Privacy Policy

Privacy Policy

for Andro Buddy Technologies Pvt. Ltd.

Andro Buddy Technologies Private Limited

Effective Date: 13 September 2026
Last Updated: 13 September 2026

Andro Buddy Technologies Private Limited, referred to in this Privacy Policy as Andro Buddy Technologies, Andro Buddy Technologies Private Limited, ABTPLABT, we, us, or our, respects your privacy and is committed to protecting personal data entrusted to us.

This Privacy Policy explains how we collect, receive, access, use, store, process, disclose, transfer, retain, secure and delete personal data when you interact with our websites, applications, products, platforms, software, APIs, integrations, customer support, recruitment activities or professional services.

This Policy is intended to operate in accordance with applicable Indian privacy, data protection, information technology and cybersecurity laws, including, to the extent applicable and in force from time to time, the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000, applicable rules issued under it, and applicable directions issued by the Indian Computer Emergency Response Team, CERT-In.

Where a provision of this Policy provides a protection that exceeds the minimum requirement presently applicable to us, we may continue to follow that protection as part of our privacy practices.

1. About Andro Buddy Technologies

Legal Entity: Andro Buddy Technologies Private Limited

CIN: U47910MH2024PTC423697

Website: https://androtechbuddy.com/

Kolhapur Office:
1327/1 F-2, First Floor, C-Ward,
Laxmipuri, Kolhapur,
Maharashtra 416002, India

Pune Office:
Office No. 503, 5th Floor,
Raichandani Galaxy, Baner Road,
Pune, Maharashtra 411045, India

Telephone: +91 788 755 7441

General Privacy and Data Requests:
[email protected]

Grievance Officer:
Lakshman Prajapati
Co-Founder & Grievance Officer
[email protected]

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data processed through:

  • androtechbuddy.com and its subdomains

  • corporate and product websites operated by us

  • contact and consultation forms

  • newsletter and marketing forms

  • recruitment and career forms

  • customer portals

  • web applications

  • mobile applications

  • software products

  • cloud-based services

  • APIs

  • third-party integrations

  • managed services

  • software-development services

  • technical-support services

  • sales and business-development activities

  • customer communications

  • recruitment processes

  • business events

  • other services operated or provided by Andro Buddy Technologies

Certain products, applications, integrations or services may have their own supplemental privacy notices.

Where a separate privacy notice applies specifically to a product or service, that notice should be read together with this Policy.

For information specifically processed through Meta Platforms, Facebook, Instagram, Messenger or the WhatsApp Business Platform, a separate Meta Platform and WhatsApp Business Privacy Policy may also apply.

3. Our Role in Processing Personal Data

Depending on the circumstances, Andro Buddy Technologies may process personal data in different capacities.

When we determine why and how personal data is processed, including in connection with our website, recruitment, marketing, customer relationships and internal business operations, we generally act as the Data Fiduciary, where that term applies under Indian data-protection law.

When we process personal data solely on behalf of a customer and according to that customer’s instructions, we generally act as a Data Processor, service provider or technology provider.

Where we act as a Data Processor, the relevant customer generally determines the purpose for which the personal data is processed and is responsible for providing appropriate privacy notices, establishing the required lawful basis and obtaining any necessary permissions or consent from individuals.

We process such information in accordance with customer instructions, contractual obligations, applicable law and relevant platform requirements.

4. Personal Data We May Collect

The personal data we collect depends on how you interact with us and the services you use.

4.1 Identity and Contact Information

We may collect:

  • full name

  • business or organisation name

  • job title or designation

  • email address

  • telephone or mobile number

  • postal address

  • city

  • state

  • country

  • other contact information voluntarily provided to us

4.2 Business Information

We may process information such as:

  • company name

  • organisation details

  • designation

  • department

  • business requirements

  • project requirements

  • requested services

  • service preferences

  • information about the organisation you represent

4.3 Account Information

Where a product or service requires an account, we may process:

  • account identifiers

  • usernames

  • user roles

  • authentication information

  • account permissions

  • workspace information

  • account preferences

  • login and authentication events

We do not intentionally store passwords in readable plain-text form.

4.4 Communications

We may process communications that you send to us through:

  • website forms

  • email

  • telephone

  • WhatsApp

  • customer-support systems

  • online meetings

  • social-media platforms

  • other communication channels

This may include messages, enquiries, feedback, support requests, meeting information and related correspondence.

4.5 Customer and Commercial Information

We may process:

  • quotations

  • proposals

  • contracts

  • statements of work

  • project information

  • service subscriptions

  • billing information

  • invoices

  • payment status

  • transaction references

  • purchase information

  • customer-support records

  • project documentation

  • related business records

4.6 Recruitment and Applicant Information

If you apply for employment, an internship or another opportunity with us, we may process information including:

  • name

  • email address

  • telephone number

  • location

  • résumé or CV

  • educational qualifications

  • employment history

  • technical skills

  • certifications

  • portfolio

  • GitHub or professional profile

  • current compensation

  • expected compensation

  • notice period

  • preferred role

  • relocation preference

  • interview assessments

  • communications relating to your application

Where additional information such as date of birth or gender is requested, we will seek to process it only where reasonably necessary or voluntarily provided.

Recruitment information is used for recruitment, candidate evaluation, workforce planning, employment administration, legal compliance and related purposes.

4.7 Technical and Device Information

When you access our websites, products or services, we may automatically receive:

  • IP address

  • browser type and version

  • operating system

  • device information

  • user agent

  • approximate location derived from IP address

  • referring URL

  • pages accessed

  • date and time of access

  • application logs

  • server logs

  • authentication logs

  • diagnostic information

  • error information

  • security events

4.8 Cookies and Similar Technologies

We may use cookies, pixels, SDKs, local storage, tags and similar technologies for purposes including:

  • website functionality

  • authentication

  • security

  • remembering preferences

  • analytics

  • performance measurement

  • conversion measurement

  • marketing, where permitted

4.9 Information Received Through Integrations

Where you connect a third-party service to one of our products or authorise an integration, we may receive information from that service according to the permissions you grant.

Such services may include:

  • Meta

  • WhatsApp

  • Facebook

  • Instagram

  • Google

  • Microsoft

  • CRM systems

  • cloud-service providers

  • payment-service providers

  • communication platforms

  • other business applications

The information available to us depends on the relevant integration and permissions.

5. Sensitive Personal Data

We do not intentionally request sensitive personal information unless it is reasonably necessary for a legitimate and lawful purpose.

Depending on applicable law, sensitive information may include information relating to passwords, financial information, health information, medical records, biometric information and other specially protected categories of information.

Where such information is processed, we seek to apply security measures appropriate to its nature and sensitivity.

You should not provide passwords, payment credentials, authentication secrets, API secrets, private keys or other highly sensitive information through ordinary contact forms or email unless specifically requested through an appropriate secure process.

6. How We Collect Personal Data

We may collect personal data:

  • directly from you

  • through forms you submit

  • when you contact us

  • when you request a quotation or consultation

  • when you create or use an account

  • when you purchase or use our services

  • when you communicate with our team

  • when you submit a job application

  • through authorised third-party integrations

  • through our business customers

  • from organisations you represent

  • from authorised representatives

  • from service providers

  • from referral partners

  • through payment providers

  • from professional or publicly available business sources, where legally permitted

If an organisation provides personal data about another individual to us, that organisation is responsible for ensuring that it has the authority and lawful basis required to provide that information.

7. Purposes for Processing Personal Data

We may process personal data for purposes including:

  • providing our products and services

  • operating our websites and applications

  • responding to enquiries

  • scheduling consultations

  • preparing proposals and quotations

  • establishing customer relationships

  • performing contracts

  • managing customer accounts

  • developing software

  • configuring APIs and integrations

  • providing customer support

  • providing technical support

  • maintaining and improving products

  • troubleshooting technical problems

  • managing subscriptions

  • processing invoices and payments

  • maintaining accounting records

  • communicating service information

  • sending security notifications

  • authenticating users

  • preventing fraud and abuse

  • protecting our systems and infrastructure

  • investigating security incidents

  • maintaining audit records

  • managing recruitment

  • analysing website or service performance

  • conducting permitted marketing

  • complying with legal and regulatory obligations

  • responding to lawful government requests

  • enforcing contractual rights

  • establishing, exercising or defending legal claims

We seek not to process personal data for purposes that are materially incompatible with the purposes communicated when the information was collected unless permitted by applicable law.

8. Consent and Other Permitted Processing

Where applicable law requires consent, we seek to obtain consent through clear and affirmative action.

A request for consent should explain the relevant purpose of processing and provide sufficient information for the individual to make an informed choice.

Where processing depends upon consent, you may withdraw that consent through an available consent mechanism or by contacting us.

Withdrawal of consent does not affect processing lawfully carried out before the withdrawal.

We may continue to process or retain information following withdrawal where such processing or retention is required or permitted by applicable law.

Certain processing may also take place without consent where expressly permitted by applicable law.

9. Data Minimisation

We seek to collect personal data that is reasonably necessary for the specified purpose.

We do not intentionally collect excessive personal information merely because it may potentially become useful in the future.

We periodically seek to review our forms, systems and processes to reduce unnecessary data collection where reasonably practicable.

10. Accuracy of Personal Data

We take reasonable steps, where relevant to the purpose of processing, to maintain accurate and complete personal information.

You may request correction or updating of eligible personal information by contacting us.

You are responsible for providing accurate information and informing us where information that is material to the service has changed.

11. Sharing and Disclosure of Personal Data

We do not disclose personal data indiscriminately.

We may share personal data where reasonably necessary with:

  • authorised employees

  • directors

  • contractors

  • consultants

  • professional advisers

  • accountants

  • auditors

  • legal advisers

  • hosting providers

  • cloud-infrastructure providers

  • database providers

  • communications providers

  • cybersecurity providers

  • analytics providers

  • payment-service providers

  • customer-support providers

  • recruitment providers

  • other authorised service providers or subprocessors

Where we process information on behalf of a customer, personal data may also be made available to that customer and its authorised users.

Service providers are expected to process information only for authorised purposes and subject to appropriate confidentiality, security or contractual obligations where applicable.

12. No Sale of Personal Data

Andro Buddy Technologies does not sell personal data to data brokers.

We do not sell:

  • customer databases

  • contact-form submissions

  • job applications

  • résumés

  • confidential project information

  • customer communications

  • end-user databases entrusted to us by customers

to unrelated third parties for their independent commercial use.

13. Third-Party Service Providers and Subprocessors

We may use third-party technology and service providers to operate our business and deliver our services.

These providers may perform functions such as:

  • cloud hosting

  • database hosting

  • email delivery

  • communications

  • analytics

  • customer support

  • monitoring

  • cybersecurity

  • payment processing

  • development infrastructure

Where reasonably appropriate, we require providers processing personal data on our behalf to maintain confidentiality and appropriate data-protection and security safeguards.

We seek to provide such providers only the information reasonably necessary to perform their services.

14. International Data Processing and Transfers

Our customers, technology providers, cloud providers and other service providers may operate in India and other countries.

Personal data may therefore be processed outside the location where it was originally collected.

Where international processing or transfers occur, we will seek to comply with applicable Indian data-protection requirements and any restrictions or conditions imposed by competent authorities.

We may also implement appropriate contractual, technical and organisational safeguards where reasonably required.

15. Data Retention

We retain personal data only for as long as reasonably necessary for:

  • the purpose for which it was collected

  • providing requested services

  • maintaining an active business relationship

  • performing contractual obligations

  • compliance with accounting and taxation requirements

  • security and fraud prevention

  • resolving disputes

  • maintaining legally required records

  • establishing, exercising or defending legal claims

  • other lawful purposes

Retention periods vary depending on the type of information.

Website Enquiries

Website enquiries and prospective customer information may generally be retained for up to 24 months following the last meaningful interaction, unless a business relationship continues or continued retention is otherwise necessary.

Recruitment Information

Information relating to unsuccessful job candidates may generally be retained for up to 12 months after completion of the recruitment process, unless the candidate agrees to a longer period or continued retention is permitted or required by law.

Customer and Contract Records

Contractual, accounting, taxation, invoicing and transaction records may be retained for the statutory or business record-retention period applicable to those records.

Security and Audit Records

Security logs, authentication records and audit information may be retained for periods reasonably necessary for security monitoring, incident investigation, fraud prevention, legal compliance and audit purposes.

Customer-Processed Data

Where we process personal data solely on behalf of a customer, retention may be governed by our agreement with that customer and the customer’s documented instructions.

At the end of the applicable retention period, information may be deleted, anonymised, de-identified or securely disposed of unless continued retention is legally permitted or required.

16. Information Security

We maintain administrative, organisational and technical safeguards designed to protect personal data against:

  • unauthorised access

  • unauthorised disclosure

  • unlawful processing

  • alteration

  • destruction

  • accidental loss

  • misuse

  • compromise of confidentiality, integrity or availability

Depending on the relevant system and risk, safeguards may include:

  • role-based access control

  • least-privilege access

  • authentication controls

  • multi-factor authentication

  • encryption in transit

  • encryption or equivalent safeguards for stored sensitive information where appropriate

  • secure credential management

  • network security controls

  • logging and monitoring

  • backups

  • vulnerability management

  • software patching

  • secure software-development practices

  • code review

  • incident-response procedures

  • business-continuity measures

  • employee confidentiality obligations

  • vendor-security requirements

No internet-connected system can be guaranteed to be completely secure.

Users are also responsible for maintaining the confidentiality of their credentials and informing us promptly if they suspect unauthorised access.

17. Personal Data Breaches and Security Incidents

We maintain procedures intended to identify, investigate, contain, remediate and document security incidents.

Where a personal-data breach or cybersecurity incident is subject to mandatory reporting or notification requirements, we will provide relevant notifications to affected customers, individuals, CERT-In, the Data Protection Board of India or other competent authorities within the timelines required by applicable law.

Where we process affected personal data on behalf of a customer, we will reasonably cooperate with that customer in connection with incident investigation and notification obligations.

We may preserve information relating to security incidents where necessary for:

  • investigation

  • remediation

  • cybersecurity

  • fraud prevention

  • audit

  • evidence preservation

  • legal compliance

18. Cookies and Similar Technologies

Our websites may use essential and non-essential cookies and similar technologies.

Essential Cookies

Essential cookies may be required for:

  • security

  • website operation

  • authentication

  • session management

  • fraud prevention

  • core functionality

Analytics Cookies

Analytics technologies may help us understand:

  • website traffic

  • page performance

  • visitor interactions

  • errors

  • general usage patterns

Marketing and Advertising Technologies

Where enabled, marketing technologies may be used for:

  • advertising measurement

  • attribution

  • conversion measurement

  • remarketing

  • campaign analysis

Where applicable law requires consent for non-essential technologies, we seek to honour the choices made through our applicable consent-management mechanism.

You may also control cookies through your browser settings.

19. Analytics and Third-Party Marketing Technologies

We may use technologies provided by third parties such as Google, Meta or similar providers for permitted analytics, performance measurement or advertising functionality.

The information collected by those providers may also be subject to their own privacy policies.

Where applicable law requires prior consent before activating a non-essential analytics or marketing technology, we intend to configure such technology in accordance with the required consent choices.

20. Marketing Communications

We may send business or marketing communications where:

  • you requested information from us

  • you expressed interest in our products or services

  • you have an existing business relationship with us

  • you subscribed to communications

  • we otherwise have an appropriate lawful basis to communicate with you

You may opt out of marketing communications using the unsubscribe method provided or by contacting us.

Marketing opt-outs do not prevent us from sending communications necessary for:

  • an existing contract

  • account administration

  • security

  • service operation

  • billing

  • customer support

  • legal compliance

21. Recruitment Privacy

Personal information submitted through our recruitment process will be used primarily for:

  • reviewing applications

  • evaluating qualifications

  • interviewing candidates

  • communicating with candidates

  • internal hiring decisions

  • workforce planning

  • employment administration

  • permitted background or verification activities

  • compliance with employment-related obligations

Applicant information will not be used for unrelated marketing merely because an individual applied for a position.

Access to recruitment information is restricted to personnel and authorised providers with a legitimate recruitment, management, HR, security or legal need.

22. Children’s Personal Data

Our corporate website and general business services are not designed or directed primarily toward children.

For purposes of the Digital Personal Data Protection Act, where applicable and in force, a child generally means an individual who has not completed eighteen years of age.

We do not knowingly use children’s personal data through our general corporate website for:

  • behavioural monitoring

  • behavioural profiling

  • targeted advertising directed at children

  • unrelated commercial exploitation

If a service legitimately requires the processing of a child’s personal data, we will seek to implement the parental or guardian consent and additional protections required under applicable law, subject to any lawful exemptions that may apply.

23. Automated Processing and Artificial Intelligence

Certain products, services or customer projects may use automated systems or artificial-intelligence technologies.

Where personal data is processed through these systems, we seek to apply appropriate:

  • purpose restrictions

  • access controls

  • confidentiality requirements

  • contractual restrictions

  • security safeguards

  • applicable legal requirements

We do not intentionally use confidential customer information to train unrelated public or general-purpose artificial-intelligence models unless such processing has the required legal basis, contractual authority and any required permission or consent.

Additional restrictions may apply to data received through third-party platforms such as Meta or the WhatsApp Business Platform.

24. Your Privacy Rights

Subject to applicable law and its commencement from time to time, you may have rights concerning your personal data.

These may include the right to:

  • obtain information about personal data processed about you

  • seek correction of inaccurate personal data

  • request completion of incomplete personal data

  • request updating of personal data

  • request erasure where applicable

  • withdraw consent where processing is based on consent

  • raise a grievance

  • exercise other rights provided by applicable law

  • nominate another individual to exercise applicable rights in circumstances permitted by law

These rights may be subject to lawful exceptions.

For example, we may be permitted or required to retain information despite a deletion request where it is necessary for:

  • legal compliance

  • taxation

  • accounting

  • security

  • fraud prevention

  • regulatory requirements

  • contractual obligations

  • dispute resolution

  • establishment or defence of legal claims

We may take reasonable steps to verify the identity and authority of a requester before fulfilling a privacy request.

25. How to Submit a Privacy Request

Privacy requests may be sent to:

[email protected]

You may use a subject such as:

  • Privacy Rights Request

  • Personal Data Access Request

  • Personal Data Correction Request

  • Personal Data Deletion Request

  • Consent Withdrawal Request

  • Privacy Grievance

Please provide sufficient information to allow us to identify the relevant account, interaction or records.

Do not send passwords, OTPs, private keys, access tokens or unnecessary sensitive information when submitting a request.

Where additional identity verification is necessary, we may request reasonable information for that purpose.

26. Personal Data Deletion

You may request deletion of eligible personal data by contacting:

[email protected]

Subject:

Personal Data Deletion Request

After appropriate verification, we will assess the request and delete, anonymise, de-identify or restrict eligible information as required by applicable law.

We may retain information where continued retention is required or permitted for purposes including:

  • compliance with law

  • accounting or taxation

  • fraud prevention

  • cybersecurity

  • contractual obligations

  • dispute resolution

  • regulatory requirements

  • establishment or defence of legal claims

Deletion from active production systems may not result in immediate deletion from encrypted or protected backups.

Where information remains in backups, it will remain protected and will be removed or overwritten in accordance with the applicable backup-retention cycle.

27. Data Processed on Behalf of Our Customers

In some cases, we process personal data solely on behalf of a business customer.

If your information was provided to us through one of our customers, that customer may be the primary Data Fiduciary or party responsible for responding to your privacy request.

In such circumstances, we may:

  • direct you to the relevant customer

  • forward the request to that customer where appropriate

  • assist the customer in responding

  • process the request according to the customer’s documented instructions

This does not remove any independent legal obligations that apply directly to Andro Buddy Technologies.

28. Third-Party Websites and Services

Our websites or services may contain links to or integrations with third-party platforms.

These may include platforms operated by:

  • Meta

  • WhatsApp

  • Facebook

  • Instagram

  • Google

  • Microsoft

  • payment providers

  • cloud-service providers

  • communication providers

  • other technology companies

Where you independently interact with a third party, the third party’s own privacy policy and terms may apply.

We are not responsible for the independent privacy practices of third-party websites or services that we do not control.

29. Government, Regulatory and Legal Disclosures

We may preserve or disclose information where reasonably necessary to:

  • comply with applicable law

  • comply with a court order

  • comply with regulatory requirements

  • respond to valid legal process

  • respond to lawful requests from competent government authorities

  • investigate cybersecurity incidents

  • prevent fraud

  • protect users or other persons

  • establish, exercise or defend legal claims

  • enforce contractual rights

Where permitted, we seek to limit disclosure to information reasonably necessary for the relevant lawful purpose.

30. Corporate Transactions

If Andro Buddy Technologies is involved in a:

  • merger

  • acquisition

  • restructuring

  • investment

  • financing

  • reorganisation

  • asset sale

  • business transfer

personal data relevant to the transaction may be transferred or disclosed as part of that process.

Any recipient will remain subject to applicable privacy and confidentiality requirements.

31. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in:

  • our business

  • our products or services

  • our technology

  • our processing activities

  • applicable laws

  • regulatory guidance

  • security requirements

The latest version will be published on this page together with the revised Last Updated date.

Where legally required, we may provide additional notice or obtain new consent before materially changing a purpose for which personal data is processed.

We encourage users to review this Policy periodically.

32. Grievance Redressal

If you have a privacy complaint or grievance, you may first contact our support team:

Email: [email protected]

If your concern requires escalation, you may contact our Grievance Officer directly.

Grievance Officer

Name: Lakshman Prajapati
Designation: Co-Founder & Grievance Officer
Email: [email protected]
Telephone: +91 788 755 7441

Address:
Andro Buddy Technologies Private Limited
1327/1 F-2, First Floor, C-Ward,
Laxmipuri, Kolhapur,
Maharashtra 416002, India

We will acknowledge, investigate and seek to resolve privacy grievances within the period required under applicable law.

Where the Digital Personal Data Protection Act and applicable rules provide further remedies, an eligible Data Principal may pursue those remedies after using the applicable grievance-redressal mechanism.

33. Contact Us

For questions about this Privacy Policy, privacy requests or our handling of personal data, contact:

Andro Buddy Technologies Private Limited
CIN: U47910MH2024PTC423697

General Privacy Requests:
[email protected]

Grievance Officer:
Lakshman Prajapati
Co-Founder & Grievance Officer
[email protected]

Telephone: +91 788 755 7441

Website:
https://androtechbuddy.com/

Kolhapur Office:
1327/1 F-2, First Floor, C-Ward,
Laxmipuri, Kolhapur,
Maharashtra 416002, India

Pune Office:
Office No. 503, 5th Floor,
Raichandani Galaxy, Baner Road,
Pune, Maharashtra 411045, India

This Privacy Policy should be read together with any product-specific, service-specific, cookie, data-deletion or platform-specific privacy notices made available by Andro Buddy Technologies.