Privacy Policy
Last updated: 2026-08-03 · Effective date: 2026-08-03
Prepared with reference to the Digital Personal Data Protection Act, 2023 (India)
2.1 Who We Are
This Privacy Policy is issued by Eleviora Tech Innovations LLP ("VeltFit"), the Data Fiduciary in respect of personal data processed through the Platform, in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and its associated rules.
2.2 Categories of Personal Data We Collect
Identity data — Name, date of birth, gender, profile photo. Collected from: you, at registration.
Contact data — Phone number, email address, address (for corporate wellness). Collected from: you, at registration.
Health Risk Assessment data — Fitness goals, activity level, allergies, medical conditions, physical limitations, target weight, dietary preferences. Collected from: you, voluntarily, via the app.
Clinical data — Physiotherapy assessment notes, treatment history, pain-point diagrams. Collected from: Partner clinical staff, during a booked session.
Fitness tracking data — Workout logs, meal logs, steps, sleep, water intake, weight history. Collected from: you, via app logging, or connected device sync.
Location data — Approximate location (with consent), gym check-in location. Collected from: your device, with your permission.
Biometric-adjacent data — Entry check-in photograph; where enabled by a Gym, biometric enrollment data. Collected from: device camera / Gym biometric hardware, at check-in.
Financial data — Transaction history, payment method type (not full card/UPI details). Collected from: Razorpay (processor), on your instruction.
Device & usage data — App usage analytics, push notification token, crash logs. Collected automatically, via the app.
2.3 Purpose & Legal Basis for Processing
Under the DPDP Act, VeltFit processes your personal data on the basis of your explicit, informed consent (obtained at registration and at each point sensitive data is collected), and, for limited categories, on the basis of "legitimate uses" recognized under the Act (e.g., fraud prevention, or compliance with a legal obligation such as tax record-keeping).
Personalizing AI-generated plans (Vayu) — uses Health Risk Assessment data and fitness tracking data. Legal basis: Consent.
Facilitating bookings & payments — uses identity, contact, and financial data. Legal basis: Consent / contract performance.
Gym attendance & access control — uses QR code, entry photograph, and biometric data (where enabled). Legal basis: Consent.
Delivering clinical physiotherapy services — uses clinical data, shared with the specific booked Partner only. Legal basis: Consent.
Fraud prevention & platform security — uses device data and usage patterns. Legal basis: Legitimate use.
Tax & regulatory compliance — uses financial/transaction data. Legal basis: Legal obligation.
Marketing communications — uses contact data. Legal basis: Consent (opt-in, revocable at any time).
2.4 Automated Decision-Making Disclosure
Vayu, VeltFit's AI assistant, uses artificial intelligence to generate suggested workout and diet plans based on the data described above. This is an automated process. VeltFit takes reasonable steps to configure Vayu to account for declared allergies and medical conditions, but the output is generated by an AI system and may not be complete or error-free. You are entitled to have a human (e.g., a Coach, Nutritionist, or Physiotherapist you separately engage) review any AI-generated plan, and you should exercise your own judgment before following one. See the Disclaimer for further limitations.
2.5 How We Share Your Data
The specific Gym/Partner/Coach you book with — receives your name, contact, relevant health data, and booking details, to deliver the booked service.
Razorpay Software Pvt. Ltd. — receives payment amount and transaction reference (not full card/UPI credentials), for payment processing.
Cloudinary Inc. — receives uploaded images (profile photos, entry photos, KYC documents), for secure media storage.
Anthropic (Claude API) / Google (Gemini API) — receives health/fitness data you provide to Vayu, for the duration of generating a response, for AI plan generation.
Google / Expo push notification services — receives your device push token, for delivering notifications.
Law enforcement / regulators — as legally compelled, for legal compliance.
VeltFit does not sell your personal data to any third party for their own independent marketing purposes.
2.6 Cross-Border Data Transfer
Some of our processing sub-contractors (including certain AI and cloud infrastructure providers referenced above) may process data on servers located outside India. [PLACEHOLDER — the DPDP Act empowers the Central Government to restrict transfers to specific countries via notification; confirm current restricted-country list and appropriate contractual safeguards with counsel before publishing.]
2.7 Data Retention
Active account data — retained for as long as your account remains active.
Health Risk Assessment & fitness tracking data — deleted entirely upon account deletion.
Clinical assessment records (Partner-held) — anonymized (clinical content removed, service-rendered record retained) upon account deletion, for continuity-of-care/liability-defense purposes.
Financial/transaction records — [PLACEHOLDER — per Indian tax law, typically 6-8 years]
Entry check-in photographs — [PLACEHOLDER — recommend a defined short retention window, e.g. 90 days, rather than indefinite retention]
2.8 Your Rights as a Data Principal
Under the DPDP Act, 2023, you have the right to:
Obtain a summary of the personal data VeltFit holds about you and the processing activities undertaken (available via the in-app "Download My Data" feature).
Request correction, completion, or updating of your personal data.
Request erasure of your personal data, which VeltFit will honor except where retention is required by law (see Section 2.7).
Withdraw consent for any consent-based processing at any time, with the same ease with which consent was given, without affecting the lawfulness of processing carried out before withdrawal.
Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
Register a grievance with VeltFit's Grievance Officer (below), and if unresolved within the statutory timeline, escalate to the Data Protection Board of India.
2.9 Data Security
VeltFit implements technical and organizational safeguards including encrypted data transmission, role-based access controls, authentication and rate-limiting on all account-access endpoints, and regular security review. A comprehensive internal security audit was conducted prior to public launch; see VeltFit's internal security documentation for details. No system is completely secure, and VeltFit cannot guarantee absolute security.
2.10 Data Breach Notification
In the event of a personal data breach that is likely to result in harm to affected Data Principals, VeltFit will notify the Data Protection Board of India and affected users as required under the DPDP Act and its rules. [PLACEHOLDER — confirm specific notification timelines once the DPDP Rules' breach-notification provisions are finalized/in force.]
2.11 Children's Data
The Platform is not intended for independent use by individuals under 18. Where a Member between 13-17 uses the Platform under a parent/guardian's account per Section 1.4 of the Terms of Service, VeltFit relies on that parent/guardian's verifiable consent for processing of the minor's data, and does not knowingly conduct behavioral tracking or targeted advertising directed at users it has identified as minors.
2.12 Grievance Officer
[NAME], Eleviora Tech Innovations LLP, [REGISTERED ADDRESS]. Email: [GRIEVANCE EMAIL ADDRESS]. — Placeholder: a real, designated Grievance Officer and contact details must be appointed and inserted here before publishing, per DPDP Act requirements.
