Privacy Policy

    Last updated:

    This Policy is designed for users in India and describes how we handle personal data across our website and products.

    1. Introduction

    This Privacy Policy explains how Nevioz ("we", "us", or "our") collects, uses, stores, discloses, and otherwise processes personal data when you use our website at www.nevioz.com, our products (including Flowcraft and Zalonz), contact forms, waitlists, demos, newsletters, and related services (collectively, the "Services").

    We are committed to protecting your privacy in line with applicable laws in India, including the Information Technology Act, 2000 ("IT Act"), the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDP Act") and rules / guidelines issued thereunder, as updated from time to time.

    By using the Services or submitting personal data to us, you acknowledge this Policy. If you do not agree, please do not use the Services.

    2. Data fiduciary and contact

    For the purposes of the DPDP Act, Nevioz acts as a Data Fiduciary in respect of personal data processed through the Services. Our principal place of business in India is Surat, Gujarat, India.

    General enquiries: hello@nevioz.com
    Phone: +91 8460079523

    3. Categories of personal data we may collect

    Depending on how you interact with us, we may collect:

    • Identity and contact data: name, email address, phone number, company or organisation name, job title, city or region.
    • Account and usage data: login identifiers, preferences, device or browser type, IP address, approximate location derived from IP, pages viewed, referring URLs, timestamps, and diagnostic logs.
    • Communication content: messages you send via forms, email, chat widgets, or support channels.
    • Marketing data: subscription choices, event registrations, and campaign interactions.
    • Payment-related data (if applicable): where payments are enabled, payment status and limited billing identifiers — payment card data is typically processed only by certified payment partners, not stored by us as full card numbers unless expressly stated for a given product.

    Certain categories may be treated as sensitive personal data or information under the SPDI Rules (for example, financial information, health information, or official identifiers) if you voluntarily provide them in connection with the Services. We collect such categories only where permitted by law and with appropriate notice and consent where required.

    4. Purposes and legal bases for processing

    We process personal data for purposes such as:

    • Providing, operating, securing, and improving the Services;
    • Creating and managing accounts, authentication, and support;
    • Responding to enquiries, demos, partnerships, and waitlist requests;
    • Sending service, technical, and administrative messages;
    • Marketing and newsletters where permitted and, where required, based on your consent (which you may withdraw);
    • Complying with legal obligations, court orders, or lawful requests from government authorities in India;
    • Detecting, preventing, or investigating fraud, abuse, or security incidents;
    • Exercising or defending legal claims.

    Under the DPDP Act, we rely on applicable grounds such as consent (where required), legitimate uses notified under law, voluntary provision of data by you for specified purposes, and legal compliance, as relevant to each processing activity.

    5. Cookies and similar technologies

    We and our partners may use cookies, local storage, pixels, and similar technologies for essential site function, analytics, and (where you agree) marketing. You can control many cookies through your browser settings. Restricting cookies may affect certain features.

    6. Disclosure and subprocessors

    We may share personal data with:

    • Service providers who assist us with hosting, email delivery, analytics, customer support, security monitoring, and similar functions, under contractual confidentiality and security obligations;
    • Professional advisers (lawyers, auditors) where necessary;
    • Authorities when required by applicable Indian law or to protect rights, safety, and integrity of users and the public.

    If personal data is transferred outside India, we do so in accordance with applicable law and implement appropriate safeguards (including contracts or standard arrangements as prescribed from time to time).

    7. Retention

    We retain personal data only as long as necessary for the purposes described, including to satisfy legal, accounting, or reporting requirements. Retention periods vary by data category and product. When data is no longer required, we delete or anonymise it in line with our internal policies, subject to applicable law.

    8. Security

    We implement reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. No method of transmission over the Internet is fully secure; we encourage you to use strong passwords and protect your credentials. Further detail is available on our Security page.

    9. Your rights as a data principal (India)

    Subject to the DPDP Act and other applicable laws, you may have rights including, where applicable, to obtain information about processing, to seek correction or completion of inaccurate data, to request erasure where grounds apply, to withdraw consent (without affecting lawfulness of prior processing), to nominate another individual to exercise rights in the event of death or incapacity, and to register a grievance with us as described below.

    You may also have rights under the SPDI Rules in respect of sensitive personal data or information, including to review the information we hold and to update or correct it where it is found inaccurate or deficient.

    To exercise rights, contact us at hello@nevioz.com. We may need to verify your identity before responding. We will respond within timelines prescribed under law where applicable.

    10. Grievance officer (India)

    In accordance with the SPDI Rules and our commitment under the DPDP framework, we have designated a Grievance Officer for India:

    • Designation: Grievance Officer, Nevioz
    • Email: hello@nevioz.com
    • Phone: +91 8460079523
    • Address: Surat, Gujarat, India

    Please mark the subject line clearly (for example, "Privacy grievance"). We will endeavour to acknowledge and address grievances in line with applicable statutory timelines and good practice.

    11. Children

    Our Services are not directed to individuals below 18 years of age (or the age of majority in your state, if higher). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will take appropriate steps to delete it, subject to law.

    12. Automated decision-making

    We do not use solely automated decision-making that produces legal or similarly significant effects concerning you, except where disclosed for a specific product and permitted by law.

    13. Changes to this Policy

    We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Where changes are material and consent is required under law, we will obtain consent as appropriate.

    14. Governing law and jurisdiction

    This Policy is governed by the laws of India. Subject to applicable law, the courts at Surat, Gujarat, India shall have exclusive jurisdiction over disputes arising from this Policy, without prejudice to any rights you may have before consumer forums or other statutory bodies.