Indian Company · DPDP Act 2023 Compliant
Privacy Policy
Effective Date: 27 May 2026 · Last Updated: 27 May 2026
Digicore Technologies Pvt. Ltd., operating as UnoSearch · India
Contents
02. Information We Collect
Contents
02. Information We Collect
01. About UnoSearch
Digicore Technologies Private Limited, operating as UnoSearch (“UnoSearch”, “we”, “us”, or “our”), is a company incorporated under the Companies Act, 2013, and headquartered in India. We operate as a digital marketing, SEO, GEO, and PPC agency serving businesses in India and globally, through our platform accessible at unosearch.io (the “Platform”).
This Privacy Policy describes how we collect, use, process, store, and protect personal data in accordance with:
The Digital Personal Data Protection Act, 2023 (DPDP Act)
The Digital Personal Data Protection Rules, 2025 (DPDP Rules)
The Information Technology Act, 2000 and the IT (Amendment) Act, 2008
Any other applicable Indian laws and regulations
Your consent to the collection and use of your personal data is obtained through a clear affirmative action (such as submitting a form or ticking a consent checkbox). Merely browsing this Platform does not constitute consent to data processing.
Our Role as Data Fiduciary and Data Processor
UnoSearch acts as a Data Fiduciary with respect to personal data of its own leads, enquiries, and clients. Where UnoSearch processes personal data of a client’s end-customers during the course of delivering marketing or campaign services, it acts as a Data Processor and processes such data only on the documented instructions of the relevant client, in accordance with the DPDP Act, 2023 (s.8) and the DPDP Rules, 2025.
02. Information We Collect
| Category | Examples | Source |
|---|---|---|
| Enquiry & Lead Data | Name, email address, phone number, company name, and details submitted via contact or enquiry forms | Provided by you |
| Client & Billing Data | Billing address, payment reference, invoice details, organisation and GST information | Provided by you at onboarding or checkout |
| Website & Technical Data | IP address, browser type, device identifiers, OS, referring URLs, pages visited, session duration | Automatically collected |
| Communication Data | Emails, messages, or support tickets sent to or received from us | Provided by you |
| Marketing & Prospect Data | Details of prospects and contacts used for outreach, campaign analytics and engagement data | Provided by you or sourced from publicly available channels with consent |
| Client-Provided Data (Processor Role) | Personal data of end-customers provided by clients for the purpose of delivering marketing, SEO, GEO, or PPC campaigns | Provided by the client under a services agreement |
Sensitive Personal Data
We do not intentionally collect sensitive personal data (e.g., financial information beyond billing, health data, biometric data). If any such data is submitted inadvertently, you may request its deletion via our Grievance Officer.
03. How We Use Your Information
We use your personal data for the following purposes:
Providing the Platform: Authenticating your account, processing search queries, indexing content, and delivering results.
Improving our AI Models: Analysing aggregated, anonymised usage patterns to enhance search relevance and accuracy.
Customer Support: Responding to your queries, resolving issues, and managing your account.
Billing & Transactions: Processing payments, issuing invoices, and preventing fraud.
Product Communications: Sending feature updates, maintenance notices, and policy changes (these are service-critical and cannot be opted out of while you hold an account).
Marketing Communications: Sending promotional emails or newsletters, subject to your explicit consent, which you may withdraw at any time.
Legal Compliance: Meeting obligations under applicable Indian law, responding to lawful government or court orders.
Legal Compliance: Meeting obligations under applicable Indian law, responding to lawful government or court orders.
Security & Fraud Prevention: Detecting and preventing unauthorised access, abuse, or illegal activities on the Platform.
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
04. Legal Bases for Processing
Under the DPDP Act, 2023, we process your personal data on the following grounds:
Consent: Where you have given us clear, free, specific, informed, and unambiguous consent through a clear affirmative action (e.g., submitting an enquiry form, opting in to marketing emails). You may withdraw consent at any time without affecting prior lawful processing. Marketing communications and use of identifiable data for service improvement always rely on consent.
Certain Legitimate Uses (s.7 DPDP Act): Processing necessary for the performance of a function of the State; compliance with a court or tribunal order; or responding to a medical emergency. Fraud detection and security measures are also covered within this ground where proportionate and not overriding your rights.
Legal Obligation: Processing required to comply with applicable Indian law, regulatory directives, or orders of a competent court, tribunal, or government authority.
The DPDP Act, 2023 provides a closed set of grounds for processing. Open-ended “legitimate interest” and standalone “contractual necessity” are not valid bases under the Act. Where we previously referenced such grounds, processing now relies on consent or the specific legitimate uses enumerated under s.7.
05. Sharing of Information
We share your personal data only in the following limited circumstances:
Service Providers (Data Processors): Trusted third-party vendors who assist in operating the Platform — such as cloud infrastructure providers, payment gateways, and analytics services — under contractual obligations to maintain data confidentiality and process data only on our instructions.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections.
Legal Authorities: Where required by law, court order, or a competent government authority in India, we may disclose your data. We will, where legally permissible, notify you before any such disclosure.
With Your Consent: We may share data with third parties if you have expressly consented to such sharing.
Cross-Border Transfers
Some of our service providers may be located outside India. Under the DPDP Act, 2023 (s.16), personal data may be transferred to countries other than those that the Central Government may restrict by notification. We apply appropriate contractual protections to all cross-border transfers and will comply with any data-localisation requirements notified by the Government from time to time.
06. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this Policy, unless a longer retention period is required by Indian law.
Account Data: Retained for the duration of your account and for up to 3 years after account closure, for legal and audit purposes.
Usage & Search Logs: Retained for up to 12 months in identifiable form, after which data is anonymised or deleted.
Financial Records: Retained for a minimum of 8 years as required under the Companies Act, 2013, and applicable tax laws.
Support Communications: Retained for 2 years from closure of the support interaction.
Upon expiry of the relevant retention period, data is securely deleted or irreversibly anonymised.
07. Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:
Right to Access: Obtain a summary of your personal data we hold and the purposes for which it is processed.
Right to Correction: Request correction of inaccurate or incomplete personal data.
Right to Erasure: Request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention obligations.
Right to Grievance Redressal: Register a complaint with our Grievance Officer, who is required to acknowledge and resolve it within the timelines prescribed under applicable law.
Right to Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity.
Right to Withdraw Consent: Withdraw consent at any time for processing based on consent, without affecting prior lawful processing.
Right to Grievance Redressal: Register a complaint with our Grievance Officer, who is required to acknowledge and resolve it within the timelines prescribed under applicable law.
To exercise any of these rights, please contact our Grievance Officer (details in Section 12). We will respond within 30 days of receipt of your request.
Complaints to the Data Protection Board
If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India (now constituted under the DPDP Act, 2023) or with the appropriate court of competent jurisdiction. Requests to exercise your rights may be submitted via email to our Grievance Officer using the contact details in Section 12, quoting your account or enquiry reference. We will endeavour to respond within 30 days, subject to the 90-day statutory maximum for grievance redressal prescribed under the DPDP Rules, 2025.
08. Cookies & Tracking Technologies
We use cookies and similar tracking technologies on the Platform to enhance your experience. The types of cookies we use are:
Essential Cookies: Required for core Platform functionality such as authentication and session management. These cannot be disabled.
Analytics Cookies: Help us understand how users interact with the Platform (e.g., pages visited, time spent). Used in aggregated, anonymised form.
Preference Cookies: Remember your settings and preferences for future visits.
Non-essential cookies are only set with your consent, which you can manage via our cookie consent banner or your browser settings. Note that disabling certain cookies may affect Platform functionality.
Complaints to the Data Protection Board
If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India (now constituted under the DPDP Act, 2023) or with the appropriate court of competent jurisdiction. Requests to exercise your rights may be submitted via email to our Grievance Officer using the contact details in Section 12, quoting your account or enquiry reference. We will endeavour to respond within 30 days, subject to the 90-day statutory maximum for grievance redressal prescribed under the DPDP Rules, 2025.
09. Children’s Privacy
The Platform is not directed at children under the age of 18 years. We do not knowingly collect personal data from minors. In compliance with the DPDP Act, 2023 (s.9) and the DPDP Rules, 2025, we commit to the following:
We will not process a child’s personal data without verifiable parental or guardian consent.
We will not engage in tracking or behavioural monitoring of children.
We will not serve targeted advertising directed at children.
If we become aware that we have inadvertently collected data from a child without verifiable parental consent, we will promptly delete such data.
If you believe a minor has submitted personal data to us, please contact our Grievance Officer immediately.
10. Security
We implement security safeguards in accordance with the DPDP Act, 2023 (s.8(5)) and the DPDP Rules, 2025, including:
Encryption of data in transit using TLS/SSL protocols
Encryption of sensitive data at rest
Access controls and role-based permissions for internal systems
Regular security audits and vulnerability assessments
Incident response procedures for data breach notification
Retention of security and access logs for a minimum period of one year (in accordance with DPDP Rule 6)
In the event of a personal data breach, we will: (a) notify affected Data Principals without undue delay upon becoming aware of the breach; and (b) submit a detailed report to the Data Protection Board of India within 72 hours of becoming aware (or within such extended period as the Board may permit), in accordance with DPDP Rule 7. Notification obligations apply to all personal data breaches and are not limited to breaches likely to cause harm.
However, no system is completely secure. We encourage you to use a strong, unique password and to log out of your account after each session.
11.Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. When we make material changes, we will:
Update the “Last Updated” date at the top of this page
Notify registered users via email or an in-Platform notification at least 15 days before the changes take effect
Your continued use of the Platform after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree, you may close your account before the effective date.
12. Grievance Officer & Contact
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, we have designated a Grievance Officer to address concerns regarding the processing of your personal data:
Grievance Officer
Name: Indira Bidari
Designation: Grievance Officer
Organisation: Digicore Technologies Private Limited (operating as UnoSearch)
Email: [email protected], [email protected],
Address: 3rd Floor, Niharika Mirage, Kharghar, Navi Mumbai, India
Response Time: Within 30 days of receipt of grievance (statutory maximum: 90 days per DPDP Rules, 2025)
For general inquiries about this Privacy Policy or your personal data, you may also write to us at:
