Privacy Statement
The Paybycal application and website (“Platform”) are made available to you by
Helthofit Private Limited (hereinafter may be referred to as the ‘Company’, ‘we’, ‘us’, and ‘our’) respect
your privacy and is committed to protecting it through its compliance with its privacy policy. This policy
amongst other things describes: (i) the type of information that the Company may collect from you when you
access or use its websites, applications and other online services (hereinafter collectively referred to as
the ‘Services’); and, (ii) the Company’s practices for collecting, using, maintaining, protecting and
disclosing that information. This commitment reflects the value we place on earning and keeping the trust of
our users, experts, vendors, business partners and others who share their personal information with us.
Scope Of The Statement
This Privacy Statement ("Statement") explains information processing practices of
Company. It applies to any personal information you provide to us and any personal information we collect
from other sources. This Statement is a statement of our practices and of your rights regarding your
personal information. This is not a contractual document, and it does not create any rights or obligations
on either party beyond those which already exist under data protection laws.
This Privacy Statement explains how we collect, use, disclose, and safeguard your
information when you visit our Website or Mobile Application (the “Application”). Please read this Privacy
Statement carefully. IF YOU DO NOT AGREE WITH THE TERMS OF THIS PRIVACY POLICY, PLEASE DO NOT ACCESS THE
Website/Mobile Application.
The collection and processing of personal data, such as the name, address, e-mail
address, or telephone number of a data subject shall always be in accordance with the Information Technology
Act, 2000, Information Technology Rules, 2011 adopted by India’s IT Ministry, India’s Ministry of
Communications ‘Press Note’ Technology, with clarifications and Ministry Of Communications And Information
Technology (Department Of Information Technology) Notification Dated 11th April 2011 and The General Data
Protection Regulation (GDPR) as may be applicable to PAYBYCAL. By means of these data protection
declaration, our enterprise would like to inform the general public of the nature, scope, and purpose of the
personal data we collect, use and process. Furthermore, data subjects are informed, by means of this data
protection declaration, of the rights to which they are entitled.
We reserve the right to make changes to this Privacy Statement at any time and for
any reason. You are encouraged to periodically review this Privacy Statement to stay informed of updates.
You will be deemed to have been made aware of, will be subject to, and will be deemed to have accepted the
changes in any revised Privacy Statement by your continued use of the Website/Mobile Application after the
date such revised Privacy Statement is posted.
This Statement does not apply to your use of a third-party site linked to on this
Website/Mobile Application or any third-party website or mobile application which you install or make
payments, including any in-app virtual items, which may also collect and use data about you. Company is not
responsible for any of the data collected by any such third party.
The primary point of contact at Company for questions regarding your personal
information is, support@paybycal.com.
What information do we collect?
We collect personal and other information of our users, experts, vendors in
various ways. The information that may be collected via the Website or Mobile Application depends on the
content and materials you use, and includes:
Personal Information
Demographic and other personally identifiable information (such as your name,
mobile number and email address) that you voluntarily give us when you register with the Website/Mobile
Application or when choosing to participate in various activities related to the Website/Mobile Application,
such as your age, gender, address, interests, writing reviews, chat, posting messages in comment sections or
in our forums, rating Experts, sending feedback, and responding to surveys. If you choose to share data
about yourself via your profile, online chat, or other interactive areas of the Website/Mobile Application,
please be advised that all data you disclose in these areas is public and your data will be accessible to
anyone who accesses the Website/Mobile Application. You are under no obligation to provide us with personal
information of any kind, however your refusal to do so may prevent you from using certain features of the
Website/Application.
Derivative Information
Information that our servers automatically collect when you access the
Website/Mobile Application, such as your native actions that are integral to the Website/Mobile Application,
including your IP address, your browser type, your operating system, your access times, the pages you have
viewed directly before and after accessing the Website/Mobile Application your liking, rating, re-blogging,
or replying to a post, as well as other interactions with the Website/Mobile Application and other users via
server log files.
Financial Information
Financial information, such as data related to your payment method (e.g., valid
credit card/debit card number, card brand, expiration date), that we may collect when you purchase, order,
exchange, or request information about our services from the Website/Mobile Application. We store only very
limited, if any, financial information that we collect. Otherwise, all financial information is stored by
our payment processors (RazorPay) and you are encouraged to review their privacy policy and contact them
directly for responses to your questions.
If the data subject resides outside India then the payment has to be made through
"PayPal" during the ordering process, we automatically transmit the data of the data subject to PayPal. By
selecting this payment option, the data subject agrees to the transfer of personal data required for payment
processing.
The personal data transmitted to PayPal is usually first name, last name, address,
email address, IP address, telephone number, mobile phone number, or other data necessary for payment
processing. The processing of the purchase contract also requires such personal data, which are in
connection with the respective order.
The transmission of the data is aimed at payment processing and fraud prevention.
The controller will transfer personal data to PayPal, in particular, if a legitimate interest in the
transmission is given. The personal data exchanged between PayPal and the controller for the processing of
the data will be transmitted by PayPal to economic credit agencies. This transmission is intended for
identity and creditworthiness checks.
PayPal will, if necessary, pass on personal data to affiliates and service
providers or subcontractors to the extent that this is necessary to fulfill contractual obligations or for
data to be processed in the order.
The data subject has the possibility to revoke consent for the handling of
personal data at any time from PayPal. A revocation shall not have any effect on personal data, which must
be processed, used or transmitted in accordance with (contractual) payment processing. The applicable data
protection provisions of PayPal may be retrieved under the policy provided by PayPal.
Information we collect over Paybycal Website, Mobile Applications and Social Media
For purposes of this Statement, "website" includes our mobile application.
We may ask you for some or all of the following types of information when you
register for services, manage accounts, access various content and features or directly visit our websites.
This includes, but is not limited to:
Contact information, such as name, e-mail address, postal address, phone number
and mobile number;
User name, password, password reminder questions and password answers;
Communication preferences, such as which newsletters you would like to receive;
Search queries;
Contact information about others when you refer a friend to a particular site or
service (note: this information is used solely to facilitate requested communications); and
Information posted in community discussions and other interactive online features.
In some instances, we automatically collect certain types of information when you
visit our websites and through e-mails that we may exchange. Automated technologies may include the use of
web server logs to collect IP addresses, "cookies" and web beacons.
Social Media
You can engage with us through social media websites or through features such as
plug-ins or applications on our site that integrate with social media sites. You may also choose to link
your account with us to third party social media sites. When you link your account or engage with us on or
through third party social media sites, plug-ins, or applications, you may allow us to have ongoing access
to certain information from your social media account (e.g., name, e-mail address, photo, gender, birthday,
the posts or the 'likes' you make).
If you post information when you interact with our websites through social media
sites, plug-ins or other applications, depending on your privacy settings, this information may become
public on the Internet. You can control what information you share through privacy settings available on
some social media sites. For more information about how you can customize your privacy settings and how
third party social media sites handle your personally identifiable information, please refer to their
privacy help guides, privacy notices and terms of use.
Mobile Devices
If you access our websites on your mobile telephone or mobile device, we may also
collect your unique device identifier and mobile device IP address, as well as information about your
device's operating system, mobile carrier and your location information. We may also ask you for consent to
provide your mobile phone number (for example, so that we can send you push notifications).
Use of Personal Information
The following is a summary of the purposes for which we use personal
information. More information about the personal information collected for each of our services,
together with the purpose and legal basis for collecting the information, will be provided to you in
separate privacy notices which are relevant to the services which affect you.
Performing services for our clients
We process personal information which our clients provide to us in order to
perform our professional consultancy and training programs based on the plan selected by our client.
This may impact you, for example, where you are the employee of our client. The precise purposes for
which your personal information is processed will be determined by the scope and specification of our
client engagement, and by applicable laws, regulatory guidance and professional standards. It is the
obligation of our client to ensure that you understand that your personal information will be disclosed
to us.
Administering your engagements
We process personal information about you in order to:
- carry out "Know Your Client" checks and screening prior to starting a new activity or training;
- carry out your communication, service, billing and administration;
- deal with your complaints;
- administer sweepstakes, promotions, and contests;
- deliver coupons, newsletters, and promotions, and other information regarding the Website/Mobile
Application to you;
- Email you regarding your account or payment confirmation;
- Fulfill and manage purchases, orders, payments, and other transactions related to the Website/Mobile
Application.
Other uses
- Assist law enforcement and respond to summons;
- Compile anonymous statistical data and analysis for use internally;
- Create and manage your account;
- Enable user-to-user communications (Only for Paybycal);
- Increase the efficiency and operation of the Website/Mobile Application;
- Monitor and analyze usage and trends to improve your experience with the Website/Mobile Application;
- Notify you of updates to the Website/Mobile Application;
- Offer new products, services, website, mobile applications, and/or recommendations to you;
- Perform other business activities as needed;
- Prevent fraudulent transactions, monitor against theft, and protect against criminal activity;
- Provide information to our Representatives and advisors, including attorneys and accountants, to
help us comply with legal, accounting, or security requirements;
- Prosecute and defend a court, arbitration, or similar legal proceeding;
- Request feedback and contact you about your use of the Website/Mobile Application;
- Resolve disputes and troubleshoot problems.
If we wish to use your personal information for a purpose which is not
compatible with the purpose for which it was collected for, we will request your consent. In all cases,
we balance our legal use of your personal information with your interests, rights, and freedoms in
accordance with applicable laws and regulations to make sure that your personal information is not
subject to unnecessary risk.
Legal basis
All processing or use of your personal information is justified by a "lawful
basis" for processing. In limited circumstances, we will use your consent as the basis for processing
your personal information, for example, where we are required to obtain your prior consent in order to
send you marketing communications.
Before collecting and/or using any special categories of data, we will
establish a lawful exemption which will allow us to use that information. This exemption will typically
be:
- your explicit consent;
- the establishment, exercise or defense by us or third parties of legal claims.
Information from Children
Our website or mobile application is not directed to children and we do not
knowingly collect personal information from children on our websites. Children are prohibited from using
our website or mobile application.
Retention of Your Personal Information
How long we retain your personal information depends on the purpose for which
it was obtained and its nature. We will keep your personal information for the period necessary to
fulfill the purposes described in this Statement unless a longer retention period is permitted by law
and in accordance with the Paybycal Record Retention Policy.
In specific circumstances we may store your personal information for longer
periods of time so that we have an accurate record of your dealings with us in the event of any
complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your
personal information or dealings.
Disclosure of Information
We do not rent, sell or otherwise disclose personal information about our
online visitors with unaffiliated third parties for their own marketing use. We do not share your
personal information with third parties except in the following circumstances discussed below.
Business Partners
We disclose personal information to business partners or consultants who
provide certain specialized services to us, or who co-operate with us on projects. These business
partners operate as separate controllers, and are responsible for their own compliance with relevant
laws. You should refer to their privacy notices for more information about their practices.
Authorized Service Providers
We may disclose your information to service providers we have retained (as
processors) to perform services on our behalf (either in relation to services performed for our clients,
or information which Company uses for its own purposes, such as marketing). These service providers are
contractually restricted from using or disclosing the information except as necessary to perform
services on our behalf or to comply with legal requirements. These activities could include any of the
processing activities that we carry out as described in the above section, ‘Use of Personal
Information.’
Examples include:
- Paybycal Consultants for providing articles on nutrition plan and activity regime;
- IT service providers who manage our IT and back-office systems and telecommunications networks;
- Purchase and delivery of products and services. We use your personal information to take, handle and
fulfil orders, deliver products and services, process payments, and communicate with you about
orders, products and services, and promotional offers;
- Marketing automation providers;
- Contact center providers.
These third parties appropriately safeguard your data, and their activities
are limited to the purposes for which your data was provided.
Legal Requirements and Business Transfers
We may disclose personal information
- (i) if we are required to do so by law, legal process, statute, rule, regulation, or professional
standard, or to respond to a subpoena, search warrant, or other legal request;
- (ii) in response to law enforcement authority or other government official requests;
- (iii) when we believe disclosure is necessary or appropriate to prevent physical harm or financial
loss;
- (iv) in connection with an investigation of suspected or actual illegal activity or;
- (v) in the event that Company is subject to a merger or acquisition to the new owner of the
business.
Disclosure may also be required for company audits or to investigate a
complaint or security threat.
Sale or Bankruptcy
If we reorganize or sell all or a portion of our assets, undergo a merger, or
are acquired by another entity, we may transfer your information to the successor entity. If we go out
of business or enter bankruptcy, your information would be an asset transferred or acquired by a third
party. You acknowledge that such transfers may occur and that the transferee may decline honor
commitments we made in this Privacy Statement. We are not responsible for the actions of third parties
with whom you share personal or sensitive data, and we have no authority to manage or control
third-party solicitations. If you no longer wish to receive correspondence, emails or other
communications from third parties, you are responsible for contacting the third party directly.
Transmission of Information Collected
Our organization has its footprint across India and business across the globe and may transfer certain
personal information across geographical borders...
Security for Protection of Information
The security of your personal information is important to us and Paybycal has implemented reasonable
physical, technical and administrative security standards...
What choices do you have about your personal information?
We offer certain choices about how we communicate with our clients and what personal information we
obtain about them and share with others...
How can you update your communication preferences?
• Profile
If you have created a profile or account on one of our Mobile Application, you can update your contact
information after you log into your account.
• Newsletters
If you request electronic communications, such as an e-newsletter, you will be able to unsubscribe at
any time by following the instructions included in the communication.
• Mobile Devices
If you previously chose to receive push notifications on your mobile device from us but no longer wish
to receive them...
• E-mail
Contact us by e-mail or postal address as noted below. Please include your current contact
information...
Other rights regarding your data
Subject to certain exemptions, and in some cases dependent upon the processing activity we are
undertaking, you have certain rights in relation to your personal information...
Right to Access
You have right to access personal information which Company holds about you...
Right to Rectification
You have a right to request us to correct your personal information where it is inaccurate or out of
date.
Right to be Forgotten (Right to Erasure)
You have the right under certain circumstances to have your personal information erased...
Right to Restrict Processing
You have the right to restrict the processing of your personal information, but only where...
Right to Data Portability
You have the right to data portability, which requires us to provide personal information to you or
another controller in a commonly used, machine readable format...
Right to Object to Processing
You have the right to object the processing of your personal information at any time...
International Transfers
As noted above, you can ask to obtain a copy of, or reference to, the safeguards under which your
personal information is transferred outside India.
Other rights regarding your data
In Short: We may collect information regarding your geo-location, mobile device, push notifications,
when you use our apps...
Geo-Location Information
We may request access or permission to and track location-based information from your mobile device...
Mobile Device Access
We may request access or permission to certain features from your mobile device, including your...
Mobile Device Data
We may automatically collect device information (such as your mobile device ID, model and
manufacturer)...
Push Notifications
We may request to send you push notifications regarding your account or the mobile application...
Messages via messaging apps
We may request to send you notifications via WhatsApp and/or other messaging apps...
DO WE USE GOOGLE MAPS?
In Short: Yes, we use Google Maps for the purpose of providing better service...
Contact Us
If you have any questions, would like further information about our privacy and information handling
practices...
Grievance Officer:
In accordance with the Information Technology Act, 2000 and the Information Technology (Intermediaries
Guidelines) Rules, 2011...
Changes to this Statement
We may update this Statement from time to time...