Mavorra
Legal

Privacy Policy

Last updated: June 2026

1. Who We Are

Mavorra is an AI consulting agency that builds automation solutions for businesses, operated as a sole proprietorship by Bharat Satwani.

Registered Address: 179 Palsikar Colony, Indore, Madhya Pradesh, India, 452001

Under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules, 2025, Mavorra acts as a "Data Fiduciary" — meaning we determine the purpose and means of processing your personal data. This privacy notice is provided in compliance with Section 5 of the DPDP Act and Rule 3 of the DPDP Rules, 2025.

This notice is standalone and must be read independently of any other terms or policies on this website.

2. Personal Data We Collect

We collect the following personal data, itemized by collection method:

When you visit our website (via PostHog): a randomly-generated anonymous identifier stored in a first-party cookie; IP address (used only to derive approximate location); device type, browser type, and operating system; pages visited, session duration, and referral source; on-site interactions such as clicks and navigation, and (where enabled) anonymized session recordings. Purpose: To understand how visitors use our website, identify popular content, and improve the user experience. We do not build a profile of you unless you identify yourself, for example by booking a call.

When you book a discovery call (via Cal.com): Full name, email address, phone number, selected date and time, and any notes or messages you enter in the booking form. Purpose: To schedule and conduct a consultation with you about our AI consulting services.

When you subscribe to our blog newsletter: Email address. Purpose: To send you updates about new blog posts and insights on AI automation.

When you contact us via the contact form: Name, email address, and message content. Purpose: To respond to your inquiry and communicate with you about our services.

3. How We Use Your Data (Lawful Basis)

Under the DPDP Act, we process your personal data on two lawful bases:

Consent (Section 6, DPDP Act): Analytics cookies (PostHog) are only activated after you provide explicit consent through our cookie consent banner. You may withdraw this consent at any time with the same ease with which it was given — by clicking the "Cookie Settings" link in our website footer.

Voluntarily provided data for a specified purpose (Section 7(a), DPDP Act): When you actively fill out a booking form, contact form, or subscribe to our newsletter, you voluntarily provide your data for the specified purpose described at the point of collection. We process this data only for that stated purpose.

We do not process your personal data for any purpose beyond what is disclosed in this notice. We do not sell, rent, or trade your personal data.

4. Third-Party Data Processors

We share your personal data with the following third-party Data Processors who process data on our behalf:

PostHog, Inc. (United States) — processes website analytics data (pageviews, on-site interactions, and optional anonymized session recordings) collected via PostHog. PostHog's privacy policy: https://posthog.com/privacy

Cal.com, Inc. (United States) — processes booking data (name, email, phone, date/time, notes) when you schedule a discovery call. Cal.com's privacy policy: https://cal.com/privacy

Notion Labs, Inc. (United States) — stores contact-form submissions, newsletter sign-ups, and booking details in our CRM. Notion's privacy policy: https://www.notion.so/privacy

Resend (United States) — delivers our transactional emails (inquiry confirmations and notifications). Resend's privacy policy: https://resend.com/legal/privacy-policy

Under Section 8(1) of the DPDP Act, Mavorra remains responsible for the processing of your personal data by these processors, irrespective of any agreement to the contrary.

5. Cross-Border Data Transfers

Your personal data may be transferred to and processed in countries outside India, specifically:

United States: PostHog, Inc. (analytics), Cal.com Inc. (booking), Notion Labs, Inc. (CRM storage), and Resend (email delivery).

Under Section 16 of the DPDP Act, cross-border transfers are permitted by default except to countries specifically restricted by the Central Government. As of June 2026, no countries have been placed on the restricted list. We will update this policy if any restrictions are notified that affect our data transfers.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the specified purpose, subject to a minimum retention period of 1 year as required by Rule 8(3) of the DPDP Rules, 2025 (for detection, investigation, and remediation purposes).

Analytics data (PostHog): Retained according to our PostHog project settings (by default up to 12 months), then automatically deleted.

Booking data (Cal.com): Retained until the consultation is completed and any follow-up is concluded, plus 1 year for the mandatory minimum retention period.

Newsletter subscription (email): Retained until you unsubscribe or withdraw consent, plus 1 year for the mandatory minimum retention period.

Contact form data: Retained until your inquiry is fully resolved, plus 1 year for the mandatory minimum retention period.

After the applicable retention period, your personal data is securely erased.

7. Your Rights as a Data Principal

Under the DPDP Act, you have the following rights:

Right to Access (Section 11): You may request a summary of all personal data we process about you, the identities of all Data Processors and Data Fiduciaries with whom your data has been shared, and a description of the data shared.

Right to Correction (Section 12): You may request correction of inaccurate personal data, completion of incomplete data, and updating of outdated data.

Right to Erasure (Section 12): You may request erasure of your personal data, unless retention is required for the specified purpose or legal compliance.

Right to Grievance Redressal (Section 13): You have the right to register a grievance with our Grievance Officer. We will acknowledge your grievance within 72 hours and resolve it within 90 days.

Right to Nominate (Section 14): You may nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, contact our Grievance Officer at the details provided in Section 11 below.

8. Consent Withdrawal

You may withdraw your consent at any time. The ease of withdrawing consent is comparable to the ease with which it was given, as required by Section 6(4) of the DPDP Act.

For analytics cookies: Click the "Cookie Settings" link in our website footer to modify or withdraw your cookie consent at any time.

For newsletter subscription: Click the "Unsubscribe" link included in every newsletter email, or email privacy@mavorra.in with the subject line "Unsubscribe."

For booking/contact data: Email privacy@mavorra.in requesting erasure of your data.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

9. Security Safeguards

In compliance with Section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules, 2025, we implement the following reasonable security safeguards:

Encryption of data in transit using HTTPS/TLS across the entire website. Access controls based on need-to-know principles for all systems containing personal data. Monitoring and logging of data access events. Regular automated backups to ensure business continuity and data availability. Retention of security logs for a minimum of 1 year as required by Rule 6(e). Contractual provisions with our Data Processors requiring equivalent security safeguards.

10. Data Breach Notification

In the event of a personal data breach, in compliance with Section 8(6) and Rule 7 of the DPDP Rules, 2025:

We will notify affected Data Principals without delay, providing a description of the breach, its likely consequences, the mitigation measures we have taken, and steps you can take to protect yourself.

We will notify the Data Protection Board of India within 72 hours of becoming aware of the breach, with a comprehensive report including the nature and scope of the breach, mitigation measures, and remedial actions.

11. Grievance Officer

In compliance with Section 8(9) and Rule 9 of the DPDP Rules, 2025, the following person is designated to handle your questions, rights requests, and grievances regarding the processing of your personal data:

Name: Bharat Satwani. Designation: Proprietor & Grievance Officer. Email: privacy@mavorra.in. Address: 179 Palsikar Colony, Indore, Madhya Pradesh, India, 452001.

Response timeline: Acknowledgment within 72 hours. Resolution within 90 days of receiving your grievance, as prescribed by Rule 14(3) of the DPDP Rules, 2025.

12. Complaints to the Data Protection Board

If you are not satisfied with our response to your grievance, you have the right to file a complaint with the Data Protection Board of India. Under Section 13(3) of the DPDP Act, you must first exhaust our internal grievance mechanism before approaching the Board.

The Data Protection Board of India can be reached at: https://www.dataprotectionboard.gov.in

13. Children's Data

Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without verifiable parental consent, we will take immediate steps to erase that data in compliance with Section 9 of the DPDP Act.

14. Changes to This Policy

We may update this privacy policy to reflect changes in our data practices, legal requirements, or business operations. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. For existing Data Principals whose data we process based on consent, we will provide notice of material changes through the contact information you have provided.

15. Applicable Law

This privacy policy is governed by the Digital Personal Data Protection Act, 2023, the DPDP Rules, 2025, the Information Technology Act, 2000, and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

We value your privacy

We use cookies to understand how you use our website. Analytics cookies are only activated with your explicit consent.

Read our Cookie Policy