Effective Date: 10/04/2025
PFC Club India Pvt. Ltd. ("PFC" or "we") is committed to protecting your privacy. This Privacy Policy describes how we collect, use, share, and protect your personal information when you use our GLP-1 weight loss subscription service, in compliance with Indian law including the Information Technology Act, 2000 and the applicable data protection rules. By using the service, you consent to the practices described in this policy.
1. Information We Collect: We collect several types of information to provide and improve our services to you:
- Personal Identification Information: Name, age, date of birth, gender, contact address, phone number, email address, government-issued ID details (if needed for verification).
- Health and Medical Information: Your medical history, current medications, allergies, health conditions, reports or lab results you provide, doctor consultation records (including audio/video if consultations are recorded with consent), and any data you enter on health questionnaires. This health information is classified as Sensitive Personal Data or Information (SPDI) under Indian law, and will be accorded special protection.
- Payment Information: Billing address, transaction references, and payment method details (credit/debit card or UPI information). We do not store full financial information like credit card numbers on our servers – payments are processed securely by compliant payment gateways.
- Technical and Usage Information: When you use our website, we may automatically collect information such as your IP address, browser type, device identifiers, pages viewed, and the dates/times of access. We may use cookies or similar technologies to enhance user experience, remember your preferences, and gather usage analytics. (You can manage cookie preferences through your browser settings, though disabling cookies may affect some functionalities of the site.)
- Referral and Communication Data: If you contact us for support or with a query, we will collect the information you provide in that communication. If we offer a waitlist or referral program, we may collect information such as the source of your referral.
2. Use of Collected Information: We use your information for the following purposes:
- Service Delivery: To provide the subscription services you have enrolled in. For example, we use your health information to facilitate doctor evaluations and to determine eligibility for the GLP-1 medication. Doctors will review the information to provide informed medical advice. We use your address to ship the medication, and your contact info to schedule appointments or provide service updates.
- Personalization and Improvement: To customize the advice, diet and exercise plans, and content we provide you. For instance, your health data may be used to tailor a nutrition plan or adjust medication dosage under medical guidance.
- Communication: To contact you with service-related announcements, reminders (for appointments, medication refills, etc.), and customer support responses. We may also send motivational messages or tips as part of the program. You will receive transactional emails/SMS for critical service updates (these are not promotional in nature).
- Improvement and Analytics: To improve our website and services. We may analyze usage patterns and feedback to enhance user experience, add new features, or improve our coaching and medical offerings. Any analytics will use anonymized or aggregated data where possible, and personal identity is not disclosed in such analysis.
- Legal Compliance and Safety: To comply with applicable laws and regulations. For example, maintaining prescription records as required by the Drugs and Cosmetics Rules, or providing information to law enforcement or regulatory authorities if lawfully required. We may also use information to enforce our Terms of Use, to detect or prevent fraud or other misuse of our platform, and to ensure the safety of our users and staff.
3. Disclosure of Information (Sharing with Third Parties): We do not sell or rent your personal information to third-party advertisers. We only share your information in the following circumstances:
- With Healthcare Providers: Your information will be shared with the doctors who provide consultations so they have your medical history and can treat you appropriately. Doctors are bound by doctor-patient confidentiality and applicable medical privacy laws. Similarly, if a dietitian, nutritionist, or fitness coach is assigned to you, relevant information (like your diet preferences or health goals, and any necessary medical constraints as cleared by the doctor) will be shared with them to serve you.
- With Pharmacy Partner: Your name, contact details, and prescription details will be shared in order to dispense and deliver your medication. The pharmacy requires this information to fulfill the prescription legally and accurately. They will also handle your information in accordance with privacy laws and only use it for fulfillment and record-keeping (e.g., to maintain sales records as required by the Drugs & Cosmetics Act).
- Payment Processors: For payment transactions, we share necessary information with our secure payment gateway/processor (such as your order ID and amount). These processors are compliant with required security standards. We do not store your card details on our servers beyond what is necessary for transaction references, in accordance with RBI guidelines.
- Service Providers: We may employ trusted third-party service providers to perform certain functions on our behalf – for example, hosting the website or database on a secure cloud server, IT support, email/SMS delivery services, or analytics tools (like Google Analytics for usage data). They may have incidental access to certain data in the course of their work, but will be contractually obligated to protect it and to use it only for providing their services to us.
- Legal Requirements: We may disclose information if required to do so by law or legal process, or if we in good faith believe that such disclosure is necessary to (i) comply with a legal obligation (for example, a court order or a government demand under law), (ii) protect and defend our rights or property, (iii) act in urgent circumstances to protect the personal safety of users or the public, or (iv) investigate and prevent fraud or security issues.
- Business Transfers: If PFC undergoes a business transition such as a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will ensure the successor entity is bound to the same standards of privacy as outlined in this policy, and we will notify you of any change in ownership or use of your personal data.
- With Your Consent: If we ever need to share your information for any purpose other than the above, we will do so only after obtaining your explicit consent. For example, if you wanted us to share your progress with your personal physician or a family member, we would do so with your written request/consent.
4. Storage and Security: We take appropriate security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data transmission (our website uses HTTPS/SSL encryption for all data exchange), secure servers with firewall protection, and access controls such that personal data is accessible only by authorized personnel on a need-to-know basis. We adhere to the "reasonable security practices and procedures" as required under Indian law (Information Technology Act & SPDI Rules), including periodic security audits. However, no method of online transmission or storage is 100% secure, so while we strive to protect your data, we cannot guarantee absolute security. In the unlikely event of a data breach that affects your personal information, we will notify you and the appropriate authorities as required by law.
5. Data Retention: We will retain your personal information for as long as necessary to fulfill the purposes outlined in this policy. In general, health records and prescriptions may be retained for a minimum period (e.g., at least three years) as recommended by medical record guidelines, or longer if required by law or for legitimate business purposes. If you delete your account or withdraw from the program, we will archive your data and retain only as much as is needed for legal compliance (for example, maintaining prescription dispensation records, or tax records of transactions) or to resolve any disputes. When no longer needed, we will securely delete or anonymize your personal data.
6. Your Rights and Choices:
- Access and Correction: You have the right to access the personal information we hold about you. You may request a copy of your data or ask for corrections or updates to any inaccurate or incomplete information (for example, updating your contact details or correcting a part of your medical history). Some information can be reviewed and edited by you directly in your account profile or by contacting customer support.
- Withdraw Consent: Where we rely on your consent to process personal data (for instance, for receiving promotional tips or for telemedicine consultation itself), you have the right to withdraw that consent at any time. Please note that if you withdraw consent for us to process essential information (like health data needed for consultations), we may have to discontinue the service for you, as we cannot provide the service without processing such information. We will inform you if that is the case.
- Deletion: You may request deletion of your personal data. We will honor such requests to the extent feasible and lawful. However, certain data may be retained in compliance with legal obligations (see "Data Retention" above). Any anonymized aggregate data (which is no longer personally identifiable) may be retained.
- Opt-Out of Communications: We ensure that you receive only relevant communications. You cannot opt out of essential service communications (such as appointment reminders or security alerts) as these are necessary for the service. However, you may opt out of non-essential communications – for example, you can unsubscribe from any optional newsletters or motivational messages. Each such email/SMS will contain an opt-out method (like an "unsubscribe" link or instructions to stop messages).
To exercise any of these rights, you can contact us at the contact information provided at the end of this policy. We will require you to verify your identity (to ensure that the person requesting access or change is actually you) before fulfilling such requests. We will respond to your request within a reasonable timeframe as required by law.
7. Cookies and Tracking Technologies: Our website uses cookies and similar technologies to enhance user experience. Cookies are small text files placed on your device to store preferences and settings, enable sign-in, and analyze site operations. For example, we might use cookies to keep you logged in during a session or to remember your preferences for next time. We may also use third-party analytics cookies (like Google Analytics) to collect information about usage of our site (such as which pages are visited, for how long, etc.) to help us improve content and navigation. These analytics cookies collect information in an aggregated form and do not identify you personally. You can control cookies through your browser settings – for instance, you can set your browser to refuse all or some cookies or to alert you when cookies are being sent. However, if you disable cookies, some parts of the service might become inaccessible or not function properly (for example, the teleconsultation interface might require session cookies).
8. Third-Party Websites: Our website or communications may contain links to external websites or services that are not operated by us (for example, an article on health information, or a reference to an exercise video on YouTube). This Privacy Policy does not apply to those third-party sites. We are not responsible for the content, privacy policies, or practices of any third-party websites. We encourage you to review the privacy policies of any external sites you visit.
9. Compliance with Telemedicine Guidelines: As part of maintaining confidentiality, all our telemedicine consultations are conducted in private. The doctor will ensure that no unauthorized person is privy to your consultation without your consent (except permissible caregivers or health workers in certain cases), and we expect you as the patient to also be in a private area during consults to maintain confidentiality. The platform and doctors abide by doctor-patient confidentiality ethics and the IT Act's data protection provisions. We also follow the Telemedicine Practice Guidelines requirement to maintain digital consultation records. Consultation records, prescriptions, and consent (implied or explicit) are documented and stored securely.
10. Changes to this Privacy Policy: We may update this Privacy Policy from time to time as we add new features or as laws change. We will notify users of any significant changes. Notification may be given by posting the updated policy on our website with a new effective date and/or by emailing you or informing you via the service. It is your responsibility to review the Privacy Policy periodically. Your continued use of the service after any changes indicates acceptance of the updated terms. If you do not agree with the changes, you should stop using the service and can request deletion of your data as described above.
11. Contact Information (Grievance Officer): If you have any questions, concerns, or complaints regarding this Privacy Policy or your personal data, you may contact our designated Grievance Officer (Data Protection Officer) at:
Name: Aniket Jain
Email: support@thepfc.club
Address: 608, Platinum Square, Sakorenagar, Pune, India.
Phone: +91 99701 63396 (available on business days [10 AM to 7 PM]).
This contact is provided in accordance with Section 7 of the SPDI Rules and the Consumer Protection (E-Commerce) Rules. We will strive to address your concerns in a timely manner. For any grievances, we will acknowledge receipt within 24 hours and resolve the issue within 15 days or as per applicable law.