Privacy Policy
Last updated: July 16, 2026
Ubikon Technologies Pvt. Ltd.
CIN: U72200MP2016PTC036666 · GSTIN: 23AADCU9791R1Z0
C21 Mall, Vijay Nagar, Indore, Madhya Pradesh 452010, India
Data Protection Officer: privacy@ubikon.in · +91 6264818989
1. Who We Are
Ubikon Technologies Pvt. Ltd. ("Ubikon", "we", "us", "our") is a software development company registered in India (CIN U72200MP2016PTC036666) with registered office at C21 Mall, Vijay Nagar, Indore, Madhya Pradesh 452010, India. We operate the website ubikon.in, the Ubikon client portal, and a family of SaaS products (Ubikon CRM, Ubikon Invoice, JARVIS AI Voice, Aivonity, and others). We provide software development services and SaaS subscriptions to clients globally.
Data Controller / Data Fiduciary contact: privacy@ubikon.in Data Protection Officer (DPO) / Grievance Officer: Rinny Jacob — grievance@ubikon.in — +91 6264818989
2. Scope
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you:
Visit ubikon.in or any Ubikon-operated subdomain; Submit a lead form, request a proposal, or use a free tool; Subscribe to any Ubikon SaaS product; Engage us for custom software development; Make a payment via our checkout; Contact us via email, WhatsApp, or JARVIS chat.
This policy is written to comply with the Digital Personal Data Protection Act, 2023 (India), the EU / UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and RBI directions on payment data storage.
3. What Data We Collect
We collect the following categories of personal data:
Contact & lead data: Name, email address, phone number, company name, and project details submitted via our contact forms, free proposal requests, or tool lead captures.
Account data: Your login email, hashed password, portal profile, and preferences for SaaS product accounts.
Payment data: For payments, we collect your billing name, billing address, email, and phone. Full card numbers, CVV, and UPI PIN are never seen or stored by Ubikon — these are handled directly by the payment gateway (Razorpay, Stripe, Wise). We store a tokenised reference to the payment method (e.g., last 4 digits and card network) provided by the gateway, plus transaction IDs and status.
Usage data: Pages visited, time on page, referral source, browser type, and device type — collected via privacy-preserving analytics (no IP addresses stored beyond 24 hours).
Communication data: Email correspondence, chat messages via our JARVIS widget, and WhatsApp messages you initiate.
Tool inputs: Data entered into our free tools (App Cost Calculator, Startup Validator, etc.) is processed to generate results and is not stored permanently unless you opt in to receive a report.
Project & delivery data: For active clients, the source code, design files, and documentation associated with your project, plus any operational data you upload into our SaaS products.
Voice call data (JARVIS AI Voice): Where you or your customers speak to a JARVIS voice agent, we process the audio in real time and store transcripts. Recordings are retained for 90 days for quality assurance, then deleted.
4. How We Use Your Data
We use your data for the following purposes:
To respond to enquiries and deliver services: Processing project proposals, communicating about ongoing projects, providing client support, delivering SaaS access.
Payment processing: Charging, refunding, chargeback handling, fraud prevention, invoice generation, and tax compliance. Payment data is shared with Razorpay / Stripe / Wise strictly to complete the transaction you authorised.
Marketing and lead nurturing: Sending relevant content, case studies, and service updates to contacts who have opted in or have a legitimate interest relationship with us. You can unsubscribe at any time from any marketing email.
Recurring billing notifications: Sending you the mandatory 24-hour pre-debit notice for UPI AutoPay / e-Mandate / SI charges as required by RBI.
Product improvement: Aggregated, anonymised analytics to understand which pages, tools, and SaaS features are most useful.
Legal compliance: Fulfilling our obligations under applicable laws, including tax (GSTIN 23AADCU9791R1Z0), anti-money laundering, RBI directions, and data protection regulations.
We do not sell your personal data to third parties. Ever. We do not use your data to train third-party AI models.
5. Legal Basis for Processing
Under the Digital Personal Data Protection Act, 2023 (India), our lawful basis is either explicit consent or a "legitimate use" as defined in DPDP §7 (contract performance, legal compliance, medical emergency, employment).
For contacts in the European Economic Area and United Kingdom, our GDPR legal bases are:
Contractual necessity: Processing required to fulfil a contract with you or to take pre-contractual steps at your request.
Legitimate interests: Responding to enquiries, sending relevant marketing to existing contacts, and improving our services — balanced against your rights.
Consent: Where you have explicitly opted in, such as subscribing to our newsletter, requesting a report from our tools, or setting up a UPI AutoPay mandate.
Legal obligation: Where required by Indian tax law, RBI directions, or foreign data protection law.
For California residents, our processing is on the basis of our commercial relationship with you or your explicit request.
6. Payment Data & PCI DSS Compliance
All card payments processed through our checkout are handled by PCI DSS v4.0.1 Level 1 certified payment gateways (Razorpay Software Pvt. Ltd., Stripe Inc., Wise Payments Ltd.). Ubikon operates a SAQ-A compliance model: we redirect / iframe to the gateway's hosted checkout so that raw card numbers and CVV never touch our servers.
Where you save a card for future use ("card-on-file"), the gateway tokenises the card per RBI Card-on-File Tokenisation (CoFT) rules and returns to us only a network token or a masked reference. We store only this token, plus the last 4 digits, card network, and expiry.
For UPI AutoPay mandates, only the mandate reference (Umn) and status are stored by us; UPI ID and PIN are never seen by Ubikon.
Payment gateway processors we use:
Razorpay — for INR payments and international payments from Indian export clients. Razorpay's privacy policy: razorpay.com/privacy/ Stripe — for international card payments and USD/EUR/GBP transactions. Stripe's privacy policy: stripe.com/privacy Wise — for international wire transfers and multi-currency invoicing. Wise's privacy policy: wise.com/gb/legal/privacy-policy
7. Data Retention
We retain personal data only as long as necessary for the stated purposes:
Lead and enquiry data: 2 years from last contact, or until you request deletion.
Client project data: 7 years after project completion for legal, tax, and accounting purposes (per Indian Companies Act and GST record-keeping requirements).
SaaS account data: For the duration of your active subscription plus 30 days grace period post-cancellation. On explicit request, immediate deletion is honoured (subject to legal retention obligations).
Payment transaction records: 8 years, as required by RBI and Indian tax law.
Newsletter subscribers: Until you unsubscribe.
Tool inputs: Not stored beyond the session unless you opt in to receive a report.
Voice call recordings (JARVIS): 90 days; transcripts 2 years unless you request deletion.
Chat and email logs: 3 years unless required longer for legal proceedings.
8. Third-Party Processors
We share data with the following categories of third-party processors, all bound by data processing agreements:
Payment processing: Razorpay Software Pvt. Ltd. (India), Stripe Inc. (USA), Wise Payments Ltd. (UK). Purpose: process payments and refunds you authorise.
Cloud infrastructure: Google Cloud Platform (asia-south1 region — Mumbai / Delhi for India-hosted data), MongoDB Atlas, DigitalOcean (managed DNS). Purpose: host our platform. Data at rest is encrypted; data in transit uses TLS 1.3.
Email delivery: Nodemailer via SMTP to Gmail / Google Workspace (primary), and transactional email providers for scheduled notifications. Purpose: send you receipts, notifications, marketing emails.
Analytics: Privacy-preserving analytics that do not track individuals across sites or store raw IP addresses.
Customer chat: JARVIS chat runs on our own infrastructure; conversation transcripts are stored on our GCP database.
AI processing: OpenAI (via API) for AI features such as summarisation and lead scoring. We do not send raw payment data, passwords, or personally sensitive information to OpenAI. OpenAI is contractually prohibited from using our API data for model training per their Zero Data Retention API terms.
WhatsApp: Meta Platforms Ireland Ltd. — for WhatsApp Business messaging you initiate.
Voice / telecom: Twilio, Bolna, Exotel, Deepgram, Groq, Sarvam AI, ElevenLabs — for our JARVIS AI Voice feature. Used only where you have opted into voice services.
Error tracking: Sentry (US-hosted) — for exception logs. Personally identifying data is scrubbed from stack traces before transmission.
All third-party processors are subject to contractual data protection obligations and are chosen based on their compliance posture (SOC 2, ISO 27001, PCI DSS, GDPR).
9. Your Rights
Depending on your location, you have the following rights regarding your personal data:
Access: Request a copy of the personal data we hold about you.
Correction / Rectification: Request correction of inaccurate data.
Erasure: Request deletion of your data ("right to be forgotten"), subject to legal retention requirements.
Restriction: Request that we limit processing in certain circumstances.
Portability: Receive your data in a machine-readable format.
Objection: Object to processing based on legitimate interests, including direct marketing.
Grievance & Consent Manager: Under DPDP 2023, you can nominate a Consent Manager and access all consents given to Ubikon via privacy@ubikon.in.
Right to nominate: You may nominate a person to exercise your rights in case of your death or incapacity (DPDP §14).
To exercise any of these rights, email privacy@ubikon.in. We will respond within 30 days (as required by DPDP §11 and GDPR Art. 12). No fee is charged for reasonable requests.
10. Cookies & Tracking
Our website uses minimal cookies:
Essential cookies: Required for the website to function (session management, security, CSRF tokens, portal login state).
Analytics cookies: Privacy-preserving, first-party analytics only. No cross-site tracking. No advertising cookies unless you explicitly consent.
Payment cookies: Set by Razorpay / Stripe on the checkout page for fraud detection and 3DS authentication. Governed by their own privacy policies.
You can control cookies through your browser settings. Disabling essential cookies may affect site functionality.
We honour the Global Privacy Control (GPC) signal.
11. International Data Transfers
We are a global company with team members and infrastructure across multiple continents. Your data may be processed in countries outside your own.
Data of Indian residents: Primary storage on GCP asia-south1 (Mumbai / Delhi region) inside India. Cross-border transfer only where required (e.g., international payment processing, OpenAI API calls). Compliant with DPDP §16.
Data of EEA / UK residents: Where we transfer data outside the EEA or UK to countries without an adequacy decision, we use Standard Contractual Clauses (SCCs) approved by the European Commission and (where applicable) the UK ICO's International Data Transfer Addendum.
Data of US residents: Held under CCPA data minimisation principles.
The following categories of data may be transferred internationally, always encrypted in transit:
Payment data — to Razorpay / Stripe / Wise per your chosen payment method. Support and analytics data — to Sentry (USA), OpenAI (USA). Voice call audio — to Deepgram, Sarvam, ElevenLabs, Groq per your chosen voice pipeline.
12. Security
We implement reasonable and appropriate technical and organisational measures to safeguard your data:
Encryption in transit: TLS 1.3 for all network traffic. HSTS headers enforced. Encryption at rest: AES-256 on database and backup volumes. Access controls: Role-based access; principle of least privilege; audit logs for all admin actions. Authentication: Bcrypt password hashing (min 10 chars + uppercase + lowercase + digit); JWT session tokens (7-day expiry); optional magic-link email login. Payment security: PCI DSS v4.0.1 SAQ-A compliance; no card / CVV / UPI PIN on Ubikon servers. Monitoring: Sentry for exception tracking; rate limiting; open-redirect and XSS prevention; input sanitisation; Zod schema validation on all API inputs. Data segregation: Multi-tenant architecture with tenant-scoped queries. Backups: Daily encrypted MongoDB snapshots; retained 30 days. Vendor due diligence: All third-party processors selected on compliance posture.
Despite these measures, no system is 100% secure. In the event of a personal data breach affecting you, we will notify you and the applicable regulator within 72 hours as required by DPDP §8(6), GDPR Art. 33, and CCPA.
13. Children
Our services are not directed to children under the age of 18. We do not knowingly collect personal data of children. If you believe a child has provided us data, contact privacy@ubikon.in and we will delete it. Per DPDP §9, processing of children's data requires verifiable parental consent.
14. Automated Decision-Making
We use automated processing for the following:
Lead scoring: Estimating deal potential from form inputs. This does not have significant legal effect on you. Fraud detection: Payment gateways run automated fraud scoring on transactions. JARVIS AI: Conversational AI responses. You may always request a human handover.
None of the above constitutes a decision producing legal or similarly significant effects solely by automated means, as defined by GDPR Art. 22.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified to registered clients and newsletter subscribers by email at least 15 days before taking effect. The date at the top of this page indicates when the policy was last updated. Continued use after changes constitutes acceptance.
16. Contact & Complaints
For privacy questions, to exercise your rights, or to file a complaint:
Data Protection Officer / Grievance Officer: Rinny Jacob — privacy@ubikon.in — +91 6264818989 Postal: Ubikon Technologies Pvt. Ltd., C21 Mall, Vijay Nagar, Indore, Madhya Pradesh 452010, India
Response SLA: 48 hours acknowledgement, 30 days resolution (per DPDP §11, GDPR Art. 12).
If unresolved:
India: Escalate to the Data Protection Board of India (dpb.gov.in) once operational. EU: Lodge a complaint with your local supervisory authority. UK: Information Commissioner's Office (ICO) at ico.org.uk. California: California Attorney General or the California Privacy Protection Agency.
