Legal

Privacy Policy

How we collect, use, disclose, and protect your personal data.

Last updated: 15 August 2026

This Privacy Policy is drafted to align with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

1. Introduction

Velorabyte ("Velorabyte", "we", "us", "our") operates the website velorabyte.com (the "Website") and provides web development, software, automation, and digital product consulting services (the "Services"). This Privacy Policy explains how we collect, use, disclose, store, and protect personal data of visitors to our Website and clients who engage our Services ("you", "your"), and describes your rights as a Data Principal under the DPDP Act, 2023.

By using the Website or engaging our Services, you consent to the collection and use of your personal data as described in this Policy.

2. Definitions

  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
  • "Data Principal" means the individual to whom the personal data relates (i.e., you).
  • "Data Fiduciary" means Velorabyte, who determines the purpose and means of processing personal data.
  • "Processing" means any operation performed on personal data, including collection, storage, use, sharing, and deletion.
  • "Consent Manager" and other terms have the meaning assigned to them under the DPDP Act, 2023.

3. Personal Data We Collect

We may collect the following categories of personal data:

  • Contact and identity data: name, email address, phone number, company name, and job title submitted via our Contact form or email.
  • Project data: information you share about your business, project requirements, budgets, and timelines when engaging our Services.
  • Technical and usage data: IP address, browser type, device information, pages visited, and referral source, collected automatically via analytics tools (e.g., Vercel Analytics).
  • Cookie data: as described in our Cookie Policy.
  • Communications: records of correspondence if you contact us by email, form, or phone.
  • Recruitment and career data: if you apply for an open position or join our talent pool via our Careers page, we collect your name, email address, phone number, resume or portfolio link, cover note or message, the role and employment type (full-time or freelance) you are applying for or interested in, and application status. This data is submitted voluntarily by you or, in limited cases, referred to us by a third party (such as a referrer) on your behalf.

We do not intentionally collect sensitive personal data (such as financial account details, health data, or biometric data) through the Website unless you voluntarily provide it in the course of a project engagement or job application, in which case it is handled under a separate written agreement or with enhanced safeguards.

4. How and Why We Use Personal Data

We process personal data only for specified, lawful purposes for which you have given consent, or where processing is a "legitimate use" recognized under Section 7 of the DPDP Act (such as responding to a service request you initiated). Purposes include:

  • Responding to enquiries submitted through our Contact form or email.
  • Preparing proposals, quotes, and service agreements.
  • Delivering, managing, and improving our Services.
  • Sending project-related communications and, where you have separately opted in, occasional updates about our work.
  • Evaluating job applications submitted through our Careers page, communicating with candidates about their application, and internal recruitment record-keeping.
  • Notifying talent-pool signups by email when a position matching their stated interest (full-time or freelance) becomes open, and suppressing repeat notifications for positions they have already been notified about.
  • Operating, securing, and improving the Website (analytics, fraud prevention, debugging).
  • Complying with applicable Indian law, accounting, and tax obligations.

We do not sell your personal data to third parties.

Where processing relies on your consent, that consent is free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action (e.g., submitting our Contact form, accepting our cookie banner). You may withdraw consent at any time by emailing privacy@velorabyte.com, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may affect our ability to continue providing Services already agreed with you.

6. Sharing and Disclosure of Personal Data

We do not share personal data with third parties except:

  • With service providers who process data on our behalf strictly to operate the Website and deliver Services (e.g., hosting/infrastructure providers, email-delivery/SMTP providers, analytics providers), under contractual confidentiality obligations.
  • Where required to comply with a legal obligation, court order, or a lawful request from a government or regulatory authority in India.
  • With your explicit consent, for any other purpose.
  • In connection with a merger, acquisition, or sale of business assets, subject to equivalent confidentiality protections.

7. Data Storage, Security, and Retention

We implement reasonable security practices and procedures as required under Section 43A of the IT Act, 2000 and the SPDI Rules, 2011, including access controls, encrypted transmission (HTTPS/TLS), and restricted internal access to personal data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, to comply with legal, accounting, or reporting obligations under Indian law, or until you request erasure (whichever is earlier). Contact form submissions and project enquiry data are typically retained for the duration of any resulting engagement plus a reasonable period thereafter for record-keeping. Job application data is retained for the duration of the hiring process for that role plus a reasonable period thereafter for record-keeping, and talent-pool data is retained until you ask us to delete it or, in the absence of such a request, for a reasonable period while we consider you for future roles.

8. Cross-Border Data Transfer

Some of our service providers (such as hosting and analytics infrastructure) may process data on servers located outside India. Where personal data is transferred outside India, we take reasonable steps to ensure it continues to be protected in line with this Policy and applicable Indian law, consistent with Section 16 of the DPDP Act, 2023, which permits transfer of personal data outside India except to countries specifically restricted by the Central Government.

9. Your Rights as a Data Principal

Under the DPDP Act, 2023, you have the right to:

  • Access a summary of the personal data we hold about you and the processing activities carried out.
  • Correction and updating of inaccurate or incomplete personal data.
  • Erasure of personal data that is no longer necessary for the purpose it was collected, subject to our legal retention obligations.
  • Grievance redressal, by contacting our Grievance Officer (see below) before approaching the Data Protection Board of India.
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
  • Withdraw consent at any time, as described in Section 5 above.

To exercise any of these rights, email privacy@velorabyte.com with your request. We will respond within a reasonable time and in any event within 30 days.

10. Children's Data

Our Website and Services are intended for businesses and professionals. We do not knowingly collect personal data of individuals under the age of 18. If you believe a minor has provided us personal data, contact us and we will delete it, consistent with Section 9 of the DPDP Act, 2023.

11. Cookies

We use cookies and similar technologies as described in our Cookie Policy.

12. Data Breach Notification

In the unlikely event of a personal data breach that is likely to affect you, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act, 2023 and applicable rules.

13. Changes to this Policy

We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page will indicate the most recent revision. Material changes will be highlighted on this page.

14. Governing Law and Grievance Officer

This Policy is governed by the laws of India. For any privacy-related grievance, contact our Grievance Officer using the details in the Grievance Redressal block below, or visit our dedicated Grievance Redressal page.

Grievance Officer / Data Protection Contact

Name
Vivek Gorasiya
Designation
Co-Founder & Grievance Officer
Company
Velorabyte (Unregistered Partnership (company registration in progress), founded and equally owned by Vivek Gorasiya and Denish Dhola)
Registered Address
Surat
Response Time
Grievances acknowledged within 24 to 48 hours and resolved within 30 days, in line with Indian data protection and IT rules.