Privacy Policy

Welcome to VitaLyfe, the online portal of Lupin Digital Health Limited (“Lupin Digital”, us” or “we”). The VitaLyfe (“Platform”) is owned and managed by Lupin Digital. The Platform is AI powered, and offers personalized healthy lifestyle management services at an agreed upon subscription fee to Users. The objective of the Platform is to provide the User a purely tech enabled, self-manageable, easily accessible platform, to control and manage their health and maintain a healthy lifestyle, in a positive and rewarding manner.

Lupin Digital is a Public Limited Company, incorporated and existing under the laws of India having its registered office at 3rd Floor, Kalpataru Inspire, Off Western Express Highway, Santacruz (East), Mumbai – 400055, India.

This policy describes our processes and procedures in relation to collection, transmission, storage, processing, disclosure, and protection of any and all data created, generated, collated, uploaded, disclosed, shared or otherwise provided on the Platform, including, but not limited to, personal data provided by you as a user while using the service (“Privacy Policy”).

A user shall mean any person who visits, uses, deals with and/or transacts on our Platform or mobile application (jointly and severally referred to as “you” or “Users” in this Privacy Policy).

For the purposes of this Privacy Policy: the ‘End-user’ is a User who is entitled to the subscribed services, downloads and uses the services offered on the Platform (“End-User”).

I. Privacy Policy

This Privacy Policy is published in compliance with Section 43A of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Information) Rules, 2011 (“SPDI Rules”) and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Digital Personal Data Protection Act 2023 and any of its rules, regulations and guidelines framed thereunder including any and all amendments made thereafter.. The Privacy Policy shall be subject to changes based on the Applicable laws as well as in case of changes in the Internal Policies of Lupin Digital.

This Privacy Policy provides information in connection with the following:

(i) The type of information collected from the Users, including personal information and SPDI (as defined below) relating to an individual;

(ii) The purpose, means and modes of collection, usage, processing, retention and destruction of such information; and

(iii) How and to whom Lupin Digital may disclose such information.

II. Collection of Personal Information

When you access the Platform or the application or avail the Services, you may provide, or we may collect certain information. We have set out below the types of information we may collect:

(i) Information provided by you: We receive and store any information you may enter on our Platform or provide us in any way. When you register for the Services on the Platform or the application, we collect registration details such as name, e-mail address, phone number. We also collect demographic data such as gender, date of birth and your pin code. We may also collect information required for providing you the Services such Personal Health Information (PHI), . You may choose not to provide certain information, but then you may consequently not be able to take advantage of the Services in their entirety. We may also collect sensitive personal data or information (“SPDI” ) when you use the Services. This information includes health information we receive from you, such as information in relation to your medical or health history, diagnostic results, medication details and any other information which may be inferred therefrom. We may also collect financial information. and payment information, and other information related thereto. We may also collect your review, opinion and feedback that you give about our Platform, products, programmes and services, your account membership number, registration and payment information, and program-specific information, when you request products and/or services directly from us, or participate in marketing programs. By using the Services, you consent to recording, storage, and disclosure of such information. We may retain such material for our records for the duration of you availing the Services and for such duration as may be mandated under the applicable law. We may also receive, store and/or process information about your location and your mobile device, including a unique identifier assigned to your device, usage, Internet Protocol (IP) address and similar information collected via automated means, such as cookies, pixels and similar technologies.

(ii) Information from other sources: We may receive information about you, from other sources including your employers, insurance company and, service providers and or from health platforms such as Google Fit and Apple Health, whose systems are integrated with our Platform, for obtaining End Users exercise data. For instance, We will be using:

-> https://www.googleapis.com/auth/fitness.activity.read, to track and monitor the number of steps taken to monitor adherence to fitness regimen

-> https://www.googleapis.com/auth/fitness.location.read, to track and monitor the distance walked

(iii) Tracking technologies and cookies: We may utilize cookies or other similar technologies. A cookie is a small text file which may be used to collect information about an activity on the Platform and/or the application. Most browsers or mobiles allow you to control cookies. Our use of such technologies allows us to improve our Platform, the mobile application and your experience.

No SPDI is automatically collected by the Platform from any casual visitors of this Platform and/ or the application, who are merely perusing the Platform. Nevertheless, certain provisions of this Privacy Policy are applicable to even such casual visitors, and such casual visitors are also required to read and understand the privacy statements set out herein, failing which they are required to leave this Platform and/or application immediately. If you, as a casual visitor, have inadvertently browsed any other page of this Platform prior to reading the privacy statements set out herein, and you do not agree with the way such information is obtained, collected, processed, stored, used, disclosed, or retained, merely quitting this browser application should ordinarily clear all temporary cookies installed by the platform. All visitors, however, are encouraged to use the “clear cookies” functionality of their browsers to ensure such clearing/deletion, as the Platform cannot guarantee, predict, or provide for the behaviour of the equipment of all the visitors of the Platform and/or application.

You agree that you are providing all information, including SPDI to us voluntarily. Collection, use and disclosure of personal information and SPDI requires your express consent.

You are providing us with your consent to our use, collection and disclose the personal information and SPDI. Should you choose to not provide us with personal information and SPDI, we may not be able to be able to provide to you the Services in its entirety.

III. Privacy Statement

(i) A condition of each User’s use of and access to the Services is their acceptance of the Terms of Use, which also involves acceptance of the terms of this Privacy Policy. Any User that does not agree with any provisions of the same has the option to discontinue using the Services.

(ii) You understand that the platform may use certain information of yours, which has been designated as personal information or SPDI under the SPDI Rules: (a) for the purpose of providing you the Services; (b) for communication purpose so as to provide you access to diagnostic service and sharing diagnostic reports; (c) debugging customer support related issues; (d) for commercial purposes and in an aggregated or non-personally identifiable form for research, statistical analysis and business intelligence purposes; (e) for sale or transfer of such research, statistical or intelligence data in an aggregated or non-personally identifiable form to third parties and affiliates; and

(iii) Lupin Digital also reserves the right to use information provided by the End-User for the following purposes: (a) providing the Users the varied Services offered on the Platform such as performing health risk assessment and providing the necessary education about the User’s current condition, booking diagnostic tests, providing personalized diet and exercise plans etc.(b) contacting Users for offering new products or services, or for procuring product or service feedback; (c) analysing software usage patterns for improving product design and utility; and (d) processing payment instructions including those through independent third party service providers such as payment gateways, banking and financial institutions, pre-paid instrument and wallet providers for processing of payment transaction or deferral of payment facilities.

(iv) You are responsible for maintaining the accuracy of the information you submit to us, such as your contact information provided as part of account registration. You may review, correct, update, change the information that you have provided by logging into your account. However, you are not permitted to delete any part of the personal information, or any other information generated on the application or request us to delete the same. If you provide any information that is untrue, inaccurate, out of date or incomplete (or becomes untrue, inaccurate, out of date or incomplete), or Lupin Digital has reasonable grounds to suspect that the information provided by thereof is untrue, inaccurate, out of date or incomplete, it may, at its sole discretion, discontinue the provision of the Services of the Platform for such Users. You may update your information at any point by writing to us at the details indicated at the end of the Privacy Policy. You will be responsible for any changes made to your data and Lupin Digital shall not be liable for any consequences because of such modifications made by you. We reserve the right to verify and authenticate your identity and your personal information to ensure accurate delivery of products and services. Access to or correction, updating or deletion of your personal information or SPDI may be denied or limited by us if it would violate another person’s rights and/or is not otherwise permitted by applicable law.

If you wish to close your account or request that we no longer use your information to provide you Services, contact us through customersupport@lupindigitalhealth.com We will retain your information for as long as your account is active and as needed to provide you the Services. We shall not retain such information for longer than is required for the purposes for which the information may lawfully be used or is otherwise required under any other law for the time being in force. After a period of time, your data may be anonymized and aggregated, and then may be held by us as long as necessary for us to provide our services effectively, but our use of the anonymized data for the purposes of analytics. Please note that your withdrawal of consent, or cancellation of account may result in Lupin Digital being unable to provide you with its Services or to terminate any existing relationship we may have with you. Notwithstanding the above, information of a User will be mandatorily retained for a period of One (1) year, post-withdrawal of consent from the use of information or cancellation of your account.

(v) Due to the communications standards on the Internet, when a User or the End-User or anyone who visits the Platform, Lupin Digital automatically receives the URL of the site from which anyone visits. Lupin Digital also receives the Internet Protocol (IP) address of each User’s computer (or the proxy server a User used to access the World Wide Web), User’s computer operating system and type of web browser the User is using, email patterns, as well as the name of User’s ISP. This information is used to analyse overall trends to help Lupin Digital improve its Service. The linkage between User’s IP address and User’s personally identifiable information is not shared with or disclosed to third parties. Notwithstanding the above, Lupin Digital may share and/or disclose some of the aggregate findings (not the specific data) in anonymized form (i.e., non-personally identifiable) with advertisers, sponsors, investors, strategic partners, and others in order to help grow its business.

(vi) If you decide to visit a third-party website linked to the Platform, you do this entirely at your own risk. Lupin Digital encourages the User to read the privacy policies of that website.

(vii) Lupin Digital maintains a strict “No-Spam” policy, which means that Lupin Digital does not intend to sell, rent or otherwise give your e-mail address to a third party without your consent.

(viii) Lupin Digital takes your right to privacy very seriously and other than as specifically stated in this Privacy Policy, we will only disclose your information in the event it is required to do so by law, including an enforcement agency, governmental official, legal authority or similar requirements or when Lupin Digital, in its sole discretion, deems it necessary in order to protect its rights or the rights of others, to prevent harm to persons or property, to fight fraud and credit risk, or to enforce or apply the Terms of Use.

Note:

(i) As part of the registration/application creation and submission process that is available to End-Users on this Platform and/or application, certain information, including personal information or SPDI is collected from the End-Users.

(ii) All the statements in this Privacy Policy apply to all End-Users, and all End-Users are therefore required to read and understand the privacy statements set out herein prior to submitting any personal information or SPDI to Lupin Digital, failing which they are required to leave the Platform and/or application immediately.

(iii) If you have inadvertently submitted any such information to Lupin Digital prior to reading the privacy statements set out herein, and you do not agree with the manner in which such information is collected, processed, stored, used, or disclosed, then you may access, modify and delete such information by using options provided on the Platform and/ or the application. In addition, you can, by sending an email to customersupport@lupindigitalhealth.com, inquire whether Lupin Digital is in possession of your personal data, and you may also require Lupin Digital to delete and destroy all such information.

(iv) End-Users’ personal information, which they choose to provide on the Platform is used to help the End-Users describe/identify themselves. Other information that does not personally identify the End-Users as an individual is collected by Lupin Digital from End-Users (such as, patterns of utilization described above) and is exclusively owned by Lupin Digital. Lupin Digital may also use such information in an aggregated or non-personally identifiable form for research, statistical analysis, and business intelligence purposes, and may sell or otherwise transfer such research, statistical, or intelligence data in an aggregated or non-personally identifiable form to third parties and affiliates. In particular, Lupin Digital reserves with it the right to use anonymized End-User demographics information and anonymized End-User health information for the following purposes: (a) analysing software usage patterns for improving product design and utility; (b) analysing such information for research and development of new technologies; (c) using analysis of such information in other commercial product offerings of Lupin Digital; (d) sharing analysis of such information with third parties for commercial use. We may use location information for internal analysis and to provide you with location-based services, such as advertising, search results, and other personalized content.

(v) Lupin Digital will communicate with the End-Users through email, phone and notices posted on the Platform or through other means available through the service, including text and other forms of messaging. The End-Users can change their e-mail and contact preferences at any time by logging into their account settings on the application.

(vi) Lupin Digital may also disclose or transfer End-Users’ personal and other information provided by a User, to a third party as part of reorganization or a sale of the assets of Lupin Digital. Any third party to which Lupin Digital transfers its assets will have the right to continue to use the personal and other information that End-Users provide to us, in accordance with the Terms and Conditions agreed and accepted for the sole purpose of ensuring continuity of subscribed service.

(vii) Data Transfer Abroad: Personal information may only be transferred by a relevant entity to any other entity in India or located in any other country, that ensures the same level of data protection that is adhered to by the relevant entity in India. Further, any disclosure to a third party would require prior permission of the provider of information unless it is necessary for the performance of a lawful contract between the body corporate and the provider of personal information.

(viii) To the extent necessary to provide End-Users with the Services, Lupin Digital may provide their personal information to third party contractors who work on behalf of or with Lupin Digital to provide End-Users with such Services, to help Lupin Digital communicate with End-Users or to maintain the Platform or independent third-party service providers to process payment instructions including providing a payment deferral facility to End-Users in relation to the Services. These third-party service providers have access to information needed to process payments but may not use it for other purposes. Generally, these contractors do not have any independent right to share this information, however certain contractors who provide services on the Platform, including the providers of online communications services, may use and disclose the personal information collected in connection with the provision of these Services in accordance with their own privacy policies. In such circumstances, you consent to us disclosing your personal information to contractors, solely for the intended purposes only.

(ix) You are not a casual visitor if you have willingly submitted any personal data or information to Lupin Digital through any means, including email, post, or through the registration process on the Platform. All such visitors will be deemed to be and will be treated as, Users for the purposes of this Privacy Policy, and in which case, all the statements in this Privacy Policy apply to such persons.

(x) The platform may also display content from a third-party website or service (e.g. social media plug-ins). We may process statistical data about your activity on our social media profiles. In this respect, when we have a social media profile, as well as when we place social media plug-ins (i.e. Plug-in, Like button or Pixel) on our Platform we are joint controllers of your data with the social media provider (e.g. Twitter, Facebook, Messenger) for the purpose of aggregate statistics of platforms. Aggregate statistics for the platforms are created on the basis of certain activities recorded by social media provider’s servers when users access our Platform and related content. Joint data controllership includes the creation of such activities and their aggregate analysis in the Platform’s statistics provided to us by social media providers.

(xi) We do not have access to your personal data processed as part of the activities; only aggregate statistics of the websites are available to us. We use this information, based on our legitimate interest, to learn how users use our Platform and related content, and based on this information to tailor content to users’ needs and interests, to optimize the performance of the Platform, and to promote our products or conduct other marketing activities. You can find the agreement defining the scope of co-management, including the principles of responsibility for the processing of your personal data by Facebook at: [insert link] by Twitter at [insert link], and by Messenger at [insert link].

IV. Confidentiality and Security

Lupin Digital takes all necessary precautions to protect your information, both online and off-line, and implements reasonable security practices and measures including certain managerial, technical, operational, and physical security control measures that are commensurate with respect to the information being collected and the nature of Lupin Digital’s business. However, for any data loss or theft due to unauthorized access to the User’s electronic devices through which the User avails the Services, Lupin Digital will not be held liable for any loss whatsoever incurred by the User.

If you suspect any unauthorized use of your account, you must immediately notify Lupin Digital by sending an email to customersupport@lupindigitalhealth.com.

You shall not host, display, upload, modify, publish, transmit, store, update or share any information that: (i) belongs to another person or is defamatory or invasive of another’s privacy ii) infringes any patent, trademark, copyright or other proprietary rights; iii) violates any law for the time being in force; iv) contains software virus (v) is patently false and untrue, and is written or published in any form, with the intent to mislead or harass a person, entity or agency for financial gain or to cause any injury to any person.

You shall be liable to indemnify Lupin Digital due to any loss suffered by it due to such unauthorized use of your account and password. In case we come across any user, who has manipulated with the any data stored on the Platform, then Lupin Digital reserves the Right to take appropriate action against such individual.

Lupin Digital makes all User information accessible to its employees, agents or partners, and third parties only on a need-to-know basis and binds only its employees to strict confidentiality obligations.

Part of the functionality of the Lupin is assisting the patients to access information relating to them. Lupin Digital may, therefore, retain and submit all such records to the relevant patients or to their doctors.

Notwithstanding the above, Lupin Digital is not responsible for the confidentiality, security, or distribution of your information by our partners and third parties outside the scope of our agreement with such partners and third parties. Further, Lupin Digital will not be responsible for any breach of security or for any actions of any third parties or events that are beyond the reasonable control of Lupin Digital including but not limited to, acts of government, computer hacking, unauthorised access to computer data and storage device, computer crashes, breach of security and encryption, poor quality of Internet service or telephone service of the User, etc.

V. Changes to Privacy Policy 

We may update this Privacy Policy at any time, with or without advance notice. In the event, there are significant changes in the way Lupin Digital treats User’s personally identifiable information, or in the Privacy Policy itself,

We will display a notice on the Platform or send an email, as provided, so that you may review the changed terms prior to continuing to use the Services. As always, if you object to any of the changes to our terms, and you no longer wish to use the Services, you may contact customersupport@lupindigitalhealth.com , to deactivate your account.

If a User uses the Services or accesses the Platform after a notice of changes has been sent to such User or published on the Platform, such User hereby provides his/her/its consent to the changed terms.

VI. Consent to this Policy

By using the Services or by otherwise giving us your information, you will be deemed to have read, understood, and agreed to the practices and policies set out in this Privacy Policy, and the Terms and Conditions of Use and agree to be bound by the covenants. You hereby consent to our collection, use and sharing, disclosure of your information as described in this Privacy Policy. You consent to transfer and use of your information to a third party for ensuring protection of your data received and or generated and collected on this platform, and if required as part of reorganization or a sale of the assets of Lupin Digital for the sole purpose of ensuring continuity of subscribed service.

VII Modifications

We reserve the right to amend or modify the terms of this Privacy Policy, at our sole discretion. If you do not agree with this Privacy Policy at any time, do not use any of the services or provide us any of your information.

VIII Miscellaneous 

Failure by Lupin Digital to exercise any right/ remedy available under the T&C applicable to you in your capacity as an End User and this Privacy Policy, shall not be construed as a waiver of such right or remedy

The Privacy Policy shall always be governed by Indian Laws and any dispute shall be subject to the exclusive jurisdiction of the Courts in Mumbai, India

Lupin Digital shall endeavour to provide complete services as available on the Platform or customized for the Subscriber but failure to provide any such service due to act of god such as fire, floods, acts of terrorism, weather, death, serious injury or other catastrophes, epidemics or quarantine restrictions, pandemics, lockdown imposed by the Government or any other local authority or other cause(s) beyond the reasonable control of Lupin Digital, not reasonably foreseeable, not caused by acts or omissions of Lupin Digital and shall not make Lupin Digital responsible or liable for such failure.

IX Grievances 

If you have any concerns or grievances, please contact the Grievance Centre, which contact details are given below.

The Grievance Centre will endeavour to resolve your grievances within fifteen (15) days from the date of receipt of such grievance.

All notices and communications or complaints of any kind may be addressed to the kind attention of the Grievance Centre/Officer at grievances@lupindigitalhealth.com.

If you wish to opt-out of receiving non-essential communications such as promotional and marketing-related information regarding the Services offered, kindly send an email at customersupport@lupindigitalhealth.com or contact the Grievance Centre/Officer for opting out of such service.