Privacy Policy

This policy explains what data KiloCare collects, why, how it is protected, and your rights over it. If you have questions, email our Data Protection Officer at privacy@kilocare.in.

1. Who We Are

KiloCare is a clinical weight management technology platformoperated by Agentic Organizations, Mohali, Punjab, India (“KiloCare,” “we,” “us,” “our”). We connect eligible patients with independent, NMC-registered physicians for supervised GLP-1 therapy. We are a technology intermediary — not a hospital, clinic, or healthcare provider.

This policy applies to kilocare.in and all associated services. It is written in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Telemedicine Practice Guidelines, 2020.

2. Data We Collect

2.1 Personal Data You Provide

2.2 Data Collected Automatically

3. Legal Basis for Processing

4. How We Use Your Data

We do not sell your personal data to any third party. We do not use your health or clinical data for advertising targeting, audience profiling, or behavioural segmentation.

5. Data Sharing

We share your data only with the following categories of recipients, and only to the extent necessary:

5.1 Your Clinical Team

5.2 Service Providers (Data Processors)

All third-party processors are bound by written Data Processing Agreements that require them to protect your data to at least the same standard as this policy.

ProviderPurposeData sharedRegion
SupabaseDatabase & authenticationAll user dataIndia (ap-south-1)
Payment processorPayment handlingTransaction data (tokenised); no health dataIndia
Licensed pharmacy partner(s)Prescription fulfilment & deliveryName, delivery address, prescriptionIndia
Google Analytics 4Website analytics (consent required)Anonymised usage data only; no health dataGoogle servers (see Section 7)
Meta PixelAd effectiveness measurement (consent required)Anonymised behavioural signals only; no health dataMeta servers (see Section 7)

5.3 Law Enforcement

We disclose data to law enforcement or regulatory authorities only when required by a valid court order or applicable Indian law. We will notify you of such requests to the extent legally permitted.

6. Data Retention Schedule

Data typeRetention periodBasis
Medical records & prescriptionsMinimum 3 years from last consultationTelemedicine Guidelines 2020; statutory
Video consultation recordings7 days, then auto-deletedQA & compliance only
Account & identity dataActive account lifetime + 12 monthsService delivery
Payment records7 yearsIncome Tax Act, GST regulations
Marketing communications consentUntil withdrawal + 36 monthsConsent audit trail
Anonymised analytics dataIndefinitely (non-identifiable)Service improvement

On account deletion request, all non-medical personal data is deleted within 30 days. Medical records that must be retained by law are archived with access restricted to authorised clinical and compliance personnel only.

7. Cross-Border Data Transfers

Your clinical and personal data is stored in India (Supabase ap-south-1, Mumbai region) and does not leave India without your explicit written consent.

When you accept analytics cookies, anonymised behavioural data is processed by Google (Google Analytics 4) and Meta (Meta Pixel) on servers outside India. These providers process only anonymised usage signals — not your name, health data, or clinical records. Both Google and Meta maintain internationally recognised data protection standards (GDPR adequacy frameworks, Standard Contractual Clauses) and are subject to Data Processing Agreements with us. By accepting analytics cookies, you consent to this limited cross-border transfer of anonymised data.

If you decline analytics cookies, no data is transferred outside India.

8. Data Security

8.1 Breach Notification

In the event of a data breach that is likely to result in risk to your rights or interests:

9. Cookies & Tracking

9.1 Essential Cookies

Required for the platform to function (session management, authentication, security). These cannot be opted out of while using the service.

9.2 Analytics & Advertising Cookies (Consent Required)

We use the following tools, activated only after you accept cookies via the consent banner on your first visit:

To withdraw cookie consent:Clear your browser's local storage for kilocare.in (DevTools → Application → Local Storage → delete “kilocare_cookie_consent”) and reload the page. The consent banner will reappear and you may choose to decline.

10. Your Rights Under the DPDP Act, 2023

You have the right to:

To exercise any of these rights, email our DPO at privacy@kilocare.inwith the subject line “Data Rights Request.”

11. Children's Privacy

KiloCare is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we discover that we have collected data from a minor without verifiable parental consent, we will delete it promptly.

12. Changes to This Policy

Material changes will be communicated via this website with an updated effective date, and — for active users — via direct notification on WhatsApp or email at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance of the updated policy.

13. Data Protection Officer

Data Protection Officer
Agentic Organizations
Mohali, Punjab, India
Email: privacy@kilocare.in
Response time: within 30 days of receipt

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India as established under the DPDP Act, 2023.