GLOBAL PRIVACY POLICY
Effective Date: August 22, 2026
NavRitu Digital (“NavRitu Digital,” “we,” “us,” or “our”) provides web and mobile development, cyber security, design, marketing, AI, production, research, cloud infrastructure, and influencer-marketing services to clients around the world. This Global Privacy Policy (“Policy”) explains how we collect, use, disclose, and protect personal information when you visit our website, submit an inquiry, engage us for services, or otherwise interact with us.
This Policy applies globally. We serve clients in the European Union/EEA, the United Kingdom, the United States, Canada, and other jurisdictions. Where local law provides additional or different rights, those rights are described in Section 9.
1. Scope of This Policy
This Policy applies to personal information collected through:
- Our website and any subdomains (including navritu.digital)
- Inquiry, contact, and project-brief forms
- Client onboarding, contracts, and invoicing for our services
- Communications by email, phone, WhatsApp Business, or social media
- Cookies and similar tracking technologies used on our site
It does not apply to third-party websites, platforms, or advertising networks we may link to or use on behalf of clients (e.g., a client's own Meta Ads or Google Ads account), which are governed by those parties' own privacy policies.
2. Information We Collect
Because we operate internationally and provide services spanning development, cyber security, marketing, and AI, we collect the categories of information below to understand client needs, deliver services, run analytics on client behaviour and engagement patterns, and protect our systems and clients from fraud and abuse.
|
Category |
Data Points Collected |
|
Identity & Contact Data |
Name, Job Title, Company, Email Address, Phone Number, Website |
|
Business & Project Data |
Industry, Project Name, Services Requested, Budget, Timeline, Project Brief, Preferred Contact Method, Currency |
|
Technical & Device Data |
IP Address, Region, City, Internet Service Provider (ISP), User Agent, Device Type, Referrer URL, Viewport Size, Screen Resolution, Network Speed, Battery Status |
|
Timestamp Data |
Date and time of form submission or website interaction |
|
Payment Data |
Billing details processed via Razorpay and Stripe (we do not store full card numbers) |
Why we collect technical and device data: Fields such as IP address, ISP, device type, user agent, referrer URL, network speed, battery status, viewport size, and screen resolution are collected primarily for two purposes: (a) understanding how prospective and existing clients discover, use, and engage with our website and services, so we can improve them and provide more relevant recommendations, and (b) cyber security and fraud-prevention purposes — including detecting bots, spam submissions, account takeover attempts, and other abusive traffic, consistent with the security services we offer our own clients.
3. How We Use Your Information
We use personal information to:
- Respond to inquiries and prepare proposals, quotes, and project briefs
- Deliver, maintain, and support development, design, marketing, AI, cloud, production, and influencer-marketing services
- Process payments and invoices through Razorpay and Stripe
- Analyze client behaviour, traffic patterns, and engagement to improve our website, offerings, and marketing performance
- Detect, investigate, and prevent fraud, security incidents, and unauthorized access
- Comply with legal, tax, accounting, and regulatory obligations
- Communicate updates, service changes, or marketing communications (where you have consented or as permitted by law)
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on one or more of the following legal bases:
- Contract — processing necessary to negotiate or perform a services contract with you
- Legitimate interests — e.g., securing our systems, improving our services, and direct marketing to existing clients
- Consent — e.g., non-essential cookies, or marketing communications where required
- Legal obligation — e.g., tax, accounting, and billing records
5. Cookies & Tracking Technologies
Our website uses cookies, pixels, and similar technologies to operate the site, remember preferences, and understand how visitors use it. This includes analytics tools and advertising/retargeting pixels consistent with the ads and analytics services we provide (such as pixel-based retargeting, conversion tracking, and performance analytics).
- Essential cookies — required for the website to function
- Analytics cookies — to understand traffic, behaviour, and patterns
- Advertising/retargeting cookies — to measure and improve ad performance
Where required by law (e.g., GDPR/UK GDPR), we will request your consent before setting non-essential cookies, and you can withdraw consent at any time through your browser settings or any cookie banner presented on our site.
6. Payment Processing
We use Razorpay and Stripe to process payments and invoices. These providers are PCI-DSS compliant, and we do not directly collect or store full payment card numbers, CVV codes, or bank account credentials — that information is handled directly by the payment processor under its own privacy and security policies. We retain records of transactions (amounts, dates, invoice references) for accounting, tax, and legal purposes.
7. How We Share Information
We do not sell personal information. We may share it with:
- Payment processors — Razorpay and Stripe, to process transactions
- Cloud, hosting, and infrastructure providers — to operate our website and deliver services
- Analytics and advertising platforms — such as those used for performance marketing, SEO, and pixel-based retargeting
- Subcontractors and staff — engaged to deliver development, design, AI, or production services under confidentiality obligations
- Professional advisors — lawyers, accountants, and auditors, where necessary
- Authorities — where required by law, regulation, or valid legal process
8. International Data Transfers
As we serve clients across India and internationally, personal information may be transferred to, stored, and processed in countries other than your own, including countries that may have different data protection laws. Where we transfer personal information out of the EU/EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or an applicable adequacy decision, to the extent required by law.
9. Your Privacy Rights
Depending on where you are located, you may have the following rights over your personal information:
|
Framework |
Who It Covers |
Key Rights |
|
GDPR (EU/UK/EEA) |
Individuals in the European Union, UK, and European Economic Area |
Access, rectification, erasure, restriction, portability, objection, withdraw consent, lodge a complaint with a supervisory authority |
|
CCPA/CPRA (California, USA) |
California residents |
Right to know, delete, correct, opt out of sale/sharing of personal information, limit use of sensitive personal information, non-discrimination |
|
DPDP Act, 2023 (India) |
Individuals (Data Principals) in India |
Access, correction, erasure, grievance redressal, right to nominate a representative, right to withdraw consent |
|
PIPEDA (Canada) |
Individuals in Canada |
Access personal information, challenge accuracy, withdraw consent, file a complaint with the Privacy Commissioner of Canada |
To exercise any of these rights, contact our Privacy Officer at legal@navritu.digital. We will verify your request and respond within the timeframe required by applicable law.
10. Data Retention
We retain personal information for as long as necessary to fulfil the purposes described in this Policy, including the duration of our business or client relationship, plus any additional period required to comply with legal, tax, accounting, or regulatory record-keeping obligations, or to resolve disputes and enforce our agreements. Analytics and advertising data collected through third-party tools is retained according to those tools' own configured retention settings.
11. Data Security
Consistent with the cyber security services we provide our clients, we apply administrative, technical, and physical safeguards to protect personal information, including encryption in transit and at rest, access controls, monitoring, and staff confidentiality obligations. No system is completely secure, and we cannot guarantee absolute security of information transmitted to us.
12. Children's Privacy
Our services are directed to businesses and professionals, not to children. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have inadvertently collected such information, we will take steps to delete it.
13. Third-Party Links
Our website and communications may contain links to third-party websites or platforms (including client sites, social media, and advertising platforms). We are not responsible for the privacy practices of those third parties, and we encourage you to review their policies separately.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, services, or legal requirements. The “Effective Date” at the top of this Policy indicates when it was last revised. Material changes will be communicated through our website or by direct notice where appropriate.
15. Governing Law & Jurisdiction
This Policy is governed by the laws of India. Subject to any mandatory rights available to you under local law (including GDPR, CCPA, DPDP, or PIPEDA as applicable), any disputes arising from this Policy shall be subject to the exclusive jurisdiction of the courts at Patna, Bihar, India.
16. Contact Us
For any questions, requests, or complaints about this Policy or how we handle your personal information, please contact our named Privacy Contact / Data Protection Officer:
NavRitu Digital — Privacy Officer
Email: legal@navritu.digital
Operating regions: Bihar, Jharkhand, Delhi, Haryana, Uttar Pradesh, Karnataka, and internationally
Website: https://navritu.digital