Back
PLEASE READ THIS POLICY CAREFULLY. It constitutes the notice of Shaventra AI Technologies Private Limited under section 5 of the Digital Personal Data Protection Act, 2023, and, where Regulation (EU) 2016/679 applies, the information required by Articles 13 and 14 thereof, in respect of Personal Data processed through shaventraai.com. It is a statement of actual practice: no processing is described that does not occur, and no processing occurs that is not described.
Document control
Issuing entity
Shaventra AI Technologies Private Limited, CIN-registered under the Companies Act, 2013 (the “Company”, “we”, “us”).
Version and effective date
Version 2.1, effective 20 August 2026. Supersedes all prior versions in their entirety upon publication.
Review cycle
Reviewed upon any change to processing operations, upon material legislative or regulatory change, and in any event not less than annually.
Privacy contact
hello@shaventra.com — the single designated channel for consent withdrawal, rights requests and grievances under Article 9 of this Policy.
Recitals
A. The Company operates the website shaventraai.com (the “Website”) and provides professional services in academic project development, research guidance, documentation, training and publication support.
B. In the course of operating the Website the Company processes a narrow and enumerated set of Personal Data, and processes no Personal Data by stealth, inference or acquisition from third parties.
C. This Policy records the entirety of that processing, the legal bases on which it rests, and the mechanisms by which the rights of Data Principals and Data Subjects may be exercised, and is published in discharge of the Company’s notice obligations under Applicable Data Protection Law.
1. Definitions and interpretation
1.1 In this Policy, unless the context otherwise requires: “Applicable Data Protection Law” means the Digital Personal Data Protection Act, 2023 together with the rules made thereunder (the “DPDP Act”), and, to the extent applicable to a given processing operation, Regulation (EU) 2016/679 and its United Kingdom equivalent (together the “GDPR”); “Personal Data”, “processing”, “Data Fiduciary”, “Data Principal” and “consent” bear the meanings assigned by section 2 of the DPDP Act; “Controller”, “Data Subject”, “Processor” and “personal data breach” bear the meanings assigned by Article 4 of the GDPR; and “Enquiry Data”, “Correspondence Data”, “Device-Local Preference” and “Infrastructure Log Data” bear the meanings given in Article 3.
1.2 For processing within the scope of the DPDP Act the Company acts as Data Fiduciary; for processing within the scope of the GDPR the Company acts as Controller. The Company is not, and does not hold itself out as, a Significant Data Fiduciary within the meaning of section 10 of the DPDP Act.
1.3 Headings are for convenience only; “including” is illustrative and not exhaustive; references to statutory provisions include their amendments, re-enactments and subordinate legislation; and the computation of any period of days follows section 9 of the General Clauses Act, 1897 (first day excluded, last day included).
2. Principles of processing
2.1 The Company adheres, in respect of all Personal Data within scope, to the principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity and confidentiality, as articulated in Article 5 of the GDPR and as reflected in the scheme of the DPDP Act.
2.2 Concretely: the Website requests no field it does not use; retains nothing beyond the periods in Article 6; and operates no processing whose purpose is not stated in Article 4. Data minimisation is architectural, not aspirational — fields that are not collected cannot be misused.
3. Categories of Personal Data collected
3.1 Enquiry Data
Upon voluntary submission of the enquiry panel on the Website’s blog: electronic mail address; telephone number with international dialling code (solely where entered); the service area selected from an enumerated list; the binary state of the marketing opt-in control; a source identifier; and a server-generated timestamp. No free-text field is collected through this panel.
3.2 Correspondence Data
The content of electronic mail the sender elects to transmit to the Company. Certain Website forms operate by composing a message within the visitor’s own mail client; such forms transmit nothing to the Company, and no data reaches the Company unless and until the visitor sends the message.
3.3 Device-Local Preference
A single interface preference (light or dark rendering) persisted in the browser’s localStorage under the same-origin policy. It is never transmitted, is not an identifier, and is not accessible to the Company.
3.4 Infrastructure Log Data
Standard HTTP request records (IP address, timestamp, URL, user agent) generated by the hosting provider in the ordinary course of content delivery, security and abuse prevention, retained and processed by that provider under its own published terms. The Company neither receives nor queries these records.
4. Purposes and lawful bases
4.1 Enquiry Data is processed for the sole and specified purpose of responding to the enquiry and conducting pre-contractual discussion of the Services requested. The lawful basis is: (a) under section 6 of the DPDP Act, the free, specific, informed, unconditional and unambiguous consent signified by affirmative submission of the panel for the purpose stated upon its face; and (b) under the GDPR, Article 6(1)(b) (steps at the request of the Data Subject prior to entering into a contract).
4.2 Correspondence Data is processed to respond to and administer the correspondence. In addition to consent, the Company relies, where applicable, on section 7(a) of the DPDP Act (voluntary provision of personal data for a specified purpose) and, under the GDPR, Article 6(1)(b) or 6(1)(f) (legitimate interest in responding to correspondence addressed to the Company), whichever applies to the communication in question.
4.3 The marketing purpose in Article 5 is processed solely on the basis of the affirmative, unbundled opt-in described there — section 6 of the DPDP Act and Article 6(1)(a) of the GDPR.
4.4 Negative enumeration. The Company does not undertake: profiling; automated decision-making producing legal or similarly significant effects within the meaning of Article 22 of the GDPR; behavioural advertising; data enrichment or matching from third-party sources; sale, rental or licensing of Personal Data; or any secondary use incompatible with the purposes stated above. The Company does not undertake unsolicited commercial communication within the meaning of the Telecom Commercial Communications Customer Preference Regulations, 2018; the telephone field exists solely so that an enquirer who prefers a call back may receive one.
5. Marketing communications; consent architecture
5.1 Marketing communications (updates on the Company’s publications and resources) are transmitted only to addresses whose holders have affirmatively selected the opt-in control, which is presented unselected, is not a condition of the enquiry, and is severable from it. An enquiry is not a subscription.
5.2 Pursuant to section 6(4) of the DPDP Act, withdrawal of consent is effected with ease comparable to its giving: by the unsubscribe mechanism contained in every marketing message, or by notice to hello@shaventra.com. Suppression is effected within seventy-two (72) hours. Withdrawal operates prospectively and without prejudice to processing already lawfully performed, and has no effect on any pending Engagement.
6. Retention schedule
6.1 Enquiry Data (no Engagement follows)
Erased not later than twenty-four (24) months after last substantive contact, or forthwith upon a valid erasure request under Article 11, whichever is earlier.
6.2 Marketing consent and suppression records
The address is retained while consent subsists and erased upon withdrawal, save a minimal suppression entry where retention is necessary to honour the withdrawal itself.
6.3 Engagement records
Retained for three (3) years from completion, corresponding to the general limitation period for suits founded on contract under the Limitation Act, 1963.
6.4 Invoices, receipts and books of account
Retained for not less than eight (8) financial years pursuant to section 128 of the Companies Act, 2013 and applicable revenue law, notwithstanding any earlier erasure request, such retention being required by law.
7. Security of processing; breach response
7.1 The Company implements reasonable security practices and procedures within the meaning of section 43A of the Information Technology Act, 2000 read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the security safeguards obligation of a Data Fiduciary under section 8 of the DPDP Act, proportionate to the limited categories processed. Without disclosing configurations whose publication would itself diminish security: all data in transit is encrypted; the public Website is technically capable of submitting an enquiry and incapable of reading any record back, so that no visitor can retrieve another person’s enquiry, or their own; and access to stored records is restricted to authorised personnel with a need to respond.
7.2 Personal Data is held on secure infrastructure within India and processed on the Company’s instructions and under contract. The Company does not sell, rent or trade Personal Data; does not disclose it to any third party in the ordinary course beyond the arrangements necessary to operate the Website and its mailbox; and discloses it to public authorities only where required by law or lawful order, to the minimum extent required and, where not prohibited, with notice to the person concerned.
7.3 No security measure is absolute, and the Company makes no representation of invulnerability. Upon a personal data breach affecting Personal Data within scope, the Company will intimate the affected Data Principals and the prescribed authority in the manner and within the periods required by the DPDP Act, and, where the GDPR applies, will proceed under Articles 33 and 34 thereof, including the seventy-two (72) hour supervisory notification where the breach is likely to result in a risk to rights and freedoms.
8. Children and vulnerable persons
8.1 The Website and the Services are directed exclusively to persons aged eighteen (18) years and above. The Company does not knowingly process the Personal Data of a child, does not undertake tracking or behavioural monitoring of children or targeted advertising directed at children, and, upon becoming aware of collection contrary to section 9 of the DPDP Act, will erase the data concerned without undue delay.
9. Rights of Data Principals and Data Subjects; procedure
9.1 Under the DPDP Act, a Data Principal may exercise: the right of access to a summary of Personal Data and processing activities (section 11); the right to correction, completion, updating and erasure (section 12); the right of grievance redressal (section 13); and the right to nominate (section 14). The attention of Data Principals is drawn to their statutory duties under section 15 of the DPDP Act, including the duty not to impersonate another and not to register a false or frivolous grievance.
9.2 Under the GDPR, a Data Subject may exercise the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20) and objection (Article 21), and rights in relation to automated decision-making (Article 22) — noting that the Company conducts no processing within Article 22.
9.3 Procedure. Requests shall be addressed to hello@shaventra.com from, or demonstrably on behalf of, the address concerned. The Company verifies identity proportionately, responds within thirty (30) days, levies no fee for a first request, and where it declines a request states the statutory ground in writing. Erasure requests are honoured except to the extent retention is required by law (Article 6.4) or for the establishment, exercise or defence of legal claims.
9.4 Escalation. A Data Principal dissatisfied with the Company’s response may approach the Data Protection Board of India in the manner provided by the DPDP Act; a Data Subject may lodge a complaint with the competent supervisory authority of their habitual residence, place of work or place of the alleged infringement.
10. Cookies and similar technologies
10.1 The Website sets no cookies of any category. The single localStorage value described in Article 3.3 is device-local, origin-scoped and untransmitted. The Company’s complete statement is the Cookie Policy at /legal/cookies/, incorporated herein by reference; in case of conflict on this subject, the Cookie Policy prevails.
11. Amendments; language; miscellany
11.1 This Policy is amended before, and never after, a change in processing operations takes effect. The version and effective date in the Document Control section identify the operative text; material amendments are signposted on this page for a reasonable period.
11.2 This Policy is published in English. Should Applicable Data Protection Law require availability in additional languages, the English text prevails to the extent of any inconsistency with a translation, save where that law provides otherwise.
11.3 This Policy is a statement of the Company’s practice designed to address the requirements of Applicable Data Protection Law. It does not constitute legal advice to any reader, and confers no contractual rights beyond those conferred by that law and the Terms of Service.