Legal & Trust
Privacy Policy
Last updated: April 2026
Download PDF1. Who we are
Zoveto Technologies (“Zoveto”, “we”, “us”) provides the Zoveto software platform and related services. This policy describes how we process personal and account-related information when you use our website and services.
For users in India, Zoveto acts as a Data Fiduciary when we determine the purpose and means of processing your personal data in connection with our website, accounts, billing, and service operations. You are the Data Principalfor personal data about you. Where you use Zoveto to process your employees', customers', or other third parties' data, you are generally the Data Fiduciary for that data and Zoveto processes it on your instructions as described in our Data Processing Agreement.
For privacy requests and data rights: privacy@zoveto.com
2. Data we collect
Depending on how you interact with Zoveto, we may process:
- Account data: email address, name, company name, phone number where provided, and credentials (passwords are stored using strong one-way hashing; we never store them in plain text).
- Marketing, demo, and contact data: information submitted through website forms, demo requests, email, phone, WhatsApp, or other business contact channels.
- Usage data: product and website interactions, diagnostic and security logs, approximate device/browser metadata, and session information needed to operate and secure the service.
- Billing and tax data: billing contact details, GST identification where applicable, invoice metadata, and payment references. Card or UPI payment details are handled by our payment service provider; we do not store full card numbers.
- Operational business data you enter: inventory, orders, invoices, and other records you choose to process in the platform (processed on your instructions as part of the service).
- Workforce and customer records submitted by clients: employee role/contact records and customer contact/order records where clients choose to store and process them in Zoveto.
3. Purposes of processing
We use data to:
- Provide, operate, maintain, and secure the Zoveto platform;
- Authenticate users, prevent fraud and abuse, and enforce our terms;
- Bill subscriptions, issue tax-compliant invoices, and meet accounting obligations;
- Improve reliability and performance using aggregated or de-identified analytics where permitted;
- Comply with applicable law and respond to lawful requests.
We do not sell your personal data. We do not use your confidential business records to train third-party AI models unless we have a clear legal basis and, where required, your explicit agreement.
4. Where data is stored
Zoveto hosts production workloads on Amazon Web Services (AWS) infrastructure, with encryption in transit (TLS) and encryption at rest for core data stores. Backup and retention policies are applied in line with our security programme and contractual commitments.
Data may be processed in data centres outside your country of residence when required for infrastructure, resilience, support, or service delivery. We apply appropriate contractual and technical safeguards required by applicable law.
5. Third-party services
We use a limited set of processors and infrastructure providers, including:
- AWS: cloud hosting, storage, networking, and related operational services;
- Payment providers: to collect subscription payments and issue receipts (their privacy notices apply to payment fields they collect directly);
- Analytics: where enabled and only if you consent (e.g. Google Analytics, Microsoft Clarity), to understand aggregated traffic and UX diagnostics on our marketing site.
- Communication providers: transactional email services (including Google Gmail SMTP), for account notifications and service communication.
A current list of material sub-processors is available at /subprocessors. Sub-processor updates are governed by our agreements and applicable law.
7. Retention
We retain information for as long as needed to provide the service, comply with law, resolve disputes, and enforce agreements. After account termination, operational copies are deleted or anonymised according to the schedule below, subject to legal holds and statutory retention.
| Data category | Typical retention period | Notes |
|---|---|---|
| Account profile and credentials | While active, then up to 12 months after closure | Deleted or anonymised unless a longer period is required for support, audit, or legal claims. |
| Billing, invoices, and GST records | Up to 8 years from the relevant financial year | Retained as required under applicable Indian tax, accounting, and company law. |
| Security, access, and audit logs | Up to 24 months | Used for security operations, abuse prevention, and incident investigation. |
| Support and grievance correspondence | Up to 3 years from last contact | Retained to resolve requests and demonstrate compliance with redressal obligations. |
| Marketing-site analytics (consent-based) | Until consent is withdrawn, then up to 30 days | Applies only where optional analytics cookies or similar technologies are enabled with consent. |
| Operational business data you enter | While your subscription is active, then per export and deletion terms | You control business records in the platform; export and deletion timelines follow your plan and our Terms. |
8. Your rights
Depending on your jurisdiction (including GDPR and India's Digital Personal Data Protection Act, 2023), you may have rights to access, correct, update, or delete certain personal data, and to withdraw consent where processing is consent-based. You may also have rights to portability, nomination, grievance redressal, or to object to certain processing.
Consent withdrawal: Where we rely on your consent (for example, optional analytics cookies on our marketing site), you may withdraw consent at any time using Manage cookies on this website or by emailing privacy@zoveto.com. Withdrawal does not affect processing that was lawful before withdrawal, and we may continue processing where another legal basis applies (such as contract performance, legal obligation, or legitimate uses permitted under applicable law).
Nomination: If you are a Data Principal in India, you may nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity. Send the nomination in writing to privacy@zoveto.com with sufficient details for us to verify and record it.
To exercise your rights, contact privacy@zoveto.com. We will verify your request and respond within a reasonable period as required by law, typically within 30 days.
- EU/EEA (GDPR): rights may include access, rectification, erasure, restriction, objection, and portability.
- India (DPDP Act 2023): rights may include access, correction, erasure, grievance redressal, and nomination. See section 9 below for additional India-specific information.
- California (CCPA/CPRA framework): rights may include access, deletion, and choices around data sharing where applicable.
- Other regions: contact privacy@zoveto.com for rights available under applicable local law.
9. India: Digital Personal Data Protection Act, 2023
This section supplements the rest of this policy for individuals whose personal data is processed under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”). It is intended to support transparency and readiness. It does not by itself certify full legal compliance with every DPDP obligation.
Zoveto processes personal data for lawful purposes connected with providing and improving the Service, securing accounts, billing, support, and compliance. We seek consent where required, and otherwise process personal data on permitted grounds under applicable law, including contract necessity and legitimate uses recognised by the DPDP Act.
As a Data Principal in India, you may have the right to:
- obtain information about the personal data we process about you and how it is used;
- seek correction, completion, updating, or erasure of personal data where applicable;
- withdraw consent for consent-based processing, subject to legal and contractual limits;
- nominate another person to exercise your rights in the event of death or incapacity;
- raise a grievance with Zoveto and, where applicable, escalate unresolved concerns through lawful channels.
We implement reasonable technical and organisational measures to protect personal data. If you believe our processing violates applicable law, contact us first at privacy@zoveto.com or through the grievance process in section 10.
10. Grievance officer and redressal
In accordance with India's DPDP Act framework, Zoveto has appointed a Grievance Officer to address Data Principal complaints relating to our processing of personal data.
- Name: Mehta Gourvansh Raina
- Role: Grievance Officer
- Email: privacy@zoveto.com
- Address: Zoveto Technologies, India
To lodge a grievance, email privacy@zoveto.com with your name, contact details, a clear description of the issue, and any supporting information. We will acknowledge receipt within a reasonable time and aim to resolve grievances within thirty (30) days of receipt, unless a longer period is permitted by applicable law or more time is reasonably required because of the complexity of the request.
If your grievance is not resolved to your satisfaction through this process, you may have additional remedies available under applicable law, including escalation to the Data Protection Board of India once operational and as permitted by law.
11. International transfers
Where personal data is transferred outside India or your country, we implement appropriate safeguards (such as contractual clauses and technical measures) consistent with applicable regulations.
12. Children
Zoveto is a business platform not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe we have collected data from a minor, contact us at privacy@zoveto.com.
13. Changes
We may update this Privacy Policy from time to time. Material changes will be communicated as required by law (for example, by email or an in-product notice). Continued use after the effective date constitutes acceptance of the updated policy where permitted.
14. Related policies
15. Contact
Zoveto Technologies
Privacy and data rights: privacy@zoveto.com
Grievance Officer: Mehta Gourvansh Raina — privacy@zoveto.com
Security and compliance requests: security@zoveto.com