1. Who we are
Enerqubix AI Private Limited is the Data Fiduciary responsible for personal data processed through the LifeChiAI platform under the Digital Personal Data Protection Act 2023 (India).
| Detail | Information |
|---|---|
| Company | Enerqubix AI Private Limited |
| Product | LifeChiAI — Pranic Healing Centre Management Platform |
| Registered address | Perungudi, Chennai, Tamil Nadu, India |
| Privacy contact | support@lifechiai.com |
| Data Protection contact | Murugesh P, Director — murugesh@lifechiai.com |
2. What data we collect
| Data Category | Specific Data | How Collected |
|---|---|---|
| Identity data | Full name, date of birth, gender | Registration or WhatsApp intake |
| Contact data | Mobile number, email address | Registration or booking form |
| Health data (special category) | Condition description, chakra assessment notes, session remarks, healing history | WhatsApp intake, healer session logs, voice recordings |
| Session data | Session date, assigned healer, session type, outcome, follow-up notes | AI Admin Agent or healer logs |
| Payment data | Invoice amount, payment method, payment status | Razorpay or manual confirmation |
| Communication data | WhatsApp messages, in-app messages | WhatsApp Cloud API, LifeChiAI in-app |
Health data is a special category under DPDPA 2023. It is accessed only by your assigned healer, the centre administrator, and the AI Admin agent. It is never shared for marketing or advertising.
| Data Category | Specific Data | How Collected |
|---|---|---|
| Identity data | Full name, date of birth, MCKS certification level | Healer registration |
| Contact data | Mobile number, email address | Registration |
| Professional data | Specialisations, availability schedule, centre affiliations | Healer profile setup |
| Financial data | Payout amounts, bank/UPI details (if provided) | Payout settlement records |
| Tax compliance data | PAN number — optional, voluntarily provided for TDS compliance (Section 194J of the Income Tax Act). Encrypted, masked in all UIs, never shared with third parties. | Healer profile settings |
| Voice data | Voice recordings for chakra scan logging | OpenAI Whisper (text transcript retained, audio discarded) |
| Data Category | Specific Data | How Collected |
|---|---|---|
| Identity and contact data | Name, email, mobile | Admin account creation |
| Operational data | Centre configuration, healer roster, session records | Platform usage |
| Financial data | Invoice records, payout approvals, Razorpay API credentials (encrypted AES-256) | Finance module |
| Tax compliance data | Centre PAN number — optional, voluntarily provided for TDS compliance (Section 194J of the Income Tax Act). Encrypted, masked in all UIs, never shared with third parties. | Centre profile settings |
What we do not collect
We do not collect biometric data, Aadhaar numbers, or passport details. PAN numbers are collected only when voluntarily provided by healers or centre administrators for TDS compliance under Section 194J of the Income Tax Act. PAN numbers are stored with encryption, never shared with third parties, and are masked in all user interfaces.
3. Why we process your data
| Purpose | Legal Basis |
|---|---|
| Processing healing requests and assigning healers | Contractual necessity |
| Sending session reminders and confirmations | Contractual necessity |
| Generating invoices and processing payments | Contractual necessity + Legal obligation (GST) |
| Running the AI Admin Agent (intake, classification, assignment) | Legitimate interest + Consent |
| Voice transcription for chakra scan documentation | Consent (explicit, per session) |
| Sending WhatsApp communications | Consent |
| Push notifications | Consent |
| Platform analytics and improvement | Legitimate interest |
| Legal compliance and audit | Legal obligation |
4. How long we keep your data
| Data Type | Retention Period | Reason |
|---|---|---|
| Patient healing records | 7 years after last session | Medical records + GST audit requirement |
| Payment and invoice records | 8 years | GST Act India — mandatory |
| Healer session logs | 7 years | Audit and dispute resolution |
| WhatsApp message logs | 90 days | Operational review |
| Voice recordings | Not retained (immediately discarded after transcription) | Data minimisation |
| Deleted account data | 30 days (then permanently purged) | Grace period for recovery |
| Audit logs | 3 years | Regulatory compliance |
5. How Long We Keep Your Data
We retain your personal data and healing records for as long as necessary to provide our services and comply with applicable laws.
Healing records and session data are retained for a minimum of 7 years following your last interaction with the platform, in accordance with health record retention requirements applicable under Indian law, including the Clinical Establishments (Registration and Regulation) Act, 2010.
Subscription and payment records are retained for 8 years in compliance with the Income Tax Act, 1961 and GST record-keeping requirements.
Account data (name, email, phone) is retained for the duration of your active account. Upon account deletion, your personal identifiers are anonymised within 30 days. Anonymised healing records are retained for the minimum legally required period. You may request deletion of your account at any time through the app under Settings → Delete Account, or by writing to us at support@lifechiai.com. We will process your request within 72 hours in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA §12 and §13).
Data shared with third-party processors (including Anthropic, OpenAI, and ElevenLabs for AI-powered features) is governed by their respective data processing agreements and is used solely for providing the LifeChiAI service. We do not sell your personal data to any third party.
6. Who we share your data with
We do not sell your data. We share only what is necessary with the following categories of recipients:
7. International data transfers
Your primary data is stored in India (MongoDB Atlas, Mumbai). Some processing involves international transfers to the USA, Singapore, France, and EU. All international transfers are governed by appropriate safeguards:
For health data specifically: we transmit only the minimum necessary for each task. The full patient record is never transmitted internationally — only the specific condition description needed for AI intake processing.
8. Your rights under DPDPA 2023
Under the Digital Personal Data Protection Act 2023, you have the following rights as a Data Principal:
Right to Access
Request a summary of what data we hold about you and how it is used.
Right to Correction
Request correction of inaccurate or incomplete data.
Right to Erasure
Request deletion of your personal data. Note: some data must be retained for legal compliance (GST records). We will explain any exceptions clearly.
Right to Withdraw Consent
Withdraw consent for any processing activity. This does not affect prior lawful processing. Some features may be unavailable after withdrawal.
Right to Grievance Redressal
Lodge a complaint if you believe we have handled your data incorrectly. If unresolved, escalate to the Data Protection Board of India.
Right to Nominate
Nominate another individual to exercise your rights in case of death or incapacity.
9. How we protect your data
- ✓All data encrypted in transit using TLS 1.2 or higher
- ✓All data encrypted at rest on MongoDB Atlas using AES-256
- ✓Production database access restricted to authorised personnel via SSH key + IP allowlisting
- ✓JWT-based authentication with 30-day token expiry
- ✓Healers can only access patients assigned to them within their centre
- ✓Razorpay API credentials stored encrypted using AES-256 per tenant
- ✓All AI Admin Agent actions recorded in a tamper-evident audit log
- ✓Patient phone numbers never included in healer-facing API responses
In the event of a personal data breach likely to result in risk to your rights, we will notify the Data Protection Board of India within 72 hours as required under DPDPA 2023. We will also notify affected users without undue delay.
10. Children's data
Pranic healing sessions are sometimes provided to minors (under 18) with parental consent. When a minor is a patient:
- ·A parent or guardian must provide consent before the first session is logged
- ·The family on-behalf-of model allows an adult account holder to create healing requests for family members including minors
- ·We do not knowingly allow minors to create their own accounts
- ·If we discover a minor has registered without parental consent, we delete the account and data within 30 days
11. Changes to this policy
We may update this policy to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- ·Update the effective date at the top of this policy
- ·Notify registered users via WhatsApp or email at least 14 days before changes take effect
- ·Highlight key changes in the notification
Your continued use of LifeChiAI after the effective date constitutes acceptance of the updated policy.
12. Contact us
For all privacy-related queries, requests, or complaints:
If your complaint is not resolved within 30 days, you may escalate to the Data Protection Board of India at dpboard.gov.in
This policy is governed by the laws of India. Disputes are subject to the exclusive jurisdiction of the courts in Chennai, Tamil Nadu, India.