Privacy Policy
Last Updated: April 6, 2026
1. Introduction
Kosha Connect (“we,” “our,” or “us”) is committed to protecting the privacy and security of personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our SaaS platform for Ayurvedic practice management.
Kosha Connect operates in compliance with:
- United Kingdom: UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
- Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial health privacy legislation
2. Data Controller Information
United Kingdom
Kosha Connect Holistic Ltd
Data Protection Officer: privacy@koshaconnect.app
Canada
Kosha Connect Inc.
Privacy Officer: privacy@koshaconnect.app
3. Information We Collect
3.1 Account Information
- Practice name and business details
- Practitioner names and professional credentials
- Contact information (email, phone, address)
- Billing and payment information
3.2 Client Data (Processed on Behalf of Practitioners)
As a data processor, we process the following categories of data that practitioners (“Data Controllers”) input into our platform:
- Client names and contact details
- Appointment history and scheduling information
- Health and wellness assessments
- Therapy plans and treatment notes
- Ayurvedic constitution (Prakriti) assessments
- Medical history and health conditions
- Communication records
3.3 Technical Data
- IP addresses and device information
- Browser type and settings
- Usage data and analytics
- Cookies and similar technologies
4. Special Category Data (Sensitive Personal Data)
Kosha Connect processes health-related data, which constitutes special category data under UK GDPR and sensitive personal information under PIPEDA. This includes:
- Health conditions and symptoms
- Treatment plans and therapy notes
- Dietary and lifestyle information related to health
- Wellness assessments and progress notes
Legal Basis for Processing (UK)
- Explicit consent from data subjects
- Necessary for the provision of health or social care services
- Necessary for reasons of substantial public interest
Consent Requirements (Canada)
- Express consent obtained by the practitioner before data entry
- Consent is informed, voluntary, and specific to the purposes identified
5. How We Use Information
We use collected information to:
- Provide, maintain, and improve the Kosha Connect platform
- Process appointments and manage scheduling
- Store and secure therapy plans and client records
- Send service-related communications and notifications
- Process payments and manage subscriptions
- Provide customer support
- Ensure platform security and prevent fraud
- Comply with legal obligations
6. Data Sharing and Disclosure
We may share information with:
| Recipient | Purpose | Safeguards |
|---|---|---|
| Cloud infrastructure providers | Data hosting and storage | Data Processing Agreements, encryption |
| Payment processors | Subscription billing | PCI-DSS compliance |
| Email service providers | Transactional communications | Data Processing Agreements |
| Professional advisors | Legal, accounting services | Confidentiality agreements |
| Law enforcement | When legally required | Valid legal process only |
We do NOT:
- Sell personal data to third parties
- Use client health data for marketing purposes
- Share data with third parties for their own purposes
7. International Data Transfers
From the UK
Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, including:
- UK International Data Transfer Agreement (IDTA)
- Standard Contractual Clauses (SCCs)
- Transfers to countries with adequacy decisions
From Canada
Cross-border transfers comply with PIPEDA requirements, ensuring comparable levels of protection through contractual arrangements.
8. Data Retention
| Data Type | Retention Period | Basis |
|---|---|---|
| Active client records | Duration of practitioner subscription + 7 years | Professional regulatory requirements |
| Inactive client records | 7 years from last appointment | Healthcare record-keeping standards |
| Account information | Duration of subscription + 2 years | Business records |
| Payment records | 7 years | Tax and accounting requirements |
| Technical logs | 12 months | Security purposes |
Practitioners may request earlier deletion of specific client records, subject to their own professional obligations.
9. Data Security
We implement robust technical and organisational measures, including:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Multi-factor authentication
- Regular security audits and penetration testing
- Role-based access controls
- Automated backup and disaster recovery
- Employee security training and confidentiality agreements
- Incident response procedures
10. Your Rights
UK Data Subjects (UK GDPR)
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion (“right to be forgotten”)
- Restriction: Limit how we use your data
- Portability: Receive data in a portable format
- Objection: Object to certain processing activities
- Withdraw Consent: Where processing is based on consent
- Complaint: Lodge a complaint with the Information Commissioner's Office (ICO)
Canadian Data Subjects (PIPEDA)
- Access: Request access to your personal information
- Correction: Request correction of inaccurate information
- Withdraw Consent: Subject to legal or contractual restrictions
- Complaint: File a complaint with the Office of the Privacy Commissioner of Canada
To Exercise Your Rights: Contact us at privacy@koshaconnect.com with proof of identity.
11. Practitioner Responsibilities
Practitioners using Kosha Connect as Data Controllers are responsible for:
- Obtaining appropriate consent from clients before entering their data
- Informing clients about data processing through their own privacy notices
- Responding to client data subject requests
- Ensuring accuracy of data entered into the platform
- Complying with professional regulatory requirements
- Notifying us of any data breaches involving their client data
12. Cookies and Tracking
We use essential cookies for platform functionality and optional analytics cookies with consent. See our Cookie Policy for details.
13. Children's Privacy
Kosha Connect is not intended for individuals under 18. Practitioners must not input data of minors without appropriate parental/guardian consent and in compliance with applicable laws.
14. Changes to This Policy
We will notify users of material changes via email or platform notification at least 30 days before changes take effect. Continued use constitutes acceptance of updated terms.
15. Use of Google User Data (Google Calendar Integration)
Kosha Connect offers optional integration with Google Calendar to support appointment scheduling and calendar management within the application. Where you choose to connect your Google account, Kosha Connect will access and process your Google Calendar data via Google's authorised APIs.
Purpose of Processing
Kosha Connect processes Google Calendar data strictly for the following purposes:
- To display your calendar events within the application
- To create new calendar events on your behalf when appointments are scheduled through Kosha Connect
- To amend or update existing calendar events where changes are made within the application
This processing is limited to what is necessary to deliver the requested functionality.
Lawful Basis
Processing of your Google Calendar data is carried out on the basis of your consent, which is provided when you authorise Kosha Connect to access your Google account. You may withdraw your consent at any time (see below).
Data Minimisation and Use Limitations
Kosha Connect:
- Accesses only the minimum necessary calendar data required to provide its services
- Uses such data solely for the purposes described above
- Does not use Google user data for advertising or marketing purposes
- Does not sell, rent, or otherwise disclose Google user data to third parties, except where required to provide the service or comply with legal obligations
Data Storage and Security
Kosha Connect does not store your Google Calendar data. All calendar events and related information remain stored on Google's servers and are accessed in real-time via Google's APIs when you use the integration.
The only Google-related information stored by Kosha Connect is:
- Your consent to connect your Google account
- Your Google account email address
- An access token required to authenticate with Google Calendar on your behalf
This limited information is:
- Protected using appropriate technical and organisational measures to ensure a level of security appropriate to the risk
- Safeguarded against unauthorised or unlawful access, accidental loss, destruction, or damage
- Retained only for as long as you maintain your Google account connection with Kosha Connect
User Control and Withdrawal of Consent
You retain full control over your Google account connection. You may revoke Kosha Connect's access at any time via your Google account permissions settings. Upon revocation, Kosha Connect will cease accessing your Google Calendar data.
Compliance with Google Policies
Kosha Connect's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
16. Contact Us
United Kingdom
Kosha Connect Holistic Ltd
Email: connect@koshaconnect.app
Exempted from ICO Registration. Kosha Connect is a Data Processor for the Practitioners.
Canada
Kosha Connect Inc.
Email: connect@koshaconnect.app