Privacy Policy

Effective Date: May 10, 2025
Last Updated: January 4, 2026

This Privacy Policy governs the collection, use, storage, processing, disclosure, and protection of personal data and sensitive personal data or information by Ayurveda Pulse, a digital informational platform and newsletter service operated as a unit of Nexorma Group, previously known as Nexorma Holdings, a registered Micro, Small and Medium Enterprise under the Udyam Registration system in the State of Uttarakhand, India (hereinafter referred to as “Company”, “we”, “us”, “our”, or “Ayurveda Pulse”). This Privacy Policy applies to all users, visitors, subscribers, contributors, and any other persons who access or interact with our website, newsletter services, digital communications, content submission portals, or any other services provided through our platform (collectively referred to as the “Platform” or “Services”).

By accessing, using, or continuing to use our Platform, you expressly acknowledge that you have read, understood, and agree to be bound by the terms and conditions set forth in this Privacy Policy. If you do not agree with any provision of this Privacy Policy, you must immediately cease all use of our Platform and Services.

1. LEGAL FRAMEWORK AND COMPLIANCE

Ayurveda Pulse operates primarily under the jurisdiction of the Republic of India and is committed to full compliance with all applicable data protection and privacy laws, rules, and regulations. Our data processing activities are governed by and conducted in accordance with the Information Technology Act, 2000 (21 of 2000) and all amendments thereto, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (hereinafter “SPDI Rules 2011”), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and any other applicable provisions under Indian law including but not limited to the Indian Contract Act, 1872, and relevant provisions of the Indian Penal Code, 1860.

Digital Personal Data Protection Framework:

In addition to the above frameworks, we comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules), which represent India’s comprehensive and modern data protection legislation aligned with international best practices. The DPDP Act establishes rights of Data Principals (individuals whose data is processed), obligations of Data Fiduciaries (entities processing personal data), and a regulatory framework overseen by the Data Protection Board of India. Until the DPDP framework is fully operational, we maintain concurrent compliance with both the IT Act 2000/SPDI Rules 2011 framework and the DPDP Act 2023 framework to ensure the highest level of data protection for all users.

Where our Services extend to users residing in the European Union or the European Economic Area, we additionally comply with the General Data Protection Regulation (EU) 2016/679 (hereinafter “GDPR”) and related European data protection legislation. For users in the United States, we adhere to applicable federal and state privacy laws including principles derived from the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), where applicable, and other relevant state privacy frameworks.

In the event of any conflict between the provisions of this Privacy Policy and applicable mandatory legal requirements, the provisions of applicable law shall prevail to the extent of such conflict. This Privacy Policy shall be interpreted and construed in accordance with the laws of India, and all disputes arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts located in Uttarakhand, India, without prejudice to the rights of data subjects under GDPR to bring proceedings in their country of residence.

2. DEFINITIONS AND INTERPRETATION

For the purposes of this Privacy Policy, unless the context otherwise requires, the following terms shall have the meanings ascribed to them herein:

“Personal Data” or “Personal Information” means any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, by reference to such information, including but not limited to name, email address, telephone number, postal address, demographic information, professional credentials, and any other information that permits the identity of such individual to be directly or indirectly inferred.

“Sensitive Personal Data or Information” shall have the meaning ascribed to it under the SPDI Rules 2011 and includes passwords, financial information such as bank account or credit card or debit card or other payment instrument details, physical, physiological and mental health condition, sexual orientation, medical records and history, biometric information, any detail relating to the above as provided to or received by us for processing or storage, and any information received by us that is classified as sensitive personal data or information under applicable law. For the avoidance of doubt, information freely available or accessible in the public domain, or furnished under the Right to Information Act, 2005, or any other law for the time being in force, shall not be regarded as sensitive personal data or information.

“Processing” means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Data Subject” means any identified or identifiable natural person whose personal data is processed by us.

“Contributor” means any individual who submits content, articles, research summaries, case studies, plant reviews, or any other materials for potential publication on the Platform, whether in a voluntary, honorary, or paid capacity.

“Third Party” means any natural or legal person, public authority, agency or body other than the data subject, Ayurveda Pulse, Nexorma Group, and persons who are authorized to process personal data under the direct authority of Ayurveda Pulse or Nexorma Group.

“Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. Under the Digital Personal Data Protection Act, 2023, Ayurveda Pulse operates as a Data Fiduciary.

“Data Principal” means the individual to whom the personal data relates. Under the DPDP Act 2023, you (the user) are the Data Principal with respect to your personal data processed by us.

“Data Processor” means any person who processes personal data on behalf of a Data Fiduciary. Under the DPDP Act 2023, our service providers who process personal data under our instructions operate as Data Processors.

“Data Protection Board” or “Data Protection Board of India” means the regulatory authority established under Section 18 of the Digital Personal Data Protection Act, 2023, responsible for monitoring and enforcing compliance with data protection laws, adjudicating complaints, imposing penalties, and protecting the rights of Data Principals.

“Consent Manager” means an entity registered with the Data Protection Board of India under Section 9 of the DPDP Act 2023 that enables Data Principals to give, manage, review, and withdraw consent for the processing of their personal data.

3. CATEGORIES OF PERSONAL DATA COLLECTED

We collect personal data through various means and for specific purposes related to the operation, security, and improvement of our Platform and Services. The categories of personal data we collect include, but are not limited to, the following:

3.1 Voluntarily Provided Personal Information

When you register for our newsletter, create an account, submit content for publication, apply as a contributor, communicate with us, or otherwise interact with our Platform, you may voluntarily provide us with certain personal information including your full legal name, email address, telephone or mobile number, postal or residential address, professional qualifications and credentials, institutional affiliations, areas of expertise or interest in Ayurveda, biographical information, curriculum vitae or resume, content submissions and related materials, communication preferences, feedback and correspondence with us, and any other information you choose to provide.

3.2 Identity Verification Documents for Contributors

In connection with our contributor verification process, which is implemented to maintain the integrity, credibility, and security of our Platform and to prevent fraud, impersonation, plagiarism, and other forms of misconduct, we may collect certain identity and verification documents from individuals who apply to serve as contributors to our Platform. The collection of such documents is entirely voluntary and occurs only when an individual chooses to apply as a contributor and submits such documents in furtherance of their application.

Such identity verification documents may include, but are not limited to, Aadhaar card issued by the Unique Identification Authority of India, provided in masked format showing only the last four digits in accordance with regulations issued by the Unique Identification Authority of India under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, Permanent Account Number (PAN) card issued by the Income Tax Department of India, passport, voter identity card, driving license, or any other government-issued identity document that is valid under the Prevention of Money Laundering (Maintenance of Records) Rules, 2005, or equivalent legislation. We may also collect recent photographs of the applicant, proof of address in the form of utility bills, bank statements, or other documents prescribed under Know Your Customer (KYC) norms, academic certificates, professional licenses, registration certificates with regulatory or professional bodies, and any other documents reasonably necessary to verify the identity, credentials, and authenticity of the contributor.

All identity verification documents are collected, stored, and processed in strict accordance with applicable laws including the Aadhaar Act, 2016, the Prevention of Money Laundering Act, 2002, regulations issued by the Unique Identification Authority of India, and the SPDI Rules 2011. Aadhaar information, when collected, is collected only in masked format and is not used for authentication purposes except where explicitly permitted by law. The collection of such documents serves the legitimate purpose of verifying contributor identity, preventing unauthorized access to our content management systems, ensuring compliance with intellectual property and copyright laws, maintaining platform security and integrity, and protecting against fraud, impersonation, and other malicious activities.

3.3 Automatically Collected Technical and Usage Data

When you access or use our Platform, we automatically collect certain technical information through various technologies including cookies, web beacons, log files, and similar tracking mechanisms. This automatically collected information may include your Internet Protocol (IP) address and approximate geographic location derived therefrom, device identifiers including Mobile Advertising ID (MAID), International Mobile Equipment Identity (IMEI), or similar persistent identifiers, browser type, version, and language settings, operating system and platform, referring and exit pages and URLs, date and time stamps of access, pages viewed and features used, click-through paths and navigation patterns, search queries entered on the Platform, time spent on pages or sections of the Platform, interaction with content including scroll depth and engagement metrics, connection speed and type, screen resolution and display characteristics, and other diagnostic and usage data that helps us understand how users interact with our Platform and enables us to improve functionality, performance, and user experience.

3.4 Optional Demographic and Preference Information

You may optionally provide demographic and preference information such as your city, state, or country of residence, professional background or occupation, educational qualifications and institutional affiliations, specific areas of interest within Ayurveda or traditional medicine, preferred types of content or topics, communication preferences and frequency, and any other information you voluntarily choose to share with us through profile completion, surveys, feedback forms, or direct communications.

3.5 Information Regarding Children

We do not knowingly collect, solicit, or process personal information from individuals below the age of eighteen (18) years, or below the age of majority in their jurisdiction, without verified parental or legal guardian consent. Our Platform and Services are not directed toward children, and we do not knowingly allow children to register for our services or submit content. If we become aware that we have collected personal information from a child below the age of eighteen years without appropriate parental or legal guardian consent, we shall take immediate steps to delete such information from our systems and databases within a reasonable timeframe not exceeding fifteen (15) days from such discovery, unless retention is required by law. Parents or legal guardians who believe that their child has provided personal information to us without appropriate consent are requested to immediately contact us at the contact information provided in Section 15 of this Privacy Policy, and we shall promptly investigate and take appropriate remedial action.

3.6 Payment and Financial Information

When you purchase paid services from us, including but not limited to professional writing services, ghostwriting services, publication fees, distribution services, editorial consulting, or any other fee-based services offered through our Platform, we collect certain financial and billing information necessary to process payments and maintain transaction records. Such payment and financial information may include:

Your full legal name as it appears on payment instruments or bank records, billing address and contact information including email address and telephone number for invoice delivery and payment communication, transaction details including order identification numbers, service descriptions, amounts charged, dates of transactions, and payment status, payment method information including the type of payment method used (credit card, debit card, bank transfer, digital wallet, or third-party payment processor), and invoice and receipt information generated for accounting and tax compliance purposes.

When you make payments through third-party payment processors including but not limited to Razorpay, PayPal, Stripe, or other authorized payment gateways, payment card information such as card numbers, expiration dates, Card Verification Value (CVV) codes, and cardholder names is collected and processed directly by these third-party payment processors in accordance with Payment Card Industry Data Security Standards (PCI DSS). We do not store complete payment card information on our servers. Our third-party payment processors may share with us limited payment information such as the last four digits of the card number, card type (Visa, Mastercard, etc.), expiration date, and cardholder name for reconciliation, customer service, and record-keeping purposes.

For payments made via direct bank transfer to our designated business bank account, we may collect and retain bank account information including account holder name, bank name, account number (where provided for verification purposes), transaction reference numbers, and Unique Transaction Reference (UTR) numbers or similar identifiers to match and reconcile payments received.

We retain transaction records, invoices, payment receipts, and related financial documentation for accounting purposes, tax compliance under the Income Tax Act, 1961 and Goods and Services Tax Act, 2017, audit requirements, fraud prevention and detection, resolution of payment disputes and chargebacks, and legal compliance with financial record-keeping obligations. Such records are typically retained for a period of seven (7) years from the date of transaction or as otherwise required by applicable law.

Payment and financial information is processed on the legal bases of contractual necessity (to fulfill our payment processing obligations and deliver paid services), legal obligation (to comply with tax laws, accounting standards, and financial regulations), and legitimate interest (to detect and prevent fraud, maintain accurate financial records, and protect against payment disputes). We implement enhanced security measures for the protection of payment and financial information including encryption of data in transit and at rest, restricted access limited to authorized personnel with a legitimate business need, secure storage in compliance with industry standards, and regular security audits and compliance assessments.

Your payment and financial information may be shared with third-party payment processors and financial institutions as necessary to process transactions, with tax authorities and government agencies as required by law, with our accountants and auditors for compliance and financial reporting purposes, and in connection with fraud prevention and chargeback management services. All such sharing is conducted in accordance with applicable data protection laws and contractual safeguards as described in Section 7 of this Privacy Policy.

4. PURPOSES AND LEGAL BASIS FOR PROCESSING

We process personal data collected through our Platform solely for specific, explicit, and legitimate purposes that are necessary for the operation of our Services and the fulfillment of our contractual obligations to users. The purposes for which we process personal data, and the corresponding legal basis under applicable law, are set forth below.

4.1 Service Delivery and Contractual Obligations

We process personal data to deliver our core services including the delivery of newsletter content, editorial updates, research summaries, and other informational communications to subscribers, processing and managing content submissions from contributors, facilitating communication between our editorial team and contributors or users, managing user accounts, preferences, and subscription settings, and responding to inquiries, support requests, and feedback. The legal basis for such processing is contractual necessity, as this processing is necessary for the performance of our contract with you and to provide the services you have requested. Under Indian law, this processing is conducted pursuant to your consent and our legitimate business interests in fulfilling our service obligations.

4.2 Platform Improvement and Analytics

We process technical and usage data to analyze user behavior patterns and preferences, improve the design, functionality, and user experience of our Platform, develop new features, services, and content offerings, conduct statistical analysis and research regarding platform usage, optimize content delivery and personalization, identify and resolve technical issues and performance bottlenecks, and enhance the overall quality and relevance of our services. The legal basis for such processing is our legitimate interest in continuously improving our Platform and providing users with high-quality, relevant content and services. This processing is necessary for the purposes of our legitimate interests in operating and improving our business, and such interests are not overridden by the fundamental rights and freedoms of data subjects.

4.3 Security, Fraud Prevention, and Platform Integrity

We process personal data, including identity verification documents, to verify the identity and credentials of contributors and prevent impersonation, detect, prevent, and investigate fraud, plagiarism, copyright infringement, and other forms of misconduct, maintain the security and integrity of our Platform and systems, protect against unauthorized access, data breaches, and cyber threats, prevent spam, abuse, and malicious activities, enforce our Terms of Service and other policies, and protect the rights, property, and safety of Ayurveda Pulse, our users, and the public. The legal basis for such processing includes our legitimate interest in ensuring platform security and preventing illegal activities, compliance with legal obligations including obligations under the Information Technology Act, 2000 and related rules, and the necessity to protect the vital interests of our users and the public. Under GDPR, such processing is justified under Articles 6(1)(c) (legal obligation), 6(1)(d) (vital interests), and 6(1)(f) (legitimate interests).

4.4 Legal Compliance and Regulatory Obligations

We process personal data to comply with applicable laws, regulations, legal processes, and governmental requests including tax laws, accounting requirements, and corporate regulations, respond to lawful requests from public authorities including law enforcement and regulatory bodies, comply with court orders, subpoenas, summons, and other legal processes, maintain records as required by applicable record-keeping laws and regulations, and fulfill our obligations under data protection laws including responding to data subject rights requests. The legal basis for such processing is compliance with legal obligations to which we are subject under applicable law. Under GDPR, this processing is justified under Article 6(1)(c) (legal obligation).

4.5 Consent-Based Processing

For certain processing activities, particularly those involving sensitive personal data or marketing communications beyond essential service communications, we rely on your explicit, informed, and freely given consent. Such consent-based processing includes sending promotional communications and updates beyond essential service notifications, using certain types of non-essential cookies and tracking technologies, processing special categories of personal data where applicable, and any other processing activities for which we have specifically requested and obtained your consent. You have the right to withdraw your consent at any time by using the unsubscribe mechanism provided in our communications, adjusting your cookie preferences through browser settings, or contacting us directly at the contact information provided in Section 15 of this Privacy Policy. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

5. DATA RETENTION AND DELETION

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, to enforce our agreements, and to protect our legal rights. The specific retention periods vary depending on the category of data and the purpose for which it was collected, and are determined based on legal requirements, operational needs, and the reasonable expectations of users.

Newsletter subscription data including email addresses, subscription preferences, and communication history is retained for the duration of your active subscription and for a period of thirty (30) days following unsubscription, after which such data is permanently deleted unless longer retention is required by applicable law or for the establishment, exercise, or defense of legal claims. Technical and usage data including IP addresses, device identifiers, and analytics information is typically retained for a period of twenty-four (24) months from the date of collection for analytical and service improvement purposes, after which such data is either permanently deleted or rendered anonymous such that it can no longer be attributed to any identified or identifiable individual.

Content submissions and related correspondence including draft articles, submitted materials, and editorial communications are retained for a period of twelve (12) months following rejection or non-publication, or indefinitely in the case of published content, as we retain copyright ownership of all published materials pursuant to our Terms of Service. Identity verification documents submitted by contributors including Aadhaar, PAN, passport, and other identity documents are retained only for the duration of the contributor’s active engagement with our Platform and for a period not exceeding twenty-four (24) months following the cessation of such engagement, after which such documents are securely deleted unless longer retention is mandated by law or required for legal proceedings. Financial records, invoices, and related business documents, where applicable, are retained in accordance with applicable tax laws and accounting regulations, typically for a period of seven (7) years as required under the Companies Act, 2013 and Income Tax Act, 1961.

Records of communications, complaints, and support requests are retained for a period of twelve (12) months from the date of final resolution unless longer retention is necessary for legal compliance or the defense of legal claims. Data processed for security purposes including security logs, incident reports, and investigation records may be retained for longer periods as necessary to maintain platform security, investigate incidents, and comply with legal obligations regarding cybersecurity and data breach notification.

Upon expiration of the applicable retention period, personal data is securely and permanently deleted or rendered anonymous through irreversible anonymization techniques such that it can no longer be attributed to any identified or identifiable individual. Deletion is carried out using industry-standard data sanitization methods including secure erasure, cryptographic erasure, or physical destruction of storage media as appropriate. In cases where complete deletion is not technically feasible or would be disproportionately burdensome, we implement appropriate safeguards including pseudonymization, aggregation, or restricted access controls to minimize privacy risks.

Notwithstanding the foregoing retention periods, we reserve the right to retain personal data for longer periods where such retention is necessary for compliance with legal obligations including statutory retention requirements, court orders, or regulatory directives, the establishment, exercise, or defense of legal claims including litigation, arbitration, or regulatory proceedings, the protection of vital interests including situations where data retention is necessary to prevent harm to individuals or the public, or with the explicit consent of the data subject. Where personal data is retained beyond standard retention periods for such reasons, we implement additional safeguards including restricted access, enhanced security measures, and periodic review of retention necessity.

6. DATA SECURITY MEASURES

We implement comprehensive technical, physical, and organizational security measures designed to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, disclosure, or access. Our security framework is designed in accordance with the reasonable security practices and procedures required under the SPDI Rules 2011 and international standards including ISO/IEC 27001 information security management standards.

Our technical security measures include encryption of personal data both in transit and at rest using industry-standard encryption protocols including Transport Layer Security (TLS) version 1.2 or higher for data transmission and Advanced Encryption Standard (AES) with a minimum key length of 256 bits for data storage, secure server infrastructure hosted in facilities that maintain physical security controls, environmental controls, and redundancy systems to ensure data availability and integrity, regular application of security patches, updates, and vulnerability assessments to address known security vulnerabilities and emerging threats, implementation of firewalls, intrusion detection systems, and intrusion prevention systems to monitor and defend against unauthorized access attempts and malicious activities, secure data backup and disaster recovery procedures to ensure business continuity and data availability in the event of system failures or security incidents, and the use of secure protocols for all data transmissions between users and our servers.

Access to personal data is restricted through strict access controls including role-based access controls limiting data access to employees, contractors, and service providers who have a legitimate business need to access such data for the purposes described in this Privacy Policy, mandatory authentication mechanisms including strong password policies, multi-factor authentication where appropriate, and regular review and revocation of access credentials, logging and monitoring of all access to personal data systems to detect and investigate unauthorized access attempts or anomalous behavior, separation of duties and least privilege principles ensuring that individuals have access only to the data necessary to perform their specific job functions, and mandatory confidentiality and data protection training for all personnel who handle personal data.

Our organizational security measures include written information security policies and procedures governing the collection, use, storage, and disclosure of personal data, appointment of responsible personnel to oversee data protection compliance and information security, regular security awareness training for employees and contractors covering topics including phishing awareness, social engineering, password security, and data handling best practices, incident response plans and procedures to address data breaches, security incidents, and other emergencies in a timely and effective manner, vendor management and due diligence processes ensuring that third-party service providers who process personal data on our behalf maintain appropriate security standards and comply with contractual data protection obligations, and periodic internal audits and compliance assessments to evaluate the effectiveness of security controls and identify areas for improvement.

Physical security measures at our facilities and those of our hosting providers include restricted access to data centers and server rooms through access controls, surveillance, and security personnel, environmental controls including fire suppression systems, climate control, and power backup to protect against physical damage to systems and data, secure disposal procedures for physical media containing personal data including shredding, degaussing, or physical destruction, and visitor management protocols requiring registration, identification, and escort of visitors to sensitive areas.

Notwithstanding the foregoing security measures, we wish to inform you that no method of transmission over the internet or method of electronic storage is absolutely secure, and we cannot guarantee absolute security of personal data. While we strive to use commercially reasonable and legally compliant means to protect personal data, we cannot warrant or guarantee that our security measures will prevent every unauthorized attempt to access, use, or disclose personal data. In the event of a data breach or security incident that poses a risk to the rights and freedoms of data subjects, we shall comply with applicable data breach notification requirements including notification to affected individuals and relevant regulatory authorities within the timeframes prescribed by law, typically within seventy-two (72) hours of becoming aware of the breach in the case of GDPR-covered incidents, and in accordance with the timelines prescribed under the SPDI Rules 2011 and any cyber security incident reporting requirements under Indian law.

7. DISCLOSURE AND SHARING OF PERSONAL DATA

We do not sell, rent, lease, or otherwise commercialize personal data to third parties for their marketing purposes. We disclose personal data to third parties only in the limited circumstances described below, and only where such disclosure is necessary for the purposes set forth in this Privacy Policy and in compliance with applicable data protection laws.

7.1 Service Providers and Processors

We engage trusted third-party service providers, vendors, and contractors (collectively “Service Providers”) to perform certain functions on our behalf and under our instruction. These Service Providers process personal data solely for the purposes of providing services to us and in accordance with our instructions, and are contractually prohibited from using personal data for any other purpose. Categories of Service Providers with whom we may share personal data include email delivery and newsletter distribution platforms that facilitate the delivery of our content to subscribers, cloud hosting and infrastructure providers that provide data storage, server hosting, and computing resources, analytics and performance monitoring services that help us understand platform usage and improve user experience, content delivery networks (CDNs) that enhance the speed and reliability of content delivery, security and fraud prevention services that help us detect and prevent malicious activities, customer support and communication tools that enable us to respond to user inquiries and provide assistance, and payment processors and financial service providers where applicable for processing transactions.

All Service Providers are selected based on their technical capabilities, security practices, and commitment to data protection. We enter into written agreements with Service Providers that include data processing terms requiring them to implement appropriate technical and organizational measures to protect personal data, process personal data only in accordance with our documented instructions, maintain the confidentiality of personal data, notify us promptly of any data breaches or security incidents, cooperate with us in responding to data subject rights requests, and delete or return personal data upon termination of services unless retention is required by law.

7.2 Legal and Regulatory Disclosures

We may disclose personal data to government authorities, law enforcement agencies, regulatory bodies, courts, and other public authorities where such disclosure is required or permitted by law. Circumstances under which we may make such disclosures include compliance with applicable laws, regulations, legal processes, or enforceable governmental requests including tax laws, accounting regulations, and corporate compliance requirements, response to court orders, subpoenas, warrants, summons, discovery requests, or other valid legal processes, investigation and prevention of fraud, illegal activities, security threats, or violations of our Terms of Service or this Privacy Policy, protection of the rights, property, safety, or security of Ayurveda Pulse, our users, or the public, cooperation with law enforcement investigations or regulatory inquiries, and compliance with national security or public interest requirements.

Where legally permissible and not prohibited by court order or applicable law, we will make reasonable efforts to notify affected users of such legal demands for personal data and provide them with an opportunity to object or seek protective orders. We will also make reasonable efforts to limit the scope of disclosure to the minimum necessary to satisfy the legal requirement and to challenge overbroad or legally deficient demands for data disclosure.

7.3 Business Transfers and Corporate Transactions

In the event of a merger, acquisition, consolidation, reorganization, sale of assets, bankruptcy, insolvency, or other corporate transaction involving Ayurveda Pulse or Nexorma Group, personal data held by us may be transferred to the successor entity or acquiring party as part of such transaction. In such circumstances, we shall require the successor entity or acquiring party to honor the commitments made in this Privacy Policy or provide affected users with notice and an opportunity to opt-out of the transfer where legally required. You will be notified via email or prominent notice on our Platform of any change in ownership or uses of your personal data, as well as any choices you may have regarding your personal data.

7.4 Consent-Based Disclosures

We may disclose personal data to third parties where you have provided explicit, informed, and freely given consent to such disclosure. In such cases, we will clearly inform you of the identity of the third party, the purpose of the disclosure, and the categories of personal data to be disclosed, and obtain your affirmative consent before making such disclosure. You may withdraw your consent at any time by contacting us using the contact information provided in Section 15 of this Privacy Policy.

7.5 Aggregated and Anonymized Data

We may disclose aggregated, anonymized, or de-identified data that does not identify any individual person or from which individual persons cannot reasonably be re-identified. Such data may be used for research, analysis, reporting, marketing, or other purposes, and may be shared with third parties including researchers, business partners, advertisers, or the public without restriction. Once data has been properly anonymized or aggregated such that it no longer constitutes personal data, it is no longer subject to the restrictions of this Privacy Policy.

8. INTERNATIONAL DATA TRANSFERS

Ayurveda Pulse operates primarily in India, and our primary data processing operations and data storage facilities are located within the territory of India. However, due to the global nature of the internet and the use of service providers and infrastructure located in various jurisdictions, personal data collected through our Platform may be transferred to, stored in, or processed in countries outside India, including countries that may not provide the same level of data protection as India or your country of residence.

For users located in the European Union or European Economic Area, we acknowledge that transfers of personal data to countries outside the EU/EEA are subject to the requirements of Chapter V of the GDPR. Where we transfer personal data from the EU/EEA to third countries that have not been subject to an adequacy decision by the European Commission under Article 45 of GDPR, we implement appropriate safeguards to ensure adequate protection of such personal data. Such safeguards include the use of Standard Contractual Clauses (also known as Model Clauses) approved by the European Commission pursuant to Article 46(2)(c) of GDPR, reliance on adequacy decisions issued by the European Commission recognizing that certain countries provide an adequate level of data protection, use of Binding Corporate Rules where applicable for intra-group transfers, or other legally recognized transfer mechanisms under GDPR.

For users located in India, we ensure that international transfers of personal data comply with applicable provisions of the Information Technology Act, 2000 and the SPDI Rules 2011. Specifically, where we transfer sensitive personal data or information outside India, we ensure that the recipient country or jurisdiction provides a standard of data protection that is at least equivalent to the level of protection provided under Indian law, or that we implement contractual safeguards requiring the recipient to maintain the same level of data protection that we are required to maintain under Indian law, and we obtain your explicit consent for such international transfers where required by the SPDI Rules 2011.

By using our Platform and providing personal data to us, you acknowledge and consent to the transfer of your personal data to countries outside your jurisdiction as described in this Privacy Policy. We commit to ensuring that all international transfers of personal data are conducted in accordance with applicable data protection laws and that appropriate safeguards are in place to protect your personal data regardless of where it is processed or stored.

9. COOKIES AND TRACKING TECHNOLOGIES

Our Platform uses cookies, web beacons, pixel tags, and similar tracking technologies (collectively “Cookies”) to collect and store information about your use of our Platform, enhance user experience, analyze usage patterns, and deliver personalized content and communications. This section explains what Cookies are, how we use them, and how you can manage your Cookie preferences.

9.1 Types of Cookies We Use

We use the following categories of Cookies on our Platform:

Strictly Necessary Cookies are essential for the operation of our Platform and enable core functionality such as user authentication, session management, security features, and load balancing. These Cookies are necessary to provide services that you have requested and cannot be disabled without severely affecting the functionality of the Platform. No personal data is processed through strictly necessary Cookies beyond what is essential for their operation.

Performance and Analytics Cookies collect information about how you use our Platform, including which pages you visit most often, how long you spend on each page, which links you click, whether you experience any errors, and similar usage patterns. These Cookies help us understand user behavior, identify areas for improvement, measure the effectiveness of our content, and optimize the performance and user experience of our Platform. The information collected through these Cookies is aggregated and analyzed in a way that does not directly identify individual users, although IP addresses and device identifiers may be collected as part of this process.

Functional Cookies enable our Platform to remember choices you make such as your language preferences, display settings, content preferences, and other customization options, and to provide enhanced and personalized features. These Cookies help us tailor the Platform to your preferences and improve your user experience by remembering your selections and settings across sessions.

Targeting and Advertising Cookies may be used to deliver content and communications that are relevant to your interests and to measure the effectiveness of our newsletters and content distribution. While we do not currently serve third-party advertisements on our Platform, we may use these Cookies to understand which content topics are most engaging to our users and to deliver personalized content recommendations. These Cookies may track your activity across different websites and build a profile of your interests.

9.2 Third-Party Cookies and Services

In addition to Cookies placed by us directly (first-party Cookies), our Platform may also use Cookies placed by third-party service providers to provide analytics, performance monitoring, and other services. Such third-party Cookies are governed by the privacy policies of the respective third parties, and we do not have control over how these third parties use Cookies or the information collected through their Cookies. Third-party service providers whose Cookies may be present on our Platform include Google Analytics for website analytics and usage tracking, email service providers for tracking email open rates and click-through rates, content delivery networks for performance optimization, and other service providers necessary for Platform operation and improvement.

We select third-party service providers based on their privacy practices and data protection commitments. However, we encourage you to review the privacy policies of these third parties to understand how they collect, use, and protect your information. Links to the privacy policies of major third-party service providers are available upon request.

9.3 Cookie Consent and Management

Upon your first visit to our Platform, where required by applicable law including GDPR and the Indian Information Technology Act, we will present you with a Cookie consent notice or banner that provides information about our use of Cookies and allows you to consent to or decline the use of non-essential Cookies. Your consent preferences are stored locally on your device and will be respected during your use of the Platform.

You can manage your Cookie preferences at any time through your web browser settings. Most web browsers allow you to view, manage, and delete Cookies that have been set, block Cookies from specific websites or all websites, receive notifications when Cookies are being set, and set your browser to automatically delete Cookies when you close your browser. The method for managing Cookies varies depending on your browser. You can typically find Cookie management options in the “Settings,” “Preferences,” “Privacy,” or “Security” section of your browser. Please note that if you choose to disable or block Cookies, particularly strictly necessary Cookies, certain features and functionality of our Platform may not work properly, and your user experience may be degraded.

In addition to browser-based Cookie controls, you may opt out of certain third-party analytics and tracking services by visiting the opt-out pages provided by those services. For example, you can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on available at https://tools.google.com/dlpage/gaoptout.

By continuing to use our Platform after being presented with Cookie information and without adjusting your browser settings to disable Cookies, you consent to our use of Cookies as described in this Privacy Policy.

9.4 Do Not Track Signals

Some web browsers include a “Do Not Track” (DNT) feature that signals to websites that users do not want their online activities tracked. Currently, there is no universally accepted standard for how websites should respond to DNT signals. At this time, our Platform does not respond to DNT signals from web browsers. However, you can use the browser-based Cookie management options described above to limit tracking on our Platform.

10. DATA SUBJECT RIGHTS

We respect your rights regarding your personal data and are committed to facilitating the exercise of these rights in accordance with applicable data protection laws. Depending on your jurisdiction and the applicable legal framework, you may have some or all of the following rights concerning your personal data processed by us.

10.1 Right of Access

You have the right to obtain confirmation from us as to whether or not personal data concerning you is being processed, and where such processing is taking place, to access that personal data along with certain information about the processing including the purposes of processing, categories of personal data concerned, recipients or categories of recipients to whom personal data has been or will be disclosed, the envisaged retention period or criteria for determining retention, and the source of personal data if not collected directly from you. Under GDPR Article 15, you are entitled to receive a copy of your personal data undergoing processing free of charge, with reasonable fees applicable for additional copies. Under the SPDI Rules 2011, you have the right to obtain information regarding personal data or sensitive personal data held by us.

10.2 Right to Rectification and Correction

You have the right to obtain from us the rectification of inaccurate personal data concerning you without undue delay. You also have the right to have incomplete personal data completed, including by providing a supplementary statement. Under GDPR Article 16 and the SPDI Rules 2011, you may request correction of any inaccurate or misleading personal data held by us, and we shall correct such data within a reasonable timeframe, typically within thirty (30) days of receiving a valid request unless a longer period is permitted by law.

10.3 Right to Erasure (Right to be Forgotten)

Under certain circumstances prescribed by law, you have the right to obtain from us the erasure of personal data concerning you. Under GDPR Article 17, such circumstances include where personal data is no longer necessary in relation to the purposes for which it was collected or processed, where you withdraw consent on which processing is based and there is no other legal ground for processing, where you object to processing under Article 21 and there are no overriding legitimate grounds for processing, where personal data has been unlawfully processed, or where erasure is required to comply with a legal obligation under EU or Member State law. Under the SPDI Rules 2011, you may withdraw consent to the use of your sensitive personal data or information, in which case we shall cease to use or disclose such data, subject to our legal obligations and legitimate interests in retaining certain records.

The right to erasure is not absolute and may be subject to limitations where retention is necessary for compliance with legal obligations, for the establishment, exercise, or defense of legal claims, for archiving purposes in the public interest, or for other legitimate purposes prescribed by law. Where we are unable to fully erase your personal data due to legal or technical constraints, we shall inform you of the reasons and implement appropriate safeguards to restrict processing of such data.

10.4 Right to Restriction of Processing

You have the right to obtain restriction of processing of your personal data in certain circumstances including where you contest the accuracy of personal data for a period enabling us to verify its accuracy, where processing is unlawful and you oppose erasure and request restriction instead, where we no longer need the personal data for processing purposes but you require it for the establishment, exercise, or defense of legal claims, or where you have objected to processing pending verification of whether our legitimate grounds override your interests. Where processing has been restricted, we shall store such personal data but shall not process it further except with your consent, for the establishment, exercise, or defense of legal claims, for the protection of the rights of another person, or for reasons of important public interest.

10.5 Right to Data Portability

Under GDPR Article 20, where processing is based on consent or contract and is carried out by automated means, you have the right to receive personal data concerning you in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us. You may also request that we transmit your personal data directly to another controller where technically feasible. This right applies only to personal data you have provided to us and does not adversely affect the rights and freedoms of others.

10.6 Right to Object

You have the right to object to processing of your personal data on grounds relating to your particular situation where such processing is based on legitimate interests pursuant to GDPR Article 6(1)(f) or is conducted for direct marketing purposes. Upon receipt of an objection, we shall cease processing personal data unless we can demonstrate compelling legitimate grounds for processing that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defense of legal claims. Where you object to processing for direct marketing purposes, we shall cease such processing without exception.

10.7 Right to Withdraw Consent

Where processing of personal data is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. You may withdraw consent by using unsubscribe links in communications, adjusting cookie settings, contacting us using the contact information in Section 15, or through any other method clearly indicated at the point of consent collection.

10.8 Right to Lodge Complaints

You have the right to lodge a complaint with a supervisory authority regarding our processing of your personal data. For users in the European Union, you may lodge a complaint with the supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. A list of EU Data Protection Authorities is available at https://edpb.europa.eu/about-edpb/board/members_en. For users in India, you may lodge complaints with the Ministry of Electronics and Information Technology, Government of India, or such other regulatory authority as may be designated under applicable data protection legislation. You may also have the right to seek judicial remedies in courts of competent jurisdiction.

10.9 Exercising Your Rights

To exercise any of the rights described above, please submit a written request to us using the contact information provided in Section 15 of this Privacy Policy. Your request must include sufficient information to enable us to verify your identity including your name, email address used for registration or subscription, and any other identifying information reasonably necessary to confirm that you are the person to whom the personal data relates. We may request additional information or documentation to verify your identity before processing your request, particularly for requests involving sensitive operations such as erasure or access to sensitive personal data.

We shall respond to valid requests without undue delay and in any event within the timeframes prescribed by applicable law. Under GDPR, we shall respond within one month of receipt of the request, which may be extended by two additional months where necessary considering the complexity and number of requests, in which case we shall inform you of the extension and reasons therefor. Under Indian law, we shall respond within a reasonable timeframe, typically not exceeding thirty (30) days unless a longer period is permitted by law or necessitated by the complexity of the request. We shall not charge a fee for processing requests unless they are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or refuse to act on the request.

Where we refuse to act on a request, we shall inform you of the reasons for refusal and of your right to lodge a complaint with a supervisory authority and to seek judicial remedy. You may designate an authorized agent to submit requests on your behalf, provided that such agent provides proof of authorization satisfactory to us.

11. DATA BREACH NOTIFICATION

We maintain incident response procedures designed to promptly detect, investigate, and respond to data breaches and security incidents that may compromise the confidentiality, integrity, or availability of personal data. In the event of a data breach involving personal data, we shall comply with all applicable data breach notification requirements under the Digital Personal Data Protection Act, 2023, DPDP Rules 2025, Information Technology Act, 2000, the SPDI Rules 2011, GDPR (where applicable), and any other applicable laws.

11.1 Reporting to Data Protection Board of India

In compliance with the Digital Personal Data Protection Act, 2023 and DPDP Rules 2025, we shall report ALL personal data breaches to the Data Protection Board of India, irrespective of the gravity, nature, or damage caused by the breach. This mandatory reporting obligation applies to all breaches involving personal data processed by us, regardless of the number of data principals affected or the severity of consequences.

Breach notifications to the Data Protection Board shall be made:

  • In the format and manner prescribed under the DPDP Rules 2025
  • Within the timeframes specified by the Data Protection Board
  • With complete information regarding the nature, scope, and circumstances of the breach

11.2 Notification to Data Principals (Affected Individuals)

In addition to reporting to the Data Protection Board, where a personal data breach is likely to result in risk to the rights and freedoms of Data Principals (affected individuals), we shall notify affected individuals without undue delay. The notification shall:

  • Describe the nature of the breach in clear and plain language
  • Specify the categories of personal data affected
  • Explain the likely consequences of the breach
  • Detail the measures taken or proposed to address the breach and mitigate its adverse effects
  • Provide contact information for our Data Protection Officer or Grievance Officer for further inquiries

Notification to Data Principals may be omitted only where:

  • We have implemented appropriate technical and organizational protection measures (such as encryption) rendering personal data unintelligible to unauthorized persons
  • We have taken subsequent measures ensuring that the risk to data principals is no longer likely to materialize
  • Notification would involve disproportionate effort, in which case we shall make a public communication or take similar measures to inform affected individuals

11.3 GDPR Compliance for EU/EEA Users

For users in the European Union or European Economic Area, we additionally comply with GDPR breach notification requirements:

Under GDPR Article 33, where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, we shall notify the relevant EU supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after having become aware of the breach. Where notification cannot be made within seventy-two hours, we shall provide reasons for the delay.

Under GDPR Article 34, where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, we shall communicate the breach to affected data subjects without undue delay.

11.4 CERT-In Reporting (India)

Under the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013, we shall report cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) and other designated authorities within the prescribed timeframes and in the prescribed format.

11.5 Penalties for Non-Compliance

Under the Digital Personal Data Protection Act, 2023, failure to:

  • Report data breaches to the Data Protection Board
  • Implement adequate security measures
  • Notify affected data principals where required
  • Take reasonable security safeguards

May result in penalties determined by the Data Protection Board based on factors including the gravity of the breach, nature of personal data affected, repetitive nature of non-compliance, and other circumstances. Penalties under the DPDP Act 2023 can extend up to INR 250 crores as prescribed under the Act.

11.6 Our Breach Response Procedures

Our breach notification procedures include:

  • Immediate containment and investigation of security incidents
  • Assessment of the scope, severity, and impact of the breach
  • Identification of affected individuals and categories of personal data
  • Determination of notification obligations under applicable laws
  • Preparation and delivery of notifications to the Data Protection Board, supervisory authorities, and affected individuals
  • Implementation of remedial measures to prevent recurrence
  • Documentation of the breach and response actions for compliance and audit purposes

We encourage users who suspect unauthorized access to their accounts or become aware of potential security vulnerabilities to immediately notify us at [email protected] with the subject line “Security Incident” so that we may promptly investigate and take appropriate action.

12. CHILDREN’S PRIVACY PROTECTION

Ayurveda Pulse is not directed to, intended for, or designed to attract children below the age of eighteen (18) years. We do not knowingly collect, use, or disclose personal information from children below the age of eighteen years without verified parental or legal guardian consent. Our Platform, Services, and content are intended solely for adults, healthcare professionals, students of Ayurveda, and other individuals who have reached the age of majority in their jurisdiction.

In accordance with the requirements of the SPDI Rules 2011, the Children’s Online Privacy Protection Act (COPPA) where applicable, and GDPR provisions regarding consent for children, we implement age verification mechanisms and parental consent procedures where we have actual knowledge that a user may be below the age of eighteen years. If we become aware that we have collected personal information from a child below the age of eighteen years without appropriate parental or legal guardian consent, we shall take immediate steps to delete such information from our systems and databases within fifteen (15) days of such discovery, unless retention is required by law.

Parents or legal guardians who believe that their child has provided personal information to us without appropriate consent, or who wish to review, modify, or request deletion of their child’s personal information, should immediately contact us using the contact information provided in Section 15 of this Privacy Policy. Upon receipt of such notification or request, we shall verify the identity of the parent or legal guardian, investigate the circumstances, and take appropriate action including deletion of the child’s personal information, cessation of communications with the child, and implementation of enhanced safeguards to prevent future unauthorized collection.

We encourage parents and legal guardians to monitor and supervise their children’s online activities, educate children about safe internet practices, utilize parental control tools and software, review the privacy policies of websites and services used by their children, and discuss with children the importance of not sharing personal information online without parental permission.

13. LINKS TO THIRD-PARTY WEBSITES AND SERVICES

Our Platform may contain links, references, or integrations with third-party websites, services, applications, or resources that are not owned, operated, or controlled by Ayurveda Pulse or Nexorma Group (collectively “Third-Party Sites”). These links are provided for your convenience and information only and do not constitute an endorsement, recommendation, or approval by us of the content, products, services, policies, or practices of such Third-Party Sites.

We have no control over and assume no responsibility for the content, privacy policies, terms of use, security practices, or other practices of any Third-Party Sites. We do not monitor, verify, or guarantee the accuracy, completeness, legality, or quality of information, content, or services provided by Third-Party Sites. When you access Third-Party Sites through links on our Platform, you do so at your own risk and subject to the terms and conditions and privacy policies of those Third-Party Sites.

Third-Party Sites may collect personal information from you, use cookies and tracking technologies, and process your data according to their own privacy policies and practices, which may differ substantially from this Privacy Policy. We strongly encourage you to read the privacy policies, terms of service, and other policies of any Third-Party Sites before providing personal information or engaging with their services. We shall not be liable for any loss, damage, or harm arising from your use of Third-Party Sites or your disclosure of personal information to such sites.

Where our Platform integrates with third-party services such as social media platforms, analytics services, or content distribution networks, your interactions with such integrated services may be governed by the privacy policies and terms of service of those third parties. We encourage you to review the relevant policies before using integrated features.

If you provide personal information to a Third-Party Site accessed through our Platform, that information is provided directly to the third party and is subject to that third party’s privacy policy, not this Privacy Policy. We shall not be responsible for the privacy practices of Third-Party Sites or for any consequences arising from your disclosure of personal information to such sites.

14. AMENDMENTS AND UPDATES TO THIS PRIVACY POLICY

We reserve the right to modify, amend, update, or replace this Privacy Policy at any time and from time to time at our sole discretion to reflect changes in our business practices, Services, legal or regulatory requirements, technological developments, or other operational, commercial, or legal reasons. Any changes to this Privacy Policy will become effective immediately upon posting the revised Privacy Policy on our Platform with a new “Last Updated” date, unless otherwise specified in the notice of changes.

Where we make material changes to this Privacy Policy that significantly affect your rights or how we process your personal data, we shall provide prominent notice of such changes through one or more of the following methods: email notification to the email address associated with your account or subscription, prominent banner or notice on our Platform homepage, in-app notification if you use any mobile applications we may offer, or such other method as we determine to be appropriate based on the significance of the changes and applicable legal requirements.

Under GDPR and other applicable data protection laws, where material changes to this Privacy Policy require renewed consent for certain processing activities, we shall obtain such consent before continuing to process your personal data for those purposes. If you do not agree to the revised Privacy Policy, you may discontinue using our Services, unsubscribe from our newsletter, and request deletion of your personal data in accordance with Section 10 of this Privacy Policy.

Your continued use of our Platform or Services after the effective date of any changes to this Privacy Policy constitutes your acknowledgment of the changes and your consent to be bound by the revised Privacy Policy. If you do not agree with any changes to this Privacy Policy, you must immediately cease using our Platform and Services. We recommend that you periodically review this Privacy Policy to stay informed about how we collect, use, and protect your personal data and to understand your rights and obligations.

Previous versions of this Privacy Policy may be retained in our archives for record-keeping purposes and may be made available upon reasonable request for users who wish to review historical versions and understand how our privacy practices have evolved over time.

15. CONTACT INFORMATION AND GRIEVANCE REDRESSAL

We are committed to addressing your questions, concerns, and complaints regarding this Privacy Policy, our data processing practices, or the exercise of your data subject rights in a prompt, transparent, and effective manner. If you have any questions, concerns, or requests related to this Privacy Policy or our processing of your personal data, please contact us using the contact information below.

Ayurveda Pulse
A Unit of Nexorma Group
Registered under Udyam (MSME), Uttarakhand, India

General Inquiries:
Email: [email protected]

Privacy and Data Protection Matters:
Email: [email protected]

Billing and Payment Inquiries:
Email: [email protected]

Grievance Officer (India):
In accordance with the Information Technology Act, 2000 and the SPDI Rules 2011, we have designated a Grievance Officer to address complaints and concerns regarding data protection and privacy matters. Indian residents may contact our Grievance Officer at:

Email: [email protected]
Subject Line: “Grievance – Data Protection Complaint”

Our Grievance Officer shall acknowledge complaints within forty-eight (48) hours of receipt and shall resolve complaints within one month from the date of receipt, or within such other timeframe as may be reasonable considering the nature and complexity of the complaint. If you are not satisfied with the resolution provided by our Grievance Officer, you may escalate the matter to the relevant regulatory authorities including the Ministry of Electronics and Information Technology, Government of India.

Data Protection Officer (EU/GDPR):
For users in the European Union or European Economic Area, or for matters specifically related to GDPR compliance, you may contact our Data Protection Officer at:

Email: [email protected]
Subject Line: “GDPR – Data Protection Inquiry”

Data Subject Rights Requests:
To exercise your rights under Section 10 of this Privacy Policy including rights of access, rectification, erasure, restriction, portability, or objection, please submit a written request to [email protected] with the subject line “Data Subject Rights Request” and include sufficient information to verify your identity and specify the right you wish to exercise.

Security and Breach Notifications:
If you become aware of any security vulnerability, unauthorized access to your account, or potential data breach, please immediately notify us at [email protected] with the subject line “Security Incident” so that we may promptly investigate and take appropriate action.

When contacting us regarding privacy matters, please provide sufficient detail about your inquiry or request including your name, contact information, description of your concern or request, relevant dates and circumstances, and any supporting documentation that may assist us in addressing your inquiry. We commit to responding to all legitimate inquiries and requests within the timeframes prescribed by applicable law and to maintaining the confidentiality of all communications regarding privacy matters.

We value your privacy and are dedicated to protecting your personal data in accordance with the highest standards of data protection and applicable legal requirements. Your trust is important to us, and we strive to maintain that trust through transparent, lawful, and ethical data processing practices.

16. MISCELLANEOUS PROVISIONS

16.1 Governing Law and Jurisdiction

This Privacy Policy and all matters relating to your access to and use of our Platform and the processing of your personal data by us shall be governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000, the Indian Contract Act, 1872, and all applicable rules, regulations, and notifications issued thereunder, without regard to principles of conflicts of laws. Any disputes, controversies, or claims arising out of or relating to this Privacy Policy, or the breach, termination, or invalidity thereof, shall be subject to the exclusive jurisdiction of the courts located in Uttarakhand, India.

Notwithstanding the foregoing, for users located in the European Union or European Economic Area, nothing in this Privacy Policy shall deprive you of any rights or protections afforded to you under GDPR or under mandatory provisions of the law of the EU Member State in which you are habitually resident. EU residents retain the right to bring proceedings before the courts of their Member State of habitual residence or before the courts of the place where we are established. For users in other jurisdictions, nothing in this Privacy Policy shall deprive you of mandatory consumer protections or rights afforded to you under the laws of your jurisdiction.

16.2 Severability

If any provision of this Privacy Policy is found to be invalid, illegal, unenforceable, or in conflict with any law of a competent jurisdiction by a court or tribunal of competent authority, such provision shall be deemed modified to the minimum extent necessary to make it valid, legal, and enforceable while preserving its intent, or if such modification is not possible, such provision shall be severed from this Privacy Policy. The invalidity, illegality, or unenforceability of any provision shall not affect the validity, legality, or enforceability of the remaining provisions of this Privacy Policy, which shall remain in full force and effect.

16.3 Waiver

Our failure or delay in exercising any right, power, or privilege under this Privacy Policy shall not operate as a waiver thereof, nor shall any single or partial exercise of any right, power, or privilege preclude any other or further exercise thereof or the exercise of any other right, power, or privilege. No waiver by us of any breach or default under this Privacy Policy shall be deemed to be a waiver of any subsequent breach or default. Any waiver must be in writing and signed by our authorized representative to be effective.

16.4 Entire Agreement

This Privacy Policy, together with our Terms of Service and any other policies or agreements expressly incorporated by reference, constitutes the entire agreement between you and Ayurveda Pulse regarding the subject matter hereof and supersedes all prior or contemporaneous understandings, agreements, representations, and warranties, whether written or oral, regarding such subject matter.

16.5 Survival

The provisions of this Privacy Policy that by their nature should survive termination or expiration of your use of our Services, including but not limited to provisions regarding data retention, security obligations, limitation of liability, indemnification, governing law, and dispute resolution, shall survive such termination or expiration and shall remain in full force and effect.

16.6 Assignment

You may not assign, transfer, or delegate any of your rights or obligations under this Privacy Policy without our prior written consent. We may assign, transfer, or delegate our rights and obligations under this Privacy Policy without your consent in connection with a merger, acquisition, corporate reorganization, sale of assets, or by operation of law. Any attempted assignment in violation of this provision shall be null and void.

16.7 Language and Interpretation

This Privacy Policy has been prepared in the English language. In the event of any conflict or inconsistency between the English version and any translation of this Privacy Policy into any other language, the English version shall prevail. The section and subsection headings in this Privacy Policy are for convenience only and shall not affect the interpretation or construction of this Privacy Policy. Unless otherwise specified, references to Sections refer to sections of this Privacy Policy.

16.8 Force Majeure

We shall not be liable for any failure or delay in performing our obligations under this Privacy Policy, including obligations to respond to data subject rights requests or to provide Services, where such failure or delay results from circumstances beyond our reasonable control including but not limited to acts of God, natural disasters, war, terrorism, civil unrest, labor disputes, government actions or restrictions, epidemics or pandemics, failure of telecommunications or internet infrastructure, cyberattacks, or other force majeure events. In such circumstances, our obligations shall be suspended for the duration of the force majeure event, and we shall use reasonable efforts to resume performance as soon as practicable.

17. DIGITAL PERSONAL DATA PROTECTION ACT 2023 COMPLIANCE

In addition to compliance with the Information Technology Act, 2000 and SPDI Rules 2011, Ayurveda Pulse is committed to full compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules), which represent India’s comprehensive data protection framework aligned with international standards.

17.1 Transition and Concurrent Compliance

The Digital Personal Data Protection Act, 2023 was enacted in August 2023, and the Digital Personal Data Protection Rules, 2025 were notified on January 3, 2025. Until the DPDP framework is fully operational and the Data Protection Board of India is established and functional, we continue to comply with both:

  • The Information Technology Act, 2000 and SPDI Rules 2011 (existing framework)
  • The Digital Personal Data Protection Act, 2023 and DPDP Rules 2025 (new framework)

This dual compliance approach ensures that your personal data receives the highest level of protection under both existing and emerging legal frameworks.

17.2 Right to Nominate

Under Section 16 of the DPDP Act 2023, you have the right to nominate another individual who may exercise your data principal rights on your behalf in the event of your death or incapacity. This nominated person will be able to:

  • Access your personal data
  • Request correction or erasure of your personal data
  • Exercise other data principal rights specified in the DPDP Act

To exercise your right to nominate:

  1. Contact us at [email protected] with the subject line “Right to Nominate – DPDP Act 2023”
  2. Provide the name, contact information, and relationship of your nominated individual
  3. Submit written authorization or consent for the nomination
  4. We will confirm receipt and record your nomination in our systems

You may change or revoke your nomination at any time by following the same process.

17.3 Consent Manager (When Operational)

Under Section 9 of the DPDP Act 2023 and the DPDP Rules 2025, you have the right to give, manage, review, and withdraw your consent through a Consent Manager registered with the Data Protection Board of India.

A Consent Manager is an entity registered with the Data Protection Board that enables you to:

  • Give consent for processing of your personal data
  • Manage and review all consents you have provided
  • Withdraw consent at any time
  • Maintain a centralized record of your consent preferences

Current Status: The Consent Manager framework is being established by the Data Protection Board of India. Once Consent Managers become operational and are registered with the Board, we will:

  • Integrate with registered Consent Manager platforms
  • Provide you with information on how to access and use Consent Managers
  • Honor all consent preferences communicated through Consent Managers
  • Update this Privacy Policy with specific instructions for using Consent Managers

Until Consent Managers become operational, you may continue to manage your consent preferences by:

  • Using unsubscribe links in our communications
  • Adjusting cookie preferences through browser settings
  • Contacting us directly at [email protected]

17.4 Language Availability and Accessibility

In accordance with Rule 5 of the DPDP Rules 2025, we are committed to making this Privacy Policy accessible to all users in a language they understand.

Current Availability: This Privacy Policy is available in English.

Additional Languages: Upon request, we can provide translations of this Privacy Policy in any of the 22 languages listed in the Eighth Schedule of the Constitution of India, which include:

  1. Assamese
  2. Bengali
  3. Gujarati
  4. Hindi
  5. Kannada
  6. Kashmiri
  7. Konkani
  8. Malayalam
  9. Manipuri
  10. Marathi
  11. Nepali
  12. Odia
  13. Punjabi
  14. Sanskrit
  15. Sindhi
  16. Tamil
  17. Telugu
  18. Urdu
  19. Bodo
  20. Santhali
  21. Maithili
  22. Dogri

To request a translation:

  • Contact us at [email protected]
  • Specify your preferred language from the list above
  • We will provide the translated Privacy Policy within 15 business days
  • Translations will be made available in accessible formats including PDF and web pages

Note: In case of any conflict or inconsistency between the English version and any translated version, the English version shall prevail for legal interpretation purposes.

17.5 Enhanced Rights Under DPDP Act 2023

In addition to the rights described in Section 10 of this Privacy Policy, the DPDP Act 2023 provides you with enhanced data principal rights including:

Right to Information: You have the right to obtain information about:

  • The personal data being processed
  • The identities of data fiduciaries (controllers) and data processors
  • The purpose of processing
  • The manner in which rights may be exercised

Right to Correction and Erasure: You may request correction of inaccurate, misleading, or incomplete personal data and erasure of personal data when it is no longer necessary for the purpose for which it was collected.

Right to Grievance Redressal: You have the right to file complaints with our Grievance Officer (contact details in Section 15) and to escalate unresolved complaints to the Data Protection Board of India.

Right to Nominate: As described in Section 18.2 above, you may nominate another person to exercise your rights in case of death or incapacity.

17.6 Our Obligations as Data Fiduciary

Under the DPDP Act 2023, Ayurveda Pulse operates as a “Data Fiduciary” (equivalent to a data controller under GDPR). As a Data Fiduciary, we are obligated to:

  1. Process personal data lawfully, fairly, and transparently for specified lawful purposes
  2. Collect only necessary personal data (data minimization principle)
  3. Ensure accuracy of personal data and keep it updated
  4. Implement appropriate security safeguards to prevent data breaches
  5. Retain personal data only as long as necessary and securely delete it thereafter
  6. Respect and facilitate data principal rights including access, correction, and erasure
  7. Appoint a Data Protection Officer if required based on volume and sensitivity of data processing
  8. Report all data breaches to the Data Protection Board
  9. Conduct Data Protection Impact Assessments for high-risk processing activities
  10. Maintain records of data processing activities

17.7 Cross-Border Data Transfers Under DPDP Act

Under Section 16 of the DPDP Act 2023, we may transfer your personal data to countries or territories outside India only to:

  • Countries or territories notified by the Central Government as providing adequate level of protection
  • Entities in other countries where such transfer is subject to Standard Contractual Clauses or other safeguards approved by the Central Government

Current Status: The Central Government has not yet notified the list of countries with adequate data protection or approved Standard Contractual Clauses under the DPDP Act. We continue to rely on safeguards under existing laws (SPDI Rules 2011) and international frameworks (GDPR Standard Contractual Clauses) until DPDP-specific mechanisms are notified.

We commit to updating our data transfer practices in accordance with any notifications or approvals issued by the Central Government under the DPDP Act 2023.

17.8 Significant Data Fiduciary Status

Based on the volume and sensitivity of personal data we process, we will determine whether we qualify as a “Significant Data Fiduciary” under the DPDP Act 2023. If classified as such, we will:

  • Appoint a Data Protection Officer (DPO) based in India
  • Appoint an independent Data Auditor
  • Conduct periodic Data Protection Impact Assessments (DPIAs)
  • Conduct annual data audits
  • Implement additional security and organizational measures

We will notify users if our status changes to Significant Data Fiduciary and update this Privacy Policy accordingly.

17.9 Children’s Data Processing Under DPDP Act

Section 9 of the DPDP Act 2023 provides special protections for processing personal data of children (individuals below 18 years of age). We do not knowingly process personal data of children without verifiable parental consent as detailed in Section 12 of this Privacy Policy.

Under the DPDP Act:

  • We do not undertake any processing that could cause harm to children
  • We do not engage in tracking, behavioral monitoring, or targeted advertising directed at children
  • We do not process personal data of children in any manner that is detrimental to their well-being
  • We implement age verification mechanisms to prevent unauthorized data collection from children

17.10 Monitoring and Updates

As the DPDP framework continues to evolve with:

  • Establishment of the Data Protection Board of India
  • Notification of rules, regulations, and guidelines
  • Registration of Consent Managers
  • Approval of Standard Contractual Clauses
  • Notification of countries with adequate data protection

We commit to:

  • Monitoring all developments and notifications
  • Updating our data processing practices accordingly
  • Revising this Privacy Policy to reflect new requirements
  • Communicating material changes to all users
  • Ensuring continuous compliance with the DPDP framework

Last DPDP Compliance Review Date: January 4, 2026
Next Scheduled Review: As per Data Protection Board notifications

For questions specifically related to DPDP Act 2023 compliance, please contact our Data Protection Officer at [email protected] with the subject line “DPDP Act 2023 Inquiry.”

18. EFFECTIVE DATE AND VERSION CONTROL

Effective Date: May 10, 2025
Last Updated: January 4, 2026
Version: 3.0

This Privacy Policy was originally adopted on May 10, 2025, and was last updated on January 4, 2026. All updates and revisions to this Privacy Policy are effective immediately upon posting to our Platform unless otherwise specified. Historical versions of this Privacy Policy are maintained in our records and may be provided upon reasonable request for transparency and audit purposes.

Major Update Summary (Version 3.0 – January 4, 2026):
– Added comprehensive Digital Personal Data Protection Act, 2023 compliance provisions
– Added mandatory Data Protection Board breach reporting requirements
– Added Right to Nominate provisions under DPDP Act
– Added Consent Manager framework provisions
– Added language availability in 22 constitutional languages
– Enhanced data breach notification procedures
– Updated definitions to include DPDP Act terminology

19. ACKNOWLEDGMENT AND ACCEPTANCE

By accessing, browsing, using, or continuing to use our Platform or Services, subscribing to our newsletter, submitting content, or otherwise engaging with Ayurveda Pulse in any manner, you expressly acknowledge, agree, and consent to the following:

You have carefully read this Privacy Policy in its entirety and understand its terms, conditions, and implications for the processing of your personal data. You acknowledge that this Privacy Policy is written in clear and plain language and that you have had adequate opportunity to review it and seek independent legal advice if desired before agreeing to its terms.

You understand and agree to the collection, use, storage, processing, disclosure, and transfer of your personal data as described in this Privacy Policy and in accordance with applicable data protection laws. You consent to the processing of your personal data for the purposes specified in Section 4 of this Privacy Policy and on the legal bases described therein.

You acknowledge that the use of our Platform and Services is voluntary and that by choosing to use our Platform and Services, you freely and voluntarily provide personal data to us. You understand that you may withdraw your consent or cease using our Services at any time as provided in this Privacy Policy, subject to our legal obligations to retain certain data.

You represent and warrant that all personal data you provide to us is accurate, current, complete, and not misleading, and that you have all necessary rights, consents, and authorizations to provide such personal data to us. If you provide personal data relating to other individuals (such as references, co-authors, or colleagues), you represent and warrant that you have obtained all necessary consents from such individuals for the processing of their personal data as described in this Privacy Policy.

You acknowledge that you have been informed of your rights under applicable data protection laws as described in Section 10 of this Privacy Policy and understand how to exercise those rights. You understand that you may contact us at any time to exercise your rights or to raise concerns about our data processing practices.

You acknowledge that this Privacy Policy forms an integral part of our Terms of Service and that your use of our Platform is subject to both this Privacy Policy and our Terms of Service. In the event of any conflict between this Privacy Policy and the Terms of Service regarding data protection matters, the provisions of this Privacy Policy shall prevail.

You understand that we may update this Privacy Policy from time to time as described in Section 14 and that your continued use of our Platform following any changes constitutes your acceptance of the revised Privacy Policy. You agree to periodically review this Privacy Policy to stay informed of any changes.

You acknowledge that the internet is not a completely secure medium and that despite our implementation of reasonable security measures as described in Section 6, we cannot guarantee absolute security of personal data transmitted through our Platform. You accept the inherent security risks of providing information and dealing online over the internet and agree that we shall not be liable for any breach of security unless such breach results from our gross negligence or willful misconduct.

BY USING OUR PLATFORM OR SERVICES, YOU SIGNIFY YOUR ACCEPTANCE OF THIS PRIVACY POLICY. IF YOU DO NOT AGREE WITH ANY PROVISION OF THIS PRIVACY POLICY, YOU MUST IMMEDIATELY DISCONTINUE ALL USE OF OUR PLATFORM AND SERVICES AND REFRAIN FROM PROVIDING ANY PERSONAL DATA TO US.

© 2026 Ayurveda Pulse, a unit of Nexorma Group. All rights reserved.

This Privacy Policy is a legally binding document. Please read it carefully and ensure you understand your rights and obligations before using our Platform or Services. If you have any questions or concerns, please contact us at [email protected].