Privacy Policy

Last Updated: April 6, 2026

1. Introduction

Kosha Connect (“we,” “our,” or “us”) is committed to protecting the privacy and security of personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our SaaS platform for Ayurvedic practice management.

Kosha Connect operates in compliance with:

  • United Kingdom: UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial health privacy legislation

2. Data Controller Information

United Kingdom

Kosha Connect Holistic Ltd
Data Protection Officer: privacy@koshaconnect.app

Canada

Kosha Connect Inc.
Privacy Officer: privacy@koshaconnect.app

3. Information We Collect

3.1 Account Information

  • Practice name and business details
  • Practitioner names and professional credentials
  • Contact information (email, phone, address)
  • Billing and payment information

3.2 Client Data (Processed on Behalf of Practitioners)

As a data processor, we process the following categories of data that practitioners (“Data Controllers”) input into our platform:

  • Client names and contact details
  • Appointment history and scheduling information
  • Health and wellness assessments
  • Therapy plans and treatment notes
  • Ayurvedic constitution (Prakriti) assessments
  • Medical history and health conditions
  • Communication records

3.3 Technical Data

  • IP addresses and device information
  • Browser type and settings
  • Usage data and analytics
  • Cookies and similar technologies

4. Special Category Data (Sensitive Personal Data)

Kosha Connect processes health-related data, which constitutes special category data under UK GDPR and sensitive personal information under PIPEDA. This includes:

  • Health conditions and symptoms
  • Treatment plans and therapy notes
  • Dietary and lifestyle information related to health
  • Wellness assessments and progress notes

Legal Basis for Processing (UK)

  • Explicit consent from data subjects
  • Necessary for the provision of health or social care services
  • Necessary for reasons of substantial public interest

Consent Requirements (Canada)

  • Express consent obtained by the practitioner before data entry
  • Consent is informed, voluntary, and specific to the purposes identified

5. How We Use Information

We use collected information to:

  • Provide, maintain, and improve the Kosha Connect platform
  • Process appointments and manage scheduling
  • Store and secure therapy plans and client records
  • Send service-related communications and notifications
  • Process payments and manage subscriptions
  • Provide customer support
  • Ensure platform security and prevent fraud
  • Comply with legal obligations

6. Data Sharing and Disclosure

We may share information with:

RecipientPurposeSafeguards
Cloud infrastructure providersData hosting and storageData Processing Agreements, encryption
Payment processorsSubscription billingPCI-DSS compliance
Email service providersTransactional communicationsData Processing Agreements
Professional advisorsLegal, accounting servicesConfidentiality agreements
Law enforcementWhen legally requiredValid legal process only

We do NOT:

  • Sell personal data to third parties
  • Use client health data for marketing purposes
  • Share data with third parties for their own purposes

7. International Data Transfers

From the UK

Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place, including:

  • UK International Data Transfer Agreement (IDTA)
  • Standard Contractual Clauses (SCCs)
  • Transfers to countries with adequacy decisions

From Canada

Cross-border transfers comply with PIPEDA requirements, ensuring comparable levels of protection through contractual arrangements.

8. Data Retention

Data TypeRetention PeriodBasis
Active client recordsDuration of practitioner subscription + 7 yearsProfessional regulatory requirements
Inactive client records7 years from last appointmentHealthcare record-keeping standards
Account informationDuration of subscription + 2 yearsBusiness records
Payment records7 yearsTax and accounting requirements
Technical logs12 monthsSecurity purposes

Practitioners may request earlier deletion of specific client records, subject to their own professional obligations.

9. Data Security

We implement robust technical and organisational measures, including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication
  • Regular security audits and penetration testing
  • Role-based access controls
  • Automated backup and disaster recovery
  • Employee security training and confidentiality agreements
  • Incident response procedures

10. Your Rights

UK Data Subjects (UK GDPR)

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion (“right to be forgotten”)
  • Restriction: Limit how we use your data
  • Portability: Receive data in a portable format
  • Objection: Object to certain processing activities
  • Withdraw Consent: Where processing is based on consent
  • Complaint: Lodge a complaint with the Information Commissioner's Office (ICO)

Canadian Data Subjects (PIPEDA)

  • Access: Request access to your personal information
  • Correction: Request correction of inaccurate information
  • Withdraw Consent: Subject to legal or contractual restrictions
  • Complaint: File a complaint with the Office of the Privacy Commissioner of Canada

To Exercise Your Rights: Contact us at privacy@koshaconnect.com with proof of identity.

11. Practitioner Responsibilities

Practitioners using Kosha Connect as Data Controllers are responsible for:

  • Obtaining appropriate consent from clients before entering their data
  • Informing clients about data processing through their own privacy notices
  • Responding to client data subject requests
  • Ensuring accuracy of data entered into the platform
  • Complying with professional regulatory requirements
  • Notifying us of any data breaches involving their client data

12. Cookies and Tracking

We use essential cookies for platform functionality and optional analytics cookies with consent. See our Cookie Policy for details.

13. Children's Privacy

Kosha Connect is not intended for individuals under 18. Practitioners must not input data of minors without appropriate parental/guardian consent and in compliance with applicable laws.

14. Changes to This Policy

We will notify users of material changes via email or platform notification at least 30 days before changes take effect. Continued use constitutes acceptance of updated terms.

15. Use of Google User Data (Google Calendar Integration)

Kosha Connect offers optional integration with Google Calendar to support appointment scheduling and calendar management within the application. Where you choose to connect your Google account, Kosha Connect will access and process your Google Calendar data via Google's authorised APIs.

Purpose of Processing

Kosha Connect processes Google Calendar data strictly for the following purposes:

  • To display your calendar events within the application
  • To create new calendar events on your behalf when appointments are scheduled through Kosha Connect
  • To amend or update existing calendar events where changes are made within the application

This processing is limited to what is necessary to deliver the requested functionality.

Lawful Basis

Processing of your Google Calendar data is carried out on the basis of your consent, which is provided when you authorise Kosha Connect to access your Google account. You may withdraw your consent at any time (see below).

Data Minimisation and Use Limitations

Kosha Connect:

  • Accesses only the minimum necessary calendar data required to provide its services
  • Uses such data solely for the purposes described above
  • Does not use Google user data for advertising or marketing purposes
  • Does not sell, rent, or otherwise disclose Google user data to third parties, except where required to provide the service or comply with legal obligations

Data Storage and Security

Kosha Connect does not store your Google Calendar data. All calendar events and related information remain stored on Google's servers and are accessed in real-time via Google's APIs when you use the integration.

The only Google-related information stored by Kosha Connect is:

  • Your consent to connect your Google account
  • Your Google account email address
  • An access token required to authenticate with Google Calendar on your behalf

This limited information is:

  • Protected using appropriate technical and organisational measures to ensure a level of security appropriate to the risk
  • Safeguarded against unauthorised or unlawful access, accidental loss, destruction, or damage
  • Retained only for as long as you maintain your Google account connection with Kosha Connect

User Control and Withdrawal of Consent

You retain full control over your Google account connection. You may revoke Kosha Connect's access at any time via your Google account permissions settings. Upon revocation, Kosha Connect will cease accessing your Google Calendar data.

Compliance with Google Policies

Kosha Connect's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

16. Contact Us

United Kingdom

Kosha Connect Holistic Ltd
Email: connect@koshaconnect.app
Exempted from ICO Registration. Kosha Connect is a Data Processor for the Practitioners.

Canada

Kosha Connect Inc.
Email: connect@koshaconnect.app