LEGAL SPECIFICATIONDPDP ACT 2023 / RULES 2025 COMPLIANT

PRIVACY POLICY

CloudLabs — evalvocloud.comInsansa Techknowledge Private Limited
Effective: June 15, 2025Last Updated: June 15, 2026
SYSTEM AUDIT CONSOLE // EVALVOCLOUD PRIVACY MANIFEST

$ evalvo-privacy-audit --target evalvocloud.com

→ Data Fiduciary: Insansa Techknowledge Private Limited

→ Statutory Compliance: DPDP Act 2023 & IT Act 2000

→ Encryption Standard: AES-256 (At Rest) | TLS 1.3 (In Transit)

→ Auth Method: Magic Link (Zero Password Storage)

→ Lab Credential Policy: Auto-expiring Ephemeral AWS Tokens

>
SECTION 01

1. Introduction & Scope

This Privacy Policy explains how Insansa Techknowledge Private Limited ("Insansa", "we", "us", or "our") collects, uses, stores, and protects your personal data when you access or interact with CloudLabs ("Platform") hosted at evalvocloud.com.

This Policy is explicitly structured to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 (enforced 2026), alongside applicable provisions under the Information Technology Act, 2000.

[CONSENT & ACCEPTANCE MANDATE]

By accessing or using our Platform, you ("Data Principal") give free, specific, informed, and unambiguous consent to the processing of your personal data in accordance with this Policy. If you do not agree with any provision herein, you must immediately discontinue use of the Platform.

SECTION 02

2. Data Fiduciary Specification

Under Section 2(i) of the DPDP Act, 2023, Insansa Techknowledge Private Limited acts as the designated Data Fiduciary determining the purpose and means of personal data processing.

Legal Corporate Entity

Insansa Techknowledge Private Limited

Registered Corporate Enterprise under the Companies Act, India.

Digital Platform & Domain

CloudLabs — evalvocloud.com

Primary web application domain & subdomains.

Grievance Officer Direct Email
[email protected]

Direct contact line for Data Principal rights requests, privacy inquiries, and statutory grievances.

SECTION 03

3. Personal Data Collected

We adhere strictly to the principle of Data Minimisation. We only process data indispensable for delivering cloud laboratory environments and account security.

3.1 Data You Directly Provide
  • Email Address: Collected upon registration or login via our passwordless Magic Link authentication system. This acts as your sole account identifier.
3.2 Automated System Telemetry
  • Ephemeral Session Credentials: Scoped, time-bound AWS IAM security tokens generated to launch cloud sandbox environments. Automatically purged post-session.
  • Usage & Event Logs: Timestamps of authentication, lab activation, and lab termination for system integrity and abuse detection.
  • IP Address: Logged transiently to prevent brute-force attacks and rate-limit API calls.
3.3 Data We Explicitly DO NOT Collect
No phone numbers, physical addresses, or government IDs.
No credit card numbers, UPI IDs, or banking credentials (processed exclusively by Razorpay).
Zero passwords stored (100% Magic Link Passwordless Architecture).
No biometric data, health records, or sensitive personal data under Indian law.
SECTION 04

4. Purpose & Legal Basis for Processing

Pursuant to Section 4 of the DPDP Act, 2023, personal data is processed solely for lawful, explicit purposes with your consent:

[EMAIL AUTHENTICATION]

To send secure Magic Link login tokens, issue order receipts, and deliver critical lab expiration notifications.

CONSENT BASED
[LAB ENVIRONMENT PROVISIONING]

To dynamically configure and grant temporary AWS infrastructure access during active lab sessions.

CONTRACTUAL NECESSITY
[SYSTEM SECURITY & AUDITING]

To monitor system health, enforce rate limits, and mitigate unauthorized infrastructure exploitation.

LEGITIMATE USES

[ZERO COMMERCIAL EXPLOITATION GUARANTEE]

We do not sell, rent, monetize, profile, or trade personal data to third-party advertisers or data brokers under any circumstances.

SECTION 05

5. Data Sharing & Third-Party Processors

We do not share your personal information with external parties, except with designated payment infrastructure providers necessary to complete transactions:

AUTHORIZED PAYMENT PROCESSORIN-PAY-01

Razorpay Payment Solutions Pvt. Ltd.

All financial checkout operations are processed directly by Razorpay. When executing a payment, your financial credentials (cards, net banking, UPI) are collected directly by Razorpay under their security architecture. Insansa receives only an automated transaction confirmation status and a Razorpay Order Reference ID.

Statutory Disclosure Exceptions:

  • When mandated by a binding court order, lawful warrant, or statutory directive from Indian law enforcement authorities under the DPDP Act or IT Act, 2000.
  • When required to enforce platform terms, investigate system sabotage, or protect legal rights of Insansa and its users.
SECTION 06

6. Storage, Security & Retention Schedule

6.1 Security Standard

Data is stored in cloud facilities situated in India or approved compliant jurisdictions enforcing stringent data protection baselines. Data transmission is safeguarded via TLS 1.3 encryption, and static assets are protected with AES-256 encryption at rest.

6.2 Access Controls

Platform access uses passwordless Magic Links with short expiration windows. AWS sandbox accounts are created with minimal-privilege IAM policies, completely isolating user lab environments.

6.3 Data Retention Schedule

Data CategoryRetention WindowPurge Directive
Email AddressAccount Active DurationPermanently deleted 30 days post account deletion
Lab Ephemeral CredentialsSession Lifespan OnlyInstant purge upon lab session completion
Payment References (Razorpay ID)7 Legal YearsMandated under Companies Act 2013 & GST law
Security Telemetry & Access Logs90 Days Rolling WindowAutomated log rotation and destruction
SECTION 07

7. Your Rights as a Data Principal

Under Chapter III of the Digital Personal Data Protection Act, 2023, you possess enforceble rights as a Data Principal:

SECTION 11 DPDP ACT

Right to Access Summary

Request a structured summary of personal data undergoing processing and identity of processing entities.

SECTION 12 DPDP ACT

Right to Correction & Erasure

Request rectification of inaccurate data or complete erasure of your account. Fulfilled within 72 hours of verification.

SECTION 13 DPDP ACT

Right to Grievance Redressal

File formal complaints with our Grievance Officer regarding data handling or statutory non-compliance.

SECTION 14 DPDP ACT

Right to Nominate

Nominate an individual to exercise your data principal rights in the event of incapacity or death.

To exercise any Data Principal right, submit an official request to:
SECTION 08

8. Minors & Children's Data

CloudLabs is tailored strictly for developer learning and professionals over 18 years of age. We do not knowingly collect personal data from minors under 18 without verifiable parental consent.

In accordance with Section 9 of the DPDP Act, 2023, we do not undertake tracking or targeted advertising directed at children, nor do we process data likely to cause harm to a child.

SECTION 09

9. Cookies & Browser Telemetry Policy

We employ exclusively strictly necessary session cookies required to maintain active magic link login sessions and security tokens.

[NO ADVERTISING TRACKERS]

We execute zero third-party advertising pixels, cross-site tracking scripts, or data-broker web beacons on evalvocloud.com.

SECTION 10

10. Grievance Redressal Mechanism

We provide a transparent, statutory grievance resolution workflow under Section 13 of the DPDP Act, 2023:

OFFICER CONTACT[email protected]
ACK TIMELINE

Within 48 Hours

RESOLVE TIMELINE

Maximum 30 Days

If your grievance is not addressed within statutory timelines or to your satisfaction, you retain the legal right to submit an appeal to the Data Protection Board of India constituted under the DPDP Act.

SECTION 11

11. Policy Modifications

We reserve the right to revise this Privacy Policy to reflect statutory amendments or service updates. Material modifications will be communicated via broadcast email notification to registered accounts alongside an updated "Last Updated" timestamp header.

SECTION 12

12. Governing Law

This Privacy Policy is strictly governed by and construed under the laws of the Republic of India. Any legal proceedings or disputes arising from this instrument shall be subject to the exclusive jurisdiction of the competent courts of India.

HAVE DATA PRIVACY QUESTIONS?

Our Data Protection Officer is ready to assist you with rights requests.