What personal data we collect, why, how long we keep it, who we share it with, and the rights you have under India's DPDP Act, 2023
Projects India is operated by Venturous Advisory Solutions Pvt Ltd ("Projects India", "we", "us"). For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary for the personal data described here, and you are the Data Principal.
This notice is given under Section 5 of the DPDP Act. It applies to our website, the subscriber platform, our tender and project services, our sales CRM, and the Projects India mobile app used by our sales team.
We collect data for the specific purposes listed below and nothing else. Where consent is our basis, you give it by ticking an unticked box at the point of collection, and you can withdraw it at any time.
| Data | Purpose | Our basis | Where it comes from |
|---|---|---|---|
| Name, work email, phone number, company name, company website | Creating and running your account, subscription, saved searches and alerts | Your consent, and performance of our contract with you | You — signup, trial registration, subscription forms |
| Name, email, phone, company, your message, the page you came from, your IP address | Replying to an enquiry, demo request or callback you asked for | Your consent (the tick on the enquiry form) | You — contact form, home page enquiry form |
| Email address | Sending newsletters, project alerts, tender alerts and offers | Your consent — separate, optional, and withdrawable | You — newsletter box, or the optional tick on an enquiry form |
| Billing name, address, GSTIN, invoice records, payment reference ids | Taking payment, issuing invoices, GST compliance, renewals | Contract, and our legal obligation under tax law | You, and our payment gateways |
| Your search terms, sector and location preferences, bidding profile, projects and tenders you view or favourite, export activity | Running the service, matching alerts to what you care about, and detecting misuse such as bulk scraping | Contract, and our legitimate interest in protecting the service | Generated as you use the platform |
| Login times, IP address, device and browser details, session and "remember me" cookies | Signing you in, keeping the account secure, investigating abuse | Contract, and security | Collected automatically |
| Page views and site usage statistics | Understanding which pages are useful and improving the site | Your consent — off unless you allow analytics cookies on our banner | Google Analytics / Google Tag Manager, if allowed |
| Call recordings, call transcripts and AI-generated call summaries; call time, duration and the number dialled | Sales quality, coaching our executives, and generating a record of what was discussed | Consent — see section 3 below, where we are explicit that this is not yet fully implemented | Our sales team's mobile app, when a call with you is recorded |
| Automated AI voice calls: the recording, a transcript, and the answers the AI agent notes down (for example whether you are interested, when to call back, and what you need) | Following up on enquiries, subscriptions and business leads, and passing interested people to a member of our sales team | [LEGAL REVIEW — legitimate interest for existing customers and enquirers; consent for uploaded lists, which our team must confirm before calling] | Our AI calling providers, when an AI agent calls you on our behalf |
| WhatsApp messages exchanged with us, and your WhatsApp profile name | Answering you on WhatsApp and keeping a record of the conversation | Your consent, given by messaging us or opting in to WhatsApp contact | Meta's WhatsApp Business Platform |
| Name, designation, company phone and company email of people at project-owning organisations | The B2B project and tender intelligence we sell to subscribers | Under review — see section 8 | Public records, tender portals, company sources, and our own research |
We do not knowingly collect data from children under 18, and the service is meant for business use. We do not collect financial account numbers or card details ourselves — those go directly to our payment gateway.
Three categories, and only the first is on by default:
You can change your choice at any time — use the Cookie Preferences link (also in the footer of every page), which clears your saved choice and brings the banner back.
Separately, our pages load fonts and stylesheets from Google Fonts, cdnjs (Cloudflare) and jsDelivr. Those requests reveal your IP address to those providers. [LEGAL REVIEW — whether these should also sit behind the consent banner, or be self-hosted to remove the transfer entirely, is an open item.]
Calls from our AI agent. We sometimes call people with an automated AI voice agent — for example to follow up an enquiry or a subscription renewal. These calls are placed only between 9 AM and 9 PM, and are not placed to numbers on our do-not-call list or refused by telecom operators under the TRAI National Customer Preference Register. Where switched on, the agent says at the start that it is an AI assistant and that the call may be recorded. If you tell the agent you do not want to be called again, your number is added to our do-not-call list automatically. You can also ask the Grievance Officer to erase the recording, transcript and notes of an AI call; your number is then kept only on the do-not-call list, so that we do not call you again. [LEGAL REVIEW — confirm the disclosure wording and whether it must be mandatory rather than a setting.]
We do not sell personal data. We share it with the processors below, each only for the purpose listed, and each bound to use it only on our instructions. Several are outside India, which means your data is transferred abroad. [LEGAL REVIEW — Section 16 permits transfer except to countries the Central Government restricts; the current list of restricted countries must be checked, and written data-processing terms must be confirmed to exist with each processor below.]
| Processor | What they receive | Why |
|---|---|---|
| Razorpay Software Pvt Ltd (India) | Name, email, phone, payment amount, subscription reference | Card / UPI payments and UPI AutoPay mandates |
| PayU Payments Pvt Ltd (India) | Name, email, phone, payment amount | Legacy payment option |
| Meta Platforms (WhatsApp Business Platform) | Your phone number, WhatsApp profile name, and message content | WhatsApp conversations, alerts and OTPs |
| DoubleTick (Wildnet Technologies) | Your phone number and template message content | Legacy WhatsApp delivery route |
| Google LLC — Analytics & Tag Manager | IP address, pages viewed, device details | Site analytics, only with your consent |
| Google LLC — Firebase Cloud Messaging | Device push tokens of our own staff | Push notifications to our sales app |
| Google LLC — Fonts & Cloudflare / jsDelivr CDNs | Your IP address and browser details | Serving fonts, icons and stylesheets |
| Anthropic PBC (USA) | Lead and enquiry details, call transcripts, tender and project text submitted for analysis | AI summarisation, call analysis and drafting assistance |
| OpenAI / Google Gemini (where configured) | The same content, when selected as the AI provider | Alternative AI provider |
| Deepgram Inc (USA) or Sarvam AI (India), depending on configuration | Audio of recorded calls | Speech-to-text transcription |
| OmniDimension | Name, company, city and phone number of people placed into AI-calling campaigns; call audio, transcript and the agent's notes | Automated outbound AI voice calls |
| Sarvam AI (India) | Name, company, city and phone number of people placed into AI-calling campaigns; call audio, transcript and the agent's notes | Automated outbound AI voice calls |
| Our hosting and email providers | Everything stored on the platform; email addresses and message content | Running the servers and delivering email |
We may also disclose data to legal or regulatory authorities where the law requires it, and to a successor entity in a merger or sale of the business, with notice to you where required.
[LEGAL REVIEW — the periods below are engineering proposals. Section 8(7) requires erasure once the purpose is served and no law requires retention. None of these periods is automatically enforced yet; see section 9.]
| Data | Proposed retention | Why that long |
|---|---|---|
| Account and subscription records | While your account is active, then 3 years | Renewals, disputes, and limitation periods |
| Invoices, GST and payment records | 8 years | Required by Indian tax law |
| Enquiries and CRM leads that never converted | 3 years from last contact | Sales follow-up cycles |
| Newsletter subscription | Until you withdraw consent | Consent is the only basis |
| Call recordings, transcripts and AI summaries | 12 months | Coaching and dispute resolution; the mobile app already refuses to import anything older |
| AI voice call recordings, transcripts and agent notes | Recording links 180 days, transcripts and notes 12 months, cleared automatically; the outcome (for example "interested") is kept with the enquiry | Reviewing the call and handing it to the right salesperson [LEGAL REVIEW — periods are admin settings; keep this row in step with them] |
| WhatsApp conversation history | 2 years | Service history |
| Login logs, activity logs and security alerts | 12 months | Investigating account abuse |
| Consent records | 3 years after the consent ends | Section 6 requires us to be able to demonstrate consent even after it is withdrawn |
As a Data Principal you have the right to:
You also have duties under Section 15 — most practically, not to give us false particulars or impersonate someone else when making one of these requests.
We aim to respond within 30 days. We will verify that the request is genuinely yours before we act on it — particularly for erasure, because acting on an unverified request would mean deleting someone else's data for them.
[LEGAL REVIEW — a named individual must be appointed and published here. Section 13(3) requires the Officer's contact details to be published, and a role-only mailbox may not satisfy that.]
Our project and tender intelligence includes the names, designations and business contact details of people at project-owning organisations, compiled from public records, tender portals and our own research. Those people did not give us that data directly.
[LEGAL REVIEW — this is the single most significant open question in this notice. The DPDP Act has a narrow "publicly available data" carve-out in Section 3(c)(ii), and it turns on whether the individual themselves made the data public. Whether our sourcing falls inside it, and what notice we owe these individuals if it does not, needs counsel's view before this paragraph is finalised.]
If you are one of these individuals and want your details corrected or removed, use the data-rights form — you do not need an account with us.
Section 8(5) requires us to take reasonable security safeguards. We use role-based access control, hashed passwords, two-factor authentication for staff accounts, session hardening, per-user data scoping, and monitoring for bulk-export abuse.
We are also candid that our security work is ongoing: a hardening programme covering transport security headers, site-wide CSRF enforcement, login rate limiting and encryption of sensitive stored fields is in progress and not complete. No system is perfectly secure, and we do not claim ours is.
If we suffer a personal data breach we will notify the Data Protection Board of India and every affected Data Principal, as Section 8(6) requires.
We will update this notice when what we do changes. The version number and date at the top change with it, and consent records store the version you were shown, so we can always tell which notice applied to you. Material changes will be brought to your attention in the product.
General queries: info@projectsinindia.ai. Privacy and data-rights queries go to the Grievance Officer in section 7. Postal address: Venturous Advisory Solutions Pvt Ltd, A/309, Centrum Business Square, Road No 16, Wagle Industrial Estate, Thane (W) – 400604, Maharashtra, India.