Privacy Policy
How we collect, use, and protect your data
Effective Date: 10-07-2026 | Last Updated: 10-07-2026
1. About This Policy
This Privacy Policy ('Policy') describes how Vanavya Consulting Pvt. Ltd., ('Company', 'we', 'us', 'our') collects, uses, stores, discloses, and protects personal data when you visit our website (https://www.vanavyaconsulting.com/) or use our Vanavya Pulse- HR Management Software platform ('Platform'). This Policy is published in compliance with Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ('IT Rules') and the Digital Personal Data Protection Act, 2023 ('DPDPA'). By using our Platform or Website, you consent to the practices described in this Policy.
2. Definitions
'Personal Data' means any data by which a Data Principal can be identified, as defined under DPDPA 2023. 'Sensitive Personal Data' includes passwords, financial information, health data, biometric data, and sexual orientation, as specified under IT Rules 2011. 'Data Fiduciary' means the Company, which determines the purpose and means of processing personal data. 'Data Principal' means the individual to whom the personal data relates. 'Data Processor' means an entity processing data on behalf of the Data Fiduciary. 'Consent Manager' has the meaning assigned under DPDPA 2023.
3. Categories of Data Collected
3.1 Data Collected from Customers (Organisations)
- Name, designation, and contact details of authorised personnel;
- Company registration details, GST/PAN numbers, and billing information
- Usage logs, feature access records, and support communication history.
3.2 Employee Data (Processed as Data Processor)
When customers use the Platform to manage their workforce, we process Employee Data on their behalf, which may include:
- Employee name, designation, department, employee ID;
- Date of birth, gender, address, contact information;
- Salary details, bank account information, tax declarations;
- Attendance, leave, performance records;
- Government-issued identifiers (Aadhaar number, PAN) where explicitly required.
- In respect of Employee Data, the Customer is the Data Fiduciary and the Company acts as a Data Processor under DPDPA 2023.
3.3 Website Visitor Data
- IP address, browser type, device identifiers;
- Pages visited, time spent, referral source;
- Cookie data (see Section 9 below).
4. Purpose of Processing
We process personal data for the following purposes:
- Provision and improvement of the Platform and associated services;
- Account management, authentication, and customer support;
- Billing, invoicing, and financial compliance (including GST compliance);
- Statutory and regulatory compliance, including under the Companies Act 2013, Income Tax Act 1961, Employees' Provident Funds Act 1952, and other applicable labour laws;
- Communication regarding updates, security alerts, and service announcements;
- Analytics and platform optimisation, in anonymised or aggregated form;
- Prevention of fraud, unauthorised access, and security incidents.
5. Legal Basis for Processing
Processing of personal data is carried out on one or more of the following lawful bases under DPDPA 2023:
- Consent of the Data Principal;
- Performance of a contract or taking steps at the request of the Data Principal;
- Compliance with a legal obligation;
- Legitimate interests of the Company or a third party, except where overridden by the interests or rights of the Data Principal.
6. Sharing and Disclosure
We do not sell, rent, or trade personal data to third parties. We may share data with:
- Service providers and Data Processors engaged to support the Platform (e.g., cloud infrastructure, payment processors, email delivery), under written data processing agreements;
- Government authorities, regulators, and law enforcement agencies when required by law, court order, or legal process;
- Professional advisors (lawyers, auditors) under strict confidentiality obligations;
- In connection with a merger, acquisition, or sale of assets, with appropriate safeguards.
7. Data Retention
We retain personal data for no longer than is necessary for the purposes set out in this Policy, or as required by applicable law. Upon account termination, Customer and Employee Data will be retained for [90] days and thereafter securely deleted or anonymised, unless longer retention is required by law.
8. Rights of Data Principals
Under DPDPA 2023, Data Principals have the following rights, exercisable by submitting a request to Email privacy@vanavya.in:
- Right to access — obtain information about personal data being processed;
- Right to correction and erasure — correct inaccurate data or request deletion;
- Right to grievance redressal — raise complaints with the Company's Grievance Officer;
- Right to nominate — nominate a person to exercise rights in case of death or incapacity;
- Right to withdraw consent — without affecting the lawfulness of prior processing.
- The Company shall respond to requests within [30] days. Certain requests may be declined where processing is required by law.
9. Cookies and Tracking Technologies
Our Website uses cookies, web beacons, and similar tracking technologies to enhance user experience. Cookies may be:
- Strictly Necessary — essential for the operation of the Website;
- Analytical — used to understand how the Website is used (Google Analytics, etc.);
- Marketing — used for remarketing and advertising purposes.
- You may configure your browser to decline cookies; however, this may affect the functionality of certain parts of the Platform.
10. Data Security
The Company implements industry-standard technical and organisational security measures, including:
- SSL/TLS encryption in transit and AES-256 encryption at rest;
- Role-based access controls and multi-factor authentication;
- Regular security audits, penetration testing, and vulnerability assessments;
- Incident response procedures in accordance with CERT-In guidelines.
- In the event of a personal data breach, the Company shall notify affected Data Principals and, where required, the Data Protection Board of India, in accordance with DPDPA 2023 and applicable CERT-In directives.
11. Cross-Border Data Transfers
Personal data is stored and processed within India. Any transfer of personal data outside India shall be made only in accordance with the provisions of DPDPA 2023 and applicable government notifications, with appropriate safeguards in place.
12. Changes to This Policy
We may update this Policy periodically. Material changes will be notified via the Platform or email at least [15] days before they take effect. The current version of this Policy shall always be accessible at privacyandpolicy .