← Back to Home
Legal Document

Privacy Policy

Version 3.0 · Effective: January 1, 2025 · Last Updated: June 2025

🔒 Our Privacy Promise to You

🚫We NEVER sell your health data to anyone, ever.
🚫We NEVER use your health data for advertising.
Your data is encrypted AES-256-GCM at all times.
You can delete all your data anytime by email.
We are GDPR & DPDP Act 2023 compliant.
Zero-knowledge GPS — location never sold.

1. Who We Are

BioAg€sis Technologies Pvt Ltd ("BioAg€sis," "we," "us") is the data controller for personal data collected through our platform. We operate globally and comply with applicable data protection laws in all jurisdictions where we operate.

Data Protection Officer: privacy@bioagesis.com

Company Address: BioAg€sis Technologies Pvt Ltd, India (registration pending)

2. What Data We Collect

Data TypeWhat We CollectWhy
Account DataName, email, phone number, password (hashed)Account creation and authentication
Health DataSymptoms described, AI report results, age, genderProviding medical advisory service
Emergency DataEmergency contacts, GPS location (during SOS)SOS notification and emergency response
Device DataDevice ID, OS version, app versionSecurity, anti-misuse enforcement, bug fixing
Payment DataPayment reference IDs only (no card numbers stored)Payment processing via Razorpay/Stripe
Usage DataFeatures used, session timestampsPlatform improvement and security

We do NOT collect: government ID numbers, financial account details, biometric data beyond what you voluntarily provide, or any data not listed above.

3. How We Use Your Data

We NEVER use your health data for advertising, marketing profiling, or selling to third parties. This is an absolute rule with no exceptions.

4. Legal Basis for Processing

5. Data Security

6. Data Sharing

We share your data ONLY in these limited circumstances:

We NEVER share data with: advertisers, data brokers, marketing companies, insurance companies, employers, government agencies (without court order), or any other third party.

7. Data Retention

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Health/AI report data12 months from creation, then auto-deleted
SOS/Emergency logs90 days (security and anti-misuse), then deleted
Payment records7 years (legal/tax requirement)
Security logs12 months

8. Your Rights

📋
Access
Request a copy of all data we hold about you
✏️
Rectify
Correct inaccurate personal data
🗑️
Delete
Request deletion of your data ("right to be forgotten")
📦
Portability
Receive your data in a machine-readable format
🚫
Object
Object to processing of your personal data
⏸️
Restrict
Restrict how we process your data

To exercise any right: email privacy@bioagesis.com. We respond within 30 days. EU users may also contact their national Data Protection Authority. Indian users may contact the Data Protection Board of India (when operational).

9. Cookies & Tracking

Our website uses minimal, essential cookies only:

We do NOT use: advertising cookies, third-party tracking pixels, social media tracking, or behavioral profiling cookies. You may disable non-essential cookies in your browser settings.

10. International Data Transfers

BioAg€sis processes data in India and may use cloud infrastructure in other regions. All international transfers comply with GDPR Chapter V requirements (Standard Contractual Clauses where applicable) and DPDP Act 2023 cross-border transfer provisions.

11. Children's Privacy

BioAg€sis is not intended for users under 18. We do not knowingly collect data from minors. If a parent or guardian registers on behalf of a minor, the adult is the account holder and data controller for the minor's use. If you believe we have inadvertently collected a minor's data, contact privacy@bioagesis.com immediately.

12. Contact Our Privacy Team

PRIVACY OFFICER
Data requests, deletion, GDPR/DPDP queries
DATA PROTECTION
EU GDPR — Data Protection Officer
SECURITY
Security concerns, breach reporting
COMPLIANCE
Legal and regulatory inquiries