$ evalvo-privacy-audit --target evalvocloud.com
→ Data Fiduciary: Insansa Techknowledge Private Limited
→ Statutory Compliance: DPDP Act 2023 & IT Act 2000
→ Encryption Standard: AES-256 (At Rest) | TLS 1.3 (In Transit)
→ Auth Method: Magic Link (Zero Password Storage)
→ Lab Credential Policy: Auto-expiring Ephemeral AWS Tokens
This Privacy Policy explains how Insansa Techknowledge Private Limited ("Insansa", "we", "us", or "our") collects, uses, stores, and protects your personal data when you access or interact with CloudLabs ("Platform") hosted at evalvocloud.com.
This Policy is explicitly structured to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 (enforced 2026), alongside applicable provisions under the Information Technology Act, 2000.
[CONSENT & ACCEPTANCE MANDATE]
By accessing or using our Platform, you ("Data Principal") give free, specific, informed, and unambiguous consent to the processing of your personal data in accordance with this Policy. If you do not agree with any provision herein, you must immediately discontinue use of the Platform.
Under Section 2(i) of the DPDP Act, 2023, Insansa Techknowledge Private Limited acts as the designated Data Fiduciary determining the purpose and means of personal data processing.
Insansa Techknowledge Private Limited
Registered Corporate Enterprise under the Companies Act, India.
CloudLabs — evalvocloud.com
Primary web application domain & subdomains.
Direct contact line for Data Principal rights requests, privacy inquiries, and statutory grievances.
We adhere strictly to the principle of Data Minimisation. We only process data indispensable for delivering cloud laboratory environments and account security.
Pursuant to Section 4 of the DPDP Act, 2023, personal data is processed solely for lawful, explicit purposes with your consent:
To send secure Magic Link login tokens, issue order receipts, and deliver critical lab expiration notifications.
To dynamically configure and grant temporary AWS infrastructure access during active lab sessions.
To monitor system health, enforce rate limits, and mitigate unauthorized infrastructure exploitation.
[ZERO COMMERCIAL EXPLOITATION GUARANTEE]
We do not sell, rent, monetize, profile, or trade personal data to third-party advertisers or data brokers under any circumstances.
We do not share your personal information with external parties, except with designated payment infrastructure providers necessary to complete transactions:
All financial checkout operations are processed directly by Razorpay. When executing a payment, your financial credentials (cards, net banking, UPI) are collected directly by Razorpay under their security architecture. Insansa receives only an automated transaction confirmation status and a Razorpay Order Reference ID.
Statutory Disclosure Exceptions:
Data is stored in cloud facilities situated in India or approved compliant jurisdictions enforcing stringent data protection baselines. Data transmission is safeguarded via TLS 1.3 encryption, and static assets are protected with AES-256 encryption at rest.
Platform access uses passwordless Magic Links with short expiration windows. AWS sandbox accounts are created with minimal-privilege IAM policies, completely isolating user lab environments.
| Data Category | Retention Window | Purge Directive |
|---|---|---|
| Email Address | Account Active Duration | Permanently deleted 30 days post account deletion |
| Lab Ephemeral Credentials | Session Lifespan Only | Instant purge upon lab session completion |
| Payment References (Razorpay ID) | 7 Legal Years | Mandated under Companies Act 2013 & GST law |
| Security Telemetry & Access Logs | 90 Days Rolling Window | Automated log rotation and destruction |
Under Chapter III of the Digital Personal Data Protection Act, 2023, you possess enforceble rights as a Data Principal:
Request a structured summary of personal data undergoing processing and identity of processing entities.
Request rectification of inaccurate data or complete erasure of your account. Fulfilled within 72 hours of verification.
File formal complaints with our Grievance Officer regarding data handling or statutory non-compliance.
Nominate an individual to exercise your data principal rights in the event of incapacity or death.
CloudLabs is tailored strictly for developer learning and professionals over 18 years of age. We do not knowingly collect personal data from minors under 18 without verifiable parental consent.
In accordance with Section 9 of the DPDP Act, 2023, we do not undertake tracking or targeted advertising directed at children, nor do we process data likely to cause harm to a child.
We employ exclusively strictly necessary session cookies required to maintain active magic link login sessions and security tokens.
[NO ADVERTISING TRACKERS]
We execute zero third-party advertising pixels, cross-site tracking scripts, or data-broker web beacons on evalvocloud.com.
We provide a transparent, statutory grievance resolution workflow under Section 13 of the DPDP Act, 2023:
If your grievance is not addressed within statutory timelines or to your satisfaction, you retain the legal right to submit an appeal to the Data Protection Board of India constituted under the DPDP Act.
We reserve the right to revise this Privacy Policy to reflect statutory amendments or service updates. Material modifications will be communicated via broadcast email notification to registered accounts alongside an updated "Last Updated" timestamp header.
This Privacy Policy is strictly governed by and construed under the laws of the Republic of India. Any legal proceedings or disputes arising from this instrument shall be subject to the exclusive jurisdiction of the competent courts of India.
Our Data Protection Officer is ready to assist you with rights requests.