PRAVYAGLOBAL

Legal

Privacy Policy

Effective date
27 August 2026
Version
1.0
Published by
Pravya Global
Contact
pravyaglobal1810@gmail.com

Summary

This website does not use cookies for analytics or advertising, does not store IP addresses, and does not disclose personal data to advertisers or data brokers. The only personal data processed is that which a visitor voluntarily submits through a comment, a newsletter subscription, or the contact form.

This summary is provided for convenience only. It does not form part of this document and does not limit or vary the terms set out below.

1. Introduction and scope

  1. This Privacy Policy (the “Policy”) describes how Pravya Global (“we”, “us”, “our”) collects, uses, discloses and retains Personal Data in connection with this website and the services made available through it (together, the “Site”).
  2. This Policy applies to all visitors to the Site. It does not apply to any third-party website, service or platform that may be linked from or embedded within the Site, each of which is governed by its own privacy notice.
  3. By using the Site you acknowledge that you have read this Policy. Where your consent is required for a particular processing activity, that consent is obtained separately and expressly, and may be withdrawn at any time in accordance with clause 8.

2. Definitions

Personal Data
Any information relating to an identified or identifiable natural person, as that term (or its equivalent, including “personal information”) is defined under applicable data protection law.
Processing
Any operation performed on Personal Data, including collection, recording, storage, use, disclosure, erasure and destruction.
Controller
The person who determines the purposes and means of the Processing. For the purposes of this Policy, the Controller is Pravya Global.
Processor
A person who processes Personal Data on behalf of the Controller and on its documented instructions.
Data Subject
An identified or identifiable natural person to whom Personal Data relates.
Aggregate Data
Data recorded as numerical counts that is not associated with, and cannot reasonably be used to identify, any individual.

3. Identity and contact details of the Controller

  1. The Controller is Pravya Global. All correspondence relating to this Policy, including requests to exercise the rights described in clause 8, should be addressed to pravyaglobal1810@gmail.com.
  2. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”). The contact address in clause 3.1 is the appropriate point of contact for all data protection matters.

4. Measurement of Site usage

  1. We operate a first-party measurement facility for the purpose of understanding how the Site is used. That facility is designed so that it does not collect or retain Personal Data.
  2. Data recorded. For each interaction, the following items are recorded as counters: the page path requested; the type of interaction (a page view, or an action such as copying a code block, commencing playback of audio or video, opening an embedded player, activating a link or share control, applying a “like”, or reaching a scroll position within an article); the hostname (but not the full address) of any referring website; campaign parameters where present in the requesting address (utm_source, utm_medium, utm_campaign); generalised technical categories comprising device class, browser family and operating system family; a country code where one is supplied by the network infrastructure serving the request; and the calendar date.
  3. Data not recorded. The following are not written to any record under our control: your Internet Protocol address; your complete user-agent string; the full address of any referring page; the content of any search performed on the Site; any identifier stored on your device; and any identifier capable of being matched against you on another website.
  4. Counting of distinct visitors. To avoid recording a single visitor more than once within a calendar day, a value is derived by applying the SHA-256 hash function to a combination of your Internet Protocol address, generalised browser information and a secret salt. That salt is regenerated every twenty-four hours and is not persisted. The resulting value is irreversible, differs for the same visitor on a subsequent day, and is deleted within forty-eight hours. Only the resulting Aggregate Data is retained.
  5. We consider that, following the deletion described in clause 4.4, the data retained under this clause 4 is Aggregate Data and is therefore outside the scope of applicable data protection law. Nevertheless, we apply the safeguards in this Policy to it.
  6. Opt-out. Where your browser transmits a Do Not Track (DNT: 1) or Global Privacy Control (Sec-GPC: 1) signal, no record of any kind is created in respect of your visit. Requests identified as originating from automated agents are likewise disregarded.

5. Personal Data you provide to us

  1. Comments. Where you submit a comment, we process the name you supply, the content of your comment, and, if you choose to provide it, your email address. The name and comment content are published on the Site following review. An email address supplied for this purpose is used solely to notify you of a reply, is not published, and is not used for any other purpose. A daily, irreversible value of the kind described in clause 4.4 is also recorded for the sole purpose of limiting the rate of submissions.
  2. Newsletter subscription. Where you subscribe, we process your email address, the page from which the subscription was initiated, and the dates of subscription and confirmation. We operate a confirmed opt-in process: no communication other than the confirmation request is sent unless and until you activate the confirmation link. An address that is not confirmed is erased automatically within fourteen days. We do not record whether an email is opened or whether a link within it is activated.
  3. Contact form. Where you contact us, we process your name, email address, and the content of your message, for the purpose of responding to you. A copy is retained on our infrastructure so that a failure in mail transmission does not result in the loss of your message, and that copy is erased automatically after 90 days.
  4. Administrative accounts. Where a person is authorised to publish to the Site, we process their name, email address, and a cryptographic hash of their password. Passwords are not stored in plain text and cannot be recovered from the stored value.
  5. We do not knowingly collect any special category data within the meaning of Article 9 GDPR, and you are asked not to submit such data through any facility on the Site.

6. Purposes and legal bases

Where the GDPR, the United Kingdom General Data Protection Regulation (“UK GDPR”) or a materially equivalent regime applies, we rely on the following legal bases:

Processing activityPurposeLegal basis
Measurement of Site usage (clause 4)Understanding whether and how published material is readLegitimate interests, Art. 6(1)(f). Our interest is in assessing the reach of our publications. The impact on Data Subjects is minimal because no Personal Data is retained.
Publication and moderation of commentsEnabling public discussion of published materialLegitimate interests, Art. 6(1)(f), in respect of material voluntarily submitted for publication
Newsletter subscriptionSending notice of new publicationsConsent, Art. 6(1)(a), evidenced by confirmed opt-in
Responding to enquiriesCorresponding with the senderLegitimate interests, Art. 6(1)(f), and where applicable steps taken at the request of the Data Subject prior to entering a contract, Art. 6(1)(b)
Rate limiting and abuse preventionMaintaining the security and availability of the SiteLegitimate interests, Art. 6(1)(f), and Recital 49
Administrative authenticationRestricting publication to authorised personsLegitimate interests, Art. 6(1)(f)

A balancing assessment has been carried out in respect of each reliance on legitimate interests. A summary of that assessment is available on request to the address in clause 3.1.

7. Disclosure and recipients

  1. We do not sell, rent, licence or otherwise make Personal Data available to third parties for their own marketing purposes, and we do not participate in any advertising network, data exchange or audience-matching arrangement.
  2. Personal Data may be disclosed to the following categories of recipient, each of which acts as a Processor on our documented instructions and under a written agreement complying with Article 28 GDPR:
    • our hosting provider, which operates the infrastructure serving the Site;
    • our database provider, which stores the data described in clause 5;
    • our email service provider, which transmits confirmation messages and correspondence.
  3. Our hosting provider may, in common with all providers of internet infrastructure, generate short-lived operational logs that include Internet Protocol addresses for the purposes of network security and fault diagnosis. Those logs are generated and controlled by that provider, are not accessible to us for analytical purposes, and are not used by us.
  4. Embedded content. Certain articles embed media hosted by third parties, being YouTube, Vimeo, Spotify, SoundCloud and Apple. Where such content is embedded, we employ the privacy-preserving variants offered by those providers, including the youtube-nocookie.com domain and Vimeo’s Do Not Track parameter, and the content is loaded only when it enters the viewport. Once you interact with such content, the relevant provider becomes an independent controller in respect of that interaction and its own privacy notice applies. Further detail is set out in the Cookie Policy.
  5. We may disclose Personal Data where required to do so by law, by a court of competent jurisdiction, or by a regulatory authority acting within its powers, or where necessary to establish, exercise or defend legal claims.
  6. In the event of a merger, acquisition or transfer of all or part of our business, Personal Data may be transferred to the acquiring party, subject to that party being bound by terms no less protective than those in this Policy. Data Subjects will be notified before any such transfer takes effect.

8. Rights of Data Subjects

  1. Subject to the conditions and exemptions in applicable law, you have the right: to be informed of the Processing of your Personal Data (Art. 13–14 GDPR); to obtain access to it (Art. 15); to have inaccurate data rectified (Art. 16); to have data erased (Art. 17); to obtain restriction of Processing (Art. 18); to data portability (Art. 20); to object to Processing carried out on the basis of legitimate interests (Art. 21); and, where Processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of Processing carried out before withdrawal (Art. 7(3)).
  2. Requests should be sent to pravyaglobal1810@gmail.com. We will respond without undue delay and in any event within one month of receipt, which period may be extended by a further two months where necessary having regard to the complexity and number of requests, in which case you will be informed within the first month. No fee is payable, save that we may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive.
  3. We may request information reasonably necessary to confirm your identity before acting on a request. Because the measurement facility described in clause 4 retains no Personal Data, a request under this clause will ordinarily concern only a comment, a newsletter subscription, or correspondence.
  4. You may withdraw consent to the newsletter at any time by activating the unsubscribe link contained in every message, which erases the subscription record in its entirety, or by writing to the address in clause 3.1.
  5. You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (Art. 77 GDPR). In the United Kingdom, the supervisory authority is the Information Commissioner’s Office. We would be grateful for the opportunity to address your concerns before you approach a supervisory authority.

9. Retention

Personal Data is retained only for as long as is necessary for the purposes for which it was collected, and is thereafter erased.

CategoryRetention period
Distinct-visitor values (clause 4.4)Erased within 48 hours
Aggregate Data (clause 4.2)Retained indefinitely; contains no Personal Data
Published comments and associated addressesUntil erasure is requested, or the associated article is withdrawn
Confirmed newsletter subscriptionsUntil unsubscribed
Unconfirmed newsletter subscriptionsErased automatically after 14 days
Contact form submissionsErased automatically after 90 days
Administrative authentication sessions30 days, or until sign-out, whichever is earlier

10. International transfers

  1. Our infrastructure providers may store or process data in territories outside the European Economic Area and the United Kingdom.
  2. Where Personal Data is transferred to a territory that is not the subject of an adequacy decision, that transfer is made subject to appropriate safeguards within the meaning of Article 46 GDPR, being the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914) and, where relevant, the United Kingdom International Data Transfer Addendum, in each case as incorporated into our agreements with the relevant provider.
  3. A copy of the relevant safeguards may be obtained by writing to the address in clause 3.1.

11. Security

  1. We implement appropriate technical and organisational measures pursuant to Article 32 GDPR, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing.
  2. Those measures include: transmission of all traffic over Transport Layer Security; storage of authentication credentials as salted cryptographic hashes; storage of session identifiers in hashed form such that a copy of the database cannot be used to obtain access; sanitisation of all submitted and published content before it is served to any visitor; restriction of file uploads to an allow-list of non-executable formats; and rate limiting of all endpoints that accept submissions.
  3. No method of transmission or storage is entirely secure. In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of it, in accordance with Article 33 GDPR, and will notify affected Data Subjects where required by Article 34.

12. Automated decision-making

We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you, within the meaning of Article 22 GDPR, and we do not carry out profiling.

13. Children

The Site is not directed to children under the age of sixteen and we do not knowingly process the Personal Data of such persons. Where we become aware that such data has been submitted, it will be erased. A parent or guardian who believes that a child has submitted Personal Data should contact the address in clause 3.1.

14. Jurisdiction-specific provisions

14.1 Scope

We are established in the United States, and this Policy is governed as set out in clause 16. Because the Site is readable from anywhere, the provisions below set out how we treat visitors to whom a particular regime applies. Where two regimes would both apply to you, we apply whichever affords you the greater protection; nothing in this clause 14 limits a right conferred on you elsewhere in this Policy.

14.2 United States — federal

We are established in the United States. Commercial email we send is governed by the CAN-SPAM Act of 2003: every message we send identifies itself accurately, states a valid postal or electronic address at which we can be reached, contains a functioning one-click unsubscribe mechanism, and honours an unsubscribe request immediately rather than within the ten business days the Act permits. We do not send commercial email to any address that has not completed the confirmed opt-in described in clause 5.2.

The Children’s Online Privacy Protection Act (“COPPA”) applies to the online collection of personal information from children under 13. This Site is not directed to children under 13, we do not knowingly collect personal information from them, and where we learn that we have done so we delete it. See also clause 13.

14.3 California

For the purposes of the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (together, the “CCPA”): we have not sold or shared personal information, as those terms are defined in the CCPA, in the preceding twelve months, and we do not do so; we do not use or disclose sensitive personal information for purposes other than those permitted by section 1798.121(a); and we do not knowingly sell or share the personal information of consumers under sixteen years of age. California residents may exercise the rights to know, to delete, to correct, to opt out, and to non-discrimination by writing to the address in clause 3.1. An authorised agent may submit a request on your behalf on production of written authorisation.

California Civil Code section 1798.83 (“Shine the Light”) permits residents of California to request information about disclosure of personal information to third parties for direct marketing purposes. We make no such disclosures.

14.4 Other United States state privacy laws

Comprehensive state privacy statutes — including those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana — confer rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling. We honour those rights for residents of every state that grants them, on request to the address in clause 3.1, without regard to whether we meet the thresholds that would make a given statute mandatory for us. We conduct no targeted advertising, make no sales of personal data, and carry out no profiling, so those particular opt-outs have nothing to act upon.

14.5 European Economic Area and United Kingdom

Clauses 6, 8, 10 and 11 give effect to the GDPR and the UK GDPR for visitors in those territories. We have not appointed a representative under Article 27 GDPR on the basis that our Processing is occasional, does not involve large-scale Processing of special category data, and is unlikely to result in a risk to the rights and freedoms of natural persons.

14.6 India

Where the Digital Personal Data Protection Act, 2023 applies to a visitor, we act as a Data Fiduciary: we process digital personal data only for the lawful purposes described in clause 6, of which notice is given by this Policy; we retain it only for so long as necessary, as set out in clause 9; we implement reasonable security safeguards as set out in clause 11; and we give effect to the rights of Data Principals to access, correction, completion, updating, erasure and grievance redressal, on request to the address in clause 3.1.

15. Amendments

  1. We may amend this Policy from time to time. The version in force is that published on this page, identified by the version number and effective date shown above.
  2. Where an amendment materially affects Personal Data already collected, we will give notice on the Site and, in the case of newsletter subscribers, by email, in each case before the amendment takes effect.

16. Governing law

This Policy and any non-contractual obligations arising out of or in connection with it are governed by the laws of the State in which the Operator is domiciled, the United States, without prejudice to any mandatory protection available to you under the law of your country of residence.

Questions about this document should be addressed to pravyaglobal1810@gmail.com. Superseded versions are available on request.