Privacy Policy
1. Introduction & Scope
This Privacy Policy ("Policy") governs how Udaya and its affiliated entities ("Udaya," "we," "us," or "our") collect, use, disclose, and otherwise process personal data in accordance with applicable privacy and data protection laws, including:
- India's Digital Personal Data Protection Act, 2023 ("DPDP Act")
- India's Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("IT Rules 2011")
- European Union's General Data Protection Regulation (GDPR) – for users in the EU/EEA
- California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA) – for California residents
This Policy applies to all individuals who access or interact with Udaya's websites, web applications, mobile applications, products, and services (collectively, "Services").
2. Definitions
Personal Data means any information relating to an identified or identifiable natural person. Under the DPDP Act, this includes data as a Data Principal, and under GDPR, as a data subject.
Data Principal (under DPDP Act) means the individual to whom personal data relates.
Processing means any operation performed on personal data, including collection, storage, use, transfer, or deletion.
Consent means freely given, specific, informed, and unambiguous indication of the Data Principal's wishes regarding their personal data.
3. Categories of Personal Data We Collect
We collect the following categories of personal data:
3.1 Information You Provide Directly
- Contact Information: Name, email address, phone number, mailing address, company name, job title
- Account Information: Username, password (encrypted), profile picture, preferences
- Transaction Information: Payment details (processed securely through third-party providers), billing address, order history
- Communication Data: Content of emails, messages, support tickets, feedback, survey responses
- Identity Verification: Government ID information (collected only when legally required)
3.2 Information Collected Automatically
- Device Information: Device type, operating system, browser type, IP address, device identifiers
- Usage Information: Pages visited, time spent on site, links clicked, features used, search queries
- Location Information: Approximate location based on IP address (not precise GPS location unless explicitly authorized)
- Log Data: Server logs containing access times, referrer pages, error messages, crash reports
- Cookie & Tracking Technologies: See Section 10 (Cookie Policy) for details
3.3 Information from Third Parties
- Analytics Providers: Information about how you interact with our Services
- Payment Processors: Confirmation of successful transactions
- Social Media Platforms: If you choose to connect via social login, basic profile information (with your consent)
- Third-Party Vendors: Information shared as part of business partnerships or integrations
4. Legal Basis for Processing (DPDP Act & GDPR)
4.1 Under the DPDP Act (India)
We process your personal data only where:
- You have provided explicit consent for specific processing purposes
- Processing is necessary to fulfill a contract with you (e.g., providing Services you've signed up for)
- Processing is required by law (e.g., tax compliance, legal obligations)
- Processing is necessary to protect your vital interests or the vital interests of others
- Processing is necessary for our legitimate interests or those of a third party, unless this conflicts with your rights
4.2 Under the GDPR (EU/EEA Users)
Our legal bases for processing include:
- Consent: Freely given consent for optional processing (e.g., marketing communications, non-essential cookies)
- Contract: Processing necessary to provide Services you've requested
- Legal Obligation: Processing required by applicable laws or regulations
- Vital Interests: Processing necessary to protect your vital interests
- Legitimate Interests: Processing necessary for our legitimate business interests (security, fraud prevention, analytics)
5. Purpose of Processing
We process your personal data for the following purposes:
5.1 Service Delivery & Account Management
- Providing, maintaining, and improving our Services
- Processing your account registration and authentication
- Delivering products or services you've requested
- Processing transactions and sending transaction confirmations
5.2 Communication & Customer Support
- Responding to your inquiries and support requests
- Sending service-related announcements and updates
- Notifying you about changes to our Services or this Policy
5.3 Marketing & Promotional Activities (with your opt-in consent)
- Sending promotional materials, newsletters, and product announcements
- Conducting surveys and requesting feedback
- Personalizing marketing content based on your interests
5.4 Analytics, Security & Fraud Prevention
- Analyzing usage patterns to improve user experience
- Detecting, investigating, and preventing fraudulent transactions
- Implementing security measures to protect against unauthorized access
- Complying with security standards and regulations (IT Rules 2011)
5.5 Legal & Regulatory Compliance
- Complying with legal obligations under Indian, EU, and other applicable laws
- Establishing, exercising, or defending legal claims
- Responding to government requests or legal processes
6. Data Retention & Deletion
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law.
Retention Schedule by Data Category
- Account Information: Retained during active account use + 2 years after account closure (for tax & legal compliance)
- Transaction Data: Retained for 7 years (per Indian tax regulations)
- Communication Records: Retained for 1 year (or longer if subject to legal holds)
- Marketing Consent Records: Retained for 2 years after opt-out
- Log & Analytics Data: Retained for 90 days (except as required for security audits)
- Device & Cookie Data: Retained for 2 years (or until cookie consent is withdrawn)
You have the right to request deletion of your personal data, subject to legal and contractual obligations. See Section 9 for instructions.
7. Data Sharing & Third-Party Processors
We do not sell, rent, or lease your personal data to third parties. However, we may share your personal data with:
7.1 Service Providers & Data Processors
The following categories of third parties process your personal data on our behalf, under Data Processing Agreements that ensure DPDP Act and GDPR compliance:
- Cloud Hosting: Amazon Web Services, in the Asia Pacific (Mumbai) region, for hosting and storage
- Email Delivery: Amazon Simple Email Service, for the messages generated when you contact us
We use no analytics provider, no advertising network, no payment processor and no third-party support or CRM tool at this time. If that changes, this list is updated before the service is introduced.
All processors are contractually obligated to:
- Process data only per our documented instructions
- Implement appropriate security measures (ISO 27001, SOC 2 Type II, or equivalent)
- Not use data for their own purposes
- Maintain confidentiality of the data
- Notify us of data breaches without undue delay
7.2 Legal Requirements & Law Enforcement
We may disclose your personal data if required by law, regulation, court order, or legal process, including:
- Responses to government requests, subpoenas, or judicial orders
- Compliance with tax authorities and regulatory bodies
- Cooperation with law enforcement investigations
7.3 Business Transfers
If Udaya is acquired, merges with another entity, or undergoes bankruptcy, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
7.4 International Data Transfers
For users in the EU/EEA: We transfer personal data to countries outside the EU/EEA only with appropriate safeguards, including:
- EU Standard Contractual Clauses (SCCs)
- Adequacy Decisions
- Your explicit consent
For users in India: We comply with the DPDP Act's data localization requirements and transfer restrictions as amended from time to time.
8. Data Security & Protection Measures
We implement comprehensive technical and organizational security measures to protect your personal data from unauthorized access, alteration, disclosure, and destruction, including:
- Encryption in Transit: TLS 1.2 and above for all data transmitted to and from our Services. Older protocol versions are refused.
- Access Controls: Least privilege. Personal data files are readable only by the service account that writes them, on a host that mounts the rest of the filesystem read-only to that service.
- Authentication: Multi-factor authentication on administrative and cloud console access.
- Network Controls: Application services bound to loopback and reachable only through a reverse proxy. Firewall rules restrict inbound access.
- Minimal Third Parties: Our website loads no analytics, advertising or third-party scripts, and serves its own fonts, so visiting it discloses nothing to anyone but us.
- Restrained Logging: Logs record outcomes and a hashed IP address. They never record the contents of a submission.
- Backups: Backups are held off the serving host.
- Compliance Standards: Adherence to the security requirements of IT Rules 2011.
- Incident Response: Procedures for detecting, investigating and responding to data breaches.
Despite these measures, no security system is impenetrable. We encourage you to use strong passwords and maintain the confidentiality of your account credentials.
9. Your Data Rights & How to Exercise Them
9.1 Rights Under the DPDP Act (India)
You have the following rights as a Data Principal:
- Right to Access: Request a copy of your personal data held by us
- Right to Correction: Request correction of inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data (subject to legal obligations)
- Right to Data Portability: Request your data in a structured, portable format
- Right to Grievance Redressal: Lodge grievances regarding processing of your data
9.2 Rights Under GDPR (EU/EEA Users)
If you are in the EU/EEA, you have additional rights:
- Right of Access: Obtain confirmation of whether we process your data and receive a copy
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure ('Right to be Forgotten'): Request deletion (with exceptions for legal obligations)
- Right to Restrict Processing: Limit how we process your data
- Right to Data Portability: Receive data in portable format and transmit to another controller
- Right to Object: Object to processing based on legitimate interests or direct marketing
- Rights Related to Automated Decision-Making: Not be subject to profiling without human review
- Right to Lodge a Complaint: File a complaint with your local data protection authority
9.3 Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights:
- Right to Know: Request what personal information we collect and how it's used
- Right to Delete: Request deletion of your personal information (with exceptions)
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out: Opt out of the sale or sharing of your personal information
- Right to Limit: Limit our use of sensitive personal information
- Right to Non-Discrimination: No discrimination for exercising your rights
9.4 How to Exercise Your Rights
To exercise any of the above rights, please submit a written request to:
Email:
Mailing Address: Data Protection Officer Udaya - A Venture of Inventum Technologies Private Limited New Delhi, India
Response Timeline:
- DPDP Act: We will respond within 30 days of receiving your request
- GDPR: We will respond within 30 days (extendable by 60 days for complex requests)
- CCPA/CPRA: We will acknowledge within 10 business days and respond within 45 calendar days
We may request verification of your identity to process your request securely.
10. Cookies & Tracking Technologies
For a detailed explanation of cookies and how to manage them, see our separate Cookie Policy. In summary:
- We set no cookies on this website. None at all, of any category.
- No performance or analytics technology is present, so there is nothing measuring how you use the site.
- No marketing or advertising technology is present, and no tracking pixel, tag or beacon.
- Two local storage values remember your appearance preference and that you answered the notice on your first visit. They never leave your device.
You can clear those two values at any time through your browser's settings for this site.
11. Children's Privacy
Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children under 18. If we become aware that we have collected data from a child under 18, we will delete such data and notify the parent/guardian.
For users in the EU under 16: Parental consent is required before processing. We may allow higher parental involvement for users between 16-18.
If you believe we have collected data from a child, please contact us at .
12. Data Breach Notification
In the event of a data breach that compromises the security or privacy of your personal data, we will:
- Notify affected individuals and relevant authorities without undue delay
- Provide information about the nature of the breach, data affected, and recommended steps
- Notify within 72 hours (GDPR requirement) and 30 days (DPDP Act requirement) where applicable
- Provide a point of contact for breach-related inquiries
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of material changes via email or by posting a notice on our website. Your continued use of our Services after such notice constitutes your acceptance of the updated Policy.
14. Contact Us & Grievance Officer
For questions, concerns, or to exercise your rights, please contact:
Data Protection Officer, Grievance Officer & Legal Inquiries: Email:
Note on Email Protection: Our email address is obfuscated on this page to prevent automated spam bots from harvesting it. Please contact us directly for any legal, privacy, or compliance inquiries.
Mailing Address: Udaya - A Venture of Inventum Technologies Private Limited Grievance Redressal Officer New Delhi, India
Response Time: We will acknowledge grievances within 48 hours and provide resolution within 30 days.
© 2026 Udaya - A Venture of Inventum Technologies Private Limited. All rights reserved.
Terms & Conditions
1. Agreement to Terms
By accessing, browsing, and using Udaya's website (udaya.io, www.udaya.io) and any related applications, products, and services (collectively, "Services"), you acknowledge that you have read, understood, and agree to be bound by these Terms & Conditions ("Terms") and our Privacy Policy. If you do not agree to these Terms, you may not use our Services.
These Terms are governed by the laws of the Republic of India and the exclusive jurisdiction of the courts of New Delhi, without regard to its conflicts of law principles.
2. Description of Services
Udaya provides technology products and services, including but not limited to:
- Web and mobile applications
- Software-as-a-Service (SaaS) solutions
- Infrastructure and networking products
- Consulting and technical support services
- Documentation and educational resources
We reserve the right to modify, suspend, or discontinue any Services (or any features thereof) at any time with or without notice. Such modifications will be effective upon posting to our website or through notification to users.
3. User Accounts & Registration
3.1 Account Creation
To access certain features of our Services, you must create an account. You agree to:
- Provide accurate, complete, and up-to-date information during registration
- Maintain the confidentiality of your account credentials (username and password)
- Be responsible for all activities that occur under your account
- Promptly notify us of any unauthorized use of your account
3.2 Age & Eligibility
You must be at least 18 years of age to use our Services. If you are between 18-21 in your jurisdiction, parental consent may be required. We do not knowingly collect information from individuals under 18.
3.3 Account Termination
We reserve the right to suspend or terminate your account at our sole discretion if you:
- Violate these Terms or our Acceptable Use Policy
- Engage in fraudulent or illegal activities
- Repeatedly breach our policies
- Fail to pay applicable fees within 30 days of due date
4. Acceptable Use Policy
You agree not to use our Services for:
- Unlawful or illegal activities
- Harassment, abuse, or threatening behavior toward others
- Distributing malware, viruses, or harmful code
- Unauthorized access to our systems or data
- Attempting to reverse-engineer, decompile, or discover source code
- Sending spam, phishing, or unsolicited communications
- Circumventing security measures or access controls
- Infringing on intellectual property rights of others
- Reselling, renting, or sublicensing the Services without authorization
- Performing unauthorized load testing or denial-of-service attacks
5. Intellectual Property Rights
5.1 Udaya's Intellectual Property
All content, software, technology, designs, graphics, logos, trademarks, and documentation associated with the Services ("Udaya Content") are the exclusive property of Udaya or its licensors. You are granted a limited, non-exclusive, non-transferable, revocable license to use the Services solely for your personal or internal business purposes.
You may not:
- Reproduce, distribute, or republish Udaya Content
- Create derivative works based on our Services or Content
- Use our trademarks or logos without written permission
- Claim ownership of or suggest you created the Services
5.2 User-Generated Content
Any content you submit, upload, or create through our Services ("User Content") remains your property. However, you grant Udaya a worldwide, royalty-free, irrevocable, perpetual license to use, modify, distribute, and display your User Content in connection with operating and improving our Services.
You represent and warrant that:
- You own or have rights to the User Content
- Your User Content does not infringe on third-party intellectual property rights
- Your User Content does not contain malware or harmful code
- You have obtained any necessary consents for using User Content
6. Fees & Payment Terms
6.1 Pricing
Pricing for our Services will be clearly displayed before purchase. We reserve the right to change pricing with 30 days' written notice. Price changes will not apply retroactively to existing subscriptions unless specified otherwise.
6.2 Billing & Payment
- Billing occurs at the start of your billing period and recurs monthly or annually (as selected)
- Payment is due within 30 days of invoice date unless otherwise stated
- Late payments may incur interest at 18% per annum
- All charges are in the currency specified in your agreement
6.3 Refunds
Refund eligibility is determined on a case-by-case basis. Requests must be made within 30 days of payment. Refunds for subscription services are subject to our refund policy provided at the time of purchase. Customization or implementation fees are non-refundable unless agreed otherwise.
6.4 Taxes
You are responsible for any applicable GST, VAT, or other taxes in your jurisdiction. If tax-exempt, you must provide valid tax documentation.
7. Data & Privacy
7.1 Privacy Compliance
Your use of our Services is subject to our Privacy Policy. By using our Services, you consent to the collection and processing of your data as described in the Privacy Policy, including under the Digital Personal Data Protection Act, 2023 (DPDP Act).
7.2 Data Processing
If you use our Services to process personal data of third parties, you must:
- Obtain necessary consents from data subjects
- Ensure compliance with DPDP Act, GDPR, CCPA, and other applicable laws
- Indemnify Udaya against third-party claims related to your data
7.3 Data Breach Notification
In the event of a data breach involving your personal information, Udaya will:
- Notify you without undue delay (within 72 hours under GDPR; 30 days under DPDP Act)
- Provide information about the nature and scope of the breach
- Notify relevant regulatory authorities as required by law
8. Warranties & Disclaimers
8.1 AS-IS BASIS
Our Services are provided on an "AS-IS" and "AS-AVAILABLE" basis. Udaya makes no representations or warranties regarding:
- Uninterrupted or error-free operation of Services
- Suitability for any particular purpose
- Accuracy, completeness, or reliability of content or data
- Freedom from viruses or harmful code
8.2 DISCLAIMER OF WARRANTIES
TO THE MAXIMUM EXTENT PERMITTED BY LAW, UDAYA DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
9. Limitation of Liability
9.1 Excluded Damages
TO THE MAXIMUM EXTENT PERMITTED BY INDIAN LAW, IN NO EVENT SHALL UDAYA BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING:
- Loss of profits or revenue
- Loss of data or business interruption
- Reputational harm or goodwill loss
EVEN IF UDAYA HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
9.2 Cap on Liability
Udaya's total liability to you for any claim arising from these Terms or your use of the Services shall not exceed the amount paid by you in the 12 months preceding the claim. If no fees were paid, liability shall not exceed ₹50,000.
10. Indemnification
You agree to indemnify, defend, and hold harmless Udaya and its officers, directors, employees, and agents from any claims, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from:
- Your violation of these Terms
- Your violation of applicable laws or regulations
- Your use of our Services in an unlawful or unauthorized manner
- Your User Content infringing on third-party rights
- Your personal data processing violating DPDP Act or GDPR
11. Third-Party Links & Content
Our Services may contain links to third-party websites and services. Udaya is not responsible for:
- Accuracy or legality of third-party content
- Availability or quality of third-party services
- Privacy practices of third-party websites
- Violations by third parties
Your use of third-party links is governed by their respective terms and privacy policies. We recommend reviewing those terms before accessing third-party services.
12. Service Availability & Uptime
While Udaya strives to maintain high availability, we do not guarantee uninterrupted service. We may perform maintenance, upgrades, or patches that may temporarily interrupt service with or without notice.
For paid Services, we commit to 99.5% uptime monthly (excluding maintenance windows). Service Level Agreement (SLA) details will be specified in your service agreement or on our website.
13. Suspension & Termination
13.1 Termination by You
You may terminate your account at any time by notifying us in writing. Upon termination, your access to the Services will be revoked, and your data may be deleted within 30 days (subject to legal retention requirements).
13.2 Termination by Udaya
Udaya may suspend or terminate your account or Services immediately if:
- You violate these Terms
- You engage in illegal activities
- You breach our Acceptable Use Policy
- Your account has been inactive for 24 months
13.3 Effect of Termination
Upon termination:
- Your access to the Services immediately ends
- Your data may be retained for legal or tax compliance purposes (minimum 7 years)
- Sections on Intellectual Property, Limitations of Liability, and Indemnification survive termination
14. Governing Law & Dispute Resolution
14.1 Governing Law
These Terms are governed by the laws of India, specifically the jurisdiction of New Delhi, without regard to conflict of law principles.
14.2 Dispute Resolution
Before initiating litigation, you agree to attempt to resolve disputes through:
- Informal negotiation (30 days)
- Mediation (45 days)
If resolution is not reached, disputes shall be resolved through arbitration under the Arbitration and Conciliation Act, 1996, with the seat of arbitration in New Delhi.
14.3 Exclusive Jurisdiction
You irrevocably consent to the exclusive jurisdiction of the courts of New Delhi for any legal action not subject to arbitration.
15. Modifications to These Terms
Udaya may update these Terms from time to time. Material changes will be announced via email or posted on our website with a 30-day notice. Your continued use of the Services after the notice period constitutes acceptance of the updated Terms.
16. Contact Us
For questions regarding these Terms, please contact:
Email:
Mailing Address: Udaya - A Venture of Inventum Technologies Private Limited Legal Department New Delhi, India
© 2026 Udaya - A Venture of Inventum Technologies Private Limited. All rights reserved.
Cookie Policy
1. Introduction
This Cookie Policy explains how Udaya ("we," "us," "our," or "Udaya") uses cookies, web beacons, pixels, and similar tracking technologies on our websites, web applications, and services ("Services"). This policy should be read alongside our Privacy Policy, which provides more information about how we process your personal data.
By accessing and using our Services, you consent to our use of cookies as described in this policy, except for non-essential cookies for which we obtain explicit opt-in consent.
2. What Are Cookies & Tracking Technologies
2.1 Cookies
A cookie is a small text file stored on your device (computer, tablet, mobile phone) when you visit our Services. Cookies allow websites to recognize your device and store information about your preferences and browsing behavior.
Types of Cookies by Duration:
- Session Cookies: Temporary cookies deleted when you close your browser. Used for maintaining login sessions and protecting against CSRF attacks.
- Persistent Cookies: Remain on your device for a set period (ranging from days to years). Used for remembering preferences and tracking behavioral data.
2.2 Tracking Technologies
Beyond cookies, we may use:
- Web Beacons (Pixels): Transparent 1x1 pixel images embedded in web pages or emails to track when content is viewed.
- Local Storage & Session Storage: Browser storage mechanisms similar to cookies, storing larger amounts of data locally.
- Device Fingerprinting: Collecting device attributes (browser, OS, IP address, hardware) to uniquely identify you (limited use, only for security).
- Analytics Tracking: JavaScript-based tracking for user behavior analysis.
3. Cookies & Tracking Technologies We Use
3.1 Essential Cookies (No Consent Required)
These cookies are necessary for the core functionality of our Services. They cannot be disabled without breaking service functionality.
This website sets no cookies at all. Not one, of any kind.
It stores two values in your browser's local storage, which never leave your device and are never transmitted to us:
| Name | Purpose | Duration |
|---|---|---|
| udaya-mode | Remembers whether you chose the light or dark appearance | Until you clear it |
| udaya-consent | Remembers that you answered the notice on your first visit, so you are not asked again | Until you clear it |
Both are strictly necessary in the sense that they exist only to honour a choice you made. Neither identifies you, tracks you, or follows you to any other website.
3.2 Performance & Analytics Cookies (Requires Opt-In Consent)
We use none. There is no Google Analytics, no Mixpanel and no analytics product of any kind on this website. We do not measure page views, sessions, funnels or referrers.
3.3 Marketing & Advertising Cookies (Requires Opt-In Consent)
We use none. There is no advertising or remarketing technology on this website, and no pixel, tag or beacon belonging to any advertising network.
3.4 Functional Cookies (Requires Opt-In Consent)
We use none. There is no login, no chat widget and no support tool on this website.
4. Cookie Consent & Management
4.1 Consent Banner
On your first visit we show a short notice explaining that we set no cookies and run no tracking, with a link to this page, and we record whether you accept or decline.
Because there are no non-essential cookies, declining does not switch anything off and does not restrict your use of the site in any way. We record the answer so we can demonstrate that the notice was shown and what you chose.
The record contains the decision, a random identifier your browser keeps, a one-way hash of your IP address, your browser's user agent string, and which version of these documents you were shown. It does not contain your name, your email address, or your IP address in a readable form.
4.2 Changing Your Mind
There is no preferences centre, because there are no optional cookies for it to govern. To reset your choice, clear this site's local storage in your browser and the notice will appear again on your next visit.
If we ever introduce analytics or any other non-essential technology, we will build granular controls and ask for your consent before it loads, not after.
4.3 Withdrawal of Consent
There is no non-essential cookie to withdraw consent for, because we set none. To reset the notice and be asked again, clear this site's local storage through your browser's settings.
If we ever introduce technology that does require consent, withdrawing it will be as easy as giving it, and withdrawal will not affect the validity of processing carried out beforehand.
5. Third-Party Cookies & Analytics
There are none. No third party places anything on your device through this website.
This website loads no external scripts, no content delivery network, no chat widget and no advertising tag. Even the typefaces are served from our own domain rather than a font service, so that loading the page reveals your visit to nobody but us.
The only network requests the page makes are to udaya.io itself.
6. "Do Not Track" Signals
Some browsers send a "Do Not Track" (DNT) signal asking websites not to track your activity. We honour it by default and by design: there is no tracking on this website to switch off, whether or not you send the signal.
7. How to Control Cookies
7.1 Browser Settings
Most browsers allow you to control cookies through settings:
- Google Chrome: Settings → Privacy & Security → Cookies and other site data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Apple Safari: Preferences → Privacy → Cookies and website data
- Microsoft Edge: Settings → Privacy → Clear browsing data
7.2 Clear Cookies
You can delete existing cookies from your browser at any time. Instructions vary by browser, but typically involve accessing browser history/cache settings and selecting "Clear browsing data."
7.3 Privacy-Focused Browsers
Browsers like DuckDuckGo, Brave, and Firefox Focus offer enhanced privacy features including cookie blocking by default.
7.4 Impact of Disabling Cookies
Disabling essential cookies will affect your ability to use core features of our Services (e.g., login functionality). Non-essential cookies can be disabled without breaking core functionality.
8. GDPR & International Privacy Law Compliance
8.1 GDPR (EU/EEA Users)
Under GDPR, cookies that collect personal data require prior explicit consent (except for technically necessary cookies). We comply by:
- Displaying a clear, comprehensive consent banner before non-essential cookies are set
- Providing detailed information about each cookie category
- Allowing granular consent withdrawal
- Implementing cookie consent records for compliance verification
8.2 DPDP Act (India)
Under India's Digital Personal Data Protection Act, 2023, we obtain explicit consent before using cookies to collect personal data, consistent with GDPR requirements.
8.3 CCPA/CPRA (California Users)
We honor California residents' rights to opt out of the sale or sharing of personal information. While CCPA defines cookies as a separate compliance category, we treat them similarly to GDPR requirements.
9. Cookie Retention & Deletion
Cookies are retained for the duration specified in Section 3. When a cookie expires:
- Session cookies are automatically deleted when you close your browser
- Persistent cookies are deleted from your device after their expiration date
- You can manually delete cookies at any time via browser settings
10. Changes to This Cookie Policy
We may update this Cookie Policy from time to time to reflect new cookies, regulatory changes, or business practices. Material changes will be announced via email or posted on our website with a 30-day notice. Your continued use of our Services after the update constitutes your acceptance of the updated policy.
11. Contact Us
For questions about this Cookie Policy, or to exercise your cookie preferences, please contact:
Email:
Mailing Address: Udaya - A Venture of Inventum Technologies Private Limited Privacy & Compliance Team New Delhi, India
© 2026 Udaya - A Venture of Inventum Technologies Private Limited. All rights reserved.
Data Processing Agreement
1. Preamble
This Data Processing Agreement ("DPA") is entered into between:
DATA CONTROLLER ("Client"): The entity entering into a Service Agreement with Udaya and designated as the Data Controller.
and
DATA PROCESSOR ("Udaya"): Udaya - A Venture of Inventum Technologies Private Limited New Delhi, India
(Collectively referred to as the "Parties")
This DPA is entered into pursuant to and as required by:
- Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR")
- Section 8(2)(h) of the Digital Personal Data Protection Act, 2023 ("DPDP Act")
- Section 4(d) of the California Consumer Privacy Act ("CCPA") and amendments thereto
2. Definitions
Personal Data means any information relating to an identified or identifiable natural person, as defined under the GDPR, DPDP Act, and CCPA.
Processing means any operation performed on Personal Data, including collection, recording, organization, storage, retrieval, use, transmission, or erasure.
Data Subject means the individual to whom Personal Data relates.
Sub-processor means any entity (other than an employee of Udaya) that processes Personal Data on behalf of Udaya.
Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to Personal Data.
3. Subject Matter, Duration & Nature of Processing
3.1 Subject Matter
Udaya will process Personal Data solely for the purpose of providing the services described in the main Service Agreement between the Parties ("Services").
3.2 Duration
This DPA commences on the effective date of the Service Agreement and continues for the duration of the service delivery relationship, unless terminated earlier in accordance with Section 13.
3.3 Nature of Processing
Nature of Data:
- Contact Information: Names, email addresses, phone numbers, mailing addresses
- Account Information: Usernames, hashed passwords, profile data
- Usage Data: IP addresses, device identifiers, browsing behavior, feature usage
- Transaction Data: Payment information, order history, billing addresses
- Communication Data: Emails, support tickets, chat messages
Categories of Data Subjects:
- End users of the Client's services
- Client employees and authorized representatives
- Clients' business partners and vendors
Types of Processing:
- Data storage and hosting
- Analytics and performance monitoring
- Security and fraud detection
- Backup and disaster recovery
- Customer support and communications
4. Processing Instructions & Legitimate Basis
4.1 Instructions
Udaya will process Personal Data only on documented written instructions from the Client, including regarding international transfers, unless required to do so by applicable law.
4.2 Authorized Processing
Udaya is authorized to process Personal Data for the following purposes without separate instruction:
- Providing and maintaining the Services
- Security audits and compliance monitoring
- Responding to legal requests and regulatory investigations
- Backup and disaster recovery
4.3 Legitimate Legal Basis
Under GDPR, Udaya's processing is based on:
- Contract: Processing is necessary to provide Services under the Service Agreement (Article 6(1)(b))
- Legal Obligation: Processing required to comply with laws and regulations (Article 6(1)(c))
- Legitimate Interests: Processing necessary for security, fraud prevention, and service optimization (Article 6(1)(f))
5. Personnel & Confidentiality
5.1 Authorized Personnel
Udaya ensures that only authorized personnel who have undergone data protection training and background checks have access to Personal Data. All personnel are bound by confidentiality obligations.
5.2 Confidentiality Commitments
Udaya personnel must:
- Maintain strict confidentiality of all Personal Data
- Not use Personal Data for purposes other than providing the Services
- Report suspected data breaches immediately
- Comply with this DPA and all applicable data protection laws
5.3 Employee Training
Udaya will provide annual data protection and privacy training to all employees handling Personal Data.
6. Technical & Organizational Security Measures
Udaya will implement and maintain appropriate technical and organizational security measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, alteration, or disclosure. These measures include:
6.1 Technical Measures
- Encryption in Transit: TLS 1.2 and above for all data transmission
- Access Controls: Least privilege, with data files readable only by the service account that writes them
- Multi-Factor Authentication: MFA for all administrative and cloud console access
- Firewalls: Firewall rules restricting inbound access, with application services bound to loopback behind a reverse proxy
- Audit Logging: Logging of access and of operations on Personal Data, recording outcomes and a hashed IP address rather than the contents of a submission
6.2 Organizational Measures
- Incident Response: Procedures for detecting and responding to data breaches
- Data Protection Impact Assessments (DPIA): Conducted for high-risk processing activities
- Physical Security: Infrastructure is operated in Amazon Web Services facilities, whose physical security controls and certifications are published by AWS
7. Sub-Processors & Third-Party Vendors
7.1 Authorization for Sub-processing
Udaya may engage sub-processors (third-party service providers) to assist in providing the Services. Udaya will:
- Obtain prior written authorization from the Client before engaging any sub-processor
- Notify the Client of any planned changes to the sub-processor list with at least 30 days' notice
- Allow the Client to object to the use of any new sub-processor within 15 days of notification
7.2 Current Sub-processors
The following sub-processors are currently authorized:
Cloud Hosting:
- Amazon Web Services (AWS), Asia Pacific (Mumbai) region – hosting, storage and infrastructure (the AWS Data Processing Addendum applies)
Email:
- Amazon Simple Email Service (AWS SES) – delivery of the messages generated when you contact us
That is the complete list. No analytics, advertising, payment, CRM or support sub-processor is engaged at this time. Any addition is subject to the notice and objection rights in Section 7.1 above.
7.3 Sub-processor Obligations
All sub-processors must:
- Process Personal Data only per Udaya's documented instructions
- Implement appropriate security measures (minimum ISO 27001 or SOC 2 Type II)
- Not disclose Personal Data to third parties without authorization
- Notify Udaya immediately of data breaches or unauthorized access
- Allow audits and inspections by Udaya or Client
- Delete or return all Personal Data upon termination
8. Assistance with Data Subject Rights
Udaya will assist the Client in fulfilling data subject rights requests by:
- Providing requested Personal Data in a timely manner upon Client request (within 10 business days of request)
- Assisting in correcting, restricting, or deleting Personal Data as directed by the Client
- Providing Personal Data in portable, structured format (e.g., CSV, JSON) for data portability requests
- Maintaining records of data subject rights requests and responses
The Client remains responsible for fulfilling the actual requests and meeting regulatory timelines.
9. International Data Transfers
9.1 Transfer Mechanisms (GDPR)
For transfers of Personal Data outside the EU/EEA, Udaya will utilize:
- European Commission Standard Contractual Clauses (SCCs) – Module C2P (Controller to Processor) for required safeguards
- Adequacy Decisions – Where available (e.g., transfers to Switzerland, Japan)
- Binding Corporate Rules (BCRs) – If Udaya implements BCRs
9.2 Supplementary Measures
Udaya will implement supplementary technical and organizational measures to address any gaps identified in a transfer impact assessment, including:
- End-to-end encryption ensuring data cannot be decrypted in third countries
- Pseudonymization where possible
- Additional access controls restricting third-country employee access
9.3 Transfer Location Disclosure
Udaya will disclose to the Client all locations where Personal Data is stored, processed, or transferred.
10. Data Breach Notification
10.1 Notification Timeline
In the event of a suspected or confirmed data breach, Udaya will notify the Client:
- GDPR: Within 24-48 hours of becoming aware of the breach (to enable Client to meet 72-hour regulatory deadline)
- DPDP Act: Within 30 days of becoming aware of the breach
- CCPA: Within 10 business days of discovery
10.2 Breach Notification Content
Udaya's notification will include:
- Nature and scope of the breach
- Categories and approximate number of data subjects affected
- Categories and types of Personal Data involved
- Likely consequences and risks
- Measures taken to mitigate the breach and prevent recurrence
- Contact point for further information
10.3 Cooperation with Investigation
Udaya will fully cooperate with the Client's breach investigations, including:
- Providing forensic analysis and investigation reports
- Assisting in regulatory authority communications
- Implementing remediation measures to prevent recurrence
11. Audits, Inspections & Assessments
11.1 Audit Rights
The Client has the right to:
- Audit Udaya's processing of Personal Data (upon 15 days' written notice)
- Inspect relevant systems, policies, and documentation
- Request evidence of compliance with this DPA (e.g., ISO 27001 certificates, SOC 2 reports)
11.2 Third-Party Audit Reports
Udaya does not currently hold ISO 27001 certification or a SOC 2 Type II audit report, and has not commissioned a third-party penetration test. We will not represent otherwise. On request we will provide the security documentation we do hold, describing our architecture, access controls and incident response, and we will share any third-party audit report if and when one is obtained.
11.3 Audit Frequency & Costs
- Audits may occur no more frequently than annually unless triggered by a security incident or breach
- Costs of Client-initiated audits shall be borne by the Client (unless audit reveals material non-compliance)
12. Deletion & Return of Personal Data
Upon termination of the Service Agreement or Client request, Udaya will:
- Delete all Personal Data from production systems within 30 days of termination (or as directed by Client)
- Provide certified proof of deletion upon request
- Retain Personal Data only where legally required (e.g., tax records for 7 years) and document such retention
- Ensure all sub-processors delete or return Personal Data
The Client may request data export in portable format (CSV, JSON, etc.) before deletion.
13. Term & Termination
This DPA commences on the effective date of the Service Agreement and continues for its duration. Upon termination of the Service Agreement, Udaya's obligations under this DPA (except for data deletion and confidentiality) shall terminate, unless Personal Data is retained for legal compliance.
14. Liability & Indemnification
14.1 Udaya's Liability
Udaya's liability for data processing violations under this DPA is governed by the main Service Agreement's liability limitations, subject to:
- Udaya remains liable for damages caused by violation of GDPR, DPDP Act, or CCPA requirements
- Liability caps do not apply to data protection violations or breaches
14.2 Client Indemnification
The Client will indemnify Udaya against claims arising from:
- Client's instructions or data that violate applicable laws
- Client's failure to obtain required data subject consents
- Client's breach of representations and warranties in this DPA
15. Governing Law & Dispute Resolution
This DPA is governed by the laws of India and the exclusive jurisdiction of the courts of New Delhi. However, where GDPR applies to the Client, the DPA shall also comply with GDPR requirements.
16. Contact Information
For inquiries regarding this DPA:
Data Protection Officer (Udaya): Email:
Client Designated Representative: The Client shall designate and provide contact information for its authorized representative during service onboarding. This information will be captured electronically through the Service Agreement or DPA acceptance process.
Acceptance & Execution
This Data Processing Agreement is deemed executed and binding upon:
- The Client's acceptance and use of Udaya's services
- The Client's affirmative consent to this DPA through any electronic means (web form, email, or digital signature platform)
- The commencement of data processing activities by Udaya on behalf of the Client
By proceeding with and utilizing Udaya's services, both parties acknowledge and accept all terms and conditions outlined in this Data Processing Agreement. No physical signatures are required; electronic acceptance through service usage or explicit digital consent constitutes valid and binding execution.
© 2026 Udaya - A Venture of Inventum Technologies Private Limited. All rights reserved.