Privacy Policy
Effective date: [07-07-2024] Last updated: [07-072024]
This Privacy Policy explains how Jugnu Hadvaidya, having its place of business at 10/1850, Mahalaxmi Matani Pole, Soni Falia, Surat, Gujarat 395003, India (“Bharat Yogas”, “we”, “us”, or “our”) collects, uses, shares, and protects personal data when you use the website at https://bharatyogas.com and the service domain https://yogho.in (together, the “Website”), the Surya Namaskar mobile application (the “App”), and related services (together, the “Services”).
We handle personal data in line with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), the Information Technology Act, 2000 and the rules made under it, and other applicable Indian law. Where you access the Services from the European Union or European Economic Area, or from the United Kingdom, we also handle your personal data in line with the EU General Data Protection Regulation (the “GDPR”) and the UK GDPR, and Section 13 applies to you. By using the Services you agree to this Policy. Where the law requires your consent, we ask for it before we process your data for that purpose.
1. Data we collect
a. Data you give us
- Account details such as name, email address, mobile number, and password.
- Profile details you choose to add, such as age, gender, city, photo, and fitness goals.
- Health-related information you choose to enter, such as practice history, body metrics, or notes. You decide whether to provide this. Please do not enter more health data than you are comfortable sharing.
- Payment details you enter at checkout. Card and bank details are handled by our payment provider and are not stored by us.
- Messages, reviews, feedback, and support requests you send us.
b. Data we collect automatically
- Device and usage data such as device model, operating system, app version, IP address, language, crash logs, and how you use features.
- A device or push token so we can send notifications, if you allow notifications.
- Cookies and similar technologies on the Website, described in Section 7.
c. Data from third parties
- If you sign in through a third-party login or buy through Google Play, we receive limited account information from that provider.
2. How we use your data
We use personal data to:
- create and manage your account and provide the Services;
- deliver classes, routines, and personalised recommendations;
- process purchases, subscriptions, and taxes, and prevent fraud;
- send service messages, reminders, and, with your consent, promotional messages;
- respond to your requests and provide customer support;
- keep the Services secure, fix problems, and improve features;
- comply with law and enforce our Terms.
3. Legal basis
We process your personal data on the basis of your consent, and where applicable for “certain legitimate uses” permitted under the DPDP Act, for performing our contract with you, and for meeting legal obligations. You can withdraw consent at any time as described in Section 9. Withdrawing consent may mean we can no longer provide part of the Services.
For users in the EU, EEA, or UK, the GDPR requires a lawful basis for each use of your data. We rely on: your consent (for example, for marketing messages, non-essential cookies, and any health-related information you choose to enter); performance of our contract with you (to create your account and provide the Services you buy); our legitimate interests (to secure, maintain, and improve the Services and prevent fraud), balanced against your rights; and compliance with a legal obligation (for example, tax records). Health-related information is a special category of data under the GDPR, and we process it only with your explicit consent, which you can withdraw at any time.
4. Sharing your data
We do not sell your personal data. We share it only as follows:
- with service providers who work for us, such as hosting, cloud storage, analytics, payment gateways, and messaging and push providers, under confidentiality and data protection obligations;
- with Google Play when you purchase through it;
- where required by law, court order, or a lawful request from a government authority;
- to protect our rights, users, or the security of the Services;
- in connection with a merger, acquisition, or sale of assets, with notice as required by law.
5. Analytics, notifications, and advertising
We may use analytics tools to understand how the Services are used. We may use a push provider, such as Firebase Cloud Messaging, to send notifications if you allow them. If the App shows ads, an advertising provider may process limited device data. You can control notifications and ad personalisation in your device settings.
6. Data retention
We keep personal data for as long as your account is active and for as long as needed for the purposes in this Policy or as required by law, such as tax and accounting records. When data is no longer needed we delete or anonymise it, unless the law requires us to keep it longer.
7. Cookies
The Website uses cookies and similar technologies to keep you signed in, remember preferences, and measure usage. You can manage cookies through your browser settings. Blocking some cookies may affect how the Website works.
8. Security
We use reasonable security practices and procedures to protect personal data, including access controls and encryption in transit where appropriate. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal data breach affects you, we will notify you and the Data Protection Board of India as required under the DPDP Act.
9. Your rights
Subject to the DPDP Act, you have the right to:
- access a summary of the personal data we hold about you and how we process it;
- ask us to correct or update inaccurate or incomplete data;
- ask us to erase your personal data where it is no longer needed and where the law allows;
- withdraw consent you gave earlier;
- nominate another person to exercise your rights in the event of your death or incapacity;
- raise a grievance with us and, if not satisfied, complain to the Data Protection Board of India.
To exercise any right, contact us at the email in Section 12. We may need to verify your identity before we act. We will respond within the time allowed by law.
10. Children
The Services are not directed to children below 13 years of age, and a person below 13 years must not create an account or use the Services. Under the DPDP Act, anyone below 18 years is treated as a child, so if a user is 13 years or older but below 18 years, a parent or legal guardian must give verifiable consent and accept our terms on the user’s behalf. We do not knowingly process the personal data of a person below 18 years without that consent. If you believe a person below 18 years has given us personal data without the required consent, contact us and we will delete it.
11. Data transfer
We store and process data in India. If we transfer data outside India, for example to a cloud provider, we do so only to countries permitted under the DPDP Act and with appropriate safeguards.
If you are in the EU, EEA, or UK, note that your personal data is transferred to and processed in India and in other countries where our service providers operate, which may not offer the same level of data protection as your home country. Where we make such a transfer, we rely on an appropriate safeguard under the GDPR, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum for UK data), or another lawful transfer mechanism. You can ask us for more information about these safeguards using the contact in Section 12.
12. Grievance Officer and Data Protection contact
For any question, request, or complaint about your personal data or this Policy, contact:
Email: info@bharatyogas.com
13. Additional rights for users in the EU, EEA, and UK (GDPR)
This section applies if you are located in the EU, EEA, or UK, and adds to the rights in Section 9. For the purposes of the GDPR, the data controller is Jugnu Hadvaidya (Bharat Yogas), at the address at the top of this Policy, reachable at info@bharatyogas.com.
Under the GDPR you have the right to: access your personal data; have inaccurate data corrected; have your data erased (“right to be forgotten”); restrict or object to certain processing, including direct marketing; data portability, meaning a copy of the data you gave us in a machine-readable form; and to withdraw consent at any time without affecting processing already carried out. Where our basis is legitimate interests, you may object, and we will stop unless we have compelling legitimate grounds.
We do not use your data for automated decision-making that produces legal or similarly significant effects on you. To exercise any right, contact us at info@bharatyogas.com. We respond within the time the GDPR allows, normally one month. You also have the right to complain to your local data protection authority (in the EU or EEA, your national supervisory authority; in the UK, the Information Commissioner’s Office), though we ask that you contact us first so we can help.
14. Changes to this Policy
We may update this Policy from time to time. When we make a material change we will update the “Last updated” date and, where appropriate, give notice within the Services. Your continued use after a change means you accept the updated Policy.
15. Governing law
Indian law governs this Policy. The courts at Surat, Gujarat will handle any dispute relating to this Policy. You may also approach the Data Protection Board of India under the DPDP Act.


