Privacy Policy
Your privacy matters to us. This Privacy Policy explains what personal and health data the Multifit's Wellis App collects, why we collect it, how we use and protect it, and the rights you have over your data. This Policy is governed by the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable Indian law.
1. Who We Are
Multifit Wellis Pvt. Ltd. ("Company", "we", "us", "our") is the operator of the Multifit's Wellis mobile application ("App" or "Application"). We are a digital wellness platform provider registered in India.
For the purposes of the Digital Personal Data Protection Act, 2023:
- We are the Data Fiduciary responsible for processing your personal data.
- You, as our App user/member, are the Data Principal.
Contact details of our Data Fiduciary and Grievance Officer are provided in Section 16 of this Policy.
2. Scope of This Policy
This Privacy Policy applies to all personal data collected by Multifit's Wellis through:
- The Multifit's Wellis mobile application (Android and iOS)
- Our website and any web-based portals linked to the App
- Integrated third-party devices and sensors used with the App (BCA machines, CGMs, wearables)
- Customer support, email, or telephonic interactions with our team
This Policy does not apply to third-party websites, applications, or services that may be linked from our App. We encourage you to review the privacy policies of any third-party service you access through or alongside our App.
3. What Data We Collect
We collect data that you provide directly, data generated through your use of the App, and data from integrated devices and third-party services you connect to your account. The categories of data we collect are detailed below.
3.1 Account & Identity Data
- Full name, date of birth, gender
- Email address, mobile number, and profile photograph
- Username, password (stored in encrypted form), and account preferences
- Government-issued ID details (where required for KYC verification)
- Corporate organisation affiliation (if accessing via an employer programme)
3.2 Health & Biometric Data
Health and biometric data is classified as sensitive personal data. We collect this only with your explicit, informed consent, and it is processed under strict security controls.
- Body composition metrics: weight, height, BMI, body fat %, muscle mass, visceral fat index, bone density, and hydration levels — collected via BCA machines and manual entry
- Facial biometric data: captured via Face Scan for identity verification, onboarding, and health risk score generation (collected only with your explicit consent at the time of onboarding)
- Blood glucose and metabolic data from Continuous Glucose Monitors (CGM), where you opt into CGM integration
- Heart rate, SpO2, sleep patterns, and activity data from connected wearable devices
- Self-reported medical history, current medications, allergies, and existing health conditions (voluntary)
- Mental wellness indicators, stress scores, and mood logs (where features are activated)
- Vital signs and health parameters input during trainer or teleconsultation sessions
3.3 Fitness & Activity Data
- Exercise logs, workout history, and training programme records
- Trainer attendance and session completion records
- Virtual class participation and performance metrics
- Step count, calorie data, distance, and movement analytics from connected devices
- Progress milestones, personal records, and gamification scores
3.4 Nutritional Data
- Dietary logs and meal records voluntarily entered by you
- Food preferences, dietary restrictions, and nutritional goal settings
- Caloric intake estimates and macronutrient tracking data
3.5 Financial & Transaction Data
- Subscription plan and membership details
- Payment transaction references (we do not store full card or bank account details; payments are processed by our PCI-DSS compliant payment gateway partner)
- Marketplace purchase history and reward redemption records
3.6 Device & Technical Data
- Device type, model, operating system version, and unique device identifiers
- App version, crash logs, and error reports
- Internet Protocol (IP) address and connection type
- Time zone and language settings
3.7 Usage & Behavioural Data
- Features accessed, screens viewed, and in-app navigation patterns
- Session duration, login frequency, and interaction timestamps
- Push notification preferences and in-app communication responses
- Search queries within the App (e.g., workout searches, marketplace searches)
3.8 Location Data
We collect location data only if you explicitly grant location permission. This is used for gym check-in verification, locating nearby Multifit's Wellis partner facilities, and context-relevant service delivery. You can withdraw location permission at any time through your device settings.
3.9 Communications Data
- Content of queries, complaints, or feedback you send to our support team
- Survey responses and in-app feedback submissions
- Records of in-app notifications and messages sent to you
4. How We Collect Your Data
We collect your data through the following means:
- Directly from you: during registration, profile setup, manual data entry, and interactions with the App's features
- Automatically: through App usage, session tracking, device sensors, and crash analytics tools
- From connected devices: biometric and activity data synced from BCA machines, CGM devices, and wearables you pair with the App
- From third-party integrations: where you connect third-party accounts or services (e.g., Google Fit, Apple Health) to the App
- From your employer or corporate administrator: basic account details for corporate wellness programme enrolment, where applicable
- From healthcare professionals: consultation notes or recommendations added to your record during teleconsultation sessions you initiate
5. Why We Process Your Data & Legal Basis
We process your personal data for specific, legitimate purposes, and only where we have a valid legal basis to do so under the DPDP Act, 2023. The table below outlines our primary processing activities:
| Processing activity | Details & legal basis |
|---|---|
| Account creation & management | Creating and maintaining your member profile, authentication, and service delivery. Basis: Contract / Consent |
| Personalised wellness insights | Generating health scores, risk assessments, fitness recommendations, and progress tracking. Basis: Consent |
| Biometric data processing | Face scan for onboarding/ID; body composition analysis; CGM data interpretation. Basis: Explicit Consent |
| Trainer & coach oversight | Sharing your programme data with your assigned trainer for session planning. Basis: Contract / Consent |
| Teleconsultation facilitation | Scheduling and enabling virtual consultations with healthcare professionals. Basis: Consent |
| Gamification & rewards | Computing points, badges, and leaderboard positions based on activity. Basis: Contract |
| Payments & billing | Processing subscription fees and marketplace transactions. Basis: Contract / Legal Obligation |
| Customer support | Responding to queries, grievances, and technical issues. Basis: Contract / Legitimate Interest |
| App improvement | Analysing anonymised usage data to improve features and fix bugs. Basis: Legitimate Interest |
| Marketing communications | Sending wellness tips, programme updates, and relevant offers (with your consent, opt-out available at any time). Basis: Consent |
| Legal compliance | Maintaining records required by law, responding to regulatory requests. Basis: Legal Obligation |
| Safety & fraud prevention | Detecting unauthorised access, protecting accounts, and preventing misuse. Basis: Legitimate Interest |
We will not process your data for any purpose materially different from those listed above without obtaining fresh consent from you or where otherwise permitted by law.
6. How We Share Your Data
Multifit's Wellis does not sell your personal data to any third party, ever. Your data may be shared in the following limited circumstances:
6.1 With Your Assigned Trainers & Coaches
Your fitness data, body composition metrics, progress records, and workout history are shared with your assigned Multifit's Wellis trainer or coach to enable effective programme delivery. Trainers access only the data relevant to your training and are bound by confidentiality obligations.
6.2 With Healthcare Professionals
If you book a teleconsultation through the App, relevant health data you choose to share will be made available to the consulting doctor or healthcare professional for the duration of and in connection with that consultation. This data sharing is governed by your explicit consent at the time of booking.
6.3 With Your Corporate Administrator (if applicable)
If your membership is part of an employer-sponsored wellness programme, your corporate administrator will receive only aggregate, anonymised programme-level data (e.g., overall participation rates, aggregate wellness score trends). Individual member health data will not be shared with your employer without your separate, explicit consent.
6.4 With Trusted Service Providers
We engage trusted third-party service providers who process data on our behalf under strict data processing agreements that prohibit them from using your data for their own purposes. These include:
- Cloud infrastructure and data storage providers
- Payment gateway and financial transaction processors (PCI-DSS compliant)
- Communication service providers (SMS, email, push notification delivery)
- Analytics and crash reporting tools (using anonymised or pseudonymised data)
- Customer support platform providers
- CGM and biometric device integration partners
6.5 As Required by Law
We may disclose your data where required by law, court order, or directive from a competent regulatory or government authority, including in connection with national security, law enforcement, or judicial proceedings.
6.6 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of assets involving Multifit Wellis Pvt. Ltd., your data may be transferred to the successor entity. We will notify you before your data becomes subject to a materially different privacy policy, and you will have the option to delete your account if you do not consent.
7. Cross-Border Data Transfers
Your data is primarily stored and processed in India. Where we engage service providers whose infrastructure is located outside India (e.g., cloud providers), such transfers are made only to countries notified by the Central Government as permissible destinations under the DPDP Act, 2023, or where adequate contractual safeguards are in place to protect your data to a standard equivalent to Indian law.
8. How We Protect Your Data
We implement industry-standard technical and organisational security measures to protect your personal data against unauthorised access, loss, alteration, or disclosure:
- End-to-end encryption for data transmission using TLS/SSL protocols
- Encryption at rest for all sensitive personal and health data stored on our servers
- Facial biometric data (face scan) is processed and converted to non-reversible mathematical templates; raw facial images are not retained after processing
- Role-based access controls ensuring only authorised personnel can access personal data, strictly on a need-to-know basis
- Multi-factor authentication (MFA) for App access and administrative systems
- Regular security audits, vulnerability assessments, and penetration testing
- Secure data processing agreements with all third-party service providers
- Incident response procedures for detecting, reporting, and managing data breaches
While we take all reasonable precautions, no method of electronic transmission or storage is 100% secure. If you become aware of any security vulnerability or unauthorised access to your account, please notify us immediately at wellis@multifit.co.in.
9. How Long We Keep Your Data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our standard retention periods are:
| Data category | Retention period |
|---|---|
| Active membership data | Retained for the duration of your active membership |
| Post-account closure | Up to 3 years after account deletion/closure for legal, compliance, and dispute resolution purposes |
| Health & biometric data | Retained for the duration of membership + 3 years, or as required by applicable health data regulations |
| Financial transaction records | Up to 8 years as required by the Income Tax Act, 1961 and applicable financial regulations |
| Customer support records | Up to 3 years from the date of the interaction |
| Anonymised/aggregated data | May be retained indefinitely as it cannot be used to identify you |
| Legal hold data | As long as required by the relevant legal obligation or proceeding |
At the end of the applicable retention period, data is securely deleted or anonymised. You may request early deletion of your data by exercising your rights under Section 11.
10. Cookies & Analytics Technologies
The App may use analytics SDKs and similar tracking technologies to understand usage patterns and improve the App's performance. These tools collect data such as session duration, feature interactions, crash events, and aggregate usage statistics.
We use Firebase Analytics (Google), or equivalent tools, which process data in pseudonymised form. We do not use advertising trackers or serve third-party advertisements within the App.
Where our web portal uses cookies, a cookie consent banner will present your choices. You can manage cookie preferences at any time through your browser settings.
11. Your Rights Under the DPDP Act, 2023
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:
11.1 Right to Access
You have the right to obtain a summary of your personal data held by us, the processing activities undertaken, and the identities of any Data Processors or third parties to whom your data has been disclosed.
11.2 Right to Correction & Erasure
You have the right to request correction of inaccurate or incomplete personal data, and to request erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to any overriding legal retention obligations.
11.3 Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal. Please note that withdrawal of consent for core data processing may result in the App being unable to deliver certain features or Services.
11.4 Right to Grievance Redressal
You have the right to raise a grievance with our Grievance Officer (details in Section 16). We will acknowledge your grievance within 24 hours and resolve it within 15 business days. If unsatisfied with our response, you may escalate your complaint to the Data Protection Board of India.
11.5 Right to Nominate
You have the right to nominate another individual who, in the event of your death or incapacity, may exercise your data rights on your behalf.
How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to wellis@multifit.co.in or via the "Privacy Settings" section within the App. We may require identity verification before processing your request to prevent unauthorised access to your data.
12. Children's Privacy
The Multifit's Wellis App is not intended for use by children under the age of 13. We do not knowingly collect personal data from children under 13 without verifiable parental consent.
For users between 13 and 17 years of age, parental or guardian consent is required prior to account creation and use of the App. Collection of sensitive health and biometric data from minors requires explicit verifiable consent from a parent or legal guardian.
If we become aware that we have inadvertently collected personal data from a child under 13 without appropriate consent, we will promptly delete such data. If you believe a child's data has been collected without proper consent, please contact us at wellis@multifit.co.in.
13. Special Notice — Health & Biometric Data
Health and biometric data (including body composition, glucose levels, facial biometrics, and medical history) is Sensitive Personal Data under Indian law. We apply heightened security and access controls to this category of data.
In addition to our general data protection practices, for health and biometric data we specifically:
- Obtain your explicit, separate consent before collecting any biometric or sensitive health data
- Limit access to health data to only those personnel and systems with a strict operational need
- Do not share individual-level health data with your employer or any third party without your explicit, action-specific consent
- Allow you to opt out of specific health data collection (e.g., CGM integration, face scan) without losing access to core App features
- Process facial biometric data only for the stated purpose (identity verification and risk scoring) and do not use it for any other purpose
- Never use your health data for advertising targeting, profiling for non-wellness purposes, or sale to data brokers
14. Marketing & Promotional Communications
With your consent, we may send you wellness tips, programme announcements, new feature updates, and promotional offers via push notification, SMS, or email. You can withdraw consent for marketing communications at any time by:
- Updating your notification preferences in the App's Settings section
- Clicking "Unsubscribe" in any marketing email we send you
- Contacting us at wellis@multifit.co.in
Withdrawing marketing consent will not affect essential service communications such as booking confirmations, payment receipts, and security alerts.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:
- Display a prominent in-app notice informing you of the change
- Send you a notification via email or SMS to the contact details associated with your account
- Update the "Effective Date" at the top of this Policy
Your continued use of the App following the effective date of a revised Policy constitutes your acceptance of the changes. If you do not agree to the revised Policy, you may delete your account and discontinue use of the App.
16. Contact Us & Grievance Officer
For any privacy-related queries, data rights requests, or concerns, please contact us at:
Multifit Wellis Pvt. Ltd.
Registered Address: [Insert Registered Office Address], Pune, Maharashtra, India
Privacy & Data Requests: wellis@multifit.co.in
Security Incidents: wellis@multifit.co.in
General Support: wellis@multifit.co.in
Grievance Officer
Name: Anshul Srivastava
Email: Anshul.srivastava@multifit.co.in
Available: Monday to Friday, 10:00 AM – 6:00 PM IST
Our Grievance Officer will acknowledge your complaint within 24 hours and endeavour to resolve it within 15 (fifteen) business days of receipt, in accordance with the DPDP Act, 2023.
If you remain unsatisfied with our response, you may file a complaint with the Data Protection Board of India at [www.dpb.gov.in] once the Board is operational.
