Legal

Privacy Policy

How Miracuves Solutions Private Limited collects, uses, shares, protects, and retains personal data — and the rights you have over it. This policy also sets out our data processing terms for clients whose platforms we build.

Effective August 5, 2026  ·  Last reviewed August 5, 2026

A · About this policy

1. Introduction and scope

Miracuves Solutions Private Limited ("Miracuves", "we", "us", "our") respects your privacy. This policy explains how personal data is collected, used, shared, protected, and retained across our website, applications, APIs, services, and business operations, and sets out the rights available to you.

It applies to: visitors to our websites and landing pages; clients, partners, vendors, and contractors; users of our software, dashboards, and APIs; leads and marketing contacts; and support communications, tickets, chats, and calls.

2. Who we are and how to contact us

Miracuves Solutions Private Limited, registered office Mumbai, Maharashtra, India, is the entity responsible for personal data described in this policy where we act as a Data Fiduciary or Controller.

PurposeContact
Privacy and data protection enquiriesprivacy@miracuves.com
Data Protection Officerdpo@miracuves.com
Grievance Officer (DPDP Act, 2023)grievance@miracuves.com

3. Definitions

Personal Data — any information relating to an identified or identifiable individual. Sensitive Personal Data — financial data, credentials, government identifiers, biometric or health data. Client Data — data submitted or processed on behalf of a client. Processing — any operation on data, including collection, access, storage, logging, analysis, transmission, and deletion.

Data Fiduciary / Controller — the party determining the purposes and means of processing. Data Processor — the party processing data on the instructions of the Data Fiduciary. Data Principal / Data Subject — the individual to whom the personal data relates.

4. Our two roles

As Data Fiduciary / Controller. For our own website visitors, enquiries, clients, vendors, and staff, we determine why and how personal data is processed. This policy governs that processing.

As Data Processor. Where we build or maintain a platform for a client, the client is the Data Fiduciary / Controller for the personal data of their end users, and we act as processor on their instructions. Clauses 26 and 27 apply.

5. Relationship to our other terms

This policy sits alongside our Terms & Conditions, End User Licence Agreement, Support Policy, Refund Policy, and Legal Notice & Disclaimer. Where a signed agreement, Master Service Agreement, Statement of Work, or Data Processing Agreement governs a specific engagement, that agreement prevails in respect of its subject matter.

B · What we collect

6. Information you provide

  • Identity and contact details — name, email, phone, company, role, country;
  • Business, contractual, and billing information;
  • Project specifications, documentation, and technical requirements;
  • Credentials and access details you supply for deployment or configuration;
  • Communications and correspondence, including support tickets, chats, and call notes.

7. Information collected automatically

  • IP address, device identifiers, operating system, and browser details;
  • Server logs, access logs, and audit trails;
  • Usage metrics and feature interactions;
  • Error logs, diagnostics, and performance metrics;
  • Security and authentication events.

8. Information from third parties

We may receive data from cloud and hosting providers, payment processors and financial institutions, analytics and monitoring tools, public professional platforms, and legal or regulatory authorities. We take reasonable steps to verify such data but are not responsible for inaccuracies originating from third-party sources.

9. Cookies and similar technologies

CategoryPurpose
Strictly necessarySecurity, sessions, consent recording. Cannot be disabled.
FunctionalRemembering preferences and settings.
AnalyticsMeasuring performance and understanding usage.
MarketingCampaign measurement, where you have consented.

You may manage cookies through your browser settings or any consent tool presented on our website. Blocking cookies may affect functionality.

C · How and why we use it

10. Legal bases for processing

We process personal data on one or more of the following bases, determined and documented before processing begins:

  • Contractual necessity — to provide services you have requested;
  • Legal obligation — tax, accounting, and regulatory requirements;
  • Consent — where required, and freely given, specific, informed, and unambiguous. You may withdraw consent at any time, without affecting processing carried out before withdrawal;
  • Legitimate interests — operating and improving our business, where not overridden by your rights and freedoms;
  • Security and fraud prevention;
  • Legal claims — establishing, exercising, or defending claims.

Where processing rests on legitimate interests, we carry out a balancing assessment and will describe it on request.

11. Purposes of processing

  • Service delivery, deployment, maintenance, and support;
  • Responding to enquiries and providing proposals;
  • Billing, invoicing, accounting, and audit;
  • Security monitoring, abuse detection, and risk management;
  • Quality assurance and internal analytics;
  • Business operations, continuity, and improvement;
  • Legal compliance and dispute resolution.

We may anonymise or aggregate data so that it no longer identifies any individual, and use it for analysis and service improvement.

12. Marketing communications

Where we send marketing communications, we do so on the basis of consent or legitimate interest as permitted by applicable law. Every marketing message includes an unsubscribe link, and you may opt out at any time by using it or by writing to privacy@miracuves.com. Opting out of marketing does not stop service or transactional messages relating to an active engagement.

13. Automated decision-making and AI

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, without human involvement.

Some of our products and internal tools incorporate machine learning or generative AI components. Where such components are used in delivering services to you, output is reviewed by a person before it is relied upon. Where a client enables AI features in their own platform, the client is responsible for their configuration, supervision, and disclosure to end users.

D · Sharing and transfers

14. Who we share data with

We share personal data only as necessary, with: cloud and infrastructure providers; payment and financial processors; analytics, security, and monitoring vendors; professional advisors; and regulators or law enforcement where legally required.

We may also disclose data where necessary to protect our legal rights, intellectual property, systems, or personnel, or to comply with a binding legal obligation.

15. Sub-processors

Where we act as processor for a client, the client authorises us to engage sub-processors necessary to deliver the services. We impose data protection obligations on sub-processors that are equivalent to those we owe, and remain responsible for their performance. A current list of sub-processors is available on request to dpo@miracuves.com.

16. International transfers

We operate internationally, and personal data may be processed in India, the European Economic Area, the United Kingdom, the United States, and other jurisdictions where we or our providers operate.

Where personal data is transferred out of the EEA or UK, we rely on a legally recognised transfer mechanism — an adequacy decision, Standard Contractual Clauses, the UK International Data Transfer Addendum, or another approved safeguard — together with supplementary measures where appropriate.

Where personal data is transferred out of India, we comply with the requirements of the Digital Personal Data Protection Act, 2023 and any restrictions notified under it.

You may request details of the safeguards applied by writing to dpo@miracuves.com.

17. We do not sell personal data

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising as those terms are defined under United States state privacy laws. We have not done so in the preceding twelve months.

E · Your rights

18. Your rights — India (DPDP Act, 2023)

If you are a Data Principal under the Digital Personal Data Protection Act, 2023, you have the right to:

  • Obtain confirmation of, and access to, your personal data being processed;
  • Correction, completion, updating, and erasure of your personal data;
  • Grievance redressal (see clause 22);
  • Nominate another individual to exercise your rights in the event of death or incapacity;
  • Withdraw consent where processing rests on consent.

19. Your rights — EEA and UK (GDPR)

If you are in the European Economic Area or the United Kingdom, you have the right under the General Data Protection Regulation to:

  • Access — obtain a copy of your personal data;
  • Rectification — correct inaccurate or incomplete data;
  • Erasure — request deletion in defined circumstances;
  • Restriction — limit how we process your data;
  • Portability — receive your data in a structured, machine-readable format;
  • Object — to processing based on legitimate interests, and to direct marketing at any time;
  • Withdraw consent at any time;
  • Lodge a complaint with your local supervisory authority.

20. Your rights — United States

Depending on your state of residence, you may have the right to know what personal data we collect and how it is used; to access and obtain a copy; to request correction or deletion; to opt out of sale or sharing for targeted advertising (we do neither — see clause 17); to limit use of sensitive personal information; and not to be discriminated against for exercising these rights.

21. How to exercise your rights

Write to privacy@miracuves.com or dpo@miracuves.com, stating the right you wish to exercise and enough information for us to identify you.

We respond within 30 days, or sooner where the law requires. If a request is complex we may extend this and will tell you why. We may need to verify your identity before acting, and we may decline a request that is manifestly unfounded, excessive, or that would infringe another person's rights — explaining our reasoning if we do.

Exercising your rights is free of charge.

Where your data was provided to us by a client for whom we act as processor, we will refer your request to that client, who is responsible for responding, and will assist them as required.

22. Grievance redressal

In accordance with the Digital Personal Data Protection Act, 2023, we have appointed a Grievance Officer. If you are dissatisfied with how your personal data has been handled or how a request was answered, contact:

Grievance Officer
grievance@miracuves.com
Miracuves Solutions Private Limited, Mumbai, Maharashtra, India

We acknowledge grievances promptly and aim to resolve them within 30 days. If you remain dissatisfied, you may escalate to the Data Protection Board of India or, if you are in the EEA or UK, to your local supervisory authority.

F · Security, retention and incidents

23. Security measures

  • Encryption in transit, and encryption at rest where supported;
  • Role-based access control on a least-privilege basis;
  • Logging, monitoring, and audit trails;
  • Credential management and periodic access review;
  • Incident response and containment procedures;
  • Contractual security obligations on sub-processors.

No system can be guaranteed completely secure. We maintain measures appropriate to the risk, but cannot warrant absolute security.

24. Data retention

CategoryRetention
Client DataPer contract, then deleted or returned on request
Financial and tax recordsMinimum 7 years, as required by law
Logs and security recordsUp to 24 months
BackupsPer operational backup cycle, then overwritten
Enquiries and marketing contactsUntil you unsubscribe or ask us to erase

We may retain limited data beyond these periods where necessary to establish, exercise, or defend legal claims, or to comply with a legal obligation.

25. Breach notification

We maintain incident response procedures. Where a personal data breach occurs, we notify affected clients without undue delay, and notify supervisory authorities and affected individuals where the law requires.

Where we act as processor for a client, we notify the client without undue delay on becoming aware, and the client remains responsible for notifying regulators and their end users unless otherwise legally mandated.

G · Client platforms and specific contexts

26. Client platforms and end-user data

Where we build, deploy, or maintain a platform for a client, this clause sets out the data processing terms between us, and forms a Data Processing Agreement unless a separate DPA is signed.

  • Roles. The client is Data Fiduciary / Controller; Miracuves is processor.
  • Instructions. We process Client Data only on the client's documented instructions, save where legally required otherwise.
  • Confidentiality. Personnel with access are bound by confidentiality.
  • Security. We apply the measures in clause 23.
  • Sub-processors. As set out in clause 15.
  • Assistance. We provide reasonable assistance with data subject requests, impact assessments, and regulator engagement, subject to verification, feasibility, and reasonable cost recovery.
  • Deletion or return. On termination we delete or return Client Data on request, save where retention is legally required.
  • Audit. We provide information reasonably necessary to demonstrate compliance.

27. Client responsibilities

As Data Fiduciary / Controller for their platform, the client is responsible for:

  • Ensuring lawful collection and use of Client Data, with a valid basis;
  • Providing privacy notices to, and obtaining consents from, their end users;
  • The accuracy and legality of data supplied to us;
  • Not uploading sensitive personal data unless expressly agreed in writing;
  • Responding to data subject requests from their end users;
  • Notifying regulators and end users of breaches affecting their platform;
  • Configuring retention, access, and security settings appropriately.

Miracuves is not responsible for unlawful Client Data, or for a client's failure to meet its obligations as Data Fiduciary.

28. Mobile application disclosures

Applications we build may collect the categories declared in their App Store and Google Play listings, typically: contact and account information; identifiers and device data; usage and diagnostic data; and, where applicable, financial data.

Such data is used for core app functionality, analytics and improvement, security and fraud prevention, and developer communications. Tracking is enabled only where explicitly declared in the store listing and consented to by the user. The store listing and privacy disclosure for a client's application is the responsibility of that client as publisher of record.

29. Children's data

Our website and services are directed at businesses and are not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@miracuves.com and we will delete it.

Where a client operates a platform accessible to children, the client is responsible for verifiable parental consent and for compliance with the Digital Personal Data Protection Act, 2023, the GDPR, COPPA, and any equivalent local requirement.

30. Third-party links

Our website may link to third-party sites we do not control. This policy does not apply to them, and we are not responsible for their privacy practices. Please read their policies before providing personal data.

H · General

31. Liability

Liability arising in connection with this policy is governed by our Terms & Conditions and, in respect of licensed software, our End User Licence Agreement. Nothing in this policy excludes or limits liability that cannot lawfully be excluded or limited, including under applicable data protection law.

32. Changes to this policy

We may update this policy from time to time. The date shown at the top indicates when it was last revised. Where a change is material, we take reasonable steps to notify you — for example by email or a notice on this website — before it takes effect.

33. Governing law and jurisdiction

This policy is governed by the laws of India, and the courts at Mumbai, Maharashtra, India have exclusive jurisdiction, subject to clause 36 of our Terms & Conditions.

Nothing in this clause affects any mandatory statutory right or remedy available to you under the data protection law of your own country, including your right to complain to a supervisory authority.

Miracuves Solutions Private Limited

Registered office: Mumbai, Maharashtra, India
Privacy: privacy@miracuves.com
Data Protection Officer: dpo@miracuves.com
Grievance Officer: grievance@miracuves.com

CIN: U62099MH2023PTC406639  ·  GST: 27AARCM0726H1ZA  ·  DUNS: 959921093