Back to Legal & Compliance Center
DPDP Act 2023 CompliantEffective Date: September 18, 2026

Privacy Policy

Proventa Technologies Private Limited (“Proventa”, “we”, “us”) is committed to the sovereign protection and lawful processing of your personal data.

1. Fundamental Principles & Zero-Monetization Mandate

Proventa operates as an exclusive, private Concierge Life OS. Our business model is founded strictly on subscription membership and concierge service fees.

Our Unconditional Sovereignty Guarantee:
  • We do NOT sell, license, lease, or monetize your personal information to third parties.
  • We do NOT display third-party advertisements or integrate behavioral ad trackers.
  • We do NOT share your request history or preferences with data brokers.
  • Your private concierge requests and prompts are NEVER used to train foundational AI models.

2. Data We Collect

Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we only collect personal data that is strictly necessary for fulfilling your concierge mandates:

Identity & Contact InformationFull legal name, verified email address, phone number (used for SMS/WhatsApp verification and urgent concierge escalation), and optional residential delivery addresses.
Lifestyle & Member PreferencesDietary requirements, seating preferences, preferred airlines/cabin class, hotel loyalty affiliations, and concierge service preferences explicitly provided during onboarding or chat.
Concierge Task Data & Approval HistoryTask descriptions submitted through “Tell Proventa”, uploaded documents/itineraries, proposal selections, explicit approval/rejection timestamps, and internal fulfillment notes.
Technical, Security & Audit TelemetryEncrypted session authentication tokens, IP addresses, browser user-agent, rate-limiting counters, and immutable audit logs of system interactions.

3. Purpose & Legal Grounds for Processing

We process your data based on your explicit consent given at registration and the contractual necessity of providing concierge services:

  • Concierge Task Execution: Synthesizing vendor options, arranging table bookings, flight research, and ground transport dispatch.
  • Member Communication: Providing real-time proposal updates, booking confirmation call sheets, and security notifications.
  • Audit & Security: Maintaining immutable tamper-evident logs of approvals and payments to prevent unauthorized transactions.
  • Statutory Compliance: Maintaining accounting, tax, and invoicing records as required under Indian commercial law.

4. Third-Party Sharing & Intermediary Role

Proventa acts as an authorized intermediary. We only share specific data with external service providers when necessary to execute an approved task:

Provider Integration Principle: When you approve an option (e.g. reserving a table at a dining venue or booking a flight via a global distribution system), Proventa shares only the minimal data required by the external provider (such as guest name, party size, dietary flags, or passenger passport details).

Proventa does not disclose your full account history or other unrelated requests to any vendor. Third-party providers operate under their own independent privacy notices.

5. Cloud Infrastructure & Data Security

Proventa implements defense-in-depth technical safeguards to protect your personal data:

  • Database Sovereignty: Primary production PostgreSQL is hosted in AWS Asia Pacific (Singapore) via Neon, with automated SSL/TLS encryption in transit and AES-256 at rest.
  • Credential Security: All passwords are cryptographic hashes using bcrypt with high work factors. Plaintext passwords are never stored or logged.
  • Access Control: Administrative access to member profiles is strictly restricted server-side via role-based access control (SUPER_ADMIN / ADMIN) and logged to tamper-evident audit trails.

6. Data Retention, Portability & Erasure (DPDP Rights)

Under the DPDP Act 2023, you maintain complete sovereignty over your digital footprint on Proventa:

Right to Access & PortabilityYou can download a complete, machine-readable JSON export of all personal data, preferences, task history, and audit records at any time via Data Rights Portal or the API endpoint /api/customer/export.
Right to Erasure (Right to be Forgotten)You can invoke complete account erasure via /api/customer/delete (requiring confirmation string DELETE_MY_ACCOUNT). Upon invocation:
  • Your name, email, phone number, and preferences are scrubbed and anonymized.
  • All active authentication sessions are instantly revoked.
  • Historical financial invoices and audit event IDs are preserved strictly for statutory tax compliance.

7. Grievance Officer & Statutory Inquiries

In accordance with the Digital Personal Data Protection Act, 2023, you may address any inquiries, complaints, or grievance escalations to our designated Grievance Officer:

Grievance Officer: TODO [Founder Configuration: Grievance Officer Name]
Designation: Data Protection & Compliance Officer
Registered Jurisdiction: Ahmedabad, Gujarat, India

We acknowledge grievances within 24 hours and resolve inquiries within 30 days as prescribed by law.