Privacy Policy
Platform: hisaabwala.org Operator / Data Fiduciary: Simply Five Studio, a sole proprietorship of Mr. Mohamed Jamnagarwala Principal place of business: 22 Josier Street, Nungambakkam, Chennai 600034, Tamil Nadu, India GSTIN: 33DCGPM7210H1ZT Grievance Officer / Data Protection Contact: Mr. Mohamed Jamnagarwala, [email protected]
Version: 1.0 Effective Date: 26 July 2026 Last Reviewed: 26 July 2026
PREAMBLE AND STATUTORY BASIS
This Privacy Policy ("Policy") is published in compliance with, and shall be read consistently with:
(a) the Information Technology Act, 2000 and the rules made thereunder, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; (b) the Digital Personal Data Protection Act, 2023 and the rules made thereunder, as and when brought into force in their respective parts; (c) the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020; (d) all other Applicable Law as defined in the Terms & Conditions.
This Policy forms an integral and inseparable part of the Terms & Conditions and must be read together with them, with the Cookies & Data notice, and with the Cancellations & Refund Policy. Capitalised terms not defined here bear the meanings given in the Terms & Conditions. In the event of any inconsistency, the provision more protective of the Operator shall prevail.
This Policy is an electronic record under the Information Technology Act, 2000 and requires no physical or digital signature.
BY CREATING AN ACCOUNT, MAKING A PAYMENT, OR ACCESSING OR USING THE PLATFORM BY ANY MEANS OR THROUGH ANY MEDIUM, YOU GIVE YOUR FREE, SPECIFIC, INFORMED, UNCONDITIONAL, UNAMBIGUOUS AND AFFIRMATIVE CONSENT TO THE COLLECTION, STORAGE, USE, PROCESSING, TRANSFER, DISCLOSURE AND RETENTION OF DATA AS DESCRIBED IN THIS POLICY. IF YOU DO NOT CONSENT, YOU MUST NOT USE THE PLATFORM.
1. SCOPE AND FUNDAMENTAL POSITION
1.1 What This Policy Covers
This Policy describes how the Operator handles data in connection with the Platform available at hisaabwala.org and its subdomains, howsoever accessed, including via web browsers, mobile devices, tablets, desktop applications, wearable or embedded devices, Internet-of-Things devices, application programming interfaces, webhooks, automations, scripts, artificial intelligence agents, personal assistant agents and autonomous agents.
1.2 What This Policy Does Not Cover
This Policy does not apply to, and the Operator accepts no responsibility whatsoever in respect of:
(a) any third-party website, application, service, gateway, network, device, browser, extension, operating system, application store or artificial intelligence service, each of which is governed exclusively by its own privacy policy; (b) the privacy practices, security posture, data handling, retention or disclosure of any User in respect of Third-Party Data that such User enters into the Platform; (c) any data after it has left the Operator's systems by any means, including any export, download, print, screenshot, forwarding, sharing, copying or transmission by any party; (d) any offline collection, processing or disclosure of data by any User.
1.3 Fundamental Position: The Platform Is a Data-Entry and Processing Utility
1.3.1 The Platform is a general-purpose data-entry, data-storage, data-arrangement and data-processing utility. It is not compliance, regulatory, accounting, audit, taxation or government-linked software, and is not associated with, approved by, backed by, linked to or endorsed by GST, any Government, any Governmental Authority, any regulator, any professional institute or any official portal. All data handled by the Platform is handled as a data-entry and data-processing job only, and never as an official, statutory or evidentiary record of any business transaction. Clause 2 of the Terms & Conditions applies in full to this Policy.
1.3.2 The Operator does not verify, validate, audit, certify or vouch for the accuracy, legality, provenance or lawfulness of any data entered into the Platform by any User.
2. ROLES: WHO IS RESPONSIBLE FOR WHAT
This distinction is fundamental and is not open to reinterpretation.
2.1 The Operator as Data Fiduciary (Account Data Only)
In respect of Account Data (defined in Clause 3.1), that is, the data of the person who signs up, the Operator acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 and determines the purposes described in Clause 4.
2.2 The Operator as Data Processor (All Third-Party Data)
2.2.1 In respect of User Content, and in particular all Third-Party Data, meaning data relating to any person other than the User, including the User's own customers, clients, buyers, sellers, suppliers, vendors, distributors, agents, brokers, employees, contractors, debtors, creditors, guarantors, tenants, members, correspondents, counterparties or any other person:
THE USER IS THE DATA FIDUCIARY (AND, WHERE ANY FOREIGN LAW APPLIES, THE DATA CONTROLLER). THE OPERATOR IS MERELY A DATA PROCESSOR, PROCESSING SUCH DATA SOLELY ON THE USER'S INSTRUCTIONS, ON THE USER'S BEHALF, AND FOR NO INDEPENDENT PURPOSE OF ITS OWN.
2.2.2 Accordingly, the User alone and never the Operator:
(a) determines what Third-Party Data is collected, entered, retained and deleted, and for what purpose; (b) is responsible for having a valid, lawful, specific, informed, free, unconditional, unambiguous and demonstrable basis (including any consent or legitimate use required by Applicable Law) for every item of Third-Party Data; (c) is responsible for giving every notice required by Applicable Law to every Data Principal, in the required form, language and manner; (d) is responsible for receiving, verifying and honouring every request and grievance of every Data Principal, including rights of access, correction, completion, updation, erasure, nomination and grievance redressal; (e) is responsible for the accuracy, adequacy, relevance, non-excessiveness and lawful retention period of such data; (f) is responsible for compliance with every sectoral, professional, contractual and confidentiality obligation applicable to such data; (g) warrants that entry of such data into the Platform, and its processing by the Operator as instructed, breaches no Applicable Law, contract, privilege or third-party right.
2.2.3 The Operator has no relationship of any kind with, no notice to, no communication with, and no means of identifying, contacting, verifying or obtaining consent from, any Third-Party Data subject. Any Data Principal whose data appears within a User's Account must approach that User directly. Where such a person approaches the Operator, the Operator may, without any obligation and without accepting any responsibility, forward the request to the relevant User and decline further involvement.
2.2.4 The User shall fully indemnify, defend and hold harmless the Operator, on the terms of Clause 16 of the Terms & Conditions, in respect of every claim, notice, complaint, proceeding, inquiry, penalty, compensation, order and cost arising from or relating to Third-Party Data, including any proceeding before the Data Protection Board of India, any consumer forum, any court or any Governmental Authority.
3. DATA WE HANDLE
3.1 Account Data (Operator as Data Fiduciary)
(a) Identity and contact: name, business or trade name, e-mail address, mobile or telephone number, postal or business address, city, state, country, postal code, and (where voluntarily provided) profile photograph or display name. (b) Authentication: password in salted-and-hashed form only (the Operator does not store plaintext passwords), password reset tokens, one-time passwords, two-factor secrets, session identifiers, API keys and their hashes, and recovery information. (c) Subscription and billing: plan selected, Subscription Term voluntarily chosen, Fee paid, currency, invoice records, payment status, payment reference and gateway transaction identifiers, refund and chargeback records, and tax particulars including GSTIN (where voluntarily furnished), legal name, registered address, place of supply and state code. (d) Configuration and preferences: Modules enabled or disabled, Workspaces created, settings, templates, formats, notification preferences, language, timezone and display preferences. (e) Support and correspondence: e-mails, tickets, messages, attachments, screenshots and records of communications with the Operator, including notices under Clause 18 of the Terms & Conditions.
3.2 Technical and Log Data (Automatically Collected)
(a) Internet Protocol address and derived approximate location at city or region level; (b) device type, model class, operating system and version, screen resolution, language and locale; (c) browser or client type and version, user-agent string, and referring or exit pages; (d) date and time stamps, session duration, pages and Modules accessed, actions taken, and clickstream within the Platform; (e) API request logs including endpoint, method, status code, latency, payload size and rate-limit counters; (f) authentication and security events including successful and failed login attempts, password changes, credential resets, session creations and terminations, permission changes and anomaly signals; (g) error reports, stack traces, diagnostic data and crash information; (h) cookie and similar-technology identifiers as described in the Cookies & Data notice.
3.3 User Content (Operator as Data Processor)
All data, text, numbers, names, addresses, identifiers, descriptions, particulars, attachments, files, notes, tags and metadata entered, uploaded, imported, transmitted or generated by or at the instance of a User, including all Third-Party Data.
The Operator neither prescribes nor controls what a User chooses to enter. The Operator does not inspect, review, verify, moderate, audit or curate User Content in the ordinary course, and is under no obligation to do so.
3.4 Payment Data
3.4.1 Payments are processed by third-party payment gateways, aggregators, processors, card networks, banks, wallets and unified payments interface providers. The Operator is not a payment system, payment aggregator, payment gateway, bank or financial institution.
3.4.2 The Operator does not collect, store, process or have access to complete payment card numbers, card verification values, card expiry data in combination with full card numbers, magnetic stripe or chip data, internet banking credentials, transaction PINs, or any authentication factor of any payment instrument. The Operator receives only a transaction reference, status, amount, timestamp, method descriptor and, where furnished by the gateway, a masked instrument identifier.
3.4.3 All payment data handling by the relevant payment service provider is governed exclusively by that provider's own terms and privacy policy, over which the Operator exercises no control and for which the Operator bears no liability whatsoever.
3.5 Data We Do Not Want and Must Not Receive
3.5.1 The Platform is not designed, hardened, certified, audited or represented as suitable for data attracting heightened or sectoral regulatory requirements. You must not enter, upload, store or process on the Platform any of the categories listed in Clause 7.4.2 of the Terms & Conditions, including full payment card data, banking credentials, Aadhaar numbers or Aadhaar-related data, biometric data, health or genetic data, data of children or of persons with disabilities having lawful guardians, credit information under the Credit Information Companies (Regulation) Act, 2005, government-classified data, or third-party system credentials.
3.5.2 If You nonetheless enter any such data, You do so entirely at Your own sole, exclusive and unlimited risk and liability. Such entry is a material breach of the Terms & Conditions, creates no enhanced duty of care, warranty, obligation or liability on the Operator's part, and gives rise to no claim against the Operator of any nature whatsoever.
3.6 Children
The Platform is not intended for and must not be used by persons under eighteen (18) years of age. The Operator does not knowingly collect Personal Data of a child or of a person with a disability having a lawful guardian, does not undertake any tracking, behavioural monitoring or targeted advertising directed at children, and will suspend and terminate any Account found to contravene this, without notice, refund or liability.
4. PURPOSES AND LAWFUL BASES
4.1 Purposes
The Operator handles data only for the following purposes:
(a) Account provisioning: creating, authenticating, maintaining, securing and administering Accounts, Workspaces and Modules; (b) Service delivery: hosting, storing, transmitting, arranging, formatting, computing upon, rendering and making available User Content and Output at the User's instruction; (c) Payments and billing: processing Subscription Fees, issuing invoices and receipts, managing renewals, mandates, reversals, chargebacks and dunning, and discharging the Operator's own tax obligations; (d) Support: responding to queries, tickets, grievances, disputes and notices; (e) Service communications: sending transactional, security, billing, administrative, operational and policy notices; (f) Security and integrity: authentication, authorisation, session management, rate limiting, abuse and fraud detection and prevention, intrusion detection, incident response, forensic investigation and audit logging; (g) Reliability: monitoring uptime, diagnosing errors, debugging, capacity planning, performance tuning and backup; (h) Improvement: analysing usage in aggregated and de-identified form to improve, secure and develop the Platform; (i) Legal and regulatory: complying with Applicable Law, responding to lawful requests of any Governmental Authority, maintaining statutory records, and establishing, exercising or defending legal claims and rights, including under Clauses 16 and 18 of the Terms & Conditions; (j) Enforcement: enforcing the Terms & Conditions and any incorporated policy, and preventing and addressing prohibited conduct under Clause 9 of the Terms & Conditions.
4.2 Lawful Bases
Processing is undertaken on the basis of: (a) Your consent, given by acceptance of this Policy and the Terms & Conditions; (b) performance of the contract of Subscription; (c) certain legitimate uses recognised under the Digital Personal Data Protection Act, 2023, including compliance with law, response to lawful orders, and prevention and investigation of offences and fraud; (d) compliance with the Operator's own legal, tax and record-keeping obligations; and (e) establishment, exercise and defence of legal claims.
4.3 What the Operator Does NOT Do
The Operator does not:
(a) sell, rent, lease, trade, barter or monetise Personal Data or User Content to or with any person, under any circumstance; (b) use Personal Data or User Content for behavioural advertising, ad targeting, ad profiling, cross-site tracking, retargeting or advertising exchanges; (c) share Personal Data or User Content with data brokers, advertising networks, marketing agencies or list vendors; (d) use User Content to train, fine-tune, evaluate, benchmark or develop any machine learning model or artificial intelligence system; (e) undertake any solely automated decision-making that produces legal effects concerning You; (f) access User Content for any purpose other than those in Clause 4.1, and in particular does not read, review or analyse User Content save where strictly necessary for support (at Your request), security, incident response, fraud prevention, enforcement, or compliance with a lawful requirement.
4.4 Aggregated and De-identified Data
The Operator may generate, retain and use aggregated, de-identified and anonymised statistical and technical information derived from use of the Platform, from which no individual, User or Data Principal can be identified or re-identified. Such information is not Personal Data, is the Operator's property, and may be used and retained without restriction.
5. DISCLOSURE AND SHARING
5.1 Categories of Recipients
Data is disclosed only to the following, and only to the extent necessary:
(a) Infrastructure and hosting providers, data centres, cloud providers, content delivery networks and network operators; (b) Payment service providers, gateways, aggregators, processors, card networks and banks, for payment processing and dispute handling; (c) Communication providers for transactional e-mail, short message service, push notification and support ticketing; (d) Security, monitoring, logging, error-tracking and backup providers; (e) Professional advisers including chartered accountants, tax practitioners, auditors and advocates, bound by professional confidentiality; (f) Governmental Authorities, law enforcement agencies, courts, tribunals, arbitral authorities and regulators, where required or permitted by Applicable Law, or in response to any summons, subpoena, warrant, notice, order, direction or lawful request; (g) Successors in interest, in connection with any merger, amalgamation, restructuring, conversion of legal form, sale of business or transfer of assets, subject to the recipient being bound by materially equivalent obligations; (h) Any person, where necessary to establish, exercise or defend the Operator's legal rights and claims, to enforce the Terms & Conditions, to prevent or investigate fraud, abuse or a security incident, or to protect the rights, property, safety or security of the Operator, any User or the public.
5.2 Processor Obligations
Where the Operator engages a processor or sub-processor, it does so under contractual arrangements requiring confidentiality, purpose limitation and reasonable security measures. However, the Operator does not warrant, guarantee or assure the security, conduct, continuity, solvency or compliance of any third party, and bears no liability for any act, omission, defect, outage, change, discontinuation, breach, data loss or misuse by any such third party.
5.3 Compelled Disclosure
The Operator may, without notice to You and without liability, preserve, access, review and disclose Account Data, Technical Data, User Content, logs and records to any Governmental Authority, law enforcement agency, court, tribunal or third party where the Operator in good faith considers it necessary or advisable to comply with Applicable Law or any lawful requirement, to enforce the Terms & Conditions, to respond to a claim of infringement or illegality, to prevent or investigate fraud, abuse or a security incident, or to protect any person's rights, property, safety or security. You expressly consent to such disclosure and irrevocably waive every claim arising therefrom. Where Applicable Law permits and it is prudent to do so, the Operator may notify You, but is under no obligation whatsoever to do so.
5.4 Onward Circulation Beyond the Operator's Control
Once any data has left the Operator's systems by any means, including by export, download, print, screenshot, screen recording, photograph, copy, transcription, forwarding, transmission, publication, sharing, sale or leak, whether by You, by any person authorised or permitted by You, by any of Your personnel or former personnel, by any person who obtains access through Your credentials or devices, or by any third party, integration, automation or artificial intelligence agent connected by You, the Operator has no knowledge of, no control over, and no responsibility or liability whatsoever for that data or for any onward circulation, republication, aggregation, indexing, resale or dissemination of it. Clause 15 of the Terms & Conditions applies in full.
6. CROSS-BORDER TRANSFER AND STORAGE
6.1 The Operator's primary infrastructure is intended to be located in India. However, certain service providers described in Clause 5.1 may store, process, replicate, cache or transit data at locations outside India, including at edge locations of content delivery networks and in the regions of cloud, e-mail, monitoring and backup providers.
6.2 By using the Platform, You expressly consent to such storage, processing, transfer and transit within and outside India, on the terms of this Policy, subject only to such restrictions as the Central Government may notify under Section 16 of the Digital Personal Data Protection Act, 2023.
6.3 Where You are the Data Fiduciary in respect of Third-Party Data, You alone are responsible for ensuring that any cross-border transfer arising from Your use of the Platform is permissible under every law applicable to You, including any data localisation, sectoral or contractual restriction. The Operator gives no representation, warranty or assurance whatsoever in that regard, and You shall indemnify the Operator in respect of any consequence.
6.4 Where You access the Platform from outside India, You do so entirely at Your own initiative and risk, and Clause 3.2 and Clause 18.3 of the Terms & Conditions apply, including the exclusive application of Indian law and the exclusive jurisdiction of the courts and tribunals at Chennai.
7. RETENTION
7.1 Data is retained only for so long as is necessary for the purposes in Clause 4.1, or for such longer period as Applicable Law requires or permits, or as is reasonably necessary for the Operator's legal defence, dispute resolution, tax compliance, security, audit, fraud prevention and backup-cycle purposes.
7.2 Indicative retention:
| Category | Retention |
|---|---|
| User Content in an active Account | While the Account is active and the Subscription subsists |
| User Content after expiry, suspension or termination | May be deleted, purged or rendered unrecoverable at any time, with no obligation of grace period, notice, export window, reactivation or restoration |
| Account and identity data | For the life of the Account, and thereafter for such period as is necessary for legal defence, tax and statutory record-keeping |
| Billing, invoice and tax records | For the period prescribed by Indian tax and accounting statutes, and thereafter as necessary for legal defence |
| Security, authentication and audit logs | For such period as the Operator considers necessary for security, forensic and legal purposes |
| Support and correspondence records | For such period as is necessary for support continuity, dispute resolution and legal defence |
| Backups | Until expiry of the applicable backup rotation cycle |
| Aggregated, de-identified data | Indefinitely (not Personal Data) |
7.3 IT IS ENTIRELY AND EXCLUSIVELY YOUR RESPONSIBILITY TO EXPORT, DOWNLOAD AND RETAIN ALL DATA OF IMPORTANCE TO YOU, WELL BEFORE EXPIRY OR TERMINATION, AND TO MAINTAIN YOUR OWN INDEPENDENT, COMPLETE, CURRENT AND SEPARATELY STORED BACKUPS AND RECORDS OUTSIDE THE PLATFORM.
7.4 The Platform is not a backup, archival, disaster-recovery or record-keeping service, and no retention period, preservation, integrity, recoverability or restorability is warranted, guaranteed or assured. The Operator bears no liability whatsoever for any deletion, loss, corruption or unrecoverability of data, and You expressly waive every claim in that regard. Clauses 7.6, 12.3, 13 and 14 of the Terms & Conditions apply in full.
7.5 Deletion from live systems does not guarantee immediate deletion from backups, logs, caches, replicas or archives; such copies expire in the ordinary course of the applicable rotation cycle. Data lawfully required to be retained, or reasonably required for legal defence, may be retained notwithstanding any deletion request.
8. SECURITY
8.1 Measures Maintained
The Operator maintains reasonable technical, organisational and administrative security measures appropriate to the nature, scale and sensitivity of its operations, consistent with the standard of reasonable security practices and procedures contemplated by the Information Technology Act, 2000 and its rules, and with the obligation of reasonable security safeguards under the Digital Personal Data Protection Act, 2023. These include, as applicable and as the Operator considers appropriate from time to time:
(a) encryption of data in transit using current Transport Layer Security, with modern cipher suites and HTTP Strict Transport Security; (b) encryption at rest for stored data and backups, where implemented; (c) storage of passwords only as salted cryptographic hashes using a recognised password-hashing function; plaintext passwords are never stored, logged or recoverable; (d) role-based access control, least-privilege administration and separation of duties; (e) support for multi-factor authentication where offered by the Platform; (f) session management, rotation and expiry, and secure cookie attributes; (g) rate limiting, throttling, brute-force lockout and anomaly detection on authentication endpoints; (h) network segmentation, firewalling and restricted administrative access; (i) logical separation and access scoping of Accounts and Workspaces; (j) audit logging of security-relevant events; (k) timely application of security patches and dependency updates; (l) periodic backups with restoration testing, as the Operator considers appropriate; (m) hardened server configuration, minimised attack surface and removal of unnecessary services; (n) confidentiality obligations on personnel and processors, and vetting of processors.
Specific technical controls evolve continuously. The Operator may add, alter, replace or withdraw any control at any time in its own judgment. Nothing in this Clause 8.1 constitutes a warranty, guarantee, service level or commitment as to any particular control, standard, certification or outcome.
8.2 No Absolute Security: Express Acknowledgement
YOU EXPRESSLY ACKNOWLEDGE, ACCEPT AND AGREE THAT:
(a) no system, network, protocol, cryptographic scheme, control, hosting arrangement, device or human process is or can be made absolutely secure, impenetrable or invulnerable, and that the Operator gives no warranty, guarantee or assurance of absolute security; (b) the internet and all public networks are inherently insecure and transmission over them is at Your own risk; (c) the security of Your own devices, browsers, extensions, operating systems, networks, routers, e-mail accounts, cloud accounts, SIM cards, physical premises and personnel is entirely Your own responsibility, and the Operator has no visibility of, control over, or responsibility for the same; (d) You are solely responsible for the confidentiality of Your credentials and for all activity occurring under Your Account, whether authorised by You or not, in accordance with Clause 4.3 of the Terms & Conditions.
8.3 Exclusion of Liability for Attacks and Exfiltration
THE OPERATOR SHALL BEAR NO LIABILITY WHATSOEVER, AND YOU SHALL HAVE NO CLAIM OF ANY KIND, IN RESPECT OF ANY UNAUTHORISED ACCESS TO, OR ACQUISITION, DISCLOSURE, ALTERATION, DESTRUCTION, EXFILTRATION OR MISUSE OF, ANY DATA ARISING FROM OR IN CONNECTION WITH:
(a) any brute-force, credential-stuffing, dictionary, password-spraying or similar attack on any server, service, account or credential; (b) any hacking, cracking, intrusion, penetration, exploitation of a vulnerability (whether known, unknown, zero-day, or residing in any third-party dependency, library, operating system, hypervisor, firmware or hardware), malware, ransomware, supply-chain compromise, denial-of-service attack, side-channel attack, or any other cyber attack, whether perpetrated by a criminal, an insider, a competitor, an activist, an organised group, or a state or state-sponsored actor; (c) any phishing, vishing, smishing, social engineering, business e-mail compromise, SIM swap, session hijacking, man-in-the-middle attack or interception directed at You or Your personnel; (d) any compromise, loss, theft, sharing, weakness, reuse or negligent handling of credentials by You or by any person to whom You granted access; (e) any compromise, infection, theft, loss or misconfiguration of Your own devices, browsers, extensions, networks, e-mail accounts, cloud accounts, integrations, automations or artificial intelligence agents; (f) any act, omission, breach, outage or failure of any third-party provider described in Clause 5.1; (g) any wilful, deliberate, negligent, inadvertent, unauthorised or mistaken export, download, print, screenshot, screen recording, photograph, copy, transcription, forwarding, transmission, publication, sharing, sale, leak, disclosure or onward circulation of any data, in any form or medium, by You, by any person authorised or permitted by You, by any of Your employees, agents, contractors, consultants, family members or former personnel, by any person obtaining access through Your credentials or devices, or by any third party, integration, automation or artificial intelligence agent connected by You; (h) any downstream republication, aggregation, indexing, resale, scraping, dark-web circulation or other dissemination following any event described in this Clause 8.3; (i) any act of God, Force Majeure Event, government-mandated access, lawful interception or compelled disclosure.
The Operator's responsibility in respect of data security is limited strictly to maintaining reasonable security practices in respect of infrastructure and systems directly and exclusively within the Operator's own operational control, and extends to nothing beyond that.
8.4 Breach Intimation
8.4.1 Where a personal data breach occurs within the Operator's own systems, the Operator shall give such intimation to the Data Protection Board of India, to affected Data Principals, and to such other Governmental Authorities, in such form and within such time, as Applicable Law mandatorily requires.
8.4.2 Where the breach concerns User Content or Third-Party Data, the Operator shall intimate the relevant User (being the Data Fiduciary), and it shall thereafter be that User's sole responsibility to make all onward intimations to Data Principals, to the Data Protection Board of India and to any other Governmental Authority, and to bear all costs of doing so.
8.4.3 The making of any intimation, notification, report or disclosure under this Clause 8.4 is a statutory compliance measure only, and shall never constitute, be construed as, be pleaded as, or be tendered as an admission of fault, negligence, deficiency, deficiency in service, breach or liability on the Operator's part, in any forum, for any purpose.
8.4.4 You shall promptly notify the Operator at [email protected] of any breach, compromise or suspected incident affecting Your Account, shall cooperate fully with the Operator's investigation and remediation at Your own cost, and shall not make any public statement, media disclosure, social media post or third-party communication attributing any incident to the Operator without the Operator's prior written consent, except where mandatorily required by Applicable Law.
8.5 Vulnerability Reports and Prohibition on Testing
8.5.1 Good-faith reports of suspected vulnerabilities are welcome at [email protected].
8.5.2 However, no person is authorised to conduct any security testing, scanning, probing, fuzzing, enumeration or exploitation against the Platform or its infrastructure without the Operator's express prior written authorisation. Unauthorised testing is a prohibited act under Clause 9.2 of the Terms & Conditions and may constitute an offence under the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, 2023, and shall be pursued accordingly.
8.5.3 The Operator operates no bug bounty programme and offers no reward, payment, recognition, immunity, safe harbour or indemnity in respect of any report.
9. YOUR RIGHTS AND HOW TO EXERCISE THEM
9.1 Rights in Respect of Account Data
Subject to Applicable Law, and in respect only of Account Data for which the Operator is the Data Fiduciary, You may:
(a) obtain a summary of the Personal Data being processed and of the processing activities undertaken; (b) obtain the identities of other Data Fiduciaries and Data Processors with whom the Personal Data has been shared, along with a description of the data shared; (c) seek correction, completion, updation or erasure of Personal Data; (d) withdraw consent, with prospective effect, in accordance with Clause 9.4; (e) nominate another individual to exercise Your rights in the event of death or incapacity; (f) have Your grievance redressed through the mechanism in Clause 10.
9.2 Rights in Respect of Third-Party Data: Approach the User, Not the Operator
If You are a person whose data appears within a User's Account (for example, as that User's customer, supplier, vendor or debtor), the Operator is a mere Data Processor in respect of Your data and has no authority, ability or obligation to access, correct, erase or disclose it. You must approach that User, who is the Data Fiduciary, directly. Any request received by the Operator may, without obligation and without acceptance of any responsibility, be forwarded to the relevant User, and the Operator shall thereafter decline further involvement.
9.3 How to Make a Request
9.3.1 Send a request to [email protected] from Your registered e-mail address, stating clearly the right invoked, the particulars sought, and Your Account identifier.
9.3.2 The Operator will verify Your identity before acting. The Operator may refuse or defer any request that: is unverified or made from an unregistered address; is manifestly unfounded, excessive, repetitive, frivolous or vexatious; would prejudice the rights, privacy or data of another person; would compromise security, fraud prevention or an ongoing investigation; would conflict with any Applicable Law, statutory retention requirement or lawful order; would prejudice the establishment, exercise or defence of any legal claim; relates to data for which the Operator is a mere Data Processor; or cannot be actioned without disproportionate effort.
9.3.3 The Operator will respond within the period prescribed by Applicable Law, or where none is prescribed, within a reasonable period.
9.3.4 You shall not make any false or frivolous grievance or request, shall not impersonate any person, and shall furnish only verifiably authentic particulars, in accordance with the duties of a Data Principal under Section 15 of the Digital Personal Data Protection Act, 2023. Breach of these duties may attract the penalty prescribed by that Act, in addition to the consequences under Clause 18.5 of the Terms & Conditions.
9.4 Withdrawal of Consent and Deletion
9.4.1 You may withdraw consent at any time. Withdrawal operates prospectively only and does not affect the lawfulness of any processing already carried out.
9.4.2 Withdrawal of consent, or a request for erasure, will ordinarily render the Platform unusable and will result in the suspension, closure and deletion of Your Account and User Content. Such closure and deletion are a direct and accepted consequence of Your own request.
9.4.3 NO REFUND, CREDIT, PRO-RATA ADJUSTMENT, EXTENSION OR COMPENSATION OF ANY KIND SHALL ARISE ON ACCOUNT OF ANY WITHDRAWAL OF CONSENT, ERASURE REQUEST, ACCOUNT CLOSURE OR CONSEQUENT LOSS OF ACCESS OR DATA. Clause 6 of the Terms & Conditions and the Cancellations & Refund Policy apply in full.
9.4.4 The Operator may retain such data as Applicable Law requires or permits, or as is reasonably necessary for legal defence, tax compliance, security, fraud prevention or backup-cycle expiry, notwithstanding any withdrawal or erasure request.
9.5 Non-Indian Users
Where You access the Platform from outside India, the Operator's obligations are, and shall remain, those arising under Indian law only. The Operator does not hold itself out as complying with, does not submit to, and expressly disclaims the applicability of any foreign data protection regime, including the EU/UK General Data Protection Regulation, the California Consumer Privacy Act as amended, and any other foreign statute, and disclaims the jurisdiction of any foreign data protection authority, regulator, court or consumer forum. Clause 18.3 of the Terms & Conditions applies in full.
10. GRIEVANCE REDRESSAL
10.1 In compliance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Consumer Protection (E-Commerce) Rules, 2020 and the Digital Personal Data Protection Act, 2023, the Operator designates:
Grievance Officer / Nodal Officer / Data Protection Contact Name: Mr. Mohamed Jamnagarwala Designation: Proprietor, Simply Five Studio Address: 22 Josier Street, Nungambakkam, Chennai 600034, Tamil Nadu, India E-mail: [email protected]
10.2 Grievances must be in writing, must identify the complainant and the Account, must set out the grievance with full particulars, and must enclose supporting material. Receipt will be acknowledged and the grievance disposed of within the periods prescribed by Applicable Law.
10.3 Anonymous, incomplete, abusive, repetitive, frivolous, vexatious or unsubstantiated communications may be closed without action.
10.4 Exhaustion of this grievance mechanism, and compliance with Clause 18.1 of the Terms & Conditions (mandatory sixty-day notice of dispute), are conditions precedent to the initiation of any proceeding against the Operator. Clause 18 of the Terms & Conditions, including its arbitration, individual-basis, exclusive Chennai jurisdiction and anti-vexatious-claim provisions, applies in full to every privacy-related dispute.
10.5 Recourse to this mechanism does not suspend, extend or excuse any obligation of the User, and creates no admission or liability on the Operator's part.
11. DISCLAIMERS AND LIMITATION OF LIABILITY
11.1 Nothing in this Policy creates, or shall be construed as creating, any warranty, guarantee, assurance, service level, certification or obligation beyond what is expressly stated herein, nor does anything in this Policy enlarge, qualify, dilute or override any disclaimer, exclusion, limitation, cap, indemnity, time bar or dispute-resolution provision of the Terms & Conditions.
11.2 Clauses 13 (Disclaimer of Warranties), 14 (Exclusion and Limitation of Liability, including the aggregate financial cap and the thirty-day notification and six-month limitation bar), 15 (Security and Attribution of Risk), 16 (Indemnity) and 18 (Dispute Resolution) of the Terms & Conditions apply in full to this Policy and to every claim, grievance, complaint, dispute or proceeding arising out of or relating to privacy, data protection, confidentiality or data security.
11.3 Neither hisaabwala.org nor Simply Five Studio nor its proprietor nor any Protected Person shall bear any responsibility or liability whatsoever for any loss, damage, harm, injury, cost, expense, penalty, claim, risk, prejudice or consequence of any nature, direct or indirect, arising out of or relating to the collection, entry, storage, processing, transfer, disclosure, export, deletion, loss, corruption, unavailability, breach or onward circulation of any data, arising from the use of the Platform by any means and through any medium, including via the web, any browser or browser extension, any desktop or laptop computer, any mobile device, tablet, wearable or smart device, any embedded or Internet-of-Things device, any API or webhook, any automation or script, any artificial intelligence agent, any personal assistant agent, any autonomous agent, or any other means, technology or medium now known or hereafter devised.
11.4 The Operator's liability, if any is nonetheless held to arise notwithstanding the foregoing, is subject in all cases to the aggregate cap in Clause 14.3 of the Terms & Conditions.
12. CHANGES TO THIS POLICY
12.1 The Operator may amend, vary, supplement, restate or replace this Policy at any time, at its sole discretion, by publishing the revised version on the Platform with an updated Effective Date, and, where the change is material, by such additional notice as the Operator considers appropriate.
12.2 Your continued access to or use of the Platform after publication constitutes Your unconditional acceptance of the revised Policy. If You do not accept a revision, You must cease all use immediately and may close Your Account; no refund shall arise on that account.
12.3 It is Your responsibility to review this Policy periodically. The version published on the Platform at any time is the operative version.
13. CONTACT
| Purpose | Contact |
|---|---|
| Privacy, data protection, grievances, support, legal notices | [email protected] |
| Postal address | Simply Five Studio, 22 Josier Street, Nungambakkam, Chennai 600034, Tamil Nadu, India |
| Grievance Officer / Data Protection Contact | Mr. Mohamed Jamnagarwala |
© Simply Five Studio. All rights reserved.
Related documents: Terms & Conditions · Cancellations & Refund Policy · Cookies & Data