Privacy Policy
Effective Date: 1 May 2026 | Last Updated: 18 May 2026
This Privacy Policy explains how Dhritam Wearable Technologies ("Dhritam", "we", "us", "our") collects, uses, stores, processes, shares, and protects personal data and sensitive personal data when you visit our website (dhritam.com), use our products (Kavach X, Agna), interact with our mobile application, or engage with our services. This policy is drafted in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the Digital Personal Data Protection Act, 2023 ("DPDPA"), and applicable provisions of the General Data Protection Regulation ("GDPR") for users located in the European Economic Area.
1. Information We Collect
1.1 Personal Information (Waitlist & Account)
When you join our waitlist, create an account, or contact us, we may collect the following personal information:
- Full name (first name and surname)
- Email address
- City, state, and country of residence
- Phone number (if voluntarily provided)
- Professional designation and employer (if voluntarily provided)
- Communication preferences and opt-in status
- Referral codes and source attribution data
- IP address and approximate geographic location derived from IP
- Browser type, operating system, device identifiers
1.2 Sensitive Personal Data (Physiological Data)
When you use Dhritam hardware products (Kavach X ECG garment, Agna EEG headband) and the companion mobile application, the following sensitive personal data may be collected and processed:
- Electrocardiogram (ECG) waveform data captured at 500Hz sampling rate
- Electroencephalogram (EEG) frequency band data (alpha, beta, theta, delta)
- Heart Rate Variability (HRV) metrics including RMSSD, SDNN, pNN50, LF/HF ratio
- Real-time heart rate and resting heart rate trends
- Autonomic nervous system stress indices and arousal levels
- Neural arousal index computed from EEG data
- Neuro-cardiac correlation data (when both devices are active)
- Sleep stage classification derived from cardiac and neural signals
- Breathing rate estimated from ECG morphology
- Personal baseline data and anomaly detection patterns
- Binaural audio session logs and neurofeedback interaction history
- BCI game performance metrics and neural training progression
1.3 Technical and Usage Data
We automatically collect certain technical data when you interact with our website and services:
- Pages visited, time spent, click patterns, and scroll depth on dhritam.com
- Referral source (search engine, social media, direct, referral link)
- Device type, screen resolution, and operating system version
- App usage patterns, feature engagement, and session duration
- Crash reports and error logs (anonymized)
- BLE connection logs and firmware version data (anonymized)
2. How We Use Your Information
We process your personal and sensitive personal data for the following purposes, each supported by a lawful basis under the DPDPA and GDPR:
- Waitlist management and communication - Legal basis: Consent (explicit opt-in at signup)
- Processing and displaying your physiological data within the Dhritam app - Legal basis: Contract performance (delivery of the service you purchased)
- Computing personal baselines, stress indices, and anomaly detection - Legal basis: Contract performance and explicit consent for health data processing
- Delivering adaptive binaural audio and BCI neurofeedback sessions - Legal basis: Contract performance
- Product improvement, bug fixes, and hardware reliability analysis - Legal basis: Legitimate interest (using anonymized and aggregated data only)
- Sending product updates, shipping notifications, and early access communications - Legal basis: Consent and legitimate interest
- Responding to inquiries from investors, press, researchers, and partners - Legal basis: Consent (contact form submission)
- Complying with legal obligations under Indian law and applicable regulations - Legal basis: Legal obligation
- Fraud prevention and protection of our services - Legal basis: Legitimate interest
3. Data Storage and Architecture
Local-first architecture. All physiological data (ECG, EEG, HRV, stress indices, baseline models, neurofeedback logs) is processed and stored locally on your personal device by default. Raw waveform data never leaves your smartphone unless you explicitly opt in to cloud synchronization.
Cloud synchronization (opt-in only). If you choose to enable cloud sync for backup or multi-device access, your data is encrypted end-to-end using AES-256 encryption before transmission. We use Google Firebase infrastructure hosted on Google Cloud Platform servers. Data at rest is encrypted with Google-managed encryption keys.
Waitlist and account data (name, email, city, referral codes) is stored in Google Firestore databases operated through Firebase. This data is protected by Firebase Security Rules, TLS 1.3 in transit, and AES-256 at rest.
Data retention. Waitlist data is retained until you request deletion or until the waitlist program concludes, whichever is earlier. Physiological data stored on your device is under your control - you may delete it at any time through the Dhritam app. Cloud-synced data is retained as long as your account is active and is permanently deleted within 30 days of an account deletion request.
No data monetization. We do not sell, rent, license, trade, or otherwise monetize your personal or physiological data. This is not a future promise - it is a present architectural constraint. Our business model is hardware and subscription revenue, not data brokerage.
4. Data Security Measures
We implement reasonable security practices and procedures as required under Rule 8 of the SPDI Rules, including but not limited to:
- AES-256 encryption for all data at rest (local device and cloud)
- TLS 1.3 encryption for all data in transit
- End-to-end encryption for cloud-synced physiological data
- Firebase Security Rules restricting database access to authenticated users
- BLE 5.0 encrypted communication between hardware devices and companion app
- Regular security audits and vulnerability assessments
- Access controls limiting employee access to personal data on a need-to-know basis
- Incident response procedures for data breach notification within 72 hours (GDPR) and as required under DPDPA
- No storage of payment information on our servers (processed by third-party payment processors with PCI-DSS compliance)
5. Third-Party Services
We use the following third-party services, each with its own privacy policy:
- Google Firebase (Firestore, Authentication, Hosting) - Purpose: Database, user authentication, website hosting. Data shared: Waitlist entries, contact form submissions, account data
- Google Analytics 4 - Purpose: Website analytics (anonymized). Data shared: Page views, session duration, traffic sources. IP anonymization enabled. No personal identifiers transmitted.
- Vercel - Purpose: Website deployment and CDN. Data shared: Standard HTTP request logs (IP, user agent). Automatically purged per Vercel retention policy.
- Google Cloud Platform - Purpose: Cloud infrastructure (if cloud sync is enabled). Data shared: Encrypted physiological data (only if user opts in)
We do not use any advertising networks, data brokers, or behavioral tracking services. We do not place advertising cookies. We do not participate in real-time bidding or programmatic advertising ecosystems.
6. Your Rights
Under the DPDPA 2023, SPDI Rules, and GDPR (where applicable), you have the following rights:
- Right to Access: Request a copy of all personal data we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data. We will comply within 30 days, subject to any legal retention obligations.
- Right to Data Portability: Request your data in a structured, commonly used, machine-readable format (JSON or CSV).
- Right to Withdraw Consent: Withdraw consent for data processing at any time. This does not affect the lawfulness of processing performed before withdrawal.
- Right to Restrict Processing: Request that we restrict processing of your data in certain circumstances.
- Right to Object: Object to processing based on legitimate interests.
- Right to Grievance Redressal: File a complaint with our Grievance Officer or with the Data Protection Board of India under the DPDPA.
To exercise any of these rights, contact us at sahil@dhritam.com. We will respond within 30 days.
7. Cookies and Tracking
dhritam.com uses the following cookies and tracking technologies:
- Essential cookies: Session management and CSRF protection. These are strictly necessary and cannot be disabled.
- Analytics cookies: Google Analytics 4 with IP anonymization enabled. Used to understand aggregate traffic patterns. No personal identifiers are transmitted.
- No advertising cookies. No retargeting pixels. No social media tracking widgets.
You may disable non-essential cookies through your browser settings without affecting the core functionality of our website.
8. Children's Privacy
Dhritam services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18, we will delete that data promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at sahil@dhritam.com.
9. Grievance Officer
In accordance with the Information Technology Act, 2000, and the SPDI Rules, the details of our Grievance Officer are as follows:
Name: Grievance Officer, Dhritam Wearable Technologies
Email: sahil@dhritam.com
Response Time: Within 30 days of receipt of complaint
Escalation: If unsatisfied with the response, you may file a complaint with the Data Protection Board of India under the DPDPA 2023.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by email (if you are on our waitlist or are a registered user) and by posting a prominent notice on dhritam.com at least 15 days before the changes take effect. Your continued use of our services after the effective date constitutes acceptance of the updated policy.
11. Contact Us
For any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
Company: Dhritam Wearable Technologies
Email: sahil@dhritam.com
Website: dhritam.com
Registered in: Gujarat, India
Dhritam is a human performance and wellness platform designed to help users better understand physiological patterns through continuous ECG-based insights. Dhritam is not a diagnostic medical device and is not intended for the treatment, cure, or prevention of any disease or disorder. Always consult a qualified healthcare professional for medical concerns.