BeyondAge ("we", "us", "our") is committed to protecting the personal information you share with us. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and the rights available to you under applicable law. It applies to all users of our website and Health Journey services.
This Policy is governed by the Digital Personal Data Protection Act 2023 (India) and, where applicable to users located in the European Economic Area or United Kingdom, the General Data Protection Regulation (GDPR). In the event of any conflict between the two frameworks as they apply to your data, the stricter standard will govern.
By using the BeyondAge website or submitting your details to begin a Health Journey, you confirm that you have read and understood this Policy.
Who We Are
BeyondAge is a longevity health platform that provides personalised, doctor-led Health Journeys across Heart Health, Metabolic Health, and Sleep Optimisation. We operate as the data controller for all personal information collected through our website and clinical intake processes.
For any questions relating to this Policy or your personal data, you may contact us at contactus@beyondage.health.
What Information We Collect
Contact Information
When you submit an enquiry, request a consultation call, or register to begin a Health Journey, we collect your name, email address, and phone number. This information is used to identify you, communicate with you about your Journey, and manage your account within our systems.
Health and Medical Information
As a health platform, we collect information that is by its nature sensitive. This includes details about your medical history, current health conditions, family health history, medications, lifestyle factors, and the health goals you share during your consultation and assessment. Where you undergo a diagnostic panel as part of your Journey, we also hold the results of those investigations and the clinical notes and recommendations prepared by your specialist physician.
Under both the DPDP Act 2023 and the GDPR, health data is classified as sensitive personal data requiring explicit consent before it is collected or processed. By submitting health information through our platform, you give that consent. You may withdraw it at any time - see Your Rights below.
WhatsApp Communications
If you choose to contact us or continue a conversation via WhatsApp, the content of those messages - including any health information you share within them - is received and stored by us. WhatsApp communications are subject to WhatsApp's own privacy policy in addition to this one. We recommend you do not share highly sensitive medical documents or diagnostic results over WhatsApp and use our secure platform for that purpose instead.
Website Usage Data
We collect standard technical information about how visitors interact with our website, including pages visited, time spent on each page, device type, browser, and approximate geographic location. This data is collected in aggregate and is not linked to your identity unless you have submitted your contact details. It is used solely to improve the performance and usability of the website.
How We Use Your Information
To Deliver Your Health Journey
The primary purpose for which we hold your contact and health data is to provide you with the clinical services you have requested. This includes scheduling and conducting your consultation call, assigning you to the appropriate specialist team, ordering and processing your diagnostic panel, and delivering your results and written action plan.
To Communicate With You
We use your contact details to send you information directly relevant to your Journey - appointment confirmations, results notifications, follow-up reminders, and responses to your queries. We do not send unsolicited marketing communications without your separate, explicit consent.
To Improve Our Platform
Aggregated, anonymised usage data helps us understand how visitors navigate the website and where the experience can be improved. This analysis does not involve your personal or health information in an identifiable form.
To Meet Legal Obligations
In certain circumstances, we may be required to process or retain your data in order to comply with a legal obligation, including obligations arising under Indian law, applicable medical record-keeping requirements, or a lawful order from a regulatory or judicial authority.
Who We Share Your Data With
BeyondAge does not sell your personal data. We do not share your information with advertisers, data brokers, or any third party for their own commercial purposes.
CRM and Communication Platforms
We use third-party customer relationship management (CRM) software to manage the administrative side of your Journey - tracking consultation scheduling, follow-up tasks, and communication history. Your name, contact details, and Journey status are stored within this system. These platforms are contractually bound to process your data only on our instructions and in accordance with applicable data protection law. We do not share health or diagnostic data with CRM platforms.
Your Clinical Team
Your health information is accessible to the BeyondAge specialist physician and health guide assigned to your Journey. It is not shared with other doctors on the BeyondAge team without your knowledge, and it is never disclosed to any party outside BeyondAge without your explicit consent, except where required by law.
Legal and Regulatory Disclosure
We may disclose your information if required to do so by law, court order, or the request of a competent government authority. Where we are legally permitted to notify you of such a request before complying, we will do so.
Your Rights
Under the Digital Personal Data Protection Act 2023 and, where applicable, the GDPR, you have a number of rights in relation to the personal data we hold about you. We take these rights seriously and will respond to any valid request within the timeframes required by law.
Right to Access
You may request a copy of the personal data BeyondAge holds about you, including your contact information, health data on file, and a summary of how it has been used.
Right to Correction
If any of the information we hold about you is inaccurate or incomplete, you have the right to ask us to correct it. Given the clinical nature of the data we hold, accuracy is a priority for us and we will act on correction requests promptly.
Right to Erasure
You may request that we delete your personal data. We will honour such requests where we are not required by law to retain the data -for example, where medical record-keeping regulations impose a minimum retention period, we will explain this to you and retain only what is legally required.
Right to Withdraw Consent
Where we process your data on the basis of your consent - which is the primary basis on which we hold sensitive health data - you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to Data Portability
You may request a copy of your personal data in a structured, machine-readable format so that it can be transferred to another provider. This right applies to data you have provided directly to us and which we process on the basis of consent.
Right to Grievance Redressal
Under the DPDP Act 2023, you have the right to raise a grievance with us and receive a response within the period prescribed by law. You also have the right, if unsatisfied with our response, to escalate your complaint to the Data Protection Board of India once operational. If you are based in the EEA or UK, you additionally have the right to lodge a complaint with your local data protection supervisory authority.
To exercise any of the above rights, please write to us at [privacy@beyondage.in]. We will verify your identity before processing any request and respond within 30 days.
How We Protect Your Data
We apply technical and organisational measures appropriate to the sensitivity of health data. Access to personal and health information within BeyondAge is role-restricted: only the staff and clinicians directly involved in your Journey can access your records. All data in transit is encrypted. Our systems are reviewed regularly for vulnerabilities.
No method of transmission over the internet is completely secure. While we take every reasonable precaution, we cannot guarantee the absolute security of data transmitted to us electronically. We ask that you take care when using public networks to access the BeyondAge platform.
How Long We Keep Your Data
We retain your contact information for as long as your relationship with BeyondAge remains active and for a reasonable period thereafter in case you choose to return. Health and diagnostic data is retained for a minimum period in compliance with applicable Indian medical record-keeping regulations, and in some cases for longer where clinical continuity or legal obligations require it.
Where you request erasure of your data and we are able to comply, all identifiable records will be deleted. Anonymised, aggregate data derived from your information may be retained for platform improvement purposes indefinitely, as it cannot be used to identify you.
Children's Privacy
BeyondAge is designed for adults aged 18 and above. We do not knowingly collect personal data from individuals under the age of 18. The DPDP Act 2023 requires that personal data of children be processed only with verifiable parental consent. If you believe a minor has submitted data to us without appropriate consent, please contact us at contactus@beyondage.health and we will delete the relevant records promptly.
International Data Transfers
BeyondAge operates primarily within India. If any of the third-party tools we use to manage communications or CRM functions process data outside India or the EEA, we ensure that appropriate safeguards are in place - including standard contractual clauses where required under the GDPR - before any transfer takes place.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data practices. When we do, we will update the effective date at the top of this page. For material changes that affect how we handle your health data, we will notify you directly by email or through a prominent notice on the website before the change takes effect.
Continued use of BeyondAge after a policy update constitutes acceptance of the revised terms.
Contact Us
If you have a question about this Privacy Policy, wish to exercise a right, or want to raise a concern about how your data has been handled, please contact our privacy team at contactus@beyondage.health.
We are committed to resolving privacy concerns promptly and transparently. If you are not satisfied with our response, you have the right to escalate to the relevant data protection authority in your jurisdiction.

