India policy
India Privacy Policy and DPDP Notice
How Aora India collects, uses, stores, shares, protects, and deletes personal data for India customers.
- Applies to
- India
- Effective:
- 11 June 2026
- Last updated:
- 11 June 2026
Scope and data fiduciary
This policy applies to India customers, visitors, account holders, leads, and support contacts. The data fiduciary for India orders is Aora India Private Limited, Aora India Private Limited, Kumara Vijayam, A-1, 187 Royapettah High Road, Mylapore, Chennai 600004, Tamil Nadu, India.
We collect and use personal data only for lawful purposes connected to operating a wellness ecommerce business, fulfilling orders, keeping products traceable, providing support, improving the site, preventing fraud, and sending marketing where permitted. This notice is issued in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000.
Personal data we collect
We may collect your name, email, phone number, billing and shipping address, payment status, order history, GST invoice details where relevant, support messages, account credentials, review content, rewards activity, device data, IP address, cookie identifiers, and marketing preferences.
If you voluntarily use a goal quiz, routine builder, consultation form, or product recommendation tool, you may share wellness goals, diet preferences, allergies, life stage, supplement use, or medication context. We use this information cautiously and only to provide education, product discovery, safety prompts, or support.
How we use personal data
We use personal data to process payments, deliver orders, generate invoices, send tracking updates, handle cancellations and refunds, answer support requests, manage subscriptions, prevent abuse, maintain product and batch records, improve customer experience, comply with law, and send opt-in marketing.
We do not use optional wellness information to diagnose, treat, or make clinical decisions. We do not sell personal data.
Aora AI and automated tools
If you use the optional Aora AI coach or AI-assisted recommendations, the questions you ask and a limited health profile you have chosen to share (such as age, goals, conditions, allergies, medications, and supplements) are sent to our AI provider Anthropic (Claude API), processed in the United States, solely to generate a personalised response. We send only what the feature needs, the output is educational and not a clinical decision, and Anthropic processes the data under its commercial terms and does not use it to train its models. You can use Aora fully without the AI features, and AI-related data is deleted with your account.
Lawful basis for processing
Under the DPDP Act, we process personal data only on a lawful basis. For most activities the basis is your consent (free, specific, informed, unconditional and unambiguous), captured at signup, at checkout, and via the cookie banner. We also rely on the legitimate uses specified in the DPDP Act where applicable, for example fulfilling your order once you ask us to ship it, complying with a statutory obligation (GST invoicing, FSSAI traceability), or responding to a medical emergency. You can review your active consents and withdraw any of them at any time from [/account/privacy](/account/privacy).
Cross-border data transfer
India customer data is hosted primarily on Amazon Web Services infrastructure in the ap-south-1 (Mumbai) region. Some processors operate outside India, for example Anthropic (AI, United States), Sentry (error monitoring, United States), and Stripe / PayPal (used only for international/USD payments). Where you use the AI coach, a limited health profile is transferred to Anthropic in the United States to generate your answer. Under the DPDP Act, the Central Government may notify a list of restricted countries; we transfer data only to countries not so restricted, and bind each recipient by contract (data-processing agreements / standard contractual terms) to security and confidentiality standards at least equivalent to ours.
Your India privacy rights (DPDP §§ 11-14)
As a Data Principal under the DPDP Act, you have the right to:
• Access, a summary of the personal data being processed and the activities undertaken.
• Correction & erasure, correct inaccurate or misleading data, complete incomplete data, and erase personal data no longer needed.
• Grievance redressal, raise complaints to our Grievance Officer (see below).
• Nominate another individual to exercise these rights in the event of your death or incapacity.
• Withdraw consent at any time, at the same ease with which it was given. Use the Privacy controls in your account for a one-click withdraw.
To exercise these rights, email privacy@aoraspectrum.com or use [/account/privacy](/account/privacy). We respond within 30 days. Some records (tax, invoice, fraud prevention, legal, product traceability) may need to be retained even after an erasure request to satisfy statutory obligations.
Data retention schedule
We keep personal data only as long as needed for the purpose collected. Indicative retention windows:
• Order, invoice & tax records, 8 years (Income-Tax Act + GST Act).
• Product batch / traceability records, 5 years post-expiry (FSSAI Schedule IV).
• Cookie consent decisions, 12 months from the date of decision (then re-prompted).
• Marketing preferences, until you opt out.
• Support tickets, 3 years from ticket close.
• Account profile + wellness data, for the lifetime of the account; deleted within 30 days of a verified deletion request (subject to the statutory retention rules above).
• One-time passwords (OTP), held in an encrypted cache for up to 10 minutes, then deleted; never written to the database.
• Aora AI conversations, kept for the lifetime of the account so you can revisit them; deleted with the account.
• Lab reports you upload, stored in a private, access-controlled file store; deleted within 30 days of a verified account-deletion request.
• Cycle, wellness, and health-tracking entries, kept while the account (or relevant household member) is active for your own reference; deleted when the account or that member is removed.
• Security & audit logs (administrative actions, hashed IP), retained for 180 days in Indian jurisdiction, per the CERT-In Directions, then purged.
Security safeguards
We apply technical and organisational measures appropriate to the sensitivity of the data, including HTTPS-in-transit encryption, encrypted storage of sensitive uploads, password hashing (bcrypt), least-privilege admin access controls, audit logging of administrative actions, CSRF + rate-limiting protection, periodic vulnerability assessment, and segregated staff access to production systems.
Personal data breach notification
If a personal data breach occurs that affects you, we will notify the Data Protection Board of India and each affected Data Principal in accordance with the DPDP Act and the Rules thereunder, promptly, and in any event within the statutory window applicable at the time (currently within 72 hours of becoming aware). The notification will describe what happened, the data categories affected, the mitigations in flight, and what you can do to protect yourself.
Children and household members under 18
Aora accounts are opened by adults aged 18 and over, and we require an age confirmation at signup. An account holder may add household members, including a minor, to use wellness features for their family. Before any health, cycle, or wellness data is collected for a household member under 18, we require the account holder to confirm they are the parent or legal guardian and to record their consent, in line with Section 10 of the Digital Personal Data Protection Act, 2023. We do not run behavioural monitoring or targeted advertising on minors. A parent or guardian can withdraw that consent and delete the minor's data at any time from family/privacy settings. If you believe a child's data has been provided without proper consent, contact privacy@aoraspectrum.com and we will review it promptly.
Privacy team & escalation
Data Protection Officer (DPO), Aora Data Protection Officer, dpo@aoraspectrum.com.
The DPO is the single point of contact for privacy queries, access requests and consent withdrawals.
Grievance Officer, Aora Grievance Officer, grievance@aoraspectrum.com.
The Grievance Officer handles unresolved complaints under the DPDP Act and the IT (Intermediary Guidelines) Rules. We respond within 30 days.
Escalation, if you are not satisfied with our response, you may file a complaint with the Data Protection Board of India (https://dpb.gov.in/).
Registered office, Aora India Private Limited, Kumara Vijayam, A-1, 187 Royapettah High Road, Mylapore, Chennai 600004, Tamil Nadu, India
Questions? Email care@aoraspectrum.com
Related policies