Skip to content
Legal

Privacy Policy

Last updated: August 16, 2026

Ubikon Technologies Pvt. Ltd.

CIN: U74999MP2017OPC044370  ·  GSTIN: 23AACCU1607J1ZM

2nd Floor, Swaraj Enterprises, Above Table World, Behind C21 Mall, Vijay Nagar, Indore, Madhya Pradesh 452010, India

Data Protection Officer: privacy@ubikon.in  ·  +91 62648 18989

1. Who We Are

Ubikon Technologies Pvt. Ltd. ("Ubikon", "we", "us", "our") is a software development company registered in India (CIN U74999MP2017OPC044370) with registered office at 2nd Floor, Swaraj Enterprises, Above Table World, Behind C21 Mall, Vijay Nagar, Indore, Madhya Pradesh 452010, India. We operate the website ubikon.in, the Ubikon client portal, and a family of SaaS products (Ubikon CRM, Ubikon Invoice, JARVIS AI Voice, Aivonity, and others). We provide software development services and SaaS subscriptions to clients globally.

Data Controller / Data Fiduciary contact: privacy@ubikon.in Data Protection Officer (DPO) / Grievance Officer: Rinny Jacob — grievance@ubikon.in — +91 62648 18989

2. Scope

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you:

Visit ubikon.in or any Ubikon-operated subdomain; Submit a lead form, request a proposal, or use a free tool; Subscribe to any Ubikon SaaS product; Engage us for custom software development; Make a payment via our checkout; Contact us via email, WhatsApp, or JARVIS chat.

This policy is written to comply with the Digital Personal Data Protection Act, 2023 (India), the EU / UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and RBI directions on payment data storage.

3. What Data We Collect

We collect the following categories of personal data:

Contact & lead data: Name, email address, phone number, company name, and project details submitted via our contact forms, free proposal requests, or tool lead captures.

Account data: Your login email, hashed password, portal profile, and preferences for SaaS product accounts.

Payment data: For payments, we collect your billing name, billing address, email, and phone. Full card numbers, CVV, and UPI PIN are never seen or stored by Ubikon — these are handled directly by the payment gateway (Razorpay, Stripe, Wise). We store a tokenised reference to the payment method (e.g., last 4 digits and card network) provided by the gateway, plus transaction IDs and status.

Usage data: Pages visited, time on each page, scroll and click behaviour, referral source (including UTM campaign parameters and ad click identifiers), approximate location derived from IP (country / city), browser and device type. Collected through the analytics and session-recording tools named in sections 8 and 10.

Enquiry context: When you submit a form or share your contact details with our assistant, we attach the pages you read in that session, the time spent on each, and your visit count, so we understand what you are looking for before we reply. This is held in your own browser while you browse and sent only when you choose to submit — see section 10.

Aggregated demographics: Where Google Signals is enabled, Google reports estimated age brackets, gender and interest categories for the portion of visitors signed in to a Google Account with Ads Personalisation on. We receive this only as aggregate statistics and never at the level of an individual person.

Communication data: Email correspondence, chat messages via our JARVIS widget, and WhatsApp messages you initiate.

Tool inputs: Data entered into our free tools (App Cost Calculator, Startup Validator, etc.) is processed to generate results and is not stored permanently unless you opt in to receive a report.

Project & delivery data: For active clients, the source code, design files, and documentation associated with your project, plus any operational data you upload into our SaaS products.

Voice call data (JARVIS AI Voice): Where you or your customers speak to a JARVIS voice agent, we process the audio in real time and store transcripts. Recordings are retained for 90 days for quality assurance, then deleted.

4. How We Use Your Data

We use your data for the following purposes:

To respond to enquiries and deliver services: Processing project proposals, communicating about ongoing projects, providing client support, delivering SaaS access.

Payment processing: Charging, refunding, chargeback handling, fraud prevention, invoice generation, and tax compliance. Payment data is shared with Razorpay / Stripe / Wise strictly to complete the transaction you authorised.

Marketing and lead nurturing: Sending relevant content, case studies, and service updates to contacts who have opted in or have a legitimate interest relationship with us. You can unsubscribe at any time from any marketing email.

Recurring billing notifications: Sending you the mandatory 24-hour pre-debit notice for UPI AutoPay / e-Mandate / SI charges as required by RBI.

Product improvement: Aggregated, anonymised analytics to understand which pages, tools, and SaaS features are most useful.

Legal compliance: Fulfilling our obligations under applicable laws, including tax (GSTIN 23AACCU1607J1ZM), anti-money laundering, RBI directions, and data protection regulations.

We do not sell your personal data to third parties. Ever. We do not use your data to train third-party AI models.

5. Legal Basis for Processing

Under the Digital Personal Data Protection Act, 2023 (India), our lawful basis is either explicit consent or a "legitimate use" as defined in DPDP §7 (contract performance, legal compliance, medical emergency, employment).

For contacts in the European Economic Area and United Kingdom, our GDPR legal bases are:

Contractual necessity: Processing required to fulfil a contract with you or to take pre-contractual steps at your request.

Legitimate interests: Responding to enquiries, sending relevant marketing to existing contacts, and improving our services — balanced against your rights.

Consent: Where you have explicitly opted in, such as subscribing to our newsletter, requesting a report from our tools, or setting up a UPI AutoPay mandate.

Legal obligation: Where required by Indian tax law, RBI directions, or foreign data protection law.

For California residents, our processing is on the basis of our commercial relationship with you or your explicit request.

6. Payment Data & PCI DSS Compliance

All card payments processed through our checkout are handled by PCI DSS v4.0.1 Level 1 certified payment gateways (Razorpay Software Pvt. Ltd., Stripe Inc., Wise Payments Ltd.). Ubikon operates a SAQ-A compliance model: we redirect / iframe to the gateway's hosted checkout so that raw card numbers and CVV never touch our servers.

Where you save a card for future use ("card-on-file"), the gateway tokenises the card per RBI Card-on-File Tokenisation (CoFT) rules and returns to us only a network token or a masked reference. We store only this token, plus the last 4 digits, card network, and expiry.

For UPI AutoPay mandates, only the mandate reference (Umn) and status are stored by us; UPI ID and PIN are never seen by Ubikon.

Payment gateway processors we use:

Razorpay — for INR payments and international payments from Indian export clients. Razorpay's privacy policy: razorpay.com/privacy/ Stripe — for international card payments and USD/EUR/GBP transactions. Stripe's privacy policy: stripe.com/privacy Wise — for international wire transfers and multi-currency invoicing. Wise's privacy policy: wise.com/gb/legal/privacy-policy

7. Data Retention

We retain personal data only as long as necessary for the stated purposes:

Lead and enquiry data: 2 years from last contact, or until you request deletion.

Client project data: 7 years after project completion for legal, tax, and accounting purposes (per Indian Companies Act and GST record-keeping requirements).

SaaS account data: For the duration of your active subscription plus 30 days grace period post-cancellation. On explicit request, immediate deletion is honoured (subject to legal retention obligations).

Payment transaction records: 8 years, as required by RBI and Indian tax law.

Newsletter subscribers: Until you unsubscribe.

Tool inputs: Not stored beyond the session unless you opt in to receive a report.

Voice call recordings (JARVIS): 90 days; transcripts 2 years unless you request deletion.

Chat and email logs: 3 years unless required longer for legal proceedings.

8. Third-Party Processors

We share data with the following categories of third-party processors, all bound by data processing agreements:

Payment processing: Razorpay Software Pvt. Ltd. (India), Stripe Inc. (USA), Wise Payments Ltd. (UK). Purpose: process payments and refunds you authorise.

Cloud infrastructure: Google Cloud Platform (asia-south1 region — Mumbai / Delhi for India-hosted data), MongoDB Atlas, DigitalOcean (managed DNS). Purpose: host our platform. Data at rest is encrypted; data in transit uses TLS 1.3.

Email delivery: Nodemailer via SMTP to Gmail / Google Workspace (primary), and transactional email providers for scheduled notifications. Purpose: send you receipts, notifications, marketing emails.

Analytics & measurement: Google Analytics 4 (Google Ireland Ltd. / Google LLC) — website measurement, and, where Google Signals is enabled, aggregated age, gender and interest reporting for visitors signed in to a Google Account with Ads Personalisation on. Microsoft Clarity (Microsoft Corporation) — heatmaps and session recordings of on-page behaviour such as clicks, scrolling and navigation. Umami Cloud — privacy-preserving aggregate site statistics. See section 10 for what each collects and how to opt out.

Advertising & remarketing: Google Ads, Meta (Facebook) Pixel and LinkedIn Insight Tag — used to measure ad conversions and build remarketing audiences. These are only active where the relevant campaign is running.

Customer chat: JARVIS chat runs on our own infrastructure; conversation transcripts are stored on our GCP database.

AI processing: OpenAI (via API) for AI features such as summarisation and lead scoring. We do not send raw payment data, passwords, or personally sensitive information to OpenAI. OpenAI is contractually prohibited from using our API data for model training per their Zero Data Retention API terms.

WhatsApp: Meta Platforms Ireland Ltd. — for WhatsApp Business messaging you initiate.

Voice / telecom: Twilio, Bolna, Exotel, Deepgram, Groq, Sarvam AI, ElevenLabs — for our JARVIS AI Voice feature. Used only where you have opted into voice services.

Error tracking: Sentry (US-hosted) — for exception logs. Personally identifying data is scrubbed from stack traces before transmission.

All third-party processors are subject to contractual data protection obligations and are chosen based on their compliance posture (SOC 2, ISO 27001, PCI DSS, GDPR).

9. Your Rights

Depending on your location, you have the following rights regarding your personal data:

Access: Request a copy of the personal data we hold about you.

Correction / Rectification: Request correction of inaccurate data.

Erasure: Request deletion of your data ("right to be forgotten"), subject to legal retention requirements.

Restriction: Request that we limit processing in certain circumstances.

Portability: Receive your data in a machine-readable format.

Objection: Object to processing based on legitimate interests, including direct marketing.

Grievance & Consent Manager: Under DPDP 2023, you can nominate a Consent Manager and access all consents given to Ubikon via privacy@ubikon.in.

Right to nominate: You may nominate a person to exercise your rights in case of your death or incapacity (DPDP §14).

To exercise any of these rights, email privacy@ubikon.in. We will respond within 30 days (as required by DPDP §11 and GDPR Art. 12). No fee is charged for reasonable requests.

10. Cookies, Analytics & Advertising Features

Our website uses the following cookies and similar technologies:

Essential cookies: Required for the website to function (session management, security, CSRF tokens, portal login state).

Analytics cookies: Google Analytics 4, Microsoft Clarity and Umami set first-party cookies to recognise a returning browser and measure how the site is used — pages viewed, time on page, scroll and click behaviour, referral source, approximate location (country / city, derived from IP), device and browser type.

Session recording: Microsoft Clarity records on-page interactions (mouse movement, clicks, scrolling, navigation) so we can see where the site is confusing. Recordings exclude the contents of password fields and are retained for 30 days. Where you submit an enquiry, we may associate that recording with your email address, which Clarity stores only as an irreversible hash — never as plain text.

Advertising cookies: Google Ads, Meta (Facebook) Pixel and LinkedIn Insight Tag set cookies to measure ad conversions and show you remarketing ads. These run only while the relevant campaign is active.

Payment cookies: Set by Razorpay / Stripe on the checkout page for fraud detection and 3DS authentication. Governed by their own privacy policies.

GOOGLE ANALYTICS ADVERTISING FEATURES — REQUIRED DISCLOSURE

We have enabled Google Analytics Advertising Features, specifically Google Signals (demographics and interests reporting, and cross-device reporting), together with Google Ads remarketing and conversion measurement.

These features mean that Google Analytics first-party cookies (or other first-party identifiers) and third-party cookies used by Google advertising services — including the DoubleClick cookie — may be read together to report on your visit, to build aggregated audience segments, and to measure advertising performance. Demographic and interest data is available only for visitors who are signed in to a Google Account with Ads Personalisation switched on, and Google provides it to us in AGGREGATE form only. We never receive, and never attempt to determine, the age, gender or interests of an individual visitor.

HOW TO OPT OUT

You can opt out of these features at any time, without affecting your ability to use the site:

Google Ads Settings (myadcenter.google.com) — turn off Ads Personalisation. This stops your Google Account data being used for demographics and interest reporting. Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout) — stops Google Analytics measurement entirely. Network Advertising Initiative opt-out (optout.networkadvertising.org) and Digital Advertising Alliance (optout.aboutads.info) — opt out of participating advertising vendors. Microsoft Clarity opt-out (clarity.microsoft.com/terms) — stops Clarity recording your sessions. Your browser settings — block or delete cookies at any time. Disabling essential cookies may affect site functionality.

WHAT WE SEND WITH AN ENQUIRY

If you choose to submit a form, book a call, or share your email with our JARVIS assistant, we attach the pages you viewed in that session, how long you spent on each, and how many times you have visited, so we can prepare properly before speaking with you. This information is kept in your own browser while you browse and is transmitted only at the moment you submit the form — never in the background. We do not sell it, and it is deleted with your lead record on request (see section 9).

We honour the Global Privacy Control (GPC) signal.

11. International Data Transfers

We are a global company with team members and infrastructure across multiple continents. Your data may be processed in countries outside your own.

Data of Indian residents: Primary storage on GCP asia-south1 (Mumbai / Delhi region) inside India. Cross-border transfer only where required (e.g., international payment processing, OpenAI API calls). Compliant with DPDP §16.

Data of EEA / UK residents: Where we transfer data outside the EEA or UK to countries without an adequacy decision, we use Standard Contractual Clauses (SCCs) approved by the European Commission and (where applicable) the UK ICO's International Data Transfer Addendum.

Data of US residents: Held under CCPA data minimisation principles.

The following categories of data may be transferred internationally, always encrypted in transit:

Payment data — to Razorpay / Stripe / Wise per your chosen payment method. Support and analytics data — to Sentry (USA), OpenAI (USA). Voice call audio — to Deepgram, Sarvam, ElevenLabs, Groq per your chosen voice pipeline.

12. Security

We implement reasonable and appropriate technical and organisational measures to safeguard your data:

Encryption in transit: TLS 1.3 for all network traffic. HSTS headers enforced. Encryption at rest: AES-256 on database and backup volumes. Access controls: Role-based access; principle of least privilege; audit logs for all admin actions. Authentication: Bcrypt password hashing (min 10 chars + uppercase + lowercase + digit); JWT session tokens (7-day expiry); optional magic-link email login. Payment security: PCI DSS v4.0.1 SAQ-A compliance; no card / CVV / UPI PIN on Ubikon servers. Monitoring: Sentry for exception tracking; rate limiting; open-redirect and XSS prevention; input sanitisation; Zod schema validation on all API inputs. Data segregation: Multi-tenant architecture with tenant-scoped queries. Backups: Daily encrypted MongoDB snapshots; retained 30 days. Vendor due diligence: All third-party processors selected on compliance posture.

Despite these measures, no system is 100% secure. In the event of a personal data breach affecting you, we will notify you and the applicable regulator within 72 hours as required by DPDP §8(6), GDPR Art. 33, and CCPA.

13. Children

Our services are not directed to children under the age of 18. We do not knowingly collect personal data of children. If you believe a child has provided us data, contact privacy@ubikon.in and we will delete it. Per DPDP §9, processing of children's data requires verifiable parental consent.

14. Automated Decision-Making

We use automated processing for the following:

Lead scoring: Estimating deal potential from form inputs. This does not have significant legal effect on you. Fraud detection: Payment gateways run automated fraud scoring on transactions. JARVIS AI: Conversational AI responses. You may always request a human handover.

None of the above constitutes a decision producing legal or similarly significant effects solely by automated means, as defined by GDPR Art. 22.

15. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to registered clients and newsletter subscribers by email at least 15 days before taking effect. The date at the top of this page indicates when the policy was last updated. Continued use after changes constitutes acceptance.

16. Contact & Complaints

For privacy questions, to exercise your rights, or to file a complaint:

Data Protection Officer / Grievance Officer: Rinny Jacob — privacy@ubikon.in — +91 62648 18989 Postal: Ubikon Technologies Pvt. Ltd., 2nd Floor, Swaraj Enterprises, Above Table World, Behind C21 Mall, Vijay Nagar, Indore, Madhya Pradesh 452010, India

Response SLA: 48 hours acknowledgement, 30 days resolution (per DPDP §11, GDPR Art. 12).

If unresolved:

India: Escalate to the Data Protection Board of India (dpb.gov.in) once operational. EU: Lodge a complaint with your local supervisory authority. UK: Information Commissioner's Office (ICO) at ico.org.uk. California: California Attorney General or the California Privacy Protection Agency.