Vanavya logo

Privacy Policy

Effective Date: [Insert Date]  |  Last Updated: [Insert Date]

1. INTRODUCTION

VANAVYA Tech (“Company”, “we”, “our”, “us”) recognizes the importance of protecting personal data in today’s digital environment and is committed to maintaining the highest standards of privacy, confidentiality, and transparency. This Privacy Policy sets out the principles and practices governing the collection, use, storage, disclosure, and protection of personal information when you interact with our services, including website development, software solutions, consultancy, and related technology offerings.

We understand that our clients, users, and visitors (“you”, “your”) entrust us with sensitive business and personal information, and we take this responsibility seriously. Our privacy framework is designed to comply with applicable data protection laws, including but not limited to the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (EU), and other international standards where relevant. By engaging with VANAVYA Tech, you acknowledge that your data will be processed in accordance with this Policy, which is intended to be both legally enforceable and operationally practical.

This Policy also reflects our commitment to accountability, lawful processing, and layered safeguards, ensuring that your data is handled with integrity, fairness, and respect for your rights.

2. SCOPE & APPLICABILITY

This Privacy Policy applies comprehensively to all data collected, processed, or stored by VANAVYA Tech in connection with:

  • Website Visitors: Individuals accessing our website, browsing content, or submitting inquiries.
  • Clients and Prospective Clients: Businesses and individuals engaging our services for website development, software solutions, or consultancy.
  • End-Users of Client Solutions: Where VANAVYA Tech develops software or platforms for clients, this Policy governs how we handle any personal data processed during development, testing, or maintenance.
  • Employees, Contractors, and Vendors: Internal stakeholders whose data is processed for operational, contractual, or compliance purposes.

This Policy does not extend to third-party websites, applications, or services that may be linked through our platforms. VANAVYA Tech is not responsible for the privacy practices of such external entities, and we encourage you to review their respective policies before sharing personal information.

The Policy applies globally to all jurisdictions where VANAVYA Tech operates or provides services. In cases of conflict between local laws and this Policy, statutory requirements will prevail, and VANAVYA Tech will implement appropriate safeguards to ensure compliance.

3. INFORMATION WE COLLECT

VANAVYA Tech collects personal and business information through direct interactions (such as service agreements, project onboarding, and customer support), automated technologies (such as cookies and analytics tools), and third-party integrations. The categories of data include:

  • Personal Identifiers: Name, email address, phone number, billing address, and government-issued identification where legally required.
  • Business Information: Company name, project specifications, contractual documents, and communication records exchanged during service delivery.
  • Technical Data: IP address, browser type, operating system, device identifiers, geolocation data, and server logs.
  • Project Data: Proprietary content, credentials, and specifications shared for website/software development, including hosting details, APIs, and integration keys.
  • Cookies & Analytics: Session data, preferences, and behavioral patterns collected via cookies, pixels, and analytics platforms.

Statutory Reference:

  • Under Section 5 of the Digital Personal Data Protection Act, 2023 (DPDPA), VANAVYA Tech provides notice at the time of collection, specifying the categories of data and purposes of processing.
  • Under GDPR Article 13, individuals are informed of the identity of the controller, purposes of processing, and rights available to them.

4. PURPOSE OF PROCESSING

VANAVYA Tech processes personal data strictly for lawful and legitimate purposes, including:

  • Service Delivery: To design, develop, and maintain websites, software, and related technology solutions.
  • Communication: To provide project updates, respond to inquiries, and deliver technical support.
  • Contractual Fulfillment: To manage billing, invoicing, and compliance with contractual obligations.
  • Security & Improvement: To enhance system security, detect fraud, and improve user experience.
  • Legal Compliance: To meet statutory obligations, respond to lawful requests, and resolve disputes.
  • Marketing (Consent-Based): To send promotional communications, newsletters, or service updates, only where explicit consent has been obtained.

Statutory Reference:

  • Section 7 of DPDPA, 2023 requires that processing be limited to lawful purposes for which consent has been obtained or for legitimate uses defined under the Act.
  • GDPR Article 6 establishes lawful bases for processing, including consent, contractual necessity, legal obligation, and legitimate interest.

5. Legal Basis for Processing

VANAVYA Tech ensures that all processing activities are grounded in a valid legal basis, depending on the jurisdiction and nature of the data:

  • Consent: Explicit consent obtained from individuals for specific purposes, such as marketing communications or optional data sharing.
  • Contractual Necessity: Processing required to fulfill service agreements, including project execution, billing, and support.
  • Legal Obligation: Processing mandated by statutory requirements, regulatory filings, or judicial orders.
  • Legitimate Interest: Processing necessary for business operations, fraud prevention, service improvement, and safeguarding network security, balanced against individual rights.

Statutory Reference:

  • Section 5(2) of DPDPA, 2023 requires clear, informed consent for processing, with the right to withdraw consent at any time.
  • GDPR Article 6(1) outlines lawful bases for processing, including consent, contract, legal obligation, vital interests, public interest, and legitimate interest.
  • CCPA (California Consumer Privacy Act) requires businesses to disclose the purposes of data collection and provide opt-out mechanisms for certain uses.

6. Data Sharing & Disclosure

VANAVYA Tech does not sell or trade personal data. Information may only be disclosed under the following circumstances:

  • Service Providers: Trusted vendors engaged for hosting, analytics, payment processing, or technical support, bound by confidentiality and data protection agreements.
  • Legal Authorities: Disclosure mandated by statutory requirements, regulatory authorities, or judicial orders.
  • Business Transfers: In mergers, acquisitions, or restructuring, subject to contractual safeguards ensuring continuity of privacy protections.
  • Client Authorization: With explicit written consent for project-specific disclosures.

Statutory Reference:

  • Section 8 of DPDPA, 2023 requires that data fiduciaries ensure processing is limited to lawful purposes and disclosures are made only with consent or legal mandate.
  • GDPR Article 28 requires that processors provide sufficient guarantees for data protection.
  • CCPA Section 1798.115 mandates disclosure of categories of personal information shared with third parties.

7. Data Security Measures

VANAVYA Tech employs layered technical and organizational safeguards to protect personal data against unauthorized access, alteration, disclosure, or destruction. Measures include:

  • Encryption of data both in transit and at rest.
  • Role-based access controls and multi-factor authentication.
  • Regular vulnerability assessments, penetration testing, and patch management.
  • Secure servers, firewalls, and intrusion detection systems.
  • Employee confidentiality agreements and periodic training on data protection.

Statutory Reference:

  • Section 8(5) of DPDPA, 2023 requires data fiduciaries to implement reasonable security safeguards to prevent personal data breaches.
  • GDPR Article 32 mandates appropriate technical and organizational measures, including pseudonymization, encryption, and resilience of processing systems.

8. Data Retention & Disposal

VANAVYA Tech retains personal data only for as long as necessary to fulfill contractual obligations, comply with statutory requirements, or achieve the purposes outlined in this Policy.

  • Retention Periods: Defined by contractual terms, statutory mandates, or operational necessity.
  • Secure Disposal: Upon expiry, data is securely deleted, anonymized, or archived in compliance with applicable law.
  • Periodic Review: Retention schedules are reviewed regularly to ensure compliance with evolving legal standards.

Statutory Reference:

  • Section 9 of DPDPA, 2023 requires that personal data be retained only for as long as necessary for the purpose of processing.
  • GDPR Article 5(1)(e) mandates that personal data be kept no longer than necessary for the purposes for which it is processed.

9. Your Rights

VANAVYA Tech respects your rights under applicable data protection laws. Subject to jurisdiction, you may exercise:

  • Right to Access: Obtain confirmation and a copy of your personal data.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of personal data, subject to legal obligations.
  • Right to Restrict Processing: Limit how your data is used in certain circumstances.
  • Right to Data Portability: Receive your data in a structured, machine-readable format and transfer it to another service provider.
  • Right to Withdraw Consent: Withdraw consent at any time, without affecting prior lawful processing.
  • Right to Grievance Redressal: File complaints with VANAVYA Tech’s Grievance Officer, who will respond within statutory timelines.

Statutory Reference:

  • Section 12 of DPDPA, 2023 grants individuals the right to access, correction, and erasure of personal data.
  • GDPR Articles 15–21 outline rights of access, rectification, erasure, restriction, portability, and objection.
  • CCPA Section 1798.105 provides consumers the right to request deletion of personal information.

10. International Data Transfers

VANAVYA Tech may transfer personal data outside India or the jurisdiction in which it was originally collected, particularly when engaging global service providers (e.g., cloud hosting, analytics, or payment gateways).

Safeguards Implemented:

  • Standard Contractual Clauses (SCCs) approved under GDPR.
  • Binding Corporate Rules (BCRs) for intra-group transfers.
  • Encryption and pseudonymization of data prior to transfer.

Jurisdictional Compliance:

  • Section 16 of DPDPA, 2023 requires that cross-border transfers be subject to conditions notified by the Central Government. VANAVYA Tech will comply with such notifications and ensure lawful transfer mechanisms.
  • GDPR Articles 44–50 mandate adequacy decisions or appropriate safeguards for transfers outside the EU.
  • CCPA Section 1798.140 requires disclosure of whether data is transferred outside the United States.

VANAVYA Tech ensures that international transfers do not dilute the level of protection afforded to personal data.

11. Children’s Privacy

VANAVYA Tech’s services are designed for businesses and adult professionals. We do not knowingly collect personal data from individuals under 18 years of age.

Preventive Measures:

  • Age-gating mechanisms on forms and service portals.
  • Immediate deletion of data if collected inadvertently from minors.

Statutory Reference:

  • Section 10 of DPDPA, 2023 requires verifiable parental consent for processing children’s data.
  • GDPR Article 8 requires parental consent for processing data of children under 16 (or lower thresholds defined by Member States).
  • COPPA (Children’s Online Privacy Protection Act, US) requires parental consent for collection of data from children under 13.

VANAVYA Tech will not provide services to minors without lawful parental or guardian authorization.

12. Grievance Redressal

VANAVYA Tech has established a formal grievance redressal mechanism to ensure timely resolution of privacy-related complaints.

Grievance Officer: Appointed in compliance with Section 13 of DPDPA, 2023.

Process:

  • Complaints acknowledged within 24 hours.
  • Resolution provided within 30 days, unless extended with justification.

Escalation: If grievances remain unresolved, individuals may escalate to the Data Protection Board of India under DPDPA, or to supervisory authorities under GDPR.

Contact Details:

Grievance Officer – VANAVYA Tech
Email: [Insert Email]
Phone: [Insert Phone Number]
Address: [Insert Office Address]

Statutory Reference:

  • DPDPA Section 13 mandates grievance redressal mechanisms.
  • GDPR Article 77 grants individuals the right to lodge complaints with supervisory authorities.
  • CCPA Section 1798.130 requires businesses to provide accessible methods for submitting requests.

13. Policy Updates

VANAVYA Tech may revise this Privacy Policy periodically to reflect changes in law, technology, or business practices.

  • Notification: Updates will be posted on our website with the revised effective date.
  • Material Changes: Where changes materially affect rights or processing purposes, individuals will be notified through email or service portals.
  • Consent Renewal: If changes introduce new purposes requiring consent, fresh consent will be obtained in compliance with Section 5(7) of DPDPA, 2023.

Statutory Reference:

  • DPDPA Section 5(7) requires notice of changes in processing purposes.
  • GDPR Article 12 mandates transparent communication of updates.

14. Contact Us

For queries, concerns, or to exercise your rights under this Privacy Policy, please contact:

VANAVYA Tech – Privacy Office
Email: info@vanavyatech.com
Phone: 9421191111
Address: B Block, Jangpura, New Delhi, 110014