Legal & Data Protection

Privacy Policy

Atharv SecureTech Private Limited is committed to managing your personal data transparently, securely, and in strict compliance with India's Digital Personal Data Protection Act, 2023.

Website

Atharv SecureTech Private Limited — Privacy Policy

Last updated: July 2026 · CIN: U62091TS2025PTC204537

Atharv SecureTech Private Limited ("we", "us", "our") respects your privacy. This Privacy Policy explains what personal data we collect and why, across our website (atharvsecuretech.com) and our general dealings with customers, job applicants, and business contacts. If you use one of our products, such as Atharv Vault, that product's own Privacy Policy governs the specifics of how it handles your data — this section covers the Company more broadly, and the two are consistent with each other.

1. Information We Collect

  • Website visitors: Standard technical data (such as IP address and browser type) and any information you choose to submit through a contact or enquiry form, plus cookies as described in our Cookie Policy.
  • Customers and product users: Account details such as your email address, and any information specific to the product you use — described in that product's own Privacy Policy.
  • Job applicants: Your CV, cover letter, and any information you provide during a hiring process.
  • Business contacts and vendors: Contact details and information exchanged in the course of a business relationship.

2. How We Use Your Information

To respond to enquiries, operate our products and services, run our hiring process, manage vendor and business relationships, and meet our legal and regulatory obligations. We do not sell personal data, and we do not use it for third-party advertising.

3. Legal Basis for Processing

We process personal data on the basis of your consent (for example, when you submit a form), the necessity of processing to perform a contract with you (for example, if you are a customer or a vendor), or our legitimate business interests and legal obligations, consistent with the Digital Personal Data Protection Act, 2023 ("DPDP Act").

4. Your Rights

Under the DPDP Act, and GDPR/UK GDPR where applicable, you have the right to access the personal data we hold about you, request its correction, and request its erasure — see our Account & Data Deletion Policy for how to make a request, or use our Data Subject Rights Request Form if we've provided one to you.

5. Data Sharing

We share personal data only where necessary — with hosting and email providers who help us run our website and products, with payment processors (Apple, Google, Razorpay, or Paddle) for purchases made through them, with RevenueCat, which we use solely to recognize and manage product subscription entitlements across platforms (it does not process payments itself), and with professional advisors where required. We do not sell personal data to third parties.

6. Data Retention

We retain personal data only for as long as necessary for the purpose it was collected for, or as required by law — for example, financial records are kept for the period mandated by Indian tax law.

7. Children's Data

Our website and products are not directed at, and may not be used by, anyone under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us using the details in Section 9.

8. International Data Transfers

Where personal data is transferred outside India — for example, to a hosting or payment provider with servers abroad — we take reasonable steps to ensure it continues to receive an appropriate level of protection.

9. Grievance Officer & Contact

In accordance with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, grievances relating to personal data processing may be directed to:

Grievance Officer: Dr. Manish Kumar
Designation: Director
Email: director@atharvsecuretech.com
Address: TBI, BITS Pilani, Hyderabad Campus, Secunderabad, Telangana, 500078, India

We aim to acknowledge and respond within 30 days of receipt, subject to the nature of the request and any statutory timelines.

For users in the European Union or United Kingdom: We have not yet appointed a representative under Article 27 of the GDPR/UK GDPR. Please use the Grievance Officer contact details above in the meantime.

10. Changes to This Policy

We may update this Privacy Policy as our operations evolve or as required by law. Material changes will be reflected by updating the "Last updated" date above.

Application Product

Atharv Vault — Privacy Policy

Last updated: July 2026 · Product-Specific Encryption Notice

Atharv SecureTech Private Limited (CIN: U62091TS2025PTC204537) (“we”, “us”, “our”) built Atharv Vault around a simple principle: we should never be able to see the contents of your files. This policy explains what limited information we do collect, why, and the rights you have over it under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, where applicable, the GDPR/UK GDPR.

1. What We Never See

Your files are encrypted and decrypted locally on your own device. In the standard encrypt/decrypt workflow, files never leave your device at all. For Secure Share, the encrypted file passes only between your device and the recipient's — our server stores a small delivery record, never the file, never your encryption password, and never any key that could unlock your file.

2. Information We Do Collect

  • Account data: Your email address and a securely hashed (never plaintext) password, used to sign in.
  • Encryption public keys: The public half of the key pair your device generates for Secure Share. Public keys are, by design, safe to store — they cannot be used to decrypt anything on their own.
  • Secure Share metadata: If you use Secure Share, we store the sender and recipient email, the original filename, an expiry time, and a one-time delivery record — never the file content or its password.
  • Activity log: A record of actions you take (e.g. “encrypted,” “decrypted,” “share received”) along with the filename, so you can review your own history in the Activity Log screen. This log does not include file contents.
  • Notifications: In-app alerts about your own account and Secure Share activity.
  • Technical/audit data: For security purposes, we log the IP address associated with certain sensitive requests (e.g. a Secure Share access attempt), kept separately from any cryptographic data.
  • Payment data: If you subscribe to Pro or Premium, payment details are handled entirely by Apple, Google, Razorpay, BillDesk, or Paddle depending on how you paid — we do not receive or store your card or bank details ourselves. We use RevenueCat to recognize and manage your subscription entitlement across these purchase channels; RevenueCat receives your purchase/subscription status but not your card or bank details.

3. How We Use Your Information

Strictly to operate the App: authenticating you, delivering Secure Share transfers, showing your own activity log and notifications back to you, enforcing your subscription plan's limits, and communicating important account or security notices (e.g. OTP codes, a Secure Share request). We do not sell your personal data, and we do not use it for third-party advertising.

4. Your Rights

Under the DPDP Act (and GDPR/UK GDPR where applicable), you have the right to access the personal data we hold about you, request its correction, and request its erasure. You can delete your account and associated data at any time from Settings within the App — see our separate Account & Data Deletion Policy for exactly what that removes. You may also raise a grievance using the contact details in Section 8.

5. Data Sharing

We share data only where necessary to run the App: with our hosting/database provider (to store the account and metadata described above), with our email provider (to deliver OTP and notification emails), with RevenueCat (to manage and verify your subscription entitlement across app stores and web checkout), and with Apple/Google/Razorpay/BillDesk/Paddle strictly for the purchase you make with them. We do not sell personal data to third parties, and we do not share the content of your files with anyone, because we never have it.

6. Data Breach Notification

If a personal data breach occurs that is likely to affect your rights or cause you harm, we will notify the Data Protection Board of India and affected users as required under the DPDP Act, 2023, without undue delay, along with the nature of the breach and steps being taken.

7. Children's Data

Atharv Vault is not directed at, and may not be used by, anyone under 18 years of age, consistent with the DPDP Act's definition of a child. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, please contact us using the details in Section 8 so we can remove it.

8. Grievance Officer & Contact

In accordance with the DPDP Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, grievances relating to personal data processing, security concerns about our services, or escalation under applicable Indian law may be directed to:

Grievance Officer: Dr. Manish Kumar
Designation: Director
Email: director@atharvsecuretech.com
Address for correspondence: TBI, BITS Pilani, Hyderabad Campus, Secunderabad, Telangana, 500078, India

We will acknowledge and endeavour to respond within 30 days of receipt, subject to the nature of the request and any statutory timelines.

For users in the European Union or United Kingdom: We have not yet appointed a representative under Article 27 of the GDPR/UK GDPR. If you are an EU/UK user with a data protection query in the meantime, please use the Grievance Officer contact details above.

9. Changes to This Policy

We may update this policy as the App evolves or as required by law. Material changes will be reflected by updating the “Last updated” date above, and, where appropriate, an in-app notice.