Privacy Policy
Effective 26 July 2026
1. Scope and Application
Andravio Labs Private Limited, trading under the business name TharCloud ("Company", "we", "us", or "our"), is the Data Fiduciary in respect of personal data processed through this website ("the Site"). References to "you" or "Data Principal" pertain to any individual whose personal data we process.
This Privacy Policy explains the nature of personal data we collect, the lawful basis and purposes of processing, retention periods, third-party disclosures, and the statutory rights available to you. This Policy is issued in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the applicable rules framed thereunder.
2. Data We Collect Through This Website
The Site is designed to operate with minimal data collection. It does not require user account registration, run analytical tracking scripts, or embed third-party marketing trackers. Navigating the Site does not construct a personal profile, nor does it store non-essential persistent cookies in your browser. Our dedicated Cookie Policy details technical browser storage parameters and operational standards.
- Server Logs: Our hosting infrastructure automatically logs standard technical data, including requesting IP addresses, browser user-agent strings, requested URL paths, and HTTP timestamps. This data is collected strictly to maintain security, prevent unauthorised access, and ensure service availability. It is not processed to re-identify individual visitors.
- Direct Correspondence: When you communicate with us via email or official channels, we retain that correspondence along with any enclosed personal data (such as your name, email address, and business details) solely to evaluate, respond to, and document your inquiry. Submitting an inquiry does not place you on a marketing distribution list.
3. Inquiries Made Through Our Brand Site
This Site does not maintain embedded public inquiry forms. Where you are redirected to submit communications through tharcloud.com, that domain is owned and operated by the Company under its trading name. Any personal data submitted there is received by us and processed exclusively for evaluating your business requirements, responding to inquiries, and negotiating formal service contracts. Processing on that platform remains subject to the privacy disclosures published thereon.
4. Purposes and Lawful Basis of Processing
We process personal data only for specific, necessary, and lawful purposes, including:
- Responding to direct inquiries, business communications, and contractual negotiations;
- Executing, administering, and performing formal service engagements, including invoicing and client onboarding;
- Monitoring, maintaining, and securing the operation and integrity of the Site; and
- Complying with legal, statutory, and regulatory obligations imposed under applicable Indian law.
We do not sell, rent, trade, or process personal data for targeted advertising, automated profiling, or automated decision-making.
5. Disclosure and Cross-Border Transfers
We do not disclose personal data to third parties except in the following limited circumstances:
- Service Providers: We share necessary data with cloud hosting, security, and communication service providers who act as Data Processors under strict contractual instructions. They are permitted to process data solely to maintain website operations and email infrastructure on our behalf.
- Legal Obligations: We may disclose personal data where required by applicable law, court order, regulatory direction, or law enforcement authority.
Where service providers process or store data outside the territory of India, such cross-border transfers are executed in strict accordance with the standards and restrictions mandated under the DPDP Act and relevant governmental notifications.
6. Data Retention
Personal data is retained only for the duration necessary to fulfil the specific purpose for which it was collected. Upon fulfilment of that purpose, the data is permanently deleted or anonymised, except where retention is required to satisfy statutory compliance obligations (including corporate, tax, and accounting mandates) or to establish, exercise, or defend legal claims.
7. Technical and Organisational Safeguards
We maintain appropriate technical, physical, and organisational security measures to protect personal data against unauthorised access, disclosure, alteration, or loss. These measures include administrative access controls, regular infrastructure security evaluations, and data encryption in transit. However, no electronic transmission over the internet or storage system can be guaranteed to be entirely immune to risk.
8. Statutory Rights of Data Principals
In accordance with applicable provisions of the DPDP Act, 2023, you retain the following rights regarding your personal data:
- Right to Access: Request a summary of personal data undergoing processing and details regarding third-party processing disclosures.
- Right to Correction and Erasure: Request the correction of inaccurate or misleading data, the completion of incomplete records, or the erasure of personal data that is no longer necessary for its initial purpose.
- Right of Grievance Redressal: Seek redressal for any concerns or complaints through our designated Grievance Redressal mechanism prior to initiating legal proceedings.
- Right to Nominate: Nominate another individual to exercise your statutory rights on your behalf in the event of death or incapacity.
9. Processing of Children's Data
The Site is directed exclusively at enterprise businesses and commercial entities. We do not intentionally target, collect, or process personal data relating to children or individuals under eighteen (18) years of age, nor do we perform behavioural tracking or targeted advertising. If we discover that personal data of a child has been submitted to us unintentionally, we will immediately delete such data from our systems.
10. Personal Data Breach Notification
In the event of a confirmed personal data breach affecting systems maintained by the Company, we will intimate the Data Protection Board of India and each affected Data Principal within the timelines and in the manner prescribed under applicable law. Such notice will outline the nature of the breach, its anticipated impact, and the corrective actions undertaken.
11. Grievance Redressal Mechanism
In compliance with Rule 4(5) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, any questions, regulatory requests, or grievances concerning this Policy or your personal data should be directed to our designated officer:
- Attn
- Data Protection & Grievance Officer
- Department
- Legal & Compliance Department
- Acknowledgement SLA
- Within forty-eight (48) hours of receipt
- Resolution SLA
- Within one (1) month from the date of receipt
12. Amendments to This Policy
The Company reserves the right to modify or update this Privacy Policy at any time to reflect operational, legal, or regulatory changes. The prevailing version will always be published on this page with the updated effective date indicated at the top. Continued use of the Site following an update constitutes acknowledgement of the revised Policy.