Legal
Privacy notice
What personal data this website and the PlanRhythm product collect, why we hold it, where it is stored, who else can see it, and what you can ask us to do about it.
Last updated 10 August 2026.
What this notice covers, and what it does not
This is our notice for two things: this website, planrhythm.com, and the PlanRhythm product a practice uses with its clients.
One line does most of the work, and every privacy law we work under starts from it. For a practice's own account data we decide what is collected and why, so we are the controller — the Data Fiduciary, in the words of India's DPDP Act. For the client health data a practice puts in, the practice is the controller and we are its processor, holding that data on its instructions and for no purpose of our own.
It is not the notice your dietitian owes you. If you are a client of a practice that uses PlanRhythm, that practice decides what to record about you and why. It stays responsible for its own privacy notice, its own consent and its own retention choices. We hold that data for it and act on its instructions.
This is a plain-language summary of how we handle personal data. It is written to be understood rather than to be exhaustive, and it is not legal advice. If you run a practice, take your own advice on what your own notice and consent must say.
1. Who we are
PlanRhythm is practice software for dietitians and nutritionists. It is built and operated from India, and offered primarily to practices in the United States, Canada, the Gulf, Europe including the UK, and Australia and New Zealand, with India also supported. In this notice, "we" and "us" mean PlanRhythm. You can reach us at [email protected].
We have written this notice to meet the regimes our practices work under: the GDPR and the UK GDPR, India's Digital Personal Data Protection Act, 2023, the PDPL in the UAE and in Saudi Arabia, Canada's PIPEDA, the Australian Privacy Principles, and US state privacy laws. Where one of them gives you something the others do not, we say which one.
The vocabulary changes between them; the idea does not. Controller, Data Fiduciary, business — the party that decides what is collected and why. Processor, Data Processor, service provider — the party that holds it and acts on instructions. For your account data we are the first. For your clients' health data we are the second. Section 2 explains why that line matters more than anything else on this page.
2. The distinction that matters
Practice account data — we decide, so we are responsible
When you sign up, we collect what we need to run your account and bill you. We chose those fields, we decide how long to keep them, and you can hold us to account for them directly. In GDPR terms we are the controller of that data; under the DPDP Act, its Data Fiduciary.
Client health data — the practice decides, we only hold it
When a dietitian records her client's intake answers, weight, meal plan, check-ins, photographs and consultation notes, that record belongs to the practice. The practice decides what goes in it and why. We store and process it on her instructions and for no purpose of our own. We do not sell it, do not show it to other practices, and do not use it to train machine-learning models.
In GDPR terms the practice is the controller and we are its processor. Our instructions come from the practice, through the agreement it signs with us, and we do not go outside them.
If you are a client and want your record corrected or deleted, ask your dietitian first — the record is hers to change. If she asks us to act on it, we act.
3. What we collect
From this website
Nothing until you type it. There is no analytics on this site, no advertising pixel, no heatmap, no social widget. If you send an enquiry — through the site, by email or on WhatsApp — we receive your name, your practice name, your email address, your phone number and whatever you write. We use it to reply and to arrange a demo, and for nothing else.
The fonts used on these pages are self-hosted on planrhythm.com. Loading the site does not contact Google Fonts, an analytics provider, an advertising network or a social widget. The WhatsApp link is only a link; your browser contacts WhatsApp only if you choose to open it.
From a practice
- Practice name, practitioner names, email addresses and phone numbers.
- Your tax registration number — a VAT number or the local equivalent — if you give it to us for invoicing.
- Your client counts for the month, invoices and payment records.
- Sign-in records and an audit trail of who changed what, and when.
About a client, on behalf of the practice
- Intake questionnaire answers, including health conditions, medication, allergies and dietary restrictions, and any answers flagged for the practitioner's review queue.
- Meal plans and every published version of them.
- Daily check-in entries — followed the plan, adapted it, ate something different, couldn't do it, skipped — and days with nothing recorded at all.
- Photos, voice notes and free text a client chooses to send.
- Water, sleep, stress and Bristol entries, when she logs them.
- Weight and measurements, when they are recorded.
- Messages and attachments between practitioner and client.
- Consultation notes written by the practitioner, with their lock and revision trail.
- The phone number or email address a one-time sign-in code is sent to, and a record of sign-ins.
- Technical records needed to sync a device that was offline and has come back online.
4. Diet, religion and explicit consent
Some diets say something about faith. A Jain or Swaminarayan diet, a halal or kosher requirement, or a fast a client keeps through Ramadan, Lent, Navratri or Ekadashi can reveal a religious belief. Under the GDPR and the UK GDPR that makes it special category data under Article 9; the DPDP Act and the PDPL treat it as sensitive too. We treat it that way rather than as one more dropdown value.
It is recorded only with the client's explicit consent, and only because it changes what a safe plan looks like — a plan that ignores it is not a plan she can follow.
Health information is treated the same way. Consent is recorded in the app with the date and the version of the wording shown, and it can be withdrawn at any time. Withdrawing consent stops further use of that information; it does not erase plans that were already published, though the practice can delete those too.
5. Why we process it
- To give a practice the product it is paying for: building plans, publishing a day at a time, check-ins, messaging, notes, charts and payments.
- To deliver one-time sign-in codes and notifications to a client's phone or email.
- To take your subscription payment and issue an invoice.
- To answer support requests and fix faults.
- To keep the audit trail and the security records that make an account checkable later.
- To meet legal obligations that apply to us, such as keeping tax and accounting records in India, where we are established.
Things we do not do with it: advertising, profiling for advertising, selling, sharing with another practice, or training machine-learning models on client health data.
And one that is a product law before it is a privacy one: we do not compute an adherence score, a grade, a streak or a red-and-green judgement of any client. A day with nothing recorded is treated as not recorded, never as failure.
6. Our lawful basis
Where we are the controller — practice account data — we rely on the contract with your practice to run the account, on legal obligation for tax and accounting records, on consent for enquiries and for any email you ask to receive, and on legitimate interests for security and audit records. Under the DPDP Act the same processing rests on consent or on the legitimate uses the Act allows.
Where we are the processor — client health data — the lawful basis is your practice's to establish, not ours. A client consents in the app, to her practice, and we keep the record of it. The diet and health information in section 4 is recorded on explicit consent.
Where the law obliges us to keep something — a tax invoice, for instance — we keep it on that basis rather than on consent, and withdrawing consent does not remove it.
7. Where the data is stored
PlanRhythm runs on Microsoft Azure. Your practice's data lives in the Azure region for your market, chosen when your account is set up: Central India, UAE North, West Europe, East US, Canada Central or Australia East. It is encrypted in transit and at rest, and it does not move between regions. Backups stay in the same region as the data they protect.
So for most practices there is no cross-border transfer of client records to weigh before signing. A practice in Germany has its clients' data in West Europe. A practice in Dubai has it in UAE North. It stays there, and if we ever needed to move a practice to a different region we would ask first.
What does cross a border is narrower, and worth saying plainly rather than burying. We are established in India and we support the product from India, so a member of our team acting on a support request can reach data held in your region. India has no adequacy decision from the European Commission or from the UK government, so that access rests on contract rather than on adequacy. Our own billing and accounting records — practice account data, not client health data — are kept in India because Indian tax law requires it.
The safeguard is contractual. The agreement your practice signs binds us to process only on your instructions, to the measures in section 12, and to hold anyone we use to the same duties. Standard contractual clauses, with the UK addendum, are being put in place as our data processing agreement — they are not signed yet. Ask for the current version before you sign and we will send you what exists rather than what we intend.
Some of the providers in section 9 operate from other countries. Where they do, the same contractual duties apply to them.
If the storage position changes, we will say so on this page and tell affected practices before it happens, not after.
8. How long we keep it
- While the account is open: for as long as the practice keeps it, because the record is the point of the product.
- After a practice closes its account: 60 days so the data can be exported, then deletion within a further 30 days.
- When a practice deletes a client's record: it goes from the live system straight away. Backups are overwritten on a rolling cycle, so a copy can survive in a backup for a short period before it is gone for good.
- Invoices and tax records: as long as the tax law that applies to us requires us to keep them. That is Indian tax law today.
- Audit records: for the life of the account. Their whole purpose is to be checkable later.
9. Who else sees it
A short list, and it stays short.
- Microsoft Azure, which provides the servers and storage the data sits on, in the region named in section 7.
- A payment processor, for collecting our own subscription fees. It gets what it needs to take the payment. It does not get client health data.
- A messaging provider, to deliver one-time sign-in codes and notifications by SMS, WhatsApp or email. It gets the phone number or email address and the message itself.
- Authorities or professional advisers, where the law requires it. We will tell the practice unless we are legally barred from doing so.
A current list of these providers, and the country each one operates from, is available on request before you sign. Ask for it.
We do not sell personal data. Not to advertisers, not to data brokers, not to pharmaceutical or supplement companies, not to anyone. There is no version of PlanRhythm in which that becomes a line of revenue.
10. Your rights
Which rights you hold depends on where you are, and the overlap is much larger than the difference. You can ask us for:
- Access — a summary of the personal data we hold about you and what we do with it.
- Correction and completion — anything wrong, out of date or missing.
- Erasure — deletion, unless the law requires us to keep it.
- Portability — your data in a format you can open and take elsewhere. Ask us and we will produce it; there is no self-service export in the product yet.
- Objection and restriction — to processing we base on legitimate interests, and to direct marketing at any time. We do no profiling and make no automated decisions about anyone.
- Withdrawal of consent — as easily as you gave it.
- Nomination — naming someone to exercise these rights if you die or cannot act for yourself.
- Grievance redressal — a complaint to us, answered by a named office, before you go anywhere else.
Three places where the regimes genuinely differ. Portability, objection and restriction come from the GDPR, the UK GDPR and PIPEDA, and the DPDP Act does not grant them — we honour them for everyone anyway, because two behaviours is how a mistake gets made. Nomination is a DPDP right the others do not have. US state laws add a right not to be treated worse for exercising any of this, and a right to opt out of the sale or sharing of your data — we sell and share nothing, so there is nothing there to opt out of.
If you are a practice, write to us and we will act. If you are a client of a practice, start with your dietitian: her record, her decision. Write to us as well if she does not respond, and we will help her act on it.
You can also complain to a regulator, and you do not need our agreement to do it: the Data Protection Board of India, your supervisory authority in the EU or the Information Commissioner's Office in the UK, the UAE Data Office or SDAIA in Saudi Arabia, the Office of the Privacy Commissioner of Canada, the OAIC in Australia, or your state Attorney General in the United States.
We aim to answer any request within 30 days, and to tell you if it will take longer and why. Where a regime gives us a month, we do not use the extra days.
11. Cookies
This website sets no cookies. None for analytics, none for advertising, none at all. Two scripts run here: one opens the mobile menu, handles the contact form and stamps the year in the footer; the other runs the calculator on the pricing page. Neither stores anything on your device — no cookie, no local storage, nothing. The calculator works entirely in your browser: the client numbers you type stay on the page, are not sent to us or to anyone else, and are gone when you close the tab. So there is no cookie banner here, because there is nothing to ask you about.
The product is different, and only in the way it has to be. When you sign in, it stores a session token so you stay signed in, and a client's app keeps her plan and her recent entries on her own device so it works on a train, in a basement or on one bar of signal, and syncs when the network returns. That is what makes offline work; it is not tracking, and it cannot be switched off without breaking sign-in.
12. How we protect it
- Data is encrypted in transit and at rest, in the Azure region named in section 7.
- Access is by role. An owner sees the practice; staff see only the clients assigned to them.
- Consultation notes carry a lock and a revision trail, so an old note still says what it said and an amendment is visible as an amendment.
- An audit trail records who read or changed what.
- Clients sign in with a one-time code rather than a password, so there is no password to reuse, leak or forget.
No system is perfectly secure and we will not claim otherwise.
If a breach occurs, we will tell the practices affected without undue delay. That is not a courtesy: a practice is the controller of its clients' data and has its own reporting clock to meet — 72 hours under the GDPR — and it cannot meet it if we are slow. We will notify the Data Protection Board of India, and any other regulator or affected person the law requires, and we will tell you what we know and when we knew it.
13. Children
PlanRhythm is intended for use with adult clients, and we do not offer a paediatric consent flow today. The age at which a young person can consent for herself differs: the DPDP Act sets it at 18 and requires verifiable consent from a parent or lawful guardian below that; the GDPR sets it between 13 and 16 depending on the country; in the United States, COPPA applies below 13. If a practice works with anyone under the age that applies to it, obtaining and recording that consent is the practice's responsibility. No regime permits tracking, profiling or targeted advertising directed at a child, and nothing in PlanRhythm profiles or advertises to anyone, of any age.
14. Changes to this notice
When this notice changes we update the date at the top of the page. If a change materially affects what we do with personal data, we will tell the practices using PlanRhythm directly rather than relying on you to re-read the page.
15. How to reach us, wherever you are
Every question about data, and every complaint, reaches a person. Different regimes expect different routes, so there are two — and both are read by the same people. You do not need a particular form of words.
Privacy contact, PlanRhythm
For anyone, anywhere: a question, a request about your data, or a complaint.
Email [email protected]
General enquiries [email protected]
Message us on WhatsApp (+1 786 957 8651)
We reply within one working day, in your timezone. Tell us what you want done and we will tell you what we can do and by when.
Grievance Officer, PlanRhythm
The route the DPDP Act requires for a Data Principal in India. It reaches the same inbox.
Email [email protected]
Raise it with us first. If we do not resolve it, you can take it to the Data Protection Board of India.
Last updated 10 August 2026.
Something here unclear?
Ask. If a line in this notice does not answer your question, that is a fault in the notice and we would like to fix it.