Privacy Policy
Zeikon Global Private Limited
Introduction
Zeikon Global Private Limited (“Zeikon Global”, “we”, “us”, or “our”) is a health-technology company incorporated in India. We provide AI-powered wellness assessments and related digital services through our websites, mobile applications, and enterprise platforms (collectively, the “Services”).
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have over it. It applies to all users of our Services, including individuals accessing them through an employer, insurer, hospital, or other enterprise partner.
Our privacy practices are designed to align with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and information security practices consistent with ISO/IEC 27001.
Data We Collect
We only collect data necessary to provide, improve, and secure the Services. Depending on how you use the Services, this may include:
- Identity & Contact Data — Your name, email address, mobile/phone number, age, gender, and profile details you choose to provide.
- Health & Wellness Data — Vitals and wellness indicators generated through our assessments, such as heart rate, respiratory indicators, stress and wellness scores, and inputs relating to fitness, nutrition, sleep, and mental wellness. This is sensitive data and is treated with the highest level of protection.
- Scan Inputs — Facial images or video frames processed during camera-based scans. Unless expressly stated otherwise for a specific feature, scan frames are processed to generate results and are not retained as raw images.
- Device & Usage Data — Device type, operating system, app version, IP address, browser type, and information about how you interact with the Services.
- Enterprise Enrolment Data — If you access the Services through an employer, insurer, or other partner, we may receive limited enrolment information (such as name, email, and employee/member ID) from that organisation.
We do not knowingly collect data from children under 18 without verifiable parental or guardian consent.
How and Why We Use Your Data
We process personal data only where we have a lawful basis:
- To provide the Services — Create your account, deliver assessments, and generate wellness reports you request.
- With your consent — To process health and wellness data, camera-based scans, and any other sensitive data. You may withdraw consent at any time.
- Legitimate interests — To secure our systems, prevent fraud, and improve the Services using aggregated or de-identified data.
- Legal obligations — To meet applicable legal, regulatory, and audit requirements.
We do not sell your personal data, and we do not use your identifiable health data for advertising.
Health Data — Special Protections
Health and wellness data is treated as a special category of personal data. In addition to our general safeguards:
- Health data is collected only with your explicit, informed consent, obtained before your first assessment.
- Health data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Access is restricted on a need-to-know basis, with role-based access controls and audit logging.
- Where health data is shared with an enterprise partner (for example, workforce wellness reporting), it is shared in aggregated and de-identified form only, unless you have expressly authorised identifiable sharing.
- Our assessments are wellness and screening tools, not medical diagnoses. Results are informational and should not replace professional medical advice.
Sharing and Disclosure
We share personal data only in these limited circumstances:
- Service providers — Vetted vendors that host or support the Services, bound by written agreements with confidentiality and security obligations.
- Enterprise partners — If you access the Services through an employer, insurer, hospital, or similar organisation, we share aggregated, de-identified insights. Identifiable data is shared only with your explicit consent.
- Legal requirements — Where required by law, regulation, or court order, or to protect the rights, safety, or property of Zeikon Global, our users, or the public.
- Business transfers — In connection with a merger, acquisition, or asset sale, subject to this Policy continuing to apply to your data.
Data Storage & Cross-Border Processing
Zeikon Global operates internationally and works with partners such as insurers, employers, and healthcare organisations across multiple countries. Wherever possible, personal data is stored and processed on infrastructure located in the user's own region — for example, data of users in India is hosted in India.
Where the Services require processing in another country (for example, to support a multinational enterprise partner, deliver the Services globally, or use vetted cloud and analytics providers), we transfer personal data only with appropriate safeguards. These include contractual protections with recipients, encryption in transit and at rest, access controls, and compliance with applicable data protection laws in both the origin and destination jurisdictions.
Sensitive health data is transferred cross-border only where necessary to provide the Services you have requested, and always subject to the safeguards described in this Policy.
Data Security
We maintain an information security programme aligned with ISO/IEC 27001 practices, including:
- Encryption of data in transit and at rest.
- Role-based access controls, multi-factor authentication for administrative access, and least-privilege principles.
- Secure development practices, periodic vulnerability assessments, and security reviews.
- Logging, monitoring, and incident response procedures.
- Confidentiality obligations and security training for personnel.
No system can be guaranteed to be fully secure. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law, without undue delay.
Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy or as required by law. In general:
- Account and profile data is retained while your account is active.
- Health and wellness results are retained so you can track trends over time, and are deleted or anonymised upon account closure, subject to legal retention requirements.
- Raw scan inputs (such as camera frames) are processed transiently and are not stored unless a specific feature states otherwise.
- Upon account deletion, personal data is deleted or irreversibly anonymised within 365 days, unless you request earlier deletion or a longer period is required by law.
Your Rights
Subject to applicable law, you have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Object to or restrict certain processing.
- Lodge a complaint with the relevant data protection authority.
To exercise any of these rights, contact us at hello@zeikonglobal.com. We will respond within the timelines required by applicable law. We may verify your identity before acting on a request.
Cookies
Our websites use cookies and similar technologies for essential functionality, security, analytics, and remembering your preferences. You can manage cookies through your browser settings. Essential cookies required for the Services to function cannot be disabled while using the Services.
Third-Party Links
The Services may contain links to third-party websites or integrate third-party services. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review their policies separately.
Changes to This Policy
We may update this Policy from time to time. Material changes will be notified through the Services or by email before they take effect. The “Last Updated” date at the top indicates the latest revision. Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
Grievance & Contact
For questions, concerns, requests, or complaints regarding this Policy or your personal data, including grievances under applicable Indian law, contact:
Grievance Officer / Data Protection Contact
Zeikon Global Private Limited
Email: hello@zeikonglobal.com
We aim to acknowledge grievances within 48 hours and resolve them within 30 days.
Governing Law
This Policy is governed by the laws of India. Subject to any non-waivable rights you may have under applicable data protection laws, the courts of Mumbai, Maharashtra, India shall have exclusive jurisdiction over disputes arising out of this Policy.
