Privacy Policy

Tevrix Digital Solutions Private Limited

Effective Date: March 10, 2025

Last Updated: March 10, 2025

Version: 4.2 | Policy ID: PRIV-POL-2025-03

Executive Summary

This Privacy Policy governs the processing of personal data by Tevrix Digital Solutions Private Limited ("Company," "we," "us," "our") across our Software-as-a-Service (SaaS) platform, websites, and related services. We are committed to implementing privacy by design and by default principles in compliance with global data protection regulations including the GDPR, CCPA, PDPA, and India's Digital Personal Data Protection Act, 2023.

Transparency

Clear disclosure of data processing activities

Security

Enterprise-grade data protection measures

Control

User-centric data management options

1

Interpretation and Definitions

Core Definitions

Personal Data

Any information relating to an identified or identifiable natural person ('data subject'), including but not limited to name, identification number, location data, online identifier, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.

Processing

Any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.

Data Controller

The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Services

Collectively refers to our SaaS platform (tevrixplatform.com), associated websites, mobile applications, APIs, developer tools, and related offerings provided by Tevrix Digital Solutions.

2

Data Controller and Representative Information

Primary Controller

Company Name

Tevrix Digital Solutions Private Limited

Registration Number

CIN U72900KA2023PTC182345

Registered Office

Level 14, Tower C, Prestige Tech Park
Marathahalli, Bangalore
Karnataka 560103, India

Tax Identification

GSTIN 29AAKCS1823A1Z5

Data Protection Officer (DPO)

Name

Ms. Priya Sharma

Email

dpo@tevrixdigitalsolutions.com

Availability

Monday to Friday, 9:00 AM - 6:00 PM IST

EU/UK Representative (Article 27 GDPR)

For data subjects in the European Union and United Kingdom, our appointed representative is:

Global Privacy Solutions GmbH
Attn: Tevrix Digital Solutions EU Representative
Friedrichstraße 123, 10117 Berlin, Germany
Email: eu-representative@tevrixdigitalsolutions.com

4

Categories of Personal Data Processed

Comprehensive Data Inventory

Identity and Contact Data

Information establishing and authenticating your identity

Personal Identifiers
  • • Full legal name
  • • Email address
  • • Phone number
  • • User account credentials
Professional Information
  • • Job title and department
  • • Company/organization details
  • • Business email and phone
  • • Professional qualifications
Verification Data
  • • Government-issued ID (masked)
  • • Proof of address documents
  • • Tax identification numbers
  • • Business registration details

Technical and Usage Data

Information collected automatically through your interaction with our Services

Device Information
  • IP address (anonymized where required)
  • Browser type, version, and language settings
  • Operating system and device type
  • Screen resolution and display settings
  • Network connection type and speed
Usage Analytics
  • Pages visited and time spent
  • Feature usage patterns and frequency
  • Clickstream data and navigation paths
  • Error logs and crash reports
  • API request patterns and response times

Financial and Transactional Data

Information related to billing, payments, and commercial transactions

Billing Information

Secure Note: We use tokenized payment processing and do not store raw credit card numbers on our servers.

  • • Billing address and contact details
  • • Company tax information
  • • Purchase history and invoice records
  • • Subscription tier and plan details
Transactional Metadata
  • • Transaction IDs and timestamps
  • • Payment method preferences
  • • Currency and exchange rate information
  • • Refund and credit history
  • • Contractual agreement records

Content and Communication Data

Information you voluntarily provide through platform interactions

Important: We do not intentionally collect special category data (sensitive personal data). Users are advised not to upload or share sensitive information through our platform.

User-Generated Content
  • • Project data and workspace content
  • • File uploads and document storage
  • • Comments, annotations, and feedback
  • • Custom configurations and templates
Communication Records
  • • Support ticket conversations
  • • Email correspondence with our team
  • • Chat transcripts (with consent)
  • • Survey responses and feedback
5

Legal Basis for Processing

GDPR Compliance Framework

Processing ActivityLegal Basis (GDPR Article 6)Data CategoryConsent Management
Account creation and user authenticationPerformance of contract (1)(b)Identity DataRequired during signup
Service delivery and platform functionalityPerformance of contract (1)(b)Technical DataImplied through usage
Payment processing and billingPerformance of contract (1)(b)Financial DataRequired for paid services
Customer support and communicationLegitimate interests (1)(f)Communication DataOptional for marketing
Platform analytics and improvementLegitimate interests (1)(f)Usage DataGranular opt-in available
Marketing communicationsConsent (1)(a)Contact DataExplicit opt-in required
Security monitoring and fraud preventionLegal obligation (1)(c)Technical DataNot applicable
Compliance with legal requirementsLegal obligation (1)(c)VariousNot applicable

Legitimate Interests Assessment

Where we rely on legitimate interests, we conduct a formal balancing test considering:

  • Purpose necessity and proportionality
  • Impact on data subject rights
  • Data minimization and protection measures
  • Transparency and control mechanisms

Withdrawal of Consent

You may withdraw consent for processing activities based on consent at any time:

Via Account Settings → Privacy Controls
Email request to privacy@tevrixdigitalsolutions.com
Through preference center links in marketing emails

Note: Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

12

Data Subject Rights and Exercise Procedures

Comprehensive Rights Framework

Under applicable data protection laws including GDPR, CCPA/CPRA, and India's DPDP Act, you have specific rights regarding your personal data. We are committed to facilitating the exercise of these rights.

🔍

Right of Access

Response time: 30 days

Obtain confirmation and copy of personal data being processed

✏️

Right to Rectification

Response time: 30 days

Request correction of inaccurate or incomplete data

🗑️

Right to Erasure

Response time: 30 days

Request deletion of personal data under certain conditions

⏸️

Right to Restriction

Response time: Immediate

Limit processing of data in specific circumstances

📤

Right to Data Portability

Response time: 30 days

Receive data in structured, commonly used format

🚫

Right to Object

Response time: 30 days

Object to processing based on legitimate interests

↩️

Right to Withdraw Consent

Response time: Immediate

Withdraw previously given consent at any time

⚖️

Right to Non-Discrimination (CCPA)

Response time: N/A

Not be discriminated against for exercising rights

📝

Right to Lodge Complaint

Response time: N/A

File complaint with supervisory authority

Rights Exercise Procedure

Step 1: Identity Verification
Self-Service Portal

Access through authenticated account

Two-Factor Authentication

For sensitive requests

Document Verification

Government-issued ID for third-party requests

Step 2: Request Submission
Digital Channels
  • Privacy Dashboard within platform
  • Email to privacy@tevrixdigitalsolutions.com
  • API endpoints for automated requests
Physical Channels
  • Postal mail to registered office
  • In-person appointment (scheduled)
  • Designated request forms
Step 3: Response Timeline
1

Request Received

Day 0

2

Verification

Day 1-3

3

Processing

Day 4-20

4

Response

Day 21-30

17

Contact Information and Complaints

📧

Primary Contact Channels

Data Protection Officer

dpo@tevrixdigitalsolutions.com

Privacy Team

privacy@tevrixdigitalsolutions.com

General Support

support@tevrixdigitalsolutions.com

📞

Telephone Support

India (Primary)

+91 80 4900 0000

International Toll-Free

+1 888 000 0000

Fax

+91 80 4900 0001

Available: Monday-Friday, 9:00 AM - 6:00 PM IST
Emergency security incidents: 24/7 response
🏢

Physical Addresses

Registered Office

Tevrix Digital Solutions Private Limited
Level 14, Tower C, Prestige Tech Park
Marathahalli, Bangalore 560103
Karnataka, India

EU Representative

Global Privacy Solutions GmbH
Friedrichstraße 123
10117 Berlin, Germany

Regulatory Complaint Procedures

Supervisory Authorities

India

Data Protection Board of India
Ministry of Electronics & IT
New Delhi, India

European Union

Berlin Commissioner for Data Protection and Freedom of Information
Friedrichstraße 219, 10969 Berlin
Germany

Complaint Resolution Process

1

Internal Resolution Attempt

Contact our DPO for resolution within 30 days

2

Mediation Option

Voluntary mediation through certified privacy dispute resolution service

3

Regulatory Complaint

File complaint with relevant supervisory authority