DPDP Act 2023 Compliant

Privacy Policy

How Vively Technology Solutions collects, uses, and protects your personal data through the VivelyDeploy platform.

Contents

  1. Who We Are
  2. Data We Collect
  3. Purpose of Data Collection
  4. Consent
  5. Data Storage & Security
  6. Data Retention
  7. Your Rights Under DPDP Act 2023
  8. Grievance Officer
  9. Data Breach Notification
  10. Third-Party Processors
  11. Cookies & Tracking
  12. Changes to This Policy
  13. Contact Information

1. Who We Are

Vively Technology Solutions ("we", "us", "our") is a technology company based in Kolkata, West Bengal, India. We operate the VivelyDeploy platform — a deployment management system that provisions and manages software applications on Cloudflare infrastructure for our clients.

For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as the Data Fiduciary for all personal data collected through VivelyDeploy.

DetailInformation
Legal EntityVively Technology Solutions
AddressKolkata, West Bengal, India
Emailbusiness@vivelytech.com
Websitevivelytech.com
Platformdeploy.vivelytech.in

2. Data We Collect

We collect the following categories of personal data when you use VivelyDeploy:

CategoryData PointsSource
Identity DataFull name, designation/titleIntake form
Contact DataEmail address, phone numberIntake form
Business DataBusiness name, business typeIntake form
Technical DataCloudflare account ID, API tokens (encrypted)Intake form (self-hosted mode)
Consent DataConsent timestamp, IP address, OTP verification recordAutomatically captured
Deployment DataApp configuration, deployment status, infrastructure identifiersGenerated during deployment
Communication DataEmail correspondence, support requestsEmail communication

We do NOT collect: Government-issued IDs, financial account details, health data, biometric data, or sensitive personal data as defined under the DPDP Act.

3. Purpose of Data Collection

Your data is collected and processed strictly for the following purposes:

  1. Deployment Services — Provisioning, deploying, and managing your software application on Cloudflare infrastructure.
  2. Identity Verification — Verifying your identity via OTP before processing deployment requests.
  3. Communication — Sending deployment status updates, credentials, certificates, support responses, and service announcements.
  4. Licensing & Billing — Managing subscription status, generating invoices, and processing payments.
  5. Platform Security — Health monitoring, audit logging, and incident response for deployed applications.
  6. Legal Compliance — Maintaining records required under applicable Indian law.

Purpose Limitation: We will never use your data for purposes other than those stated above without obtaining fresh consent from you, as required under Section 6 of the DPDP Act, 2023.

5. Data Storage & Security

We implement robust technical and organizational measures to protect your data:

MeasureImplementation
Encryption at RestCloudflare API tokens are encrypted using AES-256-GCM before storage
Encryption in TransitAll data transmitted over HTTPS/TLS 1.3
Password Hashingbcrypt with proper salt rounds; password hashes are never returned in any API response
SQL Injection ProtectionAll database queries use parameterized statements
XSS ProtectionUser input is sanitized before rendering in HTML
AuthenticationJWT-based authentication with token revocation on logout
Rate LimitingLogin and OTP endpoints are rate-limited to prevent brute force
Access ControlRole-based access (owner/admin) with audit logging of all privileged actions
InfrastructureAll data stored on Cloudflare's global network (D1, KV, R2) with enterprise-grade security

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

Data CategoryRetention Period
Active deployment dataDuration of your service agreement
Consent records3 years from consent date (legal compliance)
Cloudflare API tokensDeleted immediately after deployment completes (self-hosted mode)
OTP data10 minutes (auto-deleted)
Audit logs1 year from creation
Health check logs90 days from check date
Data post service terminationDeleted within 90 days of service termination

After the retention period, data is permanently deleted from all storage systems including databases and backups.

7. Your Rights Under DPDP Act 2023

As a Data Principal under the DPDP Act, you have the following rights:

RightDescriptionHow to Exercise
Right to AccessObtain a summary of your personal data we hold and processing activitiesEmail us
Right to CorrectionRequest correction of inaccurate or incomplete personal dataEmail us
Right to ErasureRequest deletion of your personal dataEmail us or use the erasure request form
Right to Withdraw ConsentWithdraw previously given consent at any timeEmail us
Right to Grievance RedressalFile a complaint about data processingContact our Grievance Officer
Right to NominateNominate a person to exercise your rights in case of death or incapacityEmail us

Response Time: We will acknowledge your request within 48 hours and complete processing within 30 days. For erasure requests, we will confirm deletion of all personal data within the 30-day period.

To exercise any of these rights, email business@vivelytech.com with the subject line "Data Rights Request — [Your Name]" and include your deployment reference ID (if applicable).

8. Grievance Officer

In accordance with Section 8(10) of the DPDP Act, we have appointed a Grievance Officer to address your concerns regarding data processing:

Grievance Officer: Abhinaba Dey
Email: business@vivelytech.com
Response Time: Within 48 hours of receiving your complaint
Resolution Time: Within 30 days

If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India as established under the DPDP Act, 2023.

9. Data Breach Notification

In the event of a personal data breach, we will:

  1. Notify the Data Protection Board of India within 72 hours of becoming aware of the breach.
  2. Notify all affected Data Principals (users) via email without undue delay.
  3. Provide details of: the nature of the breach, data affected, remedial measures taken, and contact information for further queries.
  4. Maintain a documented record of all breaches, including those not reported to the Board.

Our breach notification emails include the incident summary, detection time, actions taken, and contact information for our Grievance Officer.

10. Third-Party Data Processors

We engage the following third parties as Data Processors on our behalf:

ProcessorPurposeData SharedLocation
Cloudflare, Inc.Infrastructure hosting (Workers, D1, KV, R2, Pages)All deployment and configuration dataGlobal (US-headquartered)
Brevo (Sendinblue)Transactional email deliveryEmail address, nameEU (France)

All processors are bound by data processing agreements that require them to implement appropriate security measures and process data only as instructed by us.

Cross-Border Transfer: Your data may be processed in jurisdictions outside India through our infrastructure providers. We ensure that such transfers include adequate safeguards as required by the DPDP Act.

11. Cookies & Tracking

The VivelyDeploy platform uses minimal browser storage:

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes:

13. Contact Information

For any questions about this Privacy Policy or your personal data, please contact us:

Vively Technology Solutions
Email: business@vivelytech.com
Website: vivelytech.com
Platform: deploy.vivelytech.in