Global Privacy Policy
Last Updated & Effective Date: October 6, 2026 · Compliant with GDPR, UK GDPR, CCPA/CPRA & India DPDP Act 2023
1. Data Controller & Scope
This Privacy Policy describes how Pravariq Studio (operated by Sameer Chaturvedi from Sitapura Industrial Area, Jaipur, Rajasthan 302022, India, acting as "Data Controller" under GDPR and "Data Fiduciary" under the India DPDP Act 2023, hereinafter "Studio", "We", "Us", or "Our") collects, uses, processes, stores, and safeguards personal data obtained from visitors, prospective clients, and commercial partners interacting with https://studio.pravariq.in and related communication channels.
2. Categories of Personal Data We Collect
Name, business name, corporate email address, telephone/WhatsApp contact details, project scope notes, and technical requirements voluntarily submitted via our website contact interfaces or direct communication channels.
Billing entity name, registered office address, tax identification numbers (VAT, GSTIN, EIN), international wire transfer reference numbers, and bank-issued e-FIRA confirmation advice necessary to reconcile cross-border export compliance under RBI FEMA Purpose Code P0802.
IP addresses, browser type, operating system version, referring URL, time stamp, and edge server access logs collected automatically by our hosting infrastructure solely for security mitigation, DDoS prevention, and rate-limiting.
We do NOT collect sensitive personal data such as biometric data, racial/ethnic origin, religious beliefs, health records, or credit/debit card numbers. All payments are processed via client-initiated bank wire.
3. Lawful Basis for Processing (GDPR Article 6)
We process your personal information strictly under the following lawful bases recognized under Article 6 of the General Data Protection Regulation (GDPR / UK GDPR):
- Contractual Performance (Art. 6(1)(b)): Processing necessary to prepare engineering proposals, generate pro-forma invoices, execute written Statements of Work, and deliver bespoke digital software.
- Legal & Regulatory Obligation (Art. 6(1)(c)): Processing required to maintain statutory accounting, taxation, and export documentation mandated by the Reserve Bank of India (RBI), Indian Income Tax Department, and GST authorities.
- Legitimate Interests (Art. 6(1)(f)): Processing necessary to protect our technical infrastructure from cyberattacks, prevent fraudulent wire transfers, and maintain server reliability.
4. International Cross-Border Data Transfers
Because the Studio operates its core engineering and financial operations in Jaipur, India, personal data provided by clients in the European Economic Area (EEA), United Kingdom, or Canada is transferred to and stored in India. Where personal data is transferred from the EEA or UK to India, we implement appropriate safeguards in compliance with Chapter V of the GDPR, including Standard Contractual Clauses (SCCs), end-to-end TLS 1.3 cryptographic transit encryption, and restricted internal access controls.
5. Cookies & Tracking Technologies
Privacy-First Architecture (No Third-Party Ad Trackers):
Pravariq Studio does NOT deploy third-party advertising cookies, cross-site behavioral tracking pixels, or invasive remarketing scripts. The website employs only essential technical local storage mechanisms (such as active currency preference and dark mode state) necessary to render the user interface.
6. Data Retention Period
We retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was gathered. Technical server logs are purged after thirty (30) days. Project source code archives, invoices, bank wire receipts, and contractual communications are retained for seven (7) years following project completion in strict adherence to statutory Indian tax, GST, and RBI foreign exchange recordkeeping regulations.
7. Your Global Legal Rights
You possess the right to: (a) request access to your personal data; (b) request rectification of inaccurate data; (c) request erasure of your data ("right to be forgotten"), subject to statutory tax retention duties; (d) restrict or object to processing; (e) request data portability; and (f) lodge a formal complaint with your local data protection supervisory authority (such as the UK Information Commissioner's Office - ICO).
Under the California Consumer Privacy Act (CCPA/CPRA): We explicitly declare that we do NOT sell, rent, or share personal information with third-party data brokers. You have the right to request disclosure of categories of data collected, request deletion, and exercise rights free from commercial discrimination.
Indian data principals enjoy the right to access a summary of personal data processed, seek correction or completion of incomplete data, obtain erasure, nominate a representative in the event of death/incapacity, and access our Grievance Redressal mechanism.
8. Data Security Measures
We implement industry-standard technical and organizational security controls to safeguard personal data against unauthorized disclosure, interception, or destruction, including:
- Strict HTTPS/TLS 1.3 transit encryption on all domains.
- Hardened edge infrastructure and firewalled DNS.
- Confidential pro-forma invoice distribution with masked bank coordinates.
- Encrypted offline storage of client code repositories and contracts.
9. Grievance Officer & Data Inquiries
To exercise any of your statutory rights or submit a privacy inquiry, please contact our designated Grievance Officer:
Pravariq Studio · Privacy & Grievance Department
Appointed Officer: Sameer Chaturvedi
Address: Sitapura Industrial Area, Jaipur, Rajasthan 302022, India
Direct WhatsApp / Phone: +91 95218 01605
Privacy Email: pravariq@gmail.com
Formal requests are processed within thirty (30) calendar days as required by law.