21MinFit · Lifespan Twenty One LLP

Terms & Conditions and Privacy Policy

This page explains the rules for using 21minfit.com and our training services, and how we collect, use, and protect your personal data in line with India's Digital Personal Data Protection Act, 2023 (DPDPA).

Last updated: 14 August 2026

Plain-language summary (not a substitute for the full text below)

Part A — Terms & Conditions

These Terms & Conditions govern your use of the 21minfit.com website and any online fitness plan, personal training, or related service booked through it ("Services"). By using this website or booking a Service, you agree to these terms.

A.1 Who we are

Lifespan Twenty One LLP ("21MinFit", "we", "us", "our"), based in Bengaluru, Karnataka, India, operates the website 21minfit.com and the 21MinFit fitness coaching business led by Ranjith Vasu.

A.2 Our services

We offer online fitness plans (1, 3, and 6-month formats) and personal training, covering metabolic conditioning, calisthenics, hatha yoga, meditation & breathwork, strength & conditioning, and holistic fitness coaching. Package names, durations, and prices are as displayed on the site at the time of booking and may change without affecting a booking already confirmed.

A.3 Eligibility & health disclaimer

  • Our Services are intended for individuals aged 18 or older. If you are under 18, a parent or legal guardian must make the booking and provide consent on your behalf.
  • You confirm that the health, fitness, and medical information you share with us (including any injury history or medical conditions) is accurate and complete. Withholding or misrepresenting this information can affect the safety of your training.
  • Our Services are general fitness coaching and education — they are not medical advice, diagnosis, or treatment. If you have a pre-existing medical condition, are pregnant, or are unsure whether an activity is safe for you, please consult a qualified physician before starting or continuing any program.
  • Physical exercise carries an inherent risk of injury. By booking a Service, you acknowledge this risk and agree to inform your trainer immediately of any pain, discomfort, or medical concern during a session.

A.4 Booking & payment

  • Bookings are made through the "Book a Spot" flow on the site and are confirmed once payment is completed.
  • All payments are processed by our third-party payment gateway partner. 21MinFit does not collect, see, or store your card, UPI, or bank account details — these are handled entirely within the payment gateway's own secure, RBI-regulated systems.
  • Prices are listed in Indian Rupees (INR) and are inclusive of applicable taxes unless stated otherwise.
  • Cancellations & refunds: You may request a cancellation or refund of a package within 7 days from the date of payment, by emailing ranjith@21minfit.com with your booking details. Requests made after this 7-day window are not eligible for a refund, except at our discretion.
  • Once a refund request is approved, the amount is refunded through Razorpay to your original payment method, and typically reflects in your bank account, card, or UPI app within 7 business working days of approval — the exact timing beyond that point depends on your bank's or card network's own processing times, which is outside our control.

A.5 Intellectual property

All content on this site — including the 21MinFit name and logo, text, photos, videos, and program materials — belongs to Lifespan Twenty One LLP or its licensors and may not be copied, reproduced, or used commercially without our written permission.

A.6 Acceptable use

You agree to provide accurate information when contacting us or booking a Service, and not to use the site for any fraudulent, abusive, or unlawful purpose, or to attempt to disrupt, scrape, or gain unauthorised access to the site.

A.7 Third-party services

Our site relies on trusted third-party providers to operate — including our website host, our contact-form provider, our payment gateway, and (where embedded) Instagram for showing training reels. Your use of those embedded features is also subject to that provider's own terms and privacy practices.

A.8 Limitation of liability

To the fullest extent permitted by Indian law, Lifespan Twenty One LLP is not liable for any indirect, incidental, or consequential loss arising from your use of the site or participation in our Services, except where such loss results from our gross negligence, wilful default, or a violation of applicable law.

A.9 Governing law & jurisdiction

These Terms are governed by the laws of India. Any dispute arising from these Terms or our Services will be subject to the exclusive jurisdiction of the courts in Bengaluru, Karnataka.

A.10 Changes to these Terms

We may update these Terms from time to time to reflect changes in our Services or the law. The "Last updated" date at the top of this page will always reflect the most recent version. Continued use of the site after an update means you accept the revised Terms.

Part B — Privacy Policy

This Privacy Policy explains how Lifespan Twenty One LLP, operating as 21MinFit ("we", "us", the Data Fiduciary under the DPDPA), collects, uses, shares, and protects your personal data when you visit 21minfit.com, use our contact form, or book a Service. It is written to meet the notice requirements of Section 5 of the Digital Personal Data Protection Act, 2023 and Rule 3 of the Digital Personal Data Protection Rules, 2025.

B.1 Personal data we collect

CategoryWhat we collectWhen
Contact details Name, email address, phone number, and the content of your message When you submit the "Get in touch" form
Booking & payment status Package selected, booking date, and payment confirmation status (not your card/UPI/bank details — those stay with our payment gateway) When you book and pay for a Service
Health & fitness information Details you choose to share for your training — e.g. injury history, medical conditions, fitness goals, physical assessments During onboarding, consultation, or ongoing coaching (in person, by phone, or on WhatsApp)
Technical data Standard web server/security logs kept by our hosting provider (e.g. IP address, browser type, access times) Automatically, whenever you visit the site

We currently do not run advertising trackers or third-party analytics on the site. If that changes in future (e.g. adding Google Analytics), we will update this Policy and, where required, ask for your consent first.

B.2 Why we process your data, and on what basis

  • To respond to you — when you fill the contact form, based on your specific, informed consent given by submitting the form (Section 6, DPDPA).
  • To deliver a booked Service — to plan and run your fitness program, based on your consent and because it's necessary to fulfil the service you requested (Section 7(a), "certain legitimate uses").
  • To process payments — passed to our payment gateway solely to complete your transaction.
  • To personalise your training — health/fitness information is used only to design and safely deliver your program, and only with your consent.
  • To meet legal obligations — e.g. retaining transaction records for tax and accounting law.

We only process the personal data that is necessary for these specified purposes, and only for as long as those purposes remain active (see B.5).

B.3 Your consent

Where our processing relies on your consent, that consent is free, specific, informed, unconditional, and given through a clear affirmative action (for example, ticking the consent box on our contact form) — exactly as required by Section 6 of the DPDPA. You can withdraw your consent at any time, as easily as you gave it, by emailing ranjith@21minfit.com. Withdrawing consent won't affect the legality of anything we processed before the withdrawal, and won't affect a Service you've already paid for and received.

B.4 Who we share your data with

We do not sell your personal data. We share it only with the service providers who help us run 21MinFit, strictly for the purpose of delivering our Services:

  • Website hosting & form handling (Netlify) — stores form submissions and may process data on infrastructure located outside India.
  • Payment gateway (Razorpay) — an RBI-regulated, PCI-DSS compliant processor that handles your payment and any refund directly; we only receive confirmation that payment succeeded or a refund was issued.
  • WhatsApp Business, where you choose to message us there for coaching or scheduling.
  • Legal or regulatory authorities, only where required by Indian law.

Because our hosting provider operates global infrastructure, some data may be processed on servers outside India. As of this Policy's last update, the Central Government has not restricted such transfers under Section 16 of the DPDPA; if that changes, we will update this Policy accordingly.

B.5 How long we keep your data

We keep personal data only for as long as necessary for the purpose it was collected, or as required by law (for example, financial/transaction records are typically retained for the period required under Indian tax law). Once a purpose is no longer being served and you haven't approached us again about it, we erase the data, in line with Section 8(7)–(8) of the DPDPA. You can also ask us to erase your data earlier — see B.7.

B.6 How we protect your data — including anyone who fills in the contact form

Under Section 8(5) of the DPDPA and Rule 6 of the DPDPA Rules, we're required to take "reasonable security safeguards" against unauthorised access, breach, or loss of your personal data. In practice, for anyone who submits their name and details through our contact form or booking flow, that means:

Security measures in place

  • Encryption in transit — the whole site, including the contact form, loads over HTTPS/TLS, so your submission is encrypted between your browser and our servers.
  • Spam & bot protection — the contact form uses a hidden honeypot field (and can add reCAPTCHA) to block automated/bot submissions, so real people's data isn't buried in spam traffic.
  • Restricted access — only Ranjith Vasu (and, if ever needed, a bound-by-confidentiality assistant) can view submitted form data, via a password-protected dashboard.
  • No card/payment data touches our systems — all payment details are entered directly into our RBI-regulated payment gateway, never into our own forms or database.
  • Data minimisation — the form only asks for what's needed (name, email, phone, message); we don't ask you to put sensitive health details into the public contact form itself.
  • Breach response plan — if a personal data breach were ever to occur, we will notify the Data Protection Board of India and affected individuals as required by Rule 7 of the DPDPA Rules (initial notice without delay; detailed report to the Board within 72 hours).
  • Logging & monitoring — access and security logs are retained for at least one year to support any investigation, per Rule 6.

We're a small business, not a bank — but these are the same baseline safeguards recommended for any small website handling names and contact details under the DPDPA Rules, 2025.

B.7 Your rights as a Data Principal

Under Chapter III of the DPDPA, you have the right to:

  • Access a summary of the personal data we hold about you and how we're processing it (Section 11).
  • Correct, complete, or update inaccurate or incomplete personal data (Section 12).
  • Erase your personal data, once it's no longer needed for the purpose it was collected for, or you withdraw consent (Section 12).
  • Grievance redressal — raise any concern about how we've handled your data (Section 13).
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity (Section 14).

To exercise any of these rights, email ranjith@21minfit.com with your name and the request. We aim to acknowledge every request within 7 days and resolve it within 30 days, well inside the 90-day maximum set by Rule 14 of the DPDPA Rules.

B.8 Your duties as a Data Principal

Section 15 of the DPDPA also asks you to: provide only information that is accurate and not impersonate anyone else while sharing your data with us; not suppress material information relevant to your training/safety; and not raise false or frivolous complaints.

B.9 Children's data

Our Services are designed for adults. We do not knowingly collect personal data from anyone under 18 without verifiable consent from a parent or lawful guardian, and we do not carry out behavioural tracking or targeted advertising directed at children, in line with Section 9 of the DPDPA and Rule 10 of the DPDPA Rules. If you believe a minor has shared personal data with us without appropriate parental consent, please contact us and we will erase it.

B.10 Grievance redressal & how to complain

Grievance & Data Protection Contact

Ranjith Vasu, on behalf of Lifespan Twenty One LLP (21MinFit)

Email: ranjith@21minfit.com

Bengaluru, Karnataka, India

If you're unhappy with how we've handled your personal data or a rights request, please contact us first at the email above — we'll do our best to resolve it directly. If you remain unsatisfied after raising it with us, Section 13(3) of the DPDPA gives you the right to escalate your complaint to the Data Protection Board of India (established November 2025 under the DPDPA), once its public complaint mechanism is fully operational.

B.11 Cookies

We use only the minimal cookies needed to run the site (e.g. Netlify's essential functional cookies). We don't currently use advertising or tracking cookies. If we embed an Instagram Reel, Instagram's own embed script may set its own cookies under Instagram's/Meta's privacy policy — that's outside our control.

B.12 Changes to this Privacy Policy

We may update this Policy as our Services, the law, or the DPDPA Rules evolve — particularly as the Act's remaining provisions come into full force (the DPDPA Rules, 2025 are being rolled out in phases through May 2027). The "Last updated" date at the top will always show the current version.

Not legal advice. This document was drafted from the full text of the Digital Personal Data Protection Act, 2023, and publicly available summaries of the Digital Personal Data Protection Rules, 2025. It's intended as a genuine, good-faith compliance effort for a small fitness business, not a substitute for review by an India-qualified data-protection lawyer — especially given that 21MinFit collects health/fitness information and operates as an LLP. We'd recommend a lawyer confirm the exact retention periods for financial records, and whether any current data flows require additional safeguards.