This Privacy Statement is governed by the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. VrumaLabs is incorporated and operates in India.
1. Who We Are
VrumaLabs ("Company", "we", "us", "our") is a technology company registered in India, providing AI solutions, cybersecurity services, web and mobile development, automation, and cloud & network security. We also develop and operate in-house software products including Firewall Lens, Cartlist, and Extenrix.
Grievance Officer (as required under IT Act, 2000):
Name: VrumaLabs Privacy Team
Email: privacy@vrumalabs.com
Response time: Within 72 hours of receipt of grievance.
2. Personal Data We Collect
Data you provide directly
- Name, email address, and message content when you submit our contact or newsletter forms
- Professional details (company, role) when engaging our services
- Account credentials when using our products (Extenrix, Cartlist)
Data collected automatically
- IP address, browser type, and device identifiers
- Pages visited, time spent, and navigation paths
- Cookie and tracking data (see our Cookie Policy)
Sensitive Personal Data (SPDI)
We do not intentionally collect Sensitive Personal Data or Information (SPDI) as defined under the IT Rules, 2011, unless explicitly required for a specific service and with your prior written consent.
3. How We Use Your Personal Data
- To respond to enquiries and deliver contracted services
- To send the VrumaLabs newsletter (only with your explicit consent)
- To operate, maintain, and improve our products and website
- To comply with legal obligations under Indian law
- To detect, prevent, and address fraud or security incidents
4. Legal Basis for Processing
Under the DPDP Act, 2023, we process your personal data based on:
- Consent — for newsletter subscriptions and marketing communications
- Contractual necessity — to fulfil service agreements and respond to enquiries
- Legitimate interests — for website analytics and security purposes
- Legal obligation — when required by Indian law or regulatory authorities
5. Data Sharing and Disclosure
We do not sell your personal data. We may share data with:
- Service providers — hosting, analytics, and email platforms operating under data processing agreements
- Legal authorities — when required by law, court order, or a competent Indian authority
- Business transfers — in the event of a merger or acquisition, with notice to affected users
6. Your Rights Under the DPDP Act, 2023
As a Data Principal, you have the following rights:
- Right to access — obtain a summary of your personal data and processing activities
- Right to correction — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data where no longer necessary
- Right to grievance redressal — raise complaints with our Grievance Officer
- Right to nominate — nominate another person to exercise rights on your behalf
- Right to withdraw consent — withdraw consent at any time without affecting prior processing
To exercise any right, email privacy@vrumalabs.com with the subject line "Data Rights Request — [Type of Request]", including your name and the email address associated with your account. We will acknowledge within 72 hours and respond fully within 30 days. We do not sell or share your personal data with third parties for commercial gain.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India once constituted under the DPDP Act, 2023.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by Indian law. Contact form data is retained for 12 months; newsletter subscription data is retained until you unsubscribe; product account data is retained for the duration of your account plus 90 days.
8. Data Security
We implement reasonable security practices as mandated by the IT (SPDI) Rules, 2011, including encryption in transit (TLS), access controls, and regular security reviews. However, no system is completely secure, and we cannot guarantee absolute security.
9. Cross-Border Data Transfers
Where we transfer personal data outside India (e.g., to cloud service providers), we ensure adequate safeguards are in place in compliance with the DPDP Act, 2023 and any applicable rules notified by the Central Government.
10. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact our Grievance Officer immediately.
11. Changes to This Statement
We may update this Privacy Statement periodically. Material changes will be notified via email or a prominent notice on our website at least 30 days before taking effect. Continued use of our services after the effective date constitutes acceptance.
12. Contact Us
For any privacy-related queries or to exercise your rights:
Email: privacy@vrumalabs.com
General: hello@vrumalabs.com