Privacy policy

Nutribloom Health Private Limited (“Nutribloom”, “we,” “us,” or “our”), operating the ROZ Health brand and website (the “Site” or “Services”), is committed to protecting your privacy. This Privacy Policy outlines how we collect, use, share, and safeguard your personal information, in compliance with Indian law, including the Information Technology Act, 2000 and the SPDI Rules, 2011, the Consumer Protection (E-Commerce) Rules, 2020, and the principles of the Digital Personal Data Protection Act, 2023 . It also reflects industry best practices for direct-to-consumer wellness e-commerce platforms in India. By using our Site or Services, you agree to the practices described in this Privacy Policy.

1. Scope and Applicability:

This Privacy Policy applies to all users of the ROZ Health website (www.rozhealth.in), mobile applications (if any), and related services offered by Nutribloom. It governs the handling of personal data provided through online purchases, account creation, newsletters, customer support, and any other interaction with our Services. This Policy does not cover any third-party websites or services that may be linked on our Site; such external services have their own privacy policies. This Policy is published and made accessible to you in compliance with applicable Indian regulations, and provides notice of our data practices including what we collect, why we collect it, how we use it,
with whom we share it, and the measures we take to keep it secure .

2. Types of Information Collected:

We collect personal information that you provide to us, as well as data automatically collected when you use our Services. “Personal information” means any information that can identify you or be reasonably linked to you. The types of personal information we collect include:

  • Contact and Account Details: Name, email address, telephone number, shipping address, billing address, login username and password, and other registration information.
  • Order and Transaction Information: Details of the products you browse, add to cart, or purchase, order history, payment method, and transaction records. (Please note: Payment card details are processed via our secure payment gateway and we do not store your full credit/debit card numbers on our servers.)
  • Sensitive Personal Data: Certain personal data is classified as Sensitive Personal Data under Indian law (such as passwords, financial information, health or medical information, biometric data) . If you provide such data (for example, your password or any health-related information you choose to share with us), we will handle it in strict accordance with law and obtain your explicit consent for its use.
  • Communications: Any information you voluntarily provide when contacting us (such as via email, chat, or customer support inquiries), including feedback, queries, or survey responses.
  • Device and Usage Data: Technical information automatically collected when you visit our Site, including your IP address, browser type, device identifiers, operating system, referring URLs, and information about how you interact with our website (e.g. pages visited, time spent, links clicked). This may also include cookies and similar tracking data (see Cookies and Online Tracking below).
  • Cookies and Online Identifiers: We use cookies, pixels, and similar technologies that may collect unique identifiers and preferences to enhance your experience (detailed in Section 5 below).
  • We do not knowingly collect personal data from children under 18 years of age (see Children’s Privacy below). If you choose not to provide certain information (e.g. withholding mandatory details for an order), we may not be able to fulfill your request or provide the related Service.

3. Lawful Purposes of Use:

We only collect and use your personal information for purposes that are lawful and necessary to provide you with our products and services, or as otherwise permitted by law. The primary purposes for which ROZ Health uses personal data include:

  • Order Fulfillment and Service Delivery: To process your orders and transactions, provide the products or services you requested, manage payments, execute shipping and deliveries, process returns or exchanges, and provide you with an efficient shopping experience.
  • Account Management and Customer Support: To create and maintain your user account, authenticate you upon login, communicate with you about your orders or inquiries, provide customer service, handle grievances or returns, and send important service-related notices (such as order confirmations, shipping updates, or changes to our terms or policies).
  • Personalization and Improvement of Services: To remember your preferences (such as items in your cart or wishlist), recommend products relevant to your wellness needs, personalize content on our Site, conduct analytics on usage patterns, and improve the
    functionality, quality, and user-friendliness of our website and product offerings. This helps us refine our formulas, content, and user interface to better serve you.
  • Marketing and Promotional Communications: To send you promotional emails, newsletters, or SMS messages about new products, special offers, or wellness content that may interest you, only if you have consented to receive such marketing. We may tailor these communications based on your past purchases or browsing behavior. You can opt-out of marketing communications at any time (see Section 10 on your rights).
  • Security and Fraud Prevention: To ensure the integrity and security of our platform, we may use data to monitor for and prevent fraudulent transactions, unauthorized account access, misuse of our Site, or other illegal activities. This includes using certain data for identity verification, risk assessment, detecting security incidents, and protecting against harm to the rights or safety of our customers, our company, or the
    public.
  • Legal Compliance: To comply with our legal and regulatory obligations under Indian law. For example, we may process and retain transaction records for tax and accounting requirements, use personal data to meet lawful requests by government authorities, or disclose information as necessary to comply with court orders or to exercise or defend legal claims. We will use your data for these purposes only as allowed by applicable laws.

We will not use your personal information for any purpose that is incompatible with the original purposes described above without obtaining your consent or as required/allowed by law. We ensure that any new use of your data would be disclosed to you through an updated notice or Policy.

4. Legal Basis for Processing and Consent Framework:

We process personal data under the legal bases permitted by Indian law, primarily with your consent or as necessary to provide you the requested services. Our processing frameworks include:

  • Consent: In most cases, we rely on your consent to collect and use your personal data. Your consent will be obtained through clear affirmative action – for example, by you ticking a checkbox or clicking “I Agree” to this Policy or by submitting your information for a specified purpose . We ensure that any consent you give is free, informed, specific, and unambiguous, and we only collect data that is necessary for the stated purpose . For sensitive personal data (such as financial details or health information), we will expressly seek your consent (which may be written or electronic) before collection and use, as required by the SPDI Rules . You have the right to withdraw your consent at any time. If you withdraw consent, we will stop processing
    the data for which consent was given, provided there is no other legal ground that permits us to continue such processing. (Please note that withdrawal of consent will not affect the lawfulness of processing done prior to such withdrawal.)
  • Performance of a Contract (Deemed Consent): When you provide personal data in the context of using our Services – for example, entering your name and address to place an order – such provision of data is treated as voluntary and for the purpose of fulfilling your request. In these cases, separate consent may not be required as the processing is necessary to perform our contract with you or to take steps at your request before entering into a contract. We will process your information to fulfill the transaction (such as selling and delivering a product you ordered) and this is considered a lawful basis under the “deemed consent” or “legitimate use” provisions of the DPDP Act.
  • Legal Obligation: We may process personal data without your consent where such processing is required for compliance with a legal obligation. For instance, responding to law enforcement requests, regulatory requirements, or court orders; retaining invoice data for audit/tax purposes; or fulfilling duties under consumer protection laws.
    In doing so, we only process the data to the minimal extent necessary to meet those obligations.
  • Vital Interests and Public Interest: Although unlikely in the context of our e-commerce operations, if there is ever a situation where processing your data is necessary to protect your vital interests (e.g. to warn you of an urgent product safety issue) or for some public interest or as required by government authorities, we may do so as permitted by law. The DPDP Act and other laws recognize certain specific
    circumstances (such as prevention of crime, medical emergencies, etc.) where processing can occur without consent . We will always ensure such processing is lawful and limited to the applicable purpose. We do not engage in any processing of personal data that is unlawful or discriminatory. All collection and processing is done in good faith and for the legitimate purposes disclosed. We also do not employ pre-ticked boxes or default consents – any optional data processing (such as for marketing cookies or newsletters) will only be done with your active consent (no “implied” consent by silence). If you choose not to provide certain personal information or withdraw consent, we respect your choice – however, we may be unable to provide certain services or complete an ongoing transaction (for example, we cannot deliver an order without a shipping address). We will inform you of such consequences at the time you opt out or withdraw consent.

5. Cookies and Online Tracking Technologies:

Like most online platforms, we use cookies and similar tracking technologies to collect information automatically when you interact with our Site. Cookies are small text files placed on your device (computer, smartphone, etc.) that help us recognize you and remember your preferences. We use cookies for several reasons, as outlined below:

  • Strictly Necessary Cookies: These cookies are essential for the operation of our website and enable core functionality. For example, they allow you to add products to your cart, proceed to checkout, and ensure your session is secure. Without these cookies, services you have asked for (such as making a purchase or logging into your
    account) cannot be provided. These cookies do not require consent as they are necessary for our Site to function properly.
  • Functional (Preference) Cookies: These cookies allow our Site to remember choices you make (such as your login details, region, or language preferences) and provide enhanced, more personalized features . They improve your experience by retaining your settings so you don’t have to re-enter information each time. While functional
    cookies are not strictly necessary, they enable convenient features like staying logged in or remembering your cart. We inform users of these cookies, and by using the Site you agree to their use. In cases where these cookies store personally identifiable information, we will treat that information as personal data per this Policy.
  • Analytics and Performance Cookies: We use analytics cookies (often from third-party providers like Google Analytics) to understand how users interact with our website, which pages are visited, time spent on pages, and any issues users encounter . These cookies collect information such as your device’s IP address, pages visited, and usage
    patterns. This data is aggregated and does not directly identify you. Analytics cookies help us improve our website design, features, and content by analyzing usage data and website traffic. For example, they can tell us which product categories are most popular or if users experience errors on certain pages. While these cookies may not
    collect sensitive personal data, we disclose their use and, where required, we will obtain your consent before deploying certain analytics cookies.
  • Advertising and Marketing Cookies: We may allow certain third-party cookies (e.g., Facebook Pixel or Google Ads cookies) to be placed on your device to collect information about your browsing behavior and purchasing history . These marketing or tracking cookies build a profile of your interests and allow us or our advertising partners to show you relevant ads on our Site or across other websites you visit. For
    example, if you viewed a particular supplement on our Site, you may later see an advertisement for that product on another website – this is enabled by marketing cookies. These cookies can track your online activities across multiple sites and are often third-party cookies set by our marketing partners. We will obtain your explicit consent for any advertising cookies or similar tracking technologies that are not strictly
    necessary, in line with regulatory requirements and industry best practices . You have the choice to allow or block such cookies via the cookie consent banner (if applicable) or through your browser settings.
  • Other Tracking Technologies: In addition to cookies, we may use pixel tags, web beacons, or device fingerprinting techniques in our emails or on the Site. For example, our marketing emails might contain a tiny invisible image (pixel) that tells us if you opened the email. This helps us gauge the effectiveness of our communications. Such tracking will only be used to the extent permitted by law, and you can disable image
    loading in your email if you do not wish to be tracked in this way.
  • Your Choices: When you first visit our Site, you may be presented with a cookie notice or banner seeking your preferences. You can choose to accept all cookies or manage your cookie settings to block non- essential cookies. Even after consenting, you can modify your browser settings to refuse or delete cookies. Most modern browsers allow you to block third-party cookies or alert you when a cookie is being set. Please note that if you disable certain categories of cookies (especially necessary or functional cookies), some features of our Site may not function correctly. Refer to your browser’s help documentation for instructions on deleting or disabling cookies. For targeted advertising cookies, you may also opt-out using industry tools such as the Network Advertising Initiative (NAI) opt-out page or your device settings where available.

We do not presently respond to “Do Not Track” signals, and there is no uniform technological standard for such signals. However, we give you robust choices as described above to control cookies and trackers. Any use of cookies or tracking data will be consistent with this Policy and applicable laws on online privacy.

6. Data Sharing and Third-Party Processors:

We value your privacy and do not sell your personal information to third parties for their own use. However, in the course of running our business and providing services to you, we share your information with trusted third parties under strict conditions and only for legitimate purposes. The categories of third parties with whom we share data (and the purpose of sharing) include:

  • Service Providers (Processors): We employ other companies and individuals to perform functions on our behalf. These third-party service providers act under contractual instructions from us and include, for example:
  • E-commerce Platform Provider: Our Site is hosted on the Shopify platform, which provides us with the online storefront and related infrastructure. Information you provide (such as account details, orders, and payment info) is transmitted to and may be stored on Shopify’s secure servers to enable our Services . Shopify acts as a data
    processor for us and is bound by privacy and security obligations.
  • Payment Processors: For handling payments, we use secure third- party payment gateways such as Razorpay. When you enter your card or UPI details at checkout, that information is securely transmitted directly to Razorpay (which is PCI-DSS compliant) and not stored on our systems. Razorpay processes your payment and confirms the
    transaction with us. We share with Razorpay the necessary order identifiers and billing info to link your payment. These payment providers are obligated to use your data only for payment processing and comply with applicable data protection and security standards.
  • Shipping / Logistics Partners: To deliver your orders, we share your relevant personal details with our courier/delivery partners such as Delhivery. This includes your name, contact number, shipping address, and order details needed to pick, ship, track, and deliver the product to you. Our logistics partners act on our instructions and are not permitted to use your information for any purpose other than facilitating the
    shipment and delivery.
  • Marketing and Analytics Partners: We may use specialized vendors to help us with marketing campaigns, advertising, analytics, or website optimization. For instance, we might use Google Analytics (as mentioned in Cookies) to analyze site traffic, or social media advertising partners (like Facebook/Instagram) to show you relevant ads. Additionally, our branding and digital marketing agency, Summer Owl Studio, may have access to certain user data as needed to design our website, manage content, or run marketing campaigns. Importantly, Summer Owl Studio does not store or retain your personal data beyond what is necessary to perform the tasks we have engaged them for. They use the information strictly to carry out our instructions (such as designing personalized email campaigns or website graphics) and are contractually bound to maintain confidentiality and data security. We ensure that any marketing/analytics partners only receive anonymized or aggregated data wherever possible, and if any personally identifiable data is shared, they are obligated to process it only for our specified purposes and not for their independent use.
  • IT and Cloud Service Providers: We may store your information on cloud servers or use IT service providers for data storage, backup, or software support. These providers (for example, cloud infrastructure companies or email service platforms) may process data on our behalf purely for storage or technical support functions. We choose reputable providers with strong security practices, and wherever feasible, we host data on servers located in India. If any data is stored on servers outside India, we ensure it is subject to equivalent security safeguards (see International Transfers below).

In all cases above, we disclose only the minimum information necessary for each third party to perform their function. We have contracts or data processing agreements in place with each of these service providers, obligating them to protect your data to the same standards that we do and to use it only for the specific services they provide us. They cannot use your data for any other purpose. We also require that they implement adequate security measures to safeguard your information.

  • Affiliates and Corporate Group: We may share your information with our affiliates, subsidiaries, or parent company (if any) as part of our corporate group operations. Any such entity will process your data in line with this Policy and at the same level of care. Currently, ROZ Health is a brand of Nutribloom Health Pvt. Ltd., and any intra-group sharing would remain under Nutribloom’s control for internal administrative purposes.
  • Legal and Regulatory Disclosures: We may disclose personal information to government authorities, regulatory bodies, or other third parties if required by law or legal process . For example, we may respond to a court order, subpoena, or law enforcement request by providing the requested data. We may also disclose information if necessary to enforce our Terms & Conditions or to protect our rights, privacy, safety, or property, or those of our customers or others. In such cases, we will ensure the disclosure is made only to the extent lawfully required or permitted, and we will document any such disclosure.
  • Business Transfers: In the event that our business (or a portion of it) undergoes a merger, acquisition, restructuring, financing, or sale of assets, your personal information may be transferred to the successor or acquiring entity as part of the transaction. Should such a transfer occur, we will ensure that the new owner will continue to handle your data in accordance with this Privacy Policy (or you will be given notice and an opportunity to consent to any changes). Your information would remain subject to appropriate confidentiality and security obligations even in such a scenario.
  • We want to reassure you that any third party with whom we share data is carefully vetted. We do not share personal data with any external parties except as outlined above or with your explicit consent. In particular, we do not share your data with any third-party marketers or advertisers for their own independent use without your consent. All third parties are either bound by contractual privacy clauses or are subject to statutory obligations to protect personal data. For sensitive personal data or information, we will not disclose it to any third party without your prior permission, unless the disclosure is agreed upon as part of the service contract (for example, sharing payment details with Razorpay is part of the payment service contract) or where disclosure is required for legal compliance. Government agencies may receive information without your consent only if mandated by law, and even then, such agencies are typically required to use the information for the stated legal purpose and not disclose it further.

In summary, we limit data sharing strictly to what is necessary and ensure your
data remains protected in the hands of those third parties. If you have questions
about any specific third party that may have access to your data, you may contact
us for more information.

7. International Transfers:

At present, Nutribloom primarily operates within India and we strive to store and process personal data on servers located in India. However, some of our service providers or affiliates may be located in or use servers in other countries. For example, if we use a global cloud hosting service or an email delivery service, your data might be stored or processed on servers outside India. Whenever we transfer your personal data outside the territory of India, we will do so in accordance with applicable data protection laws. The Digital Personal Data Protection Act, 2023 permits the cross-border transfer of personal data to most countries, except to certain countries that may be specifically restricted by the Indian government . We will ensure that we do not transfer your personal data to any country or entity that is not allowed under Indian law. If the Government of India notifies a list of jurisdictions as “restricted” or “not whitelisted” for data transfers, we will refrain from transferring your data to those jurisdictions, or will put in place government- approved safeguards if required. For any transfer of personal data (especially sensitive personal data) to a third party located in another country, we will ascertain that the recipient entity provides a level of data protection comparable to the standards under Indian law . In practice, this means we
may use safeguards such as contractual clauses (ensuring the foreign recipient is contractually bound to protect your data per our standards), technical measures (encryption in transit and at rest), and due diligence on the recipient’s security certifications (for example, compliance with internationally recognized security standards like ISO/IEC 27001). Our goal is to ensure that your data remains secure and your privacy rights are maintained regardless of where the data is processed. If we transfer data internationally, we remain accountable for its protection. Typical scenarios of international transfer may include backup servers located abroad or support teams (working for our service providers) accessing data remotely. In all cases, we limit such access and transfers to the necessary minimum and under strict supervision.

You acknowledge that by using our Services and providing your information, you consent to the potential transfer, storage, and processing of your information outside of India as described in this section. That said, we will not transfer your data in a manner that contravenes the DPDP Act’s provisions or other Indian data transfer regulations . If in the future India imposes additional requirements for cross-border transfers (such as specific contractual terms or government approvals), we will comply with those as well. Should you require more details on cross-border data transfer mechanisms or where your data may be stored, please contact us using the details in Section 13 and we will be happy to provide additional information consistent with security requirements.

8. Data Security and Storage Practices:

We take the security of your personal information very seriously. In line with the Information Technology Act, 2000 and applicable rules, as well as international best practices, we have implemented a range of technical and organizational measures to protect your data from unauthorized access, loss, misuse, alteration, or destruction . While no system can be guaranteed to be 100% secure, we follow “reasonable security practices and procedures” as required by law to safeguard your information . Our security measures include:

  • Encryption: Our website is secured using industry-standard SSL/TLS encryption. This means that any data you submit on our Site (such a personal details or payment information) is encrypted in transit and cannot be easily intercepted by third parties . You can verify you are on a secure page by checking that the URL begins with “https://” and looking for a padlock icon in your browser’s address bar. Additionally, sensitive data (like passwords) is stored in encrypted or hashed form in our databases, adding an extra layer of protection in case of any unauthorized access.
  • Secure Servers and Infrastructure: We store personal data on secure servers that are protected by firewalls and other advanced security technologies. We use reputable hosting providers (such as Shopify’s infrastructure and/or cloud service providers) that employ robust security certifications and protocols. Access to these servers is restricted to authorized personnel only, and we ensure regular security patches and updates are applied to prevent vulnerabilities.
  • Access Controls: Internally, we follow the principle of least privilege. Only a limited number of authorized employees, who need the information to perform their job duties (for example, the customer support team or IT administrators), have access to personal data. Our staff are trained on confidentiality and data protection practices. All access to personal data is logged and monitored. We also implement authentication safeguards (strong password policies, two-factor authentication where applicable) to prevent unauthorized account access.
  • Payment Security: For online payments, as noted, we use PCI-DSS compliant payment gateways (like Razorpay). Your financial details are handled through secure, encrypted channels and processed by these certified entities. We do not store your credit/debit card numbers or CVV on our systems (aside from possibly the last 4 digits or a transaction token for reference). This approach ensures that highly sensitive financial information never traverses our servers in an unsecure manner.
  • Device and Application Security: Our website and apps (if any) undergo regular testing for security weaknesses, including vulnerability assessments and penetration testing by qualified experts. We use secure coding practices in development. We also employ anti-malware, intrusion detection systems, and continuous network monitoring to detect and respond to any suspicious activities.
  • Organizational Policies: Nutribloom has adopted an internal information security policy consistent with Rule 8 of the SPDI Rules. We maintain an information security program and periodically review our security measures to keep up with evolving threats. We may also obtain internationally recognized security certifications or align with standards such as ISO 27001, as appropriate for our scale and operations, to demonstrate our commitment to data protection. Our employees are required to adhere to confidentiality obligations and any breach of data or security protocols by staff results in disciplinary measures.
  • Data Minimization: As part of our security approach, we practice data minimization – we only collect the personal data that we truly need for the stated purposes, and we restrict access and retention of that data as described in Section 9 (Data Retention). By limiting the volume and duration of personal data stored, we reduce the risk exposure of your data.
  • Third-Party Security: When we share data with third-party service providers (Section 6), we ensure through contracts that they also implement adequate security measures. We perform due diligence on key partners to verify their security postures. For example, our cloud providers and processors must demonstrate compliance with security standards and we include data protection clauses in our agreements. If a third party cannot guarantee the required level of protection, we will not share data with them.

Despite our rigorous efforts, it is important to understand that no method of transmission over the internet, or method of electronic storage, is completely secure. We therefore cannot guarantee absolute security of your information. There is always a possibility, however minimal, of a security breach or data incident. We continuously update and test our security protocols to mitigate such risks. Your Responsibility: You also play a role in keeping your data secure. We urge you to maintain the confidentiality of your account credentials and not share your ROZ Health account password with anyone. Use a strong, unique password for our Site and change it periodically. If you suspect any unauthorized access to your account or any other security breaches, please notify us immediately so we can assist. Also, please be cautious of phishing attempts – ROZ Health will never ask for your password via email or phone. Only enter your login details on our official site (rozhealth.in) and ensure the website is genuine.

We are committed to protecting your personal data and have invested in appropriate resources to do so . In the unlikely event of a data breach, we have a response plan in place as outlined in Section 12 (Data Breach Notification). We also periodically review and upgrade our security measures as new technologies and threats emerge, to ensure continued protection of your data.

9. Data Retention Periods:

We will retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Policy, unless a longer retention period is required or permitted by law. We adhere to the principle of storage limitation: once your personal data is no longer needed for the lawful purpose it was collected, we will securely delete or anonymize it.

Our retention criteria depend on the nature of the data and the purposes of processing:

  • Account Information: If you create an account on our Site, we will retain your account data (such as your name, contact info, login credentials, order history) for as long as your account remains active. If you choose to close your account or if your account remains inactive for an extended period, we will delete or anonymize the account data within a reasonable time after account closure/inactivity, except for any information we are required to retain for legal reasons (such as past transaction records). We may retain a skeleton record of your account (name, email, and basic details) in our suppression list to ensure we do not inadvertently contact you after account deletion, and to honor your opt-out requests.
  • Purchase and Transaction Records: We retain data related to your orders and purchases for as long as necessary to complete the transaction and provide after-sale support (returns, refunds, warranty, etc.). After that, we may need to keep certain transaction records for a longer period to comply with legal and financial obligations – for example, tax, audit, and accounting laws may require retaining sales records and invoices for a certain number of years. Typically, financial records are kept for 7-10 years as required by Indian tax regulations. During this retention period, your transaction data will be stored securely and accessed only on a need-to-know basis (e.g., for audits or legal queries). We will not use it for any new marketing purposes after the initial purpose is fulfilled.
  • Customer Service Communications: If you contact us via email, chat, or phone, we may retain those communications and any attachments or notes for as long as necessary to address your query or complaint, and for a short period thereafter in case of follow-ups. Generally, routine customer service records are kept for approximately 1-2 years unless needed longer for a specific issue. If a communication leads to a legal claim or complaint resolution, we may retain relevant information for the applicable statutory limitation period.
  • Marketing Data: If you have consented to receive marketing communications (newsletter, promotions), we will retain the minimal contact information necessary (e.g., email address and preference info) until you unsubscribe or withdraw your consent. Upon opt-out, we will promptly remove you from marketing lists (usually within a few days of your request) and will keep your contact on a suppression list indefinitely to ensure we do not accidentally send you further marketing. Other analytics data used for marketing (like cookie identifiers) are retained as per the cookie’s lifespan or until you clear those cookies. Advertising data is often aggregated or anonymized; any identifiable data for targeted advertising is typically stored for shorter durations per our agreements with advertising partners.
  • Automated Logs and Analytics: Web server logs, device identifiers, and analytics datasets are usually retained for a short period (often 30 days to a few months) unless used for security analysis. For example, IP addresses in security logs might be kept for a few months to investigate suspicious access. Analytics providers like Google may keep aggregated data for longer, but that data is not personally identifiable beyond the retention period of user-level data (which we configure to minimal required, e.g., 14 months for Google Analytics user-level retention unless otherwise mandated).
  • Legal Compliance and Disputes: Notwithstanding the above, we may retain information for a longer period if required to do so by law or if it is needed for resolving any legal disputes or enforcing agreements. For instance, if we are involved in litigation or a regulatory investigation, we will preserve relevant data until the matter is resolved and no further appeal is possible. Similarly, certain data may be retained to enforce our Terms & Conditions or to prevent fraud and protect our legal interests. However, even in such cases, we will not retain personal data indefinitely. We regularly review the data we hold, and if retention is no longer justified, we securely erase it.
  • After the expiry of the applicable retention period, or upon your request (where applicable law allows deletion), we will proceed to delete or anonymize your personal data. “Deletion” involves removing the data from our active databases in a secure manner. We may continue to store information in backups for a short additional period (backup systems can take some time to purge) – during this time, your data remains protected and isolated. Anonymization means we alter the data so that it can no longer be associated with you (for example, aggregating and removing personal identifiers). Anonymized data may be retained and used for statistical or analytical purposes without further notice to you, since it no longer constitutes personal information.

In summary, we do not retain personal data longer than necessary for the purpose of
its collection or as required under law . Our retention practices are designed to meet
legal obligations and business needs while respecting your privacy. If you have
specific questions about how long we keep a particular type of data, feel free to
reach out to us (see Section 13) and we will provide guidance tailored to your query.

10. Rights of Data Principals:

As a user of our Services (a “data principal” under the DPDP Act), you have certain rights regarding your personal data. We are committed to honoring your rights and have processes in place to enable you to exercise them. Subject to applicable laws and certain exceptions, your rights include:

  • Right to Access / Confirmation: You have the right to request confirmation of whether we process any personal data about you, and to access the personal information we hold about you . Upon verification of your identity, we will provide you with a copy of your personal data that we have in our records, along with details on how we use it, whom we share it with, and how long we intend to retain it (as required by law). This enables you to know what information we have collected and ensures transparency.
  • Right to Correction / Rectification: If any of your personal data we hold is inaccurate, incomplete, or outdated, you have the right to request that we correct or update it . For instance, if you change your phone number or notice we have a wrong spelling of your name, you can ask us to rectify it. Most basic information can also be corrected by you directly by logging into your account profile on our Site. We encourage you to keep your information current, and we will comply with correction requests promptly, after necessary verification. In some cases, we may ask for documentation to validate the new information (for example, proof of a name change) if required.
  • Right to Deletion / Erasure: You have the right to request deletion of your personal data that we hold, in certain circumstances . If you no longer want us to have your information, you can ask us to remove it. We will evaluate such requests on a case-by-case basis and delete your data if: (a) the data is no longer necessary for the purpose it was collected; (b) you withdraw consent and we have no other legal basis to continue processing; (c) we collected or used the data unlawfully; or (d) erasure is required to comply with a legal obligation. Please note that we may decline or delay deletion where retention is required by law or for legal claims (as explained in Data Retention). For example, we cannot delete your past transaction records immediately if we are required to maintain them for tax compliance, but we will isolate and protect such data until it can be deleted. When we delete personal data, we will also inform our processors (like Shopify, etc.) to delete the data from their systems.
  • Right to Data Portability: As part of our commitment to user rights, you may request a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format, and you have the right to have that data transmitted to another data controller, where feasible . In practical terms, upon your request, we can provide you with a digital file containing your basic personal information and transaction history that you provided, so that you could, for instance, port it to a competing service. This right is subject to technical feasibility and applies to data processed by us through automated means, and not to data that is created by us (like internal analytics). While Indian law does not currently mandate data portability as a right, we support the principle of data portability for user convenience and will honor such requests in good faith where possible.
  • Right to Withdraw Consent: Where we rely on your consent to process personal data (for example, for sending marketing emails or for using certain cookies), you have the right to withdraw that consent at any time. You can opt out of marketing communications by using the “unsubscribe” link in our emails or by contacting us directly. For cookies, you can adjust preferences as explained in Section 5. Withdrawal of consent will not affect processing already carried out but will stop the future processing of the data in question. For instance, if you withdraw consent for marketing, we will cease sending you promotional materials going forward.
  • Right to Opt-Out of Marketing and Manage Communication Preferences: Even if you do not fully withdraw consent for all processing, you have the right to opt out of specific uses of your data. The most common example is opting out of direct marketing. We will always respect an opt-out request. You can manage your communication preferences in your account settings or by reaching out to us. If you opt out of marketing messages, we will still send you transactional or service messages as needed (e.g., order confirmations, updates about your purchases, or policy changes), since those are not promotional but rather part of our contractual obligations.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your data rights . This means we will not deny you services, charge you different prices, or provide a different quality of service just because you exercised your privacy rights. Your data rights are important to us and we treat all users equally regardless of their privacy choices. However, note that if you request deletion of essential data or withdraw consent for processing necessary to provide our Services, we may be unable to continue providing you certain services (for example, if you delete your account data, you cannot continue to have an account with us). Such consequences will be explained to you, but this is not discrimination; it’s simply a result of you no longer
    allowing us to process data that is required for service.
  • Right to Grievance Redressal: Under Indian law, you have the right to have your grievances or complaints addressed in a timely manner by us. We have appointed a Grievance Officer (Section 13) specifically for this purpose. If you believe your data rights have been infringed or have any concerns about our data practices, you can file a grievance with our Grievance Officer. We will acknowledge and resolve your complaint expeditiously, typically within 30 days as mandated . If you are not satisfied with the resolution, you may have further recourse such as appealing to the Data Protection Board of India or other authorities once the DPDP Act is fully in force. (More details on our grievance mechanism are in Section 13.

To exercise any of your rights, you may log into your account (for self-service options like edit or download data where available) or contact us using the contact details provided in Section 13 (Grievance Officer and Contact Details). Please specify which right you wish to exercise and the scope of the request (for example, if you request access, let us know what information in particular, if any, you are seeking beyond general account data). For security reasons and to prevent unauthorized access, we will need to verify your identity before fulfilling your request . Verification may include confirming details we already have on file or requesting a government ID in certain cases. We will only use this verification data to authenticate your request. In some cases, we might deny or limit a request if a law requires us to do so or if the law permits us to retain data. For example, if you request deletion of data that we are legally required to keep, we may decline deletion but will inform you of the reason. Or if a request is manifestly unfounded or excessive (especially if repetitive), we may either charge a reasonable fee or refuse to act on it, as allowed by law. We will
always inform you of the outcome of your request and the reasons if we cannot fully comply.

We aim to respond to all valid requests within a reasonable timeframe, and in any event within the timeline prescribed by applicable law (currently, under SPDI Rules, within 30 days for grievances; under DPDP Act, timelines will be prescribed for confirmation and redressal – we anticipate responding within approx. 30 days for most rights requests). If we need more time (for example, if the request is complex or we have a high volume of requests), we will let you know the reason for the delay and may extend the time as permitted.

Finally, you also have the right to lodge a complaint with the appropriate data protection authority or consumer protection authority if you believe we have violated your privacy rights. Since the DPDP Act enforcement is pending, such complaints in India may currently be directed to bodies like the Data Protection Board (once established) or courts. However, we encourage you to allow us to address your concerns first through our internal grievance redressal mechanism. We are committed to resolving any issues in a fair and transparent manner.

11. Children’s Privacy:

Our Services are not intended for use by children or minors below the age of 18 years. ROZ Health is a platform targeted at adult consumers for wellness products, and we do not knowingly solicit or collect personal information from individuals under 18 years of age. If you are under 18, you may use our Site only with the involvement and consent of a parent or legal guardian. We do not sell products for purchase by children; any products for minors must be purchased by adults.

We do not have an age verification mechanism at sign-up; therefore, we operate on the assumption that users of our Site are adults or have obtained necessary parental consent. We explicitly do not wish to collect data from anyone under 18, and we ask that minors do not provide any personal information to us. If you are a parent or guardian and believe that your child (under 18) has provided us with personal information without your consent, please contact us immediately at our Grievance Officer email (see Section 13). We will take prompt steps to delete the child’s information from our records and refrain from using it, in accordance with applicable law.

In the event that we inadvertently collect personal data from a child (for example, if a teenager places an order and we are unaware of their age), we will delete that data as soon as we identify the situation. If deletion is not feasible for specific reasons (such as if it’s kept in backup systems), we will ensure that such data is not used or disclosed further and is deleted as soon as possible.

We also ensure that any content on our Site that could be of interest to younger audiences (like general wellness education) is still directed at a general audience. We do not engage in any profiling or behavioral advertising directed at children. In fact, the DPDP Act prohibits certain types of processing for children, such as behavioral monitoring or targeted advertising. We fully adhere to such principles. We do not knowingly allow third-party advertising networks to collect information about the behavior of minors on our Site, and we do not serve personalized ads to known minors. If in the future we decide to provide services tailored to children or collect
information from minors (for example, a potential wellness program for teens), we will do so in strict compliance with Indian laws – which would likely involve obtaining verifiable parental consent before collecting any data from children and providing clear notices. As of now, we have no such plans, and our policy is to avoid any data processing of children’s data knowingly. To summarize, by using ROZ Health’s Services, you represent that you are at least 18 years old or are using the Services under the supervision of a parent/guardian. Protecting children’s privacy is important to us, and we abide by all applicable laws aimed at shielding minors from data exploitation. If you have any concerns about children’s data in context of our Services, please reach out to us.

12. Data Breach Notification:

While we strive to protect your personal data with robust security measures, we acknowledge that data breaches can happen despite best efforts. A data breach could involve unauthorized access, loss, destruction, or disclosure of personal data. We have put in place a comprehensive Data Breach Response Plan to deal with such incidents, in line with legal requirements and best practices.

In the unfortunate event of a data breach that is likely to result in a risk to your rights and freedoms or cause harm to you, we will notify you and the appropriate authorities as required by law . Our approach to breach notification is as follows:

  • Internal Reporting: The moment we become aware of a suspected personal data breach, our internal incident response team will be mobilized. We will contain the breach, secure our systems to prevent further unauthorized access, and assess the scope and impact of the breach (i.e., what data was affected, how many individuals, and the likely consequences).
  • Notification to Authorities: If the breach is of significant severity (for example, involving Sensitive Personal Data or a large number of users), we will notify the Indian Computer Emergency Response Team (CERT-In) as required under IT Act rules and any sectoral regulators as applicable. Additionally, under the DPDP Act, we are required to notify the Data Protection Board of India of such breaches . We will follow the form and timeline for notification as prescribed by the government or the Data Protection Board once those rules are in effect. Typically, CERT-In rules currently mandate notification of certain types of breaches within 6 hours of noticing the incident, and we will comply with such timelines. The breach notification to authorities will include details of the nature of personal data compromised, the number of individuals affected, likely consequences, and the measures we have taken or plan to take to mitigate the breach.
  • Notification to Users: If the breach is likely to result in a real risk of harm to you (such as financial loss, identity theft, significant embarrassment, or physical harm), we will also inform you without undue delay. We will reach out via at least one communication channel (e.g., email or phone) that we have on record for you. The notification will describe, in clear terms, the nature of the breach and the compromised data, recommendations for you to protect yourself (for example, resetting passwords or being vigilant against phishing), and our contact details for further information. We will also outline the remedial actions we are taking to address the breach (such as securing
    our systems and preventing further incidents).
  • Public Communication: If individual notification is overly burdensome or impractical (for example, if the affected users are very numerous and we lack up-to-date contact info), we may make a public announcement of the data breach via our website and/or major media outlets, as an alternative means, as permitted by law. This will ensure all affected users are made aware in a timely manner.
  • Remedial Measures: Following a breach, beyond notifications, we will do everything in our capacity to mitigate the impact. This could involve helping users to reset credentials, coordinating with financial institutions (if payment data was involved) to monitor or halt fraudulent activities, and offering credit monitoring services to affected users if appropriate. Internally, we will investigate the root cause and implement measures to prevent similar incidents (patching systems, changing processes, training staff, etc.). We will also maintain records of the breach, our response, and improvements made.

We recognize that under the DPDP Act, there may be specific rules detailing the “form and manner” of reporting breaches to the Data Protection Board and possibly to users . We will adhere to those rules once they are effective. Our policy is to err on the side of transparency: if your personal data is compromised, we want you to hear it from us directly and promptly, along with guidance on next steps. It’s important to note that not all security incidents will merit a notification. For instance, if a laptop is lost but the data on it was encrypted and we have no evidence that anyone accessed the data, we may determine that the risk to individuals is low and a formal notification is not needed. However, we will still log the incident and our rationale in our internal records. We will always comply with the notification thresholds set by law. By keeping our systems secure and up-to-date (Section 8), we aim to minimize the likelihood of breaches. However, we want you to feel confident that if something does go wrong, we will be forthright and proactive in addressing it and keeping you informed. Data breach handling is both a legal obligation and an ethical one for us, aligned with building trust with our customers.

13. Grievance Officer and Contact Details:

We have appointed a Grievance Officer to address any questions, concerns, or grievances you may have regarding this Privacy Policy or the processing of your personal data. This is in compliance with Rule 5(9) of the SPDI Rules which requires us to designate an officer for redressing user grievances in a time-bound manner , as well as the Consumer Protection (E-Commerce) Rules, 2020 which mandate a grievance mechanism for consumers. Our Grievance Officer is your primary point of contact for any privacy-related issues or complaints.

  • Grievance Officer:
    Name: [To be Designated]
    Title: Grievance Officer – Data Protection, Nutribloom Health Pvt. Ltd.
    (ROZ Health)
    Email: contact@rozhealth.in
    Postal Address: Nutribloom Health Private Limited, Aarohi Complex,
    AEC Char Rasta, University Area, 4th Floor, Ahmedabad, Gujarat –
    380009, India
    Contact Number: +91 93135 95923

You may contact the Grievance Officer by email or post. We recommend email for quicker correspondence. Please include in your communication: your name, contact information, and a detailed description of your grievance or question. If you are lodging a complaint, please provide any relevant information or evidence (such as screenshots or order numbers) that can help us understand and resolve the issue. Grievance Redressal Process: Upon receipt of your grievance, the Grievance Officer will acknowledge the complaint (generally within 48 hours, as per e-commerce rules best practice). We will then investigate the matter, which may involve retrieving logs, speaking to relevant internal teams, and reviewing applicable policies or laws. The Grievance Officer will provide you with a substantive response or resolution expeditiously and in any case within one month from the date of receipt of the grievance . We aim to resolve issues much sooner than that, but commit to the one-month outer limit as per law. If the issue is complex or requires input from third parties, we will keep you informed of the progress. For example, if your grievance is about a correction request that was not properly handled, the Grievance Officer will ensure your data is corrected and confirm the same to you. If it’s about a suspected misuse of your data, we will investigate and inform you of our findings and any remedial action taken. If it’s a general query about our privacy practices, we will clarify and answer your questions.

If you are not satisfied with our response or if you do not receive a response within the stipulated time, you have the right to escalate the matter. Under the upcoming DPDP regime, you may be able to file a complaint with the Data Protection Board of India. Additionally, consumers have recourse to consumer courts or other dispute resolution forums under Consumer Protection laws if the matter pertains to deficiency in services. We truly hope it never comes to that, as our priority is to resolve your concerns directly and amicably.

Other Contact Information: For general inquiries unrelated to privacy (like product or order questions), you can reach our customer support at hello@rozhealth.in or through the “Contact Us” page on our Site. We keep our privacy-specific contact (contact@rozhealth.in) separate to ensure that privacy queries are attended to by the Grievance Officer with priority. Please note that the Grievance Officer is based in India and is available during regular business hours (Indian Standard Time). Communications received on weekends or public holidays will be responded to as early as possible on the next business day.

We encourage you to reach out without hesitation if you have any concerns about your privacy or data security in relation to ROZ Health. Your trust is of paramount importance to us, and we believe that an open dialogue is key to maintaining that trust.

14. Governing Law and Dispute Resolution:

This Privacy Policy and any issues or disputes arising from it or related to your personal data will be governed by and construed in accordance with the laws of India. We operate in compliance with Indian privacy and data protection regulations, and by using our Services, you agree that the laws of India govern any matter regarding your privacy or this Policy.

In the event of any dispute, claim, or controversy arising out of or relating to this Privacy Policy (including its interpretation, application, or breach), we will first seek to resolve it amicably through negotiations. You agree to contact us (via the Grievance Officer detailed above) to attempt informal resolution before pursuing any formal legal action. We will do our best to address your concerns in good faith. If we are unable to reach an amicable solution within a reasonable time, the dispute shall be subject to the exclusive jurisdiction of the competent courts in Ahmedabad, Gujarat, India. You expressly agree to submit to the jurisdiction of Ahmedabad courts for resolution of any disputes related to this Privacy Policy or your use of our Services. Ahmedabad is the city where Nutribloom Health Private Limited has its registered office, and we have specified this jurisdiction for consistency with our business operations and legal compliance.

As a consumer, you may also have rights under the Consumer Protection Act, 2019 to seek redressal through consumer fora, but the governing law remains Indian law. If any dispute falls within the scope of a consumer court or tribunal, it would still likely be under the territorial jurisdiction of Ahmedabad if that is the designated place of business.

Please note that nothing in this section limits any statutory rights you may have to initiate legal proceedings in other forums as per applicable law; however, this clause constitutes our agreement on choice of law and preferred jurisdiction which may be given effect by the adjudicating body. We do not intend to deprive any consumer of protections granted under mandatory laws; rather, this clause mainly clarifies which laws apply and where a lawsuit (if one is filed) should be heard.

In any legal action, the prevailing language of the Privacy Policy (English) will be used to interpret the provisions herein. Additionally, we might be open to alternative dispute resolution mechanisms if you prefer – such as arbitration or mediation – provided both parties mutually agree on the method and rules. Any such alternative method would still be governed by Indian law and likely take place in Ahmedabad, unless agreed otherwise. By continuing to use our Site and Services, you acknowledge that you have read, understood, and agreed to this Governing Law and Dispute Resolution clause.

15. Policy Revisions and Update Mechanism:

We may update or revise this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. As our business grows and laws evolve, new features or services might be introduced that could affect how we process personal data.

We reserve the right to amend the Policy at our discretion, but with a commitment to keep you informed.

Notification of Changes: If we make material changes to this Privacy Policy, we will provide a prominent notice to users. This may include posting a notice on our website’s homepage or policy page, and/or emailing you at the email address associated with your account or purchase. The notice will outline the key changes and their implications. For minor updates that do not significantly affect your rights (e.g., grammatical edits or clarifications), we may simply update the Privacy Policy with a new effective date. Every version of this Policy will have an updated “Last Updated” date at the top so you can easily tell when it was last revised. We encourage you to review this page periodically to remain informed of how we are protecting your information.

When we update the Policy, if required by law, we will also seek re-consent from you for any new purposes or uses of data that were not originally covered by your initial consent. For instance, if in the future we seek to collect a new type of personal data or share data with a new category of third party not previously disclosed, and if these changes require consent by law, we will obtain your consent before processing under the new terms.

Effective Date of Changes: Unless otherwise required by law, the updated Privacy Policy will become effective as soon as it is posted on our Site. In certain jurisdictions or scenarios, applicable law might require a longer notice period before changes take effect – we will adhere to any such requirement. If you continue to use our Services after the Privacy Policy changes take effect, it will be deemed as acceptance of those changes. If you do not agree with the revised Policy, you have the choice to discontinue use of our Services and may request us to delete your data (as per Section 10). We will respect such decisions and handle data deletion or other requests in accordance with the revised Policy and applicable law.

We will archive previous versions of this Privacy Policy and make them available for review upon request, so you can see how our policy has evolved over time. This transparency is part of our accountability to you.

Summary of Recent Changes (if any): Along with an updated Policy, we may provide a summary of significant changes for convenience. For instance, if we add a new section on a feature or update our cookie practices, we’ll highlight that for you.

By having a clear update mechanism, we aim to maintain your trust and ensure that you are always aware of what information we collect, how we use it, and under what circumstances (if any) we disclose it. Your continued relationship with ROZ Health in terms of data will always be governed by the most current version of this Privacy Policy .

If you have any questions or comments about this Privacy Policy or our data practices, please do not hesitate to contact us (see Section 13 above for contact details). Your privacy is paramount to us, and we appreciate the opportunity to address any concerns. Thank you for placing your trust in ROZ Health. We are dedicated to safeguarding your personal wellness and your personal data with equal care.

Last Updated: