Skip to content
Aora India

India policy

India Privacy Policy and DPDP Notice

How Aora India collects, uses, stores, shares, protects, and deletes personal data for India customers.

Applies to
India
Effective:
11 June 2026
Last updated:
11 June 2026

Scope and data fiduciary

This policy applies to India customers, visitors, account holders, leads, and support contacts. The data fiduciary for India orders is Aora India Private Limited, Aora India Private Limited, Kumara Vijayam, A-1, 187 Royapettah High Road, Mylapore, Chennai 600004, Tamil Nadu, India.

We collect and use personal data only for lawful purposes connected to operating a wellness ecommerce business, fulfilling orders, keeping products traceable, providing support, improving the site, preventing fraud, and sending marketing where permitted. This notice is issued in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000.

Personal data we collect

We may collect your name, email, phone number, billing and shipping address, payment status, order history, GST invoice details where relevant, support messages, account credentials, review content, rewards activity, device data, IP address, cookie identifiers, and marketing preferences.

If you voluntarily use a goal quiz, routine builder, consultation form, or product recommendation tool, you may share wellness goals, diet preferences, allergies, life stage, supplement use, or medication context. We use this information cautiously and only to provide education, product discovery, safety prompts, or support.

How we use personal data

We use personal data to process payments, deliver orders, generate invoices, send tracking updates, handle cancellations and refunds, answer support requests, manage subscriptions, prevent abuse, maintain product and batch records, improve customer experience, comply with law, and send opt-in marketing.

We do not use optional wellness information to diagnose, treat, or make clinical decisions. We do not sell personal data.

Aora AI and automated tools

If you use the optional Aora AI coach or AI-assisted recommendations, the questions you ask and a limited health profile you have chosen to share (such as age, goals, conditions, allergies, medications, and supplements) are sent to our AI provider Anthropic (Claude API), processed in the United States, solely to generate a personalised response. We send only what the feature needs, the output is educational and not a clinical decision, and Anthropic processes the data under its commercial terms and does not use it to train its models. You can use Aora fully without the AI features, and AI-related data is deleted with your account.

Lawful basis for processing

Under the DPDP Act, we process personal data only on a lawful basis. For most activities the basis is your consent (free, specific, informed, unconditional and unambiguous), captured at signup, at checkout, and via the cookie banner. We also rely on the legitimate uses specified in the DPDP Act where applicable, for example fulfilling your order once you ask us to ship it, complying with a statutory obligation (GST invoicing, FSSAI traceability), or responding to a medical emergency. You can review your active consents and withdraw any of them at any time from [/account/privacy](/account/privacy).

Processors and sharing

We share data with service providers (Data Processors) only where needed: payment gateways (Razorpay, Cashfree, Stripe, PayPal), banks, shipping partners, warehouse providers, customer support tools, OTP and messaging providers (MSG91, for SMS one-time passwords and notifications), our AI provider (Anthropic, which powers the optional Aora AI coach, see the AI section below), error-monitoring and reliability tools (Sentry), analytics tools (Google Analytics, Microsoft Clarity, Meta Pixel, only when you consent to marketing cookies), hosting providers (Amazon Web Services), fraud prevention vendors, accountants, lawyers, auditors, and regulators where legally required.

Each processor receives only the data needed for its role and is bound by contractual confidentiality and security obligations. We do not permit service providers to use India customer data for their own marketing.

Cross-border data transfer

India customer data is hosted primarily on Amazon Web Services infrastructure in the ap-south-1 (Mumbai) region. Some processors operate outside India, for example Anthropic (AI, United States), Sentry (error monitoring, United States), and Stripe / PayPal (used only for international/USD payments). Where you use the AI coach, a limited health profile is transferred to Anthropic in the United States to generate your answer. Under the DPDP Act, the Central Government may notify a list of restricted countries; we transfer data only to countries not so restricted, and bind each recipient by contract (data-processing agreements / standard contractual terms) to security and confidentiality standards at least equivalent to ours.

Your India privacy rights (DPDP §§ 11-14)

As a Data Principal under the DPDP Act, you have the right to:

Access, a summary of the personal data being processed and the activities undertaken.
Correction & erasure, correct inaccurate or misleading data, complete incomplete data, and erase personal data no longer needed.
Grievance redressal, raise complaints to our Grievance Officer (see below).
Nominate another individual to exercise these rights in the event of your death or incapacity.
Withdraw consent at any time, at the same ease with which it was given. Use the Privacy controls in your account for a one-click withdraw.

To exercise these rights, email privacy@aoraspectrum.com or use [/account/privacy](/account/privacy). We respond within 30 days. Some records (tax, invoice, fraud prevention, legal, product traceability) may need to be retained even after an erasure request to satisfy statutory obligations.

Data retention schedule

We keep personal data only as long as needed for the purpose collected. Indicative retention windows:

Order, invoice & tax records, 8 years (Income-Tax Act + GST Act).
Product batch / traceability records, 5 years post-expiry (FSSAI Schedule IV).
Cookie consent decisions, 12 months from the date of decision (then re-prompted).
Marketing preferences, until you opt out.
Support tickets, 3 years from ticket close.
Account profile + wellness data, for the lifetime of the account; deleted within 30 days of a verified deletion request (subject to the statutory retention rules above).
One-time passwords (OTP), held in an encrypted cache for up to 10 minutes, then deleted; never written to the database.
Aora AI conversations, kept for the lifetime of the account so you can revisit them; deleted with the account.
Lab reports you upload, stored in a private, access-controlled file store; deleted within 30 days of a verified account-deletion request.
Cycle, wellness, and health-tracking entries, kept while the account (or relevant household member) is active for your own reference; deleted when the account or that member is removed.
Security & audit logs (administrative actions, hashed IP), retained for 180 days in Indian jurisdiction, per the CERT-In Directions, then purged.

Security safeguards

We apply technical and organisational measures appropriate to the sensitivity of the data, including HTTPS-in-transit encryption, encrypted storage of sensitive uploads, password hashing (bcrypt), least-privilege admin access controls, audit logging of administrative actions, CSRF + rate-limiting protection, periodic vulnerability assessment, and segregated staff access to production systems.

Personal data breach notification

If a personal data breach occurs that affects you, we will notify the Data Protection Board of India and each affected Data Principal in accordance with the DPDP Act and the Rules thereunder, promptly, and in any event within the statutory window applicable at the time (currently within 72 hours of becoming aware). The notification will describe what happened, the data categories affected, the mitigations in flight, and what you can do to protect yourself.

Children and household members under 18

Aora accounts are opened by adults aged 18 and over, and we require an age confirmation at signup. An account holder may add household members, including a minor, to use wellness features for their family. Before any health, cycle, or wellness data is collected for a household member under 18, we require the account holder to confirm they are the parent or legal guardian and to record their consent, in line with Section 10 of the Digital Personal Data Protection Act, 2023. We do not run behavioural monitoring or targeted advertising on minors. A parent or guardian can withdraw that consent and delete the minor's data at any time from family/privacy settings. If you believe a child's data has been provided without proper consent, contact privacy@aoraspectrum.com and we will review it promptly.

Privacy team & escalation

Data Protection Officer (DPO), Aora Data Protection Officer, dpo@aoraspectrum.com.
The DPO is the single point of contact for privacy queries, access requests and consent withdrawals.

Grievance Officer, Aora Grievance Officer, grievance@aoraspectrum.com.
The Grievance Officer handles unresolved complaints under the DPDP Act and the IT (Intermediary Guidelines) Rules. We respond within 30 days.

Escalation, if you are not satisfied with our response, you may file a complaint with the Data Protection Board of India (https://dpb.gov.in/).

Registered office, Aora India Private Limited, Kumara Vijayam, A-1, 187 Royapettah High Road, Mylapore, Chennai 600004, Tamil Nadu, India

Related policies