Privacy Policy

Hedso Health and Wellness Private Limited

Hedso Health and Wellness Private Limited (“Company”, “we”, “our”, “us”) respects an individual’s privacy and is committed to protecting the same. We are a company duly incorporated under the provisions of the Companies Act, 2013.

This Privacy Policy (“Policy”) describes how we collect, use, disclose and transfer Personal Information (as defined below), through this website of the individuals who browse, or access the website or provide information on or through the website, or whose information the Company otherwise collects, receives or processes in connection with the offer and sale of its products (“Products”) (hereinafter, collectively referred to as “Customers”, “you”, “your”, “yourself”) and ensure its compliance with applicable laws and regulations. This Policy does not apply to Personal Information collected from you offline (unless otherwise specified), to Customers of countries other than India or to third-party websites to which Website may link.

This Privacy Policy is a legally binding document between you and Hedso Health & Wellness Private Limited / Hoop (terms defined below). The terms of this Privacy Policy become effective upon your access to or use of the Website. By accessing, browsing, or using the Website, or by providing any personal information through the Website, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.

By accessing the website, or by seeking to avail of certain Products and Services (as defined in the Terms and Conditions), or by otherwise providing or accessing any information through the Website, you are required to agree to our Terms and Conditions (“Terms”) and acknowledge that your information will be stored, used and accessed in accordance with this Privacy Policy. For the purposes of this privacy policy, unless defined hereunder, all capitalized terms shall have the meaning ascribed to them under the Terms of the Use.

This Privacy Policy (“Privacy Policy”) is an electronic record in the form of an electronic contract formed under the Information Technology Act, 2000 and the rules made thereunder and the amended provisions pertaining to electronic documents / records in various statutes as amended by the information Technology Act, 2000. This Privacy Policy shall be construed in accordance with the provisions of the Information Technology (reasonable security practices and procedures and sensitive personal data of information) rules, 2011 under Information Technology Act, 2000; that require publishing of the Privacy Policy for collection, use, storage and transfer of sensitive personal data or information. This Privacy Policy does not require any physical, electronic or digital signature.

This document is published in compliance with inter alia:

(a)   Section 43A of the Information Technology Act, 2000 (“IT Act”); Information Technology Act, 2000

(b)   Regulation 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Information) Rules, 2011 (“SPDI Rules”); and

(c)   Regulations of the Intermediary Guidelines Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediaries Guidelines”).

(d)   Consumer Protection Act, 2019,

(e)   Consumer Protection (E-Commerce) Rules, 2020,

(f)    The Digital Personal Data Protection Act, 2023 (“DPDP Act”);

(g)   The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

(h)   Digital Personal Data Protection Rules (DPDP Rules), 2025

Our Privacy Policy explains: (i) what information we receive from you; (ii) how we collect and use that information; (iii) how you can provide information selectively, access and update the information; and (iv) how we process, share and protect your information.

Please read this Privacy Policy carefully. By using the Website, you indicate that you understand, agree and consent to this Privacy Policy. This Privacy policy is applicable to all users accessing or using our Website. If you do not agree with the terms of this Privacy Policy, please do not use this Website. By accessing or using our website or by otherwise giving us your information, you confirm that you have the capacity to enter into a legally binding contract under Indian law, in particular, the Indian Contract Act, 1872, and have read, understood and agreed to the practices and policies outlined in this privacy policy and agree to be bound by the privacy policy.

This Website is directed to be used by adults only who are above the age of 18 years. If you are not an adult, while you may look at our Site, but you should not make a purchase, register, or submit personal information to us. We do not knowingly collect information from minors. Minors should not be using this website with any personal information. In an event of default by the minor, the parent or the guardian will be liable to compensate for whatsoever damages arising out of such wrongful use by the minor.

If we become aware that personal data of a child has been collected without verifiable parental consent, we will take steps to delete such information.

Further, you agree and consent to receive all communications related to our services on the mobile number provided by you to the Company, even if such mobile number is registered under DND/NCPR list under the Telecom Commercial Communications Customer Preference Regulations, 2018 (“TRAI Regulations”). Notwithstanding your registration with the National Do Not Call Registry (In Fully or Partly blocked category under National Customer Preference Register set up under the Telecom Regulatory Authority of India), you hereby express your interest and accord informed consent to receive communications (including commercial communications) in relation to the Company’s services. You further confirm that no communication to you from the Company or on behalf of the Company shall be construed as Unsolicited Commercial Communication under Regulation 2(bw) of the TRAI Regulations and you have specifically opted to receive communications in this regard on the mobile number provided by you.

Please note that we review and may make changes to this Policy from time to time. When changes are made, the Policy link will include a notation “Last modified (date)” at the end of this page indicating that you should review the new terms, which will be effective immediately upon posting on this page, with an updated effective date. By accessing the Platform after any changes have been made, you signify your agreement on a prospective basis to the modified Policy and any changes contained therein.

If you are accessing or using the website from an overseas location, you do so at your own risk, and shall be solely liable for compliance with any applicable local laws.

By providing us your Information or by making use of the facilities provided by the Website, You hereby consent to the collection, storage, processing, use, sharing, disclosure and transfer of any or all of Your Personal Information and Non-Personal Information by us as specified under this Privacy Policy. You further agree that such collection, use, storage and transfer of Your Information shall not cause any loss or wrongful gain to you or any other person.

Hedso Health & Wellness Pvt Ltd acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023.

If you don’t agree with this privacy policy at any time, in part or as whole, write to us on care@hoophello.com Do not use the website or services provided on the website or provide us with any of your information.

1. HOW DO WE COLLECT YOUR PERSONAL INFORMATION?

We communicate with you through a variety of means and channels, including our website, email, phone or text messaging on your mobile phone. Such communications may involve giving to you, as well as receiving information from you. We collect and receive the Personal Information in the following ways:

2. WHAT INFORMATION DO WE COLLECT?

The Company limits itself to collect information which is necessary to ensure accurate services and is required to process your order of the Product or provide a refund and continually improve our Products and services. We collect and process the following information about you:

•       your name, phone number, email address, postal address, PIN code

•       date of birth, sex, language preference, location

•       any open data and public records such as information about you that is openly available on the Internet;

•       your occupation, interests, product interest information and in certain circumstances, your opinions and individual preferences

•       we may also verify your phone number or email address with the help of a one-time password sent to your phone number and email address.

For the purpose of this Policy, the term “Personal Information” shall mean any information that relates to you, which, either directly or indirectly, in combination with other information available or likely to be available with the Company, is capable of identifying you, which is submitted to and/or collected over the website and maintained by the Company in an accessible form, provided that, any information that is freely available or accessible in public domain or furnished under the Right to Information Act, 2005 or any other law for the time being in force shall not be regarded as Personal Information for the purposes of this Policy.

The IT Act and the SPDI Rules regulate the collection, usage, retention and disclosure of personal information, which is defined under the SPDI Rules as any information that relates to a natural person, which, either directly or indirectly, in combination with other information available or likely to be available to a body corporate, is capable of identifying such person. The SPDI Rules further define sensitive personal data or information of a person as personal information about that person relating to:

(i)    passwords;

(j)    financial information such as bank accounts, credit and debit card details or other payment instrument details;

(k)   physical, physiological and mental health condition;

(l)    sexual orientation;

(m) medical records and history;

(n)   biometric information;

(o)   any detail relating to the above clauses as provided to the body corporate for providing services; and

(p)   any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise.

You provide all information to us voluntarily. Collection, use and disclosure of Personal Information and SPDI requires your express consent. You are providing us with your consent to our use, collection and disclosure of the Personal Information and SPDI. You may choose to not provide us with Personal Information and SPDI, but in the event that you do so, we may be unable to provide you access to some aspects of our website.

We do not intentionally collect sensitive personal data such as medical records, biometric identifiers, or sexual orientation through our website, unless voluntarily provided in customer support interactions.

In the course of customer support interactions, customers may voluntarily share information about their health or medical conditions. Such information is used solely for the purpose of resolving the relevant support query and is not stored as part of your profile or used for any other purpose.

For the purposes of the Digital Personal Data Protection Act, 2023, Hedso Health & Wellness Private Limited acts as a “Data Fiduciary” with respect to personal data collected through the Website.

3. WHAT IS THE USE OF THIS INFORMATION?

The Information as supplied by the users enables us to improve our offerings and provide you the most user-friendly experience. We may use your Information for the following purposes:

•       To operate, maintain, protect, and improve our website, products and services (including advertising services), develop new products and services, deliver a user-friendly experience and improve our business as a whole;

•       To enable your access to our Website to purchase products and provide services;

•       To verify your identity;

•       To process and deliver your order with us;

•       Communicate with you about your account and activities on the website and to allow us in responding to your requests;

•       Ask for ratings and reviews of the Products and to respond to reviews, comments, or other feedback provided to us;

•       Administer a contest, promotion, survey or other site feature;

•       Sign up for our newsletter, respond to a survey or marketing communication;

•       Follow up with you after correspondence (live chat, email or phone inquiries);

•       Allow you to log in with a social media account and share activities on your social media pages;

•       Help us learn more about your shopping preferences;

•       Analysing data, tracking trends, building algorithms, creating databases for rating systems, recommendations engines, etc.;

•       Conduct marketing and performance research to assist us in measuring our customer services, benchmarking our performance and to help us improve your product and shopping experiences

•       Do internal research on our Customer’s demographics, interests, and behaviour to better understand and serve you

•       Provide you with exclusive offers at the website, tailor content, advertisements, and we provide you, and improve the Platform and/or for internal business purposes;

•       Analyze trends, track Customer’s web page movements, help identify you and your shopping cart for aggregate use;

•       For non-targeting reasons such as frequency capping, compliance, billing, ad reporting or delivery, market research or product development purposes;

•       Determine which of the offline locations containing our Products may be closest to you, provide promotional offers, and to offer Products to you

•       To comply with applicable law, legal obligations, policies and procedures, including compliance with relevant industry standards and the enforcement of our terms and conditions

•       To conduct audits and quality assessment procedures;

•       To analyse the use of our resources, troubleshooting problems and improving our Products and Services, by using the information regarding your mobile device and software.

•       To send communication related to order updates and offers through e-mail, SMS and social media channels, resolution of queries, order details, or offering new products or services;

•       To prevent, detect, investigate and take action against crimes (including but not limited to fraud and other financial crimes), any other illegal activities, suspected fraud, situations involving potential threats to the safety of any person, violations of our Terms, or as otherwise required by law; violations of Company’s terms and conditions in any jurisdiction, or any other illegal activities

•       To respond to any queries that you may have, and to communicate information to you, including notifications of any promotions or alerts, any changes/updates to the Website, or the introduction of any future fees or charges that we may collect at the time for purchasing Products or provision of our Services to you;

•       To establish, exercise or defend legal rights in connection with legal proceedings (including any prospective legal proceedings) and seek professional or legal advice in relation to such legal proceedings;

•       To comply with any applicable law, regulation, legal process or enforceable governmental request; and

•       To contact you, by way of SMS, email and phone calls, from time to time to record your feedback on our Products and Services, as they currently stand, and/or any potential Products and Services that may be offered in the future.

(Collectively, the above constitute “the Purposes”).

The legal basis on which we collect your Personal Information:

You can withdraw your consent, as per this Policy where applicable. You can also opt out of receiving non-essential communications such as promotional and marketing-related information regarding our Products and Services. For either, please contact us by sending an email to care@hoophello.in

We may also collect and/or generate anonymized and aggregated information from your use of the Website. The anonymized or aggregated information is not Personal Information since we are not able to re-identify you using any means available to us from that anonymized or aggregated information. The anonymized and aggregated information is used for a variety of functions, including to help us identify and remediate any bugs, and to improve the performance of our Website. The Company may use such information in a number of ways, including internal analysis, analytics and research. We may share this information with third parties for our or their purposes in an anonymized or aggregated form that is designed to prevent anyone from identifying you.

We maintain a social media presence, such as a Facebook, Instagram, LinkedIn and a Twitter feed. You can interact with us through social media, such as by entering our contests, posting content, sharing material from our Website, and using our social media plug-ins. When you interact with us using social media, we may receive information such as your user ID, your profile picture, photos you post, and similar information, which is often determined by your privacy settings at the relevant social media sites. We may use the information for the purposes we have described throughout this Policy. Your use of social media sites is primarily governed by the site operators’ privacy policies and terms of service, and the information you share with us and with others is largely controlled by the privacy settings you have established at those sites.

If you use the Website, you are responsible for maintaining the confidentiality of your access information and password. You are responsible for restricting access to your computer, mobile device, etc., and you agree to accept responsibility for all activities that occur under your password. We cannot secure any information that you release on your own, that you request us to release or that is released through another third party to whim you have given access.

In case of our customer care support, we may record calls for quality and training purposes.

4. HOW DO WE SHARE THE INFORMATION?

Only the persons authorized by us shall have access to your Personal Information. We may share your Personal Information only to those mentioned below and they are either subject to this Policy or follow practices at least as protective as those described in this Policy. We do not rent or sell your Personal Information to any third party. We may disclose your Personal Information and SPDI, as the case may be, to third parties in the manner and for the limited purposes specified below:

(q)   We may disclose your Personal Information to our logistics partners for processing of orders placed by you on the Website;

(r)    We may disclose personal information to service providers involved in order fulfilment or product delivery

(s)   We may disclose your Personal Information and SPDI to Doctors and medical experts to improve our Products, Services or Business;

(t)    We may disclose information to our partners, affiliates, investors, stakeholders or potential associates in an anonymized and aggregate manner, so that they too may understand how users use our Website and enable us to create a better overall experience for you;

(u)   We propose to share such information within our group companies and officers and employees of such group companies for the purpose of processing personal information on its behalf. We also ensure that these recipients of such information agree to process such information based on our instructions and in compliance with this Privacy Policy and any other appropriate confidentiality and security measures

(v)   We also share aggregated anonymous information about Users with our clients, partners, other Users, and other third parties so that they may be aware of the nature and number of Users, in order for them to be able to serve advertisements and other kinds of marketing information that may be relevant for you on our Website;

(w)  Should we plan to merge/sell all or substantially all of our business to another business entity or similar other transaction or be required by that business entity, we may transfer or disclose your Personal Information to that business entity who may collect, use or disclose such information for the purposes of evaluating the proposed transaction or for operating and managing the affairs of the acquired business or for other purposes identified in this Policy. We may disclose and transfer your Personal Information and SPDI to a third party who acquires, or may potentially acquire, our business, whether such acquisition is by way of a merger, consolidation or purchase of all or a substantial portion of our assets or investment in us;

(x)   We may retain other companies and individuals to perform functions on our behalf consistent with this Policy. Examples include order processing companies, courier companies, data analysis firms, customer support specialists, email vendors, web-hosting companies and fulfilment companies (e.g., companies that coordinate mailings). Such third parties may be provided with access to Personal Information needed to perform their functions but may not use such information other than on our behalf and in accordance with this Policy.

(y)   In addition, in some instances, you may be offered the opportunity to consent to the sharing of your information with a third party such as an event or promotion co-sponsor. If you consent, we will share your information with such third party and the information you provide may be used by such third party for their own purposes and in accordance with their own policies.

(z)   We will disclose your Personal Information and SPDI if legally required to do so, pursuant to an order from a governmental entity or in good faith. When it is requested or required by law or by any court or governmental agency or authority to disclose, for the purpose of verification of identity, or for the prevention, detection, investigation including identity theft, fraud, cyber incidents, and other potentially illegal acts or for prosecution and punishment of offences. These disclosures are made in good faith and belief that such disclosure is reasonably necessary for enforcing these Terms; for complying with the applicable laws and regulations. We will disclose the Information to: (i) conform to legal requirements or comply with legal process; (ii) protect our rights or property or our affiliated companies; (iii) prevent a crime or national security; or (iv) protect personal safety of our Users or the public.

(k) We share certain data with Meta Platforms, Inc. (“Meta”) through integrated Meta Business Tools, including the Meta Pixel and Conversions API. Data shared with Meta may include website event data (such as page views, purchases, and add-to-cart actions), device and browser information, IP address, and hashed customer identifiers (such as email address and phone number) for the purposes of advertising measurement, optimization, and audience targeting. This sharing is governed by Meta’s Platform Terms and Data Use Policy. You may control how Meta uses your data for advertising by visiting your Facebook Ad Preferences at https://www.facebook.com/adpreferences.

We may share personal data with trusted service providers including payment processors, logistics providers, analytics platforms, advertising partners, cloud hosting providers, and customer support tools who process data on our behalf.

We may share personal data with trusted service providers who assist in operating our business, including:

•       payment gateway providers

•       logistics and delivery partners

•       analytics and advertising platforms

•       cloud hosting providers

•       customer service and communication platforms

These parties process personal data only on our behalf and are contractually obligated to protect such data.

Personal data may be transferred outside India only in accordance with applicable Indian data protection laws including the Digital Personal Data Protection Act, 2023 and any government notifications regarding permitted jurisdictions.

Subject to applicable law, we may at our sole discretion, transfer Personal Information and SPDI to any other body corporate (as defined under the Information Technology Act, 2000) that ensures at least the same level of data protection as is provided by us under the terms hereof, located in India or any other country.

By using our Website with Meta Business Tools enabled (such as the Meta Pixel), certain data may be transferred to Meta Platforms, Inc., which is headquartered in the United States. Such transfers are conducted in compliance with applicable data protection laws and Meta’s Data Use Policy. By continuing to use the Website, you consent to such transfers.

By using the Website, you accept the terms hereof and hereby consent to the storage and processing of Personal Information and SPDI by third parties and in any of location outside India. The Company will make best efforts to ensure that the third party or the location to which the SPDI is transferred affords same level of data protection as would be afforded under Indian law.

By continuing to use the Website, you provide your consent for transfer, sharing and disclosure of such Personal Information or SPDI by us in accordance with this Privacy Policy.

Any third party to which we transfer or sell our assets, merge or consolidate with, will have the right to continue to use the Personal Information or SPDI provided to us by you, in accordance with the Terms and this Privacy Policy.

5. HOW DO WE STORE THE INFORMATION?

We may store Personal Information using our own secure on-site servers or other internally hosted technology. Your Personal Information may also be stored by third parties, via cloud services or other technology, with whom the Company has contracted, to support the Company’s business operations.

These third parties do not use or have access to your Personal Information other than for cloud storage and retrieval, and the Company requires such parties to employ at least the same level of security that we use to protect your Personal Information.

6. THIRD PARTY LINKS

Our policy discloses the privacy practices for our own web site only. Our site provides links to other websites also that are beyond our control. We shall in no way be responsible in way for your use of such sites.

The Website may include hyperlinks to various external websites, and may also include advertisements, and hyperlinks to applications, content or resources (“Third Party Links”). We have no control over such Third Party Links present on the Website, which are provided by persons or companies other than us. You acknowledge and agree that we are not responsible for any collection or disclosure of your information by any external sites, applications, companies or persons thereof. The presence of any Third Party Links on our Website, cannot be construed as a recommendation, endorsement or solicitation for the same, or any other material on or available via such Third Party Links.

You further acknowledge and agree that we are not liable for any loss or damage which may be incurred by you as a result of the collection and/or disclosure of your information via Third Party Links, as a result of any reliance placed by you on the completeness, accuracy or existence of any advertising, products services, or other materials on, or available via such Third Party Links. This will include all transactions, and information transmitted therein, between you and any such third party sites or applications or resources, such transactions are strictly bi-partite. We shall not be liable for any disputes arising from or in connection with such transactions between you and the aforementioned third parties.

Such third party websites, and external applications or resources, accessible via the Third Party Links may have their own privacy policies governing the collection, storage, retention and disclosure of your information that you may be subject to. We recommend that you exercise reasonable diligence, as you would in traditional offline channels and practice judgment and common sense before committing to any transaction or exchange of information, including but not limited to reviewing the third party website or application’s privacy policy.

If you post any comments or content on our website, you should be aware that any information you choose to provide there may be read, collected, or used by the third parties. We are not responsible for the information you choose to submit, and we cannot guarantee that third parties have not made copies of or will not use such information in any way.

We use third-party analytics services to evaluate your use of the Website, compile reports on activity, collect demographic data, analyze performance metrics, and collect and evaluate other information relating to the Platform and mobile and internet usage. These third parties use cookies and other technologies to help analyze and provide us the information and, in some cases, connect such information with other data held by our, or third party, environments. You consent to the processing of information about you by these analytics providers in the manner and for the purposes set out in this Policy.

7. DO WE USE COOKIES?

We may track your preferences and activities by utilizing “cookies” and other tracking technologies, having session or local variables. A “cookie” is a small data file that may be used, for example, to collect information about activity on the Website. These files are transferred to your computer’s hard-drive by a website, while using a web browser (if you allow). They keep a record of your activities on the Platform making your subsequent visits to the site more efficient. Some cookies and other technologies may serve to recall information previously indicated by a User.

Tracking technologies may record information such as internet domain and host names, internet protocol (IP) addresses, browser software and operating system types, stream patterns, and dates and times that our Website is accessed. Your IP address does not identify you personally. We use this information to deliver our web pages to you upon request, to tailor our site to the interests of our users, to measure traffic within our site and let advertisers know the geographic locations from where our visitors come.

Our use of cookies and other tracking technologies allows us to improve our Website and your experience. We may use cookies or similar tracking tools to improve the responsiveness of the sites for our users, to collect information to assign each visitor a unique, random number as a User Identification (User ID) to understand the user’s individual interests using the Identified Computer. The only personal information a cookie can contain is information you supply.

The use of cookies is a common practice adopted by most major websites to better serve their clients. Most browsers are designed to accept cookies, but they can be easily modified to block cookies. At all times, you may refuse all cookies on your browser by changing your settings to the extent permissible on your device. Most browsers/mobile settings allow you to control cookies, including whether or not to accept them and how to remove them. You may set most browsers to notify you if you receive a cookie, or you may choose to block cookies with your browser. However, by doing so, you may not be able to use certain features on the Website or take full advantage of all the offerings and interest-based advertising. However, you will still be able to place orders. You can control or remove cookies by managing or withdrawing cookie preferences through browser settings.

We use the Meta (Facebook) Pixel and Conversions API to track interactions on our website — such as page views, product views, add to cart actions, checkout initiation, and purchases. This data helps us measure advertising performance, personalize content, and improve your shopping experience.

Your Controls Over Meta Data: In addition to browser cookie controls, you can manage how Meta uses your data by: (i) adjusting your Ad Preferences on Facebook at https://www.facebook.com/adpreferences; (ii) opting out of interest-based advertising through the Digital Advertising Alliance at https://www.aboutads.info/choices; and (iii) adjusting your device-level advertising settings on your mobile device. Please note that opting out of interest-based advertising does not mean you will stop seeing advertisements; rather, the ads you see may be less relevant to your interests.

Note: We do not collect or share any personal health or medical data through our website or advertising tools.

8. CHANGES TO YOUR INFORMATION AND DATA DELETION

You may review, correct, update, change or delete your Personal Information relating to Registration Information and Order Information on the Website by writing to us at the contact details specified below. You can delete any part of the Personal Information or request us to delete the same, and we will comply with such requests within a reasonable time, unless we are required to keep certain information for legal purposes. You may update your SPDI at any point by writing to us at the details indicated below in the contact section.

Should you choose to delete your Personal Information or SPDI or modify it in a way that is not verifiable by us, or leads to such information being incorrect, we will be unable to provide you with access to our Website or our Services, as described under the Terms, and such a deletion or modification may be regarded as the User seeking to discontinue his or her access to our Website and Services.

We reserve the right to verify and authenticate your identity and your Personal Information in order to ensure accurate delivery of Products and Services. Access to or correction, updating or deletion of your Personal Information or SPDI may be denied or limited by us if it would violate another person’s rights and/or is not otherwise permitted by applicable law.

How to Request Deletion of Your Data: You may request the deletion of your personal data at any time by emailing us at care@hoophello.com with the subject line “Data Deletion Request.” Upon receiving your request, we will verify your identity and delete your personal data from our systems within 30 days, unless retention is required by applicable law or for legitimate business purposes (such as fulfilling a pending order or complying with tax and accounting obligations). Where we have shared your data with third parties (including Meta Platforms, Inc.), we will take reasonable steps to inform such third parties of your deletion request. You may also request deletion of your data collected via Meta Business Tools by contacting Meta directly through your Facebook account settings.

9. INFORMATION SECURITY

We take appropriate security measures to protect against unauthorized access to or unauthorized alteration, disclosure or destruction of data. These include internal reviews of our data collection, storage and processing practices and security measures, including appropriate encryption and physical security measures to guard against unauthorized access to systems where we store personal data.

We endeavour to maintain physical, technical and procedural safeguards that are appropriate to protect your Information against accidental, unlawful or unauthorized access, disclosure, destruction, loss, alteration, misuse, copying, damage, or modification.

We review our information collection, storage and processing practices, including physical security measures, to guard against unauthorized access to systems. We restrict access to Personal Information, to our employees and agents who need to know that information in order to process it for us, and who are subject to strict contractual confidentiality obligations, and may be disciplined or whose relationship with us may terminate if they fail to meet these obligations. No employee or administrator of the Company will have knowledge of your password of your account on the Website.

However, we shall not be liable to any user for any loss, damage (whether direct, indirect, consequential or incidental) or harm caused to the user due to the unauthorized access or misuse of the Personal or Sensitive Information by any third party. We cannot guarantee that information you supply will not be intercepted while being transmitted to us over the Internet. Further, any information you include in a posting to the discussion areas is available to anyone with Internet access.

It is important for you to protect against unauthorized access to your password and your mobile phone, as detailed in the ‘User Account, Password and Security’ section of the Terms. You must be sure to log off from the Website when you have finished use thereof. We do not undertake any liability for any unauthorised use of your account and password.

If you suspect any unauthorized use of your account, you must immediately notify us by sending an email to the contact details indicated in the contact section. You shall be liable to indemnify us due to any loss suffered by us due to such unauthorized use of your account or password.

Further, we shall not be responsible for any breach of security or for any actions of any third parties or events that are beyond our reasonable control including but not limited to acts of government, computer hacking, unauthorised access to computer data and storage device, computer crashes, breach of security and encryption, poor quality of internet service or telephone service of the User, etc.

In the event of any data breach affecting personal data, the Company will take appropriate steps to mitigate the breach and will notify affected individuals and relevant authorities where required under applicable law.

10. INFORMATION RETENTION AND DISPOSAL

We will retain your Personal Information only for as long as necessary to fulfil the purposes described in this Policy or as required by applicable law.

Typical retention periods include:

•       Order and transaction data: up to 8 years for tax and accounting compliance

•       Customer account data: until account deletion or inactivity for extended periods

•       Marketing communication data: until you opt-out

•       Customer support records: up to 3 years

We will only use your Personal Information for the purposes and will make sure that your privacy is protected. We shall take reasonable steps to delete or permanently de-identify Personal Information that is no longer needed.

We also have measures in place such that your SPDI which is in our possession or under our control, is destroyed and/or anonymized as soon as it is reasonable to assume that: (i) the Purposes for which your SPDI has been collected have been fulfilled; and (ii) retention is no longer necessary for any other reason. We may, however, reserve the right to retain and store your Personal Information for our business purposes, whether such Personal Information has been deleted or not. After a period of time, your data may be anonymized and aggregated and then may be held by us as long as necessary, to enable purchases of Products and provision of Services or for analytics purposes.

If you wish to withdraw your consent for processing your Personal Information and SPDI, cancel your account, or request that we no longer use your Personal Information and SPDI to deliver our Products or provide you Services, please contact us at details indicated in the contact section below. Please note, however, that your withdrawal of consent or cancellation of account may result in us not being able to deliver you Products or provide you with our Services, or terminate any existing relationship that we may have with you.

11. WITHDRAWAL OF CONSENT

If you have consented to the collection, use and/or disclosure of your Personal Information as identified in this Policy, you have the right to withdraw this consent at any time by writing an email to us. Please note that any processing that we have carried out before the withdrawal of your consent remains lawful. Provided that, notwithstanding such request, this information may be retained to comply with our legal obligations, resolve disputes and enforce our agreements.

The website provides an option to all the Customers to opt-out of receiving any promotional or marketing communications from us. If you do not wish to receive any promotional or marketing communications from us, you can write an email to us. You can also click on the “unsubscribe” link at the bottom of any promotional e-mail that you receive.

You can remove content that you posted on a public space, such as part of a ratings and review, by writing an email to us. Please note that we will endeavour and try to ensure to honour your request to remove information, however, our removal of your information does not completely erase that information from the internet viz. historical copies, or “caches,” may remain.

For all of the above, please email us at care@hoophello.com

Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:

•       Right to access information about the personal data we process about you

•       Right to request correction or updating of inaccurate personal data

•       Right to request deletion of personal data where it is no longer necessary

•       Right to withdraw consent for processing personal data

•       Right to nominate another individual to exercise these rights in case of death or incapacity

•       Right to raise grievances with the Data Protection Board of India

You may exercise these rights by contacting us at the contact details provided in this Policy.

GRIEVANCE REDRESSAL

If you are concerned about the handling of your Personal Information, or if you have any complaints or queries related to your Personal Information or our Policy, please contact:

Nona Uppal - Chief Marketing Officer

Grievance Officer

Hedso Health & Wellness Pvt Ltd

28 Vidya Vihar, West Enclave, Pitampura, Delhi – 110034

Email: care@hoophello.com

Ph: +91-9818320509

The Grievance Officer is identified above pursuant to the provisions of applicable laws including but not limited to the Information Technology Act, 2000 and the Consumer Protection Act, 2019, Digital Personal Data Protection Act, 2023 and the rules enacted under those laws. All grievances will be acknowledged within 48 hours of receipt and resolved within 30 days in accordance with the Consumer Protection (E-Commerce) Rules, 2020.

Note on Meta Platform Compliance: This Privacy Policy complies with the Meta Platform Terms and Developer Policies. For questions regarding how Meta processes your data, please refer to Meta’s Data Policy at https://www.facebook.com/privacy/policy/. Our use of Meta Business Tools (including the Meta Pixel and Conversions API) is governed by the Meta Business Tools Terms at https://www.facebook.com/legal/terms/businesstools. If you have concerns about data shared with Meta through our Website, you may contact us at care@hoophello.com or manage your Meta ad preferences directly at https://www.facebook.com/adpreferences.

Privacy Policy

Effective Date: 12 March 2026

Last Updated: 12 March 2026