Legal
Privacy Policy
Last updated: 25 July 2026
|DPDP Act, 2023 Compliant
adAura (“we,” “us,” “our”) is an engineering studio based in Solapur, Maharashtra, India. This privacy policy explains how we collect, use, store, and protect your personal data in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025.
Under the Act, adAura is a Data Fiduciary and you are a Data Principal. We believe these terms should be clear to both sides — not buried in jargon.
Scope and Applicability
This privacy policy applies to all personal data collected through the adAura website (adaura.in), our contact forms, and any communication channels we operate. It also governs personal data processed during active project engagements.
For the purposes of this policy, adAura acts as a "Data Fiduciary" as defined under the Digital Personal Data Protection Act, 2023 — meaning we determine the purpose and means of processing your personal data.
You, as the individual whose personal data is being processed, are referred to as a "Data Principal" under the Act. This policy describes your rights and our obligations in clear, plain language.
Personal Data We Collect
Contact form submissions: Your name, email address, phone number (if provided), and the content of your message. This data is collected with your explicit consent at the time of submission.
Project engagement data: If you become a client, we process your name, business name, contact details, billing address, and any project-related data you share with us (documents, specifications, credentials for systems we need to access).
Website analytics: We collect anonymised, aggregate data — pages visited, time on site, browser type, device type, and approximate geographic location (city level). This data does not identify you personally.
We do not collect sensitive personal data (financial data, biometric data, health data, caste, religious belief, or sexual orientation) through this website. Payment processing for projects is handled through separate, secured invoicing channels.
Purpose of Processing and Legal Basis
We process your personal data only for specific, lawful purposes. Under the DPDP Act, 2023, our legal basis for processing is either your explicit consent (Section 6) or a legitimate use (Section 7). Here is exactly what we use your data for and why:
Responding to enquiries: When you submit the contact form, you give explicit consent for us to use your contact details to respond to your enquiry and assess project fit. Legal basis: Consent (Section 6).
Project delivery: When you engage us for a project, we process your data as necessary to deliver the agreed services. Legal basis: Legitimate use — data voluntarily provided for a specified purpose (Section 7).
Website improvement: Anonymised analytics data is used in aggregate to understand site performance and improve user experience. This data does not constitute personal data as it cannot identify you. No consent is required.
Legal compliance: We may retain and process data where required by Indian tax law, contract law, or court orders. Legal basis: Legitimate use — compliance with legal obligations.
We do not process your personal data for any purpose beyond what is described here. We do not use your data for marketing unless you explicitly opt in. We do not sell, rent, or trade your personal data to any third party.
Consent
Under the DPDP Act, 2023, your consent must be free, specific, informed, unconditional, and unambiguous. We collect consent through clear, affirmative actions — such as submitting a contact form or signing a project agreement. We do not use pre-ticked boxes or treat silence as consent.
Before collecting your consent, we provide you with a notice (this policy and any contextual notices on forms) that describes what data we collect, why we collect it, and how you can exercise your rights.
You have the right to withdraw your consent at any time. Withdrawing consent is as easy as giving it — you can email us at contact@ad-aura.in or use the contact details of our Grievance Officer listed in this policy. Upon withdrawal, we will cease processing your data for the consented purpose within 30 days.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal, and does not affect processing based on legitimate uses under Section 7 of the Act.
Data Storage and Security
Your data is stored on servers operated by reputable cloud infrastructure providers. We use encryption for data in transit (TLS/SSL) and at rest where supported by the service provider.
Access to personal data is restricted to adAura team members who need it to respond to your enquiry or deliver your project. We maintain access controls and review them periodically.
We implement reasonable security safeguards as required under Section 8 of the DPDP Act, 2023 to protect personal data from unauthorised access, use, modification, disclosure, or destruction.
While we take reasonable precautions, no method of electronic transmission or storage is completely secure. If you suspect unauthorised access to your data, contact our Grievance Officer immediately.
Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India as required under Section 8(6) of the DPDP Act, 2023.
We will also notify affected Data Principals (you) about the breach, describing the nature of the breach, the data affected, and the steps we are taking to mitigate it. Notification will be made as soon as practicable after becoming aware of the breach.
We maintain an internal breach response process and will cooperate fully with the Data Protection Board during any investigation.
Data Retention and Erasure
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Once the purpose is fulfilled and no legal obligation requires retention, we erase the data.
Contact form submissions from non-clients: Retained for up to 12 months after the last communication, then erased.
Client project data: Retained for the duration of the project and up to 3 years after completion for support, warranty, and compliance with Indian tax and contract law requirements.
Analytics data: Retained in anonymised, aggregate form. As it does not constitute personal data, it is not subject to erasure requirements.
You can request erasure of your personal data at any time by contacting our Grievance Officer. We will process erasure requests within 30 days, unless retention is required by law.
Third-Party Data Processors
We may use third-party services for hosting, analytics, email delivery, and form processing. These third parties act as "Data Processors" under the DPDP Act and process your data only on our instructions and for the purposes we specify.
We ensure that our Data Processors maintain reasonable security safeguards and process data in compliance with the Act. We maintain contracts with our processors that reflect these obligations.
We do not embed third-party advertising, tracking pixels from ad networks, or social media widgets that track visitors across sites.
Links to external websites (such as our product sites AutoDocs and SolarFlow) are governed by their own privacy policies. We encourage you to review those policies separately.
Cross-Border Data Transfer
Some of our third-party service providers may store or process data outside India. Under the DPDP Act, 2023, cross-border data transfer is permitted except to countries specifically restricted by the Central Government.
As of the date of this policy, no country has been notified as restricted for data transfers. Should the government issue such a notification affecting our service providers, we will take steps to ensure continued compliance, including migrating data to compliant infrastructure if necessary.
We do not transfer your personal data to any country or entity that we have reason to believe does not maintain adequate data protection standards.
Your Rights as a Data Principal
Under the DPDP Act, 2023, you have the following rights. To exercise any of these, contact our Grievance Officer using the details provided in this policy.
Right to Access (Section 11): You can request a summary of your personal data that we are processing, and the identities of any Data Processors or third parties with whom we have shared your data.
Right to Correction, Completion, and Updating (Section 12): You can request that we correct inaccurate data, complete incomplete data, or update outdated data that we hold about you.
Right to Erasure (Section 12): You can request deletion of your personal data when it is no longer necessary for the purpose it was collected, or when you withdraw consent. We will comply unless retention is required by law.
Right to Grievance Redressal (Section 13): You have the right to register a grievance with us about how your data is being handled. We will acknowledge and respond within the timelines described below.
Right to Nominate (Section 14): You may nominate another individual to exercise your rights under this Act on your behalf in the event of your death or incapacity. To register a nominee, contact our Grievance Officer in writing.
Children's Data
Our services are directed at businesses and business owners. We do not knowingly collect or process personal data of children (individuals under 18 years of age).
Under Section 9 of the DPDP Act, 2023, processing of children's data requires verifiable consent from a parent or legal guardian. If we become aware that we have inadvertently collected data from a child without appropriate parental consent, we will erase it promptly.
If you believe we hold data of a child, contact our Grievance Officer immediately.
Grievance Officer
In accordance with Section 13 of the DPDP Act, 2023, we have designated a Grievance Officer to address your concerns about data processing. You can contact the Grievance Officer for any queries, complaints, or to exercise your Data Principal rights:
Name: Basvesh Hatte, Designation: Grievance Officer and Co-Founder, Email: basvesh@ad-aura.in
We will acknowledge your grievance within 48 hours and provide a resolution within 30 days of receipt. If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India.
Data Protection Board of India
If you have exhausted the grievance redressal process described above and are not satisfied with the outcome, you may file a complaint with the Data Protection Board of India as established under Chapter 5 of the DPDP Act, 2023.
The Board has the authority to investigate complaints, issue directions, and impose penalties for non-compliance. Details of the Board and complaint filing procedures will be available on the official government portal once the Board is fully constituted.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. Changes will be posted on this page with an updated revision date.
For material changes that affect how we handle your existing personal data, we will make reasonable efforts to notify affected Data Principals directly and, where required, obtain fresh consent.
We encourage you to review this page periodically. Continued use of the website after changes are posted does not constitute automatic consent to the updated policy — where consent is the legal basis, we will seek it explicitly.
Governing Law
This privacy policy is governed by the Digital Personal Data Protection Act, 2023, the DPDP Rules, 2025, and the laws of India. Any disputes arising from this policy will be subject to the jurisdiction of the courts in Solapur, Maharashtra, India.