LEGAL
Privacy Policy
Last updated: 29 May 2026
1. Introduction
SolvoConnect (operated by SolvoConnect, registered in India) is committed to protecting your personal data in accordance with the Information Technology Act, 2000 ("IT Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDP Act") as and when enforced.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website at solvoconnect.com and our mobile and web application.
2. Information We Collect
We collect the following categories of personal data:
• Account Information: Name, email address, age group, and profile picture (via Google OAuth).
• Health and Biometric Data: Stress scores, HRV (heart rate variability) estimates, and session coherence data. This constitutes Sensitive Personal Data or Information (SPDI) under Rule 3 of the SPDI Rules, 2011.
• Usage Data: Session history, breathing cycle completions, streak counts, and progress metrics.
• Payment Information: Subscription payment data processed through Razorpay. We do not store card numbers or bank details on our servers.
• Device Information: Browser type, IP address, and device type for security and analytics purposes.
• Communications: Emails and messages you send us.
3. Legal Basis for Processing
We process your personal data on the following legal bases under Indian law:
• Consent: You provide explicit consent at signup for collection of health-related data (SPDI). You may withdraw consent at any time by deleting your account.
• Contract Performance: Processing necessary to provide the SolvoConnect service you have subscribed to.
• Legal Obligation: Compliance with applicable Indian laws including the IT Act and DPDP Act.
• Legitimate Interests: Improving our services, preventing fraud, and ensuring platform security.
4. How We Use Your Information
We use your personal data for the following purposes:
• To create and manage your account
• To provide group breathing sessions and track your progress
• To send session booking confirmations and reminders
• To process subscription payments via Razorpay
• To personalise your training experience based on your plan
• To send service updates and important notifications
• To comply with legal obligations
• To improve our platform and user experience
We do not use your data for targeted advertising. SolvoConnect products are ad-free.
5. Sensitive Personal Data (SPDI)
Under Rule 3 of the SPDI Rules, 2011, health data including biometric information is classified as Sensitive Personal Data. SolvoConnect collects estimated stress and HRV scores to provide nervous system training services.
We handle this data with the highest standards of security. This data is:
• Never sold to third parties
• Never shared without your explicit consent except as required by law
• Stored in encrypted form on Supabase (AWS ap-northeast-2)
• Accessible only to you and authorised SolvoConnect personnel
6. Data Sharing and Third Parties
We share your personal data only with the following service providers who process data on our behalf:
• Supabase Inc. — Database hosting (data stored in AWS ap-northeast-2 region)
• Vercel Inc. — Application hosting and deployment
• Resend Inc. — Transactional email delivery
• Razorpay Software Pvt. Ltd. — Payment processing (India-based, RBI regulated)
• Google LLC — Authentication via Google OAuth
All third-party processors are bound by data processing agreements. We do not sell, rent, or trade your personal information to any other party.
7. Data Retention
We retain your personal data for the following periods:
• Account data: For the duration of your account plus 90 days after deletion
• Session and health data: For the duration of your account plus 30 days
• Payment records: 7 years as required by Indian financial regulations
• Emails: 2 years
You may request deletion of your data at any time by writing to solvoconnect@gmail.com.
8. Your Rights Under Indian Law
Under the IT Act, SPDI Rules, and forthcoming DPDP Act, you have the following rights:
• Right to Access: Request a copy of your personal data we hold
• Right to Correction: Request correction of inaccurate data
• Right to Deletion: Request deletion of your account and associated data
• Right to Withdraw Consent: Withdraw consent for SPDI processing at any time
• Right to Grievance Redressal: File a complaint with our Grievance Officer
To exercise these rights, contact us at solvoconnect@gmail.com or through the Contact Support page.
9. Data Security
We implement reasonable security practices and procedures as required under Rule 8 of the SPDI Rules, 2011, including:
• SSL/TLS encryption for all data in transit
• AES-256 encryption for sensitive data at rest
• Row-level security policies on our database
• JWT-based authentication with 30-day token expiry
• Regular security reviews and access controls
• No employee access to payment credentials
In the event of a data breach affecting your personal data, we will notify you within 72 hours as required by applicable law.
10. Cookies and Tracking
SolvoConnect uses only essential cookies required for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics that track you across websites.
Cookies used:
• next-auth.session-token — Authentication session (expires with session)
• next-auth.csrf-token — CSRF protection (expires with session)
11. Children's Privacy
SolvoConnect serves users aged 8 and above. For users under 18 (minors under Indian law), we require Guardian Plan accounts which are administered by schools or verified guardians.
We do not knowingly collect personal data from children under 8. If you believe we have inadvertently collected such data, contact us immediately at solvoconnect@gmail.com.
12. Grievance Officer
As required under Rule 5(9) of the SPDI Rules, 2011, we have appointed a Grievance Officer:
Name: SolvoConnect Privacy Team
Email: solvoconnect@gmail.com
Address: SolvoConnect, India
Response time: Within 30 days of receipt of complaint
If you are not satisfied with our response, you may approach the relevant authority under the IT Act or DPDP Act.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notification at least 30 days before the change takes effect. Continued use of SolvoConnect after the effective date constitutes acceptance of the updated policy.
14. Contact Us
For any privacy-related queries:
Email: solvoconnect@gmail.com
Website: solvoconnect.com/contact
Registered address: India