GLOBAL DATA GOVERNANCE, TELEMETRY & PRIVACY CHARTER
Comprehensive Institutional Compliance Manuscript Governing Data Principal Rights, Enterprise Software Tenancy (Sahyak CRM), Edge Telemetry Logging, and Multi-Tenant Isolation under the Digital Personal Data Protection Act, 2023, Information Technology Act, 2000, and International Cross-Border Data Transfer Frameworks.
ARTICLE I — STATUTORY PREAMBLE, CORPORATE IDENTITY & REGULATORY TAXONOMY
1.1. Corporate Entity and Operational Architecture: This Comprehensive Data Governance, Telemetry, and Privacy Charter (“Charter,” “Privacy Policy,” or “Policy”) constitutes a binding regulatory instrument executed by Mayalok Venture (Private Limited), an enterprise technology corporation incorporated under the Companies Act, 2013, with its executive headquarters and engineering studios situated in Greater Noida, Gautam Buddha Nagar, Uttar Pradesh 201306, India, acting through its specialized venture engineering studio, autonomous platform holding, and commercial distribution division, Deeplink Creators (hereinafter collectively referenced as “Mayalok Venture,” “Deeplink Creators,” “the Holding,” “We,” “Us,” or “Our”).
1.2. Entity Categorization & Rejection of Conventional Agency Classification: Deeplink Creators operates exclusively as an AI-first Enterprise Software Holding and Venture Studio. We develop, license, and orchestrate proprietary B2B software infrastructure—specifically including our flagship enterprise customer relationship management platform, Sahyak CRM (sahyak.com), edge cloud routing clusters, serverless database partitions, and private creator-led distribution networks. Deeplink Creators is not a third-party lead broker, consumer data reseller, or public advertising agency. All data processing activities are strictly confined to enterprise software deployment, institutional client onboarding, and authenticated distribution syndication.
1.3. Statutory Framework of Enforceability: This Charter is drafted, published, and enforced pursuant to the mandatory requirements of:
- The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023, Parliament of India) [“DPDP Act, 2023”];
- The Information Technology Act, 2000 (Act No. 21 of 2000), specifically Sections 43A, 66, 66E, 72A, and 85;
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 [“SPDI Rules, 2011”];
- The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
- International standard contractual principles and Article 28 data processing safeguards governing cross-border enterprise SaaS data routing.
ARTICLE II — DUAL STATUTORY PROCESSING CAPACITIES: FIDUCIARY VS. PROCESSOR
2.1. Capacity as a Data Fiduciary: Pursuant to Section 2(i) of the DPDP Act 2023, Deeplink Creators functions as a Data Fiduciary with respect to personal data directly provided by prospective enterprise clients, corporate representatives, venture partners, and platform visitors who navigate deeplinkcreators.com, transmit executive intake briefs, request technical demonstrations, or enter into direct Master Services Agreements (MSAs). In this capacity, Mayalok Venture determines the explicit institutional purposes and means of lawful processing.
2.2. Capacity as a Data Processor: Pursuant to Section 2(k) of the DPDP Act 2023, Deeplink Creators functions strictly as a Data Processor when hosting, maintaining, and architecting multi-tenant database partitions, webhook routes, and isolated telemetry pipelines on behalf of enterprise subscribers deploying Sahyak CRM. In such operational modalities, the enterprise client organization acts as the independent Data Fiduciary, retaining sole ownership over the end-customer records, lead databases, and sales notes ingested into their designated tenant vault. Deeplink Creators processes such tenant data strictly pursuant to automated system algorithms and written client instructions, maintaining a zero-knowledge administrative posture regarding the underlying customer information.
ARTICLE III — EXHAUSTIVE TAXONOMY OF COLLECTED DATA & INGESTION PROTOCOLS
3.1. Category A: Enterprise Intake & Authorized Representative Data: When an executive, institutional counterparty, or corporate representative initiates an inquiry or submits a commercial briefing through our intake portals, we collect:
- Identification Credentials: Full legal name, official executive designation, professional email address, corporate telephone number, and WhatsApp communication coordinates;
- Institutional Entity Data: Registered corporate entity name, state of incorporation, corporate identification number (CIN), Goods and Services Tax Identification Number (GSTIN), registered office physical address, corporate website URL, and primary business vertical;
- Project Technical Parameters: Target commercial budget allocations, operational timelines, software infrastructure requirements, technical scope dossiers, and customized integration preferences.
3.2. Category B: Sahyak CRM Multi-Tenant Application Records: When client organizations deploy and operationalize Sahyak CRM, our systems process and store within encrypted database nodes:
- Enterprise sales pipeline records, lead ingestion payloads, customer lifecycle tags, interaction notes, and conversation timestamps;
- Custom field schema definitions, workflow automation triggers, role-based access control (RBAC) logs, and administrative audit trails;
- Integrated communication webhooks (e.g., WhatsApp Cloud API message delivery acknowledgments, email transmission receipts, telephony dispatch timestamps).
3.3. Category C: Edge Telemetry, Hardware Identification & Cryptographic Visitor Tokens: To ensure DDoS mitigation, load balancing, fraud prevention, and anonymous platform analytics across our distributed global network, our edge compute nodes automatically ingest non-identifiable telemetry:
- Pseudonymized Cryptographic Hash: An irreversible client-side mathematical hash derived from non-sensitive browser environment attributes (display geometry, language token, timezone offset, user-agent string) to record returning visitation cadence without extracting persistent hardware serials;
- Edge Routing Diagnostics: Cloudflare edge server response latency, request method, protocol version (HTTP/2 or HTTP/3), TLS cipher suite version, referring domain syndication pathway, and country/region location headers derived at the network edge without persistent GPS coordinate tracking;
- First-Party Client Telemetry Storage: Local storage key-value entries (
dlc_local_visits,dlc_visited) stored solely within the Data Principal's local browser runtime to preserve analytics persistence across navigation sessions without third-party cookie beacons.
ARTICLE IV — LAWFUL GROUNDS FOR PROCESSING UNDER THE DPDP ACT, 2023
4.1. Statutory Consent Framework (Section 6, DPDP Act 2023): Where processing relies on affirmative consent, the Data Principal grants unambiguous, informed, specific, and unconditional consent by voluntarily inputting data into our intake portals and submitting an inquiry. Such consent covers the collection, verification, and internal routing of data strictly for evaluating, structuring, and fulfilling commercial software engagements.
4.2. Certain Legitimate Uses (Section 7, DPDP Act 2023): Processing is conducted without separate consent where necessary for:
- The performance of any statutory function, compliance with judicial subpoenas, enforcement of legal claims, or prevention of corporate fraud under Indian law;
- Responding to voluntary inquiries initiated by the Data Principal seeking commercial proposals or software architecture consultations;
- Information security diagnostics, network vulnerability scanning, and real-time mitigation of denial-of-service (DDoS) assaults on our cloud perimeter.
ARTICLE V — MULTI-TENANT DATABASE PARTITIONING & CRYPTOGRAPHIC ISOLATION (SAHYAK CRM)
5.1. Logical & Cryptographic Separation: Deeplink Creators enforces strict multi-tenant data architecture across all hosted deployments of Sahyak CRM. All database operations executed within our MongoDB Atlas clusters and Cloudflare D1 / edge storage layers enforce mandatory tenant scoping. Tenant identifiers (Tenant UUIDs) are cryptographically validated on every database query, ensuring zero cross-tenant contamination, unauthorized cross-reads, or shared memory leakages.
5.2. Encryption at Rest and In Transit:
- In Transit: All data transmitted between client browsers, edge proxy servers, API gateways, and database clusters is encrypted using Transport Layer Security (TLS) Version 1.3 with modern cipher suites (ECDHE-RSA-AES128-GCM-SHA256 or equivalent);
- At Rest: All stored database documents, backups, disk volumes, and transaction logs are encrypted at rest using Advanced Encryption Standard (AES) with 256-bit cryptographic keys managed under strict hardware security module (HSM) protocols;
- Zero Plaintext Key Exposure: Database connection URIs, service account tokens, and administrative credentials are injected exclusively at runtime via encrypted environment variables and secret stores, with zero plaintext persistence in source code.
ARTICLE VI — VETTED ENTERPRISE SUB-PROCESSORS & CLOUD INFRASTRUCTURE
6.1. Sub-Processor Engagement Covenants: Mayalok Venture contracts exclusively with internationally accredited cloud infrastructure providers that maintain independent SOC 2 Type II, ISO/IEC 27001, and ISO/IEC 27701 certifications. Our active certified sub-processors include:
| Sub-Processor Entity | Processing Purpose | Geographic Location | Compliance Standards |
|---|---|---|---|
| Cloudflare, Inc. | Global Edge CDN, DNS, WAF & D1 Database Shielding | Distributed Global Edge (India Nodes Primary) | SOC 2 Type II, ISO 27001, GDPR, DPDP Act |
| MongoDB, Inc. (Atlas) | Encrypted Multi-Tenant Cloud Database Clusters & Backups | AWS / GCP Asia-South (Mumbai, India) | SOC 2 Type II, ISO 27001, HIPAA, AES-256 |
| Formspree, Inc. | TLS-Encrypted Webhook Ingestion & Dispatch Routing | US / EU Encrypted Cloud Gateways | SOC 2 Compliant, TLS 1.3, GDPR SCCs |
ARTICLE VII — CROSS-BORDER DATA TRANSFERS & SOVEREIGN LOCALIZATION
7.1. Cross-Border Routing Safeguards: While our primary database instances are localized within the sovereign territory of the Republic of India (AWS/GCP Mumbai Region), edge caching and technical sub-processor routing may occasionally involve data transit through international nodes. Pursuant to Section 16 of the DPDP Act 2023, transfers of personal data outside India are restricted strictly to jurisdictions not explicitly restricted by the Central Government of India, and are governed by Standard Contractual Clauses guaranteeing equivalent data protection levels.
ARTICLE VIII — ENFORCEABLE DATA PRINCIPAL RIGHTS (DPDP ACT, 2023)
8.1. Statutory Rights Schedule: Every Data Principal whose personal data is processed by Deeplink Creators possesses the following non-derogable legal rights under Chapter III of the DPDP Act 2023:
8.1.1. Right to Access Information (Section 11): The Data Principal has the right to obtain a summary of personal data being processed, the identities of all Data Fiduciaries and Data Processors with whom data has been shared, and all other relevant processing descriptions.
8.1.2. Right to Correction and Erasure (Section 12): The Data Principal may demand the correction of inaccurate or misleading data, the completion of incomplete data, the updating of outdated records, or the complete erasure of personal data that is no longer necessary for the purpose for which it was collected.
8.1.3. Right of Grievance Redressal (Section 13): The Data Principal has the right to readily available grievance redressal mechanisms with guaranteed response and resolution from our registered Data Protection Officer.
8.1.4. Right to Nominate (Section 14): The Data Principal has the right to designate an authorized nominee who shall, in the event of death or incapacity of the Data Principal, exercise these statutory rights.
ARTICLE IX — RETENTION SCHEDULES, ARCHIVAL & IMMUTABLE DELETION
9.1. Data Minimization and Scheduled Purging: Personal data is retained strictly for the duration necessary to accomplish the contractual, operational, and statutory purposes defined herein:
- Enterprise Inquiry & Briefing Data: Retained for a period of twenty-four (24) calendar months from the date of submission, after which records are automatically purged unless converted into an active Master Services Agreement;
- Sahyak CRM Tenant Production Data: Retained throughout the active subscription term. Upon formal contract termination, tenant data enters a thirty (30) day export grace window, following which all tenant database partitions, collections, and associated backup snapshots are permanently, cryptographically, and immutably overwritten;
- Statutory Tax & Invoicing Records: Preserved for eight (8) financial years pursuant to Section 128 of the Companies Act, 2013 and Section 36 of the Central Goods and Services Tax Act, 2017;
- Edge Diagnostic & Telemetry Logs: Anonymized and aggregated rolling logs are systematically rotated and erased every ninety (90) calendar days.
ARTICLE X — PROHIBITION OF AUTOMATED SCRAPING, DATA HARVESTING & IP THEFT
10.1. Strict Prohibition of Automated Extraction: All textual formulations, code architectures, database schemas, legal manuscripts, brand identifiers, and technical specifications published on deeplinkcreators.com constitute protected proprietary property of Mayalok Venture. The deployment of automated scraping bots, web crawlers, screenshot harvesters, headless browser extractors, or data mining algorithms to ingest content for training Large Language Models (LLMs) or commercial mirroring without express written consent is strictly prohibited.
10.2. Statutory Penalties and Legal Enforcement: Any unauthorized data extraction or system compromise constitutes an actionable offense under Section 43 (Damage to computer systems), Section 66 (Computer related offenses), and Section 70 of the Information Technology Act, 2000, and will trigger immediate civil claims for damages, statutory injunctions, and formal criminal cyber complaint lodgments.
ARTICLE XI — DATA PROTECTION OFFICER & STATUTORY GRIEVANCE REDRESSAL
11.1. Designated Grievance Directorate: In compliance with Section 12 of the DPDP Act 2023 and Rule 5(9) of the SPDI Rules 2011, the identity and contact coordinates of our designated Data Protection Officer (DPO) and Statutory Grievance Redressal Officer are registered as follows:
11.2. Statutory Escalation: Our Grievance Directorate commits to acknowledging all formal grievances within twenty-four (24) business hours and delivering complete statutory resolution within seventy-two (72) business hours. If unsatisfied with the resolution, the Data Principal maintains the right to register a complaint before the Data Protection Board of India pursuant to Section 18 of the DPDP Act 2023.