Privacy Policy
Effective Date: 31 August 2026 · Last Updated: 31 August 2026
This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) and the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000 (as amended), and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
This document governs the collection, processing, storage, and protection of your personal data when you access neurobytesindia.com (the "Website") or engage with any services offered by Neuro Bytes (the "Data Fiduciary", "we", "us", or "our").
Table of Contents
- Definitions & Interpretation
- Data Fiduciary Information
- Personal Data We Collect
- Purpose & Lawful Basis of Processing
- Consent Mechanism
- Data Retention Policy
- Rights of Data Principals
- Disclosure & Third-Party Sharing
- Cross-Border Data Transfer
- Data Security Measures
- Cookies & Tracking Technologies
- Processing of Children's Data
- Data Breach Notification
- Grievance Redressal Mechanism
- Amendments to This Policy
- Governing Law & Jurisdiction
1. Definitions & Interpretation
Unless otherwise specified, the following terms shall carry the meanings ascribed to them under the DPDP Act, 2023 and the IT Act, 2000:
- "Data Principal" — The individual to whom the personal data relates. Where the individual is a child (below 18 years), the Data Principal includes the parent or lawful guardian. (Section 2(j), DPDP Act)
- "Data Fiduciary" — Any person or entity who, alone or in conjunction with other persons, determines the purpose and means of processing of personal data. In this context, Neuro Bytes acts as the Data Fiduciary. (Section 2(i), DPDP Act)
- "Data Processor" — Any person who processes personal data on behalf of a Data Fiduciary. (Section 2(k), DPDP Act)
- "Personal Data" — Any data about an individual who is identifiable by or in relation to such data. (Section 2(t), DPDP Act)
- "Processing" — Any wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure by transmission, dissemination, restriction, erasure, or destruction. (Section 2(x), DPDP Act)
- "Sensitive Personal Data or Information" (SPDI) — As defined under Rule 3 of the SPDI Rules, 2011, includes passwords, financial information, health data, biometric data, sexual orientation, and medical records.
- "Consent" — Free, specific, informed, unconditional, and unambiguous indication of the Data Principal's wishes by a clear affirmative action, signifying agreement to the processing of personal data for a specified purpose. (Section 6, DPDP Act)
2. Data Fiduciary Information
| Attribute | Details |
|---|---|
| Legal Entity Name | Neuro Bytes (Sole Proprietorship) |
| Founder & Proprietor | Ganga Sagar Shukla |
| Registered Address | Prayagraj, Uttar Pradesh, India |
| official@neurobytesindia.com | |
| Phone | +91-7791862398 |
| Website | neurobytesindia.com |
3. Personal Data We Collect
We collect and process the following categories of personal data, in accordance with Section 4 and Section 6 of the DPDP Act, 2023:
3.1 Data Provided Directly by You
- Identity Data: Full name, business name, designation
- Contact Data: Email address, WhatsApp number, phone number
- Business Data: Industry/vertical, website URL, business requirements communicated via audit request forms or consultation enquiries
- Communication Data: Content of emails, WhatsApp messages, and form submissions exchanged with us
3.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device identifiers, screen resolution
- Usage Data: Pages visited, time spent on pages, click-through data, referring URL, navigation paths
- Cookie & Tracker Data: Session cookies, persistent cookies, analytics pixels (refer to Section 11 for full cookie disclosure)
3.3 Data We Do Not Collect
We do not collect Sensitive Personal Data or Information (SPDI) as defined under Rule 3 of the SPDI Rules, 2011, including but not limited to: passwords, financial information (bank account, credit/debit card details), physical or mental health conditions, biometric data, sexual orientation, or medical records — unless explicitly and separately consented to for a specific, disclosed purpose.
4. Purpose & Lawful Basis of Processing
Under Section 4 of the DPDP Act, personal data shall be processed only for a lawful purpose for which the Data Principal has given consent, or for certain legitimate uses. We process your data for:
| Purpose | Lawful Basis (DPDP Act) |
|---|---|
| Responding to audit requests and contact form submissions | Consent (Section 6) |
| Delivering contracted services (web development, SEO, AEO, paid media management) | Performance of contract / Legitimate use (Section 7(a)) |
| Sending project updates, deliverables, and invoices | Legitimate use — contractual necessity (Section 7(a)) |
| Analytics and website performance optimisation | Consent (Section 6) via cookie consent |
| Compliance with legal obligations (tax, GST filings, CERT-In reporting) | Legal obligation (Section 7(c)) |
| Protecting our legal rights, enforcing terms of service | Legitimate use (Section 7(d)) |
We shall not process personal data for any purpose beyond what is disclosed herein without obtaining fresh, specific consent from the Data Principal.
5. Consent Mechanism
In compliance with Section 6 and Section 5 of the DPDP Act, 2023:
- Consent is obtained through clear affirmative action — submission of our contact/audit forms constitutes consent for the specified purposes described on the form and in this policy.
- Consent requests are presented in clear and plain language, with access available in English and Hindi, as required under Section 6(3) of the Act.
- Each consent request specifies the itemised description of personal data being collected and the specific purpose for which it will be processed, per Rule 3 of the DPDP Rules, 2025.
- You have the right to withdraw consent at any time with the same ease with which it was given (Section 6(4), DPDP Act). Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
- To withdraw consent, contact our Grievance Officer at the details provided in Section 14 below.
6. Data Retention Policy
In compliance with Section 8(7) of the DPDP Act, we retain personal data only for the duration necessary to fulfil the purpose for which it was collected:
| Data Category | Retention Period | Post-Retention Action |
|---|---|---|
| Audit request submissions | 12 months from submission date, or until the audit is delivered (whichever is later) | Erasure |
| Active client project data | Duration of engagement + 36 months for contractual and legal compliance | Anonymisation or erasure |
| Invoice and financial records | 8 years (as mandated by Income Tax Act, 1961 — Section 44AA and GST Act provisions) | Erasure per statutory cycle |
| Website analytics data | 26 months (aligned with Google Analytics default) | Auto-deletion |
| Communication logs (email, WhatsApp) | 24 months post-engagement or as required for dispute resolution | Erasure |
Upon expiry of the retention period, or upon a valid erasure request, data shall be erased — and the Data Fiduciary shall cause its Data Processors to erase such data — unless retention is mandated by applicable Indian law.
7. Rights of Data Principals
Under Chapter III of the DPDP Act, 2023 (Sections 11–14), you have the following enforceable rights:
- Right to Access Information (Section 11): You may request a summary of your personal data being processed by us, the processing activities undertaken, and the categories of third parties with whom your data has been shared.
- Right to Correction and Erasure (Section 12): You may request correction of inaccurate or misleading personal data, completion of incomplete data, and erasure of personal data that is no longer necessary for the purpose for which it was collected.
- Right to Grievance Redressal (Section 13): You may raise a grievance with our designated Grievance Officer. If your grievance remains unresolved, you may escalate the matter to the Data Protection Board of India.
- Right to Nominate (Section 14): You may nominate any individual to exercise your rights under this Act in the event of your death or incapacity, per the nomination procedures established under the DPDP Rules, 2025.
- Right to Withdraw Consent (Section 6(4)): You may withdraw your consent at any time. Upon withdrawal, we shall cease processing your data for the specified purpose within a reasonable timeframe, subject to contractual and legal obligations.
To exercise any of the above rights, please contact our Grievance Officer using the details in Section 14.
8. Disclosure & Third-Party Sharing
We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and under contractual obligations requiring equivalent data protection standards:
- Service Partners: The Rishi Effect (strategic brand partner) — for coordinated client engagements where you have separately engaged both entities.
- Technology Processors: Web hosting providers, cloud infrastructure (e.g., Vercel, Cloudflare), analytics platforms (e.g., Google Analytics), email service providers — acting strictly as Data Processors under written agreements per Section 8(2) of the DPDP Act.
- Advertising Platforms: Google Ads, Meta Ads — for campaign performance tracking where you have consented to remarketing or conversion tracking.
- Statutory Authorities: Government agencies, tax authorities (Income Tax Department, GST authorities), CERT-In, or courts of law — when disclosure is mandated under applicable law or in response to valid legal process.
We shall not sell, rent, or trade your personal data to any third party for their independent marketing purposes.
9. Cross-Border Data Transfer
Under Section 16 of the DPDP Act, 2023, personal data may be transferred outside India only to those countries or territories notified by the Central Government.
- Certain Data Processors engaged by us (e.g., Google LLC, Meta Platforms Inc., Cloudflare Inc.) may process data on servers located outside India.
- Such transfers are undertaken only where the receiving entity ensures a degree of data protection equivalent to the protections under Indian law, or where such transfer is to a country/territory notified under Section 16.
- Where the list of approved countries/territories has not yet been notified by the Central Government, we rely on contractual safeguards (Data Processing Agreements, Standard Contractual Clauses) to ensure adequate protection.
10. Data Security Measures
In compliance with Section 8(5) of the DPDP Act, 2023 and Rule 8 of the SPDI Rules, 2011 (requiring implementation of IS/ISO/IEC 27001 or equivalent standards), we implement the following reasonable security practices and procedures:
- Encryption: TLS 1.2+ encryption for all data in transit; AES-256 encryption for sensitive data at rest where applicable.
- Access Controls: Role-based access control (RBAC) with principle of least privilege for all internal systems handling personal data.
- Infrastructure Security: Hosting on platforms with SOC 2 Type II certification, DDoS protection, automated vulnerability scanning.
- Organisational Measures: Periodic internal security audits, staff awareness training on data handling obligations under DPDP Act.
- Incident Response: Documented incident response procedures aligned with CERT-In reporting obligations (within 6 hours of becoming aware of a cyber incident, per CERT-In Direction of 28 April 2022).
11. Cookies & Tracking Technologies
Our Website uses the following categories of cookies and similar tracking technologies:
| Category | Purpose | Duration | Provider |
|---|---|---|---|
| Strictly Necessary | Core website functionality, session management, CSRF protection | Session / 24 hours | First-party |
| Analytics | Aggregate usage statistics (page views, bounce rate, traffic sources) | Up to 26 months | Google Analytics (GA4) |
| Marketing / Remarketing | Conversion tracking, audience building for Google Ads and Meta Ads campaigns | Up to 12 months | Google Ads, Meta Pixel |
You may manage your cookie preferences through your browser settings. Disabling analytics and marketing cookies will not affect the core functionality of the Website. Note that where marketing/remarketing cookies are deployed, explicit consent is obtained in compliance with Section 6 of the DPDP Act.
12. Processing of Children's Data
In compliance with Section 9 of the DPDP Act, 2023:
- Our services are not directed at individuals below the age of 18 years.
- We do not knowingly collect personal data of children (persons below 18 years of age).
- If we become aware that personal data of a child has been processed without verifiable parental/guardian consent, we shall promptly erase such data in accordance with Section 9(1) of the Act.
- We do not engage in tracking, behavioural monitoring, or targeted advertising directed at children, in compliance with Section 9(3) of the Act.
13. Data Breach Notification
In the event of a personal data breach (as defined under Section 2(u) of the DPDP Act), we shall:
- Notify the Data Protection Board of India within the timeframe prescribed under Rule 7 of the DPDP Rules, 2025.
- Notify the affected Data Principal(s) about the nature of the breach, the categories of data affected, and the remedial measures undertaken — in the manner and timeframe prescribed by the Board.
- Report the incident to CERT-In within 6 hours of becoming aware of the incident, in compliance with CERT-In Direction dated 28 April 2022.
- Document the breach in our internal incident register including the facts, effects, and remedial actions taken, as required under Section 8(6) of the DPDP Act.
14. Grievance Redressal Mechanism
In compliance with Section 8(9), Section 8(10), and Section 13 of the DPDP Act, 2023, we have designated the following Grievance Officer to address your concerns regarding the processing of your personal data:
Grievance Officer: Ganga Sagar Shukla
Designation: Founder & Proprietor, Neuro Bytes
Email: sagar@neurobytesindia.com
Alternate Email: official@neurobytesindia.com
Phone: +91-7791862398
Address: Prayagraj, Uttar Pradesh, India
Response Time: We shall acknowledge your grievance within 48 hours of receipt, and endeavour to resolve it within 30 days from the date of receipt, in compliance with Rule 4(6) of the SPDI Rules, 2011 and the DPDP Rules, 2025.
If your grievance is not satisfactorily resolved within the prescribed timeframe, you may escalate your complaint to the Data Protection Board of India established under Section 18 of the DPDP Act, 2023.
15. Amendments to This Policy
- We reserve the right to amend or update this Privacy Policy at any time to reflect changes in our data processing practices, legal requirements, or regulatory guidance issued under the DPDP Act, 2023.
- Any material changes to this policy shall be communicated through a prominent notice on our Website and, where feasible, via direct communication to affected Data Principals.
- The "Last Updated" date at the top of this document shall be revised upon each amendment.
- Continued use of the Website after the publication of an amended policy constitutes acceptance of the updated terms, subject to your right to withdraw consent under Section 6(4) of the Act.
16. Governing Law & Jurisdiction
- This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of India, including but not limited to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 (as amended), and the SPDI Rules, 2011.
- Any disputes arising from or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts at Prayagraj, Uttar Pradesh, India.
- In matters pertaining to data protection enforcement, the Data Protection Board of India shall have adjudicatory jurisdiction as established under Section 18 of the DPDP Act, 2023.
This Privacy Policy was last reviewed and updated on 31 August 2026.
For questions regarding this policy, contact official@neurobytesindia.com.