Tracky Pro Diary and Tracky Pro ABPM Analysis Mobile Applications Privacy Notice

Healthquad (who manages the tracky platform) believes that the User is the owner of his or her data or information (provided or generated by the User) during the use of the services. As custodians of User’s Personal Data or Information, healthquad is very transparent about what personal information is collected and how it may be used.

IMPORTANT:

THIS PRIVACY POLICY SHOULD BE READ IN CONJUNCTION WITH TERMS OF USE AND EULA AND APPLIES MANDATORY TO ALL USERS WITHOUT EXCEPTIONS OF ANY KIND.

Personal data may be freely provided by the User, or, in case of Usage Data, collected automatically when using healthquad. Unless specified otherwise, all information or data requested by healthquad is mandatory and failure to provide this information or data may make it impossible for healthquad to provide its services. In cases where healthquad specifically states that some information or data is not mandatory, Users are free not to communicate this information or data without consequences to the availability or the functioning of the service.

Healthquad views protection of Your privacy as a very important principle. We understand clearly that You and Your Personal Information is one of Our most important assets. We store and process Your Information on computers that may be protected by physical as well as reasonable technological security measures and procedures in accordance with Information Technology Act 2000 and Rules there under. If You object to Your Information being transferred or used in this way please do not use Website/ application

We may share personal information with our other corporate entities and affiliates. These entities and affiliates may market to you as a result of such sharing unless you explicitly opt-out.

We may disclose personal information to third parties. This disclosure may be required for us to provide you access to our Services, to comply with our legal obligations, to enforce our User Agreement, to facilitate our marketing and advertising activities, or to prevent, detect, mitigate, and investigate fraudulent or illegal activities related to our Services. We do not disclose your personal information to third parties for their marketing and advertising purposes without your explicit consent.

We may disclose personal information if required to do so by law or in the good faith belief that such disclosure is reasonably necessary to respond to subpoenas, court orders, or other legal process. We may disclose personal information to law enforcement offices, third party rights owners, or others in the good faith belief that such disclosure is reasonably necessary to: enforce our Terms or Privacy Policy; respond to claims that an advertisement, posting or other content violates the rights of a third party; or protect the rights, property or personal safety of our users or the general public.

We and our affiliates will share some or all of your personal information with another business entity should we (or our assets) plan to merge with, or be acquired by that business entity, or reorganization, amalgamation, restructuring of business. Should such a transaction occur, another business entity (or the new combined entity) will be required to follow this privacy policy with respect to your personal information.

DATA COLLECTED

Healthquad may collect the following information about User when the User signs up and during the use of any of the features and services available via Service Platform

mobile phone number, email, first name, last name, marital status;

date of birth, gender, height, weight, waist size, blood group, health conditions;

family members and their demographic and health related information;

postal address including city, state and pincode;

food related logs including food eaten, time, meal type, water intake and related information;

food preferences and food allergies

health related User information like heart rate, sleep duration and times, blood sugar, blood pressure, exercise provided by the user directly or tracked using sensors with permission from User.

health goals, targets like step count, weight etc. and related information

activity information including general activity data, heart rate and other vital data, movement activity, sleeping activity;

payment related information

pattern of usage on the Service Platform

device information used to access the Service Platform

location unless permission is not provided

lifestyle related like working and commute times, smoking habits

emergency contact name and contact number

health related documents to store online

app logs when user shares any complaint or issue unless user disables the collection while sharing feedback

Healthquad may request following device related permissions when the User signs up and during the use of any of the features and services available via Service Platform

camera permission;

precise location permission (non-continuous),

approximate location permission (non-continuous);

storage permission;

motion sensors permission;

bluetooth sharing permission;

photo library permission; and

call permission;

HOW WE USE DATA

PERSONAL INFORMATION

signup and register

track diet and nutrition

suggest recommended calorie and nutrition intake

suggest activities and other wellness improvement suggestions and recommendations

payment towards services and products on Service Platform

send promotional offers

communicate to Users, resolving issues and complaints, customer service

location dependant and location specific filtering of services and offerings

DEVICE RELATED PERMISSIONS

Depending on the User's specific device, healthquad may request certain permissions that allow it to access the User's device data or information as described below. By default, these permissions must be granted by the User before the respective information can be accessed. Once the permission has been given, it can be revoked by the User at any time. In order to revoke these permissions, Users may refer to the device settings and revoke the permissions at any time.The exact procedure for controlling app permissions may be dependent on the User's device and software. Please note that the revoking of such permissions might impact the proper functioning of healthquad.

If User grants any of the permissions listed below, the respective Personal Data may be processed (i.e accessed to, modified or removed) by healthquad.

approximate location permission (continuous) and precise location permission (non-continuous): Used for accessing the User's approximate device location. Healthquad may collect, use, and share User location Data in order to provide location-based services. When using a non-continuous location, the geographic location of the User is determined in a manner that isn't continuous. This means that it is impossible for healthquad to derive the exact position of the User on a continuous basis;

bluetooth sharing permission: Used for accessing Bluetooth related functions such as scanning for devices, connecting with wearable devices, and allowing data transfer between devices;

call permission: Used for sending incoming call notifications on the smart band or wearable device or similar device.

HEALTHQUAD DOES NOT STORE ANY CALL RELATED INFORMATION ON ITS SERVERS AND IS MAY BE ONLY USED TO SEND CALL ALERTS OR NOTIFICATIONS TO COMPANION WEARABLE DEVICE

camera permission: Used for accessing the camera or capturing images and video from the device for features like profile pictures etc;

motion sensors permission: Used for accessing the User's device motion sensors to measure the User's activity such as step counts, stairs climbed, and movement type (walking, cycling, etc.);

photo library permission: Allows access to the User's photo gallery or library to upload pictures from photo gallery or photo library; and

storage permission: Used for accessing shared external storage, including the reading and storing, uploading, downloading, renaming files or deleting files, documents or reports from healthquad server.

REGISTRATION AND AUTHENTICATION

By registering or authenticating, Users allow healthquad to identify them and give them access to dedicated services. Depending on what is described below, third parties may provide registration and authentication services. In this case, healthquad will be able to access some Data, stored by these third-party services, for registration or identification purposes. Some of the services listed below may also collect Personal Data for targeting and profiling purposes; to find out more, please refer to the description of each service.

Google OAuth (Google LLC): Social login using Google Account;

Firebase Authentication (Google LLC): Firebase Authentication is a registration and authentication service provided by Google LLC. To simplify the registration and authentication process, Firebase Authentication can make use of third- party identity providers and save the information on its platform. Personal Data collected: email address; phone number; Username; and

Direct registration (healthquad): The User registers by filling out the registration form and providing the Personal Data directly to healthquad.Personal Data collected: mobile number

PAYMENT INFORMATION

Payment related information about Users may be collected to complete the payment and may include the credit card, the bank account etc. used for the transfer, or any other means of payment envisaged. The kind of data collected by healthquad depends on the payment system used in general and unless otherwise stated, Users are requested to provide their payment details and personal information directly to such payment service providers. Healthquad isn't involved in the collection and processing of such information: instead, it may only receive a notification by the relevant payment service provider as to whether payment has been successfully completed.

PUSH NOTIFICATIONS

Healthquad may send push notifications to the User.Users must be aware that disabling push notifications may negatively affect the utility of healthquad. Healthquad may send push notifications to the User for the purpose of direct marketing (to propose services and products provided by third parties or unrelated to the product or service provided by healthquad) or send instant reminders, new offers on products and services as available on the Platform.

Users may in most cases opt-out of receiving push notifications by visiting their device settings, such as the notification settings for mobile phones, and then changing those settings for healthquad or all of the apps on the particular device.Users must be aware that disabling push notifications may negatively affect the utility of healthquad. Besides applicable device settings, the User may also make use of the rights described under User rights in the relevant section of this privacy policy.

SALE AND DELIVERY OF SERVICES

The Personal Data collected are used to provide the User with services or to sell goods and services, including payment and possible delivery. Users that provided their phone number might be contacted for commercial or promotional purposes related to healthquad, as well as for fulfilling support requests.

ANALYTICS

Healthquad may utilize third party services like Google Analytics to monitor and analyze traffic and track User's usage patterns on the Service Platform. Healthquad may use this data for improving User experience, services and other offerings on Service Platform. Google may utilize the Data collected to track and examine the use of healthquad, to prepare reports on its activities and share them with other Google services. Google may use the Data collected to contextualize and personalize the ads of its own advertising network.

MODE, PLACE AND PURPOSE OF DATA PROCESSING

Healthquad takes appropriate security measures to prevent unauthorized access, disclosure, modification, or unauthorized destruction of the User’s information or data. The Data processing is carried out using computers and/or IT enabled tools, following organizational procedures and modes strictly related to the purposes indicated. In addition to the Owner, in some cases, the Data may be accessible to certain types of persons in charge, involved with the operation of healthquad (administration, sales, marketing, legal, system administration) or external parties (such as third-party technical service providers, mail carriers, hosting providers, IT companies, communications agencies) appointed, if necessary, as Data Processors by the healthquad. The updated list of these parties may be requested from the healthquad at any time.

Depending on the User's location, data transfers may involve transferring the User's Data to a country other than their own. To find out more about the place of processing of such transferred Data, Users can check the section containing details about the processing of Personal Data.

Users are also entitled to learn about the legal basis of Data transfers to a country outside the European Union or to any international organization governed by public international law or set up by two or more countries, such as the UN, and about the security measures taken by the Owner to safeguard their Data. If any such transfer takes place, Users can find out more by checking the relevant sections of this document or inquire with the Owner using the information provided in the contact section.

Personal Data shall be processed and stored for as long as required by the purpose they have been collected for. Therefore:

Personal Data collected for purposes related to the performance of a contract between the healthquad and the User shall be retained until such contract has been fully performed;

Personal Data collected for the purposes of the healthquad’s legitimate interests shall be retained as long as needed to fulfill such purposes. Users may find specific information regarding the legitimate interests pursued by the healthquad within the relevant sections of this document or by contacting the healthquad;

The Company may be allowed to retain Personal Data for a longer period whenever the User has given consent to such processing, as long as such consent is not withdrawn. Furthermore, the Company may be obliged to retain Personal Data for a longer period whenever required to do so for the performance of a legal obligation or upon order of an authority; and

Once the retention period expires, Personal Data may be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to data portability cannot be enforced after expiration of the retention period.

The company may not be able to permanently delete the data and in that case the data will be unlinked from the user information making it anonymous and untraceable to the user.

The Data concerning the User is collected to allow the Company to provide its service, comply with its legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as the following: Registration and authentication, Registration and authentication provided directly by healthquad, device permissions for personal data access, analytics, contacting the User, content commenting, displaying content from external platforms, handling activity data, handling payments, hosting and backend infrastructure, infrastructure monitoring, location-based interactions, Platform services and hosting and social features.

USE OF COOKIES

Cookes or other tracking tools by healthquad or by the owners of third-party services used by healthquad serves the purpose of providing the Service required by the User, in addition to any other purposes described in the present document and in the Cookie Policy, if available. Users are responsible for any third-party Personal Data obtained, published or shared through healthquad and confirm that they have the third party's consent to provide the Data to healthquad.

APP STORE / PLAYSTORE

By virtue of being distributed via google play store app store, Google may collect usage and diagnostics data and share aggregate information with the healthquad. Much of this information is processed on an opt-in basis. Users may opt-out of this analytics feature directly through their device settings

HOSTING AND INFRASTRUCTURE

Hosting and backend infrastructure is meant for the purpose of hosting Data and files that enable healthquad to run and be distributed as well as to provide a ready-made infrastructure to run specific features or parts of healthquad. Infrastructure monitoring services allows healthquad to monitor the use and behavior of its components so its performance, operation, maintenance and troubleshooting can be improved.Platform hosting and services have the purpose of hosting and running key components of healthquad, therefore allowing the provision of healthquad from within a unified Platform. Such platforms provide a wide range of tools to the Company like analytics, User registration, commenting, database management, e-commerce, payment processing, that imply the collection and handling of Personal Data.

Some services among these listed below, if any, may work through geographically distributed servers, making it difficult to determine the actual location where the Personal Data are stored. Which Personal Data are processed depends on the characteristics and mode of implementation of these services, whose function is to filter the activities of healthquad.

Amazon Web Services (AWS) (Amazon Web Services, Inc.);

Firebase Realtime Database (Google LLC);

Firebase Cloud Functions (Google LLC);

Splunk MINT Express (Splunk Inc.);

Google Play Store (Google LLC);

Firebase Dynamic Links (Google LLC);

Firebase Invites (Google LLC)

ADDITIONAL INFORMATION

In addition to the information contained in this privacy policy, healthquad may provide the User with additional and contextual information concerning particular Services or the collection and processing of Personal Data upon request.

System logs and maintenance: For operation and maintenance purposes, healthquad and any third-party services may collect files that record interaction with healthquad (System logs) use other Personal Data (such as the IP Address) for this purpose;

Information not contained in this policy: More details concerning the collection or processing of Personal Data may be requested from the Company at any time;

Do Not Track requests: Healthquad does not support “Do Not Track” requests.

IMPORTANT: CHANGES TO PRIVACY POLICY

Healthquad reserves the right to make changes to this privacy policy at any time by notifying its Users on this page and possibly within healthquad and/or as far as technically and legally feasible like sending a notice to Users via any contact information available to the Company. It is strongly recommended to check the Privacy Policy page or information on the Service Platform often, referring to the date of the last modification listed at the top.

CONTACT

EMAIL: support@healthquad.co.in

ADDRESS: A-504, BESTECH PARK VIEW S