Privacy Policy
Welcome to Metaboliq (“Metaboliq”, “Company”, “We”, “Us” or “Our”). Metaboliq is operated by WITNESS THE FITNESS PRIVATE LIMITED, a private limited company incorporated under the Companies Act, 2013, bearing Corporate Identity Number (CIN) U74999UP2021PTC150280 and Permanent Account Number (PAN) AADCW0244J, having its registered office at Flat No. S-1502, Amarpali Silicon City, Sector 76, Noida West, Noida, Gautam Buddha Nagar, Uttar Pradesh, India – 201306 (hereinafter referred to as the “Company”, which expression shall, unless repugnant to the context or meaning thereof, be deemed to mean and include its successors and permitted assigns).
This Privacy Policy (“Policy”) describes the manner in which the Company collects, receives, accesses, stores, uses, processes, shares, transfers, retains and protects information relating to identifiable or identifiable users when they access or use Metaboliq’s website, mobile application, digital platforms, programs, products and services, or otherwise interact with the Company (collectively, the “Services”).
This Policy is intended to provide transparency regarding the categories of information processed, the purposes for which such information is processed, the circumstances in which information may be shared, the security and retention practices adopted by the Company, and the choices and rights available to users under applicable law.
Definitions and Interpretation
“Personal Information” means information that relates to an identified or identifiable individual, or any other category of personal data/information recognised under applicable law.
“Processing” includes collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, sharing, transmission, restriction, deletion or destruction, as applicable.
“User”, “You” or “Your” means any person who accesses, registers with, purchases from, communicates with, or otherwise uses the Services.
References to applicable law include applicable Indian privacy, data protection, information technology, consumer protection and other laws, rules, regulations, notifications and amendments applicable to the relevant processing activity.
Scope and Applicability
This Policy applies to Personal Information collected through the Metaboliq website, mobile application, online forms, registrations, consultations, assessments, customer support, communications, transactions and other channels through which the Company provides or facilitates the Services.
This Policy does not govern the privacy practices of independent third parties, external websites, payment gateways, healthcare professionals, consultants or other service providers except to the extent the Company is legally responsible for their processing on its behalf.
Consent and Lawful Processing
Where consent is required under applicable law, the Company will seek consent in an appropriate manner before processing Personal Information for the relevant purpose. Consent may be recorded electronically, digitally, in writing or through another legally permissible mechanism.
You may decline to provide information that is not mandatory. However, certain Services may require specific information for registration, assessment, consultation, payment, service delivery, customer support, security or compliance purposes.
Where legally permitted, the Company may process information without separate consent where another lawful basis or statutory ground applies, including compliance with legal obligations, performance of a contract, prevention of fraud or security incidents, exercise or defence of legal rights, or other permitted purposes.
Where consent is the applicable basis, you may withdraw consent in accordance with applicable law. Withdrawal may affect the availability of a Service where the information is necessary for that Service.
Categories of Personal Information
Depending on the Services used, the Company may collect:
- Identity and demographic information: name, age/date of birth, gender and related registration details.
- Contact information: telephone/mobile number, email address and address details.
- Account information: username, login credentials, user ID, profile information and account preferences.
- Health and wellness information: information voluntarily provided for fitness, wellness, nutrition, lifestyle, consultation, assessment or related Services, including relevant reports or records where applicable.
- Transaction information: purchase history, invoices, billing information, payment status and limited transaction details required to administer payments.
- Communications: emails, messages, support requests, feedback, complaints and records of interactions with authorised Company personnel.
- Usage information: access time, frequency, duration, features used, preferences, interactions and other usage patterns.
- Technical information: IP address, device/browser type, operating system, language, time zone, referring URL, log data, error information and similar technical identifiers.
- Cookies and similar technologies: information collected through cookies, SDKs, pixels, tags or comparable technologies.
- Other information: information voluntarily provided by you or lawfully obtained in connection with the Services.
Information Relating to Professionals, Coaches and Service Providers
Where the Services involve doctors, nutritionists, trainers, coaches, consultants or other professionals, the Company may process professional and service-related information necessary to coordinate appointments, consultations, service delivery, communications, billing, quality management and compliance.
Independent professionals may have their own professional obligations and privacy notices. Where they process information independently rather than on behalf of the Company, their own applicable privacy terms may apply.
How We Collect Information
Information may be collected directly when you register, complete forms, purchase Services, provide information during consultations or assessments, contact customer support, submit feedback, participate in programs, communicate through email/SMS/WhatsApp or similar channels, or otherwise provide information.
The Company may also collect information automatically when you use the Website or Application, including through logs, cookies and similar technologies.
Where permitted by law, the Company may receive information from authorised service providers, payment processors, technology partners, referral partners or other third parties in connection with the Services.
Purposes of Collection and Processing
Personal Information may be processed for one or more of the following purposes:
- To create, authenticate and manage user accounts;
- To provide, administer and personalise requested Services;
- To schedule and manage consultations, appointments, assessments and programs;
- To process orders, payments, refunds, invoices and other transactions;
- To communicate service-related information, reminders, alerts and support responses;
- To improve Website/Application functionality, user experience, products and Services;
- To conduct analytics, research, statistical analysis and business intelligence, including using aggregated or appropriately de-identified information where feasible;
- To maintain records and administer agreements;
- To detect, investigate and prevent fraud, abuse, unauthorised activity and security incidents;
- To comply with legal, regulatory, tax, accounting and contractual obligations;
- To respond to lawful requests, notices, court orders and governmental processes;
- To establish, exercise or defend legal claims and protect the rights, property and safety of the Company, users and other persons;
- To send promotional or marketing communications where legally permitted and subject to applicable consent/choice requirements.
Communications and Marketing
The Company may contact users through telephone, SMS, email, WhatsApp, push notifications, in-app communications or other permitted channels for service administration, appointment reminders, technical issues, payment reminders, security notices, customer support and other operational matters.
Where permitted by law, the Company may send information about products, programs, offers or services of the Company or selected partners. Users may opt out of promotional communications through the available unsubscribe mechanism or by contacting the Company, subject to applicable law and the continued delivery of essential service communications.
Business Transfers and Corporate Transactions
In the event of a proposed or completed merger, acquisition, restructuring, financing, sale of assets, transfer of business or similar corporate transaction, Personal Information may be transferred as part of the relevant transaction, subject to applicable law and appropriate confidentiality and security measures.
Any successor or transferee receiving Personal Information will be expected to handle it consistently with applicable legal requirements and the applicable privacy commitments, subject to any revised policy or notice that may lawfully apply.
Cross-Border Data Transfers
Personal Information may be stored, accessed or processed in India or in other jurisdictions through the Company's infrastructure or third-party service providers, subject to applicable law.
Where cross-border processing or transfer is permitted or regulated by applicable law, the Company will take reasonable steps to comply with the applicable transfer requirements and implement appropriate contractual, organisational or technical safeguards where required.
Data Security
The Company considers the security of Personal Information important and seeks to maintain reasonable technical and organisational safeguards appropriate to the nature and risk of the information processed.
Measures may include role-based access, authentication controls, password protection, encryption where appropriate, access restrictions, monitoring, secure infrastructure, confidentiality obligations and incident-management procedures.
Access to Personal Information is restricted to personnel, contractors and service providers who require such access for legitimate and authorised purposes. Nevertheless, no electronic transmission or storage system can be guaranteed to be completely secure.
Personal Information Breaches
Where a Personal Information breach occurs, the Company will assess and respond to the incident in accordance with its internal incident-response procedures and applicable law, including any applicable requirements concerning containment, investigation, notification, remediation and cooperation with competent authorities or affected individuals.
Data Retention
The Company will retain Personal Information for no longer than reasonably necessary for the purpose for which it was collected, to provide the Services, maintain business and transaction records, comply with legal or regulatory requirements, resolve disputes, enforce agreements, prevent fraud and protect legitimate rights and interests.
Retention periods may differ by category of information. Where information is no longer required and there is no legal or legitimate reason to retain it, the Company will seek to delete, anonymise or otherwise dispose of it in accordance with applicable law and internal retention practices.
Your Rights and Requests
Subject to applicable law, users may have rights relating to their Personal Information, which may include requesting access to information, correction or updating of inaccurate information, withdrawal of consent where consent is the legal basis, deletion/erasure where legally available, nomination or other rights prescribed by applicable law, and raising a grievance.
Requests may be subject to identity verification, applicable exceptions, legal retention obligations, contractual requirements and reasonable administrative procedures. The Company may retain a limited record of the request and its resolution for compliance and audit purposes.
Accuracy and User Responsibility
You are responsible for providing information that is accurate, complete and not misleading and for updating relevant information when it changes. The Company may rely on the information supplied by you for delivering the Services.
If you provide information relating to another individual, you are responsible for ensuring that you have the necessary authority or permission to provide such information and to permit its processing, to the extent required by applicable law.
Third-Party Links, Platforms and Integrations
The Services may contain links to external websites, applications, payment gateways, social media platforms or other third-party services. These third parties may collect and process information under their own privacy policies and terms.
The Company does not control the privacy practices of third parties that operate independently. Users should review the relevant third-party privacy notices before providing information or using such third-party services.
Payment Information
Payments may be facilitated through third-party payment gateways or financial service providers. The Company may receive transaction identifiers, payment status, billing information and other information necessary to reconcile and administer transactions.
Where payment credentials are processed directly by a third-party payment provider, such information may be subject to that provider's security and privacy practices. The Company does not intend to retain complete payment-card credentials except where lawfully and operationally necessary.
Children and Minors
The Services are not intended to knowingly collect Personal Information from children except where such collection is permitted by applicable law and the required parental/guardian consent or authorisation has been obtained.
If you believe Personal Information relating to a child has been submitted without appropriate authorisation, please contact the Company using the details below so that the matter can be reviewed and appropriate action can be taken.
Data of Employees, Professionals and Business Contacts
Where the Company processes Personal Information of employees, prospective employees, doctors, coaches, consultants, vendors, partners or other business contacts, the processing may be governed by additional notices, contracts, employment documentation or internal policies, as applicable.
Legal and Regulatory Compliance
The Company may process, preserve or disclose Personal Information where reasonably necessary to comply with applicable law, regulatory requirements, tax and accounting obligations, lawful government requests, court orders, arbitration or dispute-resolution proceedings, or to exercise or defend legal rights.
Nothing in this Policy is intended to restrict any mandatory rights available to an individual under applicable law.
Grievance Redressal and Privacy Contact
For privacy-related questions, access/correction requests, consent-related requests, complaints or grievances, please contact:
Email: support@metaboliq.wtf
Registered Office: WITNESS THE FITNESS PRIVATE LIMITED, Flat No. S-1502, Amarpali Silicon City, Sector 76, Noida West, Noida, Gautam Buddha Nagar, Uttar Pradesh, India – 201306.
Please provide sufficient information to identify the relevant account or request. The Company will endeavour to address grievances and requests within the timelines prescribed under applicable law.
Changes to this Privacy Policy
The Company may modify this Policy from time to time to reflect changes in its Services, technology, business practices, legal requirements or regulatory guidance.
Where appropriate, material changes may be communicated through the Website, Application, email, in-app notification or another reasonable channel.
Your continued use of the Services after a lawful update becomes effective will be subject to the revised Policy to the extent permitted by applicable law.
Governing Law
This Policy shall be governed by and construed in accordance with the laws of India, subject to applicable mandatory privacy and data-protection rights and requirements.
Any dispute concerning this Policy shall be subject to the jurisdiction and dispute-resolution arrangements contained in the applicable agreement or terms governing the relevant Services, subject always to applicable law.
Severability
If any provision of this Policy is determined to be invalid, unlawful or unenforceable, that provision shall be interpreted or modified to the minimum extent necessary to make it lawful and enforceable, and the remaining provisions shall continue in full force to the extent permitted by law.
Entire Policy and Contact
This Policy constitutes the Company's privacy notice for the Services described herein and should be read together with applicable Terms of Use, service agreements, consent forms, notices and other contractual documents.
For clarification regarding this Policy or the Company's privacy practices, please contact the Privacy/Grievance Officer at the contact details stated above.
Annexure A – Privacy Contact / Operational Details
- Official privacy/grievance email: support@metaboliq.wtf
- Website privacy-policy URL: https://metaboliq.wtf/privacy