TUVASIA

Responsible AI & DPDPA Privacy

AI-Assisted Services, Responsible AI, Information Security, Privacy and Data Protection

1. Purpose and General Principle

The Consultant may use technology-enabled tools, including Artificial Intelligence (AI), Machine Learning (ML), Generative AI, automation, analytics and other digital technologies, where considered appropriate to support the efficient and effective delivery of professional services under this Agreement.

Such technologies shall be used as assistive capabilities within the Consultant's professional methodology and shall not, by themselves, constitute delegation of the Consultant's professional responsibility, professional judgement, contractual obligations or accountability to an AI system or technology provider.

The Consultant shall apply a risk-based and proportionate approach to the use of such technologies, having regard to the purpose, context, sensitivity, potential impact and nature of the relevant activity.

2. AI-Assisted Activities

AI-enabled or technology-assisted activities may include, without limitation:

  • research and information analysis;
  • document drafting and refinement;
  • summarisation and knowledge support;
  • analysis of structured information;
  • preparation of training and awareness material;
  • development of checklists, templates and working material;
  • audit planning and preparation support;
  • identification of potential risks, controls and improvement opportunities;
  • analysis and classification of information;
  • quality review and consistency checks;
  • productivity and workflow support; and
  • other activities reasonably associated with the delivery of professional services.

The extent to which AI or other technology is used may vary depending upon the engagement, service requirements, available technology, confidentiality requirements and risk considerations.

3. Human Oversight and Professional Judgement

AI-generated or AI-assisted outputs shall be regarded as supporting inputs and not as an independent source of professional determination.

The Consultant shall retain appropriate human oversight and professional judgement in reviewing, interpreting, validating and, where necessary, modifying outputs used in the delivery of services.

Final professional conclusions, audit observations, recommendations, opinions, assessments and deliverables remain subject to appropriate human review.

The Consultant shall not knowingly rely solely upon an AI-generated output where professional judgement, verification, independent assessment or objective evidence is reasonably required by the nature of the engagement.

4. Information Security

The Consultant shall apply reasonable and appropriate information-security safeguards to information processed in connection with the services, having regard to the nature, sensitivity and risk associated with such information.

Where applicable, the Consultant's information-security practices may be aligned with or informed by the principles and controls of ISO/IEC 27001 – Information Security Management Systems (ISMS), including consideration of:

  • confidentiality;
  • integrity;
  • availability;
  • access control;
  • information classification;
  • secure handling of information;
  • authentication and authorization;
  • protection against unauthorized access or disclosure;
  • incident management;
  • business continuity considerations; and
  • supplier and third-party security considerations.

The Consultant shall apply such controls as are appropriate and proportionate to the nature of the engagement and information being processed.

Nothing in this clause shall be interpreted as a representation that every control or requirement of ISO/IEC 27001 is applicable to, implemented for or certified in respect of every engagement unless expressly stated in the applicable SOW.

5. Privacy and Personal Data Protection

Where personal data is encountered, received, accessed or otherwise processed in connection with the services, the Consultant shall apply appropriate privacy and data-protection safeguards proportionate to the nature and sensitivity of the information and the applicable legal and contractual requirements.

Where applicable, privacy management practices may be aligned with or informed by ISO/IEC 27701 – Privacy Information Management Systems (PIMS), including appropriate consideration of:

  • privacy governance;
  • purpose limitation;
  • data minimisation;
  • lawful and transparent processing;
  • access and correction mechanisms;
  • retention and deletion;
  • privacy risk management;
  • data-subject/Data Principal rights;
  • processor/third-party considerations;
  • information-security controls supporting privacy; and
  • management of privacy incidents and requests.

The Consultant shall process personal information only to the extent reasonably necessary for the relevant professional, contractual, administrative or legally permissible purpose.

6. Categories of Personal Data

Depending upon the nature of the engagement and services requested, personal data that may be encountered or processed may include, where relevant and legitimately required:

Identity and Contact Information

  • Full Name;
  • Email Address;
  • Phone Number;
  • Physical Address;
  • Aadhaar or other Government-issued Identification information, where lawfully required and specifically authorized.

Financial Information

  • Bank Account information;
  • Payment and billing information;
  • Credit or debit card information, where applicable;
  • Other information reasonably necessary for payment processing or financial administration.

Digital and Location Information

  • Location Data, including GPS or IP Address information where technically collected or required;
  • Browsing, access and usage information;
  • Device, system or technical information associated with service use, where applicable.

Employment and Professional Information

  • Employment information;
  • Designation and organizational information;
  • Professional qualifications or competency information;
  • Training, assessment or certification-related information, where applicable.

Other Information

  • Information provided by the Data Principal or Client in connection with the services;
  • Information contained in documents, records, evidence or communications supplied for the engagement;
  • Any other category of personal data reasonably necessary for the specified purpose and permitted under applicable law.

The actual categories of personal data processed shall depend upon the scope and nature of the applicable engagement and shall not be interpreted as an obligation to collect or process all categories listed above.

7. Purposes of Processing

Personal data may be processed, where applicable and reasonably necessary, for one or more of the following purposes:

  • Service Delivery and Performance;
  • Account Management and Maintenance;
  • Payment Processing and Billing;
  • Customer Support and Assistance;
  • Legal and Regulatory Compliance;
  • Contractual administration and fulfilment;
  • Audit, assessment, certification-support or consultancy activities;
  • Training, competency and professional development activities;
  • Information security and access management;
  • Quality management and service improvement;
  • Analytics and Business Insights;
  • Research and Product Development, where applicable;
  • Marketing and Promotional Activities, where separately permitted and appropriately controlled;
  • Sharing with authorized third-party service providers supporting the delivery or administration of services;
  • Fraud prevention, security monitoring and incident management;
  • Maintenance of professional, contractual, financial and statutory records; and
  • Other purposes communicated to the relevant Data Principal or Client and permitted under applicable law.

Personal data shall not be processed for an unrelated purpose merely because it has become available to the Consultant.

8. Lawful Basis, Notice and Consent

Where processing is based upon consent, the Consultant shall seek consent in an appropriate manner and shall process personal data consistently with the relevant notice, consent and applicable legal requirements.

Where processing is undertaken on another lawful basis permitted under applicable law, processing may occur without relying upon consent where such processing is legally permitted or required.

Nothing in this Agreement shall be interpreted as requiring consent where applicable law provides another lawful basis for processing.

Where consent is relied upon, the relevant Data Principal may withdraw consent in accordance with applicable law and the applicable procedure communicated by the Consultant.

Withdrawal of consent shall not affect the lawfulness of processing undertaken prior to such withdrawal and shall be subject to any lawful retention or processing requirement applicable to the Consultant or Client.

9. India – Digital Personal Data Protection Requirements

Where applicable to the relevant processing activity, the Consultant shall have regard to the Digital Personal Data Protection Act, 2023 (DPDP Act), the Digital Personal Data Protection Rules, 2025, and applicable amendments, notifications, directions or subordinate requirements issued by the Government of India from time to time.

The Consultant shall adopt reasonable and appropriate measures, proportionate to the applicable processing activity, to support compliance with relevant requirements concerning:

  • processing of digital personal data;
  • specified and legitimate purposes;
  • appropriate notice and transparency;
  • consent and withdrawal of consent, where applicable;
  • reasonable security safeguards;
  • personal data breach management;
  • retention and erasure;
  • Data Principal requests and rights;
  • grievance redressal;
  • management of processors and third parties; and
  • other applicable obligations under the DPDP framework.

The Consultant's obligations under this clause shall be determined by its actual role in the relevant processing activity, including whether it acts as a Data Fiduciary, Data Processor or in another capacity under applicable law.

The parties shall cooperate reasonably where information or assistance is required to fulfil an applicable legal or contractual obligation.

10. Data Principal Rights

Where applicable under the DPDP Act and Rules, the Consultant shall provide appropriate mechanisms for the exercise of applicable Data Principal rights.

Such rights include, subject to applicable conditions and procedures:

Right to Information

The Data Principal may have the right to obtain information concerning processing of their personal data, including applicable information regarding the personal data being processed and processing activities, in accordance with applicable law.

Right to Correction, Completion and Updating

A Data Principal may request correction of inaccurate or misleading personal data, completion of incomplete personal data and updating of personal data, subject to applicable requirements.

Right to Erasure

A Data Principal may request erasure of personal data where applicable.

Erasure shall remain subject to lawful retention requirements, contractual obligations, statutory requirements, legitimate record-keeping requirements and other circumstances in which retention is legally permissible or required.

Right to Grievance Redressal

The Data Principal shall have access to the applicable grievance redressal mechanism established by the Consultant or relevant Data Fiduciary, subject to the applicable legal framework.

Right to Nominate

Where applicable, a Data Principal may exercise the right to nominate another individual in accordance with the procedure prescribed under applicable law.

The exercise of these rights shall be subject to applicable identity verification, procedural requirements, legal exceptions, retention obligations and any other conditions prescribed by applicable law.

11. No Overstatement of Data Principal Rights

For avoidance of doubt, the Consultant shall not be contractually deemed to provide rights beyond those required under applicable law.

In particular, references to data portability, a general right to object, or other privacy rights shall not be interpreted as statutory rights under the DPDP Act unless such rights are expressly provided under applicable law or separately agreed by the parties.

Where another applicable privacy or data-protection law provides additional rights, the parties shall consider such requirements to the extent applicable to the relevant processing activity.

12. Data Minimisation and Sensitive Information

The Consultant shall seek to limit the collection, access, use and disclosure of personal information to information reasonably necessary for the relevant purpose.

The Consultant shall not intentionally request or process Aadhaar numbers, government identification information, financial information, health information, biometric information, authentication credentials or other high-risk personal information through AI-enabled tools merely for convenience where such information is not reasonably necessary for the relevant professional activity.

Where such information is necessary, appropriate safeguards shall be considered based upon the nature of the information, applicable law, contractual requirements and the relevant processing environment.

13. AI and Personal Data

Where AI-enabled tools are used in connection with personal data, the Consultant shall consider, as appropriate:

  • whether the processing is necessary for the intended purpose;
  • whether personal data can reasonably be minimised, masked, anonymised or pseudonymised;
  • whether the AI service is appropriately authorized for the intended use;
  • confidentiality and access controls;
  • applicable data-retention arrangements;
  • whether submitted information may be used by the service provider for model training or other secondary purposes;
  • applicable contractual restrictions;
  • privacy and security risks;
  • potential bias or discriminatory outcomes;
  • accuracy and reliability of AI outputs; and
  • the potential impact of AI-assisted processing on individuals.

Where practicable and appropriate, personal information that is not necessary for the intended AI-assisted activity should not be included in the input provided to an AI-enabled service.

14. Confidentiality and Client Information

Confidential, proprietary, personal, sensitive, regulated or otherwise restricted information shall be handled in accordance with applicable contractual requirements, confidentiality obligations, information-security requirements and applicable laws and regulations.

The Consultant shall not intentionally expose Client information to an AI service where such use would be inconsistent with:

  • the Client's documented contractual restrictions;
  • applicable law or regulation;
  • agreed confidentiality obligations;
  • information-security requirements; or
  • established internal controls.

Where Client-specific restrictions are communicated in writing, the Consultant shall take them into consideration in determining the appropriate technology and methodology for the engagement.

15. Third-Party Technology and Service Providers

The Consultant may use third-party technology providers, cloud services, software platforms and AI-enabled services where such services support the delivery or administration of the engagement.

The Consultant shall exercise reasonable diligence in selecting and using such services, taking into consideration relevant security, privacy, confidentiality, data-processing, reliability and contractual considerations.

Where third-party technology is used, the Consultant may rely upon the security, privacy and operational controls represented or provided by the applicable service provider, to the extent reasonably available and within the Consultant's control.

The Consultant shall not be deemed responsible for changes, failures, vulnerabilities, service interruptions or processing practices of a third-party provider that are outside the Consultant's reasonable control, except to the extent otherwise expressly agreed or required by applicable law.

16. Information Security and Privacy Incidents

The Consultant shall maintain processes appropriate to identify, manage and respond to information-security, privacy and personal-data incidents relevant to its role and responsibilities under the engagement.

Where an incident materially affects Client information or triggers a notification obligation applicable to the Consultant, the Consultant shall provide appropriate notification and cooperation in accordance with the applicable Agreement, SOW and legal requirements.

The Consultant shall not be responsible for incidents caused exclusively by Client systems, Client personnel, Client-appointed third parties or circumstances outside the Consultant's reasonable control, except to the extent otherwise required by applicable law or expressly agreed in the Agreement.

17. Audit and Assessment Activities

Where the Consultant performs audit, assessment, verification or assurance-related activities, AI-enabled tools may be used to support planning, preparation, research, analysis, documentation, checklist development, working-paper preparation or quality review.

AI shall not independently determine:

  • conformity or nonconformity;
  • certification status;
  • legal compliance;
  • regulatory compliance;
  • audit conclusions; or
  • final professional opinions.

Audit and assessment conclusions shall be based upon appropriate evidence, applicable criteria, professional methodology and professional judgement.

Objective evidence, applicable standards, regulatory requirements, Client records and professional audit judgement shall take precedence over unverified AI-generated content.

18. Responsible and Ethical AI

Where AI-enabled technologies are used, the Consultant shall seek to apply appropriate principles of responsible, ethical and trustworthy AI, including, where relevant:

  • human oversight and accountability;
  • transparency proportionate to the activity;
  • confidentiality and privacy;
  • information security;
  • reliability and appropriate verification;
  • consideration of accuracy and relevance;
  • consideration of potential bias;
  • appropriate risk management;
  • proportionality;
  • compliance with applicable law and contractual obligations; and
  • consideration of reasonably foreseeable adverse impacts.

The nature and extent of such controls shall be risk-based and proportionate to the purpose, context, technology and potential impact of the activity.

19. ISO/IEC 42001 Alignment

Where relevant to the services, the Consultant may apply principles and practices informed by ISO/IEC 42001 – Artificial Intelligence Management System (AIMS).

Such practices may include consideration of:

  • AI governance;
  • AI risk assessment and treatment;
  • AI impact considerations;
  • human oversight;
  • responsible AI principles;
  • transparency and accountability;
  • data governance;
  • AI system lifecycle considerations;
  • supplier and third-party considerations;
  • monitoring and continual improvement.

Unless expressly stated in the applicable SOW, references to ISO/IEC 42001 shall not constitute a representation that the Consultant or any Client AI system is certified to ISO/IEC 42001 or that the Consultant is providing an independent certification or conformity assessment against that standard.

20. ISO/IEC 27001 and ISO/IEC 27701 Alignment

Where relevant, the Consultant may apply information-security and privacy-management practices informed by ISO/IEC 27001 and ISO/IEC 27701, respectively.

These references are intended to establish a risk-based management approach and shall not, unless expressly stated in the applicable SOW, create an obligation that every control contained within either standard applies to every engagement.

Where a specific certification, conformity assessment, audit or implementation requirement is included in the SOW, the applicable scope, criteria and deliverables shall be determined separately.

21. AI Output Limitations

The Consultant recognizes that AI systems may produce inaccurate, incomplete, outdated, biased, misleading or otherwise unsuitable information.

Accordingly, AI-assisted content may be subject to appropriate review, validation, cross-checking against authoritative sources, professional assessment and contextual interpretation before incorporation into final deliverables, where the nature and materiality of the output warrant such review.

The Consultant does not warrant that any third-party AI system, AI model or AI-generated output is completely accurate, unbiased, error-free, secure, uninterrupted or free from inherent limitations.

22. Scope of AI Disclosure

The Client acknowledges that AI-enabled functionality may form part of the Consultant's internal professional methodology, productivity environment and supporting work processes.

Unless otherwise required by applicable law, regulation, accreditation requirements, contractual terms or the specific SOW, the Consultant is not required to disclose every instance, tool, prompt, model, algorithm, software feature or internal workflow involving AI assistance, provided that such use remains consistent with the Consultant's applicable confidentiality, information-security, privacy, professional, contractual and legal obligations.

Where the Client requires disclosure of material AI use, the parties may agree the appropriate level, format and scope of disclosure as part of the applicable SOW.

For avoidance of doubt, use of ordinary software functionality incorporating embedded AI features shall not automatically create an obligation to separately identify every such feature unless disclosure is required by applicable law, regulation, contractual terms, accreditation requirements or the agreed SOW.

23. Client Responsibility

The Client remains responsible for:

  • providing accurate and complete information required for the services;
  • identifying Client-specific restrictions concerning AI, information security or privacy;
  • determining the lawfulness and appropriateness of information supplied to the Consultant;
  • obtaining any permissions, notices or consents that are the Client's responsibility;
  • decisions taken by the Client based upon Consultant deliverables; and
  • AI systems, models, datasets, applications and technology environments owned, operated or controlled by the Client or another third party.

The Consultant shall not be responsible for consequences arising from information supplied by the Client that is inaccurate, incomplete, misleading or not appropriately authorized for use.

24. Limitation Relating to AI, Security and Privacy

The Consultant shall remain responsible for the professional services expressly undertaken under the Agreement and applicable SOW.

However, to the extent permitted by applicable law and subject to the liability provisions of the Agreement, the Consultant shall not be responsible for:

  • inherent limitations or unexpected behaviour of third-party AI systems;
  • hallucinations or inaccuracies generated by third-party AI systems;
  • changes to third-party AI models, algorithms, policies or functionality;
  • security or privacy incidents originating solely within third-party platforms outside the Consultant's reasonable control;
  • unauthorized use of AI tools by Client personnel or third parties;
  • Client-controlled AI systems, applications or datasets;
  • decisions independently taken by the Client based upon AI-assisted information; or
  • consequences arising from Client-provided information that is inaccurate, incomplete, misleading or unauthorized.

Nothing in this clause shall exclude or limit liability to the extent such exclusion or limitation is prohibited by applicable law or expressly overridden by the Agreement.

25. Regulatory and Legal Change

The Consultant may periodically review and update its practices relating to AI, information security, privacy and data protection in response to changes in technology, emerging risks, applicable legislation, regulatory guidance, recognized standards and professional good practice.

References in this clause to the DPDP Act, 2023, DPDP Rules, 2025, ISO/IEC 42001, ISO/IEC 27001 and ISO/IEC 27701 shall be understood as references to the applicable versions, amendments, replacements or legally applicable requirements from time to time.

Where a change in applicable law, regulation, Client requirement or agreed control materially affects the scope, methodology, effort, resources, timelines or cost of the services, the parties may mutually agree an appropriate adjustment to the applicable SOW.

26. No Independent Regulatory or Certification Assurance

Unless expressly stated in the applicable SOW, this clause does not constitute:

  • a legal opinion;
  • regulatory certification;
  • certification against ISO/IEC 42001, ISO/IEC 27001 or ISO/IEC 27701;
  • independent assurance that an AI system complies with all requirements of the EU AI Act or any other AI regulation;
  • independent assurance that a Client's processing activities comply with all requirements of the DPDP Act or other privacy legislation; or
  • a representation that every AI, information-security or privacy risk has been identified or eliminated.

The Consultant's obligations shall remain limited to the professional services, deliverables, scope and responsibilities expressly agreed under the applicable Agreement and SOW.

Privacy Notice under Section 5 of The DPDPA, 2023

Last Updated: 05/09/2026

1. Introduction & Applicability

This Privacy Notice has been prepared in accordance with the Digital Personal Data Protection Act, 2023 (hereinafter referred to as "DPDPA" or "the Act") and the rules framed thereunder.

This notice is applicable to Company, operating as per this website name, in the Other sector.

2. Categories of Personal Data

We collect the following categories of personal data from Data Principals:

  • Full Name
  • Email Address
  • Phone Number
  • Physical Address
  • Aadhaar/Government ID
  • Financial Data (Bank Account, Credit Card Info)
  • Location Data (GPS, IP Address)
  • Browsing and Usage Data
  • Employment Information
  • Other Data Types

3. Purpose of Processing

The personal data is processed for the following purposes:

  • Service Delivery and Performance
  • Account Management and Maintenance
  • Payment Processing and Billing
  • Marketing and Promotional Activities
  • Analytics and Business Insights
  • Legal and Regulatory Compliance
  • Customer Support and Assistance
  • Research and Product Development
  • Sharing with Third-party Service Providers

4. Consent Statement

By using our services and providing personal data, Data Principals provide explicit consent for the processing of their personal data as outlined in this notice. Consent can be withdrawn at any time by contacting our Grievance Officer.

5. Rights of Data Principal

Under the DPDPA, 2023, Data Principals have the following rights:

  • Right to Access: Data Principals can request access to their personal data held by us.
  • Right to Correct: Data Principals can request correction of inaccurate or incomplete personal data.
  • Right to Erase: Under certain conditions, Data Principals can request erasure of their personal data.
  • Right to Data Portability: Data Principals can request their personal data in a structured, commonly used, machine-readable format.
  • Right to Object: Data Principals can object to processing of their personal data.

6. Grievance Redressal Mechanism

In case of any concerns or grievances regarding the processing of personal data, Data Principals can contact our Grievance Officer:

  • Name: DPO
  • Email: as per the contact us page of website
  • Response Time: We aim to respond to all grievances within 30 days of receipt.

7. Data Retention

Personal data will be retained as long as it is necessary to serve the purposes for which it was collected. Once the purposes are fulfilled, the data will be securely deleted unless retention is required by law.

8. Cross-border Transfer of Personal Data

Personal data may be transferred to countries outside India. Such transfers are conducted in compliance with the DPDPA and applicable international data transfer agreements. Data Principals will be informed of any such transfers.

10. Updates & Changes to this Notice

We reserve the right to update this Privacy Notice from time to time to reflect changes in our data processing practices or applicable laws. Data Principals will be notified of any material changes through our website or direct communication.

Disclaimer

This Privacy Notice is generated for informational purposes. It does not constitute legal advice. Organizations should consult with qualified legal professionals to ensure full compliance with the Digital Personal Data Protection Act, 2023, and all applicable regulations.

Legal Framework

This Privacy Notice is framed in accordance with:

  • Digital Personal Data Protection Act, 2023
  • Digital Personal Data Protection Rules, 2025
  • Guidelines issued by the Data Protection Board of India

Authorization

This Privacy Notice has been reviewed and authorized for publication by the undersigned authorized officer of the organization.

Signature
Authorized Officer / Data Protection Officer

Official Seal

Date
Place:

Generated on 05/09/2026 | Organization: Company | Language: English

Our Clients

meet our team

Steven Marks

CEO

Lara Smith

CTO

John Doe

COO