Legal
Privacy Policy
How Heartivy collects, uses, stores, and protects your personal information on www.heartivy.com.
Heartivy ("we", "our", "us", or "Heartivy") respects the privacy of all users who access or use the Heartivy website, platform, or related services (collectively referred to as the "Platform"). This Privacy Policy explains how we collect, use, store, and protect the information provided by users when using the services available on www.heartivy.com.
This Privacy Policy is published in accordance with the provisions of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (DPDP Act) as applicable in India.
By accessing or using the Heartivy platform, you agree to the collection, use, and processing of your information as described in this Privacy Policy.
Download official document (DOCX)
User Consent
By accessing the Heartivy platform, you acknowledge that you have read, understood, and agreed to this Privacy Policy.
For sensitive personal data or information (such as mental health information shared during consultations), Heartivy will obtain your explicit, informed, and written consent prior to collecting or processing such information, in accordance with the IT (SPDI) Rules, 2011 and the DPDP Act, 2023.
Your continued use of the platform indicates your consent to the collection, processing, storage, and usage of your personal information as described in this policy. You have the right to withdraw your consent at any time by contacting us at support@heartivy.com, subject to any legal obligations we may have to retain your data.
If you do not agree with the terms of this Privacy Policy, you should discontinue using the platform immediately.
Information We Collect
Heartivy may collect the following categories of personal and non-personal information when users interact with the platform:
2.1 Account Registration Information
When users create an account or register on the platform, we may collect:
2.2 Sensitive Personal Data (Consultation Information)
Users may voluntarily share sensitive personal information during consultations with psychiatrists, consultants, or other professionals available on the platform. Such information may include emotional concerns, personal experiences, mental health history, or other information relevant to the consultation. This category of information is classified as Sensitive Personal Data or Information (SPDI) under Indian law and is subject to enhanced protection.
2.3 Technical Information
We may also collect technical information such as:
- Full name
- Phone number
- Email address
- Age and date of birth (for age verification purposes)
- Other details required for account creation
- IP address
- Browser type and version
- Device information and operating system
- Access time and pages visited
- Cookies and similar tracking technologies
Purpose of Information Collection
The information collected by Heartivy is used for the following specific purposes:
Heartivy will not use your personal information for any purpose beyond those listed above without obtaining your prior consent.
- Creating and managing user accounts on the platform
- Facilitating consultations between users and independent mental health professionals
- Managing Heartivy Wallet transactions and processing payments
- Providing customer support and resolving disputes
- Communicating important updates, service notifications, and platform information
- Analytics and research to improve platform services (using aggregated or anonymized data)
- Fraud detection, security monitoring, and ensuring platform integrity
- Complying with applicable legal obligations and regulatory requirements
Legal Basis for Processing Personal Data
In accordance with the Digital Personal Data Protection Act, 2023, Heartivy processes your personal data on the following legal bases:
- Consent: Processing of sensitive personal data (including mental health information) is based on your explicit consent.
- Contract: Processing necessary to provide services you have requested and agreed to under our Terms of Service.
- Legal Obligation: Processing required to comply with applicable Indian laws and regulatory requirements.
- Legitimate Interests: Processing for fraud prevention, security monitoring, and platform improvement, where such interests do not override your rights and freedoms.
Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you have the following rights regarding your personal data:
5.1 Right to Access
You have the right to obtain a summary of your personal data being processed by Heartivy and the purposes for which it is being processed.
5.2 Right to Correction and Erasure
You have the right to correct inaccurate or incomplete personal data, and to request erasure of your personal data that is no longer necessary for the purposes for which it was collected, subject to any legal obligations we may have to retain it.
5.3 Right to Withdraw Consent
You have the right to withdraw your consent for processing of your personal data at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
5.4 Right to Grievance Redressal
You have the right to have your grievances addressed in accordance with this policy. See Section 13 for Grievance Redressal details.
5.5 Right to Nominate
You may nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, please contact our Grievance Officer as detailed in Section 13 of this policy.
Heartivy Wallet System
Heartivy may provide users with a digital wallet system known as the Heartivy Wallet. Users may recharge their wallet using supported payment methods to access consultations and services on the platform.
Wallet balances may include credits purchased by the user as well as promotional credits provided by the platform. Wallet transaction details including recharge history, usage history, and payment verification data may be stored securely for transaction management and compliance purposes.
Heartivy does not store complete credit card or banking information on its servers. Payments are processed through secure third-party payment gateways compliant with applicable financial regulations.
Wallet credits can only be used within the Heartivy platform for purchasing services and cannot be withdrawn as cash or transferred to other users. In the event of account closure or termination, unused wallet credits will be handled in accordance with Heartivy's Refund and Dispute Policy. For wallet-related disputes or failed transactions, please contact support@heartivy.com within 30 days of the transaction.
Information Shared During Consultations
Heartivy operates as a technology platform that connects users with independent psychiatrists, consultants, and mental health professionals. Information shared during consultations is voluntarily provided by the user and is used for the purpose of facilitating the consultation session.
Mental health information shared during consultations is treated as Sensitive Personal Data or Information (SPDI) under Indian law and is subject to enhanced security measures and access controls.
While Heartivy implements security measures to protect user information, users are advised to exercise discretion while sharing sensitive personal details during consultations. Heartivy does not control or monitor the professional advice provided by independent consultants and professionals.
Communication and Notifications
Heartivy may contact users through email, phone calls, SMS, or other communication methods to provide updates related to consultations, platform services, wallet transactions, and account activity.
Users may also receive promotional communications, service updates, or notifications regarding platform features. Users may opt out of promotional communications at any time by:
Please note that opting out of promotional communications does not affect transactional communications related to your account and services.
- Clicking the "Unsubscribe" link in any promotional email
- Contacting us at heartiivyy@gmail.com
- Updating preferences in your account settings
Data Security
Heartivy implements reasonable security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction. We use appropriate technical and organizational safeguards including:
However, users should understand that no method of internet transmission or electronic storage is completely secure, and Heartivy cannot guarantee absolute security.
Users are responsible for maintaining the confidentiality of their account login credentials and should notify us immediately at heartiivyy@gmail.com if they suspect unauthorized access to their account.
- Secure servers with access controls
- Encrypted communications (SSL/TLS)
- Controlled access systems and role-based access
- Regular security assessments
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of users, Heartivy will:
Users may report suspected data breaches or unauthorized access to: support@heartivy.com
- Notify affected users without undue delay and within the timeframe required under applicable law
- Notify the Data Protection Board of India as required under the DPDP Act, 2023
- Take reasonable steps to contain and mitigate the breach
- Provide information about the nature of the breach, categories of data affected, and remedial steps taken
Data Retention
Heartivy retains personal information only for as long as necessary for the purposes outlined in this policy, or as required by law. The following general retention periods apply:
Upon expiry of the applicable retention period, personal data will be securely deleted or anonymized. Information may also be retained for fraud prevention, security monitoring, and regulatory compliance purposes where required.
- Account information: Retained for the duration of your active account and for up to 3 years after account closure for legal compliance purposes
- Consultation records: Retained for up to 7 years in accordance with applicable health information regulations
- Payment and wallet transaction data: Retained for up to 8 years for financial compliance
- Technical and log data: Retained for up to 1 year
Data Localization and International Transfers
Heartivy stores personal data of Indian users on servers located within India, in accordance with applicable data localization requirements under Indian law.
Where data is transferred to or processed by third-party service providers located outside India (such as analytics platforms or cloud service providers), Heartivy ensures that such transfers are subject to appropriate contractual safeguards and are carried out in compliance with the DPDP Act, 2023 and applicable rules. Users will be informed of any such international transfer where required by law.
Children's Privacy
Heartivy services are strictly intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from individuals under the age of 18. Age verification measures are implemented during registration to enforce this requirement.
If we become aware that personal information of a minor has been collected without proper authorization, we will take prompt steps to delete such information from our systems. If you believe we have inadvertently collected information from a minor, please contact us immediately at support@heartivy.com.
Third-Party Services
Heartivy may use third-party service providers to operate the platform, including:
Information shared with such providers is limited to what is necessary for their specific function and is governed by data processing agreements ensuring appropriate protection. Users are encouraged to review the privacy policies of any third-party services they interact with. Heartivy is not responsible for the privacy practices of third-party platforms once data leaves our control in accordance with their terms.
- Payment gateway providers (for processing wallet transactions and payments)
- Analytics service providers (for platform usage analysis)
- Cloud hosting and infrastructure providers
- Communication service providers (for email and SMS notifications)
Disclaimer of Professional Advice
Heartivy operates solely as a technology platform that connects users with independent psychiatrists, consultants, and mental health professionals. Heartivy itself does not provide medical, psychiatric, psychological, or therapeutic services.
All consultations and guidance provided through the platform are delivered by independent professionals. Heartivy does not guarantee the accuracy, reliability, or effectiveness of any advice or consultation provided through the platform. Users are encouraged to seek professional medical or mental health care where appropriate.
Emergency Disclaimer
IMPORTANT: Heartivy is NOT designed to provide emergency medical or mental health assistance.
If you are experiencing a medical emergency, severe mental distress, suicidal thoughts, or thoughts of harming yourself or others, please immediately:
The platform should not be used as a substitute for emergency medical care.
- Contact emergency services (Dial 112 in India)
- Contact iCall (a mental health helpline): 9152987821
- Contact Vandrevala Foundation 24x7 Helpline: 1860-2662-345
- Visit the nearest hospital emergency department
Changes to this Privacy Policy
Heartivy reserves the right to update or modify this Privacy Policy at any time. In the event of material changes — particularly changes affecting how your sensitive personal data is collected, used, or shared — Heartivy will provide active notice via email or in-app notification at least 14 days prior to the changes taking effect.
For minor or non-material updates, updated versions will be published on the platform and users are encouraged to review the policy periodically. Continued use of the platform after the effective date of updates constitutes acceptance of the revised Privacy Policy.
Grievance Redressal
In accordance with the Information Technology Act, 2000, the IT (SPDI) Rules, 2011, and the Digital Personal Data Protection Act, 2023, a Grievance Officer has been appointed to address your concerns and complaints regarding the use of your personal data.
Grievance Officer Details:
Name: Diwakar paliwal
Designation: Co-founder
Email: heartiivyy@gmail.com
Address: Building No./Flat No.: 1326-A
Road/Street: DABUA COLONY-1
Nearby Landmark: MOBILE TOWER
Locality/Sub Locality: DABUA COLONY
City/Town/Village: Faridabad
District: Faridabad
State: Haryana
PIN Code: 121001
India
Working Hours: Monday to Friday, 10:00 AM to 6:00 PM IST
Users may submit grievances in writing or via email. The Grievance Officer will acknowledge complaints within 48 hours and endeavor to resolve them within 30 days of receipt.
If you are not satisfied with the resolution provided, you may escalate your grievance to the Data Protection Board of India once it is constituted under the DPDP Act, 2023.
Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or the exercise of your data rights, users may contact:
Heartivy Support
Email: heartiivyy@gmail.com
Website: www.heartivy.com
Address: Building No./Flat No.: 1326-A
Road/Street: DABUA COLONY-1
Nearby Landmark: MOBILE TOWER
Locality/Sub Locality: DABUA COLONY
City/Town/Village: Faridabad
District: Faridabad
State: Haryana
PIN Code: 121001, India
For grievances specifically, please contact the Grievance Officer as detailed in Section 18 above.
© 2026 Heartivy. All Rights Reserved.
Questions? Contact us or email heartiivyy@gmail.com.