Privacy Policy
SVEGA Consulting (“SVEGA”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect information about you when you visit our website (svegaconsulting.com) or engage with us for consulting services.
This Policy is issued in accordance with applicable Indian law, including the Information Technology Act, 2000 (“IT Act”), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and the Digital Personal Data Protection Act, 2023 (“DPDPA”).
Who We Are and How to Contact Us
Data Fiduciary (Controller):
SVEGA Consulting
Website: svegaconsulting.com
Email: info@svegaconsulting.com
For any queries, concerns, or requests relating to your personal data, please contact us at the email address above. We will endeavour to respond within 30 days of receiving your request.
What Information We Collect
We collect only the minimum information necessary for our business purposes. We do not sell your personal data to third parties.
2.1 Information You Provide to Us
When you contact us via our website, request a consultation, or enter into an engagement with us, we may collect:
- Contact information: your name, email address, phone number, and job title
- Company information: your organisation’s name, industry, size, and business challenges or goals
- Engagement data: documents, reports, policies, supplier records, workforce data, and other business materials shared with us during a consulting engagement
- Communications: emails, messages, and meeting notes exchanged with us
2.2 Information We Collect Automatically
When you visit our website, our hosting provider may automatically collect limited technical information, such as:
- IP address and general geographic location (country/region)
- Browser type and operating system
- Pages visited and time spent on our website
We do not use behavioural advertising trackers or fingerprinting technologies. If we deploy analytics tools in the future, this Policy will be updated accordingly.
2.3 Sensitive Information
We do not intentionally collect sensitive personal data (such as health information, biometric data, or financial account numbers) unless it is directly relevant to a specific engagement and you have provided explicit consent. If an engagement requires access to such data, this will be addressed explicitly in the applicable NDA and engagement documentation.
How We Use Your Information
We use the information we collect for the following purposes:
• Responding to your enquiries and scheduling consultations – legal basis: legitimate interests and pre-contractual steps.
• Delivering consulting services and producing deliverables – legal basis: performance of contract.
• Sending you relevant updates, insights, or invitations (if you have opted in) – legal basis: consent.
• Managing invoicing, payments, and financial records – legal basis: legal obligation and performance of contract.
• Complying with legal and regulatory obligations – legal basis: legal obligation.
• Improving our services and website experience – legal basis: legitimate interests.
• Protecting our legal rights and enforcing our agreements – legal basis: legitimate interests.
Confidentiality and the Role of NDAs
SVEGA signs a Non-Disclosure Agreement (NDA) with every client before any confidential information is exchanged. The NDA governs the treatment of all business-sensitive and proprietary information shared during an engagement, including company data, operational data, supplier records, and strategic plans.
All members of the SVEGA team are bound by confidentiality obligations. Client data is accessed only by team members who need it to perform the specific engagement and is never used for any purpose outside the scope of that engagement.
How We Share Your Information
We do not sell, rent, or trade your personal data. We may share your information in the following limited circumstances:
- Service providers: We may share data with trusted third-party service providers (such as cloud storage, project management tools, or communication platforms) who assist us in delivering our services. All such providers are required to handle data in accordance with applicable law and our confidentiality requirements.
- Legal requirements: We may disclose information if required to do so by law, court order, or government authority, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: In the event of a merger, acquisition, or restructuring of SVEGA, your data may be transferred to the successor entity, subject to equivalent privacy protections.
We do not share client engagement data with any third party without your explicit written consent, except as required by law or as set out in the applicable NDA.
Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. Our general retention practices are:
• Enquiry and contact information – retained for 3 years from last contact, unless an engagement commences.
• Engagement and client data – retained for 7 years after the end of the engagement, for legal and financial record-keeping obligations.
• NDA and contractual documents – retained for 7 years after expiry or termination of the agreement.
• Website technical logs – retained for up to 12 months.
• Marketing communications (opted-in) – retained until you withdraw consent or unsubscribe.
After the applicable retention period, data is securely deleted or anonymised.
Data Security
SVEGA implements appropriate technical and organisational security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- Encrypted communication channels for data transfer
- Access controls limiting data access to authorised personnel only
- Secure cloud storage with reputable, compliant service providers
- Confidentiality obligations for all team members
While we take all reasonable precautions, no method of electronic storage or transmission over the internet is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights or interests, we will notify you and the relevant authorities as required by applicable law.
International Data Transfers
SVEGA is based in India and primarily processes data within India. If any of our service providers process data outside India, we take steps to ensure that appropriate safeguards are in place to protect your data in accordance with the requirements of the DPDPA and other applicable laws.
Your Rights
Under the Digital Personal Data Protection Act, 2023, and other applicable Indian law, you have the following rights in relation to your personal data:
- Right of access: You may request confirmation of whether we hold personal data about you and obtain a copy of that data.
- Right to correction: You may request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to erasure: You may request that we delete your personal data where it is no longer necessary for the purpose for which it was collected, subject to any legal retention obligations.
- Right to withdraw consent: Where we process your data on the basis of your consent (e.g., for marketing communications), you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
- Right to nominate: Under the DPDPA, you may nominate another individual to exercise your privacy rights on your behalf in the event of your death or incapacity.
- Right to grievance redressal: You have the right to lodge a grievance with us. If you are dissatisfied with our response, you may approach the Data Protection Board of India.
To exercise any of these rights, please contact us at hello@svegaconsulting.com. We will respond within 30 days of receiving your request. We may need to verify your identity before processing your request.
Cookies and Tracking Technologies
Our website may use essential cookies required for the site to function properly (such as session cookies). We do not currently use advertising or profiling cookies.
If we introduce non-essential cookies in the future, we will update this Policy and obtain your consent where required by law. You may control cookie settings through your browser at any time.
Third-Party Links
Our website may contain links to third-party websites. This Privacy Policy applies only to SVEGA’s website and services. We are not responsible for the privacy practices of third-party websites and encourage you to review their privacy policies before providing any personal data.
Children's Privacy
Our services are intended for business clients and are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us and we will promptly delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will update the ‘Last Updated’ date at the top of this Policy and, where appropriate, notify you by email or through our website.
We encourage you to review this Policy periodically to stay informed about how we protect your information.
Grievance Officer
In accordance with the IT Act and applicable rules, we have designated a Grievance Officer to address any concerns relating to this Policy or the processing of your personal data:
Grievance Officer, SVEGA Consulting
Email: info@svegaconsulting.com
We will acknowledge your grievance within 48 hours and endeavour to resolve it within 30 days.