Privacy Policy
The legal suite below is published in draft. It has not been reviewed by counsel and no customer has been asked to accept it.
LAZweaver Privacy & Data Protection Policy
Last Updated & Effective Date: 17 September 2026
Document Version: 1.0.0-draft
Status: DRAFT — NOT YET PUBLISHED. Clauses marked [REVIEW: …] need the owner's or a lawyer's confirmation; the list is at the top of `README.md`.
Operating Entity: Alons Advanced Technologies Private Limited ("Alonstech", "Company", "we", "us", or "our")
Product: LAZweaver — a hosted LiDAR and point-cloud processing service
Applicable Legal Framework: Information Technology Act, 2000 (IT Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), which are the presently operative data protection framework; the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (as amended); the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025, which are being brought into force in stages and whose substantive provisions are not yet commenced (see Section 2.3); and the Guidelines for Acquiring and Producing Geospatial Data and Geospatial Data Services (DST, 2021).
1. Commitment to Privacy & Sovereign Data Protection
1.1. Introduction. Alons Advanced Technologies Private Limited ("Alonstech", "we", "our", "us") operates LAZweaver, a service that processes point clouds its customers supply. This Policy explains what personal data we hold, why, for how long, and what a person can require of us.
1.2. Privacy by Design. Privacy on LAZweaver is a property of how the software, the database, the network and the monitoring are built:
- Tenant isolation applied by the database itself, on every query, so that one Organisation's records are never served to another; and object storage separated by per-Organisation prefix.
- A single data plane inside the Republic of India (the
in-mumbai-1cell in AWS Mumbai). - A point cloud is the customer's survey data, and we treat it as the customer's. We do not mine it, sell it, aggregate it, or use it to train any model.
- Operational telemetry designed and checked to contain no personal data and no customer data (Section 4.2).
1.3. Scope. This Policy covers the LAZweaver console in a browser, the HTTP API, the MCP server where a deployment enables it, and the messages the product sends.
2. Regulatory Status: Data Fiduciary & Data Processor Roles
2.1. Alonstech as a Data Fiduciary. Alonstech acts as a Data Fiduciary in respect of the personal data of registered individual users, Organisation account holders and billing administrators. In that capacity we determine the purpose and means of processing for account creation, authentication, subscription billing, statutory tax compliance and customer support.
2.2. Alonstech as a Data Processor. When a Customer Organisation submits point clouds, trajectories, control files or the notes and parameters that go with them, the Customer Organisation is the Data Fiduciary and Alonstech acts strictly as a Data Processor. We process such data solely on that Organisation's instructions and in accordance with the Master Terms of Service.
- A point cloud ordinarily contains no personal data. It can: a scan of an occupied street contains the shapes of people and vehicles, and a cadastral survey may be accompanied by owner attributes the Customer supplies. Where it does, the Customer is the Data Fiduciary for it and is responsible for the lawful basis on which it was acquired.
[REVIEW: whether a Data Processing Agreement should be offered as a standard addendum, which EU and UK business customers will ask for.]
2.3. Commencement Status of the DPDP Act, and What Presently Binds Us. The DPDP Act, 2023 is being brought into force in stages by notification G.S.R. 843(E) dated 13 November 2025. Section 2 (definitions) and the provisions establishing the Data Protection Board are in force. Sections 3 to 17 — the notice and consent requirements, the obligations of a Data Fiduciary, the rights of a Data Principal, and the cross-border transfer provision — are not yet in force, and are expected to commence approximately eighteen months from the publication of that notification. Section 6(9) and Section 27(1)(d) commence approximately one year from that publication. The Digital Personal Data Protection Rules, 2025 follow the same phasing.
- Because Section 44(2) of the Act — which repeals Section 43A of the IT Act — is itself in the eighteen-month tranche, the SPDI Rules, 2011 remain the operative statutory security framework today, and Alonstech complies with them.
- Where this Policy describes a DPDP Act right or obligation, it does so as a description of a scheme Alonstech has chosen to honour voluntarily and ahead of commencement, and to which it will be bound when the relevant provision commences. Nothing here asserts that a provision is in force before it is.
3. Categories of Data Collected
3.1. Account & Identity Data (Fiduciary context):
- Name and display name.
- Verified email address.
- Passwords, stored only as a salted hash computed with the memory-hard Argon2id function using a cryptographically random per-password salt. Passwords are never encrypted and cannot be recovered or read by anyone, including Alonstech.
- Multi-factor authentication (TOTP) secrets and recovery codes, stored encrypted.
- Federated identity claims where you sign in with Google or Microsoft Entra ID: your email address, a unique subject identifier, and where provided a display name.
- API key material, stored only as a hash; a key is displayed once, at creation, and never again.
3.2. Organisation & Billing Data (Fiduciary context):
- Legal entity name and billing address.
- Where the Customer is in India, its Goods and Services Tax Identification Number (GSTIN) and state code; where the Customer is in the European Union or the United Kingdom, its VAT number and the result and timestamp of our validation of it; elsewhere, the tax identifier the jurisdiction requires and the Customer's confirmation that the purchase is for business use.
- Billing contact address, invoices and payment history.
- Payment identifiers and masked payment methods. Full card numbers and banking credentials are never received or stored by Alonstech; they are processed directly by the payment providers named in Section 13.
3.3. Point Clouds, Runs and Artifacts (Processor context):
- The point clouds the Customer submits — LAS, LAZ and COPC files — together with any trajectory, control, classification-override or boundary file supplied with them. These are the Customer's survey data.
- The artifacts a run produced: the classified cloud, cloud-optimised point clouds, tile pyramids, derived surfaces and rasters, contours, packaged deliverables and the run report.
- The run ledger: which Organisation submitted which file, under which parameters, when, how long it took, how many points it processed, what it produced and the SHA-256 checksum of each output. This is the record of work done and is what the meter and the invoice are computed from.
- Parameters, preset choices and notes the Customer supplied with a run.
3.4. Technical & Operational Data:
- Internet Protocol (IP) addresses, used for rate limiting, sign-in lockout protection, the tax and currency defaults described in the Terms, and the record of where a session was opened.
- Browser user-agent and device characteristics.
- Opaque session tokens, stored only as SHA-256 hashes.
- Application and access logs. These carry request paths, status codes and timings; they never carry point geometry, file contents, tokens or tax identifiers.
4. Media Handling & Operational Telemetry
4.1. Point Clouds Are Read, Not Mined. A submitted cloud is read by the engine to do the work the Customer asked for, and for nothing else. It is not indexed for search, not sampled into any aggregate dataset, not used to train, fine-tune or evaluate any machine-learning model, and not made available to any third party. [REVIEW: whether metadata stripping of the kind GISweaver performs on uploaded images is needed here. LAZweaver accepts no images today; if avatars or company logos are added, this Section must be written before that ships.]
4.2. Operational Telemetry. Operational telemetry — system metrics, error reports and performance measurements about the Platform itself — is collected and used to keep the Service reliable, to diagnose faults and to improve performance. It is designed and checked so that it contains no personal data and no customer data: no coordinates, no point geometry, no file names, no tokens, no tax identifiers. If we find telemetry carrying such data we treat it as an incident, remove it and close the cause.
5. Lawful Grounds for Processing
The DPDP Act, 2023 admits two grounds and no others: the consent of the Data Principal under Section 6, and the enumerated "certain legitimate uses" under Section 7. The Act contains no equivalent of a "contractual necessity" or "legitimate interests" ground of the kind found in European law, and Alonstech does not rely on any such ground. Sections 4 to 7 are not yet in force; the scheme below is what Alonstech applies today and what it will be bound by on commencement.
5.1. Consent (Section 6). We obtain free, specific, informed, unconditional and unambiguous consent by clear affirmative action when you register an account. The version of the Terms you accepted, the address at which they were published, the time of acceptance and the IP address it came from are recorded against your account, so that the question "which agreement did this person accept" has an answer. Consent may be withdrawn at any time with the same ease with which it was given; withdrawal does not affect the lawfulness of processing carried out before it, nor our retention of records the law requires us to keep.
5.2. Voluntarily Provided for a Specified Purpose (Section 7(a)). Where you give us personal data for a specified purpose and have not objected to its use for that purpose, we process it for that purpose: authenticating sessions, admitting and scheduling runs, metering what was processed, and answering your support requests.
5.3. Compliance with Law and Judicial Process (Section 7(b), 7(f) and 7(g)). We process personal data where necessary to comply with a law in force in India, with a judgment, decree or order, and with a legal obligation to disclose to the State — including issuing GST tax invoices under the Central Goods and Services Tax Act, 2017, maintaining books of account under the Companies Act, 2013, and responding to court orders and lawful requests under the Information Technology Act, 2000.
5.4. Customer Data. Where Alonstech acts as a Data Processor (Section 2.2), the lawful ground for processing any personal data contained in a Customer's point cloud is a matter for that Customer as Data Fiduciary. Alonstech processes it only on that Customer's instructions.
6. Purposes of Processing
- Running the Service: provisioning Organisations, managing members and roles, admitting runs, and serving artifacts.
- Processing: reading, validating, classifying, modelling, tiling and packaging the point clouds a Customer submits, as that Customer instructed.
- Metering and billing: counting the points processed in a month, computing the tax treatment, and issuing statutory invoices.
- Security and abuse prevention: per-IP and per-account lockout, defence against credential stuffing, and refusal of files that fail verification.
- Communications: verification codes, invitations, password resets, invoices, security notices and the notices this Policy and the Terms require — including notice before a retention period ends.
We send no unsolicited commercial mail and no third-party marketing.
7. Technical & Operational Security Measures
7.1. Cryptographic Controls.
- Passwords are salted and hashed with Argon2id and a cryptographically random per-password salt. They are not encrypted, and no process, key or person can reverse them.
- Session tokens and API keys are stored solely as SHA-256 hashes.
- Application secrets and database credentials are encrypted at rest with a managed key service.
- Browser and API traffic is encrypted in transit with TLS 1.2 or later, preferring TLS 1.3. Browsers are instructed to connect only over HTTPS, to run scripts only from our own origin and from the providers named in Section 13, and never to guess a file's type; our cookies are not sent on requests made from other sites (Section 14).
7.2. Tenant Isolation.
- Every record belonging to an Organisation is protected by rules the database itself applies to every query, whichever part of the Platform issues it; no account the running Platform uses can switch those rules off.
- Before any Organisation's data is touched, the Platform establishes which Organisation the signed-in actor is acting within, and the database then serves only that Organisation's records.
- A request for a record that is absent, malformed or belongs to another Organisation is answered identically, so that neither the record nor its existence is disclosed.
- In object storage, each Organisation's inputs and outputs live under a prefix reachable only by credentials scoped to it.
7.3. Intake Verification. Every upload is verified against a SHA-256 checksum declared before transfer, is identified by its content rather than by its filename, and has its point-cloud structure and georeferencing read and reported before a run may be submitted. No antivirus scanner is installed and uploaded files are not scanned for malware; Section 3.1 of the Terms of Service states that plainly and says what stands in its place.
8. Data Localisation & Cross-Border Transfer
8.1. The India Cell (in-mumbai-1). All point clouds, derived artifacts, account records and billing records are stored and processed exclusively in AWS Mumbai (ap-south-1), within Indian jurisdiction — for Indian and foreign customers alike, because today there is one cell and it is this one. A Customer outside India should know, before it signs, that its data is processed in India. [REVIEW: a European or United Kingdom customer will ask on what basis its personal data is transferred to India. Standard Contractual Clauses or the UK Addendum will be needed as part of a Data Processing Agreement before selling into those markets.]
8.2. Browser Origins & the Edge Boundary. Your browser talks to one host for the console and its API. Global edge networks are confined to authoritative DNS with DNSSEC and to the challenge that protects sign-in and sign-up. No point geometry, no coordinate and no artifact transits a foreign proxy, an overseas cache, an international queue or a non-Indian storage system.
8.3. Cross-Border Transfers.
- Section 16 of the DPDP Act (not yet in force) operates permissively rather than prohibitively: it empowers the Central Government to restrict, by notification, transfer to a country so notified. Alonstech will observe any such restriction. Where another law affords a transfer a higher degree of protection, that law prevails.
- Four operational exceptions are disclosed for completeness, none of which carries point geometry or an artifact: outbound transactional email is dispatched through Cloudflare's email service; inbound correspondence to our published mailboxes is received through Google Workspace; payments from customers outside India are processed by Stripe; and federated sign-in involves Google or Microsoft where the user chooses it. All four are in Section 13.
9. Data Retention
9.1. The Retention Invariant. Payment state never deletes customer data. An Organisation that downgrades, lapses or is frozen keeps sign-in, complete read access and unrestricted download of everything it holds. We run no sweep that deletes or degrades artifacts on a payment event.
9.2. The Plan Retention Period. LAZweaver is a processing service and stores gigabytes per run, so every plan states how long a finished run's outputs are kept. That period is stated before purchase, runs from the completion of the run, and is the period that was in force at that time. Removal at the end of it is a scheduled act with advance notice, never a consequence of payment state, and the Organisation may download or move to a longer-retention plan at any point before the stated day. The run record survives: its identity, parameters, status, events, report, artifact manifest and the SHA-256 checksum of each artifact are kept after the bytes are gone. A checksum of geometry identifies no person. See Section 5.2 of the Terms of Service.
9.3. Statutory & Audit Retention.
- Tax invoices, payment and subscription records: retained for seventy-two (72) months from the due date of furnishing the annual return for the year to which they pertain, as required by Section 36 of the Central Goods and Services Tax Act, 2017, and where an appeal, revision or investigation is pending, until one year after its final disposal, whichever is later.
- Books of account: retained for not less than eight (8) financial years immediately preceding the relevant financial year, as required by Section 128(5) of the Companies Act, 2013.
- Terms acceptances: retained for the life of the account and thereafter for the statutory periods above, because the record of what somebody agreed to is the evidence for every other record.
- Audit trails: append-only by enforcement inside the database, not by convention; they become pseudonymous once the accounts they name are erased.
- Backups age out on their own schedule; an erasure does not reach into a backup, and Alonstech does not represent that it does.
- Where periods differ for a given record, Alonstech retains it for the longer applicable statutory period.
9.4. User-Initiated Deletion & Erasure. When an individual user or Organisation Owner requests permanent deletion, the personal account profile and the data covered by the request are permanently erased within thirty (30) days, subject to the statutory retention above and to the categories the requester is asked to acknowledge before confirming. The procedure is in Section 5.3 of the Terms of Service.
10. Rights of Data Principals
Chapter III of the DPDP Act, 2023 confers the rights below. Sections 11 to 14 are not yet in force (Section 2.3). Alonstech honours them voluntarily and in full from today, and will be bound by them on commencement. Nothing in this Section is a statement that they are presently enforceable against Alonstech as a matter of statute.
10.1. Right to Access Information (Section 11). You may obtain a summary of the personal data being processed about you, the identities of the Data Fiduciaries and Data Processors with whom it has been shared, and any other information the Rules prescribe.
10.2. Right to Correction & Erasure (Section 12). You may require the correction of inaccurate or misleading personal data, the completion of incomplete data, and the updating or erasure of personal data no longer necessary for the purpose for which it was collected.
10.3. Right of Grievance Redressal (Section 13). You may have your grievances redressed by our designated Grievance Officer within the timeframes in Section 15. Section 13(3) requires that redressal be exhausted before a complaint is made to the Data Protection Board of India.
10.4. Right to Nominate (Section 14). You may nominate an individual to exercise your rights in the event of your death or incapacity.
10.5. Exercising Your Rights. Use the account settings in the LAZweaver console, or write to [email protected]. We answer verified requests within the timeframes in Section 15, without undue delay.
11. Children's Personal Data
11.1. 18+ Business Service. LAZweaver is exclusively a professional B2B service. We do not knowingly solicit, collect or process personal data from anyone under the age of eighteen (18).
11.2. No Tracking, No Targeting. Section 9 of the DPDP Act, 2023 prohibits processing likely to cause a detrimental effect on the well-being of a child, and the tracking or behavioural monitoring of children and targeted advertising directed at them. That Section is not yet in force (Section 2.3); we observe it in full today regardless. We engage in no behavioural tracking, no targeted advertising and no harmful processing, whether directed at minors or at anyone else. If we discover that an account has been registered by a minor, we will deactivate it and delete the associated personal data.
12. Personal Data Breach Protocol & Notification
12.1. Response. Alonstech maintains a security incident response plan to detect, contain, mitigate and remediate unauthorised access, accidental loss, disclosure or alteration of personal data.
12.2. Notification. Section 8(6) of the DPDP Act, 2023 and Rule 7 of the DPDP Rules, 2025 prescribe the breach notification regime. Neither is yet in force (Section 2.3). Alonstech undertakes to follow that regime from today, and on a confirmed personal data breach shall:
- Notify each affected Data Principal and each affected Customer Organisation without delay, describing the nature and extent of the breach, the categories of data affected, its likely consequences, the measures taken to mitigate it, and how the Data Principal may protect their interests.
- Notify the Data Protection Board of India without delay with an initial description, and provide the Board with detailed information — the events and circumstances, the measures taken, the findings as to who caused it, and the remedial measures — within seventy-two (72) hours, or such longer period as the Board may allow on written request.
13. Sub-processors & Infrastructure Partners
| Partner / Provider | Purpose | Data it receives | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | The entire LAZweaver data plane: container compute for the control plane and the engine workers, managed PostgreSQL, S3 object storage for point clouds and artifacts, queueing, key management, load balancing, secrets, logging, backup, DNS and the image registry | All point clouds and artifacts, all account and billing records, and all application logs | Mumbai, India (ap-south-1) — the in-mumbai-1 cell |
| Razorpay Software Private Limited | Payment gateway for customer-initiated checkouts by Indian customers (UPI, net banking, NEFT/RTGS, cards) | The payer's name, email address and telephone number, and the order amount. Alonstech neither receives nor stores card numbers or banking credentials | India |
| Stripe, Inc. | Payment gateway for customer-initiated checkouts by customers outside India, and threshold monitoring for indirect-tax registration | The payer's name, email address, billing address and country, the tax identifier where one is given, and the order amount. Alonstech neither receives nor stores card numbers | Global |
| Cloudflare, Inc. | (a) Authoritative DNS with DNSSEC; (b) the Turnstile challenge protecting sign-in and sign-up; (c) the email service that dispatches transactional messages | (a) DNS queries; (b) a challenge token and the client IP address; (c) the recipient address, subject and body of transactional messages such as verification, invitation, password reset, invoice and security notices | Global edge, including India points of presence. No point geometry and no artifact is sent to Cloudflare |
| Google LLC — Sign in with Google | Federated sign-in, where you choose it | An OAuth authorisation code exchange, from which we receive your email address, a unique subject identifier and, where provided, a display name | Global |
| Google LLC — Google Workspace | The mailboxes behind our published support@ and grievance@ addresses |
Whatever you choose to write to us | Global |
| Microsoft Corporation — Entra ID | Federated sign-in with a work or school account, where you choose it | An OpenID Connect authentication, from which we receive your email address and a unique subject identifier | Global |
Alonstech employs no behavioural advertising tracker, no session-replay or surveillance script, no cross-site data aggregator and no third-party analytics service. No content delivery network stands in front of the application.
13.1. Notice of Change. Alonstech will publish an updated version of this table before engaging any new sub-processor that processes personal data, and will notify Organisation Owners by email or a prominent in-app announcement not fewer than thirty (30) days before that engagement takes effect, save where a sub-processor must be replaced urgently to maintain the security or availability of the Service, in which case notice is given as soon as practicable.
13.2. Operational Telemetry. Operational telemetry contains no personal data and no customer data, and is described in Section 4.2. [REVIEW: telemetry is exported to a managed observability backend in the deployment design. If that backend is operated by a third party, it belongs in the table above before publication.]
14. Cookie & Local Storage Policy
14.1. Strictly Necessary Operational Cookies.
LAZweaver sets only strictly necessary cookies. This is the complete list; there are no others. None carries a Domain attribute, so each is scoped to the exact host that set it.
Every cookie below is additionally written with the browser-enforced __Host- prefix wherever the deployment is secure — the cookie your browser stores for lazweaver_session is named __Host-lazweaver_session, and so on. A browser refuses to store a cookie so named if it carries a Domain or is set over an insecure connection, which means no other host can write or overwrite it in your browser. The names are given below without the prefix because that is what identifies each cookie's purpose; the prefix is a security attribute, not a different cookie.
| Cookie | Purpose | Attributes | Lifetime |
|---|---|---|---|
lazweaver_session |
Opaque customer session token. Retained on our servers only as a SHA-256 hash | HttpOnly, Secure, SameSite=Strict, Path=/ |
24 hours by default |
lazweaver_csrf |
Per-session CSRF value, echoed by the application into the X-CSRF-Token header to validate every change. Deliberately readable by the page, which is what makes the double-submit check work |
Secure, SameSite=Strict, Path=/ |
Matches the session |
lazweaver_staff_session |
The same as the first row, for the Alonstech staff console | HttpOnly, Secure, SameSite=Strict, Path=/ |
24 hours by default |
lazweaver_staff_csrf |
The same as the second row, for the staff console | Secure, SameSite=Strict, Path=/ |
Matches the session |
lazweaver_mfa_challenge |
Carries a pending two-factor challenge across the redirect to and from a federated sign-in provider, so the second factor can be resumed. Readable by the page, which has to carry the value into the next step; it is single-use and useless without a code | Secure, SameSite=Strict, Path=/ |
5 minutes |
lazweaver_staff_mfa_challenge |
The same, for the staff console — and HttpOnly, because the staff application never reads it: the requests that spend it are same-origin and the browser attaches it itself |
HttpOnly, Secure, SameSite=Strict, Path=/ |
5 minutes |
lazweaver_signup_completion |
Authority to complete registration after a federated provider has proved an email address for which no account yet exists. Readable by the page for the same reason as the challenge above; it names a row that expires and is spent once | Secure, SameSite=Strict, Path=/ |
15 minutes |
lazweaver_oauth_tx_… |
A family, not a single cookie. Each federated sign-in round trip gets its own, named from a hash of that transaction's own state value, so two sign-in tabs cannot overwrite one another's. It holds a nonce that binds the provider's answer to the browser that started the request. SameSite=Lax because the provider's return is a cross-site top-level navigation, which Strict would withhold the cookie from |
HttpOnly, Secure, SameSite=Lax, Path=/ |
The transaction's own lifetime, ordinarily 10 minutes |
14.2. Browser Local Storage. The LAZweaver console stores nothing in localStorage, sessionStorage or IndexedDB. Everything it needs about your session is the cookie above and what the server answers. [REVIEW: this is true of the console as it stands. If a preference, a draft or a resumable upload is later kept in the browser, this Section must be written in the same change.]
14.3. No Third-Party or Advertising Storage. We set no third-party analytics cookie, no advertising cookie and no cross-site tracking identifier of any kind. You may configure your browser to reject cookies; rejecting lazweaver_session will prevent sign-in.
15. Privacy Contact & Grievance Redressal Mechanism
15.1. Privacy Contact and Grievance Officer. Alonstech has designated a single officer who is both the Grievance Officer required of every intermediary by Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the person able to answer on Alonstech's behalf about the processing of personal data.
- Officer: [name published on the LAZweaver website and in the application]
[REVIEW: the officer's name must be published before this document is published.] - Designation: Privacy Contact and Grievance Officer
- Company Legal Name: Alons Advanced Technologies Private Limited
- Corporate Headquarters: Alons Advanced Technologies Private Limited, No. 4/461, 2nd Floor, Suite No. 1123, Valamkottil Towers, Thrikkakara, Ernakulam, Kochi, Kerala 682021, India (CIN U62099KL2026PTC102744)
- Grievance Email:
[email protected] - Support Email:
[email protected]
Alonstech is not a Significant Data Fiduciary and has not been notified as one. The obligation to appoint a Data Protection Officer under Section 10(2)(a) of the DPDP Act, 2023 applies to Significant Data Fiduciaries; Alonstech has not appointed one and does not describe the officer above as a Data Protection Officer. Should Alonstech be notified as a Significant Data Fiduciary, it will appoint a Data Protection Officer based in India and publish that officer's business contact information here.
15.2. Timelines.
- Acknowledgement of any privacy grievance, consent withdrawal or data enquiry within twenty-four (24) hours.
- Disposal within seven (7) days of receipt, in accordance with Rule 3(2)(a) as amended by G.S.R. 120(E) dated 10 February 2026.
- The mechanism is available to any user of the Platform and to any victim, whether or not that person is a user or a Customer.
15.3. What the DPDP Act Will Require, and When. Sections 6(3), 8(9), 8(10) and 13 of the DPDP Act, 2023 — requiring, respectively, contact details within a consent request, publication of the business contact information of a Data Protection Officer or of a person able to answer on the Data Fiduciary's behalf, an effective grievance redressal mechanism, and the Data Principal's right to it — are not yet in force (Section 2.3). Alonstech has put all four in place voluntarily, ahead of commencement, and will comply with each as a statutory obligation when it commences.
15.4. Escalation to the Data Protection Board of India. Section 13(3) of the DPDP Act requires a Data Principal to exhaust the Data Fiduciary's own grievance redressal before approaching the Board. If you are not satisfied with our response, you may lodge a complaint before the Data Protection Board of India in accordance with the Act, on and from the commencement of the relevant provisions.
16. Policy Updates & Material Modifications
16.1. Periodic Review. We review and update this Policy to reflect technical changes, operational changes, and changes to Indian data protection or geospatial regulation.
16.2. Notice of Changes. On a material change we publish the updated Policy with a revised effective date and notify registered Organisation Owners by email or a prominent in-app announcement at least thirty (30) days before the effective date. Continued use after that date signifies acceptance of the updated Policy.