24K ₹15190022K ₹13975018K ₹11544014K ₹911409K ₹60760
SonaSetu Logo

Legal

Privacy Policy

Effective Date: 1 July 2026 · Last Updated: 15 July 2026 · Version 2.0

Sonasetu Services Private Limited
CIN: U47912UP2026PTC246292
Registered Office: 33, T.N., Room No. 402, Durgma Tower, 4th Floor, Lucknow, Uttar Pradesh, India – 226001

Effective Date: 1 July 2026
Last Updated: 15 July 2026
Version: 2.0


1. Introduction and Scope

1.1 Sonasetu Services Private Limited, a company incorporated under the Companies Act, 2013, having its registered office at the address stated above (hereinafter referred to as the "Company", "Sonasetu", "We", "Us" or "Our"), is committed to protecting the privacy of individuals whose personal data it processes and to handling such data in accordance with applicable law.

1.2 This Privacy Policy (the "Policy") constitutes an electronic record within the meaning of the Information Technology Act, 2000 and the rules framed thereunder, and is published in accordance with Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules"). This Policy does not require any physical, electronic or digital signature.

1.3 This Policy sets out the manner in which the Company, acting as a Data Fiduciary, collects, receives, stores, processes, uses, discloses, transfers, retains and erases the personal data of Data Principals in connection with the Services, and describes the rights available to Data Principals and the means by which those rights may be exercised.

1.4 This Policy applies to all personal data processed by the Company through the Website, any mobile application, and any related product, feature or service operated by the Company (collectively, the "Services"). It does not apply to any third-party website, platform or service that the Company does not own or control, notwithstanding that such third party may be accessible via the Services.

1.5 Acceptance. By accessing or using the Services, or by submitting personal data to the Company, You acknowledge that You have read and understood this Policy and, where consent is the applicable lawful basis, You consent to the processing of Your personal data in accordance with this Policy. If You do not agree with this Policy, You must not access or use the Services.

1.6 This Policy is to be read together with the Company's Terms of Service, Cookie Policy and any product-specific or service-specific notice issued by the Company, each of which is incorporated herein by reference. In the event of any conflict between this Policy and a service-specific notice, the service-specific notice shall prevail to the extent of such conflict, and only in respect of the service to which it relates.

2. Governing Legal Framework

2.1 The Company processes personal data in accordance with the laws of India, including in particular:

  • the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the rules framed thereunder, as and when brought into force;
  • the Information Technology Act, 2000, together with the SPDI Rules and other rules framed thereunder;
  • the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020, to the extent applicable; and
  • any other statute, rule, regulation, direction, order or guideline issued by a competent authority in India that is applicable to the Company's processing activities.

2.2 Where the Company offers goods or services to individuals located in the European Economic Area or the United Kingdom, or otherwise falls within the territorial scope of Regulation (EU) 2016/679 (the "GDPR") or the UK GDPR, the supplementary provisions set out in Annexure A shall additionally apply to such individuals.

2.3 Nothing in this Policy shall be construed as limiting or excluding any right or remedy available to a Data Principal under applicable law that cannot lawfully be limited or excluded.

3. Interpretation and Definitions

3.1 Interpretation

Words beginning with a capital letter have the meaning ascribed to them in this Clause 3 or elsewhere in this Policy. Definitions bear the same meaning whether used in the singular or the plural. Headings are inserted for convenience only and do not affect construction. The words "include", "includes" and "including" shall be construed as being followed by the words "without limitation". A reference to any statute or statutory provision includes that statute or provision as amended, re-enacted or replaced from time to time.

3.2 Definitions

  • "Account" means a unique registered account created by or for a User to access the Services or any part thereof.

  • "Affiliate" means, in relation to any entity, any other entity that directly or indirectly controls, is controlled by, or is under common control with, that entity, where "control" means the ownership of fifty percent (50%) or more of the shares, equity interest or other securities carrying the right to vote for the election of directors or other managing authority.

  • "Applicable Law" means all statutes, enactments, ordinances, rules, regulations, notifications, guidelines, policies, directions, directives, orders and judgments of any Governmental Authority having the force of law and applicable to the Company or the Services.

  • "Consent Manager" means a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform, as contemplated under the DPDP Act.

  • "Cookies" means small text files placed on a Device by a website, application or service, which store information relating to the use of that website, application or service.

  • "Data Fiduciary" means any person who, alone or in conjunction with other persons, determines the purpose and means of processing Personal Data. For the purposes of this Policy, the Company is the Data Fiduciary.

  • "Data Principal" means the individual to whom the Personal Data relates and, where such individual is a Child, includes the parent or lawful guardian of such Child, and where such individual is a person with disability, includes their lawful guardian acting on their behalf.

  • "Data Processor" means any person who processes Personal Data on behalf of the Company pursuant to a valid contract.

  • "Data Protection Board" means the Data Protection Board of India constituted under the DPDP Act.

  • "Device" means any device capable of accessing the Services, including a computer, mobile telephone, tablet or other connected device.

  • "Child" means an individual who has not completed eighteen (18) years of age.

  • "Governmental Authority" means any government, statutory authority, regulatory body, court, tribunal or other authority having jurisdiction over the Company.

  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data, and includes "personal information" and "sensitive personal data or information" as those terms are defined under the SPDI Rules.

  • "Personal Data Breach" means any unauthorised processing of Personal Data, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to Personal Data, that compromises the confidentiality, integrity or availability of such Personal Data.

  • "Processing" means any wholly or partly automated operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction.

  • "Sensitive Personal Data" means such categories of Personal Data as are classified as "sensitive personal data or information" under Rule 3 of the SPDI Rules, including passwords, financial information such as bank account, credit card, debit card or other payment instrument details, physical, physiological and mental health condition, sexual orientation, medical records and history, and biometric information.

  • "Service Provider" means any natural or legal person engaged by the Company to process Personal Data on its behalf, or to facilitate, provide, support, analyse or improve the Services.

  • "Services" has the meaning given in Clause 1.4.

  • "Usage Data" means data collected automatically through the use of the Services or generated by the infrastructure of the Services.

  • "User" or "You" means the individual accessing or using the Services, or the body corporate or other legal entity on whose behalf such individual accesses or uses the Services.

  • "Website" means the website operated by the Company and accessible at https://www.sonasetu.com, together with any subdomain thereof.

4. Categories of Personal Data Processed

4.1 Personal Data Provided by You

In the course of registering for, accessing or using the Services, the Company may collect the following categories of Personal Data directly from You:

  • Identity Data: first name, last name, and any username or similar identifier;
  • Contact Data: email address, telephone or mobile number, postal address, city, state, province, and ZIP or postal code;
  • Account Data: login credentials, account preferences and settings;
  • Transaction Data: records of goods or services obtained through the Services and details of payments made or received;
  • Communications Data: the contents of support tickets, correspondence, chat transcripts, feedback and survey responses.

4.2 Usage Data Collected Automatically

Usage Data is collected automatically when You use the Services and may include: the Internet Protocol (IP) address of Your Device, browser type and version, operating system, mobile device type, unique device identifiers, the pages of the Services visited, the date and time of visit, time spent on pages, referral URLs, clickstream data and other diagnostic data.

4.3 Data Collected from Third-Party Sources

The Company may receive Personal Data from Service Providers, analytics providers, payment processors, business partners, and publicly accessible sources, in each case only where such collection is permitted under Applicable Law.

4.4 Sensitive Personal Data

The Company collects Sensitive Personal Data only where strictly necessary for a specified lawful purpose, only with Your express prior consent where such consent is required, and subject to enhanced security safeguards. The Company does not require You to disclose Sensitive Personal Data that is not necessary for the purpose for which it is sought.

4.5 Data Minimisation

The Company shall not collect Personal Data that is not necessary for, or reasonably connected with, the purposes set out in Clause 6.

5. Lawful Basis for Processing

5.1 The Company processes Personal Data only on one or more of the following lawful bases:

  • (a) Consent. Where You have given free, specific, informed, unconditional and unambiguous consent, signified by a clear affirmative action, to the processing of Your Personal Data for a specified purpose. Such consent is limited to the Personal Data necessary for that specified purpose.

  • (b) Certain Legitimate Uses. Where processing is necessary for a legitimate use recognised under Section 7 of the DPDP Act, including: (i) where You have voluntarily provided Personal Data for a specified purpose and have not indicated an objection; (ii) for compliance with any judgment, decree or order; (iii) for responding to a medical emergency involving a threat to life or immediate threat to health; (iv) for taking measures to ensure safety during any disaster or breakdown of public order; and (v) for purposes related to employment or safeguarding the Company from loss or liability.

  • (c) Performance of a Contract. Where processing is necessary for the performance of a contract to which You are a party, or in order to take steps at Your request prior to entering into such a contract.

  • (d) Legal Obligation. Where processing is necessary for compliance with a legal obligation to which the Company is subject under Applicable Law.

5.2 Withdrawal of Consent. Where processing is based on consent, You may withdraw such consent at any time, with the same ease with which it was given, by writing to the Grievance Officer at the address in Clause 17 or by using the controls made available within Your Account or through a Consent Manager. The withdrawal of consent shall not affect the lawfulness of processing carried out on the basis of that consent prior to its withdrawal.

5.3 Consequences of Withdrawal. Where consent is withdrawn, the Company shall, within a reasonable time, cease processing the relevant Personal Data and cause its Data Processors to do the same, unless such processing is required or authorised under Applicable Law. You acknowledge that the withdrawal of consent may result in the Company being unable to continue to provide all or part of the Services to You, and that You shall bear the consequences of such withdrawal.

6. Purposes of Processing

6.1 The Company processes Personal Data for the following specified, lawful purposes:

  • Provision of the Services: to provide, operate, maintain and monitor the Services and to make them available to You;
  • Account Administration: to create, authenticate, manage and administer Your Account and to enable access to functionality available to registered Users;
  • Contractual Performance: to perform, administer and enforce contracts entered into with You, including the processing of orders, payments, invoices and refunds;
  • Communications: to contact You by email, telephone, SMS, push notification or other electronic means in relation to updates, transactional notices, security alerts and administrative or informative communications concerning the Services;
  • Customer Support: to receive, attend to, investigate and resolve Your queries, requests, complaints and grievances;
  • Marketing: to provide You with news, offers and information regarding goods, services and events offered by the Company that are similar to those You have purchased or enquired about, subject always to Your right to opt out at any time and to Your prior consent where such consent is required under Applicable Law;
  • Analytics and Improvement: to conduct data analysis, identify usage trends, evaluate the effectiveness of promotional campaigns, and to test, improve and develop the Services;
  • Security and Fraud Prevention: to detect, investigate, prevent and address fraud, unauthorised access, security incidents, technical faults and activity that is unlawful or prohibited under the Terms of Service;
  • Legal and Regulatory Compliance: to comply with Applicable Law, to respond to lawful requests from Governmental Authorities, to establish, exercise or defend legal claims, and to enforce the Company's rights; and
  • Corporate Transactions: to evaluate, negotiate or give effect to any merger, acquisition, restructuring, reorganisation, divestiture, financing, dissolution or transfer of all or part of the Company's business or assets, whether as a going concern or as part of an insolvency, liquidation or similar proceeding.

6.2 The Company shall not process Personal Data for any purpose that is incompatible with the purposes set out in this Clause 6, save where a further lawful basis is obtained.

7. Cookies and Similar Tracking Technologies

7.1 The Company and its Service Providers use Cookies, web beacons, pixel tags, clear GIFs, tags and scripts to operate the Services, to store information, and to analyse and improve the Services.

7.2 Cookies may be Session Cookies, which are erased when You close Your browser, or Persistent Cookies, which remain on Your Device until deleted or until they expire.

7.3 The Company uses the following categories of Cookies:

  • (a) Strictly Necessary CookiesType: Session. Administered by: the Company. Purpose: to authenticate Users, maintain sessions, prevent fraudulent use of Accounts, and deliver functionality that You have expressly requested. These Cookies are essential and cannot be disabled without impairing the Services.

  • (b) Consent and Notice Acceptance CookiesType: Persistent. Administered by: the Company. Purpose: to record whether You have accepted the use of Cookies and to store Your cookie preferences.

  • (c) Functionality CookiesType: Persistent. Administered by: the Company. Purpose: to remember choices You make, such as language preference and login details, so as to avoid the need to re-enter preferences on each visit.

  • (d) Analytics and Performance CookiesType: Persistent. Administered by: the Company and its Service Providers. Purpose: to measure and analyse usage of the Services in order to improve them.

7.4 Consent. Where required under Applicable Law, non-essential Cookies (including analytics, advertising and remarketing Cookies) are deployed only with Your prior consent. You may grant, refuse, modify or withdraw consent at any time using the Company's cookie preference tool, where available, or through Your browser or Device settings. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.

7.5 You may configure Your browser to refuse Cookies or to notify You when a Cookie is being placed. You acknowledge that refusal of certain Cookies may impair or prevent the functioning of parts of the Services.

8. Disclosure and Sharing of Personal Data

8.1 The Company does not sell Personal Data. The Company may disclose Personal Data only in the following circumstances:

  • (a) Service Providers and Data Processors. To Service Providers engaged to perform functions on the Company's behalf, including hosting, storage, payment processing, analytics, communications and customer support. Each such Service Provider is engaged under a valid written contract that: (i) restricts processing to the Company's documented instructions; (ii) imposes obligations of confidentiality; (iii) requires the implementation of reasonable security safeguards; and (iv) prohibits any use of the Personal Data for the Service Provider's own purposes.

  • (b) Affiliates. To Affiliates of the Company, provided that such Affiliates are bound to observe standards of protection no less stringent than those set out in this Policy.

  • (c) Business Partners. To business partners, where necessary to offer You products, services or promotions, and subject to Your consent where such consent is required.

  • (d) Corporate Transactions. To a proposed or actual acquirer, successor or assignee in connection with any merger, acquisition, restructuring, financing, sale of assets, insolvency or similar transaction. The Company shall provide notice before Personal Data is so transferred and becomes subject to a different privacy policy.

  • (e) Legal, Regulatory and Enforcement Disclosures. To Governmental Authorities, courts, tribunals, law enforcement agencies or other third parties, where the Company determines in good faith that such disclosure is reasonably necessary to: (i) comply with Applicable Law or a valid legal process; (ii) enforce the Company's Terms of Service or other agreements; (iii) protect and defend the rights, property or safety of the Company, its Users or the public; (iv) prevent, detect or investigate fraud, security incidents or wrongdoing in connection with the Services; or (v) protect against legal liability.

  • (f) Other Users. Where the Services include public or shared areas, any Personal Data You elect to post or disclose in such areas may be viewed and used by other Users and may be publicly accessible. You should exercise caution before disclosing Personal Data in such areas.

  • (g) With Your Consent. To any other recipient, for any other purpose, with Your prior consent.

8.2 The Company shall remain responsible for compliance with Applicable Law in respect of Personal Data processed on its behalf by a Data Processor.

9. Third-Party Service Providers

9.1 The Company engages the following categories of third-party Service Providers, which may access Personal Data in the course of providing services to the Company. Such third parties process Personal Data in accordance with their own privacy policies and the contractual terms agreed with the Company.

  • Google Places (Google LLC) — a service that returns information about places in response to HTTP requests, and which may collect information from You and Your Device, including for security purposes. Google's privacy policy is available at https://www.google.com/intl/en/policies/privacy/.

  • Razorpay (Razorpay Software Private Limited) — a payment aggregator authorised by the Reserve Bank of India, engaged by the Company to process payments made through the Services. Razorpay collects and processes payment instrument details, transaction data and related identity and contact information for the purposes of payment processing, settlement, refunds, fraud prevention and compliance with Applicable Law, including the Payment and Settlement Systems Act, 2007 and directions issued by the Reserve Bank of India. Razorpay's privacy policy is available at https://razorpay.com/privacy/.

  • Amazon Web Services (Amazon Web Services, Inc. and Amazon Web Services India Private Limited) — engaged by the Company as its cloud infrastructure and hosting provider. Personal Data processed through the Services is stored and processed on Amazon Web Services infrastructure located in the [Insert AWS region actually used, e.g. Asia Pacific (Mumbai) ap-south-1] region. Amazon Web Services acts as a Data Processor and processes Personal Data solely in accordance with the Company's documented instructions and the AWS Data Processing Addendum. The AWS privacy notice is available at https://aws.amazon.com/privacy/.

  • [Insert any analytics provider (e.g. Google Analytics), email or SMS communication provider, and customer support platform actually engaged, together with a link to each provider's privacy policy. An accurate and complete list is a compliance requirement; placeholders must not be published.]

9.2 Payment Data. Payments made through the Services are processed by Razorpay in its capacity as an authorised payment aggregator. Card numbers, card verification values, unique payment instrument details and banking credentials are transmitted directly to and processed by Razorpay, and are not collected, stored or retained by the Company on its own systems. The Company receives only such transaction data as is necessary to confirm, reconcile, invoice, refund and account for a payment, including the transaction identifier, amount, date, status and the last four digits of the payment instrument. Your use of Razorpay's services is additionally governed by Razorpay's own terms and privacy policy.

9.3 Hosting and Storage Location. The Company's application infrastructure, databases and backups are hosted on Amazon Web Services. Where the data centre region used is located within India, Personal Data is stored within Indian territory. Where any Personal Data is stored or processed in an Amazon Web Services region outside India, such transfer is effected in accordance with Clause 11.

10. Retention of Personal Data

10.1 The Company retains Personal Data only for so long as is necessary for the purposes for which it was collected, or for such longer period as is required or permitted under Applicable Law. The periods stated below are maximum periods; the Company may delete, aggregate or anonymise Personal Data earlier where it is no longer necessary for the relevant purpose.

10.2 Retention Schedule.

  • (a) Account Information. Retained for the duration of the Account relationship and for a period of up to twenty-four (24) months following closure of the Account, in order to address post-termination matters and to resolve disputes.

  • (b) Customer Support Data. Support tickets and correspondence: up to twenty-four (24) months from the date of closure of the ticket. Chat transcripts: up to twenty-four (24) months, for quality assurance and training.

  • (c) Usage Data. Website analytics data (including Cookies, IP addresses and device identifiers): up to twenty-four (24) months from the date of collection. Server logs (including IP addresses and access times): up to twenty-four (24) months, for security monitoring and troubleshooting.

  • (d) Financial and Transaction Records. Retained for such period as is prescribed under the Companies Act, 2013, the Income-tax Act, 1961, applicable goods and services tax legislation and other Applicable Law, being not less than eight (8) years from the end of the relevant financial year.

10.3 Personal Data may be retained beyond the periods stated in Clause 10.2 where: (a) retention is required under Applicable Law; (b) the Personal Data is necessary to establish, exercise or defend legal claims; (c) You have expressly requested such retention; or (d) the Personal Data subsists in encrypted backup systems pending scheduled deletion.

10.4 Erasure. Upon expiry of the applicable retention period, the Company shall securely erase or anonymise the Personal Data. Residual copies may persist in encrypted backups for a limited period consistent with the Company's backup retention schedule, and shall not be restored except where necessary for security, disaster recovery or legal compliance. Anonymised data, which cannot be attributed to an identifiable individual, may be retained indefinitely for statistical, research and analytics purposes.

10.5 You may request particulars of the retention period applicable to Your Personal Data by writing to the Grievance Officer.

11. Cross-Border Transfer of Personal Data

11.1 The Company's operations, and those of its Service Providers, may involve the storage or processing of Personal Data at locations outside the state, province or country in which You are situated, where data protection laws may differ from those of Your jurisdiction.

11.2 The Company may transfer Personal Data outside India in accordance with Section 16 of the DPDP Act, and shall not transfer Personal Data to any territory in respect of which the Central Government has issued a notification restricting such transfer.

11.3 Where a transfer is subject to the GDPR or the UK GDPR, the Company shall effect such transfer only on the basis of an adequacy decision, Standard Contractual Clauses approved by the European Commission (or the UK International Data Transfer Agreement or Addendum, as applicable), or another lawful transfer mechanism, together with such supplementary measures as may be appropriate.

11.4 The Company shall take all steps reasonably necessary to ensure that Personal Data so transferred is treated securely and in accordance with this Policy, and shall not effect any such transfer to an organisation or country unless adequate controls are in place in respect of the security of that Personal Data.

12. Security Safeguards

12.1 The Company has implemented and maintains reasonable security practices and procedures in accordance with Rule 8 of the SPDI Rules and Section 8(5) of the DPDP Act, comprising managerial, technical, operational and physical controls that are commensurate with the nature of the Personal Data processed and the risks associated with such processing. Such controls include, as applicable: encryption of data in transit and at rest, access controls on a need-to-know basis, logging and monitoring, secure development practices, periodic security testing, staff confidentiality undertakings, and incident response procedures.

12.2 Limitation. Notwithstanding Clause 12.1, You acknowledge that no method of transmission over the Internet and no method of electronic storage is entirely secure. While the Company employs commercially reasonable measures to protect Personal Data, the Company does not warrant, and cannot guarantee, the absolute security of Personal Data. To the maximum extent permitted under Applicable Law, the Company shall not be liable for any loss or damage arising from unauthorised access to, or use of, Personal Data occurring otherwise than as a result of the Company's failure to observe the standard of care required under Applicable Law.

12.3 User Obligations. You are responsible for maintaining the confidentiality of Your Account credentials and for all activity conducted through Your Account. You shall notify the Company immediately upon becoming aware of any unauthorised use of Your Account.

13. Personal Data Breach

13.1 In the event of a Personal Data Breach, the Company shall, in accordance with Section 8(6) of the DPDP Act and directions issued by the Indian Computer Emergency Response Team (CERT-In), give intimation of such breach to the Data Protection Board and to each affected Data Principal, in such form and manner as may be prescribed.

13.2 The Company maintains a documented incident response procedure providing for the identification, containment, assessment, remediation, notification and post-incident review of Personal Data Breaches.

14. Rights of Data Principals

14.1 Subject to Applicable Law, You have the following rights in respect of Your Personal Data:

  • (a) Right to Access Information. To obtain from the Company a summary of the Personal Data being processed and the processing activities undertaken in respect thereof, the identities of all Data Fiduciaries and Data Processors with whom the Personal Data has been shared and a description of the Personal Data so shared, and any other information relating to the Personal Data and its processing as may be prescribed.

  • (b) Right to Correction, Completion, Updating and Erasure. To require the Company to correct inaccurate or misleading Personal Data, to complete incomplete Personal Data, to update Personal Data, and to erase Personal Data, save where retention is necessary for the specified purpose or for compliance with Applicable Law.

  • (c) Right of Grievance Redressal. To have readily available means of registering a grievance with the Company in respect of any act or omission regarding the performance of the Company's obligations or the exercise of Your rights, and to have such grievance addressed within the period prescribed under Applicable Law.

  • (d) Right to Nominate. To nominate any other individual who shall, in the event of Your death or incapacity, exercise Your rights under the DPDP Act in accordance with Applicable Law.

  • (e) Right to Withdraw Consent. As set out in Clause 5.2.

  • (f) Right to Opt Out of Marketing. To opt out of receiving marketing communications at any time, by using the unsubscribe facility contained in such communications or by writing to the Grievance Officer.

14.2 Exercise of Rights. Rights may be exercised by submitting a request to the Grievance Officer at the address in Clause 17, or through the account management facilities made available within the Services. The Company may require verification of Your identity prior to giving effect to a request, and may decline a request that is manifestly unfounded, excessive or repetitive, or where compliance would prejudice the rights of another person or contravene Applicable Law. The Company shall respond to requests within the period prescribed under Applicable Law and, in any event, within thirty (30) days of receipt of a valid request.

14.3 Duties of Data Principals. In accordance with Section 15 of the DPDP Act, You shall: (a) comply with Applicable Law when exercising Your rights; (b) not impersonate another person while providing Personal Data for a specified purpose; (c) not suppress any material information while providing Personal Data to the Company for any document, identifier, proof of identity or proof of address issued by the State; (d) not register a false or frivolous grievance or complaint; and (e) furnish only such information as is verifiably authentic when exercising the right to correction or erasure.

14.4 Right to Complain. Without prejudice to Clause 17, You may make a complaint to the Data Protection Board of India where You are not satisfied with the Company's response to Your grievance.

15. Children's Personal Data

15.1 The Services are not directed at, and are not intended for use by, Children. The Company does not knowingly collect Personal Data from a Child.

15.2 In accordance with Section 9 of the DPDP Act, where the Company processes the Personal Data of a Child or of a person with disability having a lawful guardian, it shall do so only after obtaining verifiable consent from the parent or lawful guardian, in such manner as may be prescribed.

15.3 The Company shall not undertake any processing of a Child's Personal Data that is likely to cause a detrimental effect on the well-being of the Child, and shall not undertake tracking, behavioural monitoring or targeted advertising directed at Children.

15.4 Where the Company becomes aware that it has collected Personal Data from a Child without verifiable parental consent, it shall take steps to erase such Personal Data from its systems without undue delay. A parent or lawful guardian who becomes aware that a Child has provided Personal Data to the Company should contact the Grievance Officer immediately.

16. Third-Party Links

16.1 The Services may contain links to websites, applications or services that are not operated or controlled by the Company. Selecting such a link will direct You to the relevant third party's platform.

16.2 The Company does not control, and assumes no responsibility or liability for, the content, privacy policies or practices of any third-party website, application or service. You are strongly advised to review the privacy policy of every third party whose platform You visit. The inclusion of a link does not constitute an endorsement.

17. Grievance Redressal — Grievance Officer

17.1 In accordance with Rule 5(9) of the SPDI Rules, Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and Section 13 of the DPDP Act, the Company has appointed a Grievance Officer to address complaints and grievances relating to the processing of Personal Data.

17.2 The particulars of the Grievance Officer are as follows:

  • Name: [Insert full name of Grievance Officer]
  • Designation: Grievance Officer, Sonasetu Services Private Limited
  • Email: grievance@sonasetu.com
  • Postal Address: 33, T.N., Room No. 402, Durgma Tower, 4th Floor, Lucknow, Uttar Pradesh, India – 226001
  • Telephone: [Insert Telephone Number]
  • Hours: Monday to Friday, 10:00 to 18:00 IST (excluding public holidays)

17.3 The Grievance Officer shall acknowledge receipt of a grievance within twenty-four (24) hours and shall dispose of the grievance within fifteen (15) days of receipt, or within such other period as may be prescribed under Applicable Law.

17.4 General queries regarding this Policy may also be directed to support@sonasetu.com.

18. Amendments to this Policy

18.1 The Company reserves the right to amend, modify or supplement this Policy at any time in order to reflect changes in its practices, the Services, or Applicable Law.

18.2 Any amended Policy shall be published on this page and the "Last Updated" date shall be revised accordingly. Where an amendment is material, the Company shall, prior to the amendment taking effect, provide notice by email and/or by a prominent notice within the Services. Where the amendment materially expands the purposes for which Personal Data is processed, the Company shall obtain fresh consent to the extent required under Applicable Law.

18.3 Amendments take effect on the date on which they are posted, unless a later effective date is specified. Your continued use of the Services after the effective date constitutes acceptance of the amended Policy. You are advised to review this Policy periodically.

19. General Provisions

19.1 Governing Law. This Policy shall be governed by, and construed in accordance with, the laws of India.

19.2 Jurisdiction. Subject to the jurisdiction of the Data Protection Board in respect of matters falling within its statutory remit, the courts and tribunals at Lucknow, Uttar Pradesh shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.

19.3 Severability. If any provision of this Policy is held to be invalid, illegal or unenforceable by a court of competent jurisdiction, such provision shall be severed and the remaining provisions shall continue in full force and effect.

19.4 No Waiver. No failure or delay by the Company in exercising any right or remedy under this Policy shall operate as a waiver of that right or remedy, nor shall any single or partial exercise preclude any further exercise thereof.

19.5 Language. This Policy is drafted in the English language. Where the Company publishes a translation, the English version shall prevail in the event of any inconsistency, save to the extent that Applicable Law requires otherwise.

19.6 Entire Notice. This Policy, together with the Company's Terms of Service and Cookie Policy, constitutes the entire notice given by the Company in respect of the processing of Personal Data and supersedes all prior privacy notices issued by the Company.


Annexure A — Supplementary Provisions for Data Subjects in the EEA and the United Kingdom

A.1 This Annexure applies only where the GDPR or the UK GDPR applies to the Company's processing of Your personal data. In the event of any conflict between this Annexure and the main body of this Policy, this Annexure shall prevail in respect of such data subjects.

A.2 Controller. Sonasetu Services Private Limited is the controller in respect of the personal data described in this Policy.

A.3 Legal Bases. The Company relies on the following legal bases under Article 6(1) GDPR: (a) consent; (b) performance of a contract; (c) compliance with a legal obligation; and (d) the legitimate interests pursued by the Company or a third party, provided such interests are not overridden by Your interests or fundamental rights and freedoms. Where processing is based on legitimate interests, You may obtain particulars of the balancing assessment by contacting the Grievance Officer.

A.4 Rights. You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection (including objection to processing based on legitimate interests and to direct marketing), together with the right not to be subject to a decision based solely on automated processing which produces legal effects concerning You or similarly significantly affects You.

A.5 Supervisory Authority. You have the right to lodge a complaint with the supervisory authority of the Member State of Your habitual residence, place of work or place of the alleged infringement, or (in the United Kingdom) with the Information Commissioner's Office.

A.6 International Transfers. Transfers of personal data outside the EEA or the United Kingdom are effected in accordance with Clause 11.3.