BeyondAge Innovations Private Limited (“BeyondAge”, “we”, “us”, “our”) is committed to protecting the privacy, confidentiality and integrity of the personal information you share with us. This policy (“Privacy Policy”) applies to the collection, storage, processing, disclosure and transfer of your Personal Information, including Sensitive Personal Information, which we may collect during your interactions with our website or otherwise in the course of providing, or in connection with the potential provision of, our services.
For the purposes of the Privacy Policy:
(a) “Personal Information” means any information that relates to a natural person, which either directly or indirectly, in combination with other information available or likely to be available, is capable of identifying such person; and
(b) “Sensitive Personal Information” or “SPDI” means such sensitive personal data or information of a person, which consists of information relating to: (i) password; (ii) financial information, such as bank account or credit card or debit card or other payment instrument details; (iii) physical, physiological and mental health condition; (iv) sexual orientation; (v) medical records and history; (vi) biometric information; (vii) any detail relating to the above clauses as provided to us to enable us to provide services; and (viii) any of the information received under any of the above clauses by us for processing, stored or processed under a lawful contract or otherwise. Provided that any information that is freely available or accessible in public domain or furnished under the Right to Information Act, 2005 or any other law for the time being in force will not be regarded as Sensitive Personal Information/ SPDI for the purposes of the Privacy Policy.
In accordance with: (a) the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; and (b) the Digital Personal Data Protection Act, 2023, and Digital Personal Data Protection Rules, 2025, in each case, to the extent applicable and as amended from time to time, this Privacy Policy outlines the manner in which “Personal Information” or “Sensitive Personal Information” will be handled or dealt with by BeyondAge.
This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and the key rights available to you under applicable law. It applies to all users of our website and Health Journey services.By using the BeyondAge website or submitting your details to begin a Health Journey, you confirm that you have read and understood this Privacy Policy, and agree to its terms and provide your explicit consent to the processing of your Personal Information (including SPDI) in accordance with and for the purposes described in this Privacy Policy.
Who We Are
BeyondAge is a longevity health platform that provides personalised, doctor-led Health Journeys across Heart Health, Metabolic Health, and Sleep Optimisation. We operate as the data controller for all personal information collected through our website and clinical intake processes.
For any questions relating to this Privacy Policy or your Personal Information (including SPDI), you may contact us at [privacy@beyondage.in]. Our registered address is MG911B, the Magnolias, DLF City Phase -V, Galleria DLF-IV, Gurugram, Haryana – 122 009, India.
What Information We Collect
[JSA Note: Please ensure that all categories of information intended to be collected, or that may be collected in the course of providing services, are expressly referenced here.]
Contact Information
When you submit an enquiry, request a consultation call, or register to begin a Health Journey, we collect your name, email address, and phone number. This information is used to identify you, communicate with you about your Journey, and manage your account within our systems.
Health and Medical Information
As a health platform, we collect information that is by its nature sensitive. This includes details about your medical history, current health conditions, family health history, medications, lifestyle factors, and the health goals you share during your consultation and assessment. Where you undergo a diagnostic panel as part of your Journey, we also hold the results of those investigations and the clinical notes and recommendations prepared by your specialist physician.
By submitting health information through our platform, you give your explicit consent for the collection, storage and processing of such information in accordance with the terms hereof. You may withdraw it at any time - see Your Rights below.
WhatsApp Communications
If you choose to contact us or continue a conversation via WhatsApp, the content of those messages - including any health information you share within them - is received and stored by us. WhatsApp communications are subject to WhatsApp’s own privacy policy in addition to this one. We recommend you do not share highly sensitive medical documents or diagnostic results over WhatsApp and use our secure platform for that purpose instead.
Website Usage Data
We collect standard technical information about how visitors interact with our website, including pages visited, time spent on each page, device type, browser, and approximate geographic location. This data is collected in aggregate and is not linked to your identity unless you have submitted your contact details. It is used solely to improve the performance and usability of the website.
You may decline to provide any Personal Information (including SPDI); however, doing so may affect our ability to provide certain services or part thereof that rely on such information. Where the provision of Personal Information and/ or SPDI is necessary for core functionality, we may be unable to provide the relevant services.
How We Use Your Information
To Deliver Your Health Journey
The primary purpose for which we hold your contact and health data is to provide you with the clinical services you have requested. This includes scheduling and conducting your consultation call, assigning you to the appropriate specialist team, ordering and processing your diagnostic panel, and delivering your results and written action plan.
To Communicate With You
We use your contact details to send you information directly relevant to your Journey - appointment confirmations, results notifications, follow-up reminders, and responses to your queries. We do not send unsolicited marketing communications without your separate, explicit consent.
To Improve Our Platform
Aggregated, anonymised usage data helps us understand how visitors navigate the website and where the experience can be improved. This analysis does not involve your personal or health information in an identifiable form.
To Meet Legal Obligations
In certain circumstances, we may be required to process or retain your data in order to comply with a legal obligation, including obligations arising under Indian law, applicable medical record-keeping requirements, or a lawful order from a regulatory or judicial authority.
Who We Share Your Data With
BeyondAge does not sell your Personal Information or SPDI. We do not share your information with advertisers, data brokers, or any third party for their own commercial purposes. Subject to the applicable law, we may disclose Personal Information or SPDI only where necessary for the provision of the services, or where required under applicable law. All disclosures will be subject to appropriate contractual and organisational safeguards, requiring processors to maintain confidentiality, security, and purpose limitation.
CRM and Communication Platforms
We use third-party customer relationship management (CRM) software to manage the administrative side of your Journey - tracking consultation scheduling, follow-up tasks, and communication history. Your name, contact details, and Journey status are stored within this system. These platforms are contractually bound to process your data only on our instructions and in accordance with applicable data protection law. We do not share health or diagnostic data with CRM platforms.
Your Clinical Team
Your health information is accessible to the BeyondAge specialist physician and health guide assigned to your Journey. It is not shared with other doctors on the BeyondAge team without your knowledge, and it is never disclosed to any party outside BeyondAge without your explicit consent, except where required by law.
Legal and Regulatory Disclosure
We may disclose your information if required to do so by law, court order, or the request of a competent government authority. Where we are legally permitted to notify you of such a request before complying, we will do so.
Additionally, the Personal Information or SPDI may be disclosed to the following types of third parties (whether in India or overseas):
(a) agents, contractors, service providers and external advisers engaged by us from time to time to provide services or advise on the functions/ activities where the Personal Information or SPDI is required;
(b) other related bodies corporate/ affiliates of BeyondAge;
(c) any person who BeyondAge deems necessary for carrying out the instructions you give to BeyondAge.
Your Rights
Under the applicable law, you have a number of rights in relation to the Personal Information and SPDI we hold about you. We take these rights seriously and will respond to any valid request within the timeframes required by law.
Right to Access
You may request a copy of the Personal Information, including SPDI BeyondAge holds about you, including your contact information, health data on file, and a summary of how it has been used.
Right to Correction
If any of the information we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. Given the clinical nature of the data we hold, accuracy is a priority for us and we will act on correction requests promptly.
Right to Erasure
You may request that we delete any of your Personal Information and/ or SPDI. We will honour such requests where we are not required by law to retain the data - for example, where medical record-keeping regulations impose a minimum retention period, we will explain this to you and retain only what is legally required.
Right to Withdraw Consent
Where we process your data on the basis of your consent - which is the primary basis on which we hold sensitive health data - you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to Data Portability
You may request a copy of your Personal Data and/ or SPDI in a structured, machine-readable format so that it can be transferred to another provider. This right applies to data you have provided directly to us and which we process on the basis of consent.
Right to Grievance Redressal
Under the applicable law, you have the right to raise a grievance with us and receive a response within the period prescribed by law. You also have the right, if unsatisfied with our response, to escalate your complaint to the Data Protection Board of India once operational.
To exercise any of the above rights, please write to us at [privacy@beyondage.in]. We will verify your identity before processing any request and respond within 30 days.
How We Protect Your Data
We apply technical and organisational measures appropriate to the sensitivity of health data. Access to personal and health information within BeyondAge is role-restricted: only the staff and clinicians directly involved in your Journey can access your records. All data in transit is encrypted. Our systems are reviewed regularly for vulnerabilities.
BeyondAge (or any authorized person on its behalf) has formulated adequate security practices and procedures to ensure that the information is adequately protected as per the applicable laws, industrial practice and standards. We strive hard for ensuring that the Personal Information and SPDI we hold is protected from misuse, loss and unauthorized access, modification or disclosure.
How Long We Keep Your Data
We retain your contact information for as long as your relationship with BeyondAge remains active and for a reasonable period thereafter in case you choose to return. Health and diagnostic data is retained for a minimum period in compliance with applicable Indian medical record-keeping regulations, and in some cases for longer where clinical continuity or legal obligations require it.
Where you request erasure of your data and we are able to comply, all identifiable records will be deleted. Anonymised, aggregate data derived from your information may be retained for platform improvement purposes indefinitely, as it cannot be used to identify you.
Children’s Privacy
BeyondAge is designed for adults aged 18 and above. We do not knowingly collect Personal Information or SPDI from individuals under the age of 18. The Personal Information or SPDI of children can be processed only with verifiable parental consent. If you believe a minor has submitted data to us without appropriate consent, please contact us at [privacy@beyondage.in] and we will delete the relevant records promptly.
International Data Transfers
BeyondAge operates primarily within India. If any of the third-party tools we use to manage communications or CRM functions process data outside India or the EEA, we ensure that appropriate safeguards are in place in accordance with the applicable law - including standard contractual clauses where required under the applicable law - before any transfer takes place.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data practices. When we do, we will update the effective date at the top of this page. For material changes that affect how we handle your health data, we will notify you directly by email or through a prominent notice on the website before the change takes effect.
Continued use of BeyondAge after a policy update constitutes acceptance of the revised terms.
Contact Us
If you have a question about this Privacy Policy, wish to exercise a right, or want to raise a concern about how your data has been handled, you may address them to our Grievance Officer/ Data Protection Officer (DPO): [JSA Note: Please include details of the individual designated the data protection/ grievance officer.]
Name: [insert]
Designation: Data Protection Officer; Grievance Officer
Email: [privacy@beyondage.in]
Phone:
Registered Address: Beyondage Innovations Private Limited, MG911B, the Magnolias, DLF City Phase -V, Galleria DLF-IV, Gurugram, Haryana – 122 009, India.
We are committed to resolving privacy concerns promptly and transparently. If you are not satisfied with our response, you have the right to escalate to the relevant data protection authority in your jurisdiction.

