1. Information We Collect
Avana may collect account details such as full name, business contact information, login credentials, and organization metadata needed for platform access and role-based controls.
We also process operational logistics data entered by users, including shipment records, party details, vehicle information, billing references, and communication metadata generated through normal system usage.
2. How We Use Information
Collected information is used to provide, secure, and improve the Avana platform, including user authentication, shipment workflows, invoice processing, reporting, and customer support.
We may also use limited usage metrics for product reliability, fraud prevention, and service optimization, always aligned with legitimate business operations.
3. Data Sharing and Disclosure
AVARTANA LABS LLP does not sell personal information. Data may be shared with trusted infrastructure and service providers only to the extent required for hosting, communications, analytics, and security monitoring.
Information may be disclosed when required by applicable law, regulatory authority, or legally binding process.
4. Data Security and Retention
We maintain administrative, technical, and procedural safeguards appropriate for a logistics SaaS platform, including controlled access, encrypted transport, and monitored infrastructure.
Data is retained for operational continuity, compliance, and dispute resolution needs, then archived or deleted according to internal retention controls and legal requirements.
5. Where Your Data Is Stored
The Avana application and its database run on Oracle Cloud Infrastructure in the Mumbai (India) region. Files you upload — scanned consignment notes, proofs of delivery, and similar documents — are stored in Backblaze B2 object storage in the European Union. Those files are therefore held outside India.
Payments are processed by Razorpay, which stores payment-instrument data on its own systems in India as its regulatory obligations require. AVARTANA LABS LLP does not store card numbers, UPI credentials, or bank credentials at any point.
The Digital Personal Data Protection Act, 2023 permits transfer of personal data outside India except to territories that the Central Government has restricted by notification. The European Union is not restricted at the date of this policy. If that changes, we will relocate the affected storage and update this page.
6. Sub-Processors
Oracle Cloud Infrastructure (Mumbai, India) — application hosting and database.
Backblaze B2 (European Union) — object storage for uploaded documents and files.
Razorpay (India) — subscription payments, UPI mandates, and payment records.
We do not sell personal data, and we do not share it with anyone outside this list except where the law compels disclosure.
7. Breach Notification
If a personal data breach occurs, we will notify each affected Data Principal and the Data Protection Board of India as required by section 8(6) of the Digital Personal Data Protection Act, 2023.
Notification will describe what happened, the categories of data involved, and the steps we are taking, without waiting for the investigation to conclude.
8. Your Rights and How to Exercise Them
You may ask for a copy of the personal data we hold about you, ask us to correct it, ask us to erase it, and withdraw a consent you previously gave. Several of these can be actioned directly: export from Settings → Data Export, and consent from Settings → Privacy.
For anything not available in the product, or to nominate another person to exercise these rights on your behalf, write to our Grievance Officer, Mayank Batra, Co-Founder, at mayank@avartanalabs.com. We acknowledge within 5 business days and aim to resolve within 30 days.
Where we decline a request — for example because a record must be retained to meet a statutory obligation — we will tell you which obligation applies.
9. Policy Updates
We may update this policy. Material changes are notified in the product or by email to account administrators before they take effect, and the effective date above always reflects the current version.