This document may change. As PROFR grows, our practices, features, and legal obligations evolve. We will always notify you by email at least 14 days before any material change takes effect. The latest version is always published at this URL. Continued use of the platform after the effective date of a change constitutes acceptance. You can find the full change policy in Section 11 below.

Plain-English summary: PROFR collects only the data needed to run your practice. We do not sell your data or your clients' data to anyone — ever. We use reputable third-party services (listed below) to operate the platform. You can request deletion of your data at any time by writing to us.

Who we are

PROFR is a practice management platform operated by CIVIGO Solutions Private Limited, a company incorporated under the Companies Act, 2013, with its registered office in Hyderabad, Telangana, India ("CIVIGO", "we", "us", or "our").

CIVIGO is the Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 ("DPDP Act") for all personal data processed through the PROFR platform, accessible at profr.in, dashboard.profr.in, and associated subdomains.

This Privacy Policy describes how we collect, use, store, share, and protect personal data, and explains your rights as a Data Principal under applicable Indian law, including the DPDP Act and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").

Data we collect

2.1 Data you provide directly

  • Account registration: Full name, business email address, mobile number, professional category, and password (stored as a one-way bcrypt hash — never in plain text).
  • Professional profile: Business name, handle/URL slug, profile photo, professional qualifications, specialisations, service descriptions, and session pricing.
  • Client records: Client name, contact details, health background notes, intake notes, session notes, and any custom fields you define. This data is entered by you (the professional) as part of managing your practice.
  • Payment information: Invoice details, session amounts, GST percentage, and payment status. We do not store card numbers, UPI credentials, or banking details. All payment processing is handled by Razorpay (see Section 5).
  • Communications: Messages you send to our support team via email or in-app contact forms.

2.2 Data collected automatically

  • Log data: IP address, browser type, operating system, pages visited, timestamps, and referring URLs — collected when you access the platform.
  • Device data: Device type, screen resolution, and browser language.
  • Session data: Authentication tokens stored as HttpOnly cookies (not accessible to JavaScript). These tokens expire automatically and are invalidated on logout or password change.
  • Usage data: Feature interactions, page views, and error reports — used to improve the platform. These are processed by Sentry (see Section 5) with personally identifiable information masked.

2.3 Data from third-party integrations (with your consent)

  • Google Calendar: If you connect your Google Calendar, we store your Google account email address and OAuth tokens (encrypted using AES-256-GCM). We use these solely to create Google Meet links for your sessions and to read/write calendar events on your behalf. We do not access any other Google data.
  • WhatsApp Business: If you use WhatsApp-based client communication via PROFR, message metadata (send/delivery status) is processed through Meta's WhatsApp Business API. Message content is governed by Meta's Privacy Policy.

2.4 Sensitive Personal Data or Information (SPDI)

Under the SPDI Rules, certain categories of data receive heightened protection. PROFR may process the following SPDI on behalf of professionals managing health and wellness clients:

  • Physical or mental health information entered into session notes or health background fields
  • Dietary and lifestyle information entered into intake forms

This SPDI is entered by professionals about their clients, stored in an encrypted database (PostgreSQL on AWS RDS with encryption at rest), and is never shared with any third party for commercial purposes. Access is restricted to the professional who entered the data, using row-level security enforced at the database layer.

How we use your data

We use personal data only for the purposes for which it was collected or as required by law. Specifically:

  • To provide the PROFR platform: Creating and managing your account, enabling client management, session booking, invoicing, and Google Calendar integration.
  • To facilitate payments: Passing the minimum required information to Razorpay to process session payments and generate GST invoices.
  • To send service communications: Password reset OTPs, session reminders, booking confirmations, and platform notifications via email or WhatsApp. These are transactional communications, not marketing.
  • To improve the platform: Aggregated, anonymised usage analytics to understand which features are used and to fix errors. We do not profile individual users for this purpose.
  • To maintain security: Detecting and preventing fraud, unauthorised access, and abuse of the platform. Login attempt monitoring, rate limiting, and audit logging are performed for this purpose.
  • To comply with legal obligations: Responding to lawful requests from courts, law enforcement, or regulatory authorities under applicable Indian law, including Section 79 of the IT Act, 2000.

We do not use your data or your clients' data for advertising, profiling for third-party commercial purposes, or training artificial intelligence models.

Third-party processors

We engage the following sub-processors to operate the PROFR platform. Each processes your data only to the extent necessary for the stated purpose, under contractual data protection obligations:

Processor Purpose Data shared Location Privacy policy
Amazon Web Services (AWS) Cloud infrastructure, database hosting (RDS), file storage (S3), email delivery (SES), compute (ECS) All platform data at rest and in transit ap-south-1 (Mumbai, India) aws.amazon.com/privacy
Razorpay Software Pvt. Ltd. Payment processing, sub-merchant accounts for professionals Name, email, phone, invoice amount, GST details India razorpay.com/privacy
Google LLC Calendar integration (Google Calendar API), video conferencing (Google Meet links), SMTP relay OAuth tokens (encrypted), calendar event data, email delivery USA (Standard Contractual Clauses apply) policies.google.com/privacy
MSG91 (Walkover Web Solutions Pvt. Ltd.) SMS OTP delivery, WhatsApp Business API messaging Mobile number, OTP code, WhatsApp message content India msg91.com/privacy-policy
Anthropic PBC AI-powered features (Chavi follow-up agent, session summaries) Conversation context — anonymised where possible USA (Standard Contractual Clauses apply) anthropic.com/privacy
Sentry (Functional Software Inc.) Error tracking and platform monitoring Error logs with PII masked — no email, phone, or health data transmitted USA (Standard Contractual Clauses apply) sentry.io/privacy
Meta Platforms, Inc. WhatsApp Business API (message delivery infrastructure) Phone number, message content for WhatsApp communications USA (Standard Contractual Clauses apply) facebook.com/policy
Formspree Inc. Landing page waitlist form submission Email address only USA formspree.io/legal/privacy-policy

We do not sell, rent, or trade your personal data or your clients' data to any third party for commercial or marketing purposes. We do not permit any sub-processor to use your data for their own independent purposes beyond what is stated above.

5.1 Cross-border data transfers

Some of our sub-processors are located outside India. Where personal data is transferred to countries that do not have an adequacy decision from the Indian government, we rely on Standard Contractual Clauses or equivalent contractual safeguards, as permitted under the DPDP Act, 2023, to ensure your data receives an equivalent level of protection.

All primary platform data — your account, client records, session notes, and payments — is stored exclusively on AWS infrastructure in the ap-south-1 (Mumbai) region within India.

Data retention

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by applicable law:

  • Account data: Retained for the duration of your active subscription plus 3 years after account closure, to comply with GST and tax record-keeping obligations under the GST Act, 2017.
  • Client records and session notes: Retained for the duration of the professional's active subscription. Upon account closure, client records are retained for 2 years to comply with applicable professional and health record-keeping obligations, after which they are permanently deleted.
  • Payment and invoice records: Retained for 7 years as required under the Income Tax Act, 1961, and GST Act, 2017.
  • Authentication logs and security audit trails: Retained for 180 days, as required under the IT (Amendment) Act, 2008 and CERT-In guidelines.
  • Error and system logs: Retained for 90 days.
  • Google OAuth tokens: Retained only while your Google Calendar is connected. Revoked and deleted immediately upon disconnecting your calendar.

After the applicable retention period, data is permanently deleted or anonymised such that it can no longer be linked to an identifiable individual.

Your rights

As a Data Principal under the DPDP Act, 2023, and under the SPDI Rules, you have the following rights:

Right to access

You may request a summary of the personal data we hold about you and the purposes for which it is being processed. We will respond within 30 days of a verifiable written request.

Right to correction

You may request correction of inaccurate or incomplete personal data. Most profile data can be updated directly through your account settings. For other corrections, write to us.

Right to erasure

You may request deletion of your personal data. We will honour erasure requests subject to: (a) our legal obligation to retain certain records as described in Section 6; and (b) the practical necessity of retaining anonymised data for audit purposes. Upon erasure, your account will be deactivated and your data permanently deleted within 30 days, except where legal retention obligations apply.

Right to grievance redressal

You have the right to have your grievances addressed by our Grievance Officer within the timelines specified in Section 12.

Right to withdraw consent

Where processing is based on your consent, you may withdraw consent at any time by writing to us. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal. However, withdrawal of consent for core platform functionality (e.g., processing your account data) will result in termination of the service.

Right to nominate

You have the right to nominate another individual to exercise your rights on your behalf in the event of death or incapacity, as provided under Section 14 of the DPDP Act, 2023.

To exercise any of these rights, write to santosh@profr.in with the subject line "Data Rights Request — [Your Name]". We will acknowledge your request within 72 hours and provide a substantive response within 30 days. We may ask for identity verification before processing requests.

Security measures

We implement reasonable security practices as required under Section 43A of the IT Act, 2000 and the SPDI Rules, 2011. Our security measures include:

  • Encryption in transit: All data transmitted between your browser and PROFR servers uses TLS 1.2 or higher (HTTPS enforced).
  • Encryption at rest: Database (AWS RDS), file storage (AWS S3), and cache layer (AWS ElastiCache) are encrypted at rest using AES-256.
  • OAuth token encryption: Google Calendar OAuth tokens are encrypted using AES-256-GCM before storage and are never stored in plain text.
  • Password security: Passwords are hashed using bcrypt with a cost factor of 12. Plain text passwords are never stored or transmitted.
  • Authentication controls: Multi-factor authentication (OTP and TOTP), session invalidation on password change, refresh token rotation with reuse detection, and account lockout after 5 failed login attempts.
  • Access controls: Row-level security (RLS) enforced at the database layer ensures each professional can only access their own client data.
  • Infrastructure isolation: All production resources operate within a private AWS VPC. Database and cache are not publicly accessible.
  • Audit logging: All significant actions are logged with timestamps, user identifiers, and IP addresses.
  • Vulnerability management: Dependencies are monitored for known vulnerabilities on every code deployment. Critical vulnerabilities are patched within 24 hours of disclosure.

Notwithstanding the above, no system is completely immune to security breaches. In the event of a data breach that is likely to cause harm to Data Principals, we will notify affected users and the relevant authority within the timeframes prescribed by the DPDP Act and CERT-In guidelines.

Children's privacy

PROFR is a business platform intended for use by independent professionals and their adult clients. We do not knowingly collect personal data from individuals under the age of 18 years.

If you believe that a minor's data has been provided to us without appropriate parental or guardian consent, please contact us immediately at contact@profr.in. We will take prompt steps to delete such data upon verification.

Professionals using PROFR to manage clients who are minors are responsible for obtaining appropriate parental or guardian consent before entering any data related to such clients into the platform, in compliance with applicable law including Section 9 of the DPDP Act, 2023.

Cookies & tracking

Authentication cookies (essential)

We use HttpOnly, Secure session cookies solely to maintain your login session. These cookies:

  • Are set only after you log in
  • Cannot be accessed by JavaScript (preventing XSS theft)
  • Expire automatically after 15 minutes of inactivity (access token) or 7 days (refresh token)
  • Are immediately invalidated on logout or password change

These cookies are strictly necessary for the platform to function and cannot be disabled without preventing login.

Analytics (landing page only)

The PROFR landing page (profr.in) does not set any third-party analytics cookies. We do not use Google Analytics, Facebook Pixel, or any behavioural tracking on the landing page.

No advertising cookies

We do not use advertising cookies, retargeting pixels, or any tracking technology for commercial advertising purposes on any part of the PROFR platform.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or the services we offer. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Notify registered professionals by email to their registered address at least 14 days before the changes take effect
  • Where required by law, obtain fresh consent before processing your data under the revised terms

If you do not agree with a material change, you have the right to close your account and request deletion of your data before the change takes effect. Continued use of the platform after the effective date constitutes acceptance of the updated policy.

For non-material changes (such as corrections, clarifications, or addition of new sub-processors offering equivalent protections), we will update the policy without advance notice but will update the "Last updated" date.

Grievance officer

In accordance with Rule 5(9) of the SPDI Rules, 2011, and the DPDP Act, 2023, we have designated a Grievance Officer to address privacy-related complaints and requests:

Grievance Officer

Santosh Maturi

Founder & Director, CIVIGO Solutions Private Limited

Email: santosh@profr.in

General enquiries: contact@profr.in

Address: Hyderabad, Telangana, India

Response: acknowledgement within 24 hours · resolution within 30 days

Grievances must be submitted in writing (email accepted). We will acknowledge receipt of your complaint within 24 hours and endeavour to resolve it within 30 days of receipt, in accordance with the IT Act, 2000 and DPDP Act, 2023.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India, once constituted under the DPDP Act, 2023, or to any other authority having jurisdiction under applicable law.

Contact us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, you may contact us by:

  • Email: contact@profr.in
  • Grievance Officer (data rights requests): santosh@profr.in
  • Postal address: CIVIGO Solutions Private Limited, Hyderabad, Telangana, India

This Privacy Policy is governed by and construed in accordance with the laws of India. Any disputes arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Hyderabad, Telangana.