Questions about our policies? Email team@vedvika.com
Home Legal
Legal Documents

Privacy Policy &
Terms of Service

DPDP Act 2023 Compliant IT Act 2000 & 2008 Effective: 1 January 2025
Version 2.0
Last updated
01 Jan 2025
India's Digital Personal Data Protection Act, 2023
This Privacy Policy is drafted in compliance with India's Digital Personal Data Protection (DPDP) Act, 2023, the Information Technology Act, 2000 (as amended in 2008), and the IT (Reasonable Security Practices and Procedures) Rules, 2011. It applies to all personal data processed by Vedvika Technologies Pvt. Ltd. in connection with our website, services, and products.
Section 01

Data Fiduciary — Who We Are

Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), Vedvika Technologies Pvt. Ltd. is the Data Fiduciary responsible for determining the purpose and means of processing your personal data.

DetailInformation
Registered NameVedvika Technologies Pvt. Ltd.
Registered OfficeB-140, First Floor, iThum Tower, Noida, Uttar Pradesh, India
Data Protection OfficerVinod Kumar Suryavanshi — team@vedvika.com
Grievance OfficerVinod Kumar Suryavanshi — team@vedvika.com
Contact+91 78386 00519
Websitevedvika.com
Section 02

Personal Data We Collect

We collect only the personal data that is necessary for the specified purpose — a core principle under Section 6 of the DPDP Act. We do not collect personal data beyond what is required to provide our services.

Data you provide directly

Data TypePurposeLegal Basis
Full nameProject enquiry and service deliveryConsent
Business email addressCommunications, service deliveryConsent
Phone numberDirect communication (optional)Consent
Company / organisation nameProject scoping and invoicingConsent
Project descriptionResponding to enquiriesConsent
Payment informationInvoicing (processed by payment gateway)Contract

Data collected automatically

Data TypePurposeRetention
IP addressSecurity monitoring, abuse prevention90 days
Browser type & versionTechnical compatibilitySession
Pages visited, time on pageWebsite improvement (anonymised)13 months
Referring URLMarketing attribution13 months
Device typeResponsive design optimisationSession
We do not collect Sensitive Personal Data
We do not collect or process any Sensitive Personal Data or Information (SPDI) as defined under the IT (Reasonable Security Practices) Rules, 2011, including passwords, financial information beyond invoicing, health data, biometric data, or caste or religious beliefs.
Section 03

Lawful Basis for Processing

Under the DPDP Act 2023, we process personal data only on valid legal grounds. We rely on the following bases:

  • Consent (Section 6, DPDP Act): Where you submit an enquiry form, contact us, or subscribe to communications. You may withdraw consent at any time by emailing us at team@vedvika.com.
  • Legitimate Uses (Section 7, DPDP Act): For compliance with legal obligations, employment-related processing, and responding to medical emergencies.
  • Contractual Necessity: To fulfil obligations under a signed engagement agreement or service contract.
  • Legal Obligation: Where processing is required under applicable Indian law, including tax records, audit requirements, and responses to lawful government orders.
Section 04

How We Use Your Personal Data

  • To respond to project enquiries, consultation requests, and support tickets.
  • To deliver contracted software development, cybersecurity, or AI services.
  • To issue invoices and process payments in connection with service agreements.
  • To send transactional communications directly related to your project or service.
  • To improve website performance and user experience using anonymised analytics.
  • To comply with applicable laws, regulations, and government directions.
  • To detect, investigate, and prevent fraudulent activity and security incidents.
We do not sell or rent your personal data
Vedvika Technologies does not sell, rent, trade, or share your personal data with third parties for their own marketing purposes. We do not engage in any data monetisation activities.
Section 05

Data Sharing & Disclosure

We may share personal data only in the following limited circumstances:

RecipientPurposeSafeguards
Payment gateways (e.g. Razorpay, PayU)Payment processingPCI-DSS compliant; data minimisation
Cloud service providers (e.g. AWS, hosting)Infrastructure & email deliveryData Processing Agreements in place
Analytics tools (anonymised only)Website improvementNo personally identifiable data shared
Legal authoritiesCompliance with law, court ordersOnly upon verified lawful demand
Professional advisorsLegal, accounting, audit servicesBound by professional confidentiality

All third-party processors with whom personal data is shared are required to maintain appropriate technical and organisational security measures and process data only as instructed.

Section 06

Cross-Border Data Transfer

Some of our service providers (such as cloud infrastructure providers) may process data outside India. Under Section 16 of the DPDP Act, cross-border transfers of personal data are permitted to countries notified by the Central Government as having adequate data protection standards.

Where such transfers occur, we ensure that appropriate contractual safeguards are in place, including Standard Contractual Clauses or equivalent mechanisms, and that the receiving entity provides a level of protection equivalent to that required under the DPDP Act.

Section 07

Data Retention

Under Section 8(7) of the DPDP Act, we retain personal data only for as long as it is necessary for the specified purpose or as required by law. We do not retain personal data indefinitely.

Data CategoryRetention PeriodBasis
Project enquiry data (non-converted)24 months from submissionLegitimate interest
Client project data (engaged clients)Duration of engagement + 7 yearsLegal obligation (tax, audit)
Payment and invoicing records7 years from transaction dateCompanies Act, GST Act
Website analytics data13 months, then anonymisedLegitimate interest
Security logs and incident records3 yearsIT Act 2000, security compliance
Email communicationsDuration of relationship + 3 yearsContractual necessity

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised such that it can no longer be attributed to an identified individual.

Section 08

Your Rights as a Data Principal

Under Chapter III of the DPDP Act, 2023, you have the following rights as a Data Principal. We are committed to facilitating these rights without undue delay and without charge (unless requests are manifestly unfounded or excessive).

Right of Access (Section 11)
You may request a summary of the personal data we hold about you and the processing activities performed on it.
Right to Correction & Completion (Section 12)
You may request correction of inaccurate personal data and completion of incomplete personal data we hold about you.
Right to Erasure (Section 12)
You may request deletion of your personal data where the purpose for processing has been served or consent is withdrawn, subject to legal retention obligations.
Right to Withdraw Consent (Section 6)
Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Right to Grievance Redressal (Section 13)
You may lodge a grievance with our Grievance Officer and, if unsatisfied, escalate to the Data Protection Board of India established under the DPDP Act.
Right of Nomination (Section 14)
You may nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, please submit a written request to our Grievance Officer at team@vedvika.com with the subject line "DPDP Rights Request". We will respond within 30 days of receiving a valid request, as required under the DPDP Act.

Section 09

Data Security Measures

As a cybersecurity engineering company, we hold ourselves to a higher standard than the minimum requirements of the IT (Reasonable Security Practices) Rules, 2011. Our security practices include:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. We enforce HTTPS across all services.
  • Encryption at rest: Personal data stored in our databases and cloud storage is encrypted at rest using AES-256 or equivalent standards.
  • Access controls: Access to personal data is restricted to authorised personnel on a strict need-to-know basis. Role-based access control is enforced across all systems.
  • Audit trails: All access to personal data is logged. Audit logs are retained for 3 years and reviewed periodically.
  • Vulnerability management: Our systems undergo regular vulnerability assessments and penetration testing — the same discipline we apply to client systems.
  • Incident response: We maintain a documented Incident Response Plan. In the event of a data breach, we will notify affected Data Principals and the Data Protection Board within the timeframes prescribed under the DPDP Act.
  • Vendor security: All data processors and sub-processors are assessed for security compliance before engagement and are contractually bound to maintain appropriate security measures.
TLS 1.2+ Enforced AES-256 Encryption at Rest Role-Based Access Control Regular VAPT Documented Incident Response IT Rules 2011 Compliant
Section 10

Processing of Children's Personal Data

Under Section 9 of the DPDP Act, we do not knowingly collect personal data from individuals under 18 years of age without verifiable parental or guardian consent. Our services are designed for businesses, enterprises, and adult professionals, and are not directed at children.

If we become aware that personal data of a minor has been collected without appropriate consent, we will take immediate steps to delete such data. If you believe a minor's data has been submitted to us, please contact our Grievance Officer immediately.

Exception: Disha LMS
Where our Disha LMS product is deployed by educational institutions and may involve student data including minors, the institution operates as an independent Data Fiduciary under the DPDP Act. Vedvika Technologies acts as a Data Processor and processes such data only under the documented instructions of the institution, which is responsible for obtaining necessary parental consents and complying with Section 9 obligations.
Section 11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, applicable law, or the DPDP Act's implementing rules as notified by the Ministry of Electronics and Information Technology. The date of the most recent revision appears at the top of this page.

Where changes are material, we will notify affected Data Principals by email (where we hold your contact details) at least 14 days before the changes take effect, and will obtain fresh consent where required by the DPDP Act. Continued use of our services after the effective date of changes constitutes acceptance of the revised policy, except where fresh consent is legally required.

Section 12

Grievance Officer & Escalation

Under Rule 5 of the IT (Reasonable Security Practices and Procedures) Rules and Section 13 of the DPDP Act, we have designated a Grievance Officer to address privacy-related complaints and requests.

ContactDetails
NameVinod Kumar Suryavanshi
DesignationGrievance Officer & Data Protection Officer
Emailteam@vedvika.com
Phone+91 78386 00519
AddressB-140, First Floor, iThum Tower, Noida, UP
Response TimeWithin 30 days of receipt

If you are not satisfied with the response from our Grievance Officer, you may lodge a complaint with the Data Protection Board of India (to be established under the DPDP Act) or approach the appropriate judicial or quasi-judicial authority under Indian law.

Privacy Questions?
Reach our Grievance Officer directly
We respond to all privacy requests within 30 days as mandated by the DPDP Act, 2023.
Email Us
Governing Law
These Terms of Service are governed by and construed in accordance with the laws of the Republic of India, including the Information Technology Act, 2000, the Indian Contract Act, 1872, the Consumer Protection Act, 2019, and other applicable statutes. All disputes are subject to the exclusive jurisdiction of the courts in Noida, Uttar Pradesh, India.
Section 01

Agreement to Terms

By accessing our website at vedvika.com, submitting an enquiry, entering into a project agreement, or using any Vedvika Technologies product or service, you ("Client", "User", or "Data Principal") agree to be bound by these Terms of Service ("Terms").

If you do not agree with any part of these Terms, you must not use our website or services. These Terms constitute a legally binding agreement between you and Vedvika Technologies Pvt. Ltd. ("Vedvika", "we", "us", or "our").

Section 02

Services We Provide

Vedvika Technologies provides the following categories of services, subject to a separate written engagement agreement or Statement of Work (SOW) in each case:

  • Custom software development — web applications, mobile applications, API systems, and cloud-native platforms
  • Cybersecurity services — vulnerability assessments, penetration testing (VAPT), infrastructure hardening, and security monitoring
  • AI and automation solutions — machine learning model development, workflow automation, LLM integration, and data pipelines
  • Licensed software products — CloudV24, AdvanceExcel, Disha, MIS 17000ft, ExcelAnt
  • Consultation, advisory, and technical audit services

The specific scope, deliverables, timelines, and commercial terms for each engagement are defined in a written agreement signed by both parties. In the event of conflict between these Terms and a signed agreement, the signed agreement shall prevail.

Section 03

Client Obligations

By engaging Vedvika Technologies, you agree to:

  • Provide accurate, complete, and timely information necessary for service delivery
  • Ensure you have authority to authorise penetration testing, security assessments, or system access granted to us
  • Pay invoices within the agreed payment terms (typically net-15 unless otherwise specified)
  • Not use our services for unlawful purposes, including activities that violate the IT Act, IPC, or other applicable Indian law
  • Not engage our team in activities designed to harm third parties, including but not limited to offensive cyberattacks against systems you do not own or have authorisation to test
  • Maintain confidentiality of any credentials, API keys, or access provisioned by Vedvika for project purposes
  • Provide written authorisation before any penetration test or vulnerability assessment commences
Section 04

Intellectual Property

Custom deliverables

Unless otherwise specified in a signed engagement agreement, intellectual property rights in custom-developed software, code, and deliverables created specifically for a client project vest in the client upon receipt of full payment. During the project, all work product remains the property of Vedvika Technologies.

Vedvika proprietary technology

All intellectual property rights in Vedvika's proprietary frameworks, tools, libraries, methodologies, know-how, and pre-existing technology ("Background IP") remain exclusively with Vedvika Technologies. Use of Background IP in client deliverables constitutes a limited, non-exclusive, non-transferable licence to use that Background IP solely within the delivered system.

Licensed products

Software products (CloudV24, AdvanceExcel, Disha, MIS 17000ft, ExcelAnt) are licensed, not sold. Licence terms specific to each product are provided in the relevant Product Licence Agreement, which forms part of the engagement agreement.

Website content

All content on vedvika.com — including text, graphics, logos, design elements, and code — is the intellectual property of Vedvika Technologies and is protected under the Copyright Act, 1957. Reproduction or use without written permission is prohibited.

Section 05

Confidentiality

Both parties acknowledge that in the course of an engagement, each may receive Confidential Information belonging to the other. "Confidential Information" includes technical specifications, business plans, financial information, client data, security findings, and any information marked or reasonably understood to be confidential.

  • Each party agrees to hold the other's Confidential Information in strict confidence and not to disclose it to any third party without prior written consent
  • Confidentiality obligations survive the termination of the engagement for a period of 5 years
  • Security assessment reports, penetration test findings, and vulnerability disclosures are treated as Highly Confidential and subject to enhanced handling requirements
  • Vedvika Technologies treats all client enquiries — including those that do not proceed to engagement — as confidential by default
Section 06

Payment Terms & Invoicing

Payment terms for all engagements are defined in the signed agreement. Standard terms unless otherwise agreed:

MilestoneStandard Payment
Project commencement30–50% advance (depending on project size)
Mid-project milestone30–40% (as defined in SOW)
Final deliveryRemaining balance, due within 15 days of delivery

All invoices are subject to applicable GST as per Indian tax laws. Late payments accrue interest at 1.5% per month on the outstanding balance. Vedvika reserves the right to suspend service delivery for invoices overdue by more than 30 days.

Section 07

Limitation of Liability

To the fullest extent permitted by applicable Indian law:

  • Vedvika Technologies' total liability to any client, in aggregate, shall not exceed the total fees paid by that client in the 12 months preceding the claim
  • We shall not be liable for any indirect, incidental, consequential, or punitive damages, including loss of profits, data, or business opportunities, even if advised of the possibility of such damages
  • Nothing in these Terms limits liability for fraud, wilful misconduct, death or personal injury caused by negligence, or any liability that cannot lawfully be excluded under Indian law
  • For cybersecurity services, our liability is limited to the scope defined in the written engagement agreement and the authorised test environment. We are not liable for systems, vulnerabilities, or attack surfaces outside the agreed scope
Penetration Testing — Important Limitation
Security assessments and penetration tests are point-in-time exercises. A clean test result does not guarantee that systems are free from all vulnerabilities or will remain secure against future threats. Clients are responsible for implementing recommended remediations and maintaining ongoing security hygiene.
Section 08

Termination

  • By mutual agreement: Either party may terminate an engagement by mutual written consent, with agreed settlement of fees for work completed
  • For breach: Either party may terminate with 14 days' written notice if the other party commits a material breach that is not remedied within the notice period
  • For non-payment: Vedvika may terminate immediately if payment is not received within 45 days of the due date, after written notice
  • By Vedvika for legal or ethical reasons: We reserve the right to terminate any engagement immediately if we become aware that our services are being used for unlawful purposes, to harm third parties, or in ways inconsistent with our values

Upon termination, each party shall return or destroy the other's Confidential Information within 30 days. Provisions relating to IP, confidentiality, payment, and dispute resolution survive termination.

Section 09

Dispute Resolution

In the event of a dispute arising out of or in connection with these Terms or any engagement:

  • Step 1 — Good faith negotiation: The parties shall first attempt to resolve the dispute amicably through direct negotiation within 30 days of written notice of the dispute
  • Step 2 — Mediation: If negotiation fails, the parties agree to submit the dispute to mediation administered by a mutually agreed mediator in Noida, UP
  • Step 3 — Arbitration: If mediation fails within 45 days, disputes shall be finally resolved by arbitration under the Arbitration and Conciliation Act, 1996, with the seat and venue in Noida, UP, India. The arbitration shall be conducted in English
  • Courts: Both parties submit to the exclusive jurisdiction of the courts in Noida, Uttar Pradesh, India for interim relief and enforcement of arbitral awards
Section 10

Prohibited Conduct

When using our website or services, you must not:

  • Use our services to conduct cyberattacks on systems you do not own or lack written authorisation to test — this constitutes an offence under Section 66 of the IT Act, 2000
  • Attempt to gain unauthorised access to our systems, servers, or databases
  • Introduce malware, ransomware, or any malicious code into systems under our management
  • Use our services to process, store, or transmit personal data in violation of the DPDP Act 2023
  • Misrepresent your identity or authority when engaging our security assessment services
  • Reproduce, reverse-engineer, decompile, or disassemble any Vedvika proprietary software product
Security-First Engineering Company
As a cybersecurity engineering firm, we hold ourselves to the same standards we recommend to clients. This document describes our internal security practices — not as a marketing statement, but as a commitment we are accountable to.
Section 01

Infrastructure Security

  • Hosting: All production systems are hosted on tier-1 cloud providers (AWS / equivalent) with SOC 2 Type II certified data centres in India or approved jurisdictions
  • Network hardening: Servers are configured with minimal open ports. Only ports 80, 443, and a non-standard SSH port are permitted inbound. All other traffic is blocked at the firewall level
  • SSH access: All server access requires SSH key authentication. Password-based SSH login is disabled on all production systems
  • Automated patching: Operating system and application security patches are applied within 72 hours of release for critical vulnerabilities, and within 30 days for non-critical patches
  • Intrusion detection: Wazuh-based HIDS is deployed on production servers. Alerts are triaged within our defined incident response window
  • DDoS protection: Production services are deployed behind Cloudflare or equivalent DDoS mitigation services
Section 02

Application Security

  • OWASP Top 10: All applications we develop are assessed against the OWASP Top 10 Web Application Security Risks before deployment
  • Input validation: All user-supplied input is validated and sanitised server-side. Parameterised queries are mandatory — raw SQL string concatenation is prohibited in our codebase standards
  • Authentication: All production systems use bcrypt or Argon2 for password hashing. Plain-text password storage is strictly prohibited
  • Session management: Session tokens are generated using cryptographically secure random number generators. Session expiry and regeneration on privilege change are enforced
  • HTTPS enforcement: HSTS is enforced on all production domains. HTTP traffic is permanently redirected to HTTPS. TLS 1.0 and 1.1 are disabled
  • Security headers: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy headers are configured on all web-facing applications
  • Dependency management: Third-party dependencies are scanned for known vulnerabilities using automated tooling. Vulnerable dependencies are updated or replaced within defined SLAs
Section 03

Access Control & Identity

  • Least privilege principle: Every team member has access only to the systems and data strictly necessary for their role. Excessive permissions are reviewed and revoked on a quarterly basis
  • Multi-factor authentication: MFA is mandatory for all team members accessing production systems, cloud consoles, and internal tooling
  • Privileged access management: Root / administrator credentials are stored in a password manager with MFA. Shared credentials are prohibited
  • Offboarding: All system access is revoked within 4 hours of a team member's departure. Credential rotation follows immediately
  • Client access: Temporary access credentials provisioned for client projects are rotated after project completion and never reused
Section 04

Secure Development Lifecycle (SDLC)

PhaseSecurity Activity
RequirementsThreat modelling, security requirements definition, risk assessment
DesignSecure architecture review, data flow analysis, trust boundary mapping
DevelopmentSecure coding standards, peer code review with security checklist
TestingSAST, DAST, dependency scanning, OWASP Top 10 assessment
Pre-deploymentInternal VAPT, security sign-off by security team lead
ProductionSecurity monitoring, anomaly detection, vulnerability management
MaintenancePatch management, periodic re-assessment, incident response
Section 05

Incident Response

We maintain a documented Incident Response Plan (IRP) aligned with CERT-In guidelines and the reporting requirements of the DPDP Act, 2023. Our response process follows these phases:

  • Detection & identification: Automated monitoring triggers alerts. Security team acknowledges within 1 hour of alert during business hours; 4 hours outside business hours
  • Containment: Affected systems are isolated to prevent lateral movement within 2 hours of confirmed incident
  • Eradication: Root cause identified, malicious artefacts removed, vulnerability patched
  • Recovery: Systems restored from clean backups or rebuilt. Business continuity maintained where possible
  • Notification: Affected clients notified within 24 hours of confirmed breach confirmation. Personal data breach notifications submitted to the Data Protection Board per DPDP Act timelines
  • Post-incident review: Written post-mortem conducted within 7 days. Lessons learned incorporated into security controls
Responsible Disclosure
If you discover a security vulnerability in any Vedvika Technologies system or product, please disclose it responsibly by emailing team@vedvika.com with "Security Disclosure" in the subject line. We will acknowledge within 48 hours and aim to patch within 30 days for critical findings. We commit to not taking legal action against good-faith security researchers who follow responsible disclosure principles.
Section 06

Compliance Framework

Our security practices are aligned with the following frameworks and standards:

DPDP Act 2023 IT Act 2000 & Rules 2011 CERT-In Guidelines OWASP Top 10 NIST Cybersecurity Framework ISO 27001 Aligned CIS Benchmarks CVSS Scoring
Plain-language Cookie Notice
This Cookie Policy explains what cookies are, which ones we use on vedvika.com, why we use them, and what choices you have. India's DPDP Act 2023 requires us to obtain consent for processing personal data, which may include data derived from non-essential cookies.
Section 01

What Are Cookies?

Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work, work more efficiently, and to provide information to website owners. Cookies can be "session" cookies (deleted when you close your browser) or "persistent" cookies (remaining on your device for a set period).

In addition to cookies, we may use similar technologies such as web beacons, pixels, and local storage for comparable purposes. All such technologies are referred to as "cookies" in this policy.

Section 02

Cookies We Use

Category Name / Provider Purpose Duration Consent?
Strictly Necessary Session cookie Maintains session state, CSRF protection Session Not required
Strictly Necessary Cookie preference Remembers your cookie consent choice 12 months Not required
Functional vdv_announce_closed Remembers if you closed the announcement banner Session Consent
Analytics Google Analytics (_ga, _gid) Anonymised website usage statistics Up to 13 months Consent
Analytics Hotjar (if enabled) Session recording and heatmaps (anonymised) 12 months Consent
No advertising or tracking cookies
Vedvika Technologies does not use any advertising cookies, remarketing pixels, or cross-site tracking technologies. We do not build user profiles for advertising purposes or share cookie data with ad networks.
Section 03

Your Cookie Choices

You have the following options to control cookies:

  • Browser settings: Most browsers allow you to block or delete cookies through their settings. Note that blocking all cookies may affect website functionality. Consult your browser's help documentation for instructions
  • Google Analytics opt-out: You may opt out of Google Analytics tracking using the Google Analytics Opt-out Browser Add-on
  • Withdraw consent: To withdraw consent for non-essential cookies, email us at team@vedvika.com. We will delete any personal data collected through those cookies from our systems
Section 04

Third-Party Cookies

Where third-party cookies are used (such as Google Analytics), the third-party service provider sets and reads those cookies according to their own privacy policies. We are not responsible for the practices of third-party cookie providers. We encourage you to review:

Section 05

Questions About Cookies

If you have any questions about our use of cookies or wish to exercise your rights in relation to data processed through cookies, please contact our Grievance Officer at team@vedvika.com.

Questions? Concerns?
Our team responds within 30 days
All legal, privacy, and cookie enquiries are handled by our Grievance Officer.
Email Us