Who we are
This policy explains how Arventiq Labs LLP (LLPIN: ADC-3527) (“Arventiq Labs”, “we”), BMS Innovation Centre, Yelahanka, Bengaluru, Karnataka 560119, India, handles personal data collected through arventiqlabs.com, its free security tools, event registration, careers pages and related email. We act as the data fiduciary for this data under the Digital Personal Data Protection Act, 2023 (DPDP Act). Our products (FortifyHub, LMS Platform, Placement Portal, NexusGuard and others) have their own notices, and the institution that contracts with us is usually the data fiduciary for data inside them.
What we collect, and why
- Enquiries (contact form): name, email, phone, organisation, interest and message, to reply and arrange demonstrations.
- Event registration: name, email, phone, organisation, role, city and attendance mode, to register you, send confirmations and run the event. For paid events, payment is handled by Razorpay; we receive the payment status and reference, never your card, UPI PIN or bank details.
- Job and internship applications: name, contact details, education, the links you provide (CV, LinkedIn, portfolio) and your answers, to assess your application and contact you. We also keep a record of your application’s progress (stage changes, interview schedules, our internal notes and ratings, and the emails we send you) and give you an application number so you can check its status or withdraw it on our application tracker.
- Newsletter: your email, only after you confirm the subscription by email. Every message has a one-click unsubscribe.
- Product reviews: name, work email, organisation, role, rating and review. The email is used for verification and is never published; the rest is published only if you consent and we approve the review.
- Security self-assessment: your answers and, if you ask for the report, your name, email and institution.
- Vulnerability reports: what you tell us, and your name and email if you give them.
- Scam reports and disputes: the UPI ID, phone number, link, IP address or email you report, your description, any amount lost and evidence, and optionally your name and email. We never publish who reported or what a report says; we show only counts and categories. Disputes need your name and email so we can reply.
- Free security tools: files and passwords are processed in your browser and never sent to us. Links, IP addresses, domains and email addresses you check are sent to our server only to run the check and are not stored. For password checks, only the first five characters of a SHA-1 hash go to Have I Been Pwned. We count how many times each tool runs (tool name and date only).
- Security and abuse prevention: a one-way hash of your IP address, kept for up to 10 minutes for rate limiting (24 hours for scam reports, to stop duplicate submissions), and the checks performed by Cloudflare Turnstile and Cloudflare’s network.
We rely on your consent, given on each form, and on legitimate uses permitted by the DPDP Act, such as responding to a request you made and preventing fraud and abuse.
Children
Our events and internships are aimed at adults. If you are under 18, a parent or lawful guardian must agree to your registration or application and may be asked to confirm that consent. We do not knowingly track, profile or target advertising at children.
Who we share data with
We do not sell personal data or use advertising trackers. We share data only with service providers that process it on our behalf, under contract:
- Cloudflare (website hosting, database, security and bot protection);
- Resend (sending confirmation and notification emails);
- Razorpay (payments for paid events);
- Google Workspace (our email).
Some of these providers process data outside India. We may also disclose data where the law requires it, for example to a court or a law-enforcement agency acting under a lawful order.
How long we keep it
- Enquiries: up to 24 months after our last contact.
- Event registrations and payment records: up to 8 years where tax and accounting law requires it, otherwise 24 months after the event.
- Applications: up to 12 months after the role closes, unless you ask us to keep it for future roles.
- Newsletter: until you unsubscribe.
- Scam reports: rejected reports 30 days, all others 12 months; disputes 24 months.
- Email delivery logs: 60 days.
Your rights
Under the DPDP Act you can ask for a summary of the personal data we hold about you, ask us to correct, complete or erase it, withdraw consent at any time (this does not affect what was done before), and nominate someone to exercise these rights if you die or become incapable. Email info@arventiqlabs.com with the subject “Privacy request”. We may ask you to confirm your identity. If you are not satisfied with our answer, you can contact our Grievance Officer, and then complain to the Data Protection Board of India.
Security
We protect data with encryption in transit, access controls, rate limits and the measures described in our Trust Centre. If a breach affects your personal data, we will inform you and the Data Protection Board as the law requires.
Cookies and storage
We do not use advertising or analytics cookies. The website uses your browser’s storage to remember page content for faster loading, and administrators’ sign-in uses a secure session cookie. Cloudflare and Razorpay may set cookies needed for security and payment.
Grievance Officer
Grievance Officer: Beerappa Belsakkarge
Email: info@arventiqlabs.com (subject “Grievance”)
Phone: +91 70287 00361 (Monday to Friday, 10:00–18:00 IST)
Address: Arventiq Labs LLP (LLPIN: ADC-3527), BMS Innovation Centre, Yelahanka, Bengaluru, Karnataka 560119, India
We acknowledge grievances within 24 hours and resolve them within 15 days. See Grievance redressal.
Changes
We will post changes here and update the date at the top. If a change materially affects how we use data you gave us, we will tell you by email where we can.