Privacy Standard

Privacy Policy

This Privacy Policy explains how AVARTANA LABS LLP manages personal and operational data for Avana, including collection, usage, storage, and protection practices.

Product

Avana

Company

AVARTANA LABS LLP

Effective

14 September 2026

Section
01

1. Information We Collect

Avana may collect account details such as full name, business contact information, login credentials, and organization metadata needed for platform access and role-based controls.

We also process operational logistics data entered by users, including shipment records, party details, vehicle information, billing references, and communication metadata generated through normal system usage.

Section
02

2. How We Use Information

Collected information is used to provide, secure, and improve the Avana platform, including user authentication, shipment workflows, invoice processing, reporting, and customer support.

We may also use limited usage metrics for product reliability, fraud prevention, and service optimization, always aligned with legitimate business operations.

Section
03

3. Data Sharing and Disclosure

AVARTANA LABS LLP does not sell personal information. Data may be shared with trusted infrastructure and service providers only to the extent required for hosting, communications, analytics, and security monitoring.

Information may be disclosed when required by applicable law, regulatory authority, or legally binding process.

Section
04

4. Data Security and Retention

We maintain administrative, technical, and procedural safeguards appropriate for a logistics SaaS platform, including controlled access, encrypted transport, and monitored infrastructure.

Data is retained for operational continuity, compliance, and dispute resolution needs, then archived or deleted according to internal retention controls and legal requirements.

Section
05

5. Where Your Data Is Stored

The Avana application and its database run on Oracle Cloud Infrastructure in the Mumbai (India) region. Files you upload — scanned consignment notes, proofs of delivery, and similar documents — are stored in Backblaze B2 object storage in the European Union. Those files are therefore held outside India.

Payments are processed by Razorpay, which stores payment-instrument data on its own systems in India as its regulatory obligations require. AVARTANA LABS LLP does not store card numbers, UPI credentials, or bank credentials at any point.

The Digital Personal Data Protection Act, 2023 permits transfer of personal data outside India except to territories that the Central Government has restricted by notification. The European Union is not restricted at the date of this policy. If that changes, we will relocate the affected storage and update this page.

Section
06

6. Sub-Processors

Oracle Cloud Infrastructure (Mumbai, India) — application hosting and database.

Backblaze B2 (European Union) — object storage for uploaded documents and files.

Razorpay (India) — subscription payments, UPI mandates, and payment records.

We do not sell personal data, and we do not share it with anyone outside this list except where the law compels disclosure.

Section
07

7. Breach Notification

If a personal data breach occurs, we will notify each affected Data Principal and the Data Protection Board of India as required by section 8(6) of the Digital Personal Data Protection Act, 2023.

Notification will describe what happened, the categories of data involved, and the steps we are taking, without waiting for the investigation to conclude.

Section
08

8. Your Rights and How to Exercise Them

You may ask for a copy of the personal data we hold about you, ask us to correct it, ask us to erase it, and withdraw a consent you previously gave. Several of these can be actioned directly: export from Settings → Data Export, and consent from Settings → Privacy.

For anything not available in the product, or to nominate another person to exercise these rights on your behalf, write to our Grievance Officer, Mayank Batra, Co-Founder, at mayank@avartanalabs.com. We acknowledge within 5 business days and aim to resolve within 30 days.

Where we decline a request — for example because a record must be retained to meet a statutory obligation — we will tell you which obligation applies.

Section
09

9. Policy Updates

We may update this policy. Material changes are notified in the product or by email to account administrators before they take effect, and the effective date above always reflects the current version.