This Privacy Policy (this “Policy”) governs the use of the Platform owned, operated and managed by VeriScript Private Limited, a company incorporated under the provisions of the Companies Act, 2013, having its registered office at 7/20 Industrial Area, Kirti Nagar, West Delhi, New Delhi – 110015, India (hereinafter referred to as the “Company”, “We”/ “we”, “Us”/ “us”, or “Our”/ “our”). The terms capitalized but not defined in this Policy shall have the meaning ascribed to them in the terms of use of the Platform available at [•] (the “Terms of Use”). In the event of any conflict or inconsistency between this Policy and the Terms of Use in relation to the processing of Personal Data, this Policy shall prevail.
This Policy describes how We collect, receive, use, store, process, disclose, transfer, retain, and otherwise handle Your Personal Data and other information when You access or use Our products, services, websites, applications, and related offerings. We are committed to protecting Your privacy and processing Your Personal Data in a lawful, fair, transparent, and secure manner in accordance with applicable data protection, privacy, and health-information laws in the jurisdictions in which We operate, including but not limited to:
India
- Section 43A of the Information Technology Act, 2000;
- Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Information) Rules, 2011 (“SPI Rules”);
- Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”);
- The Mental Healthcare Act, 2017 (“MHA”), including its provisions on confidentiality of, and access to, mental-health records; and
- The Telemedicine Practice Guidelines, 2020 (issued under the Indian Medical Council Act / National Medical Commission framework), where care or prescriptions are delivered through or alongside the Platform.
United States of America
- The Health Insurance Portability and Accountability Act of 1996, together with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule (collectively, “HIPAA”), to the extent We act as a Business Associate of a Covered Entity;
- Section 5 of the Federal Trade Commission Act and the FTC Health Breach Notification Rule, to the extent applicable to consumer health information not covered by HIPAA; and
- Applicable U.S. state privacy and health-data laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), the Washington My Health My Data Act (“MHMDA”), and other state statutes.
United Arab Emirates:
- Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (“UAE PDPL”) and its Executive Regulations;
- Federal Law No. 2 of 2019 concerning the Use of Information and Communication Technology in the Health Fields (“UAE Health ICT Law”), including its health-data residency requirements; and
- Where We or an Enterprise Client operate within a UAE free zone, the applicable free-zone framework, including the DIFC Data Protection Law No. 5 of 2020, the ADGM Data Protection Regulations 2021, and the Dubai Healthcare City health-data regulations.
European Economic Area (“EEA”)
- The General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), to the extent it applies.
The Company operates the empaithy™ brand across two distinct product offerings. While this Policy applies to both products, certain provisions differ depending on the nature of the Services provided and Our role in processing Your Personal Data.
1Definitions
Unless the context otherwise requires, the following terms have the meanings given below. Terms defined in the Terms of Use and not redefined here carry the same meaning:
“Authorised User” has the meaning given in the Terms of Use, being an individual who is an employee, agent, contractor or representative of an Enterprise Client, who has been granted access to Enterprise Application, and who accesses or uses it in connection with the rights of that Enterprise Client under the Enterprise Agreement.
“Bridge” means the module of Enterprise Application that supports post-session continuity of care, as described in the Terms of Use.
“Business Associate” and “Covered Entity” have the meanings given under HIPAA. Where We process Protected Health Information on behalf of a Covered Entity Enterprise Client, We act as a Business Associate under a Business Associate Agreement (“BAA”).
“Clinical Data” means, collectively, assessment and questionnaire responses entered by or at the direction of an Authorised User, session audio, transcripts and derived text, extracted clinical elements, and any prescription-related documentation prepared by or at the direction of a clinician, as mentioned in Clause 4.
“Consent” means the free, specific, informed, unconditional and unambiguous indication of a Data Principal’s agreement to the processing of their Personal Data, given by a clear affirmative action, as required under Section 6 of the DPDP Act, Article 4(11) and Article 7 of the GDPR, and the corresponding consent requirements of the UAE PDPL; and, where HIPAA applies, includes any authorization required under the HIPAA Privacy Rule.
“Consumer Application” means the mobile application titled “Empaithy”, and has the meaning ascribed to it in the Terms of Use.
“Data Fiduciary” / “Controller” means the person who alone or in conjunction with others determines the purpose and means of processing Personal Data (DPDP Act, Section 2(i); GDPR, Article 4(7); UAE PDPL, “Controller”).
“Data Principal” / “Data Subject” means the individual to whom the Personal Data relates, and, in relation to a child, includes the parent or lawful guardian of such child, and, in relation to a person with disability who has a lawful guardian, includes such lawful guardian acting on their behalf (DPDP Act, Section 2(j)).
“Data Processor” / “Processor” means the person who processes Personal Data on behalf of a Data Fiduciary or Controller (DPDP Act, Section 2(k); GDPR, Article 4(8); UAE PDPL, “Processor”).
“Enterprise Agreement” means the separate written agreement entered into between the Company and an Enterprise Client governing, inter alia, access to and use of Enterprise Application by the Authorised Users of that Enterprise Client, and includes any data-processing addendum, BAA or equivalent agreement entered into thereunder.
“Enterprise Application” shall have the meaning ascribed to it in the Terms of Use.
“Enterprise Client” means a hospital, clinic, healthcare institution or other entity, including an individual practitioner operating in a professional capacity, that has entered into an Enterprise Agreement with the Company for access to and use of Enterprise Application.
“Health Data” means Personal Data relating to the physical or mental health of an individual, including data relating to the provision of health services, and includes “Protected Health Information” under HIPAA, “health data” under the UAE Health ICT Law, “consumer health data” under the MHMDA, and “data concerning health” under the GDPR.
“Individual User” has the meaning given in the Terms of Use.
“Output” has the meaning given in the Terms of Use.
“Patient” has the meaning given in the Terms of Use.
“Personal Data” means any data or information about an individual who is identifiable by or in relation to such data (DPDP Act, Section 2(t)); any information relating to an identified or identifiable natural person (GDPR, Article 4(1)); and Personal Data as defined under the UAE PDPL.
“Platform” has the meaning given in the Terms of Use and, as described in Clause 2, includes Consumer Application and Enterprise Application.
“Prescription” means a prescription for medication or treatment, the clinical content of which is determined solely by a qualified, licensed healthcare professional and which is issued only following such professional’s independent review and approval.
“Protected Health Information” has the meaning given to it under HIPAA.
“Risk Alert” has the meaning given in the Terms of Use, being an automated alert generated by the Platform where it detects possible indicators of risk, including risk of self-harm.
“Sensitive Personal Data” / “Special Category Data” means Personal Data including health, mental-health, biometric, genetic, and financial information, and other categories as defined under Rule 3 of the SPI Rules, Article 9(1) of the GDPR and the UAE PDPL, and Health Data as defined above. The DPDP Act does not create a separate statutory category of sensitive personal data; accordingly, such data is treated as Personal Data under the DPDP Act and processed with the additional safeguards described in this Policy.
“Services” has the meaning given in the Terms of Use.
“Signal” means the module of Enterprise Application that generates proactive Risk Alerts, as described in the Terms of Use.
“Sub-processor” means a third party engaged by the Company to process Personal Data in the provision of the Services, as described in Clauses 6 and 7.
“User”/ “You”/ “you” / “Your”/ “your” means, individually or collectively as the context requires, an Individual User and/or an Authorised User; and “Users” shall be construed accordingly.
2Scope and Application
This Policy applies to the Personal Data processed by the Company through the Platform, including the to be confirmed, the Enterprise Application web-based and/or mobile application, and the Consumer Application mobile application for Android and iOS, which together constitute the Platform as defined in the Terms of Use.
This Policy applies to:
- individuals who access or use the Consumer Application to reflect on their own mental well-being;
- Patients and other individuals whose Personal Data is processed through Enterprise Application by or on behalf of an Enterprise Client;
- clinicians and other Authorised Users of Enterprise Application, who are Users for the purposes of the Terms of Use; and
- administrators and representatives of Enterprise Clients,
in each case, to the extent that the Company processes their Personal Data.
Territorial Scope
This Policy is intended to comply with the laws of each jurisdiction in which the Company operates or offers the Services, and applies, without limitation, to India, United States of America, United Arab Emirates, and the EEA.
Where more than one law applies to a given processing activity, We will apply the standard that provides the higher level of protection to the Data Principal, to the extent the applicable laws can be reconciled.
Our Role in Relation to Your Personal Data
(a) in respect of Consumer Application, the Individual User registers directly with the Company, and the Company determines the purposes and means of processing that Individual User’s Personal Data and accordingly acts as the Data Fiduciary / Controller in respect of such data; and (b) in respect of Enterprise Application, the Enterprise Client holds the clinical relationship with, and determines the purposes and means of processing of, Patient data, and the Company acts as a service provider and Data Processor processing such data on the documented instructions of the Enterprise Client. Where the Company processes Protected Health Information on behalf of a Covered Entity Enterprise Client, it does so as a Business Associate under a BAA. Nothing in this Policy or the Terms of Use makes the Company the treating provider of, or responsible for the clinical care of, any Patient.
Language. This Policy is published in English. You may request a copy of this Policy, and of any notice issued under it, in English or in any language specified in the Eighth Schedule to the Constitution of India, by writing to Us at [].
3Consent
Where the Company relies on Consent as the legal basis for processing Personal Data, such Consent shall be free, specific, informed, unconditional, and unambiguous, and obtained through a clear affirmative action in accordance with applicable law. Before or at the time of collecting Personal Data, We will provide a notice describing the categories of Personal Data collected and the purposes for which it will be processed.
For Consumer Application, Consent is obtained directly from Users during account registration and, where applicable, when optional features (such as audio journaling) are first enabled. Consent for optional processing activities may be granted or withheld independently, and the withdrawal of Consent for one feature shall not affect any Consent previously provided for another. Where the MHMDA or a comparable U.S. state law applies, We will obtain any separate Consent (and, where required, separate authorisation) needed to collect, process, or share consumer health data.
For Enterprise Application, the responsibility for obtaining any Consent required for the recording, transcription, storage, and AI-assisted analysis of clinical interactions and any authorization required under HIPAA rests with the relevant Enterprise Client and the treating clinician in accordance with applicable law and professional obligations. Where the Platform facilitates the collection of such Consent through an in-app interface, the Company does so solely on the instructions of the Enterprise Client, and such functionality does not replace or limit the Enterprise Client’s independent legal obligations. These allocations of responsibility mirror the representations given by each Authorised User under the Terms of Use, including that the Patient (or their lawful guardian, where applicable) has been clearly informed that their information will be recorded, transcribed and analysed using automated and AI-based tools and may be processed by third-party Sub-processors, including outside India; that the Patient’s free, specific and informed Consent has been obtained and documented in a manner capable of being withdrawn; and that the Authorised User will honour any withdrawal of Consent and any request to cease recording, and will promptly communicate any such request to the Company where action by the Company is required to give effect to it.
Withdrawal of Consent
You may withdraw Your Consent at any time, with the same ease with which it was provided, by contacting Us at to be confirmed or through the in-app settings, where available. Withdrawal of Consent shall not affect the lawfulness of any processing carried out prior to such withdrawal. Upon receiving a valid request, We will cease the relevant processing, or, where We process Personal Data on behalf of an Enterprise Client, act in accordance with the instructions of the relevant Enterprise Client and applicable law. Certain Personal Data may continue to be retained where required or permitted by law.
4Information Collected
The categories of Personal Data We collect depend on the application You use and the Services You access. Personal Data processed through Enterprise Application, and certain Personal Data processed through Consumer Application, may include health and mental-health information, which We process with additional safeguards in accordance with applicable law.
Information Collected Through Consumer Application
- Account Information, including Your name, email address, phone number, password, one-time password, and profile picture.
- Journal Entries, including text-based journal entries and speech converted into text. Voice recordings used for speech-to-text conversion are processed only for transcription and are not retained thereafter. The Company does not store any voice or speech data captured through the voice-to-text feature of Consumer Application. This does not apply to session audio captured through Enterprise Application, which is addressed below.
- Screening and Check-in: The information You record to document Your emotional states over time, which are recorded as informational inputs to support Your self-reflection.
- AI-Generated Reports, including reflective reports, emotional insights, and summaries of mood and emotional themes generated from Your journal entries to help You understand and reflect on Your mental and emotional well-being.
- Emergency Contact Information, where You choose to provide such details and expressly consent to their use. The Platform is not a crisis, emergency or suicide-prevention service; the Company does not monitor journal entries or Risk Alerts in real time and does not undertake to contact any emergency contact, emergency service or other person on Your behalf. Emergency contact details are stored so that they remain available to You and will be disclosed only with Your Consent or where disclosure is required or permitted by applicable law.
- Device and Usage Information, including device identifiers, application analytics, and crash or diagnostic logs.
- Payment Information, where applicable including subscription and billing details processed through Our authorised payment service providers. Payments are made through the online payment methods made available on the Platform, including credit cards, debit cards, net banking, UPI and digital wallets, as described in the Terms of Use. Full payment card numbers and equivalent credentials are collected and stored by Our authorised payment service providers and are not stored by the Company.
Information Collected Through Enterprise Application
When Personal Data is processed through Enterprise Application, We may process the following categories of information on behalf of the relevant Enterprise Client (the categories other than Identity and Account Information together constituting Clinical Data):
- Identity and Account Information, including the names, contact details, and account credentials of clinicians, Enterprise Client administrators, and, where applicable, Patients.
- Clinical Information, including responses to assessments, screening questionnaires , symptom and history descriptions, and other clinical records submitted through the Platform.
- Session Recordings, including audio recordings of therapy or psychiatric sessions where recording has been enabled by the Enterprise Client.
- Transcripts and Clinical Documentation, including transcripts generated from session recordings and other structured clinical records.
- AI-Assisted Documentation, including AI-generated summaries and organised extracts of information recorded in session content (such as themes, reported symptoms and medications), Risk Alerts, and other analytical Outputs generated through the Platform.
Prescription Drafting Content, including prescription drafts prepared from prescription information that has already been determined and entered by the clinician and which are issued only following the clinician’s independent review and approval. The Platform does not select, suggest, recommend, calculate or determine any drug, formulation, dosage, strength, route, frequency, duration or combination of medicines, and does not generate any therapeutic recommendation.
Unlike Consumer Application, where voice recordings are processed solely for speech-to-text conversion and are not retained, audio recordings captured through Enterprise Application may be retained for transcription, quality assurance, clinical documentation, and other purposes authorised by the relevant Enterprise Client and applicable law. The retention of such recordings is governed by the Company and the applicable agreement with the Enterprise Client, and, where applicable, by HIPAA and the UAE Health ICT Law.
5Use of the Data Collected
We process Your Personal Data only where We have a lawful basis to do so under applicable law and solely for the purposes described in this Policy. Depending on the application You use and the jurisdiction in which You are located, We may process Your Personal Data on the basis of Your Consent, where processing is necessary for the performance of a contract with You, to comply with Our legal obligations, to protect vital interests, to perform tasks carried out in the public interest where applicable, or where such processing is necessary for Our legitimate interests, provided that such interests are not overridden by Your rights and freedoms. Notwithstanding the foregoing, in respect of Personal Data processed under the DPDP Act, We process Your Personal Data only on the basis of Your Consent or for a legitimate use recognised under Section 7 of the DPDP Act, and the other lawful bases referred to in this paragraph apply only where recognised by the law of the relevant jurisdiction. We may process Your Personal Data without Your Consent only where such processing is for a legitimate use recognised under the DPDP Act.
Legal Bases for Processing under the GDPR
Where the GDPR applies to the processing of Your Personal Data and the Company acts as a Controller, We rely on the following legal bases under Article 6(1) of the GDPR:
- Performance of a contract (Article 6(1)(b)): to create, manage and administer Your account, provide the Services (including AI-assisted insights and reports), process payments and subscriptions, and provide customer support;
- Consent (Article 6(1)(a)): to enable optional features (such as audio journaling), send marketing and promotional communications, place non-essential cookies and similar tracking technologies, and use Your Personal Data for the development or improvement of AI models where Consent is required;
- Compliance with a legal obligation (Article 6(1)(c)): to comply with tax, accounting, record-keeping, breach-notification and other legal and regulatory obligations, and to respond to lawful requests from competent authorities;
- Legitimate interests (Article 6(1)(f)): to maintain the security, integrity and performance of the Platform, detect and prevent fraud and misuse, analyse usage to improve the Services, and establish, exercise or defend legal claims, in each case provided that such interests are not overridden by Your interests or fundamental rights and freedoms; and
- Vital interests (Article 6(1)(d)): in limited circumstances, where processing is necessary to protect Your life or the life of another natural person, including the disclosure of emergency contact details where permitted by applicable law.
Where We rely on legitimate interests, You may request further information on the balancing test We have carried out by contacting Us, and You have the right to object to such processing under Article 21 of the GDPR. Where We rely on Consent, You may withdraw it at any time in accordance with Clause 3, without affecting the lawfulness of processing carried out before its withdrawal. Where the provision of Personal Data is a contractual requirement or a requirement necessary to enter into a contract, failure to provide it may mean that We are unable to provide the Services to You.
Where We process Health Data or Special Category Data subject to the GDPR, We will do so only where an additional condition under Article 9 of the GDPR applies, including Your explicit Consent or where processing is necessary for the provision or management of healthcare services by or under the responsibility of a healthcare professional or healthcare institution.
Where We process Protected Health Information as a Business Associate under HIPAA, We do so only as permitted by the applicable BAA and the HIPAA Privacy and Security Rules, and only for the treatment, payment, and healthcare-operations purposes of the Covered Entity Enterprise Client, or as otherwise required by law.
Where We process Health Data subject to the UAE Health ICT Law, We do so in accordance with that law’s purpose-limitation, security, and residency requirements.
Where the Company acts as a Data Processor on behalf of an Enterprise Client through Enterprise Application, the Enterprise Client remains responsible for determining the lawful basis for processing Personal Data, providing the required privacy notices, and obtaining any legally required Consents or authorizations. In such cases, the Company processes Personal Data solely on the documented instructions of the Enterprise Client, except where otherwise required by applicable law.
Depending on the Services You use, We may process Your Personal Data to:
- create, manage, and administer Your account and provide the Services;
- enable the journalling, screening, mental well-being check-in, and other self-reflection features of Consumer Application, and identify trends and generate insights from the information You submit to help You understand Your mental and emotional well-being;
- generate AI-assisted insights, reports, summaries, and, in the case of Enterprise Application , AI-assisted analysis and summaries of information recorded over time, prescription-drafting and documentation support (without selecting, suggesting or recommending any medication or treatment), and Risk Alerts generated by Signal;
- facilitate continuity of care and clinical workflows through the Platform, including Bridge;
- process payments, subscriptions, and related transactions;
- provide customer support and respond to Your requests, feedback, or grievances;
- maintain the security, integrity, and performance of the Platform, including detecting, preventing, and investigating fraud, misuse, or other unauthorised activities;
- comply with applicable legal, regulatory, and contractual obligations, including responding to lawful requests from competent authorities; and
- where You have provided Your Consent, improve Our Services, conduct research and analytics, and send marketing or promotional communications.
We do not use Clinical Data processed through Enterprise Application, or journal entries submitted through Consumer Application, for any purpose other than those described in this Policy (including the development and enhancement of the Company’s own AI models on an anonymised basis), those authorised by the relevant Enterprise Client (where applicable), or as otherwise permitted or required by applicable law. In particular, We do not sell Health Data, and We do not use Protected Health Information for marketing except as expressly permitted under HIPAA and any applicable authorization.
6Processing and Sharing the Data
We do not sell, rent, or otherwise disclose Your Personal Data for commercial purposes including “sale” or “sharing” as defined under the CCPA/CPRA, or any sale of consumer health data within the meaning of the MHMDA. We share Personal Data only where necessary to provide the Services, comply with applicable law, protect Our interests, or with Your Consent. Wherever Personal Data is shared with third-party service providers, We require them to process such information only on Our instructions and to implement appropriate technical and organisational safeguards, and, where they process Protected Health Information, to enter into a BAA.
We may share Personal Data with the following categories of recipients:
- Artificial Intelligence and Machine Learning Service Providers, for generating AI-assisted insights, summaries, reports, transcription, and other analytical Outputs.
- Cloud Hosting and Infrastructure Providers for securely hosting, processing, and storing Personal Data, using regions consistent with applicable data-residency requirements.
- Speech-to-Text Service Providers for transcribing audio recordings where such functionality is enabled.
- Payment Service Providers for processing subscription payments and related billing transactions.
- Analytics and Diagnostic Service Providers for monitoring platform performance, usage analytics, and error reporting.
- Communication Service Providers for sending transactional emails, notifications, security alerts, and other service-related communications.
- Application Store Operators, such as the Apple App Store and Google Play Store, in connection with the distribution and operation of Consumer Application.
- Third-party applications with which the Company integrates the Platform, in which case Personal Data is shared only to the extent necessary for the integration and subject to the safeguards described in this Policy (including Clause 12) and applicable Cookie Policy. Any such third-party application is operated by a third party and is governed by its own terms of use and privacy policy.
We may also disclose Personal Data:
- to the relevant Enterprise Client, treating clinician, or other Authorised Users of Enterprise Application, where necessary to provide the Services;
- where required to comply with applicable law, legal process, regulatory requirements, or lawful requests from competent authorities;
- in connection with a merger, acquisition, restructuring, financing, or sale of all or part of Our business, subject to appropriate confidentiality and data protection obligations; or
- with Your prior Consent or at Your direction.
7Use of AI and Training Model
Both Consumer Application and Enterprise Application use AI (as defined in the Terms of Use) to process information submitted through the Platform. Depending on the Services You use, AI may be used to analyse journal entries, transcribed audio, clinical documentation, and other text-based inputs to generate insights, summaries, reflective reports, AI-assisted analysis, prescription-drafting and documentation support, risk indicators, and other analytical Outputs.
To provide these functionalities, certain Personal Data, including journal entries, clinical text, and transcribed audio, may be processed by third-party AI service providers acting on the Company’s behalf as Sub-processors. These providers are engaged under contractual terms that restrict their use of the data to providing the Services, and We take reasonable steps to ensure that Personal Data is not used to train third-party AI models except with a lawful basis and, where required, Your Consent.
Training and improvement of the Company’s own AI models. Personal Data collected through the micro-journaling features of Consumer Application may be used for the ongoing development and enhancement of the Company’s own AI models. All such data is anonymised before being used for AI model training, with identifiers removed such that it cannot be linked back to a User or reasonably re-identified; once anonymised, it no longer constitutes Personal Data. Where applicable law requires Consent for the use of Personal Data for model training, We will obtain that Consent separately, and You may withdraw it at any time in accordance with Clause 3.
Where such processing involves the transfer of Personal Data outside Your jurisdiction, the Company will implement appropriate safeguards and contractual protections in accordance with applicable law. Where Health Data is subject to the UAE Health ICT Law’s residency requirements, such data will not be transferred to AI or other service providers located outside the UAE except where a permitted exception or authorisation applies.
AI-generated Outputs are intended to assist Users and, in the case of Enterprise Application , support qualified healthcare professionals in their clinical workflows. Such Outputs are generated using probabilistic models and may not always be complete or accurate. They should not be treated as medical advice, a diagnosis, or the sole basis for clinical or other significant decisions. The Platform does not select, suggest, recommend or determine any medication or treatment, and every Prescription is determined, reviewed, verified and issued solely by a qualified, licensed healthcare professional.
Use of AI under the GDPR. Where the GDPR applies, the third-party AI service providers referred to in this Clause act as Our Processors under written agreements that meet the requirements of Article 28 of the GDPR, and any transfer of Personal Data to such providers outside the EEA is subject to the safeguards described in Clause 9. The legal bases on which We rely for processing Your Personal Data using AI are set out in Clause 5, and any use of Your Personal Data for training or improving AI models that requires Consent will be undertaken only with Your Consent. Where processing using AI or other new technologies is likely to result in a high risk to Your rights and freedoms, We carry out a data protection impact assessment in accordance with Article 35 of the GDPR. Information on automated decision-making and profiling, and Your related rights, is set out in Clause 21.
8User Rights
Depending on Your location and the Services You use, You may have certain rights in relation to Your Personal Data. In this Clause 8, references to “You” and “Your” include any Patient or other Data Principal whose Personal Data is processed through the Platform. Where the Company processes Personal Data on behalf of an Enterprise Client through Enterprise Application, certain requests may need to be exercised through the relevant Enterprise Client, which acts as the applicable Data Fiduciary, Controller, or Covered Entity.
Rights under the Digital Personal Data Protection Act, 2023 (India)
Subject to applicable law, You have the right to:
- obtain a summary of Your Personal Data and the processing activities undertaken by the Company;
- request the correction, completion, updating, or erasure of Your Personal Data;
- seek grievance redressal in relation to the processing of Your Personal Data;
- nominate any other individual, in the manner prescribed under the DPDP Act and the DPDP Rules, who shall be entitled to exercise Your rights under the DPDP Act in the event of Your death or incapacity; and
- withdraw Your Consent at any time, where processing is based on Consent.
In addition, where Your mental-health records are involved, You may have rights of access and confidentiality under the MHA, which the relevant clinician or Enterprise Client is responsible for honouring.
Rights under HIPAA (United States)
Where We hold Protected Health Information as a Business Associate, and subject to the applicable BAA and the direction of the Covered Entity, You may have the right to:
- access and obtain a copy of Your Protected Health Information;
- request amendment of inaccurate or incomplete Protected Health Information;
- receive an accounting of certain disclosures;
- request restrictions on certain uses and disclosures; and
- request confidential communications.
Such requests are ordinarily directed to, and fulfilled by, the Covered Entity Enterprise Client; We will support the Covered Entity as required under the BAA.
Rights under U.S. State Privacy and Health-Data Laws
Where CCPA/CPRA, the MHMDA, or a comparable state law applies, You may have the right to know, access, correct, and delete Your Personal Data or consumer health data, to opt out of the sale or sharing of Personal Data and of certain targeted advertising, to limit the use of sensitive personal information (as defined under the CCPA/CPRA), and to withdraw Consent to the collection or sharing of consumer health data. We do not discriminate against You for exercising these rights.
Rights under the UAE PDPL
Where the UAE PDPL applies, You may have the right to access, rectify, and erase Your Personal Data, to restrict or object to processing, to data portability, to withdraw Consent, and to lodge a complaint with the UAE Data Office, subject to the exceptions in that law.
Rights under the GDPR (EEA)
Where the GDPR applies, You may also have the right to:
- access Your Personal Data;
- rectify inaccurate or incomplete Personal Data;
- request the erasure of Your Personal Data;
- restrict the processing of Your Personal Data;
- receive Your Personal Data in a portable format;
- object to certain processing activities, including direct marketing;
- object to decisions based solely on automated processing, where applicable; and
- lodge a complaint with the competent supervisory authority.
You may exercise any of the above rights by contacting Us at to be confirmed or through Our Grievance Officer / Data Protection Officer, whose details are provided in Clause 26. We will respond to Your request within the time prescribed under applicable law.
Please note that certain rights, including the right to erasure, may be restricted where We are required to retain Personal Data to comply with applicable law, fulfil contractual obligations, establish or defend legal claims, or maintain clinical records in accordance with legal or regulatory record-keeping requirements (including under the MHA, HIPAA, and the UAE Health ICT Law).
Where the Data Principal is a child or a person with disability who has a lawful guardian, the rights set out in this Clause may be exercised by the parent or lawful guardian, as applicable, on their behalf.
Your duties as a Data Principal. While using the Platform or exercising Your rights under this Policy, You shall: (a) comply with all applicable laws, including the DPDP Act and the DPDP Rules; (b) not impersonate another person while providing Your Personal Data for a specified purpose; (c) not suppress any material information while providing Your Personal Data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities; (d) not register a false or frivolous grievance or complaint with Us or the Data Protection Board of India; and (e) furnish only such information as is verifiably authentic while exercising the right to correction or erasure. You shall not provide the Personal Data of any other individual (including any emergency contact) without the Consent or lawful authority of such individual.
9Data Transfer and Cross-border Processing
To provide and improve the Services, We may process or transfer Your Personal Data outside the country in which it was collected. This may occur where We engage trusted third-party service providers, including cloud hosting providers, artificial intelligence service providers, payment processors, and other technology partners that support the operation of the Platform.
Where such transfers take place, We ensure that Your Personal Data is processed only for the purposes described in this Policy and subject to appropriate contractual, technical, and organisational safeguards designed to protect its confidentiality, integrity, and security. Depending on the jurisdictions involved, We implement appropriate transfer mechanisms before Personal Data is transferred across jurisdictions, which may include:
India (DPDP Act): transfers only to countries not restricted by the Central Government, and in accordance with any conditions notified under the DPDP Act;
EEA (GDPR): the safeguards described under “Transfers from the EEA” below;
United States (HIPAA): BAAs and equivalent safeguards for any Protected Health Information transferred to or accessed by Sub-processors; and
United Arab Emirates (UAE PDPL): transfers only to jurisdictions with an adequate level of protection or subject to appropriate safeguards or a valid exception.
Critical health-data residency requirement (UAE): The UAE Health ICT Law restricts the storage, processing, and transfer, outside the UAE, of Health Data generated in connection with health services provided inside the UAE, except where the competent UAE health authority permits it. Where the Services are provided to Enterprise Clients or Users in the UAE, We will store and process such Health Data within the UAE and will not transfer it outside the UAE including to AI or speech-to-text providers hosted abroad unless and until a permitted exception or authorisation applies. Enterprise Clients in the UAE are responsible for confirming the residency treatment applicable to their deployment.
Transfers from the EEA
The Company is established in India. This means that when You use the Platform from the EEA, Your Personal Data will be processed in India. India has not been recognised by the European Commission as providing an adequate level of protection for Personal Data. Our service providers may also process Your Personal Data in other countries outside the EEA.
Where We transfer Your Personal Data (including onward transfers by Us to Our service providers and Sub-processors) to a country outside the EEA, We ensure that the transfer is subject to appropriate safeguards in accordance with Chapter V of the GDPR, namely:
(a) transfers to countries that have been recognised as providing an adequate level of protection by an adequacy decision of the European Commission;
(b) the Standard Contractual Clauses approved by the European Commission; or
(c) where none of the above applies, one of the derogations under Article 49 of the GDPR ,such as where the transfer is necessary for the performance of Our contract with You.
You may request a copy of the relevant safeguards (with commercially sensitive information redacted) by contacting Us using the details in Clause 26.
If applicable laws require additional safeguards or impose restrictions on cross-border transfers of Personal Data, We will comply with such requirements before transferring or permitting access to Your Personal Data.
10Data Retention
We retain Your Personal Data only for as long as it is necessary to fulfil the purposes for which it was collected, provide the Services, comply with applicable legal, regulatory, contractual, or accounting obligations, resolve disputes, enforce Our agreements, and protect the security and integrity of the Platform.
The retention period for Personal Data depends on the nature of the information, the purpose for which it was collected, and applicable legal or regulatory requirements, including minimum clinical-record retention obligations under the MHA, HIPAA, applicable state medical-records laws, and the UAE Health ICT Law. Unless a longer retention period is required or permitted by law:
- Account Information and Identity and Account Information will be retained for the duration of Your account and for to be confirmed days/months after account closure or deletion.
- Journal Entries, Screening and Check-in information, AI-Generated Reports, Emergency Contact Information, and other content submitted through Consumer Application will be retained until You delete such content, delete Your account, or withdraw Your Consent, following which such information will be deleted or anonymised within to be confirmed days, unless We are legally required or permitted to retain it.
- Clinical Data (including Session Recordings, Transcripts and Clinical Documentation, AI-Assisted Documentation and Prescription Drafting Content) and other information processed through Enterprise Application will be retained in accordance with the instructions of the relevant Enterprise Client, the applicable agreement between the Company and the Enterprise Client, and any applicable legal or regulatory record-retention requirements. Where applicable, session recordings will be retained for to be confirmed after transcription / for the duration of the clinical record, as determined by the Enterprise Client’s retention policy and applicable law.
- Payment Information will be retained for to be confirmed years, or such longer period as required under applicable tax, accounting, or financial-reporting laws.
- Device and Usage Information, system logs, security records and backup data will be retained for to be confirmed days/months, after which they will be securely deleted or anonymised, unless a longer retention period is required for security, business continuity, or legal compliance.
Where You withdraw Your Consent, We will cease processing Your Personal Data for the purpose(s) for which Consent has been withdrawn and, subject to applicable law, erase such Personal Data as soon as reasonably practicable. However, We may retain certain Personal Data where such retention is necessary to comply with applicable law, fulfil contractual obligations, establish or defend legal claims, prevent fraud or misuse, maintain clinical records, or comply with the lawful instructions of the relevant Enterprise Client.
Where the Company acts as a Data Processor on behalf of an Enterprise Client, requests for deletion, correction, or retention of Clinical Data will be processed in accordance with the instructions of the relevant Enterprise Client and any applicable legal or regulatory requirements.
Upon expiry of the applicable retention period, or once the Personal Data is no longer required for the purposes for which it was collected, We will securely delete, anonymise, or otherwise irreversibly dispose of such Personal Data in accordance with Our internal data-retention and information-security practices.
11Data Breach Response
We implement appropriate administrative, technical, and physical security measures to protect Your Personal Data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. Despite these safeguards, no method of electronic transmission or storage is completely secure, and We cannot guarantee absolute security. If We become aware of any Personal Data breach, We will promptly investigate the incident, take appropriate steps to contain and mitigate its impact, and implement remedial measures to prevent similar incidents.
Where required under applicable law, We will notify the relevant regulatory authorities, affected Enterprise Clients, and affected individuals of a Personal Data breach within the timelines prescribed by law, which may include:
- India: notification of every Personal Data breach to the Data Protection Board of India and to each affected Data Principal, in the form and within the timelines prescribed under the DPDP Act and the rules made thereunder, and reporting to CERT-In ;
- United States: where We act as a Business Associate, notification to the Covered Entity without unreasonable delay and no later than 60 (sixty) days, to support the Covered Entity’s obligations under the HIPAA Breach Notification Rule; and, for consumer health information not covered by HIPAA, notification consistent with the FTC Health Breach Notification Rule and applicable state breach-notification laws;
- United Arab Emirates: notification to the UAE Data Office and affected individuals as required under the UAE PDPL, and to the relevant health authority where required under the UAE Health ICT Law; and
- EEA: notification to the competent supervisory authority within 72 (seventy-two) hours, and to affected individuals where required, under the GDPR.
We will also provide such information and assistance as may be reasonably necessary to enable affected individuals and Enterprise Clients to take appropriate protective measures. Following any Personal Data breach, We will review the circumstances of the incident and implement appropriate corrective, preventive, and security measures to strengthen the protection of Personal Data processed through the Platform.
12Cookies and Tracking Technology
We use cookies and similar technologies on the to be confirmed website to ensure the website functions properly, enhance Your browsing experience, analyse website usage, and, where You have provided Your Consent, personalise content and communications.
When You first visit Our website, You will be presented with a cookie consent banner that allows You to accept, reject, or manage Your cookie preferences. You may also modify or withdraw Your cookie preferences at any time through the cookie preference centre or Your browser settings. Please note that disabling certain cookies may affect the functionality of the website. We will not use tracking technologies to collect consumer health data without any Consent it requires.
Consumer Application and Enterprise Application do not use traditional browser cookies. Instead, they use authentication tokens and similar technologies to manage secure User sessions, authenticate Users, maintain application functionality, and enhance security.
You may manage or disable certain non-essential tracking technologies through Your device or application settings, or by contacting Us at to be confirmed, subject to the limitations of the relevant operating system or platform.
13Disclaimers
The Platform is intended to support the understanding of mental and emotional well-being and the documentation and administrative workflows of healthcare professionals through digital tools and AI-assisted functionalities. It does not provide medical, psychiatric, or psychological diagnosis, treatment, or emergency intervention, and it does not itself prescribe medication or practise medicine. The Company provides software tools and does not hold the Platform out as a medical device; the Platform is not intended to diagnose, cure, mitigate, treat or prevent any disease or condition. The Platform is not a crisis, emergency or suicide-prevention service and does not provide emergency intervention, monitoring or supervision.
AI-generated insights, reports, summaries, prescription drafts prepared from information determined and entered by a clinician, risk indicators, and other Outputs are intended solely to assist Users and, where applicable, qualified healthcare professionals. Such Outputs are generated using probabilistic models and may not always be accurate, complete, or up to date. They should not be relied upon as the sole basis for making medical, clinical, or other significant decisions, and any Prescription or treatment decision must be independently made, reviewed and approved by a qualified, licensed healthcare professional. Use of the Platform does not create a doctor-patient, therapist-patient, or other healthcare provider relationship between the Company and any User. Any such relationship exists solely between the User and the relevant healthcare professional or Enterprise Client.
Risk Alerts. Risk Alerts are decision-support only. The Company does not warrant that the Platform will detect, or correctly detect, any particular risk. Risk Alerts may be inaccurate, over-inclusive, delayed or absent, and the absence of a Risk Alert must never be interpreted as an assurance that no risk exists. The Company does not monitor Risk Alerts and does not provide any intervention.
If You are experiencing a medical or mental-health emergency, or believe that You or another person may be at immediate risk of harm, You should immediately contact the appropriate emergency services or a qualified healthcare professional. The Platform should not be relied upon for emergency assistance or crisis intervention.
14Professional Oversight, Prescription Drafting, and Telemedicine
Where the Platform supports the preparation of clinical documentation or the drafting of prescriptions, the following principles apply:
- Clinician approval is mandatory: Any prescription drafted using the Platform is a draft only until it is reviewed, verified, and expressly approved by a qualified, licensed healthcare professional who is responsible for the clinical decision.
- No autonomous prescribing: The Platform does not autonomously issue Prescriptions and does not exercise independent clinical judgment. The Company does not make clinical decisions on behalf of any healthcare professional. The Platform does not select, suggest, recommend, calculate or determine any drug, formulation, dosage, strength, route, frequency, duration or combination of medicines, and does not generate any therapeutic recommendation. The prescription-drafting feature is limited to preparing prescription information that has already been determined and entered by the relevant Authorised User who is a qualified, licensed healthcare professional.
- Compliance with laws: Prescriptions and any care delivered through or alongside the Platform must comply with the applicable telemedicine, licensure, and prescribing laws of the relevant jurisdiction, including the Telemedicine Practice Guidelines, 2020 (India), applicable U.S. federal and state telehealth and prescribing rules, and applicable UAE telehealth and health-practice regulations. The relevant clinician and Enterprise Client remain responsible for such compliance.
- Scope of the Company’s role: In relation to Prescriptions and clinical documentation, the Company acts as a technology and processing service provider to the Enterprise Client and does not act as a healthcare provider. Responsibility for the clinical appropriateness, accuracy and legality of every Prescription rests solely with the Enterprise Client, as set out in the Terms of Use.
15Registration and Cancellation
Registration
Users may register for Consumer Application using the registration options made available through the Platform. Access to Enterprise Application is generally provided by the relevant Enterprise Client directly or by the Company at the instance of the Enterprise Client. By creating an account or accessing the Platform, You acknowledge that You have read and understood this Policy and consent to the collection, use, disclosure, and processing of Your Personal Data in accordance with this Policy and applicable law. You are responsible for ensuring that the information You provide during registration is accurate, complete, and up to date. The Company reserves the right to suspend or terminate Your account where any information provided is false, inaccurate, misleading, or where Your use of the Platform violates applicable law or the Terms of Use. Registration requires the User to sign up using their email address or mobile number together with such additional details as the Company may require and, only individuals who are 18 (eighteen) years of age or older may register. You are solely responsible for maintaining the confidentiality of Your account credentials and for all activity occurring under Your account, and for securing the devices and browsers You use. Each Authorised User acknowledges that their access to Enterprise Application may be created, managed or disabled by the relevant Enterprise Client.
Account Deletion
You may request deletion of Your account at any time through the in-app settings, where available, or by contacting Us at to be confirmed. Upon receiving a valid deletion request, We will delete or anonymise Your Personal Data within to be confirmed days, unless We are required or permitted to retain certain information under applicable law, to comply with legal or regulatory obligations, fulfil contractual commitments, resolve disputes, establish or defend legal claims, maintain clinical records, or comply with the documented instructions of the relevant Enterprise Client.
Withdrawal of Consent
Where the processing of Your Personal Data is based on Your Consent, You may withdraw such Consent at any time with the same ease with which it was provided, through the relevant in-app settings, where available, or by contacting Us at to be confirmed. Withdrawal of Consent will not affect the lawfulness of any processing carried out prior to such withdrawal. Upon receiving a valid request, We will cease processing the Personal Data for the relevant purpose, unless continued processing is required or permitted under applicable law or is necessary to comply with legal obligations, protect legal rights, or fulfil the instructions of the relevant Enterprise Client. Where withdrawal of Consent results in the inability to provide the Services, Your access to all or part of the Platform may be restricted or discontinued. Where applicable, deletion of Your account will also constitute withdrawal of Your Consent for the continued processing of Your Personal Data.
16Acceptance
By accessing or using the Platform, You acknowledge that You have read, understood, and agree to the collection, use, disclosure, and processing of Your Personal Data in accordance with this Policy. Where You access or use the Platform on behalf of an Enterprise Client or another legal entity, You represent and warrant that You are authorised to accept this Policy on its behalf. Your acceptance of this Policy is indicated by clicking ‘I Agree’, ‘Accept’, ‘Register’, or any similar affirmative action.
17Terms of Payment
Information relating to subscriptions, billing, and payment transactions is collected and processed solely for the purpose of providing the Services, processing payments, managing subscriptions, preventing fraud, and complying with applicable legal and accounting obligations. Payment transactions are processed through authorised third-party payment service providers. For more information on how We collect, use, and share payment-related Personal Data, please refer to the relevant clauses of this Policy. Subscription plans, fees, billing terms, and payment obligations are governed by the applicable Terms of Use and, in the case of Authorised Users, by the Enterprise Agreement entered into between the Company and the relevant Enterprise Client, which prevails over the Terms of Use to the extent of any inconsistency.
18Security Measures
We are committed to protecting Your Personal Data and implement appropriate administrative, technical, and physical security measures to safeguard it against unauthorised access, disclosure, alteration, loss, misuse, or destruction, including measures designed to meet the HIPAA Security Rule (where applicable) and the security requirements of the DPDP Act, the UAE PDPL, and the UAE Health ICT Law.
Security
- secure User authentication and access controls to ensure that only authorised Users can access their accounts;
- assignment of a unique internal identifier to each User, with identifying information associated with such identifier stored separately from the User’s account and other data, and the use of encrypted identifiers to identify Users within Our systems;
- encryption of data transmitted between Your device and the Platform using industry-standard security protocols;
- regular backup and recovery measures to support the availability and integrity of the Platform;
- encryption of Personal Data at rest and in transit;
- restricted access to Personal Data on a need-to-know basis through role-based access controls;
- secure cloud infrastructure and storage environments designed to protect against unauthorised access and data loss, configured to meet applicable data-residency requirements;
- monitoring, auditing, and security controls to detect and respond to potential security incidents; and
- contractual, technical, and organisational safeguards with third-party service providers and Sub-processors that process Personal Data on Our behalf, including BAAs where Protected Health Information is involved.
While We take reasonable steps to protect Your Personal Data, no method of electronic transmission, storage, or processing can be guaranteed to be completely secure. Accordingly, We cannot guarantee absolute security, and You acknowledge that You provide Personal Data at Your own risk.
19Children
The Platform is intended only for individuals who are 18 (eighteen) years of age or older. We do not knowingly collect or process Personal Data from individuals under the age of 18 (eighteen) through Consumer Application or Enterprise Application, except where an Enterprise Client lawfully uses Enterprise Application in connection with a minor Patient and all Consents and authorisations required under applicable law (including guardian consent) have been obtained. Where an Enterprise Client uses Enterprise Application in connection with a minor Patient, the representations given by the relevant Authorised User under Terms of Use extend to the Consent of that Patient’s parent or lawful guardian.
Where any processing of a minor’s Personal Data occurs, it is subject to the heightened protections of applicable law, including the DPDP Act’s requirements for verifiable parental consent and its prohibition on certain processing of children's data, the U.S. Children’s Online Privacy Protection Act for individuals under 13, and comparable protections under the UAE PDPL and the GDPR. Enterprise Clients are responsible for ensuring that Personal Data submitted through Enterprise Application relates only to individuals who meet the applicable age requirements and that all necessary Consents and authorisations have been obtained. We shall not undertake any processing of a child’s Personal Data that is likely to cause any detrimental effect on the well-being of the child, and shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.
If We become aware that We have collected or processed Personal Data relating to a minor in contravention of this Policy, We will take reasonable steps to delete such Personal Data or otherwise comply with applicable legal requirements. If You believe that a minor has provided Personal Data through the Platform, please contact Us at to be confirmed.
Persons with disabilities. Where the Personal Data of a person with disability who has a lawful guardian is processed through the Platform, We will process such Personal Data only upon obtaining the verifiable Consent of such lawful guardian in accordance with the DPDP Act and the DPDP Rules, and such lawful guardian may exercise the rights of such person under Clause 8 on their behalf.
20Confidentiality
The Company recognises the confidential and sensitive nature of the information processed through the Platform, particularly Personal Data, Clinical Data, and mental-health information, and is committed to maintaining its confidentiality in accordance with the MHA, HIPAA, the UAE Health ICT Law, and other applicable law.
Access to Personal Data and other confidential information is limited to authorised employees, contractors, service providers, and, where applicable, the relevant Enterprise Client, strictly on a need-to-know basis and only for the purposes of providing and improving the Services, complying with legal obligations, or otherwise as described in this Policy. The Company requires its employees, contractors, and authorised third-party service providers to maintain appropriate confidentiality and security obligations and to process Personal Data only in accordance with applicable law and contractual commitments.
Where Personal Data or Clinical Data is processed by third-party service providers, including cloud infrastructure providers, AI service providers, analytics providers, or other authorised Sub-processors, such processing is undertaken solely for the purposes of providing the Services and is subject to appropriate contractual, technical, and organisational safeguards. Nothing in this clause restricts the Company from disclosing information where required by applicable law, pursuant to a valid order of a court or competent authority, or where such disclosure is necessary to protect legal rights, investigate fraud or security incidents, prevent harm, or comply with regulatory obligations.
21Automated Decision Making
The Platform uses artificial intelligence and other automated technologies to support certain features and functionalities. Depending on the Services You use, such automated processing may include:
- analysing journal entries, reflections, and other User-provided content;
- identification of mood and emotional themes to support Your understanding of Your well-being;
- generation of reflective reports, summaries, insights, and personalised recommendations through Consumer Application;
- transcription and summarisation of sessions recorded by an Authorised User;
- organisation of information recorded in session content, such as themes, reported symptoms and medications;
- preparation of session summaries and summaries of information recorded over time;
- identification of potential risk indicators and generation of Risk Alerts by Signal through Enterprise Application
The Platform uses automated processes to organise information, highlight relevant patterns and generate summaries or other Outputs based on information provided to or available through the Platform. AI-generated Outputs are intended to support Users in reviewing and working with information and should not be treated as definitive conclusions or relied upon without appropriate independent review.
For Enterprise Application, AI-generated session summaries, prescription drafts, and Risk Alerts generated by Signal are intended to be reviewed and approved by the relevant healthcare professional or Enterprise Client before any clinical or treatment-related decision is made. The Company does not make clinical decisions on behalf of healthcare professionals. AI-generated Outputs are based on the information provided to the Platform and the capabilities of the underlying AI models. Such Outputs may be incomplete, inaccurate, inconsistent, or influenced by the quality of the input data and should be independently reviewed before being relied upon.
Where You have the right under applicable law (including Article 22 of the GDPR and other provisions of other applicable laws), You may request information regarding the automated processing of Your Personal Data, request human review of an automated Output where applicable, express Your point of view, contest an automated decision, or object to certain automated processing by contacting Us at to be confirmed. Where the Company acts as a Data Processor, such requests may be handled in coordination with the relevant Enterprise Client and in accordance with applicable law.
22Sensitive Content and Emergency Situations
Certain features of the Platform require the processing of Sensitive Personal Data, including information relating to an individual’s mental health, emotional wellbeing, assessment responses, journal entries, therapy sessions, and other health-related information.
Where You choose to provide emergency contact information through Consumer Application, We will process such information only for the purposes described in this Policy and in accordance with Your preferences and applicable law. The Platform may use AI-assisted technologies to identify patterns, generate summaries , or produce risk indicators based on the information submitted through the Platform. Where such functionalities are available through Enterprise Application, any Risk Alerts or other risk indicators are intended to support, and not replace, the clinical judgment of the relevant healthcare professional or Enterprise Client, who is responsible for determining whether and how to act on any such Risk Alert or indicator. The Company does not monitor the Platform, journal entries or Risk Alerts for indicators of risk in real time, does not provide crisis intervention, and does not undertake to notify any emergency contact, emergency service, clinician or other person.
If You are experiencing a medical or mental-health emergency, or believe that You or another person may be at immediate risk of harm, You should immediately contact the appropriate emergency services or a qualified and designated healthcare professional.
23Third-party Links and Content
The Platform may contain links to third-party websites, applications, or services that are not owned or controlled by the Company. Any access to or use of such third-party websites or services is at Your own discretion and is subject to their respective terms of use and privacy policies. The Company is not responsible for the privacy practices, content, security, or policies of any third-party website or service. We encourage You to review the privacy policies and terms applicable to any third-party service before providing Your Personal Data or using such services.
24Changes to Privacy Policy
We reserve the right to update or modify this Policy from time to time. Where a change is material, or affects the purposes for which or the manner in which Your Personal Data is processed, We will give reasonable prior notice (and in any event not less than to be confirmed days’ notice) before the change takes effect and, where applicable law requires fresh Consent, We will obtain it. In the event of significant changes in the way We handle Users’ Personal Data, We will either prominently display a notice on Our website or send an email notification. The latest version of this Policy will always be available on Our website, and We encourage You to check it periodically.
Your continued use of the Platform after a notice of changes takes effect indicates Your acknowledgement of the revised Policy. However, where applicable law requires Consent for a new or changed processing purpose, that Consent will be sought separately by a clear affirmative action and will not be inferred from Your continued use of the Platform alone. If You object to any of the updated terms and no longer wish to use Our Platform, You are free to deactivate Your account.
25Compliance With Applicable Laws
The Company is committed to processing Personal Data in accordance with the applicable data-protection, privacy, health-information, and cybersecurity laws governing the operation of the Platform in India, the United States, the United Arab Emirates, and any other jurisdiction in which the Services are offered. Where applicable, the Company processes Personal Data in compliance with the DPDP Act and the rules made thereunder, the MHA, HIPAA, applicable U.S. federal and state privacy and health-data laws, the UAE PDPL and the UAE Health ICT Law, and, where the processing is subject to the GDPR, the requirements of the GDPR.
The collection, use, disclosure, storage, retention, transfer, and protection of Personal Data are governed by this Policy, which forms an integral part of the Terms of Use. By accessing or using the Platform, You acknowledge that Your Personal Data will be processed in accordance with this Policy and applicable law. Nothing in this Policy or the Terms of Use shall limit or exclude any rights or obligations that cannot be excluded under applicable data-protection laws, including the rights available to Data Principals under the DPDP Act, individuals under HIPAA and applicable U.S. state laws, individuals under the UAE PDPL, and, where applicable, Data Subjects under the GDPR.
26Grievance Officer, Data Protection Officer, and Contact Mechanism
If You have any questions, concerns, requests, or complaints regarding this Policy or the processing of Your Personal Data, You may contact Us using the details below:
Grievance Officer: to be confirmed
Email: support@empaithy.com
Address: 7/20 Industrial Area, Kirti Nagar, West Delhi, New Delhi – 110015, India.
EU Representative: to be confirmed
Where required by applicable law, We will designate and publish the details of a Data Protection Officer, a representative for the EEA (GDPR Article 27), and any local representative required in the UAE or the United States. We will acknowledge and respond to Your request or grievance within the timelines prescribed under applicable law. If You are not satisfied with Our response, You may avail Yourself of any remedies available under applicable law, including lodging a complaint with the Data Protection Board of India, the relevant U.S. authority, the UAE Data Office, or, where applicable, the competent EEA supervisory authority.
27Governing Law and Dispute Resolution
This Policy shall be governed by and construed in accordance with the laws of India, without regard to its conflict-of-law principles. Any dispute, controversy, claim, or difference arising out of or in connection with this Policy, the Terms of Use, the Platform, or the Services, including any question regarding their existence, validity, interpretation, performance, breach, or termination, shall first be attempted to be resolved amicably through good-faith discussions between the parties.
If parties are unable to resolve the dispute within 30 (thirty) days from the date written notice of the dispute is received, the dispute shall be referred to and finally resolved by arbitration under the Arbitration and Conciliation Act, 1996, as amended, by a sole arbitrator appointed mutually by You and the Company, in accordance with Clause 21 of the Terms of Use. The seat and venue of the arbitration shall be New Delhi, India, and the proceedings shall be conducted in English. Subject to the above, the courts at New Delhi, India, shall have exclusive jurisdiction over all disputes arising out of or relating to this Policy, the Terms of Use and the use of the Platform, including in respect of any application in aid of arbitration.
Notwithstanding the foregoing, nothing in this Policy displaces any mandatory local law that applies to the processing of Your Personal Data in Your jurisdiction, and Your statutory rights and remedies under applicable data-protection and health-information laws (including in the United States, the UAE, and the EEA) remain available to You regardless of the governing-law and jurisdiction provisions above.
Questions about this policy can go to support@empaithy.com.