electronic means either within or outside the Platform, so that you may review the changed terms. As always, if you object to any of the changes to our terms, and you no longer wish to use the Platform, you may contact helpdesk@iiumina.health to deactivate your account. Unless stated otherwise, our current Privacy Policy applies to all information that the Company has about you and your account.

Using the Company Services or accessing the Platform after a notice of changes has been sent to you or published on our website shall constitute your consent to the changed terms.

14. Consent to This Policy

The Terms of Use Agreement is incorporated herein by reference in its entirety.

15. Grievance Officer

If you have any grievance with respect to the Platform or the Services, including any discrepancies and grievances with respect to processing of information, you can contact our Grievance Officer at:

E-mail: grievance.redressal@iiumina.health

The Grievance Officer shall redress your grievances expeditiously, within 1 (one) month from the date of receipt of grievance. Except where required by law, the Company cannot ensure a response to questions or comments regarding topics unrelated to this policy or the Company's privacy practices.

16. Contact person in data protection matters

If you have any questions regarding the processing of your personal data, please contact us via the following:

Data Protection Officer:

E-mail: dpo@iiumina.health

17. CONSENT

By consenting to the terms under this Privacy Policy, you hereby provide express consent to the Company to collect, share, transfer, store, retain, disseminate, or use the information collected by the Company from your usage of the Platform in accordance with the terms of the Privacy Policy. The Company will continue to retain information provided by you until you specifically request the Company to destroy such information. You may, at any time, withdraw consent for the collection or processing of any information provided by you, by sending an email to consent manager. Upon verification of such request, the Company may, subject to its obligations pursuant to law, destroy all information provided by you from its servers. However, please note that the Company shall continue to retain a copy of the information provided by you for the purpose of carrying out periodic audits. In such a case, the Company shall also instruct its partners/ clients to delete any copy of your information. However, the Company shall not have the obligation to validate or enforce any such deletion by the partner / client.

Consent Manager:
E-mail: helpdesk@iiumina.health
Contact Number: <Insert Contact Number>
You have read this privacy policy and agree to all the provisions contained above.

18. References

Scroll to Top