Privacy Policy
When you use our services, you're trusting us with your information. We understand this is a big responsibility and work hard to protect your information and put you in control. This Privacy Policy is meant to help you understand what information we collect, why we collect it, and how you can update, manage, export, and delete your information. Download PDF.
1. Introduction
We build a range of services that help industries, educational institutes, and startups protect personal data and comply with India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), the European Union's General Data Protection Regulation (EU) 2016/679 (“GDPR”), and other applicable privacy laws. Our services include:
- Ninebloom Compliance Platform — a cloud-based suite for data protection governance, consent management, data subject request handling, privacy impact assessments, breach response workflows, and audit readiness;
- Ninebloom Consul — advisory and implementation services for DPDP Act and GDPR compliance, including policy drafting, gap assessments, and remediation support;
- Ninebloom Eduguard — privacy tools specifically designed for educational institutes to manage student and parent data, verifiable parental consent, and institutional data governance;
- Ninebloom Startshield — a lightweight privacy and compliance toolkit for early-stage startups to get DPDP-ready quickly.
You can use our services in a variety of ways to manage your privacy. For example, you can create a Ninebloom account if you want to use our compliance platform, or you can simply browse our website and read our resources without creating an account at all. Across our services, you can adjust your privacy and consent settings to make choices about whether we save certain types of data and how we use it.
To help explain things as clearly as possible, we've added examples and definitions for key terms. And if you have any questions about this Privacy Policy, you can contact us at privacy@ninebloom.co.
2. Information Ninebloom collects
We collect information to provide better services to all our users — from understanding basic things like which language you prefer, to more complex things like how we can help your organisation become privacy-compliant. The information Ninebloom collects, and how that information is used, depends on how you use our services and how you manage your privacy controls.
Things you create or provide to us
When you create a Ninebloom account, you provide us with personal information that includes your name, work email address, password, phone number, and company name. You can also choose to add your designation, business address, and GSTIN/PAN for invoicing and tax compliance. Even if you don't have a Ninebloom account, you might choose to provide us with information — like an email address to receive our newsletter, or your contact details when you request a demo.
We also collect the content you create or upload when using our services. This includes compliance documents you draft within the platform, data subject request records, consent registers, audit reports, and configuration settings you apply to your organisation's privacy programme.
Your apps, browsers & devices
We collect information about the apps, browsers, and devices you use to access Ninebloom services, which helps us provide features like secure session management and compatibility checks. The information we collect includes unique session identifiers, browser type and settings, device type and settings, operating system, and application version number. We also collect information about the interaction of your apps, browsers, and devices with our services, including IP address, crash reports, system activity, and the date, time, and referrer URL of your request.
Client data processed through our platform
When a client (for example, an educational institute or a startup) uses our compliance platform, the client may store or process personal data belonging to their own end-users — such as student records, employee data, or customer information — through our services. The categories of such data are determined entirely by the client, not by Ninebloom. Clients remain responsible for issuing their own privacy notices to their end-users and for having a lawful basis for collection.
Ninebloom processes this Client Data strictly as a Data Processor under documented instructions in each client's Data Processing Agreement. We never use Client Data for our own marketing, product training, AI/ML model training, or any purpose not expressly authorised by the client in writing.
Information we do not collect
We do not knowingly collect government-issued identity numbers (such as Aadhaar) through our website forms, except where a client's contracted configuration lawfully requires specific identifiers and the client has an independent legal basis for sharing them with us. We do not knowingly collect sensitive personal data (as defined under the DPDP Act) or special categories of data (under GDPR) on our own website. We do not knowingly collect data directly from children on our website.
3. Why Ninebloom collects data
We use the information we collect from all our services for the following purposes:
- Provide our services — We use your information to deliver the services you've engaged us for — such as processing your account registration, running compliance assessments, generating audit reports, managing consent records, and routing data subject requests to the appropriate team within your organisation.
- Maintain & improve our services — We use your information to ensure our services are working as intended, such as tracking outages or troubleshooting issues you report to us. We use aggregated and de-identified data to make improvements to our services — for example, understanding which compliance features are most used helps us prioritise product development.
- Communicate with you — We use your contact information to send you service notifications, security alerts, contract-related communications, and (with your consent) newsletters, product updates, and event invitations. You can opt out of marketing communications at any time using the unsubscribe link in any email or through your account settings.
- Process payments and billing — We use your business and transaction information to process payments, issue invoices, and meet tax compliance requirements. Payment processing is handled through Zoho Payments and Zoho Billing; we do not store full card numbers on our servers.
- Protect our services and users — We use information to protect the security of our platform, detect and prevent fraud, abuse, and security incidents, and investigate violations of our terms of service.
- Meet legal and compliance obligations — As a RegTech company, we are subject to legal and regulatory obligations. We use information to comply with applicable laws, respond to lawful requests from authorities, and maintain records required for audit and statutory purposes.
4. Your privacy controls
You can use our services in a variety of ways to manage your privacy. Here's how:
Managing, reviewing, and updating your information
When you're signed in to your Ninebloom account, you can always review and update your personal information — such as your name, email address, phone number, company details, and notification preferences — through your account settings. You can also review which team members in your organisation have access to the platform and manage their permissions.
Consent management
Where we process your personal data on the basis of consent (for example, marketing emails, newsletter subscriptions, or non-essential cookies), you can give, manage, review, and withdraw consent at any time through your account settings or by contacting privacy@ninebloom.co. Withdrawing consent does not affect the lawfulness of processing before withdrawal, though it may affect our ability to provide certain optional features.
For our clients, the Ninebloom platform includes a built-in Consent Manager that helps them collect, manage, and honour consent from their own end-users in compliance with the DPDP Act and GDPR.
Cookies and tracking technologies
We use only the cookies that are strictly necessary to operate and secure our services — authentication and session cookies, and a device fingerprint cookie used to recognise the device you sign in from, so we can protect your account from unauthorised access. We do not use analytics, advertising, personalisation, or third-party tracking cookies of any kind.
Because every cookie we set is strictly necessary for the service to function, no consent banner is required — but we still publish a detailed Cookie Notice explaining each cookie, its purpose, and its lifetime at https://www.ninebloom.co/cookies and /cookie-policy. You can block or delete cookies through your browser settings, though this will sign you out of the platform and may prevent you from signing in.
Nominees and organization members
Clients can add one or more nominees or organization members to their Ninebloom account, so multiple authorised people are always available to manage the client's data, consents, and compliance settings. This provides continuity if a primary administrator is unavailable, leaves the organisation, or — for individual Data Principals — in the event of death or incapacity, where the DPDP Act allows nomination of another individual to exercise rights on their behalf.
Account administrators control which organization members have access, what permission level each member holds, and can revoke access at any time.
Privacy settings for client administrators
Client administrators can configure data retention rules, access control policies, audit logging, and consent workflows for their tenant. They can also control which members of their organisation have access to specific modules within the platform.
5. Sharing your information
We do not share your personal information with companies, organisations, or individuals outside of Ninebloom except in the following cases:
With sub-processors and vendors
We share personal data only with vetted service providers who help us operate our platform. Each is bound by data protection terms no less protective than this Policy, and we remain responsible for their performance. Our current sub-processors are:
| Sub-processor | Purpose | Hosting location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, compute, storage, databases | ap-south-1 (Mumbai, India) |
| Zoho Mail | Business email | India |
| Zoho Desk | Support ticketing | India |
| Zoho Billing | Subscription billing and invoicing | India |
| Zoho Payments | Payment processing | India |
We review this list regularly. An up-to-date version is maintained at https://www.ninebloom.co/subprocessors. We will notify clients at least 30 days before adding or replacing a sub-processor that processes Client Data, and clients may object on reasonable data-protection grounds.
With your consent
We'll share personal information outside of Ninebloom when we have your consent. We'll ask for your explicit consent before sharing any sensitive personal information.
With domain administrators
If you are part of an organisation that uses Ninebloom, your organisation's administrator may have access to certain information about your account — such as your name, email address, role, and activity logs within the platform. This is limited to what the administrator needs to manage their organisation's use of the service. The administrator is responsible for informing their members about what they can access.
For legal reasons
We may disclose personal data to comply with a legally valid and binding request from law enforcement, a court, or a regulator. For Client Data, we will notify the affected client before disclosing their data where law permits, and we will challenge overbroad or unlawful requests. We also disclose information when necessary to protect the rights, property, safety, or security of Ninebloom, our clients, or the public.
In corporate transactions
In connection with a merger, acquisition, or sale of assets, we may transfer personal data to the acquiring entity. We will provide prior notice to you and ensure the transferee honours this Privacy Policy before any transfer occurs.
6. Keeping your information secure
We build our products and services with security and privacy in mind, and we invest significant resources in protecting the personal data entrusted to us. Our security programme includes:
- Encryption: all data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256 encryption. Encryption keys are managed through AWS Key Management Service (KMS) with rotation policies.
- Tenant isolation and dedicated databases: each client's data resides in a logically isolated tenant environment with strict access boundaries that prevent cross-tenant access. Clients may also opt for a dedicated, single-tenant database. Client data is never commingled across tenants.
- Access control: we enforce role-based access control (RBAC) with least-privilege principles. All access to Client Data environments requires multi-factor authentication (MFA), is logged and auditable, and is reviewed quarterly. Access is granted on a need-to-know basis and revoked promptly when no longer required.
- Security testing: we conduct regular vulnerability assessments and annual penetration tests conducted by independent third-party security firms. We follow a secure software development lifecycle (SSDLC) with code reviews, automated security scanning, and dependency monitoring.
- Incident response: we maintain a documented security incident response plan with defined roles, escalation paths, and notification timelines. In the event of a personal data breach, we notify affected parties and regulators as described in Section 9.
- Personnel and physical security: all employees and contractors sign confidentiality and acceptable-use agreements and undergo privacy and security training at onboarding and annually thereafter.
- Business continuity: we maintain encrypted, access-controlled backups with tested recovery procedures. Backups are encrypted with separate key material and stored in a different availability zone.
No system is perfectly secure. We continuously monitor and improve our security posture, and we are committed to transparency if a security incident affects your data.
7. Exporting & deleting your information
We believe you should be in control of your data. Here's what you can do:
Export your information
You can export a copy of your personal data and platform content associated with your Ninebloom account in a structured, commonly used, machine-readable format (JSON or CSV). For clients, the platform provides an export function for Client Data stored in your tenant or dedicated database. To request an export, use the export tool in your account settings or email privacy@ninebloom.co.
Delete your information
You can delete specific items or your entire Ninebloom account at any time. To do so:
- Delete individual data items through your account settings;
- Delete your entire account and associated data by contacting privacy@ninebloom.co or your account manager;
- For marketing data, use the unsubscribe link in any email.
When you delete data, we remove it from our active systems within 30 days and from our backups within 90 days, subject to any legal hold or statutory retention requirement. Some data may be retained in de-identified or aggregated form that can no longer identify you.
For client end-users
If your personal data is processed through a client's use of our platform (for example, you are a student of an institute or an employee of a company that uses Ninebloom), your organisation is the Data Fiduciary or Controller for your data. Please direct your export or deletion requests to them. Under our Data Processing Agreements, we assist clients in fulfilling such requests within the timelines required by the DPDP Act or GDPR.
Client offboarding and data exit
When a client engagement ends — at contract expiry or early termination:
- Export window: for 30 days after the termination date, the client can export all of their data — Client Data, configuration, and compliance records — in JSON or CSV format through their account or with assistance from our support team.
- Server shutdown: at the close of the export window, we shut down the client's tenant environment and decommission any dedicated servers or databases provisioned exclusively for that client.
- Deletion from our side: we delete all Client Data from our active systems within 30 days of the export window closing, and purge it from our backups within 90 days, subject to any legal hold. We issue a written deletion confirmation to the client once complete.
- No reuse: deleted Client Data is never reused, mined, or retained in any form that could identify the client's end-users.
8. Retaining your information
We retain the data we collect for different periods of time depending on what it is, how we use it, and how you configure your settings:
- Account and profile data — we keep this data in your Ninebloom account until you remove it or delete your account.
- Website enquiry and prospect data — retained for 24 months from your last interaction with us, after which it is automatically deleted or anonymised.
- Client account and contract data — retained for the duration of the client engagement, plus 8 years thereafter for statutory and tax record-keeping under Indian law.
- Invoices and payment records — retained for 8 years as required under the Indian Income Tax Act and Goods and Services Tax Act.
- Marketing consent records — retained for the duration of consent plus 3 years as evidence of consent and withdrawal.
- Platform and audit logs (Client Data) — retained as specified in each client's DPA; default retention is 12 months, configurable by the client administrator up to 36 months.
- Support tickets and communications — retained for 3 years after resolution, then deleted.
- Security event logs — retained for 24 months for forensic and audit purposes, then automatically purged.
When retention periods expire, data is securely deleted or irreversibly anonymised. Backups containing deleted data are rotated on a defined schedule and purged within 90 days of the deletion taking effect, subject to legal holds.
Some data we retain for longer periods when necessary for legitimate business or legal purposes, such as security incident investigation, fraud and abuse prevention, or financial record-keeping. When we do so, we limit the data to what is strictly necessary and restrict access to authorised personnel only.
9. Compliance & cooperation with regulators
DPDP Act, 2023 compliance
We comply with the Digital Personal Data Protection Act, 2023. Where we act as Data Fiduciary, we process personal data on the basis of consent or legitimate uses (Section 7 of the DPDP Act). Where we act as Data Processor for Client Data, we process solely on the documented instructions of the client under a signed Data Processing Agreement.
We maintain records of processing activities, conduct data protection impact assessments for high-risk processing, and cooperate with the Data Protection Board of India on any inquiry or investigation.
GDPR compliance
Where the GDPR applies to our processing, we rely on the lawful bases set out below:
| Lawful basis | Typical use at Ninebloom |
|---|---|
| Contract | Delivering services to clients, account management, support |
| Consent | Marketing emails, newsletters, non-essential cookies |
| Legal obligation | Tax, accounting, and statutory record-keeping |
| Legitimate interests | Website security, fraud prevention, service improvement, B2B communications |
| Vital interests | Exceptional circumstances (e.g., safety incidents) |
We cooperate with EU supervisory authorities and respond to legitimate requests within the timelines prescribed by the GDPR.
Children's data
Because we serve educational institutes, we take child protection obligations especially seriously. Under the DPDP Act, processing personal data of children (individuals under 18) requires verifiable parental consent, and children's data must not be used for tracking, behavioural monitoring, or targeted advertising. Our Eduguard module is designed to help client institutes enforce these requirements, including consent workflows for parents and guardians.
Under the GDPR, the age of digital consent is 13–16 depending on the EU member state. Where parental consent is required, our platform supports its capture, audit, and withdrawal.
We do not knowingly collect personal data directly from children on our own website. If we learn that a child's personal data has reached us without a lawful basis, we will delete it promptly and notify the client where the data originated. Parents or guardians may contact privacy@ninebloom.co or grievance@ninebloom.co at any time.
Automated decision-making and profiling
We do not carry out solely automated decision-making that produces legal or similarly significant effects for individuals using our own website or services. Our platform's compliance dashboards, risk scores, and alerts are advisory tools for our clients. Decisions about an individual — for example, by an institute or employer — always rest with the client, who is responsible for any automated decision-making they perform and for ensuring human review where the law requires it.
Data breach notification
In the event of a personal data breach:
- As Data Fiduciary/Controller: we notify the Data Protection Board of India and each affected Data Principal without delay and in the manner and timeframes prescribed under the DPDP Act and any rules issued under it. Where GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and affected data subjects without undue delay where the breach poses a high risk to them.
- As Data Processor: we notify the affected client without undue delay, and in any event within 24 hours of becoming aware of a breach affecting Client Data. We provide the information the client needs to meet their own notification obligations and cooperate fully in investigation and remediation.
Notifications will describe the nature of the breach, the data and approximate number of individuals affected (where known), likely consequences, and the remedial steps taken or proposed.
Your rights
Under the DPDP Act, you have the right to:
- Access a summary of the personal data we process about you, the processing activities we undertake, and the identities of other fiduciaries or processors with whom we have shared it;
- Correct inaccurate or misleading personal data;
- Erase your personal data (subject to retention required by law);
- Nominate another individual to exercise your rights in the event of your death or incapacity — through the nominees and organization members feature in your account, or by contacting privacy@ninebloom.co;
- Approach our Grievance Officer for redressal of any grievance;
- Withdraw consent at any time where processing is consent-based.
Under the GDPR, you additionally have the right to:
- Rectification of inaccurate data;
- Restriction of processing in certain circumstances;
- Data portability — receive your data in a structured, commonly used, machine-readable format or have it transmitted to another controller;
- Object to processing based on legitimate interests, including profiling;
- Not be subject to solely automated decisions with legal or similarly significant effects;
- Lodge a complaint with your national Data Protection Authority.
To exercise any right, email privacy@ninebloom.co or use the self-service tools in your account. We will respond within 30 days (GDPR requires a response without undue delay and in any event within one month, extendable by two months for complex requests). We may verify your identity before acting and will explain if we cannot comply with a request and why.
If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India, or — for GDPR matters — your national data protection authority.
10. Related privacy practices
Some Ninebloom services have specific privacy practices that supplement this Privacy Policy:
- Ninebloom Eduguard — includes additional safeguards for student and child data, including verifiable parental consent workflows, restrictions on processing children's data for behavioural targeting, and enhanced audit logging specific to educational regulatory requirements.
- Ninebloom Startshield — provides startups with privacy policy templates, consent management tools, and basic data subject request handling. Startups using Startshield remain the Data Fiduciary for their own end-users' data; Ninebloom acts as Processor.
- Ninebloom Consul — advisory engagements may involve Ninebloom personnel reviewing client personal data for compliance assessment purposes. Such access is governed by a separate engagement letter and is strictly time-bound and purpose-limited.
Separate notices apply to job applicants and individuals engaged by Ninebloom, who are covered by separate internal notices and not this Policy.
11. About this policy
When this policy applies
This Privacy Policy applies to all Ninebloom services described in Section 1, including our website, compliance platform, advisory services, and tools. It does not apply to third-party services that we do not own or control — such as services our clients build using our APIs or services linked from our website. We encourage you to read the privacy policies of any third-party services you use.
Changes to this policy
We may update this Privacy Policy to reflect changes in law, regulation, technology, or our services. We will post the updated policy on our website and update the “Effective” date at the top. If we make material changes — changes that significantly affect what data we collect, how we use it, or your rights — we will notify you by email and post a prominent notice on our website at least 15 days before the changes take effect. Archived versions of this Policy are available on request.
How to contact us
If you have any questions about this Privacy Policy or our privacy practices, please contact us:
Grievance Officer
For grievances or complaints under the DPDP Act:
Data Protection Officer (GDPR)
For GDPR-related matters: privacy@ninebloom.co
12. Data transfer frameworks
Where your data is stored
Our primary infrastructure is hosted on Amazon Web Services (AWS) in the ap-south-1 region (Mumbai, India). This means that personal data we collect is stored in India by default. Some sub-processors (listed in Section 5) may process limited data in other regions, as specified in the table.
Cross-border transfers under the DPDP Act
Where personal data is transferred outside India, we comply with the DPDP Act's cross-border transfer framework, including any restrictions notified by the Central Government on transfers to specific countries. We continuously monitor government notifications and will adjust our transfer mechanisms accordingly.
Cross-border transfers under the GDPR
Where personal data subject to the GDPR is transferred outside the European Economic Area (EEA), we rely on an adequacy decision of the European Commission (where available for the destination country) or Standard Contractual Clauses (SCCs) adopted by the European Commission, together with a transfer impact assessment where required. Where neither an adequacy decision nor SCCs are available, we rely on an explicitly consented, one-time transfer or another lawful derogation under Article 49 of the GDPR.
Client data transfers
For Client Data, cross-border transfer arrangements are specified in each client's Data Processing Agreement. Clients remain the decision-maker for their end-users' data location wherever their regulatory duties require it. We do not transfer Client Data to a new region without the client's prior written authorisation.
Contact emails
| Used for | |
|---|---|
| privacy@ninebloom.co | Privacy Policy, data protection matters, DPA |
| terms@ninebloom.co | Terms of Service, contract matters |
| cookies@ninebloom.co | Cookie Policy |
| grievance@ninebloom.co | Grievance Officer (DPDP Act) |
| ceo@ninebloom.co | General, billing, account management |