Privacy Notice
The short version. We collect the least we need to run a DPDP compliance-management tool: who you are, how to reach you, what you record in the tool, and the technical records needed to keep it secure. We do not sell personal data. We do not show advertising. We do not use what you record to train AI models. The database is in Mumbai; outgoing email passes through a US company (Resend). You can ask us to show, correct or erase your data, and complain to us, and then to the Data Protection Board of India.
1. Two different roles
This matters because the law treats them differently.
| Role | When | What that means |
|---|---|---|
| Data Fiduciary (we decide why and how) | We handle personal data for our own purposes: your sign-up and account details, billing, messages you send us, website and service logs, security records. | This notice is our notice to you. We are responsible to you for it. |
| Data Processor (we act for our customer) | A customer organisation puts personal data into VERIDIAN DPDP — for example its staff, vendors, clients, students or parents — to manage its own DPDP work. | The customer is the Data Fiduciary and decides what is collected, why and for how long. We process it only on its behalf under our Terms. If you are one of those people, your main contact for your data is the organisation that gave us your details; we will help them help you. |
Who we are: SHOBHA KAMAL SOLUTIONS PRIVATE LIMITED, CIN U74999UP2017PTC098453, B-1105, Plot No. 14, Shipra Krishna Vista, Ahinsa Khand-1, Indirapuram, Ghaziabad, Uttar Pradesh 201014, India (the "Company", "we").
2. What we collect
| What | Examples | From whom / how |
|---|---|---|
| Account and contact details | Name, business email address, role, organisation name, phone (if given) | You, or the customer that invited you |
| Work records (Customer Data) | Jobs assigned to you, your answers and notes, dates, who confirmed or approved, fingerprints (hashes) of evidence, names of vendors or processors the customer lists, consent and parent-consent responses collected through the customer's pages | You, the customer and people it invites. Each change is written to a history that cannot be edited. |
| Email and delivery records | The emails we send you (for example the Monday email), whether they were delivered, opened links you used, unsubscribe choices | Our systems and our email provider. Open and click tracking on our sending domain is off. |
| Mail you send us | Messages and attachments sent to dpdp@veridian-aios.com, sender address, ticket number and category | You |
| Payment records | Invoice details and proof of payment you send us. We do not keep card numbers on this Service. | You |
| Technical and security data | IP address, browser type, date and time, pages requested, security and error logs | Automatically. Our hosting provider (Cloudflare) processes request data to deliver and protect the site and may set strictly security-related cookies. |
| AI work link activity | That a link was created, its level and expiry, what was read or changed through it, and when | Our systems |
We do not intentionally collect sensitive personal data such as health records, biometric data, passwords, identity-document images or financial credentials. Please do not enter them; describe them instead. The Service is not directed at children. Children's data reaches it only when a school or other customer, as Data Fiduciary, adds it or collects a parent's consent through the Service.
3. Why we use it, and on what basis
| Purpose | Basis |
|---|---|
| To set up your account, sign you in, give you the jobs and pages the customer has assigned you, send the weekly email and reminders, and keep the dated record | Your consent (and, for people added by an employer, processing for purposes of employment where the customer relies on it); performance of the service the customer has asked for |
| To answer you, give support, handle grievances and data requests, and keep the ticket record of them | Your request; legal obligation |
| To keep the Service secure, prevent misuse and fix faults | Our legitimate operation of the service and reasonable security safeguards required by law |
| To invoice and to meet tax, accounting and company-law duties | Legal obligation |
| To protect or defend legal rights, and to comply with lawful orders | Legal obligation; legal claims |
We do not use personal data for advertising, we do not sell it, and we do not use Customer Data to train artificial-intelligence models. We do not make decisions about you by automated means that have legal effect on you.
4. Who receives it
| Recipient | Why | Where |
|---|---|---|
| The customer organisation you are linked to (and, for a CA/CS/audit/legal firm, the client it serves, and the reverse) | It is their record | — |
| Supabase (database, authentication) | Hosting and storage | Mumbai, India (AWS ap-south-1) |
| Cloudflare | Website hosting, network security, routing of mail sent to dpdp@veridian-aios.com | Global network |
| Resend | Sending our emails to you; the content of those emails passes through its service | United States (its service; sending identity dpdp@veridian-aios.com) |
| Google (mailbox) | Our operator's mailbox that receives forwarded copies of mail sent to dpdp@veridian-aios.com | Google's network |
| Professional advisers, auditors, insurers | To advise us, under duties of confidence | India |
| Courts, the Data Protection Board of India, police and other authorities | Only where the law requires or a lawful order is received | India |
| A successor to the business | If we are restructured or sold, on the same terms as this notice | — |
| An AI provider chosen by a user | Only if a user hands an AI work link to their own AI assistant. That provider then acts for the user, under its own terms; it is not our sub-processor | The provider's location |
Transfers outside India are made under section 16 of the Digital Personal Data Protection Act, 2023, which allows them except to countries the Central Government restricts by notification. We will follow any restriction it notifies. We do not otherwise sell, rent or disclose personal data.
5. How long we keep it
- Account and work records: while the customer's account is active and the purpose continues. After the account ends we make the data available for export for 30 days and then delete or irreversibly de-identify it within a reasonable time, except what the law requires us to keep.
- Mail to dpdp@ and tickets: for as long as needed to deal with the matter and any follow-up, then deleted or de-identified, unless a grievance, dispute or legal duty needs them kept longer.
- Invoices and accounting records: for the period the tax and company laws require.
- Security and delivery logs: for a short operational period, and longer where the law requires logs to be kept (for example for a period after erasure under the DPDP Rules) or where needed for an investigation.
- Back-ups expire on their normal cycle.
6. How we protect it
We take reasonable security safeguards: encrypted connections; separation of one customer's data from another's enforced in the database; role-based access for our own staff on a need-to-know basis; an append-only history of changes; limited, expiring links for AI work; contracts with our providers. No system is perfectly secure and we cannot promise otherwise. If there is a personal data breach affecting data we hold, we will tell the customer concerned without undue delay and, for data we hold as a Data Fiduciary, the Data Protection Board and the people affected, as the law requires.
7. Your rights and how to use them
Under the Digital Personal Data Protection Act, 2023 you may: get a summary of the personal data we process about you and with whom we have shared it; ask us to correct or complete it; ask us to erase it (we will unless the law requires us to keep it or we need it for the purpose you agreed to); withdraw consent at any time, as easily as you gave it (the weekly email has an unsubscribe link; withdrawing does not undo what was lawfully done before); have your grievances answered; and nominate another person to exercise these rights if you die or cannot. To use a right, write to dpdp@veridian-aios.com with the subject Data request (or Grievance). We may ask you to prove who you are. If your data belongs to a customer's records, we may pass your request to that customer, who decides it; we will help.
- Grievance Officer. The Grievance Officer of the Company handles grievances at dpdp@veridian-aios.com (subject: Grievance). We aim to acknowledge promptly and to resolve within the time the law allows (and in any case within 90 days, sooner where the SPDI Rules' one-month period applies).
- Data Protection Board. You may complain to the Data Protection Board of India, but the law expects you to have first used our grievance process and given us the chance to respond.
- Complaints about a customer's handling of your data go first to that customer.
8. Cookies and similar tools
The public pages do not use advertising or cross-site tracking cookies. The signed-in application keeps a sign-in session in your browser and may store small items to remember your place. Our hosting provider may use cookies strictly necessary for security and performance. You can block cookies in your browser, but the signed-in application will not work without the sign-in session.
9. Changes
We will post changes here with a new date. For a change that materially affects how we use your data we will also tell you by email or in the Service, and ask for fresh consent where the law requires it.
10. Contact
dpdp@veridian-aios.com (subject: Grievance, Data request, Sales or Partner)
SHOBHA KAMAL SOLUTIONS PRIVATE LIMITED · CIN U74999UP2017PTC098453 · B-1105, Plot No. 14, Shipra Krishna Vista, Ahinsa Khand-1, Indirapuram, Ghaziabad, Uttar Pradesh 201014, India.