Privacy Policy
DPDP Act (2023) & Data Governance.
Zyvora is committed to responsible, transparent personal data processing in full compliance with the Digital Personal Data Protection Act (DPDP Act, 2023).
Notice under DPDP Act, 2023 (Section 5)
Our commitment to you as a Data Principal
When you interact with Zyvora or submit a project enquiry, you are the Data Principal, and Zyvora acts as the Data Fiduciary. We collect only the data necessary to evaluate your project, respond to your communications, and provide digital design and development services.
1. Notice & Categories of Data Collected
What personal data we collect.
In accordance with Section 5 of the DPDP Act, we inform you that we collect only the information you explicitly provide:
- Contact Identifiers: Name, business name, business email address, phone number (optional), and website URL.
- Project Briefs: Service interests, timeline preferences, project budget guidance, and scope messages.
- Technical Logs: IP address and standard HTTP request timestamps used strictly for security monitoring and rate-limiting abuse prevention.
2. Specified Purpose & Consent (Section 6)
How and why we process your data.
Your personal data is processed exclusively on the basis of your affirmative, verifiable consent for specific and lawful purposes:
- To evaluate project feasibility and deliver preliminary design, technical, or scoping proposals.
- To respond to your inquiries via email or scheduling calls.
- To maintain audit trails of consent as legally required under Indian privacy legislation.
We never sell, rent, or trade your personal data to third parties, nor do we enroll you in unsolicited marketing lists without separate opt-in consent.
3. Data Processors & Infrastructure
Where your data is processed.
Zyvora works with enterprise-grade data processors bound by strict security and confidentiality obligations:
MongoDB Atlas
Encrypted database storage (TLS 1.3 in-transit and AES-256 at-rest).
Cloudinary
Secure CDN media delivery for portfolio screenshots and public assets.
Brevo (Sendinblue SAS)
Encrypted transactional email routing for enquiry confirmations.
4. Your Rights as a Data Principal (Sections 11–14)
Your statutory rights under DPDP Act.
As a Data Principal, you possess the following enforceable rights:
Right to Access Information (Sec. 11)
You may request a summary of personal data held about you and identities of any data processors with whom it has been shared.
Right to Correction & Erasure / "Right to be Forgotten" (Sec. 12)
You may request that inaccurate data be updated or that your personal records be permanently erased from our databases.
Right of Grievance Redressal (Sec. 13)
You are entitled to readily available grievance redressal from our designated Data Protection & Grievance Officer.
Right to Nominate (Sec. 14)
You have the right to nominate an individual who will exercise your rights in the event of death or incapacity.
5. Grievance Redressal Mechanism & Officer
How to contact our Grievance Officer
Under Section 6(2) and Section 13 of the DPDP Act, 2023, if you wish to exercise your rights to access, update, withdraw consent, or request complete erasure of your data, contact our designated Grievance Redressal Officer:
Zyvora Grievance & Data Protection Desk
Email: zyvora.comp@gmail.com
Response SLA: Inquiries and erasure requests are acknowledged within 48 hours and processed within 30 days as required by law.
