Effective date: 10 July 2026 · Governed under the Digital Personal Data Protection Act, 2023 (India)
Zadok Ventures India Pvt Ltd
No:83, 4th Cross, 4th Main, New Rajanna Layout, Horamavu Agra, Bangalore 560113, India
Email: enterprise@healthnessplus.com
Call: +91 88803 88804
WhatsApp: +91 96060 35491
For the purposes of the DPDP Act, 2023, roles are allocated as follows: the Client is the Data Fiduciary in respect of its employees' decision to be invited into the programme, it is the Client's responsibility to have a lawful basis (such as an employment-related notice or policy) for sharing employee contact details with us and inviting them to participate. Healthness+ acts as Data Fiduciary for the Health Risk Assessment (HRA) responses and related health data each employee submits directly to us, since that data is collected on the basis of the employee's own explicit consent at the point of assessment, independent of the Client's instruction.
We do not collect financial account details, government identity documents, or biometric data as part of the HRA.
| Source | Category | What we collect |
|---|---|---|
| From the Client | Corporate & roster data | Company details, authorised contact persons, and the employee roster (name, work email, department) provided to enable enrollment invitations |
| From employees, directly | Health data | HRA responses, lifestyle, nutritional, gut health, digestive, metabolic, and stress markers, plus any optional Food Intelligence photo submissions |
| Automatically | Usage data | Platform interaction logs, collected via server logs only, with no third-party advertising trackers |
This is the core commitment of the Enterprise product and is non-negotiable regardless of contract terms:
Employee personal data is processed solely to: generate the individual's HRA report and roadmap; enable medical review and coaching; populate aggregate, anonymised metrics on the Client's dashboard; and calculate programme billing based on anonymised risk-band distribution. We will not process employee data for any purpose beyond this without fresh consent from the employee.
Employee HRA responses and reports are retained for the duration of the Client engagement plus 3 years, after which they are permanently deleted unless a longer period is required by law. Roster data supplied by the Client that does not result in employee enrollment is deleted within 12 months of receipt. Anonymised, aggregated data with no personally identifiable information may be retained indefinitely for benchmarking and product improvement across Client engagements.
We do not sell, rent, or trade personal data. We may share it only in the following limited circumstances: with assigned coaches and our medical review team to deliver the service; with third-party sub-processors bound by data processing agreements; or when required by law or court order.
Third-party sub-processors we currently use:
| Provider | Purpose | Data Involved | Agreement |
|---|---|---|---|
| OpenRouter, Inc. (USA) | AI model routing layer that routes queries to downstream LLM providers on our behalf | Coaching queries passed through for routing; actual inference performed by the downstream provider | Data Processing Agreement (GDPR/CCPA). Current DPA covers general personal data; Sensitive Data (incl. health data) routed to downstream providers under their own DPAs. |
| OpenAI, L.L.C. (USA) Current AI inference provider |
Powers Freya clinical coaching assistant and blood work analysis | Health coaching queries; blood work data (only with explicit employee consent) | Data Processing Agreement. Data is not used for model training; deleted after inference. We may switch to any market LLM provider meeting these same criteria. |
| Razorpay Software Pvt Ltd (India) | Payment processing for Client invoices | Transaction amount, order reference; card/bank details handled directly by Razorpay | Razorpay Data Processing Agreement; PCI-DSS compliant |
| BigRock / Endurance International | Transactional email delivery (HRA reports, enrollment invitations, reminders) | Employee name, work email address, and report content | Standard SMTP provider terms |
Any cross-border transfer of personal data will only occur where permitted under the DPDP Act, 2023 and applicable rules, and will be disclosed to affected Clients in advance.
By providing an employee roster or inviting employees to enrol, the Client warrants that it has the lawful right to share the contact details provided and has given employees appropriate notice of the programme, consistent with its own internal HR and privacy policies. Healthness+ processes roster data on the good-faith basis of this warranty and is not responsible for verifying the Client's internal consent or notice practices before roster upload.
We implement appropriate technical and organisational measures, including TLS/HTTPS encryption in transit, role-scoped access controls (a Client's HR login can never see another Client's data or any individual employee's raw responses), and audit logging on sensitive health data access. In the event of a personal data breach likely to result in high risk to data principals' rights, we will notify affected parties and the Data Protection Board of India within 72 hours of becoming aware of it.
Every employee, as Data Principal for their own HRA data, retains the right to access, correct, or request erasure of their personal data, and to withdraw consent at any time, directly with Healthness+, independent of their employer. Exercising these rights does not require the Client's involvement or approval. Contact our Grievance Officer (Section 11) to action a request.
Personal data is hosted and processed within India. Any future cross-border transfer will only occur where permitted under the DPDP Act, 2023 and applicable rules, and will be disclosed to affected Clients and employees in advance.
Grievance Officer: Amrit
Zadok Ventures India Pvt Ltd
No:83, 4th Cross, 4th Main, New Rajanna Layout, Horamavu Agra, Bangalore 560113
Email: enterprise@healthnessplus.com
Call: +91 88803 88804
WhatsApp: +91 96060 35491
A complaint may also be lodged with the Data Protection Board of India if a grievance is not resolved to the complainant's satisfaction.
We may update this Privacy Policy to reflect changes in our practices or applicable law. Material changes affecting an active Client engagement will be communicated to the Client's authorised contact in advance of taking effect. The effective date above always reflects the latest version.