Privacy Policy
This Privacy Policy explains how IAFA Ayurveda India / Institute of Applied Food Allergy (“IAFA”, “we”, “us”, or “our”) collects, receives, uses, processes, stores, protects, shares, retains, and deletes personal information in connection with its websites, digital platforms, clinical and consultation services, assessments, communications, research and educational activities, and online store.
This Privacy Policy applies to, as applicable:
- www.iafaforallergy.com
- store.iafaforallergy.com
- IAFA digital assessment like PAAM and healthcare-support platforms;
- online consultation and appointment systems;
- patient-registration and assessment forms;
- clinical communication channels;
- email, telephone, SMS, WhatsApp and other official communication channels;
- research and educational activities;
- customer-support systems;
- online ordering, payment and delivery systems;
- product reviews, feedback and related store functionality; and
- other digital services or platforms operated or authorized by IAFA.
By accessing or using an IAFA platform, submitting information to IAFA, requesting a consultation, participating in an assessment, communicating with IAFA, or purchasing a product through the IAFA Store, you acknowledge that you have read and understood this Privacy Policy and agree to the processing of information described herein, subject to applicable law and any separate consent or service-specific terms that may apply.
If you do not agree with the applicable terms or privacy practices, you should discontinue use of the relevant service and should not voluntarily submit unnecessary personal or health information through the platform.
1. PRIVACY COMMITMENT
IAFA recognizes that personal information, particularly health-related information, clinical history, medical reports, allergy information, and clinical photographs may be sensitive.
IAFA seeks to:
- provide appropriate mechanisms for privacy-related requests;
- delete or irreversibly anonymize information when it is no longer required, subject to applicable retention requirements; and
- prevent unauthorized public access to confidential clinical information.
- collect information that is reasonably necessary for identified purposes;
- communicate the relevant purpose for which information is collected;
- use information for legitimate and disclosed purposes;
- restrict access to authorized persons where appropriate;
- implement reasonable technical and organizational safeguards;
- avoid unnecessary retention;
- maintain appropriate records concerning consent and privacy preferences where required;
IAFA does not intend to sell identifiable patient health information as a commercial data product.
2. ORGANIZATION RESPONSIBLE FOR PERSONAL INFORMATION
IAFA Ayurveda India / Institute of Applied Food Allergy is responsible for the personal information collected directly through its own websites, platforms, forms, services, communications, and store, subject to the role and obligations applicable to a particular processing activity.
Where third-party service providers process information on behalf of IAFA, such providers may process information under their own applicable legal responsibilities, contractual obligations, privacy policies, and security arrangements.
Organization: IAFA Ayurveda India / Institute of Applied Food Allergy
Official Website: www.iafaforallergy.com
Privacy Email: info@iafaforallergy.com
Privacy Contact: +91-96121-80000
Registered/Business Address: #26 Sector-7 Gohana, Haryana, India Pin Code-131301
3. INFORMATION WE MAY COLLECT
The information collected depends upon how an individual interacts with IAFA.
IAFA may collect information directly provided by an individual and certain technical or transactional information generated through use of the relevant platform.
3.1 Identity and Contact Information
This may include:
- full name;
- date of birth or age;
- gender, where relevant;
- email address;
- telephone/mobile number;
- residential or postal address;
- delivery address;
- country, state, city or locality;
- communication preferences;
- emergency-contact information where voluntarily provided and relevant; and
- other information voluntarily provided by the individual.
3.2 Account and Authentication Information
Where an online account is created, IAFA or its service provider may process:
- username;
- account identifier;
- email/mobile number associated with the account;
- authentication information;
- password-related security information;
- account preferences;
- wishlist information;
- saved products;
- order history;
- account activity;
- login and security records; and
- related technical information.
Passwords should be protected using appropriate security mechanisms and should not ordinarily be stored in plain-text form.
4. HEALTH, CLINICAL AND MEDICAL INFORMATION
Where an individual requests or participates in an IAFA clinical, consultation, assessment, healthcare-support, or related service, IAFA may collect information including:
- medical history;
- presenting complaints;
- symptoms;
- allergy history;
- food-allergy information;
- previous diagnoses;
- treatment history;
- medication information;
- supplement and herbal-product information;
- dietary information;
- lifestyle information;
- family history where relevant;
- laboratory reports;
- diagnostic reports;
- imaging reports;
- prescriptions;
- clinical observations;
- consultation records;
- follow-up information;
- treatment responses;
- Prakriti-related information;
- Ayurveda-related assessment information;
- information relating to physical or mental health;
- clinical photographs;
- videos;
- health questionnaires; and
- other health information voluntarily provided for the relevant service.
Health information will be handled with appropriate confidentiality and access controls.
5. CLINICAL PHOTOGRAPHS, VIDEOS AND IMAGES
Where an individual voluntarily provides photographs, clinical images, skin photographs, videos, medical reports, or other visual information for consultation, assessment, documentation, follow-up, research, education, or another disclosed purpose, IAFA may collect and process such information for that purpose.
Clinical photographs and visual health information may constitute sensitive health information.
IAFA will take reasonable measures to prevent unauthorized public access to clinical images.
Clinical images should not be intentionally exposed through:
- public URLs;
- search-engine-indexed folders;
- unsecured public cloud folders;
- predictable public file paths;
- anonymous download endpoints;
- publicly accessible databases; or
- unauthorized third-party applications.
Identifiable clinical images will not knowingly be used for public advertising, promotional campaigns, unrelated marketing, or unrelated commercial purposes without appropriate consent where such consent is required.
Separate consent may be obtained where clinical images or identifiable health information are intended for:
- research;
- academic publication;
- scientific presentation;
- educational publication;
- case reports;
- testimonials;
- public display; or
- other secondary purposes.
6. CHILDREN AND MINORS
IAFA may provide services, assessments, educational information, or products that involve children or minors.
Where a parent, legal guardian, or legally authorized representative is required to provide consent, IAFA may request appropriate confirmation of that authority.
Parents or legal guardians are responsible for ensuring that information supplied concerning a minor is accurate and that they are legally authorized to provide such information and consent.
IAFA will seek to collect only information reasonably necessary for the relevant service or purpose.
Where applicable law requires additional safeguards concerning children’s personal information, IAFA will apply such requirements to the extent legally applicable.
7. INFORMATION COLLECTED THROUGH THE ONLINE STORE
When an individual purchases or attempts to purchase a product through the IAFA Store, IAFA or its service providers may collect:
- name;
- email address;
- telephone number;
- billing information;
- shipping address;
- delivery information;
- order details;
- products purchased;
- quantities;
- transaction status;
- invoice information;
- refund information;
- cancellation information;
- customer-service communications;
- account information;
- product reviews;
- wishlist information; and
- information necessary to process or fulfill the transaction.
IAFA may receive transaction-related information from payment providers without receiving or storing complete payment-card credentials where payment is processed directly by the payment provider.
8. PAYMENT PROCESSING
Payments may be processed through independent third-party payment gateways or financial-service providers. Payment providers may independently collect and process payment and financial information under their own terms, privacy practices, security measures, and legal obligations.
IAFA does not control the independent privacy practices of third-party payment providers.
Users should review the applicable privacy notice of the payment provider where relevant.
9. SHIPPING, DELIVERY AND ORDER FULFILLMENT
For product purchases, IAFA may provide information reasonably necessary for order fulfillment to:
- courier companies;
- logistics providers;
- shipping partners;
- fulfillment providers;
- warehouse or dispatch partners;
- manufacturers or suppliers where relevant; and
- other authorized service providers.
Information may include:
- name;
- delivery address;
- telephone number;
- email address;
- order number;
- product/order information; and
- shipment information.
Such information will be shared only to the extent reasonably necessary for the relevant purpose, subject to applicable law.
10. WISHLISTS, REVIEWS AND USER-GENERATED CONTENT
Where the IAFA Store provides wishlist, compare, review, rating, comment, testimonial, account, product-saving, or similar functions, IAFA may process information necessary to operate those functions.
If a user voluntarily submits content intended for public display, including:
- product reviews;
- ratings;
- comments;
- testimonials;
- photographs; or
- other user-generated content,
such information may become publicly visible depending on the functionality selected.
Users must not submit to another person’s confidential, private, sensitive, or health information without appropriate authorization.
IAFA may moderate, remove, restrict, or otherwise manage user-generated content in accordance with applicable Terms & Conditions and law.
11. THIRD-PARTY PRODUCTS, MANUFACTURERS AND SUPPLIERS
The IAFA Store may offer products manufactured, formulated, supplied, distributed, or otherwise provided by third-party brands or manufacturers.
The presence of a third-party product on the IAFA Store does not necessarily mean that IAFA is:
- the manufacturer;
- formulator;
- importer;
- distributor;
- regulatory sponsor; or
- exclusive supplier
of that product.
Where reasonably necessary for order fulfillment, customer support, product safety, replacement, warranty handling, quality investigation, regulatory compliance, or another legitimate purpose, IAFA may share relevant transaction or customer information with an applicable manufacturer, supplier, distributor, or authorized service provider.
Third-party organizations may have their own privacy practices and legal obligations.
12. PURPOSES FOR WHICH IAFA MAY PROCESS INFORMATION
IAFA may process personal information for purposes including:
- providing requested consultations and healthcare-support services;
- conducting assessments;
- maintaining clinical documentation;
- scheduling appointments;
- communicating with patients and customers;
- providing follow-up;
- responding to inquiries;
- processing product orders;
- processing payments and refunds;
- arranging shipping and delivery;
- managing customer accounts;
- maintaining wishlists and store functions;
- providing customer support;
- processing product reviews and feedback;
- conducting quality improvement;
- conducting research or scientific analysis where appropriately authorized;
- educational activities;
- maintaining website and platform functionality;
- cybersecurity;
- fraud and abuse prevention;
- maintaining system integrity;
- responding to lawful requests;
- complying with applicable legal, professional, tax, accounting, regulatory or contractual requirements;
- preventing unauthorized access;
- protecting IAFA’s rights, property, systems and users;
- communicating service-related information;
- sending promotional communications where appropriately permitted;
- administering franchise, distributorship, partnership or professional inquiries;
- maintaining required business records; and
- other purposes disclosed at or before collection.
IAFA will not intentionally use personal information for materially unrelated purposes without appropriate notice or authorization where required.
13. DATA MINIMIZATION
IAFA seeks to collect personal information that is reasonably necessary and relevant for the purpose for which it is collected.
IAFA does not intend to collect health information merely because it may potentially be useful in the future.
Users are encouraged not to submit unnecessary personal, medical, financial, or third-party information.
14. CONSENT
Where IAFA relies upon consent for processing, consent may be obtained through:
- electronic checkboxes;
- forms;
- written consent;
- digital confirmation;
- consultation consent;
- clinical image consent;
- research consent;
- marketing consent; or
- another appropriate affirmative mechanism.
Where appropriate:
- consent will identify the relevant purpose;
- optional purposes will be separated from necessary purposes;
- consent will not be inferred merely from silence;
- consent may be withdrawn where applicable;
- withdrawal will not invalidate processing already lawfully performed before withdrawal; and
- Withdrawal may affect IAFA’s ability to provide a service where the information is necessary for that service.
Separate consent may be obtained for clinical images, research, publication, testimonials, marketing, or other optional uses.
15. WITHDRAWAL OF CONSENT
Where processing is based on consent, an individual may request withdrawal of consent by contacting IAFA through the privacy contact provided in this Policy or through the applicable consent-management mechanism.
Withdrawal of consent does not automatically require deletion of information where IAFA is legally required or otherwise lawfully permitted to retain or process that information.
Withdrawal may also affect IAFA’s ability to provide a requested service where the relevant information is necessary to provide that service.
16. SOURCES OF PERSONAL INFORMATION
IAFA may obtain information:
- directly from the individual;
- from a parent or legal guardian;
- from an authorized representative;
- from healthcare professionals involved in the requested service;
- through IAFA websites;
- through online forms;
- through digital assessment tools;
- through consultation systems;
- through product orders;
- through customer-service interactions;
- through payment providers;
- through shipping providers;
- through authorized service providers;
- from publicly available sources where legally permitted; and
- from other sources where collection is authorized or legally permitted.
17. DATA SHARING AND DISCLOSURE
IAFA may disclose information where reasonably necessary to:
- authorized IAFA personnel;
- healthcare professionals;
- consultants;
- service providers;
- cloud and hosting providers;
- payment processors;
- logistics providers;
- manufacturers or suppliers;
- customer-support providers;
- communication providers;
- technology providers;
- cybersecurity providers;
- professional advisers;
- accountants;
- auditors;
- insurers where applicable;
- research collaborators where appropriately authorized;
- government authorities;
- regulators;
- courts;
- law-enforcement authorities; or
- other people where disclosure is required or permitted by law.
IAFA seeks to limit disclosure to information reasonably necessary for the relevant purpose.
18. THIRD-PARTY SERVICE PROVIDERS
IAFA may use third-party service providers for:
- website hosting;
- cloud storage;
- database services;
- cybersecurity;
- payment processing;
- appointment scheduling;
- email;
- SMS;
- WhatsApp or other messaging;
- video consultation;
- analytics;
- customer support;
- order fulfillment;
- shipping;
- accounting;
- technical maintenance;
- research support;
- professional services; and
- other operational requirements.
Where appropriate, IAFA will seek contractual and technical safeguards appropriate to the nature of the information being processed.
Third-party providers may have their own privacy policies and legal responsibilities.
19. INTERNATIONAL DATA PROCESSING
IAFA is an India-based organization.
Personal information may be processed, stored, accessed, or transmitted within India and, where necessary, through authorized third-party service providers located in other countries.
International processing may occur because IAFA uses third-party technology, hosting, communication, payment, analytics, storage, consultation, or operational services.
By voluntarily submitting information to IAFA, an individual acknowledges that such information may be processed through these systems where reasonably necessary for the relevant service or purpose.
20. INTERNATIONAL ACCESS AND FOREIGN PRIVACY LAWS
IAFA’s websites and services may be accessible from countries outside India.
Internet accessibility does not mean that IAFA represents that:
- IAFA is licensed or authorized to provide healthcare or Ayurveda services in every country;
- IAFA practitioners are licensed in every country;
- IAFA products are approved or registered in every country;
- IAFA’s services satisfy every foreign privacy or healthcare regulation;
- IAFA has obtained certification or approval from every foreign regulatory authority; or
- IAFA has voluntarily submitted itself to every foreign legal or regulatory regime merely because its website is accessible internationally.
The applicability of any foreign law depends upon the facts and circumstances relevant to that law.
IAFA does not represent that this Privacy Policy constitutes compliance with every privacy, healthcare, telemedicine, consumer-protection, data-protection, or other law of every country. Where a mandatory legal requirement is legally applicable to a particular IAFA activity, IAFA will address that requirement to the extent legally required.
21. INTERNATIONAL USER RESPONSIBILITY
Individuals accessing IAFA from outside India do so voluntarily and at their own initiative.
International users are responsible for determining whether:
- access to IAFA;
- submission of personal or health information;
- online consultation;
- digital assessment;
- communication with IAFA;
- purchase of products;
- importation of products; or
- use of IAFA products or services
is lawful in their jurisdiction.
IAFA does not provide individualized foreign legal or regulatory advice.
22. NO AUTOMATIC FOREIGN PROFESSIONAL RELATIONSHIP
Accessing IAFA from outside India does not, by itself, establish that IAFA or an IAFA practitioner is practicing a regulated healthcare profession within the user’s jurisdiction.
It also does not automatically establish a local physician-patient, doctor-patient, practitioner-patient, telemedicine, telehealth, or other regulated professional relationship solely because the user is physically located outside India.
Any separately offered consultation or professional service is subject to the terms applicable to that service and the circumstances under which it is provided.
23. INTERNATIONAL CLAIMS, LIABILITY AND COMPENSATION
To the maximum extent permitted by applicable law, voluntary access to IAFA from outside India shall not, solely because of the user’s location, constitute:
- an admission by IAFA that it is subject to the user’s local professional licensing regime;
- an admission that IAFA has established a healthcare practice in that jurisdiction;
- an agreement by IAFA to submit to every foreign court, regulator, or professional authority;
- a guarantee of any healthcare, therapeutic, commercial, or other outcome;
- an automatic entitlement to compensation, damages, reimbursement, or other monetary remedy; or
- an automatic acceptance by IAFA of liability under a foreign legal regime solely because the user accessed the platform internationally.
Any dispute, claim, compensation request, liability issue, or legal proceeding shall be governed by the applicable IAFA Terms & Conditions, service-specific agreement, contractual terms, governing-law provisions, and mandatory law applicable to the particular circumstances.
Nothing in this Privacy Policy is intended to exclude or limit any liability, right, remedy, or protection that cannot lawfully be excluded or limited.
24. INTERNATIONAL PRODUCT IMPORTATION
The legal classification of an Ayurvedic medicine, herbal product, supplement, food, cosmetic, personal-care product, or other product may differ between jurisdictions.
A product that is lawfully manufactured, marketed, or sold in India may be subject to different requirements in another country.
International customers are responsible for determining:
- whether the product may legally be imported;
- whether a permit or authorization is required;
- whether a prescription is required;
- whether customs restrictions apply;
- whether taxes or duties apply;
- whether the product may legally be possessed or used; and
- whether the product is appropriate for their individual circumstances.
IAFA does not guarantee customs clearance, import approval, regulatory acceptance, delivery, or lawful use of a product outside India.
25. CLINICAL DATA ACCESS AND CONFIDENTIALITY
Patient health information and clinical images shall be accessible only to people who require access for legitimate IAFA-related purposes, subject to the systems and services involved.
IAFA seeks to prevent clinical information from being made accessible through:
- public URLs;
- public search-engine indexing;
- unsecured shared folders;
- unrestricted cloud links;
- predictable file paths;
- anonymous download endpoints; or
- unauthorized applications.
Users should also use only official IAFA communication channels when submitting sensitive information.
26. RESEARCH, EDUCATION AND SCIENTIFIC USE
IAFA may conduct or participate in:
- research;
- scientific analysis;
- educational activities;
- academic work;
- quality improvement;
- statistical analysis;
- publication; and
- other legitimate research-related activities.
Where possible, IAFA will use de-identified or anonymized information.
Identifiable clinical information or clinical images may be used for research, publication, education, or scientific presentation only where an appropriate consent, authorization, legal basis, or other lawful mechanism exists.
Optional research consent will be kept separate from consent necessary to provide ordinary clinical services wherever appropriate.
27. ANONYMIZATION
Where personal information is irreversibly anonymized so that an individual can no longer reasonably be identified, IAFA may retain and use the resulting anonymized information for legitimate purposes including:
- research;
- statistics;
- education;
- scientific analysis;
- quality improvement;
- service development; and
- other lawful purposes.
IAFA will not intentionally attempt to re-identify properly anonymized information except where permitted or required by law.
28. TESTIMONIALS, CASE STUDIES AND PATIENT EXPERIENCES
IAFA may receive or publish testimonials, reviews, case studies, patient experiences, or educational examples.
A person’s experience does not guarantee that another person will achieve the same result.
Where identifiable health information, clinical photographs, or sensitive information is used in a testimonial, case study, publication, or public presentation, IAFA will obtain appropriate consent or authorization where required.
Consent for clinical treatment or assessment does not automatically constitute consent for public publication or marketing use.
29. COOKIES AND TRACKING TECHNOLOGIES
IAFA may use cookies and similar technologies for:
- essential website functionality;
- security;
- session management;
- authentication;
- preferences;
- performance;
- analytics;
- service improvement;
- fraud prevention; and
- marketing or advertising where permitted.
Cookies and tracking technologies may be operated directly by IAFA or by authorized third-party service providers.
Users may manage available cookie settings through applicable browser or device controls and, where provided, IAFA’s cookie-preference mechanism.
Disabling certain technologies may affect website functionality.
Where applicable law requires a specific consent mechanism for non-essential tracking technologies, IAFA may provide the relevant mechanism.
30. TECHNICAL AND DEVICE INFORMATION
IAFA may automatically receive technical information when users access its websites or digital systems.
Depending on the technology used, this may include:
- IP address;
- browser type;
- operating system;
- device information;
- access time;
- referring page;
- pages visited;
- session information;
- security events;
- authentication events;
- error information;
- approximate location derived from technical information; and
- other diagnostic information.
This information may be used for:
- cybersecurity;
- system administration;
- fraud prevention;
- troubleshooting;
- performance monitoring;
- service improvement; and
- lawful operational purposes.
31. AUTOMATED, ALGORITHMIC AND DIGITAL ASSESSMENT SYSTEMS
IAFA may use digital questionnaires, algorithms, computational systems, automated tools, artificial-intelligence-assisted tools, or other technology-enabled assessment systems.
Such systems may generate informational, administrative, research, or assessment outputs.
Unless expressly stated otherwise:
- automated outputs are not intended to replace qualified professional judgment;
- automated outputs may contain errors or limitations;
- automated systems may not capture the complete clinical circumstances of an individual;
- automated outputs should not be used as the sole basis for emergency decisions; and
- clinical decisions remain subject to appropriate professional evaluation where required.
32. DATA SECURITY
IAFA seeks to maintain reasonable technical and organizational safeguards appropriate to the nature of information processed.
Depending upon the relevant system, safeguards may include:
- encryption in transit;
- encryption at rest where appropriate;
- authentication;
- role-based access control;
- least-privilege access;
- secure hosting;
- access logging;
- monitoring;
- vulnerability management;
- backups;
- restricted administrative access;
- security testing; and
- incident-response procedures.
No internet transmission, electronic communication, website, cloud system, or digital storage system can be guaranteed to be completely secure.
Accordingly, users acknowledge that transmission of information through the internet carries inherent risks.
33. SECURITY INCIDENTS AND DATA BREACHES
IAFA may maintain procedures for identifying, investigating, containing, documenting, and responding to suspected security incidents.
Where applicable law requires notification concerning a security incident or personal data breach, IAFA will take the actions required by the applicable legal framework.
The nature and timing of any notification may depend upon:
- the type of information involved;
- the nature of the incident;
- the applicable law;
- the risk created by the incident; and
- the information reasonably available to IAFA at the relevant time.
34. DATA RETENTION- THREE-YEAR STANDARD FOR PATIENT/CLINICAL DATA
IAFA’s standard operational retention period for patient-provided clinical and health information is a maximum of three (3) years from the date of the patient's last relevant clinical interaction, consultation, assessment, or follow-up.
This may include:
- medical history;
- consultation information;
- clinical notes;
- assessment information;
- clinical photographs;
- uploaded reports;
- health questionnaires;
- follow-up information;
- treatment-response information; and
- related clinical records.
The three-year period is IAFA’s standard operational retention policy and is not intended to override any mandatory legal, professional, regulatory, accounting, tax, litigation, or other legally applicable retention requirements.
35. THIRD-PARTY RETENTION
IAFA’s three-year clinical retention policy does not automatically control independent retention periods maintained by:
- payment providers;
- courier companies;
- logistics providers;
- cloud providers;
- communication providers;
- external healthcare professionals;
- insurers;
- government authorities;
- manufacturers;
- suppliers; or
- other independent third parties.
Such parties may retain information according to their own lawful obligations and applicable policies.
36. STORE, PAYMENT, TAX AND ACCOUNTING RECORDS
The three-year clinical retention policy does not automatically apply to commercial records.
IAFA may retain:
- orders;
- invoices;
- payment records;
- tax records;
- refunds;
- shipping records;
- warranties;
- customer disputes;
- transaction records;
- accounting information; and
- other commercial records
for as long as reasonably necessary or legally required for the relevant purpose.
37. PRIVACY REQUESTS AND INDIVIDUAL RIGHTS
Depending upon applicable law, individuals may have rights relating to their personal information, including:
- requesting access;
- requesting correction;
- requesting updating;
- requesting deletion where applicable;
- withdrawing consent;
- requesting information concerning processing;
- requesting information concerning relevant disclosures;
- objecting to certain processing where legally available;
- opting out of promotional communications; and
- making a privacy complaint or grievance.
The availability and scope of these rights may differ depending on the applicable law, the nature of the information, the purpose of processing, and the relationship between IAFA and the individual.
38. ACCESS REQUESTS
An individual may contact IAFA to request information concerning personal information held by IAFA, subject to applicable law.
IAFA may require reasonable identity verification before providing information to prevent unauthorized disclosure.
Where an authorized representative submits a request, IAFA may request evidence of the representative’s authority.
39. CORRECTION AND UPDATING
Individuals may request correction or updating of inaccurate or incomplete information where applicable.
IAFA may take reasonable steps to verify the requested correction before updating information where appropriate.
40. DELETION REQUESTS
Individuals may request deletion of personal information where such right is available under applicable law.
IAFA may refuse or limit deletion where retention is:
- legally required;
- necessary for a transaction;
- necessary to establish or defend legal claims;
- required for tax or accounting purposes;
- required for regulatory purposes;
- necessary for security or fraud prevention; or
- otherwise legally permitted.
The standard three-year clinical retention policy will apply where no overriding retention requirement exists.
41. MARKETING AND COMMUNICATION PREFERENCES
IAFA may send service-related communications necessary for:
- consultations;
- appointments;
- orders;
- payments;
- shipping;
- customer support;
- security;
- account administration; or
- other requested services.
Promotional or marketing communications may be subject to applicable consent or opt-out mechanisms.
Individuals may request cessation of non-essential promotional communications through the available unsubscribed mechanism or by contacting IAFA.
Withdrawal from marketing communications does not necessarily stop essential service-related communications.
42. CONSENT AND PREFERENCE RECORDS
Where appropriate, IAFA may retain records concerning:
- consent;
- consent withdrawal;
- clinical-image consent;
- research consent;
- marketing preferences;
- privacy requests;
- opt-out requests; and
- communication preferences.
Such records may be retained for as long as reasonably necessary to administer the relevant preference, demonstrate the history of consent, protect IAFA’s legal interests, or comply with applicable requirements.
43. EMAIL, WHATSAPP, TELEPHONE AND OTHER COMMUNICATION CHANNELS
IAFA may communicate through:
- email;
- telephone;
- SMS;
- WhatsApp;
- video-conferencing platforms;
- online forms;
- messaging systems; and
- other communication technologies.
Third-party communication providers may have their own privacy and security practices.
Users should avoid sending unnecessary sensitive health information through unofficial or unsecured communication channels.
Where IAFA provides an official secure channel for clinical information, users should preferentially use that channel.
44. PUBLIC REVIEWS AND SOCIAL MEDIA
If an individual voluntarily publishes information about IAFA through:
- public reviews;
- social-media platforms;
- public comments;
- online forums; or
- other publicly accessible services,
that information may become publicly accessible.
IAFA will not assume that publicly posted information constitutes permission to access or disclose unrelated private clinical records or confidential health information.
45. THIRD-PARTY WEBSITES AND SERVICES
IAFA websites may contain links to:
- scientific databases;
- external websites;
- payment services;
- courier services;
- social-media platforms;
- communication platforms;
- external healthcare resources; and
- other third-party services.
This Privacy Policy does not control the independent privacy practices of third parties.
Users should review the applicable privacy policies and terms of third-party services before providing information to them.
46. BUSINESS, FRANCHISE, DISTRIBUTORSHIP AND PARTNER INQUIRIES
Individuals may contact IAFA regarding:
- franchise opportunities;
- distributorship;
- product distribution;
- third-party manufacturing;
- professional collaboration;
- research collaboration;
- educational programs;
- institutional partnerships;
- employment;
- professional opportunities; or
- other business activities.
IAFA may process information necessary to evaluate and respond to such inquiries.
This may include:
- name;
- professional information;
- business information;
- contact details;
- location;
- organization;
- qualifications;
- documents voluntarily submitted; and
- other relevant information.
47. NEWSLETTERS, SURVEYS, PROMOTIONS AND FEEDBACK
Where IAFA offers:
- newsletters;
- educational communications;
- surveys;
- feedback requests;
- promotional campaigns;
- educational programs; or
- similar activities,
IAFA may process the information reasonably necessary to administer those activities.
Optional promotional participation should not ordinarily be required as a condition of receiving an unrelated clinical service.
48. PRIVACY BY DESIGN AND ACCESS CONTROL
Where reasonably appropriate, IAFA seeks to incorporate privacy and security considerations into the design and operation of its systems.
Measures may include:
- data minimization;
- role-based access;
- separation of clinical and administrative access;
- restricted clinical-image access;
- secure authentication;
- access logging;
- limited third-party disclosure;
- retention controls;
- secure deletion procedures; and
- periodic review of security practices.
49. USER RESPONSIBILITY
Users are responsible for:
- providing reasonably accurate information;
- updating important information where necessary;
- providing information only through appropriate channels;
- protecting account credentials;
- not sharing passwords;
- not submitting another person’s information without authorization;
- reviewing product information before purchase or use;
- complying with applicable laws;
- informing healthcare professionals of relevant medical information; and
- using IAFA services responsibly.
50. PRIVACY OF INFORMATION PROVIDED BY OR ABOUT ANOTHER PERSON
If an individual provides IAFA with information concerning another person, including a child, family member, patient, employee, or other individual, the person providing the information represents that they are authorized to provide that information or are otherwise legally permitted to do so.
IAFA may rely upon such representation unless it has reasonable grounds to believe that the information was provided without appropriate authority.
51. LEGAL DISCLOSURES
IAFA may disclose personal information where reasonably necessary to:
- comply with applicable law;
- respond to a valid legal process;
- comply with a court or regulatory order;
- protect the safety of individuals;
- investigate fraud or misuse;
- protect IAFA’s systems;
- establish, exercise, or defend legal rights; or
- comply with another lawful requirement.
IAFA will seek to limit such disclosures to information that is reasonably necessary for the relevant purpose where practicable.
52. NO SALE OF IDENTIFIABLE PATIENT HEALTH INFORMATION
IAFA does not intend to sell identifiable patient health information as a commercial data product.
IAFA may, however, share information with authorized service providers, healthcare professionals, payment providers, logistics providers, technology providers, professional advisers, regulators, or other parties where such sharing is reasonably necessary, authorized, or legally required for the relevant purpose.
53. INTERNATIONAL JURISDICTION AND NO AUTOMATIC CLAIM
Accessing IAFA from outside India does not automatically mean that IAFA accepts:
- foreign professional licensing jurisdiction;
- foreign healthcare regulation;
- foreign court jurisdiction;
- foreign regulatory jurisdiction;
- foreign compensation claims;
- foreign consumer claims; or
- foreign liability
solely because the website or service was accessible from that country.
Any contractual dispute, service dispute, commercial dispute, liability issue, or compensation claim shall be subject to the applicable IAFA Terms & Conditions, service agreement, purchase terms, Indian governing-law provisions, and mandatory law applicable to the particular circumstances.
No provision of this Privacy Policy is intended to unlawfully exclude any mandatory legal right or remedy.
55. CHANGES TO THIS PRIVACY POLICY
IAFA may modify this Privacy Policy from time to time to reflect:
- changes in services;
- changes in technology;
- changes in data-processing practices;
- changes in security practices;
- changes in business operations;
- changes in applicable law; or
- regulatory developments.
Where applicable law requires additional notice or consent for a material change, IAFA will provide such notice or obtain such consent as required.
56. SEVERABILITY
If any provision of this Privacy Policy is found to be invalid, unlawful, or unenforceable, the remaining provisions shall continue to operate to the maximum extent permitted by applicable law.
The affected provision shall be interpreted or limited only to the extent necessary to make it enforceable where legally permissible.
57. GOVERNING LAW AND APPLICABLE REQUIREMENTS
This Privacy Policy is intended to operate subject to the laws and regulations applicable to IAFA and the relevant processing activity.
IAFA’s principal operations are based in India.
Nothing in this Privacy Policy constitutes a representation that every law of every jurisdiction applies to IAFA merely because IAFA’s websites or services are accessible internationally.
Where a mandatory law applies to a particular activity and cannot legally be excluded, IAFA will comply with that mandatory requirement to the extent legally required.
58. CONTACT AND PRIVACY REQUESTS
For privacy questions, requests concerning personal information, correction requests, deletion requests, consent withdrawal, or privacy complaints, contact:
IAFA Ayurveda India / Institute of Applied Food Allergy
Privacy Email: info@iafaforallergy.com
Privacy Contact: +91-96121-80000
Postal Address: #26 Sector-7 Gohana, Haryana, India Pin Code-131301
Website: www.iafaforallergy.com
Telephone: +91-96121-80000
When submitting a privacy request, IAFA may require sufficient information to verify the identity and authority of the requester.
59. IMPORTANT NOTICE REGARDING CLINICAL DATA
Individuals should provide only information that is reasonably necessary for the requested IAFA service.
Clinical photographs, medical reports, prescriptions, allergy information, and other health information should be submitted only through official IAFA channels.
Users should not submit unnecessary personal information belonging to another individual.
60. USER ACKNOWLEDGEMENT
By continuing to use an IAFA platform, the individual acknowledges that:
- they have read and understood this Privacy Policy;
- they understand that IAFA may process personal information for the purposes described herein;
- health and clinical information may require additional safeguards;
- clinical photographs and medical information may be processed for the relevant disclosed purpose;
- international access does not establish foreign professional licensure or authorization;
- IAFA does not represent that its services or products are approved or recognized in every country;
- international users are responsible for complying with applicable local requirements;
- information may be processed in India and through authorized service providers;
- the standard operational retention period for patient/clinical information is one year, subject to lawful exceptions;
- optional research, publication, testimonial, marketing, or similar secondary uses may require separate consent;
- third-party service providers may process information necessary for their respective functions; and
- this Privacy Policy should be read together with applicable IAFA Terms & Conditions, Disclaimer, Consent Forms, Product Terms, Shipping Policy, Cancellation/Refund Policy, and other service-specific terms.
61. FINAL PRIVACY STATEMENT
IAFA Ayurveda India / Institute of Applied Food Allergy is committed to handling personal, health, clinical, transaction, and technical information responsibly and with appropriate safeguards.
IAFA seeks to collect only information reasonably necessary for identified purposes, restrict unauthorized access, maintain appropriate security measures, avoid unnecessary retention, and delete or anonymize information when it is no longer required, subject to applicable legal and operational requirements.
IAFA’s standard operational retention period for patient/clinical information is three (3) years from the patient's last relevant clinical interaction, consultation, assessment, or follow-up.
International availability of IAFA’s websites or services does not constitute foreign licensure, regulatory approval, professional authorization, or automatic acceptance of foreign jurisdiction solely because the service is accessible online.
Nothing in this Privacy Policy is intended to unlawfully exclude mandatory rights, remedies, protections, or obligations that cannot legally be excluded.
or




















