Privacy Policy.
Entraved Pvt. Ltd. — Master Privacy Policy
Effective Date: 07 August 2026
Last Updated: 07 August 2026
This Master Privacy Policy explains how Entraved Pvt. Ltd. (“Entraved,” “Company,” “we,” “us,” or “our”) collects, uses, stores, shares, secures, and otherwise processes personal data across all products, services, and touchpoints where a privacy policy may be required, including websites, mobile applications, web applications, software platforms, client dashboards, production portals, contact forms, support channels, marketing systems, recruitment workflows, business development processes, events, and any other digital or offline interaction that results in personal data being digitised or processed by Entraved. Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the law applies to digital personal data collected in digital form or collected offline and digitised later, and it may also apply to processing outside India where connected with offering goods or services to individuals in India.
This policy is Entraved’s primary, all-purpose privacy policy. Where a specific app, service, campaign, client portal, country, payment flow, child-facing feature, or contractual environment requires more specific disclosures, Entraved may provide a supplemental notice, in-app notice, consent screen, or contractual privacy addendum that applies in addition to this policy.
1. Who We Are
Entraved Pvt. Ltd. is the entity responsible for deciding why and how personal data is processed in connection with the services it controls, except where another party is expressly identified for a specific activity. Under the DPDP Act, this role is generally referred to as the “Data Fiduciary.”
Entraved Pvt. Ltd.
Registered / Principal office: 82/3, K.N.C. Road, 4th Floor, Diamond Tower, Haritala, Barasat, Kolkata – 700124, West Bengal, India
Website: https://www.entraved.com/
General contact: namaste@entraved.com
Privacy / Grievance contact: namaste@entraved.com
Phone: +91 9143480800
If Entraved processes personal data on behalf of a client, platform, or business partner under a contract, Entraved may act in a processor, contractor, vendor, or service-provider role for that activity, while the client or partner remains the primary controller or decision-maker for that processing context.
2. Scope of This Policy
This policy applies to all Entraved-operated channels and environments where personal data is processed, including:
-
Corporate websites and landing pages.
-
Mobile apps and app-based services.
-
Web apps, SaaS products, dashboards, and user accounts.
-
E-commerce pages, order forms, payment flows, and billing systems.
-
Support systems, ticketing tools, live chat, emails, calls, and feedback forms.
-
Recruitment forms, vendor onboarding forms, and contract workflows.
-
Client portals, project workspaces, review platforms, and production-security systems.
-
Marketing campaigns, newsletters, event registration pages, and CRM tools.
-
Offline or paper-based interactions where the data is later digitized.
This policy does not apply to third-party websites, stores, platforms, payment gateways, app marketplaces, social media networks, or external services that operate under their own privacy notices, even if they are linked from Entraved services or used alongside them.
3. Personal Data We Collect
Depending on the service, workflow, device, or interaction, Entraved may collect the following categories of personal data:
-
Identity data: name, salutation, display name, username, signature, date of birth where necessary, and identification details voluntarily provided.
-
Contact data: email address, phone number, billing address, delivery address, city, state, country, and messaging contact information.
-
Account data: login credentials, profile details, account settings, subscription preferences, authentication records, and account status.
-
Transaction data: purchase records, order details, invoices, payment status, tax details, refunds, fulfilment records, and service history.
-
Payment-related data: limited payment metadata, payment confirmation details, masked card information, billing references, and tokenized transaction data; where secure third-party payment providers are used, full payment credentials are ordinarily handled by those providers rather than stored directly by Entraved.
-
Technical and device data: IP address, browser type, operating system, device model, device identifiers, app version, network information, language settings, crash logs, and diagnostic data.
-
Usage and interaction data: page views, app sessions, feature usage, clicks, navigation paths, ad interactions, session duration, error reports, and event analytics.
-
Location-related data: approximate geolocation inferred from IP, or more precise location data if the relevant app or device permission requests and receives it.
-
Communication data: emails, chat transcripts, support requests, call logs, meeting notes, survey responses, reviews, complaints, and business correspondence.
-
Professional and business data: company name, employer, designation, department, client relationship information, vendor details, and project role.
-
Recruitment and HR-related data: CVs, portfolios, work history, education data, references, interview records, onboarding details, and employment-related submissions where relevant.
-
Production and collaboration data: user access logs, project activity, watermark identifiers, review notes, file access trails, approval histories, and collaboration records relevant to production or client service.
-
Security data: audit logs, access records, CCTV footage where applicable at company premises, device compliance records, and incident reports relevant to security or misuse investigations.
The DPDP Act requires personal data processing to be tied to a lawful purpose and limits consent-based processing to such personal data as is necessary for the specified purpose.
4. How We Collect Personal Data
Entraved may collect personal data:
-
Directly from individuals when they sign up, submit a form, place an order, contact Entraved, request support, apply for a role, register for an event, subscribe to updates, join a project portal, or otherwise interact with Entraved.
-
Automatically through cookies, SDKs, pixels, log files, analytics tools, advertising technologies, or similar technologies embedded in websites, apps, or platforms.
-
From clients, vendors, business partners, service providers, payment processors, public sources, app stores, social platforms, or other lawful sources relevant to the service being delivered.
-
Internally from business operations, production systems, CRM tools, ticketing platforms, security systems, recruitment workflows, or collaboration tools used by Entraved.
Where consent is required, the request for consent will be accompanied or preceded by a notice describing the personal data involved, the purpose of processing, how rights may be exercised, and how a complaint may be made.
5. Why We Process Personal Data
Entraved may process personal data for the following purposes, depending on the context:
-
To provide, deliver, operate, maintain, and improve websites, apps, products, services, portals, and support functions.
-
To create, verify, secure, and manage user, customer, employee, applicant, partner, or vendor accounts.
-
To process purchases, subscriptions, invoices, payments, deliveries, access rights, applications, and contractual requests.
-
To communicate about transactions, support issues, project updates, legal notices, service changes, and security alerts.
-
To personalize experiences, content, product recommendations, or communication preferences where appropriate.
-
To measure site and app performance, understand user behavior, improve UX, troubleshoot technical issues, and evaluate campaigns.
-
To conduct business development, vendor management, customer relationship management, and partnership activities.
-
To operate production systems, client collaboration environments, and project-security workflows.
-
To monitor, investigate, and prevent fraud, abuse, unauthorized access, leaks, malware, phishing, and policy violations.
-
To comply with legal, tax, accounting, employment, contractual, insurance, audit, and regulatory obligations.
-
To establish, exercise, or defend legal rights and claims.
-
To send newsletters, event information, updates, promotional content, or direct marketing where permitted by law and, where required, based on consent.
Under the DPDP Act, personal data may be processed for a lawful purpose either on the basis of consent or certain legitimate uses recognized by the Act.
6. Legal Grounds for Processing
Where applicable, Entraved may rely on one or more of the following grounds:
-
Consent provided by the individual.
-
Voluntary provision of personal data by the individual for a specified purpose, where the individual has not indicated refusal for that use.
-
Performance of a contract or steps requested before entering into a contract.
-
Compliance with a legal or regulatory obligation.
-
Employment-related processing and protection of confidentiality, intellectual property, systems, or business operations where permitted by law.
-
Legal claims, dispute handling, due diligence, investigations, security response, or other lawful grounds recognised by applicable law.
The DPDP Act requires that consent be free, specific, informed, unconditional, and unambiguous, given through clear affirmative action, and that the individual be able to withdraw consent with comparable ease.
7. Cookies, SDKs, Pixels, and Similar Technologies
Entraved may use cookies, mobile SDKs, tags, web beacons, local storage, session technologies, and related tools in websites and apps to support login sessions, security, navigation, user preferences, analytics, diagnostics, campaign measurement, and advertising or remarketing where used. These may include:
-
Strictly necessary technologies for login, account security, core functionality, fraud prevention, and shopping-cart or session continuity.
-
Preference technologies for language, display, region, and saved settings.
-
Analytics technologies for usage measurement, crash reporting, diagnostics, and performance insights.
-
Advertising technologies for campaign effectiveness, frequency management, remarketing, conversion tracking, or personalization where applicable.
Before non-essential cookies or similar technologies are activated, Entraved will display a cookie banner or consent prompt offering a clear choice to accept, reject, or manage preferences, describing the categories and purposes involved. Non-essential analytics and advertising cookies or SDKs will not load until consent is given, where required by law.
Individuals can manage cookies at any time through browser settings, the cookie preference/settings link, device or in-app controls, or a consent management tool where available, and may request deletion of data associated with certain first-party cookies through the applicable deletion process where available. Disabling certain technologies may affect functionality, saved preferences, analytics accuracy, personalized features, or account access.
8. Mobile Apps and Device Permissions
Where Entraved offers mobile applications or app-based services, those apps may request access to device features only where reasonably necessary for the relevant feature — for example, camera, microphone, storage, files, media, contacts, photos, location, notifications, Bluetooth, clipboard, or biometric or device authentication permissions. Permission prompts will explain the purpose in context, and Entraved will avoid requesting access that is not necessary for the feature being used.
Individuals may accept, deny, or later withdraw many permissions through device settings or in-app controls. If a permission is denied or withdrawn, some features may not function properly or may become unavailable.
App marketplaces, operating systems, SDK providers, analytics providers, crash reporting tools, and push notification services may independently process app-related information under their own terms and privacy notices when an app is downloaded, installed, or used.
9. Google, Analytics, and Advertising Services
Where Entraved uses services such as Google Analytics, Google Ads, AdSense, remarketing tools, campaign pixels, tag managers, or similar advertising and analytics tools, those services may process device, browser, usage, and advertising-related information through cookies or similar technologies. Where such tools are used in contexts where consent is required before non-essential tracking begins, Entraved will use consent banners, preference tools, or in-app consent requests before activating those technologies. Individuals may separately manage ads personalisation through the relevant provider’s own settings (for example, Google Ads Settings).
10. How We Share Personal Data
Entraved may share personal data where reasonably necessary for the purposes described in this policy, including with:
-
Cloud hosting, infrastructure, storage, CDN, and backup providers.
-
Payment processors, banks, invoicing providers, bookkeeping tools, and tax service providers.
-
Email, SMS, communication, ticketing, CRM, support, and workflow platforms.
-
Analytics, security, anti-fraud, monitoring, logging, and performance providers.
-
App infrastructure, notification, crash reporting, and SDK providers.
-
Advertising, media-buying, campaign, and remarketing partners where used.
-
Clients, production partners, contractors, vendors, consultants, and service providers where required to perform contracts or services.
-
Professional advisers such as lawyers, auditors, insurers, compliance consultants, and investigators.
-
Government bodies, regulators, law enforcement, courts, or authorised parties where required by law or reasonably necessary to protect rights, safety, property, systems, or legal interests.
-
Acquirers, investors, successors, or advisers in connection with a merger, acquisition, financing, restructuring, insolvency process, or transfer of assets.
Under the DPDP Act, a Data Fiduciary remains responsible for compliance in relation to processing undertaken by it or on its behalf by a Data Processor, and a Data Processor may be engaged only under a valid contract.
11. International Transfers
Entraved may process or store personal data in India and in other countries where its service providers, business partners, clients, vendors, or technical infrastructure are located. The DPDP Act permits transfers outside India, subject to any restrictions notified by the Central Government from time to time and any other applicable laws imposing higher standards or additional limitations.
Where personal data is transferred across borders, Entraved will use contractual protections, access restrictions, security controls, provider assessments, and internal safeguards appropriate to the nature of the processing.
12. Retention of Personal Data
Entraved retains personal data only for as long as necessary for the purpose for which it was collected or processed, including service delivery, account administration, contractual obligations, production workflows, payment and tax records, legal claims, dispute management, security investigations, regulatory compliance, and archival or backup needs where justified.
The DPDP Act requires personal data to be erased when consent is withdrawn or when it is reasonable to assume the specified purpose is no longer being served, unless retention is necessary for compliance with applicable law.
Retention periods may vary by category and context, including website forms, app accounts, client portals, applicant records, vendor records, payroll data, security logs, CCTV footage, production records, or contractual archives. When personal data is no longer required, Entraved will delete, anonymise, aggregate, archive under restricted conditions, or securely isolate the information.
13. Security Measures
Entraved applies reasonable technical, physical, administrative, and organisational safeguards designed to protect personal data from unauthorised access, use, disclosure, alteration, destruction, or loss. Depending on the service and environment, these measures may include role-based access controls, password standards, multi-factor authentication, device restrictions, endpoint protection, network segregation, secure transfer tools, logging, backups, malware controls, patch management, watermarking, confidentiality obligations, onboarding and offboarding controls, physical access restrictions, and incident-response procedures, consistent with Entraved’s internal security policy.
The DPDP Act requires Data Fiduciaries to implement reasonable security safeguards. The specific safeguard and breach-notification rules under the DPDP Rules, 2025 are being phased in over 2025–2027; Entraved’s practices are designed to meet both current legal requirements (including under the Information Technology Act, 2000 and applicable CERT-In directions) and the fuller DPDP Rules obligations as they come into force.
No system, network, app, website, device, or communication channel is completely secure. Individuals are responsible for keeping account credentials confidential and for notifying Entraved promptly if suspicious activity or unauthorised access is detected.
14. Personal Data Breaches
Under the DPDP Act, a personal data breach includes unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access that compromises confidentiality, integrity, or availability.
If Entraved becomes aware of a personal data breach, Entraved will assess the incident, contain the impact, investigate the cause, remediate vulnerabilities, work with affected clients or vendors, preserve evidence where appropriate, and notify affected individuals and authorities where required by applicable law — including any timelines prescribed under the Information Technology Act, 2000, CERT-In directions, and, as its provisions come into force, the DPDP Act and Rules. Entraved’s internal security policy also requires rapid internal reporting and containment of security incidents.
15. Children’s Privacy
Entraved does not knowingly process children’s personal data in violation of applicable law. Under the DPDP Act, a child is an individual who has not completed eighteen years of age, and a Data Fiduciary must obtain verifiable consent from the parent or lawful guardian before processing a child’s personal data, subject to any notified exceptions. The DPDP Act also prohibits tracking, behavioural monitoring of children, and targeted advertising directed at children, subject to any prescribed exceptions.
Where a shoot, production, or engagement involves a child model or child artist, Entraved separately obtains parental/guardian consent and warranties through its production release documentation (including verification of the parent or guardian’s legal capacity to consent on the child’s behalf), in addition to — not instead of — the protections in this section.
If Entraved offers any service, feature, app, or educational content that may involve children’s personal data, Entraved may provide a supplemental notice and implement additional consent, safety, age-screening, or restricted-processing controls.
16. Your Rights
Subject to applicable law, individuals may have the right to:
-
Obtain a summary of personal data being processed and related processing information.
-
Request correction, completion, updating, or erasure of personal data.
-
Withdraw consent where consent is the basis of processing.
-
Seek grievance redressal regarding Entraved’s handling of personal data.
-
Nominate another individual to exercise rights in the event of death or incapacity, where permitted by law.
Entraved may request information reasonably necessary to verify identity, confirm authority, protect against fraud, and understand the scope of the request before taking action.
17. Withdrawal of Consent
Where Entraved relies on consent as the basis of processing, consent may be withdrawn at any time with ease comparable to the means by which it was originally given. Withdrawal does not affect processing that was lawfully carried out before withdrawal.
If consent is withdrawn, Entraved may stop providing the relevant feature, service, subscription, account function, app capability, or communication that depended on that consent, while continuing processing where otherwise authorised or required by law, contract, dispute handling, or legitimate operational necessity under applicable law.
18. Grievance Redressal and Complaints
The DPDP Act requires a Data Fiduciary to publish business contact information for a person able to answer questions regarding personal data processing, and to establish an effective grievance-redressal mechanism.
Entraved designates a Grievance Officer / Privacy Officer responsible for receiving and coordinating responses to privacy and personal data requests, including complaints, corrections, erasure requests, and consent-withdrawal requests. If Entraved is notified as a Significant Data Fiduciary in the future, it will appoint and publish the details of a Data Protection Officer in accordance with the Act. If a grievance remains unresolved after Entraved’s internal process, the individual may escalate the matter to the Data Protection Board of India in accordance with applicable law.
Privacy, grievance, correction, erasure, access, or consent-withdrawal requests may be sent to:
Privacy / Grievance Email: namaste@entraved.com
Postal Address: 82/3, K.N.C. Road, 4th Floor, Diamond Tower, Haritala, Barasat, Kolkata – 700124, West Bengal, India
Contact Person / Grievance Officer: Sagar Nil Santra, Director
Please include sufficient details to identify your relationship with Entraved, the relevant product or app, the nature of the request, and any supporting information needed for verification and response.
Entraved aims, as a matter of internal practice, to acknowledge grievances promptly and resolve them within 30 days; applicable law may separately prescribe its own timelines, which will be followed where they differ from this internal target.
19. Marketing Communications
Entraved may send promotional emails, newsletters, event notices, product updates, service announcements, surveys, or marketing communications where permitted by law and, where required, based on consent or another lawful ground.
Individuals may unsubscribe from promotional communications using the unsubscribe link, account preferences, app settings, or direct contact with Entraved. Transactional, security, contractual, support, and service messages may still be sent even when promotional communications are declined.
20. Third-Party Links, Stores, and Services
Entraved services may contain links to third-party websites, payment gateways, app stores, social media pages, embedded content, plugins, login providers, or other independent services. Those third parties may process personal data under their own policies and terms, and Entraved is not responsible for their independent practices. Before using a third-party service, individuals should review the privacy notice, cookie policy, and terms of that provider — especially where payments, app distribution, social sign-in, or external messaging tools are involved.
21. Business Transfers and Reorganisation
If Entraved undergoes or evaluates a merger, acquisition, investment, financing, restructuring, demerger, insolvency process, or transfer of part or all of its business or assets, personal data may be reviewed, disclosed, or transferred as part of due diligence or transaction implementation, subject to confidentiality, security, and legal requirements, including any special provisions of the DPDP Act relevant to such scenarios.
22. Region-Specific or Service-Specific Notices
Because this is a master privacy policy, some Entraved products or channels may also present supplemental notices for app permissions, cookies, advertising consent, recruitment, vendor onboarding, client project portals, payment pages, children’s features, or country-specific compliance requirements. Those notices are intended to work alongside this policy and may override it for the specific point of collection or service, where required by law or contract.
23. Changes to This Policy
Entraved may update this Master Privacy Policy from time to time to reflect changes in law, products, services, systems, vendors, business operations, or security practices. The updated version will be posted in the relevant website, app, account area, or other appropriate location and will become effective on the date stated at the top, unless another notice method is required by law. Where appropriate, Entraved may also provide notice through email, app notification, banner, dashboard message, or consent-refresh screen.
If at any time you would like to unsubscribe from receiving future emails, you can email us at
namaste@entraved.com
and we will promptly remove you from ALL correspondence.
Contacting Us
If there are any questions regarding this privacy policy, you may contact us using the information below.
ENTRAVED PVT. LTD.
Barasat, Kolkata,
West Bengal 700124
India
