📞 Call Now

Indian Company · DPDP Act 2023 Compliant

Privacy Policy 

Effective Date: 27 May 2026  ·  Last Updated: 27 May 2026
Digicore Technologies Pvt. Ltd., operating as UnoSearch  ·  India

Contents

01. About UnoSearch
03. How We Use Your Information
05. Sharing of Information
07. Your Rights as a Data Principal
09. Children’s Privacy
11. Changes to This Policy

02. Information We Collect

04. Legal Bases for Processing
06. Data Retention
08. Cookies & Tracking Technologies
10. Security
12. Grievance Officer & Contact

Contents

01. About UnoSearch

02. Information We Collect

03. How We Use Your Information
04. Legal Bases for Processing
05. Sharing of Information
06. Data Retention
07. Your Rights as a Data Principal
08. Cookies & Tracking Technologies
09. Children’s Privacy
10. Security
11. Changes to This Policy
12. Grievance Officer & Contact

01. About UnoSearch

Digicore Technologies Private Limited, operating as UnoSearch (“UnoSearch”, “we”, “us”, or “our”), is a company incorporated under the Companies Act, 2013, and headquartered in India. We operate as a digital marketing, SEO, GEO, and PPC agency serving businesses in India and globally, through our platform accessible at unosearch.io (the “Platform”).

This Privacy Policy describes how we collect, use, process, store, and protect personal data in accordance with:

    The Digital Personal Data Protection Act, 2023 (DPDP Act)

    The Digital Personal Data Protection Rules, 2025 (DPDP Rules)

    The Information Technology Act, 2000 and the IT (Amendment) Act, 2008

    Any other applicable Indian laws and regulations

    Your consent to the collection and use of your personal data is obtained through a clear affirmative action (such as submitting a form or ticking a consent checkbox). Merely browsing this Platform does not constitute consent to data processing.

    Our Role as Data Fiduciary and Data Processor

    UnoSearch acts as a Data Fiduciary with respect to personal data of its own leads, enquiries, and clients. Where UnoSearch processes personal data of a client’s end-customers during the course of delivering marketing or campaign services, it acts as a Data Processor and processes such data only on the documented instructions of the relevant client, in accordance with the DPDP Act, 2023 (s.8) and the DPDP Rules, 2025.

    02. Information We Collect

    Category Examples Source
    Enquiry & Lead Data Name, email address, phone number, company name, and details submitted via contact or enquiry forms Provided by you
    Client & Billing Data Billing address, payment reference, invoice details, organisation and GST information Provided by you at onboarding or checkout
    Website & Technical Data IP address, browser type, device identifiers, OS, referring URLs, pages visited, session duration Automatically collected
    Communication Data Emails, messages, or support tickets sent to or received from us Provided by you
    Marketing & Prospect Data Details of prospects and contacts used for outreach, campaign analytics and engagement data Provided by you or sourced from publicly available channels with consent
    Client-Provided Data (Processor Role) Personal data of end-customers provided by clients for the purpose of delivering marketing, SEO, GEO, or PPC campaigns Provided by the client under a services agreement

    Sensitive Personal Data

    We do not intentionally collect sensitive personal data (e.g., financial information beyond billing, health data, biometric data). If any such data is submitted inadvertently, you may request its deletion via our Grievance Officer.

    03. How We Use Your Information

    We use your personal data for the following purposes:

      Providing the Platform: Authenticating your account, processing search queries, indexing content, and delivering results.

      Improving our AI Models: Analysing aggregated, anonymised usage patterns to enhance search relevance and accuracy.

      Customer Support: Responding to your queries, resolving issues, and managing your account.

      Billing & Transactions: Processing payments, issuing invoices, and preventing fraud.

      Product Communications: Sending feature updates, maintenance notices, and policy changes (these are service-critical and cannot be opted out of while you hold an account).

      Marketing Communications: Sending promotional emails or newsletters, subject to your explicit consent, which you may withdraw at any time.

      Legal Compliance: Meeting obligations under applicable Indian law, responding to lawful government or court orders.

      Legal Compliance: Meeting obligations under applicable Indian law, responding to lawful government or court orders.

      Security & Fraud Prevention: Detecting and preventing unauthorised access, abuse, or illegal activities on the Platform.

      We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.

        04. Legal Bases for Processing

        Under the DPDP Act, 2023, we process your personal data on the following grounds:

        Consent: Where you have given us clear, free, specific, informed, and unambiguous consent through a clear affirmative action (e.g., submitting an enquiry form, opting in to marketing emails). You may withdraw consent at any time without affecting prior lawful processing. Marketing communications and use of identifiable data for service improvement always rely on consent.

        Certain Legitimate Uses (s.7 DPDP Act): Processing necessary for the performance of a function of the State; compliance with a court or tribunal order; or responding to a medical emergency. Fraud detection and security measures are also covered within this ground where proportionate and not overriding your rights.

        Legal Obligation: Processing required to comply with applicable Indian law, regulatory directives, or orders of a competent court, tribunal, or government authority.

        The DPDP Act, 2023 provides a closed set of grounds for processing. Open-ended “legitimate interest” and standalone “contractual necessity” are not valid bases under the Act. Where we previously referenced such grounds, processing now relies on consent or the specific legitimate uses enumerated under s.7.

        05. Sharing of Information

        We share your personal data only in the following limited circumstances:

        Service Providers (Data Processors): Trusted third-party vendors who assist in operating the Platform — such as cloud infrastructure providers, payment gateways, and analytics services — under contractual obligations to maintain data confidentiality and process data only on our instructions.

        Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.

        Legal Authorities: Where required by law, court order, or a competent government authority in India, we may disclose your data. We will, where legally permissible, notify you before any such disclosure.

        With Your Consent: We may share data with third parties if you have expressly consented to such sharing.

        Cross-Border Transfers

        Some of our service providers may be located outside India. Under the DPDP Act, 2023 (s.16), personal data may be transferred to countries other than those that the Central Government may restrict by notification. We apply appropriate contractual protections to all cross-border transfers and will comply with any data-localisation requirements notified by the Government from time to time.

        06. Data Retention

        We retain your personal data only for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required by Indian law.

         

        Account Data: Retained for the duration of your account and for up to 3 years after account closure, for legal and audit purposes.

        Usage & Search Logs: Retained for up to 12 months in identifiable form, after which data is anonymised or deleted.

        Financial Records: Retained for a minimum of 8 years as required under the Companies Act, 2013, and applicable tax laws.

        Support Communications: Retained for 2 years from closure of the support interaction.

        Upon expiry of the relevant retention period, data is securely deleted or irreversibly anonymised.

        07. Your Rights as a Data Principal

        Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:

          Right to Access: Obtain a summary of your personal data we hold and the purposes for which it is processed.

          Right to Correction: Request correction of inaccurate or incomplete personal data.

          Right to Erasure: Request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention obligations.

          Right to Grievance Redressal: Register a complaint with our Grievance Officer, who is required to acknowledge and resolve it within the timelines prescribed under applicable law.

          Right to Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity.

          Right to Withdraw Consent: Withdraw consent at any time for processing based on consent, without affecting prior lawful processing.

          Right to Grievance Redressal: Register a complaint with our Grievance Officer, who is required to acknowledge and resolve it within the timelines prescribed under applicable law.

          To exercise any of these rights, please contact our Grievance Officer (details in Section 12). We will respond within 30 days of receipt of your request.

            Complaints to the Data Protection Board

            If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India (now constituted under the DPDP Act, 2023) or with the appropriate court of competent jurisdiction. Requests to exercise your rights may be submitted via email to our Grievance Officer using the contact details in Section 12, quoting your account or enquiry reference. We will endeavour to respond within 30 days, subject to the 90-day statutory maximum for grievance redressal prescribed under the DPDP Rules, 2025.

            08. Cookies & Tracking Technologies

            We use cookies and similar tracking technologies on the Platform to enhance your experience. The types of cookies we use are:

              Essential Cookies: Required for core Platform functionality such as authentication and session management. These cannot be disabled.

              Analytics Cookies: Help us understand how users interact with the Platform (e.g., pages visited, time spent). Used in aggregated, anonymised form.

              Preference Cookies: Remember your settings and preferences for future visits.

              Non-essential cookies are only set with your consent, which you can manage via our cookie consent banner or your browser settings. Note that disabling certain cookies may affect Platform functionality.

                Complaints to the Data Protection Board

                If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India (now constituted under the DPDP Act, 2023) or with the appropriate court of competent jurisdiction. Requests to exercise your rights may be submitted via email to our Grievance Officer using the contact details in Section 12, quoting your account or enquiry reference. We will endeavour to respond within 30 days, subject to the 90-day statutory maximum for grievance redressal prescribed under the DPDP Rules, 2025.

                09. Children’s Privacy

                The Platform is not directed at children under the age of 18 years. We do not knowingly collect personal data from minors. In compliance with the DPDP Act, 2023 (s.9) and the DPDP Rules, 2025, we commit to the following:

                We will not process a child’s personal data without verifiable parental or guardian consent.

                We will not engage in tracking or behavioural monitoring of children.

                We will not serve targeted advertising directed at children.

                If we become aware that we have inadvertently collected data from a child without verifiable parental consent, we will promptly delete such data.

                If you believe a minor has submitted personal data to us, please contact our Grievance Officer immediately.

                10. Security

                We implement security safeguards in accordance with the DPDP Act, 2023 (s.8(5)) and the DPDP Rules, 2025, including:

                  Encryption of data in transit using TLS/SSL protocols

                  Encryption of sensitive data at rest

                  Access controls and role-based permissions for internal systems

                  Regular security audits and vulnerability assessments

                  Incident response procedures for data breach notification

                  Retention of security and access logs for a minimum period of one year (in accordance with DPDP Rule 6)

                  In the event of a personal data breach, we will: (a) notify affected Data Principals without undue delay upon becoming aware of the breach; and (b) submit a detailed report to the Data Protection Board of India within 72 hours of becoming aware (or within such extended period as the Board may permit), in accordance with DPDP Rule 7. Notification obligations apply to all personal data breaches and are not limited to breaches likely to cause harm.

                  However, no system is completely secure. We encourage you to use a strong, unique password and to log out of your account after each session.

                    11.Changes to This Policy

                    We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. When we make material changes, we will:

                    Update the “Last Updated” date at the top of this page

                    Notify registered users via email or an in-Platform notification at least 15 days before the changes take effect

                    Your continued use of the Platform after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree, you may close your account before the effective date.

                    12. Grievance Officer & Contact

                    In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, we have designated a Grievance Officer to address concerns regarding the processing of your personal data:

                    Grievance Officer

                    Name: Indira Bidari 
                    Designation: Grievance Officer
                    Organisation: Digicore Technologies Private Limited (operating as UnoSearch)
                    Email: [email protected], [email protected],
                    Address: 3rd Floor, Niharika Mirage, Kharghar, Navi Mumbai, India
                    Response Time: Within 30 days of receipt of grievance (statutory maximum: 90 days per DPDP Rules, 2025)

                    For general inquiries about this Privacy Policy or your personal data, you may also write to us at:

                    [email protected]  ·  unosearch.io