Sarvasv Technologies Private Limited ("Sarvasv", "Appify", "we", "us", or "our") is committed to protecting the privacy, confidentiality, and sovereign integrity of personal and technical data belonging to visitors of appify.in (the "Website"), early access pilot participants, and enterprise clients utilizing our platforms and services.
This Privacy Policy explains how we collect, handle, process, and protect data in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and internationally recognized zero-trust security standards.
1. Scope and Operating Brands
This policy covers electronic and online interactions conducted through appify.in. Appify is an operating brand and proprietary technology platform of Sarvasv Technologies Private Limited, alongside sister brand zerotosaas.in and corporate site sarvasv.in.
2. The Sovereign Air-Gapped Zero Telemetry Guarantee
3. Information We Collect on the Public Website
3.1 Information You Provide Voluntarily
- Contact & Pilot Request Details: Your name, official agency or organizational email address, role, phone number, and organization name when submitting the early access pilot waitlist form or briefing requests.
- Architecture Inquiries: Technical specifications, compliance frameworks (FedRAMP, FIPS, HIPAA, SOC 2), and deployment parameters shared during initial architecture consultations.
- Billing & Statutory Data: GSTIN, PAN, organizational billing address, and authorized signatory details for enterprise engagements and pilot licensing agreements.
3.2 Privacy-Preserving Cookieless Web Analytics
On our public informational website, we prioritize user privacy by deploying cookieless, non-invasive analytics. We do not use third-party advertising tracking cookies, nor do we track individuals across third-party websites or construct behavioral advertising profiles. Data collected is aggregated and anonymized for measuring page performance and site reliability.
4. Purposes and Lawful Bases of Processing
Under the DPDP Act, 2023, we process personal data under the lawful bases of consent and legitimate business execution:
- Evaluating Pilot Eligibility: Reviewing and approving requests for early access pilot sandbox participation.
- Service Delivery: Facilitating architecture briefings, providing technical documentation, and delivering enterprise software synthesis licenses.
- Statutory Invoicing: Generating tax-compliant invoices and maintaining statutory records in accordance with Indian tax authorities.
- Security & Abuse Prevention: Protecting our infrastructure against unauthorized intrusion, denial-of-service vectors, or automated malicious scanning.
5. Data Sovereignty and Third-Party Sharing
We do not sell, rent, monetize, or trade personal data or organizational project information. Data is never shared with third parties except under the following strict boundaries:
- Infrastructure Providers: Encrypted hosting providers operating under strict enterprise data protection agreements.
- Statutory & Legal Mandates: Where disclosure is strictly required by competent Indian law enforcement, court order, or regulatory decree.
6. Data Security and Cryptographic Protections
We apply multi-layered technical controls including AES-256-GCM encryption for stored data, TLS 1.3 transport security, role-based access control (RBAC), and automated pre-flight security testing to protect personal data from unauthorized access or compromise.
7. Data Subject Rights Under DPDP Act, 2023
As a data principal, you hold the following statutory rights under the DPDP Act, 2023:
- Right to Access: Request a summary of personal data held about you and processing activities undertaken.
- Right to Correction & Erasure: Request correction of inaccurate information or deletion of personal data when no longer required for legitimate business or statutory purposes.
- Right of Grievance Redressal: Register a grievance regarding personal data handling with our designated officer.
- Right to Nominate: Nominate an individual to exercise your rights in the event of incapacity.
8. Grievance Redressal and Data Protection Officer
In compliance with the Digital Personal Data Protection Act, 2023, data protection inquiries, requests to exercise statutory data rights, or grievances may be directed to our Grievance Officer at [email protected] or [email protected]. Full postal details for our registered office are available in the footer below.