Legal

Privacy Policy

How LifeChiAI collects, uses, and protects your personal data

Effective: June 2026DPDPA 2023 Compliant
Plain English Summary

LifeChiAI processes health data. We never sell your data. It is stored in India (MongoDB Atlas, Mumbai). AI processing uses Anthropic Claude (USA) under a data processing agreement. You can access, correct, or delete your data at any time by emailing support@lifechiai.com

1. Who we are

Enerqubix AI Private Limited is the Data Fiduciary responsible for personal data processed through the LifeChiAI platform under the Digital Personal Data Protection Act 2023 (India).

DetailInformation
CompanyEnerqubix AI Private Limited
ProductLifeChiAI — Pranic Healing Centre Management Platform
Registered addressPerungudi, Chennai, Tamil Nadu, India
Privacy contactsupport@lifechiai.com
Data Protection contactMurugesh P, Director — murugesh@lifechiai.com

2. What data we collect

From Patients
Data CategorySpecific DataHow Collected
Identity dataFull name, date of birth, genderRegistration or WhatsApp intake
Contact dataMobile number, email addressRegistration or booking form
Health data (special category)Condition description, chakra assessment notes, session remarks, healing historyWhatsApp intake, healer session logs, voice recordings
Session dataSession date, assigned healer, session type, outcome, follow-up notesAI Admin Agent or healer logs
Payment dataInvoice amount, payment method, payment statusRazorpay or manual confirmation
Communication dataWhatsApp messages, in-app messagesWhatsApp Cloud API, LifeChiAI in-app

Health data is a special category under DPDPA 2023. It is accessed only by your assigned healer, the centre administrator, and the AI Admin agent. It is never shared for marketing or advertising.

From Healers
Data CategorySpecific DataHow Collected
Identity dataFull name, date of birth, MCKS certification levelHealer registration
Contact dataMobile number, email addressRegistration
Professional dataSpecialisations, availability schedule, centre affiliationsHealer profile setup
Financial dataPayout amounts, bank/UPI details (if provided)Payout settlement records
Tax compliance dataPAN number — optional, voluntarily provided for TDS compliance (Section 194J of the Income Tax Act). Encrypted, masked in all UIs, never shared with third parties.Healer profile settings
Voice dataVoice recordings for chakra scan loggingOpenAI Whisper (text transcript retained, audio discarded)
From Centre Admins
Data CategorySpecific DataHow Collected
Identity and contact dataName, email, mobileAdmin account creation
Operational dataCentre configuration, healer roster, session recordsPlatform usage
Financial dataInvoice records, payout approvals, Razorpay API credentials (encrypted AES-256)Finance module
Tax compliance dataCentre PAN number — optional, voluntarily provided for TDS compliance (Section 194J of the Income Tax Act). Encrypted, masked in all UIs, never shared with third parties.Centre profile settings

What we do not collect

We do not collect biometric data, Aadhaar numbers, or passport details. PAN numbers are collected only when voluntarily provided by healers or centre administrators for TDS compliance under Section 194J of the Income Tax Act. PAN numbers are stored with encryption, never shared with third parties, and are masked in all user interfaces.

3. Why we process your data

PurposeLegal Basis
Processing healing requests and assigning healersContractual necessity
Sending session reminders and confirmationsContractual necessity
Generating invoices and processing paymentsContractual necessity + Legal obligation (GST)
Running the AI Admin Agent (intake, classification, assignment)Legitimate interest + Consent
Voice transcription for chakra scan documentationConsent (explicit, per session)
Sending WhatsApp communicationsConsent
Push notificationsConsent
Platform analytics and improvementLegitimate interest
Legal compliance and auditLegal obligation

4. How long we keep your data

Data TypeRetention PeriodReason
Patient healing records7 years after last sessionMedical records + GST audit requirement
Payment and invoice records8 yearsGST Act India — mandatory
Healer session logs7 yearsAudit and dispute resolution
WhatsApp message logs90 daysOperational review
Voice recordingsNot retained (immediately discarded after transcription)Data minimisation
Deleted account data30 days (then permanently purged)Grace period for recovery
Audit logs3 yearsRegulatory compliance

5. How Long We Keep Your Data

We retain your personal data and healing records for as long as necessary to provide our services and comply with applicable laws.

Healing records and session data are retained for a minimum of 7 years following your last interaction with the platform, in accordance with health record retention requirements applicable under Indian law, including the Clinical Establishments (Registration and Regulation) Act, 2010.

Subscription and payment records are retained for 8 years in compliance with the Income Tax Act, 1961 and GST record-keeping requirements.

Account data (name, email, phone) is retained for the duration of your active account. Upon account deletion, your personal identifiers are anonymised within 30 days. Anonymised healing records are retained for the minimum legally required period. You may request deletion of your account at any time through the app under Settings → Delete Account, or by writing to us at support@lifechiai.com. We will process your request within 72 hours in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA §12 and §13).

Data shared with third-party processors (including Anthropic, OpenAI, and ElevenLabs for AI-powered features) is governed by their respective data processing agreements and is used solely for providing the LifeChiAI service. We do not sell your personal data to any third party.

6. Who we share your data with

We do not sell your data. We share only what is necessary with the following categories of recipients:

Anthropic (Claude API)

AI Admin Agent processing — healing request classification and response generation. Receives: session context. Patient names are replaced with role labels before sending. Clinical condition data is included to enable AI responses. Cross-border transfer to USA.

USA Data Processing Agreement — no training on API data
OpenAI (Whisper API)

Voice-to-text transcription for chakra scan documentation. Audio is discarded immediately after transcription. Cross-border transfer to USA.

USA Data Processing Agreement — audio discarded immediately after transcription
Apple Inc.

Sign in with Apple — identity verification during authentication. Name and relay email provided to LifeChiAI at first sign-in only.

Google LLC

Google Sign-In — identity verification during authentication. Email address and display name provided to LifeChiAI during token exchange.

Razorpay

Payment processing for patient invoices and healer payouts

India PCI-DSS compliant payment processor
Meta (WhatsApp Business API)

WhatsApp message delivery to patients and healers

USA WhatsApp Business Terms of Service
Brevo

Transactional email delivery (invoices, notifications, welcome emails)

France/EU Data Processing Agreement
MongoDB Atlas

Primary data storage

India (Mumbai, AWS ap-south-1) AES-256 encryption at rest
Render

Backend API hosting

Singapore SOC 2 Type II certified
ElevenLabs

Text-to-speech for AI voice responses

USA API usage — no data retained
Cloudflare R2

Centre verification document storage

USA/Global CDN Encrypted object storage

7. International data transfers

Your primary data is stored in India (MongoDB Atlas, Mumbai). Some processing involves international transfers to the USA, Singapore, France, and EU. All international transfers are governed by appropriate safeguards:

Anthropic, OpenAI, ElevenLabs: Standard Contractual Clauses + Data Processing Agreements. Neither company trains on data submitted via API.
Meta: WhatsApp Business Terms of Service. Messages sent via Business API are not used for Meta advertising targeting.
Render (Singapore): SOC 2 Type II certified. Standard hosting agreement.
Brevo (France/EU): GDPR-compliant. EU data protection standards apply.

For health data specifically: we transmit only the minimum necessary for each task. The full patient record is never transmitted internationally — only the specific condition description needed for AI intake processing.

8. Your rights under DPDPA 2023

Under the Digital Personal Data Protection Act 2023, you have the following rights as a Data Principal:

📋

Right to Access

Request a summary of what data we hold about you and how it is used.

How to exercise
Email support@lifechiai.com with subject “Data Access Request”. We respond within 30 days.
✏️

Right to Correction

Request correction of inaccurate or incomplete data.

How to exercise
Email support@lifechiai.com or update directly in your LifeChiAI profile.
🗑️

Right to Erasure

Request deletion of your personal data. Note: some data must be retained for legal compliance (GST records). We will explain any exceptions clearly.

How to exercise
Email support@lifechiai.com with subject “Erasure Request”. We action within 30 days.
↩️

Right to Withdraw Consent

Withdraw consent for any processing activity. This does not affect prior lawful processing. Some features may be unavailable after withdrawal.

How to exercise
Email support@lifechiai.com. We action within 7 days.
⚖️

Right to Grievance Redressal

Lodge a complaint if you believe we have handled your data incorrectly. If unresolved, escalate to the Data Protection Board of India.

How to exercise
Email support@lifechiai.com. We acknowledge within 72 hours and resolve within 30 days.
🫂

Right to Nominate

Nominate another individual to exercise your rights in case of death or incapacity.

How to exercise
Email support@lifechiai.com with subject “Nomination Request”.

9. How we protect your data

Technical safeguards
  • All data encrypted in transit using TLS 1.2 or higher
  • All data encrypted at rest on MongoDB Atlas using AES-256
  • Production database access restricted to authorised personnel via SSH key + IP allowlisting
  • JWT-based authentication with 30-day token expiry
  • Healers can only access patients assigned to them within their centre
  • Razorpay API credentials stored encrypted using AES-256 per tenant
  • All AI Admin Agent actions recorded in a tamper-evident audit log
  • Patient phone numbers never included in healer-facing API responses
Data breach notification

In the event of a personal data breach likely to result in risk to your rights, we will notify the Data Protection Board of India within 72 hours as required under DPDPA 2023. We will also notify affected users without undue delay.

10. Children's data

Pranic healing sessions are sometimes provided to minors (under 18) with parental consent. When a minor is a patient:

  • ·A parent or guardian must provide consent before the first session is logged
  • ·The family on-behalf-of model allows an adult account holder to create healing requests for family members including minors
  • ·We do not knowingly allow minors to create their own accounts
  • ·If we discover a minor has registered without parental consent, we delete the account and data within 30 days

11. Changes to this policy

We may update this policy to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • ·Update the effective date at the top of this policy
  • ·Notify registered users via WhatsApp or email at least 14 days before changes take effect
  • ·Highlight key changes in the notification

Your continued use of LifeChiAI after the effective date constitutes acceptance of the updated policy.

12. Contact us

For all privacy-related queries, requests, or complaints:

Emailsupport@lifechiai.com (responses within 72 hours on business days)
Data Protection contactMurugesh P, Director — murugesh@lifechiai.com
Postal addressEnerqubix AI Private Limited, Perungudi, Chennai, Tamil Nadu, India
Data Protection Board of India

If your complaint is not resolved within 30 days, you may escalate to the Data Protection Board of India at dpboard.gov.in

Email Us About Privacy

This policy is governed by the laws of India. Disputes are subject to the exclusive jurisdiction of the courts in Chennai, Tamil Nadu, India.