Privacy Policy
INTRODUCTION
Infiheal HealthTech Pvt Ltd ("Infiheal," "we," "us," or "our") respects the privacy of its Users ("User," "your," or "you"). This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use the Infiheal Platform, including its services and the product Infiheal's AI Coach: Healo (the "Platform"), through our app, website at https://www.infiheal.com/ (the "Website"), or https://healo.infiheal.com/ (the "WebApp"). We are committed to protecting your privacy and ensuring that your information is handled safely.
By accessing or using our Website, WebApp, or Platform, you agree to all the terms outlined in this Privacy Policy and acknowledge the practices described herein. If you have any questions regarding this Privacy Policy, please email us at support@infiheal.com.
PURPOSE AND LIMITATIONS OF THE APP
The app is designed to help you feel happier by providing guidance on taking care of your mental health and well-being. Please note that the app does not diagnose diseases or conditions, nor does it provide medical treatments. The app offers general advice for mental health and well-being. The AI Coach, known as "Healo," is an AI-powered technology, not a real person and its capabilities are limited accordingly. It does not provide medical advice. If you require medical advice, Healo will Redirect to a human therapist or will try to connect with a helpline so that you get immediate support. The app cannot provide specific advice for complex health issues.
We collaborate with public institutions, healthcare providers, educational institutions and other organizations to deliver our services, referred to as "Institutional Services." Before using these services, you must agree to our terms as well as the rules set by your Institution.
By using our website, webpages, app, or any of our services, you consent to the usage of your information as described in this Privacy Policy and any related policies. When using the App, Platform, WebApp, or WebPages, the Infiheal Privacy Policy will apply to you.
DEFINITIONS
To help you better understand this Privacy Policy, we have defined some key terms below:
ABOUT INFIHEAL AND OUR CONTACT DETAILS
Infiheal HealthTech Pvt. Ltd. ("Infiheal") is the creator of the Infiheal app and its services, including the AI Coach "Healo." Infiheal is headquartered in India. Our app and services are available in over 72 languages, including native English, with select services offered in multiple regional and international languages to cater to a diverse user base.
Where Infiheal decides the purpose of personal data processing, we act as the "data controller or data fiduciary." When we process personal data at the direction of your Institution, we serve as "data processors."
If you have any questions, comments, complaints, or requests regarding our app and services, please email us at support@infiheal.com.
WEBSITE COVERED
The Service is currently provided through our website and related app at https://www.Infiheal.com/ and the Infiheal app available at https://play.google.com/store/apps/details?id=healoai.infiheal.app&pcampaignid=web_share Our Web App at https://healo.infiheal.com/
DATA PRIVACY FRAMEWORKS
We continuously work to ensure compliance with data protection laws, particularly the EU GDPR, UK data protection regulations and other applicable regional regulations. We transfer and process user data in a manner that can comply with these laws.
INFORMATION WE COLLECT AND HOW WE USE IT
When you use any of our services, including but not limited to the AI Coach (Healo), digital tools, Therapist Matching, or any other features, we collect the following information. You have full control over the information you share with us. We strive to collect only the minimal personal data necessary to provide our services, ensuring your privacy and reducing the risk of data misuse.
Information Provided by You?
- Information About You: This includes details such as your nickname, age range, gender, pronouns, or any other identifiers you voluntarily provide. Additionally, any contact information shared with Infiheal's AI Coach, therapist, or as required by your Institution is included.
- Conversation Data: This includes information you type in messages, challenges you face, preferences, feelings, moods, thoughts, task lists and any safety information shared. It also covers answers to surveys or questionnaires and interactions during voice or video calls with Healo or our mental health professionals.
- Correspondence Data: If you contact us through email, we may collect personal information such as your name, email address, home address, company name, job title and the content of your communication.
- Feedback Data: When we ask for your thoughts on our app and services, we collect your contact information along with some basic details about you.
Information Collected via Automated Means or by Third Parties
- Information from Your Institution: Sometimes, your Institution or their appointed representatives may share or ask you to provide personal data (e.g., contact details) with us to facilitate the use of our services.
- App Event Data: We may collect information about your interactions with the app, such as which parts you access, what actions you take, your settings, notifications and the screens you visit.
- Device Data: When you install the app, we may collect information such as your device ID (from Google Play Store), the type of phone, time zone and operating system. A third-party service provider that delivers content may also collect your IP address to provide services effectively.
- Cookie Information: We and our third-party providers use cookies or similar technologies to collect information about your use of our app. We only use mandatory or necessary cookies to ensure our services function effectively.
- IP Address: We collect your ip address to provide better service as per your location and by using our app you give your consent to use your IP . We keep extreme care while storing your ip.
When You Use Our Services through B2B Partners or Collaborators
Our services help Institutions guide users to appropriate care and support. The following information may be collected:
- Information from Your Institution: You can access our services by logging in through your Institution’s Single Sign-On (SSO) page. Your Institution may provide us with a unique, encrypted identifier for you, allowing access without collecting personal login details.
- Information About You: This may include pronouns, country, service group, or other relevant information needed to personalize your experience.
When You Participate in an Infiheal Research Study
You may choose to sign up for one of our online studies. We collect information such as:
- Information About You: This may include your contact details, country, gender, socio-economic details and age range.
- Health and Wellness Data: This may include information such as ethnicity, alcohol/substance use concerns, medication usage, mental health conditions and validated assessment responses.
When You Visit Our Website or Social Media Accounts
When you visit our Website, WebPages, or contact us for business purposes, we collect:
- Correspondence Data: Information like your name, email address, home address, company, job title, business contact details and the content of your communication.
- Cookie Information: Our Website uses cookies or similar technologies to collect data such as browser type, operating system, web page views, clicks and IP address.
You can also follow us on social media through our app settings. If you choose to interact with us on social media, any personal information you provide there may also be visible to us, though it won’t be linked directly to your Infiheal account.
When You Use Healo: The AI Coach
Healo is built to provide an enhanced experience of our AI Coach services, offering high-quality, safe and clinically-approved content. Healo uses third-party Generative AI, along with our proprietary AI, to provide tailored responses.
All content generated by Healo is thoroughly reviewed by our clinical staff to ensure it is safe, private and of high quality. Your conversation data is processed to improve these services, but only after it passes our safety and quality checks. For more information, please contact us at support@infiheal.com.
When You Participate in Online Group Well-being Sessions
We may collect limited personal information, such as your name and contact details, when you participate in group well-being sessions or webinars conducted by us.
When You Participate in Our Campaigns, Promotions, or Marketing Events
If you join any promotions, campaigns, or surveys, this data will not be linked to your app account. Instead, this information is stored securely in our marketing tools. We may collect:
- Promotion Event Data: Your name and contact details for promotional activities. We may also post online advertisements to understand interest in our services, but no personal information is collected during these promotional activities.
When You Apply for a Role at Infiheal
If you apply for an open position at Infiheal or attend our interviews, we may collect and process:
- Recruitment Data: Information such as your name, contact details, resume, references, credentials, transcripts, government-issued identification, compensation information, race or ethnic origin, physical or mental health status and other personal details.
Sources of Personal Data
We obtain your personal data either directly from you or through your Institution when necessary.
PRIVACY IN INTERACTIVE FEATURES
When participating in group sessions or interactive features, certain information may be visible to others. We take measures to limit visibility to what is necessary and encourage caution.
OUR COOKIE POLICY
Cookies are used for improving user experiences, remembering preferences and compiling data on site interactions. Users can set browsers to refuse cookies, but some functionality may be affected.
HOW WE USE YOUR INFORMATION
Legal Grounds: We adhere to data protection laws to ensure your personal data is handled properly. Here are the legal grounds on which we use your data:
- Consent: At times, we may ask for your consent to use your personal data. You have the right to withdraw this consent at any time by writing to us.
- Contract Performance: When you use our app or services, we may need some of your personal data to deliver our services and ensure their smooth operation.
- Legitimate Interests: We may use your data to safeguard our services against fraud or security threats and to enhance our offerings.
- Legal Obligation: In some situations, we may need to use your personal data to comply with legal requirements or to protect our organization and those who provide our services.
For sensitive data, such as information about your emotions or mental health, we only process it when we have a valid legal basis, such as:
- Providing support and advice, or ensuring your safety while using our app and services.
- Acting on behalf of your Institution to direct you to appropriate care resources.
USES OF YOUR INFORMATION
We use the information you provide through our app and services for various purposes:
TO PROVIDE AND MANAGE APP AND SERVICES (Information About You)
- Recognize you as a user—whether direct or through an Institution.
- Collect, store and process your provided information to ensure the functionality of our services.
- Manage and monitor your interactions with the app and our services.
- Facilitate nickname customization.
- Connect with your Institution’s approved systems to manage your data, if required.
- Connect you to a human mental health and professional if your Institution offers this feature.
- In case of emergencies, contact you or a designated trusted individual.
- Keep records of permissions granted by you.
- Notify you about changes to our rules or privacy policy within the app.
Legal Grounds: Contract performance, legitimate interests and consent.
TO PROVIDE AND MANAGE APP AND SERVICES (Conversation Data)
- Develop and enhance AI programs, conversation flows and content for Healo. We only use anonymised data.
- Translate your preferred language to English and vice versa, ensuring effective communication with Healo.
- Remember text messages and choices made within the app.
- Understand your mood or feelings and provide appropriate support resources.
- Offer safe tools and techniques tailored to your needs.
- Ensure any personal details shared by mistake are removed and anonymized.
- Identify medical or emergency keywords in your messages to ensure safety.
- Notify your Institution in case of an emergency.
Legal Basis: Contract performance, legitimate interests and consent. Additional conditions apply to any sensitive data.
TO PERFORM WELL-BEING ASSESSMENTS
- Periodically inquire about your mental well-being.
- Detect emergencies and notify your Institution if support is required.
- Guide you to relevant hotlines and resources as needed.
- Recommend tips, resources and techniques to improve well-being.
Legal Basis: Contract performance, legitimate interests. Additional conditions apply to any sensitive data.
To Provide Healo Services
- Facilitate text, video, or audio interactions with Healo.
- Provide information and resources as recommended by Healo.
- Share your AI Coach data with a human professional if needed for care, unless you opt-out in the app settings.
- Conduct quality checks on messages to enhance safety and improve service.
Legal Basis: Contract performance, legitimate interests and consent. Additional conditions apply to any sensitive data.
To Provide In-App Notifications and Reminders
- Send alerts, reminders for events and session updates
Legal Basis: Consent
For Research, Analytics and Compliance Reporting
- Anonymize data to evaluate app safety and effectiveness.
- Use anonymized data for regulatory compliance purposes
Legal Basis: Legitimate interests, legal obligations.
To Communicate Effectively with You
- Respond to questions, feedback, or complaints.
- Address issues with our services.
- Provide important updates and maintain records of interactions.
Legal Basis: Contract performance, legitimate interests.
To Improve Our App and Services
- Invite you to participate in product research or testing.
- Utilize feedback to enhance safety and user experience.
- Use personal details to ensure fair opportunities in testing.
Legal Basis: Consent and legitimate interests.
To Provide and Manage App and Services for Your Institution
- Send unique codes for app access.
- Verify your association with the Institution.
- Share usage statistics with your Institution.
- In emergencies, notify your Institution for further support.
Legal Basis: Contract performance. Additional conditions apply to any sensitive data.
To Understand App Usage and Ensure Quality
- Anonymize data for safety and performance analysis.
- Record usage details for compliance purposes.
- Confirm session information with professionals.
- Share usage analytics with trusted providers.
- Innovate new services and technologies.
Legal Basis: Contract performance, legitimate interests, legal obligations. Additional conditions apply to any sensitive data.
For Marketing Purposes
- Run promotional campaigns, send surveys and update programs.
- Use anonymized data for benchmarking and marketing materials.
Legal Basis: Legitimate interests, consent.
To Ensure Availability and Security
- Ensure that all features on the app work correctly.
- Protect your information from unauthorized access and online threats.
Legal Basis: Contract performance, legitimate interests.
For Fraud Prevention
- Prevent misuse and secure the system.
Legal Basis: Legitimate interests.
Use of Cookie Information
- Essential Cookies: Necessary for basic app and website operations. These do not collect personal data.
- Analytical Cookies: Used to evaluate app and website performance, sometimes through tools like Google Analytics.
Legal Basis: Legitimate interests.
Additional Processing for Digital Front Door (e-triage) Service
Institution-Provided Data:
- Redirect to your Institution’s SSO page and use Institution-provided identifiers for access.
Legal Basis: Contract performance and defined by your Institution.
Your Provided Data:
- Direct you to suitable resources based on your needs.
- Share aggregate engagement data with your Institution.
Legal Basis: Contract performance and defined by your Institution.
Additional Processing for Chronic Care Management Service
Institution-Provided Data:
- Facilitate Chronic Care Management and adherence to medication on behalf of healthcare providers.
- Record case notes and share them with healthcare providers.
Legal Basis: Contract performance and defined by your Institution.
Additional Processing for Participation in Infiheal Research Studies
- Collect information to determine eligibility and manage participation.
- Send study-related information and reminders.
Legal Basis: Consent and legitimate interests. Note: You can opt out anytime by contacting support@infiheal.com.
Additional Processing When You Visit Our Website or Social Media Accounts
Correspondence Data:
- Store and use business data for communication.
- Manage accounts and grow the business.
Legal Basis: Consent and legitimate interests. Cookie Information: See section ("Use of Cookie Information").
Additional Processing During Group Well-being Sessions
- Collect and use information to connect you to sessions and provide materials.
Legal Basis: Consent, legitimate interests and as defined by your Institution.
Additional Processing for Campaigns, Promotions, or Marketing Events
- Contact you regarding promotions and send information about upcoming events.
Legal Basis: Consent, legitimate interests and as defined by your Institution. Note: You can opt out of promotions at any time by contacting us at support@infiheal.com.
Additional Processing When Applying for a Role at Infiheal
Recruitment Data:
- Gather and process recruitment information for hiring purposes.
Legal Basis: Consent and legitimate interests.
Processing for Legitimate Interests
We may use your data to:
- Comply with agreements with your Institution.
- Respond to legal requirements or investigations.
- Prevent fraud and misuse.
- Secure our systems and ensure app quality.
- Communicate with you effectively.
Note: We always prioritize your rights and privacy before processing your data for these purposes.
How We Protect Your Information
Where is your information stored: The information we collect is saved and kept safe in our cloud servers managed by Amazon Web Services (AWS) and our databases (MongoDB). Some of your information might be shared and stored with our third-party service providers to provide our services.
How long do we keep your information: 10 years from your last activity.
When you use our app
When you send us text messages, any personal identifier you share is removed and saved in a way that cannot be undone. We keep this information only for as long as we need to follow the law. If no specific time limit is mentioned, we retain your information for up to 10 years from the last time it was updated or as long as required for business purposes. You also have the option to permanently delete all your conversation data by emailing us at support@infiheal.com.
Your correspondence data
When you email us, we use the information you give to help you. We keep your emails safe in our Google Workspace account and only certain staff can look at them. We will keep your email for up to 10 years from the last time you contacted us or as long as required for business purposes.
Information received from your Institution
We keep your information for the time your Institution has decided. After that time, we delete your information forever. Once you send us your information, we cannot change it. If you need to fix something or have any questions, please talk to your Institution or if you have any doubts or queries you can email us at support@infiheal.com.
Data Security
We use physical, organizational and technical safeguards to keep your information safe.
Protecting your privacy
- You do not need to register to use the WebApp.
- Just give us a nickname so our AI Assistant knows what to call you.
- We use masked identifiers to keep your data and identity safe.
- No real people can listen to what you are talking about with the AI Coach.
- The AI Coach will always make sure it understands you before moving on.
- If you accidentally share personal data, we will ensure it is protected by using data masking techniques during processing.
- As an app user, you can choose to delete your information by emailing us at support@infiheal.com.
- Before we use any personal data about you, we make sure it respects your privacy and security rights.
Protecting your security
- We use strong encryption to protect your data when it is being sent or stored.
- Only authorized people can access your data. They have to use strong passwords and an additional access code.
- All our staff computers have extra security.
- We maintain contracts with companies we work with to keep your data safe.
- We carefully check the background of new staff before hiring them.
- We train our staff on how to handle your information securely.
- Each year, we engage external experts to review our processes and ensure that we are in compliance with all regulations.
- We regularly test our app and systems for any weaknesses.
- We fix any problems in our computer code to make sure it is safe.
- We often check to make sure we are following our safety plans and rules.
Responsible Use of Artificial Intelligence
At Infiheal, we use Artificial Intelligence (AI) programs to understand what you communicate to us. These AI programs, including Healo, help us engage with you effectively and guide you towards useful resources and information. Our AI systems operate under set rules and do not learn independently. We ensure that Healo is fair, safe and handles your personal information with care.
If you use the Healo service, we utilize Generative AI technology to assist you. We have implemented robust safety measures to maintain the security and reliability of our conversations. Additionally, we have established best practices for monitoring and reviewing AI usage at Infiheal, ensuring that your rights and privacy are always protected. If you have any questions about our use of AI, please reach out to us at support@infiheal.com.
While we strive to keep your personal data safe, no security method is flawless. You can also help protect your information by not copying or sharing your chats with anyone you do not trust.
Payment Data
We do not collect, keep, or store your credit card information. Third-party payment companies handle your card processing. We do not get any personal data from app stores after you buy something or from our third-party payment providers. However, we might note the name of the business for our internal purposes. Please read the payment gateway’s terms and privacy policy before you make a payment. We do receive and handle payment confirmations and subscription details. This is to help you with your subscription requests.
Third-Party Sites
The app might have links to other websites or resources. When you click on these links, remember that these other sites have their own rules about privacy. We do not control these other sites and we are not responsible for their privacy rules. It is a good idea to read their privacy rules before you share any personal data on those sites.
Children’s Privacy
Our services are intended for individuals who are at least 13 years of age, or the minimum age of digital consent as defined by applicable laws in your jurisdiction (for example, 16 years in certain regions under the GDPR). If you are using our services through an institution (such as a school or healthcare provider), you must also follow the age criteria and rules set by that institution. We do not knowingly collect personal information from children under the applicable age of digital consent. If you are a parent or guardian and believe that your child has provided personal data to us, please contact us immediately. Once we verify the request, we will take appropriate steps, including deletion of the child's account and associated data. If we are unable to verify the identity of the requester, we may be unable to fully comply.
We encourage parents and guardians to actively supervise their children's online activity. Children should not share personal information without parental consent, and payment methods (such as credit/debit cards) should never be provided to children for in-app purchases.By using our services, you confirm that you meet the required age criteria, and you acknowledge that we are not responsible if users misrepresent their age in order to access our services.
Best Practices
We want to help you stay safe online. Here are some important tips to stay secure:
- Always lock your mobile screen with a password. Make sure it is strong and do not share it with anyone. Never leave your device alone.
- Always update your mobile’s operating system to the latest version.
- Turn on remote access on your device so you can find and control it if it gets stolen.
- Install anti-virus software to protect your device from viruses.
- Be careful with emails. Do not open files, click on links, or download anything from sources you do not know.
- Be smart about using Wi-Fi. Before sending personal or important data over a public Wi-Fi in places like a coffee shop or airport, check if the network is safe.
WHO WE SHARE INFORMATION WITH
Service Providers: We work with third-party companies that help us operate our app, resolve technical issues and provide essential services. These companies may have access to your personal data to carry out services on our behalf. We ensure that these providers handle your data in accordance with our privacy standards.
Legal Requirements: In certain situations, we must use your personal data to comply with legal requirements. This might involve sharing your information with organizations like insurance companies, courts, law enforcement, or other authorized entities. We may also use your information to prevent significant health or safety issues, compile public health reports, or preserve data for legal proceedings. Additionally, we might share your information to aid in fraud prevention or criminal investigations. We take steps to ensure your rights and interests are protected during these situations.
Reorganization: If there are changes such as selling our business, merging with another company, undergoing reorganization, or facing bankruptcy, we may need to share some of your personal data with others involved in the business transaction. These third parties will use your data to assess the business deal. After the changes occur, we may also share your information with the new company for the same purposes outlined in this privacy policy. We will make an effort to inform you of such changes by posting a notice on our website, notifying your Institution, sending you a notification in the app, or updating this privacy notice.
SHARING INFORMATION OUTSIDE YOUR COUNTRY
Occasionally, we may need to share, store and manage your information with our service providers located in other countries. Some of these service providers may be in regions where data protection laws are not as strict as those in your country. To ensure your data remains protected, we have agreements with our service providers that include comprehensive data protection requirements.
We only share the necessary data between our Infiheal offices to deliver the best possible service to you. We employ robust technologies and security measures to keep your information safe during cross-border transfers.
If you have any questions regarding how we transfer your data internationally, please contact us at support@infiheal.com.
YOUR DATA PROTECTION RIGHTS
When You Trigger “Reset My Data” from App Settings: The "Reset My Data" feature is available in the app settings. If you choose to use this feature, all your personal information—including your ID, past conversations, reminders, assessment responses and settings—will be permanently deleted or the links between these will be permanently broken so that no one can track back any detail from our system. Once reset, you will be treated as a new user and no old data can be retrieved. Please consider this carefully before using this feature.
Your Privacy Rights - What Can You Do About Your Data?
- Ask Questions: You can ask us how we are using your personal data.
- Get a Copy: You have the right to request a copy of the personal data we hold about you.
- Fix It: If any of your personal data is incorrect or incomplete, you can request that we correct it.
- Delete It: You can ask us to delete your personal data if it is no longer necessary for our purposes.
- Pause It: If you have questions about how your data is being used, you can ask us to temporarily stop processing it by emailing us at support@infiheal.com.
- Change Your Mind: If you previously gave consent for something, you can withdraw it at any time by emailing us at support@infiheal.com.
- Send It Elsewhere: You have the right to request that we send your encrypted and masked data electronically to another service.
- Object: You can object to our use of your personal data for activities we deem necessary.
- No Marketing: If you do not want to receive marketing emails, simply click ‘unsubscribe’ in the email footer or by emailing us at support@infiheal.com.
- Be Fair: We will not treat you unfairly for exercising your rights when using our app.
- No Sale: You can opt out of having your personal data sold or shared with others who might want to sell it.
Automated Decisions: We use AI to assist you, but we do not use AI to make decisions that define your identity. We always seek your input before making key suggestions. If you feel that the AI is not helping you, we can adjust our approach accordingly. We or our service providers may use AI for automated decision-making or information processing when necessary to perform our services or to prevent fraud, abuse, or misuse. By using our services, you consent to our use of AI for these purposes. We may modify our automated processes in the future to improve your experience.
This version has been adapted to align with the context and specific features of Infiheal, including the AI Coach, Healo. It emphasizes transparency in data sharing practices, user rights and responsible use of artificial intelligence, providing users with the necessary tools and information to exercise their data protection rights.
HOW TO EXERCISE YOUR RIGHTS
You typically do not have to pay anything to exercise your rights. However, we may need to verify your identity to ensure that the request is legitimate. You can contact us using the details provided at the beginning of this privacy policy. We will respond to your request within one month.
If a data breach occurs that could seriously affect your rights and freedoms, we will inform you as required by data protection laws.
When We Might Say "No"
We may not be able to fulfill your request if:
- The law prevents us from doing so.
- It affects someone else’s privacy.
- It could cause harm to you, us, or someone else.
- The request is unreasonable or does not make sense.
HOW TO COMPLAIN
If you have any concerns about how we use your personal data, you can file a complaint by contacting us using the details provided at the beginning of this privacy policy. We aim to respond to your complaint within three working days. Some issues may take longer to resolve, but we will keep you updated throughout the process.
If you are not satisfied with our response, you can escalate the matter by emailing us at support@infiheal.com.
SUPPLEMENTARY PRIVACY NOTICES
For more information, please refer to our supplementary privacy notice applicable to specific regions, such as the USA.
CHANGES TO THIS POLICY
If we make changes to our Privacy Policy, we will inform you within our platforms. By continuing to use our services using our platform after these updates, you are agreeing to the revised terms.
Contact Us
Don't hesitate to contact us if you have any questions.
Via Email:
support@infiheal.comVia Phone (Optional):
9619111300Via Website:
infiheal.com/contactVia Address:
17 Yashodhan, Dinshaw Wachha Road, Churchgate, Mumbai - 400020