Nabha Privacy Policy
Written to satisfy BOTH the SPDI Rules 2011 (live until 13 May 2027) and the DPDP Act 2023 + Rules 2025 (substantive duties from ~14 May 2027), plus IT Rules 2021 Rule 3(1)(a).
Last updated: 17 August 2026 · Version: v1.0
Who we are. Varalix Digitech Solutions ("Varalix", "we"), H No 589, Shri Laxmi Narasimha Nilaya, Panchakshari Nagar, Hubli, Dharwad, Karnataka 580025, India, operates the Nabha platform (nabha.cloud, app.nabha.cloud, mqtt.nabha.cloud). Contact for anything in this policy: founder@nabha.cloud. Our Grievance Officer (Section 11) is Vrunda Chavate, Founder, Varalix Digitech Solutions, founder@nabha.cloud, H No 589, Shri Laxmi Narasimha Nilaya, Panchakshari Nagar, Hubli, Dharwad, Karnataka 580025, India, founder@nabha.cloud.
1. Two roles — read the one that applies to you
- Your account with us (we are the Data Fiduciary / "body corporate"). When you sign up, log in, subscribe, contact support or visit our website, we decide how your personal data is used. Sections 2–11 apply.
- Data inside your organisation's workspace (we are a Data Processor). Telemetry, device names, dashboards, alarms, and any personal data your organisation puts into Nabha (for example operator names or contact emails) belong to your organisation, which decides why and how it is processed. We process it only on your organisation's instructions under the Data Processing Addendum. If you are an end-user of a customer's workspace and have a privacy question about that data, contact your organisation first; we will assist them.
2. What personal data we collect (itemised)
| Category | Items | Source |
|---|---|---|
| Identity & contact | full name, email address, organisation name, role/designation | you, at signup or invitation |
| Organisation verification & billing | legal entity name, entity type, address, phone, GSTIN or tax ID, key contact — some collected by Paddle at checkout | you / Paddle |
| Credentials | password (stored only as a salted hash), one-time verification codes, MFA secrets, API keys and broker credentials you generate | you / generated |
| Usage & technical | IP address and timestamp at signup and each login, browser/user-agent, device type, pages and features used, API/MQTT client IPs and connection metadata, error logs | automatically |
| Support | the content of your messages to support and our replies | you |
| Marketing preference | whether you opted in to product updates | you (separate, unticked checkbox) |
| Cookies | see the Cookie Policy | your browser |
We do not collect financial account or card details — payment is taken by our reseller Paddle as Merchant of Record under Paddle's privacy policy. We do not knowingly collect data of persons under 18. Passwords and secrets are "sensitive personal data" under the SPDI Rules and are protected accordingly (Section 7).
3. Why we use it (purposes)
- To create and secure your account, authenticate you and your organisation's users, and send transactional emails (verification codes, security alerts, invoices, service notices).
- To provide the Service you subscribed to: workspaces, device onboarding, dashboards, alarms, support.
- To meet legal duties: verifying and keeping subscriber records, retaining logs, responding to lawful requests, tax and accounting.
- To protect the platform: detecting abuse, fraud, credential misuse and security incidents; enforcing our Terms and AUP.
- To improve the Service using aggregated, de-identified usage statistics.
- To send product news only if you opted in; you can unsubscribe in every email or in Settings.
We do not sell personal data, and we do not use it for behavioural advertising.
4. Consent and how to withdraw it
Where processing rests on your consent (creating an account; marketing), you give it by an unticked checkbox at signup, and you may withdraw it as easily as you gave it — in Settings → Privacy or by writing to the contact above. Withdrawing account consent means closing the account; we may then be unable to provide the Service. Withdrawal does not affect processing done before it, or processing we must continue by law (Section 8). A short Consent Notice is shown at signup and is available at published at nabha.cloud/legal when notified.
5. Who we share it with
We share personal data only with sub-processors who help us run the Service, under contracts that bind them to protect it, and only as needed:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud (Google Cloud India / Google LLC) | hosting, databases, storage, logging (region: asia-south1, Mumbai, India) | India |
| Paddle.com Market Ltd | Merchant of Record: checkout, invoicing, tax, refunds | UK / EU / US |
| Resend | transactional email (verification codes, notices) | US |
| Mistral AI | AI-assisted interpretation of device data (see AI Features Addendum; only data your organisation submits for inference; not account data) | France (European Union) |
The current list is maintained at nabha.cloud/legal/sub-processors and we give 30 days' notice of changes. We may also disclose personal data: to comply with law, a court order or a lawful written request from a government agency stating its purpose; to protect rights, safety or the platform; or to a successor of our business (with notice). We do not publish sensitive personal data and require recipients not to disclose it further.
6. International transfers
Our primary hosting is in India. Some sub-processors process data outside India (table above). We transfer personal data outside India only where necessary to perform our contract with you or with your consent, to recipients that provide a comparable level of protection, and subject to any conditions the Government of India may notify under the DPDP Act. If the Government restricts transfers to a country we use, we will stop using that sub-processor for personal data.
7. Security
We apply reasonable security practices proportionate to the data we hold, following a documented information-security programme aligned to ISO/IEC 27001 controls: encryption in transit (TLS) and at rest, salted password hashing, access control and least privilege, audit logging with monitoring and review, tenant isolation, backups, and an incident-response plan. Details: the Security Overview. No system is perfectly secure; keep your credentials confidential and enable multi-factor authentication.
8. How long we keep it (retention schedule)
| Data | Retention | Why |
|---|---|---|
| Account & profile data | while the account is active, then as below | contract |
| Registration information after account cancellation | 180 days minimum | IT Rules 2021, Rule 3(1)(h) |
| Personal data, traffic data and processing logs | at least 1 year from processing | DPDP Rules 2025, Rule 8(3) |
| Subscriber records (validated name, address, contact, signup email/IP/timestamp, service period, IPs used, purpose, ownership pattern) | 5 years after account closure | CERT-In Directions 28 Apr 2022, direction (v) |
| Application, access and security logs | rolling 180 days minimum, kept in India | CERT-In direction (iv) |
| Billing and tax records | 8 years | GST / Income-tax law |
| Support correspondence | 2 years | support quality |
| Marketing consent record | until withdrawn + 1 year | evidence |
When you close your account we deactivate immediately, export on request within 30 days, and delete on schedule — statutory records are retained in a restricted store and then deleted. Customer Data (workspace content) follows the Terms, Section 11.3.
9. Your rights and how to use them
You may access, correct, complete, update or erase your personal data, withdraw consent, nominate another person to exercise your rights if you are unable to, and raise a grievance. Use Settings → Privacy in the app, or email founder@nabha.cloud from your registered email address; to identify you we need your registered email address and organisation name (and your customer ID if you have it). We respond within 30 days for SPDI Rule 5(6) reviews and in any event within the statutory period, and every response will carry the contact details of the person able to answer your questions. Erasure is subject to the retention duties in Section 8. You may also complain to the Data Protection Board of India once its complaint mechanism is operational (published at nabha.cloud/legal when notified).
10. Cookies and analytics
See the Cookie Policy. Strictly necessary cookies (session, security, preferences) need no consent; analytics or marketing cookies are set only if you accept them in the banner, and you can reject or change that at any time.
11. Grievance Officer and contact
In accordance with the SPDI Rules 2011 (Rule 5(9)), the IT Rules 2021 (Rule 3(2)) and the DPDP Rules 2025 (Rule 9), our Grievance Officer is: Vrunda Chavate, Founder, Varalix Digitech Solutions — founder@nabha.cloud — H No 589, Shri Laxmi Narasimha Nilaya, Panchakshari Nagar, Hubli, Dharwad, Karnataka 580025, India — founder@nabha.cloud. We acknowledge within 24 hours and aim to resolve within 7 days, and in any case within one month. Full process: Grievance Redressal page.
12. Changes
We will notify material changes by email or in the app at least 30 days before they take effect, and remind all users of the current policy at least once a year. Earlier versions are available on request.