Privacy Policy
This policy explains how HEYOKAA HEALTH PRIVATE LIMITED ("Heyokaa", "we") handles personal information across our website, applications and services. Heyokaa is a mental wellbeing and clinical care platform, so much of what we handle is health information. We treat it accordingly.
1. Our role
We are the controller of your account details, assessment responses, mood and journal entries, programme activity, and website and support interactions.
We are a processor for clinical records created by a clinician, clinic or hospital using Heyokaa — there, the treating provider is the controller and their own notice governs — and for eligibility data an employer gives us to set up its programme. Where we act as a processor, we do not use the data for our own purposes.
2. What we collect
You give us: name, email, mobile number and login credentials; optional profile details such as age range, gender, department or location; your responses to wellbeing assessments; mood, sleep and check-in entries; journal entries and programme exercises; messages you send us; and, if you book care, appointment records, clinical history you disclose, session notes and any treatment plan or prescription issued by your clinician.
We collect automatically: device type, operating system, app version, browser, language, IP address (used for approximate region, not precise location), feature usage and timestamps, and crash logs.
We receive from others: eligibility lists from your employer; patient onboarding from your clinician; and transaction confirmations from our payment processor. We do not store full card numbers.
We do not collect GPS location, and we do not access your contacts, photos, microphone or camera unless you grant permission for a specific feature such as a video consultation.
3. How we use it
To operate your account and deliver assessments, programmes and your own results (contract); to enable consultations, treatment planning and clinical documentation with your clinician (contract, explicit consent, provision of health care); to personalise recommendations (explicit consent); to produce de-identified organisational reporting (contract with that organisation); to respond to credible risk of serious harm (vital interests, legal obligation); to improve and secure the Service, including audit logging and abuse detection (legitimate interests); and to meet record-keeping, tax and clinical retention obligations (legal obligation).
You can withdraw consent at any time. Withdrawal does not affect processing already carried out, and may mean parts of the Service stop working.
We do not sell personal information, and we do not use wellbeing or clinical data for advertising.
4. What your employer sees
Your employer never receives your individual assessment scores or responses, your mood or journal entries, whether you booked or attended a session, or any clinical record, note or diagnosis.
Your employer may receive aggregate, de-identified metrics — participation rates, score distributions and trends over time. We only report a group figure where at least 10 individuals are in that group; below that, the figure is suppressed so it cannot identify anyone. Where an employer pays per active user, we share the count, never the identities.
5. Safety
Assessments can surface indicators that someone is at risk of serious harm. In those cases we show you support options directly in the app, and if you are under the care of a clinician on the platform, that clinician may be alerted to follow up. We disclose information without your consent only where we reasonably believe it is necessary to prevent a serious and imminent threat to life or safety, or where the law requires it.
Heyokaa is not an emergency service and does not provide crisis monitoring. If you are in immediate danger, contact your local emergency services or a crisis helpline.
6. Who else sees it
Your treating clinician, limited to what is needed to treat you, with role-based and logged access. Service providers who run the platform — hosting, database, email and notifications, payments, video consultation, error monitoring and analytics — under written contracts restricting them to our instructions; a current list is available on request. Authorities, where required by law or to establish or defend legal claims. An acquirer, in a merger or sale, with notice to you beforehand. And anyone you direct us to share with.
7. How long we keep it
Account and wellbeing data for the life of your account, then deleted or anonymised within 90 days of closure. Clinical records for the period required by applicable medical record-keeping law or as instructed by the controlling provider. Support enquiries 24 months; billing records as tax law requires; security logs 12 months. Aggregated data that no longer identifies you may be kept indefinitely. Data in encrypted backups is isolated from active use and deleted on the backup cycle.
8. Your rights
You may access, correct, delete or export your data, withdraw consent, object to or restrict processing, nominate someone to act for you, and complain to your data protection authority. Use your account settings or write to info@heyokaa.com; we respond within 30 days and may verify your identity first, particularly for health data. If a clinician holds the record under our processor role, we will route your request to them.
Assessment scoring and programme recommendations are generated algorithmically. They are informational, are never shared with your employer, and are not a diagnosis — only a qualified clinician can diagnose or treat a condition.
9. Security
We encrypt data in transit and at rest, enforce role-based least-privilege access, log access to clinical and wellbeing records, keep production data out of development and testing, bind personnel to confidentiality, and maintain backups and a documented incident response process. No system is completely secure; if a breach is likely to affect you, we will notify you and the relevant authorities without undue delay. We do not currently hold certification under a specific security standard, and will state it here if that changes rather than imply it.
10. Transfers, cookies, children, changes
We host in Asia/India and use lawful transfer mechanisms, such as standard contractual clauses, where data moves across borders.
We use cookies that are strictly necessary (authentication, session, security), preference-based (theme, language, accessibility) and analytics. We use no advertising or cross-site tracking cookies, and ask consent for non-essential ones where required.
Self-signup is not open to anyone under 18. Where a minor is treated through a provider using Heyokaa, that provider obtains and records guardian consent. We do not profile or advertise to children.
If we make material changes to this policy we will update the date above and notify you before the change takes effect.
11. Contact
Heyokaa Health Pvt LTD, Unit 101, Oxford Towers, 139, HAL Old Airport Road, Kodihalli, Bangalore, Karnataka, India, 560008 Privacy: info@heyokaa.com · General: sales@heyokaa.com · Phone: +91 99954 98520
Grievance Officer (India, Digital Personal Data Protection Act 2023):], info@heyokaa.com
If our response does not resolve your concern, you may complain to the Data Protection Board of India or the supervisory authority in your jurisdiction.
Governed by the laws of India.
Privacy Policy
This policy explains how HEYOKAA HEALTH PRIVATE LIMITED ("Heyokaa", "we") handles personal information across our website, applications and services. Heyokaa is a mental wellbeing and clinical care platform, so much of what we handle is health information. We treat it accordingly.
1. Our role
We are the controller of your account details, assessment responses, mood and journal entries, programme activity, and website and support interactions.
We are a processor for clinical records created by a clinician, clinic or hospital using Heyokaa — there, the treating provider is the controller and their own notice governs — and for eligibility data an employer gives us to set up its programme. Where we act as a processor, we do not use the data for our own purposes.
2. What we collect
You give us: name, email, mobile number and login credentials; optional profile details such as age range, gender, department or location; your responses to wellbeing assessments; mood, sleep and check-in entries; journal entries and programme exercises; messages you send us; and, if you book care, appointment records, clinical history you disclose, session notes and any treatment plan or prescription issued by your clinician.
We collect automatically: device type, operating system, app version, browser, language, IP address (used for approximate region, not precise location), feature usage and timestamps, and crash logs.
We receive from others: eligibility lists from your employer; patient onboarding from your clinician; and transaction confirmations from our payment processor. We do not store full card numbers.
We do not collect GPS location, and we do not access your contacts, photos, microphone or camera unless you grant permission for a specific feature such as a video consultation.
3. How we use it
To operate your account and deliver assessments, programmes and your own results (contract); to enable consultations, treatment planning and clinical documentation with your clinician (contract, explicit consent, provision of health care); to personalise recommendations (explicit consent); to produce de-identified organisational reporting (contract with that organisation); to respond to credible risk of serious harm (vital interests, legal obligation); to improve and secure the Service, including audit logging and abuse detection (legitimate interests); and to meet record-keeping, tax and clinical retention obligations (legal obligation).
You can withdraw consent at any time. Withdrawal does not affect processing already carried out, and may mean parts of the Service stop working.
We do not sell personal information, and we do not use wellbeing or clinical data for advertising.
4. What your employer sees
Your employer never receives your individual assessment scores or responses, your mood or journal entries, whether you booked or attended a session, or any clinical record, note or diagnosis.
Your employer may receive aggregate, de-identified metrics — participation rates, score distributions and trends over time. We only report a group figure where at least 10 individuals are in that group; below that, the figure is suppressed so it cannot identify anyone. Where an employer pays per active user, we share the count, never the identities.
5. Safety
Assessments can surface indicators that someone is at risk of serious harm. In those cases we show you support options directly in the app, and if you are under the care of a clinician on the platform, that clinician may be alerted to follow up. We disclose information without your consent only where we reasonably believe it is necessary to prevent a serious and imminent threat to life or safety, or where the law requires it.
Heyokaa is not an emergency service and does not provide crisis monitoring. If you are in immediate danger, contact your local emergency services or a crisis helpline.
6. Who else sees it
Your treating clinician, limited to what is needed to treat you, with role-based and logged access. Service providers who run the platform — hosting, database, email and notifications, payments, video consultation, error monitoring and analytics — under written contracts restricting them to our instructions; a current list is available on request. Authorities, where required by law or to establish or defend legal claims. An acquirer, in a merger or sale, with notice to you beforehand. And anyone you direct us to share with.
7. How long we keep it
Account and wellbeing data for the life of your account, then deleted or anonymised within 90 days of closure. Clinical records for the period required by applicable medical record-keeping law or as instructed by the controlling provider. Support enquiries 24 months; billing records as tax law requires; security logs 12 months. Aggregated data that no longer identifies you may be kept indefinitely. Data in encrypted backups is isolated from active use and deleted on the backup cycle.
8. Your rights
You may access, correct, delete or export your data, withdraw consent, object to or restrict processing, nominate someone to act for you, and complain to your data protection authority. Use your account settings or write to info@heyokaa.com; we respond within 30 days and may verify your identity first, particularly for health data. If a clinician holds the record under our processor role, we will route your request to them.
Assessment scoring and programme recommendations are generated algorithmically. They are informational, are never shared with your employer, and are not a diagnosis — only a qualified clinician can diagnose or treat a condition.
9. Security
We encrypt data in transit and at rest, enforce role-based least-privilege access, log access to clinical and wellbeing records, keep production data out of development and testing, bind personnel to confidentiality, and maintain backups and a documented incident response process. No system is completely secure; if a breach is likely to affect you, we will notify you and the relevant authorities without undue delay. We do not currently hold certification under a specific security standard, and will state it here if that changes rather than imply it.
10. Transfers, cookies, children, changes
We host in Asia/India and use lawful transfer mechanisms, such as standard contractual clauses, where data moves across borders.
We use cookies that are strictly necessary (authentication, session, security), preference-based (theme, language, accessibility) and analytics. We use no advertising or cross-site tracking cookies, and ask consent for non-essential ones where required.
Self-signup is not open to anyone under 18. Where a minor is treated through a provider using Heyokaa, that provider obtains and records guardian consent. We do not profile or advertise to children.
If we make material changes to this policy we will update the date above and notify you before the change takes effect.
11. Contact
Heyokaa Health Pvt LTD, Unit 101, Oxford Towers, 139, HAL Old Airport Road, Kodihalli, Bangalore, Karnataka, India, 560008 Privacy: info@heyokaa.com · General: sales@heyokaa.com · Phone: +91 99954 98520
Grievance Officer (India, Digital Personal Data Protection Act 2023):], info@heyokaa.com
If our response does not resolve your concern, you may complain to the Data Protection Board of India or the supervisory authority in your jurisdiction.
Governed by the laws of India.