Statutory Compliance
Adherence to the DPDP Act 2023 and IT Rules 2011, ensuring lawful, fair, and transparent data processing.
Last updated: August 2, 2026
Effective date: August 2, 2026
Welcome to the Privacy Policy of TechnWaves. This document is formulated in strict compliance with the Digital Personal Data Protection (DPDP) Act 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (IT Act 2000), outlining our rigorous data governance framework, security protocols, and your rights as a digital citizen.
At TechnWaves, we operate on the fundamental principle of data minimization and privacy by design. As an essential toolkit for Indian businesses and freelancers, we recognize the critical importance of safeguarding your proprietary information, business calculations, and business documentation.
This policy delineates the modalities of our data handling practices, explicitly mapping to the statutory obligations under the DPDP Act 2023. We ensure that every facet of our platform architecture respects the sanctity of your digital footprint, implementing state-of-the-art client-side processing techniques to prevent unnecessary server-side data retention.
By utilizing our platform, you acknowledge and consent to the practices described herein. We strongly encourage all users to thoroughly review this document to understand the breadth of our security measures and the mechanisms available for exercising your statutory data rights under Indian jurisprudence.
In accordance with the Digital Personal Data Protection (DPDP) Act 2023, TechnWaves operates strictly as a Data Fiduciary only when absolutely necessary, and primarily functions with a zero-knowledge architectural approach for the majority of its utilities. The DPDP Act establishes a framework for the processing of digital personal data, recognizing the right of individuals to protect their personal data and the need to process such data for lawful purposes.
We categorically affirm that your consent is the bedrock of any data processing activity we undertake, howsoever minimal. Under Section 6 of the DPDP Act, we ensure that any consent obtained is free, specific, informed, unconditional, and unambiguous with a clear affirmative action.
Additionally, we strictly adhere to the purpose limitation principle. Any data collected is utilized solely for the explicitly stated purpose and is expunged immediately upon the cessation of that purpose, aligning with the data retention guidelines mandated by the regulatory authorities.
In fulfillment of the mandates prescribed under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, promulgated under the Information Technology Act, 2000, TechnWaves has implemented secure, industry-standard security control measures. These rules necessitate the deployment ofdocumented information security programs and policies that contain managerial, technical, operational, and physical security control measures.
We recognize the distinction between personal information and sensitive personal data or information (SPDI) as defined under Rule 3 of the IT Rules 2011. Our platform is intentionally engineered to avoid the collection, storage, or transmission of SPDI, such as passwords, business information (bank account or payment details), physical, physiological, and mental wellness conditions, sexual orientation, emergency records and history, and biometric information.
In the exceptional event that our support channels incidentally receive such information during a grievance resolution process, it is handled with the utmost confidentiality and subjected to immediate cryptographic sanitization and deletion protocols, ensuring no unauthorized access or disclosure occurs. Our security posture is continuously audited and refined to mitigate emergent cyber threats and vulnerabilities.
The architectural cornerstone of TechnWaves is our unwavering commitment to Client-Side Processing. Unlike traditional cloud-based applications that transmit your inputs to remote servers for computation, our guides execute intricate logic—including invoice generation, tax calculation, and QR code rendering—entirely within the sandboxed environment of your web browser.
This decentralized processing paradigm fundamentally neutralizes the risk of data harvesting. Because your business data, client details, and operational figures never traverse our network infrastructure, they cannot be intercepted, stored, profiled, or monetized by us or any third-party threat actor targeting our servers.
Local Storage mechanisms are employed strictly for your convenience, allowing you to resume sessions without re-entering boilerplate information. This data remains localized on your physical device, governed by your browser's security policies. You retain absolute sovereignty over this data, with the autonomous capability to purge it instantly via your browser settings, ensuring a zero-footprint exit from our platform.
In strict alignment with the statutory requirements of the DPDP Act 2023 and the IT Rules 2011, TechnWaves has instituted a formalized Grievance Redressal Mechanism to address and resolve any concerns regarding your privacy and data protection rights. We recognize the paramount importance of providing a transparent, accessible, and highly responsive channel for Data Principals to exercise their rights and seek remediation for any perceived infractions.
To this end, we have designated a dedicated Grievance Officer, whose contact coordinates are prominently published within this policy. The Grievance Officer is statutorily mandated to acknowledge the receipt of any complaint within 24 hours and to actively investigate, address, and dispose of such grievances within a maximum period of 30 days from the date of its receipt, ensuring expeditious justice and regulatory compliance.
If you believe that your data has been handled in a manner inconsistent with this policy or applicable Indian laws, you are encouraged to initiate a formal complaint by emailing grievance@technwaves.com. Your correspondence must explicitly state the nature of the grievance, the specific data points in question, and any supporting evidence, which will be treated with absolute confidentiality during the investigative process.
To further expand on our commitment to data security, we enforce rigorous data minimization protocols across all operational vectors. This means we deliberately constrain our systemic capabilities to collect only the absolute minimum telemetry required to maintain service availability and diagnose critical infrastructural anomalies.
We do not engage in the aggregation of behavioral metadata, device fingerprinting, or cross-site tracking methodologies that are prevalent in the industry. Additionally, our platform architectures and security practices are subjected to periodic scrutiny by independent cybersecurity auditors to ensure our assertions of client-side processing and zero-knowledge storage remain cryptographically verifiable and technically sound.
Adherence to the DPDP Act 2023 and IT Rules 2011, ensuring lawful, fair, and transparent data processing.
Advanced browser-based execution prevents data harvesting by keeping your sensitive inputs locally secured on your device.
A formal, rapid-response mechanism for addressing privacy concerns and facilitating your rights as a Data Principal.