This Data Policy describes how DevAura technically collects, stores, secures, retains, and shares data — it complements our Privacy Policy, which describes your rights and our lawful basis for processing. Where the two documents overlap, they are intended to be read together and are not in conflict. This policy is drafted in accordance with the Information Technology Act, 2000 (Act No. 21 of 2000), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the CERT-In Cyber Security Directions of 28 April 2022 (issued under Section 70B(6) of the IT Act), and — in anticipation of its commencement — the Digital Personal Data Protection Act, 2023. Per Gazette notification G.S.R. 843(E) dated 13 November 2025, the DPDP Act's core Data Fiduciary obligations commence on 13 May 2027 and are not yet in force as of the date of this policy; we describe our voluntary alignment with them below.

1. What Data We Collect

Account and identity data: first name, last name, email address, phone number, password (stored as a salted hash, never in plain text).

Ritual preference data: gotra, sampradaya, kuladevata, and paddhati preference, collected solely to match you with an appropriate pandit.

Transaction and booking data: booking IDs, order IDs, ceremony date/time, ceremony or delivery address, payment mode preference. We do not store full card numbers, CVVs, or UPI PINs — these are handled directly by our payment gateway partner, not by DevAura's own servers.

Device and log data: IP address, browser type and version, pages visited, referring URL, and timestamps — collected automatically via server logs for security and diagnostic purposes.

2. How We Collect It

Directly from you, when you create an account, make a booking, place an order, or contact us; and automatically, via standard web server logging, when you browse the site.

3. Where and How Data Is Stored

Data is stored on hosting infrastructure operated by our web hosting provider. We take reasonable steps to prefer data storage within India where operationally feasible, consistent with data localisation expectations under Indian law. Passwords are stored as salted cryptographic hashes, never in plain text. Data in transit between your browser and our servers is encrypted using TLS 1.2 or higher.

4. How Long We Keep It

Booking and transaction records: retained for 8 years, consistent with limitation periods under the Limitation Act, 1963 (Act No. 36 of 1963), and applicable tax and accounting record-keeping norms.

Server and security logs: retained for a rolling period of at least 180 days, consistent with the log-retention requirement under the CERT-In Directions dated 28 April 2022 (issued under Section 70B(6) of the Information Technology Act, 2000).

Account data: retained for as long as your account is active, and deleted within 30 days of a verified account-deletion request, except where continued retention is required by law.

5. Who We Share Data With

Pandits on our panel — limited to ceremony-relevant details (name, address, gotra, sampradaya, booking time) needed to perform the ceremony.

Payment processors — for transaction processing only. We do not share your data with payment processors for their own marketing purposes.

Hosting and infrastructure providers — who store data on our behalf under contractual confidentiality obligations, and do not independently use it for their own purposes.

Legal and regulatory authorities — where required under applicable Indian law, including in response to a valid legal order.

We do not sell, rent, or trade your personal data to any third party for their independent marketing use.

6. Security Measures

We apply reasonable security practices as required under Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. These include: encrypted data transmission (TLS 1.2+), access controls limiting who within our team can view personal data, and periodic review of our security practices.

7. Data Security Incident Response

In the event of a cyber security incident affecting personal data, we follow the reporting timeline mandated by the CERT-In Directions dated 28 April 2022 (issued under Section 70B(6) of the Information Technology Act, 2000) — reporting qualifying incidents to CERT-In within 6 hours of becoming aware of them. Where a data breach affects you personally, we will notify you without undue delay once we have enough information to do so meaningfully, in anticipation of the breach-notification principles under the DPDP Act, 2023 (not yet in force — see note above).

8. Your Control Over Your Data

You may request a copy of the personal data we hold about you, request correction of inaccurate data, or request deletion of your account and associated data (subject to our legal retention obligations described in Section 4) by writing to connect@devaura.co.in. We aim to respond within 30 days.

9. Children's Data

DevAura does not knowingly collect personal data from children (persons under 18 years of age). If we become aware that we have collected data from a child without verifiable parental consent, we will delete it promptly.

10. Changes to This Policy

We may update this Data Policy from time to time, particularly as the DPDP Act's provisions come into force. The "Last updated" date at the top reflects the most recent revision.

11. Questions

For any question about how your data is handled, write to connect@devaura.co.in.