Effective Date:
[
2
nd
September
2022
]
Last Updated on: [
2
nd
September
2022
]
This privacy policy (“
Policy
”) explains how
HealthLane Technologies Pvt Ltd.
or any of its affiliates or subsidiaries. (“
We
”, “
Us
”, “
Our
”) Processes Personal Data collected from You.
-
DEFINITIONS
-
1.1
“Controller”
means the natural or legal person, public authority, agency, or other body which alone or jointly with others, determines the purposes and means of the processing of Personal Data.
-
1.2
“Customer Data”
shall have the meaning ascribed to it in the
MSA
.
-
1.3
“
End-User
” means any person or entity with whom the Subscriber interacts using the Services.
-
1.4
“Personal Data”
means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person, including SPDI.
-
1.5
“To Process/Processing”
means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
-
1.6
“SPDI”
means sensitive personal data or information of a natural person as defined in Rule 3 of the SPDI Rules.
-
1.7
“SPDI Rules”
means the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011.
-
1.8
“
Services
” shall have the meaning ascribed to it in the
MSA
.
-
1.9
“
Subscriber
” means the natural or legal person that has subscribed to the Services by entering into the MSA with Us.
-
1.10
“
MSA
” means the Master Subscr
iption Agreement entered into between You and Us for the provision of Services.
-
1.11
“
User
” shall have the meaning ascribed to it in the MSA.
-
1.12
“
Website(s)
” means the websites that
We
operate.
-
1.13
“
You
” and “
Your
” means an identified or identifiable natural person from whom we collect Personal Data as a Controller, as specified in Section 2 of this Policy.
-
PERSONAL
DATA COLLECTED BY US
-
2.1
You directly provide Us with most of the data We collect. We collect Personal Data from You directly as follows: a) When You subscribe for any of Our Services, We collect sign-up, account information including Your name, e-mail address, billing information, geographic location, phone number of the account administrator or information required for authentication of a User into Our Services; b) When You submit forms on Our Website(s) or as You use interactive features of the Website(s), including providing feedback or suggestions, testimonials, making requests, participation in surveys, contests promotions or sweepstakes, We collect Your feedback, name and e-mail address; c) When You attend an event conducted by Us, including webinars or seminars, We may collect Your contact information such as name, e-mail address, phone number, designation and company name; d) When You request customer support or otherwise communicate with Us, We collect Your name, Services usage information or any other Personal Data You may provide Us in the course of such interaction; e)
When You interact with Us on public forums, Our social media channels, Our community forums, or Our blogs, We collect the information You provide Us while interacting with Us and Personal Data such as Your name, location and any information You provide in Your bio while registering with such forums
; f) When You apply for a job with Us, whether through Our Website or otherwise, We collect Your Personal Data, including Your resume, in connection with Your job application; g) When You are a representative of Our business partners, suppliers or vendors, We collect Your name, e-mail and contact information
; (h) When You communicate with Us via a phone call, We may record such call. Where required by applicable law, We will get Your consent before We record such a call; (i) When You visit Our office, We collect
Your name, email address, phone number, company name and time and date of arrival
Additionally, due to the COVID-19 pandemic, We may collect information regarding Your health status, including Your temperature, COVID-19-related symptoms, exposure to COVID-19 positive individuals, and recent travel history.
-
2.2
We may also receive Your Personal Data indirectly as follows: a) from third party sources like marketing lists, databases and social media but only where We have checked that these third parties either have Your consent or are otherwise legally permitted or required to disclose Your Personal Data to Us; b) When You use the Services and/or Website(s), We automatically collect information on the type of device You use, browser information, IP Address and the operating system version, to perform Our agreement with You; c) When You use or view Our Website(s), information is collected via Your browser’s cookies as described in clause 10 herein; d) We may also collect or receive Your Personal Data from other sources such as Our business or channel partners through whom You create or access Your Account, publicly available sources, email add-ons and/ or through the combining of information We obtain from third parties along with the Personal Data You provide to Us.
-
2.3
The Website(s) includes social media features and widgets that are either hosted by a third-party or hosted directly on the Website(s) and Your interaction with these social media features and widgets is governed by the privacy statement of the companies that provide them. You should check Your privacy settings on these third-party services to understand and change the information sent to Us through these services.
-
LEGAL BASIS FOR PROCESSING
-
3.1
If You are a data subject from the European Economic Area, Our legal basis for collecting and using the Personal Data described above will depend on the Personal Data concerned and the specific context in which We collect it. We will normally collect Personal Data from You only where We need it to perform a contract with You, where the Processing is in Our legitimate interests and not overridden by Your data protection interests or fundamental rights and freedoms, or where We have Your consent. In some cases, We may also have a legal obligation to collect Personal Data from You. If We Process Personal Data with reliance on Your consent, You may withdraw Your consent at any time.
-
3.2
If You are a resident of India, We collect Your
Personal Data where We have Your consent as required under the SPDI Rules for the purposes mentioned in Clause 4. We shall, prior to collecting Your Personal Data, provide You the option to not provide Personal Data
to Us. Where You opt to not provide Personal Data to Us, We shall have the option to not provide the Services under the MSA for which the Personal Data is required.
-
3.3
If You have questions or need further information concerning the legal basis on which We collect and use Your Personal Data, please contact Us using the contact details provided under Clause
13.
-
PURPOSES FOR WHICH PERSONAL DATA WILL BE PROCESSED
We
Process Your Personal Data to:
a)
facilitate
Y
our access to the Website(s) and Services ;
b)
process and complete payment transactions;
c)
provide customer service and support;
d)
send
Y
ou communication on
Y
our use of the Services, updates on Our policies
;
e)
send
Y
ou communication on new features in the Services or new service offerin
gs; f) perform Our obligations or receive products/services in accordance with any contract that We may have with You or Your organization; g) Organis
e events or for other marketing/ promotional activities;
h)
investigate and prevent fraudulent transactions, unauthorized access to the Website(s) and Services, and other illegal activities;
i)
personalize the Website(s) and Services;
j) evaluate You for the job position that You have applied for or any position that We consider You suitable for, to ensure that We can make the best recruitment decisions, and k) for
other purposes for which
We
obtain
Y
our consent.
-
SHARING OF PERSONAL DATA
-
5.1
You acknowledge that
We
will share
Y
our Personal Data with
Our
group companies and third-party service providers so that they may offer
Y
ou
Our
Services and/or to send information or updates on the Services if
Y
ou are a Subscriber.
-
5.2
When
We
Process
Y
our order where
Y
ou are a Subscriber,
We
may send
Y
our Personal Data to and also use the resulting information from credit reference agencies to prevent fraudulent purchases.
-
5.3
We
share Personal Data with
Our
third-party service providers that host and maintain the
Our
Website(s), applications, backup, storage, payment processing, analytics and other services. These third-party service providers may have access to or Process
Y
our Personal Data for the purpose of providing these services
to
U
s.
-
5.4
We
may share
Y
our Personal Data with third-party providers who assist
U
s in marketing and promotions
in compliance with applicable laws
.
-
5.5
We
may be required to disclose
Y
our Personal Data in response to: a) lawful requests by public authorities, including to meet national security or law enforcement requirements
;
b) subpoenas, court orders, or legal process, and/or c) to establish or exercise
Our
legal rights or defend against legal claims.
-
5.6
We
may share Your Personal Data to assist investigation and prevention of illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of
the MSA, or as otherwise required by law.
-
5.7
We may also share Your Personal Data with an entity to which we divest all or a portion of our business, or otherwise in connection with a merger, consolidation, change in control, reorganization or liquidation of all or a portion of our business.
-
INTERNATIONAL TRANSFER
-
6.1
We mainly Process
Personal Data in India. However,
We
may transfer Personal Data outside
India
for the purposes referred to in Section 4.
We
will ensure that the recipient of
Your Personal Data offers an adequate level of protection that is at least comparable to that which is provided under applicable data protection laws.
-
6.2
If You are a resident of the European Economic Area and when Your Personal Data is Processed outside EEA, We will ensure that the recipient of Your Personal Data offers an adequate level of protection, for instance by entering into standard contractual clauses for the transfer of Personal Data as approved by the European Commission (Article 46 General Data Privacy Regulation, 2016), or We will ask You for Your prior consent to such international data transfers.
-
RETENTION OF PERSONAL DATA
-
7.1
We
retain the Personal Data collected where an ongoing legitimate business requires retention of such Personal Data.
-
7.2
In the absence of a need to retain Personal Data under Section 7.1. above,
We
will either delete it
or aggregate it,
or, if this is not possible then
We
will securely store
Y
our Personal Data and isolate it from any further Processing until deletion is possible. Customer Data shall be retained as specified in the
MSA
.
-
SECURITY OF PERSONAL DATA
We use appropriate technical and organizational measures to protect the Personal Data that We collect and Process. The measures We use are designed to provide a level of security appropriate to the risk of Processing Your Personal Data. If You have questions about the security of Your Personal Data, please contact Us immediately as described in this Policy.
-
YOUR RIGHTS
You are entitled to the following rights:
-
9.1
You can request Us for access and correction of Your Personal Data.
-
9.2
If We have collected and processed Your Personal Data with Your consent, then You can withdraw Your consent at any time by writing to Us at the details provided in Clause 13. Withdrawing Your consent will not affect the lawfulness of any Processing We have conducted prior to Your withdrawal, nor will it affect Processing of Your Personal Data conducted in reliance on lawful processing grounds other than consent.
-
9.3
You have the right to complain to a data protection authority about Our collection and use of Your Personal Data. For more information, please contact Your local data protection authority.
-
9.4
You have the right to opt-out of marketing communications We send You at any time. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing emails We send You. To opt-out of other forms of marketing (such as postal marketing or telemarketing), please contact Us.
-
9.5
If You are a resident of the EEA, UK, or Switzerland, You are also entitled to the following rights:
-
9.5.1
You can request Us for deletion and erasure of Your Personal Data.
-
9.5.2
You can object to the Processing of Your Personal Data, ask Us to restrict Processing of Your Personal Data or request portability of Your Personal Data.
-
9.6
If You seek to exercise Your rights under this clause, please contact Us at the details provided in clause 13. We will verify any requests before acting on the request and respond to all requests We receive from individuals wishing to exercise their data protection rights within a reasonable timeframe in accordance with applicable data protection laws.
-
COOKIE POLICY
-
10.1
Cookies are text files that are placed on Your computer to collect standard internet log information and visitor behaviour information by
Us
. When You visit the Website(s),
We
may collect Personal Data automatically from You through cookies or similar technology.
We also set cookies to collect information that is used either in aggregate form to help Us understand how Our Website(s) is being used or how effective Our marketing campaigns are, to help customise the Website(s) for You or to make advertising messages more relevant to You.
-
10.2
Essential Cookies
:
We
set essential cookies that enable core functionality such as security, network management, and accessibility. You may not opt-out of these cookies. However, You may disable these by changing
Y
our browser settings, but this may affect how the Website(s) functions.
-
10.3
Analytics, Customisation and Advertising Cookies
:
We
set these cookies to help
Us
improve
Our
Website(s) by collecting and reporting information on how
Y
ou use it. The cookies collect information in a way that does not directly identify anyone.
-
10.4
When You visit the Website(s), a cookie banner will be displayed providing additional information about cookies and options to opt out of non-essential cookies as required by applicable laws.
-
PRIVACY OF CHILDREN
-
11.1
We recognize the importance of children's safety and privacy. We do not request, or knowingly collect, any Personal Data from children under the age of 18. If a parent or guardian becomes aware that his or her child has provided Us with Personal Data, they should write to Us at the email address provided in clause 13.
-
NOTICE TO END-USER AND OTHER EXCLUSIONS
-
12.1
With the exception of Personal Data collected when a Subscriber registers for an account to access or use the Services and other information We collect in connection with the registration or authentication of Users into Our Services, this Policy does not apply in connection with access and use of the Services. The security and privacy practices, including how We protect, collect and use Customer Data are detailed in and governed by
the MSA
or such other applicable agreement between You and Us relating to Your access to and Your use of the Services.
-
12.2
Our Services are intended for use by enterprises.
Where the Services are made available to an End-User through a Subscriber, that enterprise is the Controller of the End-User’s Personal Data. In such a case, the End-User’s data privacy questions and requests should be submitted to the Subscriber in its capacity as the End-User’s Controller. If the End-User is an individual who interacts with a Subscriber using Our Services, the End-User will be directed to contact Our Subscriber for assistance with any requests or questions relating to their Personal Data. We are not responsible for Subscribers’ privacy or security practices which may be different from this notice. Subscribers to Our Services are solely responsible for establishing policies for and ensuring compliance with all applicable laws and regulations, as well as any and all privacy policies, agreements, or other obligations, relating to the collection of Personal Data in connection with the use of Our Services by End-Users.
-
12.3
Our Website(s) contain links to other websites. O
ur
Policy applies only to
Our
Website(s), so if You click on a link to another website, You should read their privacy policy.
We
encourage You to review the privacy statements of any such other websites to understand their Personal Data practices.
-
CONTACT INFORMATION
You may contact Our Grievance Redressal Officer if You have any enquiries or feedback on Our personal data protection policies and procedures, or if You wish to make any request, in the following manner:
Email Address: privacy@zelthy.com
-
CHANGES TO THE POLICY
We
keep this Policy under regular review and may update this webpage at any time. This Policy may be amended at any time and
Y
ou shall be notified only if there are material changes to this Policy.