Privacy Policy

Home Privacy Policy

Privacy Policy

Last Updated: December 2024

At Shivaryaa Innovations Private Limited, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect your information when you engage with our custom software development services, mobile applications, web platforms, and digital products including our Sanduk Digital Gold Saving App.

1. Information We Collect

We collect information necessary to deliver our digital product development services:

  • Client Information: Name, email, phone, company name, business address, GST number
  • Project Details: Technical requirements, business logic, user stories, API specifications, database schemas
  • Development Access: Server credentials, database access, third-party API keys, version control repository access
  • Communication Data: Email correspondence, project management tool entries, meeting notes, feedback and approvals
  • Financial Information: Invoices, payment records, billing addresses, bank account details for transactions

2. How We Use Your Information

Your information is used specifically for:

  • Developing custom mobile apps, web applications, and digital platforms
  • Project management, timeline tracking, and deliverable coordination
  • Invoice generation, payment processing, and financial record keeping
  • Technical support, bug fixes, and maintenance services
  • Quality assurance testing and deployment management

3. Information Sharing and Third Parties

We share your information only with:

  • Development Team: Project managers, developers, designers, and QA testers directly involved in your project
  • Cloud Providers: AWS, Google Cloud, or Azure for hosting and development environments
  • Payment Processors: Razorpay, PayU, or bank gateways for transaction processing
  • Legal Authorities: When required by Indian law, court orders, or government regulations

4. Data Security Measures

We implement enterprise-grade security for your project data:

  • Encryption: AES-256 encryption for data at rest, TLS 1.3 for data in transit
  • Access Control: Role-based access, multi-factor authentication, VPN access for remote development
  • Code Security: Private Git repositories, code reviews, vulnerability scanning
  • Backup Systems: Daily automated backups with 30-day retention, disaster recovery protocols

5. Client Application Data

For applications we develop, client data handling follows these principles:

  • Data Ownership: Clients retain full ownership of their application data and user information
  • Storage Location: Data stored in client-chosen regions (India, US, EU, or other specified locations)
  • Access Logs: Comprehensive audit trails for all data access and modifications

6. Your Rights Under Indian Law

As per IT Act 2000 and related regulations, you have the right to:

  • Access: Request copies of your personal data we hold (within 30 days)
  • Correction: Update inaccurate or incomplete personal information
  • Erasure: Request deletion of personal data (subject to legal obligations)
  • Portability: Receive your data in a machine-readable format

7. Data Retention Policy

Project Data: Retained for 7 years after project completion as per Indian business record requirements.

Financial Records: Kept for 8 years to comply with GST and income tax regulations.

Communication Logs: Retained for 3 years unless required for ongoing projects or legal purposes.

8. Website and Marketing

Our website uses:

  • Essential Cookies: Required for website functionality and security
  • Analytics: Google Analytics for website usage analysis (anonymized data)
  • Contact Forms: Information submitted via website contact forms stored securely

9. International Data Transfers

For international clients, data transfers comply with:

  • GDPR: For EU clients through Standard Contractual Clauses
  • APPI: For Australian clients under Australian Privacy Principles
  • CCPA: For California residents under California Consumer Privacy Act

10. Security Incident Response

In case of data security incidents:

  • Notification: Affected clients notified within 72 hours of discovery
  • Investigation: Immediate forensic analysis and containment procedures
  • Remediation: Free security patches and fixes for vulnerabilities

11. Policy Updates

We update this Privacy Policy as needed. Changes are posted on our website with a new "Last Updated" date. For significant changes, we notify clients via email within 30 days of implementation.

12. Contact for Privacy Matters

For privacy-related questions, data requests, or concerns:

Email: [email protected]
Phone: +91 9950905050
Address: A-304, Madhav Mangal Apartment, Times of India Building, Vejalpur, Manekbag, Ahmedabad - 380015, Gujarat, India

Data Protection Officer: Available Monday-Friday, 9:00 AM - 6:00 PM IST

By engaging Shivaryaa Innovations Private Limited for digital product development services, you confirm that you have read, understood, and consent to this Privacy Policy.