01Data Fiduciary Identity & Scope
This Privacy Policy governs the processing of personal data by The Revieree Studios (a commercial venture and brand operated under legal entity Yasavri Multibiz Pvt Ltd), having its principal office at The Revieree Studios, Bund Garden Road, Pune, Maharashtra 411001, India (hereinafter referred to as the "Data Fiduciary", "we", "us", or "our").
We are committed to protecting the privacy, confidentiality, and statutory rights of Data Principals ("you", "your", or "user") in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and applicable rules framed thereunder.
02Specified Grounds & Purposes of Processing (Section 5)
In accordance with Section 5 of the DPDP Act, personal data is collected and processed solely for specified, lawful, and explicit purposes based on valid, free, informed, unconditional, and unambiguous consent, or for legitimate uses recognized by law:
- Studio Inquiries & Client Engagement: Processing names, business emails, phone numbers, and project briefs submitted via our contact and briefing forms to evaluate, scope, and execute creative mandates.
- Platform Performance & Security: Operating our web infrastructure, maintaining system resilience, preventing cyber security incidents, and monitoring abuse under Section 8.
- Consensual Analytics: Aggregating non-identifiable usage statistics to optimize website storytelling, interactive motion performance, and user navigation, strictly contingent upon consent collected via our Consent Management Platform (CMP).
- Statutory Compliance & Legal Obligations: Fulfilling tax, corporate governance, auditing, and regulatory requirements under Indian law.
03Categories of Personal Data Collected
Directly Provided Information
- • Full Name and Corporate Affiliation
- • Business Email Address (
name@company.com) - • Telephone / WhatsApp Contact Number
- • Project Brief details, budget ranges, and design requirements
Telemetry & Technical Data
- • IP Address (anonymized for geolocation verification)
- • Browser Type, Version, and Viewport Resolution
- • Cookie consent tokens and timestamp records
- • Referrer URLs and page interaction latencies
04Third-Party Data Processors & Cloud Infrastructure
We engage trusted third-party Data Processors bound by written contracts and strict confidentiality obligations pursuant to Section 8(2) of the DPDP Act. We never sell, rent, or trade your personal data to third parties for commercial advertising.
- Cloud Database & Storage: Neon Serverless PostgreSQL (encrypted data at rest and in transit via TLS 1.3).
- Media Asset Delivery: Cloudinary Inc. (optimized image rendering and CDN caching).
- Edge Hosting & CDN: Vercel Inc. and Cloudflare (distributed delivery and DDoS mitigation).
05Data Retention Policy & Storage Limitation (Section 8(7))
Under Section 8(7) of the DPDP Act (Storage Limitation), we retain personal data only for as long as necessary to satisfy the specified purpose for which it was collected, or as required by statutory record-keeping regulations.
• Prospective Client Inquiries: Retained for a maximum of 180 days following the last substantive communication, after which records are permanently purged or anonymized.
• Executed Client Contracts & Invoices: Retained for 8 financial years in accordance with the Companies Act, 2013 and Goods and Services Tax (GST) statutory requirements.
• Consent Records & Logs: Retained for 3 years to demonstrate compliance with DPDP consent notices and regulatory audits.
• Immediate Deletion on Request: Upon receipt of a valid erasure request or consent withdrawal under Section 11, data is erased within 7 calendar days across active databases and backups.
06Children's Data Protection & Age Gate (Section 9)
In strict compliance with Section 9 of the DPDP Act:
- Not Intended for Minors: Our services, creative agency solutions, and website are directed strictly at business entities and individuals who are at least 18 years of age (legally competent to contract under the Indian Contract Act, 1872).
- No Knowingly Collected Children's Data: We do not knowingly solicit, collect, or process personal data from children under the age of 18 or persons with disability without verifiable parental consent.
- Prohibition on Behavioral Monitoring: We do not engage in behavioral monitoring, tracking, or targeted advertising directed at children.
- Parental Deletion Mechanism: If a parent or guardian becomes aware that a child has submitted personal data without verifiable consent, they may contact our Grievance Officer at grievance@thereviereestudios.com for immediate, irreversible erasure within 48 hours.
07Rights of Data Principals (Section 11 — DSAR)
As a Data Principal under the DPDP Act, you possess explicit, legally enforceable statutory rights:
To exercise any of the above rights, visit our dedicated Data Rights (DSAR) Portal or email our Grievance Officer.
08Grievance Officer & Data Protection Officer (Section 10 & 13)
In accordance with Section 10 and Section 13 of the DPDP Act and Rule 3(11) of the Information Technology (Intermediary Guidelines) Rules, we have designated an official Grievance Redressal Officer & Data Protection Officer:
09Technical & Organisational Security Safeguards (Section 8)
We implement industry-grade technical and organizational security measures pursuant to Section 8(5) to prevent personal data breaches:
- Full Transport Encryption: Enforced HTTPS with TLS 1.3 encryption across all public and authenticated endpoints.
- Database Encryption: High-entropy cryptographic hashing and AES-256 encryption at rest.
- Zero-Trust Access Control: Strict least-privilege role-based access control (RBAC) and immutable administrative audit logs.