Legal

Privacy policy

Last updated 1 October 2026

This policy explains what personal data Freaquer Corporation Private Limited (“TotalHeal”, “we”) processes when you use the TotalHeal apps, browser extension, website and account (the “Services”), why, and the choices and rights you have under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian law.

1. Who we are

Freaquer Corporation Private Limited, India, is the Data Fiduciary for the Services. Contact our privacy team at [email protected] and our Grievance Officer at [email protected].

2. Data we process

  • Account data: name, email address and identifiers from your TotalHeal ID; your plan, licence, product-key activations and invoices.
  • Device data: device name, platform, operating-system and app versions, a random install identifier, health score, which protections are enabled, definitions version, last scan and last-seen times.
  • Security events: for threats detected on your device — the file’s SHA-256 fingerprint, detection name, engine, action taken, time and, where needed to show you your history, the file path.
  • Web safety data: when a site is checked in the cloud, the address being checked; for sites we warned you about, the host name, verdict and rule. We do not collect your browsing history.
  • Files for cloud analysis (paid plans): a suspicious file up to 25 MB may be sent for analysis. Its contents are analysed and not stored; we keep the fingerprint and result.
  • Family data: if you create or join a family: member names, roles (parent, adult, child), invite emails and which devices belong to whom.
  • Support and communications: what you send us when you contact support.
  • Payment data: processed by our payment partner. We receive the payment status and an invoice reference — never your card number or UPI PIN.

3. Why we process it (purposes)

  • To provide protection: detecting and blocking malware, ransomware, phishing and scams, and updating definitions.
  • To run your account: sign-in, licences, devices, family sharing, billing and support.
  • To keep the Services secure and improve detection quality (for example, using file fingerprints to recognise new threats faster).
  • To meet legal obligations, such as tax invoicing and lawful requests.

We process personal data on the basis of your consent, given when you create an account or enable a feature, and for legitimate uses permitted under section 7 of the DPDP Act. You can withdraw consent at any time (see section 7); this does not affect processing already done.

4. What we never do

We do not sell or rent personal data, show advertising, build advertising profiles, or collect your browsing history, keystrokes, screen, camera, contacts or location.

5. Children

A parent may add a child as a profile in a family without the child having an account. We process a child’s data only with verifiable consent of the parent or lawful guardian, only for protection, and never for tracking, behavioural monitoring for advertising, or targeted advertising.

6. Where data is stored and how long we keep it

Account, licence and device data is stored on servers in India. Update files are delivered through a global content-delivery network and contain no personal data. We keep data only as long as needed:

  • Account and licence data: while your account is active, then deleted within 90 days of account deletion, except invoices kept as required by tax law (currently 8 years).
  • Device data and security events: up to 12 months, or until you remove the device.
  • Support messages: up to 24 months.

7. Your rights

Under the DPDP Act you may: access a summary of your personal data and processing; correct, complete or update it; ask us to erase it; withdraw consent; nominate another person to exercise your rights in case of death or incapacity; and have your grievance redressed. Many of these are available in your account settings; otherwise email [email protected]. We respond within the time required by law. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

8. Security

We protect data with encryption in transit (TLS), access controls, signed software updates and audited access to sensitive actions. No system is perfectly secure; we will notify you and the Data Protection Board of a personal-data breach as the law requires.

9. Processors

We use carefully selected processors for hosting, content delivery, email and payments, under contracts that require them to protect your data and use it only on our instructions.

10. Changes

We will tell you about material changes in the app or by email before they take effect.

11. Grievance Officer

Grievance Officer, Freaquer Corporation Private Limited — [email protected]. We acknowledge grievances within 24 hours and resolve them within 15 days.