1. Introduction & Overview
At TriVergeTech Private Limited ("Company", "TriVergeTech", "we", "us", or "our"), we maintain an uncompromising commitment to data protection, transparency, and information security. This Privacy Policy outlines how we collect, store, utilize, disclose, and safeguard information obtained from visitors, corporate clients, academic institutions, software users, and business partners across our websites, applications, and managed infrastructure.
This policy has been designed in strict accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the General Data Protection Regulation (GDPR) for European data subjects, and applicable international privacy frameworks.
2. Data Controller & Entity Representation
The legal entity responsible for the collection and processing of personal data under this Privacy Policy is:
- Entity Name: TriVergeTech Private Limited
- Corporate Identification Number (CIN): U72900MP2024PTC068942
- Goods & Services Tax Number (GSTIN): 23AAMCT0499B1ZE
- Address: Ward 15, Maichal Chowk, Colliery Road, Dhanpuri Nargada Hari Dafai, Shahdol, Madhya Pradesh – 484114, India
- Data Protection Inquiries: privacy@trivergetech.com
- Corporate Legal Communications: legal@trivergetech.com
- Direct Hotline: +91 79991 55066
3. Categories of Data We Collect
Depending on how you interact with our platforms and services, we collect information across the following categories:
3.1 Information Provided Directly by You
- Inquiry & Project Brief Data: Full name, professional work email address, organization or institutional name, telephone/WhatsApp number, project requirements, and scope documentation.
- Commercial & Billing Data: Corporate billing address, GSTIN, authorized signatory contact details, invoice history, and bank wire transfer confirmations. (Note: We do not store raw credit card numbers; payment processing is handled through PCI-DSS Level 1 certified gateways).
- Account Credentials: Usernames, business email addresses, and encrypted password hashes for authorized client access to software dashboards and portals.
3.2 Automated & Technical Information
- Device & Telemetry Data: IP addresses, browser user agent strings, device operating system versions, referring URLs, access timestamps, and page interaction diagnostics.
- Attribution Data (AffTrax Network): Pseudonymized click identifiers, conversion postback signals, device classification metrics, and network latency logs.
4. Vertical-Specific Data Safeguards
TriVergeTech operates diversified technology units with distinct data protection protocols tailored to their operational profiles:
4.1 Custom Product Engineering & Applied Enterprise AI
When engineering custom software, cloud architectures, or private Retrieval-Augmented Generation (RAG) pipelines for clients:
- Zero Foundational Training: Client proprietary data, source code, and knowledge bases are never utilized to train public foundation models.
- Private Tenancy: All vector databases, embeddings, and API processing environments operate within isolated tenant boundaries with role-based access control (RBAC).
- Confidentiality by Default: Engineering sprints are governed by strict mutual non-disclosure agreements (NDAs).
4.2 TriVerge STEM Labs & Educational Technology
Our K–12 educational robotics and STEM lab installations adhere to the highest standard of minor and student privacy:
- Institutional Authorization: Student access to digital lab tools and Olympiad grading portals is facilitated exclusively through authorized school administrative agreements.
- No Commercial Profiling: We strictly prohibit advertising, behavioral tracking, or commercial profiling of students.
- Minimal Collection: We collect only the minimum information necessary (such as student first name and grade level) to facilitate interactive simulations and project grading.
4.3 AffTrax SaaS Infrastructure
Our performance marketing tracking software (https://afftrax.com) is engineered with privacy-by-design:
- IP Anonymization: IP addresses collected during redirection are hashed or truncated to prevent persistent user tracking.
- Ephemeral Processing: Click logs are processed in memory at the global network edge and aggregated for analytical reporting.
- FraudShield™ Telemetry: Traffic quality scoring evaluates non-personal network anomalies to detect automated bot activity without infringing upon end-user privacy.
4.4 Affluence Media Group
Creator partnerships and digital media campaigns collect business contact information of creators, audience engagement analytics, and conversion verification metrics in compliance with advertising industry disclosure standards.
5. Purpose & Legal Basis for Processing
We process personal and organizational data only where we have a valid legal basis under applicable law:
- Performance of Contract: To deliver custom software milestones, deploy physical STEM lab equipment, maintain AffTrax SaaS subscriptions, and fulfill executed Statements of Work (SOWs).
- Legitimate Business Interests: To secure our network infrastructure against cyber threats, improve platform performance, prevent ad fraud, and provide enterprise technical support.
- Statutory & Legal Compliance: To maintain corporate statutory records, comply with GST invoicing mandates, fulfill MCA audit obligations, and respond to lawful government directives.
- Consent: Where you have explicitly opted in to receive technical whitepapers, newsletters, or partnership communications (with the right to revoke consent at any time).
7. Sub-Processors & Data Sharing
We do not sell your data. We share information only with trusted third-party service providers ("Sub-Processors") who adhere to strict contractual data protection agreements:
- Cloud Infrastructure Providers: ISO/IEC 27001 and SOC-2 certified cloud server and edge hosting facilities for secure data storage.
- Communication & SMTP Gateways: Transactional email delivery and SMS notification providers.
- Banking & Payment Processors: Regulated banking institutions and payment gateways for invoicing and settlements.
- Legal & Professional Advisors: Statutory auditors, legal counsel, and compliance consultants bound by professional confidentiality obligations.
8. Cross-Border Data Transfers
TriVergeTech operates primarily from data centers located in India and globally distributed edge servers. Where cross-border data transfer occurs (e.g., routing API traffic through global cloud regions), we ensure appropriate safeguards are enacted:
- Standard Contractual Clauses (SCCs) approved by international regulatory authorities.
- End-to-end TLS 1.3 encryption during international data transit.
- Strict compliance with cross-border data transfer restrictions mandated by the DPDP Act 2023.
9. Data Retention & Secure Disposal
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required to satisfy statutory, legal, tax, or regulatory obligations:
- Active Client Accounts: Retained throughout the duration of active commercial engagement plus standard post-termination archival periods (typically 3 to 7 years for tax and statutory audit records).
- Project Briefs & Inquiries: Non-converting prospect briefs are securely purged after eighteen (18) months unless continuing engagement is requested.
- AffTrax Ephemeral Logs: Raw attribution click logs are rotated and permanently purged according to tier retention schedules (30 to 90 days).
- Secure Disposal: Data slated for deletion is cryptographically shredded or sanitized using NIST SP 800-88 compliant data destruction standards.
10. Information Security & Encryption Standards
TriVergeTech implements defense-in-depth technical, administrative, and physical security measures to protect data against unauthorized access, alteration, disclosure, or destruction:
- Encryption in Transit: All data transmissions are encrypted using modern Transport Layer Security (TLS 1.3 / HTTPS).
- Encryption at Rest: Sensitive databases and backups are encrypted utilizing AES-256 bit encryption algorithms.
- Access Control: Strict Principle of Least Privilege (PoLP), Multi-Factor Authentication (MFA), and role-based access control (RBAC) across all production infrastructure.
- Continuous Monitoring: Real-time security telemetry, automated DDoS mitigation, and continuous vulnerability scanning.
11. Your Statutory Data Rights
Under the Digital Personal Data Protection Act, 2023 and international privacy regulations, data principals possess specific legal rights regarding their personal information:
- Right to Access & Summary: The right to request confirmation of whether we process your data and receive a clear summary of processing activities.
- Right to Correction & Erasure: The right to correct inaccurate data, complete incomplete records, or request erasure of personal data that is no longer necessary for the purpose it was collected.
- Right to Withdraw Consent: The right to withdraw previously granted consent at any time without affecting the lawfulness of processing based on consent prior to withdrawal.
- Right of Grievance Redressal: The right to have grievances addressed by our appointed Grievance Officer within statutory timelines.
- Right to Nominate: The right to nominate an individual to exercise your data rights in the event of death or incapacity.
To exercise any of these rights, please submit a written request to privacy@trivergetech.com. We will verify your identity and respond within thirty (30) calendar days.
12. K–12 & Minor Data Protection
TriVergeTech does not knowingly collect personal data directly from children under the age of 18 without verifiable parental or institutional school consent.
In the context of our TriVerge STEM Labs school partnerships, any interaction by students with our learning platforms is authorized and supervised by the partner school acting as an educational intermediary. If we discover that personal data of a minor has been collected without appropriate verifiable consent, we will take immediate steps to expunge such data from our systems. Parents or guardians may contact privacy@trivergetech.com to review, modify, or request deletion of their child's records.
13. Incident Response & Breach Notification
TriVergeTech maintains an active Incident Response Plan. In the unlikely event of a confirmed personal data breach that poses risk to data principals:
- We will notify the Data Protection Board of India (DPBI) and relevant regulatory authorities within statutory timelines mandated by law.
- We will promptly notify affected data principals and enterprise clients with actionable guidance and descriptions of remedial measures enacted.
- Our security and forensics team will conduct an immediate root-cause investigation to remediate the vulnerability and prevent recurrence.
14. Policy Modifications & History
We may periodically review and update this Privacy Policy to reflect changes in our technology stack, business verticals, legal requirements, or regulatory guidance.
When material changes are made, we will update the "Last Revised" date at the top of this document and provide prominent notice across our websites. Continued use of our platforms following the publication of revised terms constitutes your acknowledgment and acceptance of the updated practices.
15. Grievance Officer & Contact Details
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, TriVergeTech has designated a dedicated Grievance Officer for data protection and privacy matters:
Data Protection & Grievance Officer
TriVergeTech Private Limited
CIN: U72900MP2024PTC068942
GSTIN: 23AAMCT0499B1ZE
Grievance Officer Email: privacy@trivergetech.com
Legal & Compliance: legal@trivergetech.com
Direct Hotline: +91 79991 55066
Address: Ward 15, Maichal Chowk, Colliery Road, Dhanpuri Nargada Hari Dafai, Shahdol, Madhya Pradesh – 484114, India