Kairova Wellness Private Limited

Data Privacy Policy

How Valyova collects, uses, stores, shares and protects your personal data across the Membership and every clinical, consumer and support touchpoint that forms part of the Protocol.

Framework
DPDP Act, 2023 · DPDP Rules, 2025
Governing law
India · Courts at Mumbai
Grievance Officer
Akash Banerji
Contents

1. Introduction and Scope

This Data Privacy Policy (“Policy”) explains how Kairova Wellness Private Limited (CIN: U46497MH2026PTC471272), operating under the consumer brand “Valyova” and the website valyova.com (together, “Valyova”, “we”, “us” or “our”), collects, uses, stores, shares and protects Personal Data in connection with the Membership and all related consumer, clinical and support touchpoints.

This Policy is framed to comply with the Digital Personal Data Protection Act, 2023 (“the Act”) and the Digital Personal Data Protection Rules, 2025 (“the Rules”), and applies to every individual who visits valyova.com, registers interest, completes the pre-purchase safety gating questionnaire, purchases a Membership, or otherwise shares Personal Data with us through our website, checkout flow, the Concierge, or any physician, diagnostic or support process forming part of the Protocol (each, a “Data Principal”, “you” or “your”).

This Policy should be read together with the separate consent notice document issued from time to time alongside it, which contains the itemized notice presented to you at each specific point where we ask for your consent (“Consent Notice(s)”). Where this Policy and a specific Consent Notice in that document address the same processing, that Consent Notice governs for the specific touchpoint it covers, and this Policy provides the overarching framework.

2. Definitions

“Act”
means the Digital Personal Data Protection Act, 2023.
“Rules”
means the Digital Personal Data Protection Rules, 2025.
“Board”
means the Data Protection Board of India established under section 18 of the Act.
“Data Fiduciary”
means Valyova, which determines the purpose and means of Processing of your Personal Data.
“Data Principal”
means the individual to whom the Personal Data relates, i.e. you.
“Data Processor”
means any person who processes Personal Data on Valyova’s behalf.
“Personal Data”
means any data about an individual who is identifiable by or in relation to such data.
“Processing”
means any operation performed on Personal Data, including collection, storage, use, sharing and erasure.
“Policy”
means this Data Privacy Policy.
“Membership”
means your paid subscription to the Protocol.
“Protocol”
means the physician-supervised Valyova Protocol delivered as part of the Membership, including the VPD, biomarker testing, physician triage, the AM/PM product regimen, and weekly check-ins.
“VPD”
means the Vitality Performance Dossier, the structured intake described at clause 4.
“Concierge”
means the WhatsApp-based member support channel operated by Valyova.
“Physician”
means the independent, registered medical practitioner engaged by Valyova to conduct physician triage and clearance under the Protocol.
“Diagnostics Partner”
means the third-party diagnostics provider engaged by Valyova to collect and process biomarker samples and results.
“Technology Partner”
means the third-party technology provider engaged by Valyova to design, host and maintain the central member database.
“Payment Aggregator”
means the independent payment aggregator, regulated by the Reserve Bank of India (“RBI”), engaged to process checkout payments on Valyova’s behalf.
“Diagnostic ID”
means the anonymous identifier generated to route your VPD and biomarker data to the Physician without revealing your name or contact details.
“Grievance Officer”
means the individual designated by Valyova to receive and address grievances under clause 15.
“IEC”
means an Institutional Ethics Committee.
“Study”
means the IEC-approved observational research study referred to under clause 17.
“Principal Investigator”
means the independent researcher supervising the Study.
“Consent Manager”
means a person registered with the Board under Rule 4 of the Rules to enable a Data Principal to give, manage, review and withdraw consent through an interoperable platform.
“Significant Data Fiduciary”
means a Data Fiduciary notified as such by the Central Government under section 10 of the Act.

Terms used but not defined in this Policy have the meaning given to them in the Act and the Rules.

3. Who We Are

Valyova is the Data Fiduciary in respect of the Personal Data described in this Policy. Our registered office is at 1st Floor, 104, T-6 Emerald Isle, Saki Vihar Road, Mumbai, Maharashtra, 400072, India. You can contact us using the Grievance Officer details in clause 15 for any question about how your Personal Data is processed.

4. Personal Data We Collect

We collect different categories of Personal Data for different purposes across your journey with Valyova. The table below sets these out.

Purpose Personal Data Collected Nature
Registering interest / creating an account Name, mobile number, email (where provided), age or age-bracket, plan of interest Identity / contact data
Pre-purchase safety screening Your yes/no responses to screening questions about specified medical conditions Health-adjacent screening data
Payment and checkout Plan selected, transaction reference and billing details required by the Payment Aggregator. Full card, UPI or bank credentials are captured and processed directly by the Payment Aggregator; Valyova does not receive or store these credentials Transaction data
Health and lifestyle assessment (VPD) Health history, current symptoms, current medications, lifestyle factors, and your Self-Assessment scores (energy, stress, sleep, cognition, physical capacity) Health data
Biomarker testing Day 0 and Day 90 blood panel results (including cortisol, testosterone, hsCRP, HOMA-IR, lipid panel and Vitamin D) Health data
Physician triage and prescription Your triage tier outcome, the Physician’s clinical notes and recommendations, and any prescription issued in your name Health data
Concierge support Your WhatsApp number, message content and chat transcripts, onboarding and scheduling responses Communications data
Weekly wellbeing check-ins Your weekly responses on sleep, energy, stress and dosing compliance, and any free-text notes (including discomfort or adverse-event flags) Health-adjacent data
Clinical review routing Your Diagnostic ID and age bracket Pseudonymised identifier
Customer support and grievance redressal Your contact details, correspondence, complaint details, and records of prior interactions Contact / communications data
Marketing communications (offers, new launches, festive discounts) via SMS/WhatsApp/Email/push notification Your contact details, communication preferences, and engagement history (e.g. opens/clicks) Contact / marketing preference data
Personalisation, on-site recommendations and analytics cookies Your browsing behaviour on our website/app, device and cookie identifiers, and usage patterns Technical / usage data
Loyalty / rewards programme Your loyalty/rewards account details, points balance, redemption history, and referral information Account / transactional data

5. Why We Process Your Personal Data, and Our Legal Basis

In addition to the specific purposes below, we process your Personal Data generally to provide, operate, maintain and improve the services offered by Valyova (including the Membership and the Protocol). Our primary basis for processing your Personal Data is your consent under section 6 of the Act, given in response to the Consent Notice(s), for the following specified purposes:

  • Determining whether you may safely proceed to purchase, or should be routed to concierge review, through the pre-purchase safety gate;
  • Enabling the Physician’s triage and clearance decision before your first sachet ships;
  • Delivering, and supervising your use of, the Protocol across your Membership;
  • Establishing your Day 0 biomarker baseline and measuring change at Day 90;
  • Operating weekly compliance and wellbeing check-ins, including routing discomfort or adverse-event flags for review;
  • Delivering Concierge support, reminders and (where applicable) prescription delivery over WhatsApp;
  • Processing your payment for the Membership;
  • Responding to your customer support queries and grievances;
  • Sending you marketing communications about offers, new launches and discounts, where you have separately consented;
  • Personalising your experience and generating on-site recommendations, and for website/app analytics, where you have consented to non-essential cookies (see clause 18);
  • Operating any loyalty or rewards programme you choose to join; and
  • Where you have separately and explicitly consented, using de-identified data for research, product improvement and statistical purposes.

In addition, and only to the limited extent permitted by section 7(f) of the Act, we may process relevant health data without further consent where necessary to respond to a medical emergency involving a threat to your life or an immediate threat to your health; for example, where a discomfort or adverse-event flag indicates an urgent safety concern. This is a narrow backstop and does not replace our consent-based processing architecture generally.

6. Anonymization and Privacy by Design

Your VPD and biomarker data are stored against your Diagnostic ID. When the Physician reviews your case for physician triage, they see only this Diagnostic ID and your age bracket and not your name, phone number or other identifying details. This anonymization statement is presented to you before, and separately from, the consent checkbox in the VPD flow, so that you understand how your data is protected before you are asked to consent to its processing.

7. Consent: How It Works and How to Withdraw It

Each consent we ask for is free, specific, informed, unconditional and unambiguous, and requires clear affirmative action on your part through the Consent Notice. You may access each Consent Notice in English; Refer to clause 19 for other language options.

You may withdraw your consent at any time, with the same ease with which you gave it, by contacting the Grievance Officer or through the Concierge. Refer to clause 8 for the consequences of not consenting or withdrawing your consent.

We do not currently route consent through a Consent Manager; your consent is given to, and managed directly by, Valyova.

8. Consequences of Not Consenting or Withdrawing Consent

Some processing of your Personal Data is necessary for us to provide you the Membership and the Protocol safely, for example, the pre-purchase safety screening, the VPD, biomarker testing and physician triage. If you do not consent to this processing, or later withdraw your consent, we may be unable to allow you to purchase, continue, or safely supervise your Membership, and it may be paused, deferred or discontinued as a result.

Other processing is optional and not a condition of receiving the Protocol, for example, the separate research-use consent, marketing communications, personalisation/analytics cookies, and the loyalty/rewards program. If you do not consent to this optional processing, or withdraw your consent later, you can still purchase and use the Membership; we will simply stop that optional processing.

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and you remain responsible for any consequence of withdrawal as described above, consistent with section 6 of the Act.

9. Sharing of Personal Data

We share Personal Data only as necessary to deliver the Protocol and our other services, and never in order to sell it. The table below sets out who we share Personal Data with, described by role rather than by name.

Recipient Role Data Shared Purpose
Physician Independent registered medical practitioner engaged by us VPD and biomarker data via Diagnostic ID and age bracket Triage, clearance and prescription
Diagnostics Partner Data Processor Contact/address for sample collection; biomarker results Biomarker testing
Technology Partner Data Processor (infrastructure) The central member database in its entirety Data architecture, hosting and storage
Payment Aggregator Independent, RBI-regulated payment aggregator Payment and transaction data Checkout processing
Communications platform provider Communications infrastructure provider Your phone number and messages Delivering the Concierge experience over WhatsApp
Cloud hosting provider Infrastructure host (India-based data centre) The central member database Underlying cloud hosting
Marketing service providers Data Processor, where engaged Contact details and communication preferences Sending marketing communications
Analytics service providers Data Processor, where engaged Website/app usage and cookie data Personalisation, on-site recommendations and analytics
Government / regulators As required by law As lawfully required Compliance with applicable law

10. Storage Location and Cross-Border Transfer

Our central member database is hosted with a cloud hosting provider based in India. Under section 16 of the Act, Personal Data may generally be transferred outside India unless the Central Government has specifically restricted transfer to a notified country or territory; as of the date of this Policy, no such restriction affects our processors. To the extent a processor engaged by us processes data on servers outside India as part of its own global infrastructure, this is incidental to providing that service and is governed by that processor’s own data-processing terms. We will update this clause if the Central Government issues any country-specific restriction under section 16 of the Act.

11. Data Retention

We retain Personal Data only for as long as necessary for the purpose for which it was collected, or as required by law. Separately, and regardless of the above, we retain Personal Data and associated processing logs for a minimum of one year from the date of processing, in line with Rule 8(3) of the Rules.

Indicative retention periods are set out below. These are placeholders pending confirmation from Valyova’s clinical, regulatory and finance advisors, and should not be treated as final.

Category Indicative Period
Account / enquiry data 3 years after last interaction
VPD, biomarker and physician/prescription data 3 years after last interaction, after which the data is deleted except for where the Member has given separate research consent, transitioned to de-identified/anonymised form for research retention
Weekly check-in data Membership + 1 year, longer if a discomfort/adverse-event flag was raised
Payment / transaction records In accordance with timelines prescribed under Companies Act, 2013
WhatsApp/Concierge chat logs Membership + 1 year
Marketing communication preferences & engagement data Until consent is withdrawn, or 2 years of member inactivity, whichever is earlier
All categories (floor) Minimum 1 year from date of processing

12. Security Safeguards

We take reasonable security safeguards to protect Personal Data in our possession or control, including data processed on our behalf by the Diagnostics Partner and Technology Partner, in line with Rule 6 of the Rules. These include, at a minimum:

  • Encryption and access controls over Personal Data, including the Diagnostic ID architecture that limits the Physician’s access to identifiable member data;
  • Logging, monitoring and review to detect and investigate unauthorised access;
  • Data back-up and business continuity measures;
  • Contractual security obligations imposed on the Diagnostics Partner, Technology Partner and our other processors; and
  • Organisational measures, including confidentiality obligations on our personnel.

13. Personal Data Breach

If we become aware of a Personal Data breach, we will, without delay, inform you through your registered WhatsApp number or other communication channel, describing the nature and extent of the breach, its likely consequences for you, the steps we have taken or are taking to mitigate it, safety measures you may wish to take, and contact details of a person who can answer your questions. We will also notify the Board without delay, and provide the Board with further prescribed details within seventy-two hours of becoming aware of the breach, in line with Rule 7 of the Rules.

14. Your Rights as a Data Principal

Subject to the Act and the Rules, you have the right to:

  • Obtain a summary of the Personal Data we process about you and our processing activities, and the identities of other fiduciaries and processors we have shared it with;
  • Request correction, completion, updating or erasure of your Personal Data;
  • Have your grievances redressed; and
  • Nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, contact the Grievance Officer using the details at clause 15. We will respond within a reasonable period not exceeding 90 (ninety) days, in line with Rule 14(3) of the Rules.

15. Grievance Redressal Mechanism

If you have a grievance regarding our processing of your Personal Data, you may write to our Grievance Officer at:

Name
Akash Banerji
Email
hello@valyova.com
Contact number
9820382537

We follow this process to redress your grievance:

  • Submission: you may submit your grievance in writing, by email or WhatsApp, to the Grievance Officer, describing the issue and the Personal Data concerned.
  • Acknowledgement: we will acknowledge receipt of your grievance within 48 (forty-eight) hours.
  • Resolution: we will investigate and respond to your grievance within a reasonable period not exceeding 90 (ninety) days from the date of receipt, in line with Rule 14(3) of the Rules.
  • Escalation: if you are not satisfied with our response, or do not receive a response within this period, you may approach the Board. You must exhaust this grievance redressal process before approaching the Board, in line with section 13(3) of the Act.

16. Children and Persons with Disability

Membership and the Protocol are intended only for individuals who are 18 years of age or older. We do not knowingly process the Personal Data of a child (an individual who has not completed 18 years), and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children, in line with section 9 of the Act. If we become aware that a Data Principal is a child and that verifiable parental consent was not obtained in accordance with Rule 10 of the Rules, we will delete the relevant Personal Data or bring our processing into compliance without delay.

Where a Data Principal is a person with disability who has a lawful guardian, we will obtain verifiable consent from that guardian only after observing due diligence to verify the guardian’s appointment, in line with Rule 11 of the Rules.

17. Research Use and the Clinical Study

We distinguish between two separate uses of data that might loosely be called “research”:

  • De-identified, aggregate analysis: With your separate, optional consent, we may use de-identified VPD and biomarker data in aggregate to improve the Protocol and for internal statistical analysis. This is never a condition of receiving the Protocol.
  • The Study: An observational study conducted separately, under the supervision of an independent Principal Investigator and approved by an IEC. Participants in the Study are recruited and consented separately from, and are not drawn from, the commercial founding-cohort Membership, and their data is held in a segregated dataset. Participation in the Study is never a condition of purchasing or using Membership, and vice versa.

18. Cookies and Website Analytics

Our website and app may use cookies and similar tracking technologies, including:

  • Essential cookies, necessary for the website/app to function (for example, session management, security, and load balancing), these cannot be disabled without affecting core functionality, and do not require separate consent, as they are necessary to provide the service you have requested;
  • Functional cookies, which remember your preferences (for example, language or plan of interest);
  • Analytics and performance cookies, which help us understand how you use our website/app, measure performance, and generate on-site recommendations and personalisation as described in clause 4; and
  • Advertising/targeting cookies, where used, which may be used by us or third parties to measure and improve the effectiveness of marketing communications.

Some cookies may be placed by third-party analytics or advertising service providers embedded on our website/app, who may process this data under their own privacy policies.

You can manage or disable cookies through your browser settings, and, where available, through an on-site cookie preference tool. Disabling non-essential cookies may affect personalisation and site functionality but will not affect your ability to access the core Membership services. Please note that browsers’ “Do Not Track” signals are not uniformly recognized across all browsers and service providers.

Cookie data is retained in line with the retention principles at clause 11.

19. Language

This Policy is available in English. Under section 5(3) of the Act, you have the option to access this Policy in English or in any language specified in the Eighth Schedule to the Constitution of India. You may request a copy in any of these languages by writing to the Grievance Officer at the details in clause 15.

20. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes through a notice on our website, or via WhatsApp or email. If we intend to process your Personal Data for a new purpose not covered by your existing consent, we will seek fresh, specific consent for that purpose rather than relying on this Policy alone.

21. Business Transfers

In the event of a merger, acquisition, reorganization, sale of assets, insolvency, or other similar transaction involving Valyova, your Personal Data may be transferred to the successor or acquiring entity as part of that transaction. We will require any such successor entity to protect your Personal Data in a manner consistent with this Policy, and will notify you of any such transfer and any resulting material change in how your Personal Data is processed, in accordance with clause 20 (Changes to This Policy).

22. Dispute Resolution

Any dispute, controversy or claim arising out of or relating to this Policy, including its formation, interpretation, breach or termination, shall first be addressed through good-faith negotiation between the parties. If not resolved within 30 days of one party notifying the other in writing of the dispute, the dispute shall be referred to and finally resolved by arbitration under the Arbitration and Conciliation Act, 1996, by a sole arbitrator appointed by mutual agreement of the parties. The seat and venue of arbitration shall be Mumbai, India, and the language of arbitration shall be English.

This clause does not affect your right to approach the Board in respect of a grievance concerning the Processing of your Personal Data, or your rights under applicable consumer protection law, which you may exercise independently of this clause.

23. Governing Law

This Policy is governed by the laws of India, and the courts at Mumbai shall have exclusive jurisdiction over any dispute arising out of or in connection with it, subject to clause 22 (Dispute Resolution).

Questions about your data

Write to our Grievance Officer, Akash Banerji, at hello@valyova.com or call 9820382537.

We acknowledge every grievance within 48 hours and respond within a period not exceeding 90 days, in line with Rule 14(3) of the Rules.

Email the Grievance Officer