This policy explains what personal data we handle, why, where it is kept and for how long, and what you can do about it. It is written against India’s Digital Personal Data Protection Act, 2023 (“the DPDP Act”).
We use the DPDP Act’s terms throughout. A data principal is the individual the data is about. A data fiduciary decides why and how personal data is processed. A data processor handles it only on a fiduciary’s instructions.
1. The two roles Juvlon plays
Juvlon does two quite different things with personal data, and which one applies changes what we may do and who you should talk to.
- Your Juvlon account — your users, logins, billing and support conversations. Juvlon is the Data Fiduciary, and we decide why that data is processed.
- The subscriber lists our customers upload, and the campaign activity recorded against them. Juvlon is the Data Processor, and our customer decides why that data is processed.
So if you are a Juvlon customer, read Part A. If you received a marketing email or SMS that was sent through Juvlon, read Part B. Part C applies to everyone.
Part A — IF YOU ARE A JUVLON CUSTOMER OR USER
2. What we collect about you
When you register: your name, work email address, telephone number, company name and website, and the IP address the registration came from.
While you use Juvlon: your login credentials, the actions you take in the application, your usage and sending volumes, your billing and invoicing records, and your correspondence with our support team.
We do not store card numbers. Payments are handled by a payment processor and card details do not reach our systems.
3. Why we process it
- Providing the platform under our contract with you — performance of a service you have requested.
- Billing, invoicing and credit accounting — legitimate use.
- Security, fraud and abuse prevention, audit logging — legitimate use.
- Support and incident response — performance of a requested service.
- Statutory and tax record-keeping — legal obligation.
- Service announcements about your account — legitimate use
- Marketing about other Juvlon products — consent.
You can withdraw consent for marketing at any time without affecting your service. Withdrawing consent for processing that is necessary to run the platform will generally mean we can no longer provide it.
AI-generated analytics reports. Some customers use an optional reporting product that turns their campaign statistics into a written commentary. To produce it, we send aggregate figures — counts, rates, subject lines and time-of-day totals — to an AI provider in the United States. No subscriber’s name, email address, telephone number or identifier is included: the commentary is generated from totals, not from people.
This feature is off unless you ask for it. We will not switch it on for your account without telling you first and obtaining your agreement, because it involves data leaving India.
Nothing else about your account is sent outside India
4. How long we keep it
While your account is open, we keep your account, billing and usage data for as long as the account exists.
After your account closes:
- Your account data and the subscriber data you uploaded are deleted within 90 days.
- Billing, invoicing and tax records are kept for the period Indian tax and companies legislation requires — currently eight years for books of account under the Companies Act, 2013.
- Support records are kept for as long as we may need them to answer a later query or a legal claim, and are then deleted.
Logs. Server authentication logs are kept for about four to five weeks. Application access logs are kept for 365 days. Other operational logs are kept only as long as they are useful for security, billing accuracy and troubleshooting, and are then deleted.
Backups. We take routine backups, and deleting something from the live system does not immediately remove it from backups already taken. Backup copies age out on their own cycle, and data held only in a backup is not used for any other purpose.
5. Your rights
As a data principal you may:
- Access the personal data we hold about you, and a summary of how it is processed.
- Correct it where it is wrong, and complete it where it is missing something.
- Erase it, where we are not required to keep it for a legal or contractual reason.
- Withdraw consent where consent is the basis for the processing.
- Nominate someone else to exercise your rights for you if you are unable to (DPDP s.14).
- Complain to us, and then to the Data Protection Board of India.
How to exercise them. Write to privacy@juvlon.com. We will acknowledge within 5 working days and respond substantively within 30 days. We may need to confirm who you are first, and we will ask only for what is necessary to do that.
Most of your account data can also be viewed and corrected directly in the Juvlon dashboard, which is usually faster.
Part B — IF YOU RECEIVED A CAMPAIGN SENT THROUGH JUVLON
If a company sent you a marketing email or SMS using Juvlon, that company decides what data it holds about you and why. They are the data fiduciary. We are their processor, and we act on their instructions.
That matters for a practical reason: we cannot change or delete their records for you. Requests have to go to them. If you write to us we will pass your request on and tell you we have done so, but we will not answer it ourselves, because it is not our data to answer for.
6. What data our customers hold in Juvlon
Our customers decide what they upload. The platform is able to hold:
- Name, title and prefix
- Email address, telephone and mobile number
- Company name, job title, and business address details
- Home address details
- Date of birth and anniversary
- The customer’s own reference number for you
- Six custom fields whose contents the customer defines
- A free-text note
- Your subscription and opt-out status
- Whether and when messages were delivered to you, and whether you opened or clicked them
Campaign activity is recorded against you individually, not only as an overall total. That is what allows a company to see who opened what. We say so plainly here rather than leaving you to work it out.
We require our customers to have a lawful basis for holding your data, not to upload sensitive personal data, and not to upload data about anyone under 18.
7. Where your data is stored and processed
Everything stays in India.
- Databases holding subscriber data — Amazon Web Services, Mumbai region, India.
- Application, API, tracking and reporting servers — Amazon Web Services, Mumbai region, India.
- Mail servers, which messages pass through on delivery — Iron Mountain Datacenter, Mumbai, India. This is our own hardware.
- Files and archives — Amazon Web Services, Mumbai region, India.
We do not transfer subscriber personal data outside India. Nothing about you as a campaign recipient — your name, email address, telephone number, or your opens and clicks — leaves the country.
8. Who else may receive it
- Amazon Web Services — hosting, databases and storage, in India.
- Our SMS gateway — mobile numbers and message content, where a customer sends SMS.
- A payment processor — for our own customers’ billing only. This does not involve subscriber data.
We do not sell, rent or licence personal data to anyone, and we never market to our customers’ subscribers on our own behalf. We do not use personal data held in Juvlon to train or develop machine-learning models, our own or anyone else’s.
Where a customer has opted in to AI-generated analytics reports (section 3), aggregate campaign figures are sent to an AI provider in the United States. No subscriber-level data is included in those reports — no names, email addresses, telephone numbers or identifiers.
9. Your rights as a campaign recipient
Unsubscribing works, always. Every campaign sent through Juvlon carries an unsubscribe or preference link. Using it stops further messages from that sender. This is a condition of using our platform, not something a sender can switch off.
For access, correction or deletion, contact the company that emailed you. Their name and contact details are in the message you received.
If you cannot reach them, or you do not know who they are, write to privacy@juvlon.com with a copy of the message. We will identify the sender and pass your request to them within 5 working days, and tell you we have done so.
One thing to know about deletion. When a sender deletes you, we stop sending to you immediately. If there is no record of us having sent to you before, the record is erased entirely. If there is, the record is deactivated and kept so the sender’s historical reporting stays intact — but you stop receiving messages either way. If you want full erasure beyond that, ask the sender to raise it with us and we will help them do it.
You may also complain to the Data Protection Board of India.
Part C — APPLIES TO EVERYONE
10. Trial accounts
A Juvlon trial runs for 30 days. During it you can upload subscriber lists and send campaigns as a paying customer would, and we treat that data in exactly the same way — same separation, same security, same restrictions on what we may do with it.
Two days before the trial ends we email you a reminder to activate a paid plan.
If you decide not to continue, your account and the data you uploaded during the trial are deleted automatically 60 days after the trial period ends, and your database is dropped at that point. We keep the account for those 60 days so you can come back and activate a plan without registering again.
You can export your data at any point before deletion. If you would rather we removed your account and everything in it sooner — at any time, including during the trial — contact our support team and we will do it.
If you convert to a paid plan, none of the above applies. Your data is then retained as described in section 4.
11. How we protect personal data
- Traffic between you and Juvlon is encrypted with TLS.
- Each customer’s subscriber data is held in a separate database of its own, rather than in a shared table divided up by a customer identifier.
- Access to production systems is restricted to named staff, over key-based SSH, and is logged. Keys are rotated as a defined procedure.
- Access inside the application is role-based.
- Where our staff access a customer’s account to provide support, the session is recorded — which staff member, which account, when — and those records are kept and can be reviewed.
- Automated monitoring runs against the sending pipeline and alerts our systems team.
- Staff with access to personal data are under written confidentiality obligations and receive data protection training for their role.
No system is perfectly secure, and we do not claim otherwise.
12. If something goes wrong
We keep a written process for handling personal data breaches, and we review it after every notifiable incident.
If anyone at Juvlon sees signs of a breach it goes straight to our Director, who owns the response, grades how serious it is and decides who has to be told. We contain the incident and record the moment we became aware, because that is when our notification clock starts — not when the breach is confirmed. Containment work does not pause it.
Where a breach affects a customer’s subscriber lists, we notify that customer within 72 hours of becoming aware. Our customer is the data fiduciary for that data, so notifying the Data Protection Board of India and the affected individuals is theirs to do, and we give them the information and cooperation they need to do it.
Where a breach affects data for which Juvlon is itself the data fiduciary — your account, billing or support data — we notify the Data Protection Board and the affected individuals ourselves, as section 8(6) of the DPDP Act requires.
Either way we set out what happened, what data was involved, roughly how many people are affected, the likely consequences, what we have done, and who to contact. If we do not have the full picture inside 72 hours we send what we have and keep you updated, rather than waiting until it is complete. Once the incident is closed we issue a written report covering the root cause and what we changed.
13. Contact us
Under section 13 of the DPDP Act we have appointed a Grievance Officer to answer questions about your personal data and to handle complaints.
- Grievance Officer: Naresh Bhagtani, Director
- Deputy: Pralhad Badgujar, Product Development Manager
- Email: privacy@juvlon.com
- Post: Niche Software Solutions Private Limited, 39/D Swastik House, Gultekdi, Pune, Maharashtra 411037, India
We will acknowledge your request within 5 working days and respond substantively within 30 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
14. Cookies
The Juvlon website and application use cookies that are necessary for the service to work — keeping you signed in, holding your session, and remembering preferences you have set. These cannot be switched off without breaking the service.
We also use analytics cookies to understand how the website is used. You can refuse these without losing access to anything.
You can control cookies through your browser settings. Blocking essential cookies will stop you signing in.
15. Children
Juvlon is a business tool and is not directed at children. We do not knowingly process the personal data of anyone under 18.
Under section 9 of the DPDP Act, processing a child’s personal data requires verifiable parental consent, and behavioural advertising directed at children is prohibited outright. Our customers are contractually required not to upload children’s data to the platform. If we learn that a customer has, we will act under our agreement with them.
16. Changes to this policy
We will post any change on this page and update the date at the top. Where a change materially affects your rights we will tell customers directly, and in advance where we reasonably can.
Juvlon
Address:
39/D Swastik House
Gultekdi, Pune
Maharashtra 411037
Email:
customerfirst@juvlon.io
