Privacy Policy

Effective Date: September 17, 2026  |  Version 2.1

Issued by Saproh Private Limited for the Pingovo Platform

This Privacy Policy describes in detail how Saproh Private Limited, operating the Pingovo platform, collects, uses, stores, shares, and otherwise processes your Personal Data. Please read this document in its entirety. Your continued use of the Platform constitutes your acceptance of this Policy.

1. Overview & Identity of the Controller

The Pingovo platform is a software-as-a-service (SaaS) product developed, owned, and operated by Saproh Private Limited, a company incorporated under the Companies Act, 2013 of India ("Saproh", "We", "Us", or "Our").

Saproh acts as the Data Controller in respect of Personal Data it collects from users, website visitors, and account holders in connection with the provision of the Services.

Saproh acts as a Data Processor when processing Personal Data of third parties (such as email contacts) on behalf of Customers who upload such data to the Platform for verification or campaign sending purposes. In such cases, the Customer is the Data Controller.

This Privacy Policy applies to all interactions with the Pingovo Platform, including the website at pingovo.com, the web application, the REST API, and all related tools and services.

This Privacy Policy should be read in conjunction with our Terms of Service, which govern your use of the Platform.

2. Scope of This Policy

This Privacy Policy applies to Personal Data collected from or about:

  • Visitors who browse the Pingovo website without creating an account
  • Registered users and account holders
  • Paying subscribers on any plan tier
  • Users of the guest verification feature
  • API consumers and developer users
  • Individuals who contact our support team
  • Individuals who submit enquiries, leads, or contact forms
  • Recipients of email campaigns sent through the Platform (to the extent tracking data is collected)
  • Blog readers and commenters

This Policy does not apply to third-party services or websites linked from the Platform, or to the data practices of Customers who use Pingovo to send communications to their own contact lists — Customers bear sole responsibility for their own data practices with respect to their contacts.

3. Definitions

"Contact" — A natural person identified or identifiable from data uploaded by a Customer to the Platform, such as an email address or name.

"Customer" — A company or individual with a registered Pingovo account.

"Data Controller" — The entity that determines the purposes and means of processing Personal Data.

"Data Processor" — An entity that processes Personal Data on behalf of a Data Controller.

"Data Subject" — An identified or identifiable natural person whose Personal Data is processed.

"DPDPA" — The Digital Personal Data Protection Act, 2023 of India, and rules made thereunder.

"GDPR" — Regulation (EU) 2016/679 of the European Parliament and of the Council.

"Email Data" — Email addresses and associated contact records submitted by Customers to the Platform for verification, campaign sending, or any other purpose.

"Personal Data" — Any information relating to an identified or identifiable natural person, as defined under applicable law.

"Platform" — The Pingovo SaaS application operated by Saproh Private Limited.

"Processing" — Any operation or set of operations performed on Personal Data, including collection, storage, use, disclosure, deletion, and all other forms of handling.

"Services" — All features and functions provided through the Platform, including email verification, campaigns, warmup, API access, and analytics.

"Sensitive Personal Data" — Financial information, passwords, payment card details, and other categories of sensitive data as defined under applicable Indian law.

"Verification Data" — The inputs (email addresses) and outputs (verification results, MX records, SMTP responses, deliverability status) generated through the email verification Services.

4. Categories of Data We Collect

4.1 Account & Identity Data

  • Full name and display name
  • Email address (used as primary identifier)
  • Password (stored as a bcrypt hash — never in plaintext)
  • Company name and account type (individual or enterprise)
  • Business email addresses (enterprise accounts)
  • Account role and permissions

4.2 Billing & Financial Data

  • Subscription plan details and billing cycle
  • Transaction history, invoice records, and payment amounts
  • Razorpay customer ID and subscription ID (tokenised reference — full card data is never stored by Saproh)
  • Applied coupon codes
  • GST/VAT registration number where applicable

4.3 Email Data & Verification Data

  • Email addresses submitted for verification (single or bulk)
  • Verification results: status (safe/risky/invalid/unknown), syntax validity, MX records, SMTP response, catch-all flag, disposable flag, role account flag, free email flag, spamtrap flag, domain typo, parked domain flag
  • Uploaded CSV/Excel files containing email lists
  • Job identifiers, timestamps, and processing metadata

4.4 Campaign & Template Data

  • Campaign names, subject lines, and email body content
  • Recipient lists and associated contact attributes
  • Email templates (HTML and drag-drop designs)
  • Campaign settings: sending schedules, daily limits, delay configurations
  • Campaign delivery statistics: sent, opened, clicked, bounced, unsubscribed counts

4.5 SMTP & Sending Infrastructure Data

  • SMTP host, port, and username
  • SMTP passwords (encrypted with AES-256 at rest; never returned through API or UI after initial input)
  • Sender email addresses and their verification status
  • SMTP health metrics: delivery rate, bounce rate, connection test results

4.6 Technical & Usage Data

  • IP address and approximate geolocation
  • Browser type, version, and operating system
  • Device type and screen resolution
  • Pages visited, features used, and session duration
  • Referral sources and UTM parameters
  • API request logs including endpoint, timestamp, response code, and IP address
  • Error logs and crash reports
  • Rate limiting data

4.7 Communication & Support Data

  • Support ticket content and history
  • Email correspondence with Saproh
  • Contact form submissions and sales lead data
  • Blog comments
  • Notification preferences
  • Feedback and feature requests

4.8 Warmup Data

  • Warmup campaign configurations and schedules
  • Warmup engagement logs: open events, reply events, spam-folder-rescue events
  • Domain health scores and inbox placement metrics

4.9 Webhook & Integration Data

  • Webhook endpoint URLs
  • Event subscription preferences
  • Webhook delivery logs and retry records
  • Custom headers provided by the Customer

4.10 Subscriber List & Public Signup Data

  • Subscriber list contact data uploaded by a Customer, including email addresses and any additional attributes the Customer includes
  • Where a Customer enables a public signup form for one of their subscriber lists, data submitted directly by the visitor who signs up: the submitted email address, any additional fields the Customer has configured for that form, the visitor's IP address, browser user agent, and the timestamp of double opt-in confirmation
  • Subscriber status (active, unsubscribed, bounced) and consent-source records

5. How We Collect Data

5.1 Directly from You

When You register for an account, complete forms, upload files, create campaigns, configure SMTP settings, contact support, or otherwise interact with the Platform.

5.2 Automatically Through Your Use

Through server logs, cookies, tracking pixels, and similar technologies as You navigate the website and use the Platform. This includes IP addresses, browser data, and usage patterns.

5.3 From Your Email Lists

When You upload email addresses for verification or campaign purposes, We process those addresses as part of the service delivery. This data is submitted by You and You are responsible for its legal basis.

5.4 From Email Recipients (Tracking)

When recipients open campaign emails containing tracking pixels, or click tracked links, the Platform records this activity including IP address, timestamp, user agent, and geolocation. This data is attributable to the recipient's email address.

5.5 From Third-Party Services

From Razorpay regarding payment status and billing events. From DNS and SMTP infrastructure during the verification process. From any third-party integrations authorised by the Customer.

5.6 From Guest Verification

When visitors use the guest verification feature on the landing page, We collect the submitted email address, the verification result, the visitor's IP address, and browser information for rate limiting and fraud prevention purposes.

5.7 From Public Signup Forms (Double Opt-In)

A Customer may enable a public signup form for one of their subscriber lists and share its link with their own audience. When a visitor submits that form, the Platform sends them a confirmation email; the visitor is added to the Customer's subscriber list only once they click the confirmation link (double opt-in). We record the visitor's IP address and browser user agent as evidence of that consent. In this flow the visitor submits their own data directly to the Platform, rather than the data being uploaded by the Customer. The Customer remains the Data Controller of this data and Saproh acts as the Data Processor, as described in Section 1.

5.8 From Live Chat

When You use the chat widget on our website, We collect the messages You send and, if You ask to speak to our Support or Sales team without being signed in, the name, email address and mobile number You enter so that a team member can reply to You. We also record the page You were on, Your browser user agent, and a one-way hash of Your IP address (We do not store the address itself) to route the chat and to prevent abuse. Answers to general questions are produced from Pingovo's own help content; if We enable an AI language model to rephrase those answers, Your message is sent to it with contact details removed. Chats You have while signed in are part of Your account data and are deleted with it. Chats from visitors without an account are deleted automatically after a fixed retention period (chats that only involved the automated assistant are deleted sooner). A sales chat may also create a lead record so that our team can follow up.

6. Purposes & Legal Bases for Processing

PurposeData CategoriesLegal BasisRetention
Account creation & managementIdentity, billing dataContract performanceDuration of account + 30 days post-deletion
Providing verification servicesEmail Data, Verification DataContract performanceVisible to the Customer for their plan retention period (1–365 days); retained internally for up to 5 years (see §9.3); cached results may be held longer for system improvement
Email campaign deliveryCampaign data, recipient lists, SMTP dataContract performanceCampaign records for the duration of the account; recipient lists visible to the Customer for their plan retention period (1–365 days), retained internally for up to 5 years (see §9.4); campaign logs up to 24 months
Campaign analytics & trackingOpen/click events, tracking pixel dataLegitimate interest (Customer's performance analytics)Visible to the Customer for their plan retention period (1–365 days); retained internally for up to 5 years (see §9.4)
Billing & payment processingBilling data, transaction recordsContract performance / Legal obligationAs required by tax law (typically 7 years)
Email warmup servicesWarmup data, SMTP dataContract performanceDuration of warmup campaign + 12 months
API access & key managementAPI keys, usage logsContract performanceDuration of account; logs 12 months
Fraud detection & preventionTechnical data, IP, usage patternsLegitimate interestUp to 12 months
Security monitoring & abuse preventionIP, logs, rate limit dataLegitimate interest / Legal obligationUp to 12 months
Platform improvement & R&DAggregated/anonymised usage dataLegitimate interestIndefinitely in anonymised form
Customer supportCommunication data, account dataContract performance / Legitimate interestDuration of account + 12 months
Legal compliance & regulatory obligationsAny relevant dataLegal obligationAs required by applicable law
Marketing communications (opted-in)Email, name, preferencesConsentUntil consent is withdrawn
Guest verification (unregistered users)Email address, IP, browser dataLegitimate interest / Contract performance30 days
Webhook & integration deliveryWebhook data, event logsContract performanceDuration of account + 6 months
Subscriber list management & public signup formsSubscriber list data, public signup submissions, consent recordsContract performance (with the Customer) / Consent (the visitor's own opt-in)Duration of the Customer’s account

7. Processing of Email Data & Verification Data

7.1 Nature of Email Data Processing

Email addresses submitted to the Platform for verification represent Personal Data of third parties. Saproh processes such data strictly as a Data Processor on behalf of the Customer (the Data Controller). The Customer is solely responsible for ensuring a lawful basis for submitting such Personal Data to Saproh.

7.2 Technical Verification Process

To provide verification services, Saproh's systems perform the following technical operations on submitted email addresses:

  • Syntax analysis — parsing and validating the format of the email address
  • DNS lookups — resolving MX records for the domain component of the address
  • SMTP handshake testing — initiating SMTP connections to the domain's mail exchangers to test mailbox acceptance. This involves sending EHLO/HELO and RCPT TO commands to the receiving mail server. No actual email is sent. The Customer expressly acknowledges and consents to these technical operations.
  • Disposable, spamtrap & pattern checks — cross-referencing against internal databases of known disposable domains, spamtrap patterns, and parked domain MX records

7.3 Verification Result Caching

Saproh caches verification results for service efficiency. Cached results are keyed to the email address (or a hash thereof) and may be returned to any customer who subsequently verifies the same address. By submitting Email Data, the Customer consents to Saproh caching results and using cached results for the benefit of all Platform customers. Cached results are retained according to the status-based cache TTL set out in the Documentation (safe: 4 hours; risky: 24 hours; invalid: 7 days).

7.4 SMTP Sender Domain Use

To perform SMTP verification, the Platform uses a pool of Saproh-controlled sender domains (including subdomains of pingovo.com and other registered domains). SMTP connections are initiated from these domains. The Customer acknowledges this and agrees that Saproh's use of these domains for verification is a standard and necessary part of the Services.

7.5 Pingovo Mail — From Address Handling

When a Customer chooses the Pingovo Mail sending method, campaign emails are delivered from a Saproh-assigned subdomain address (e.g. [email protected]) with the Customer's real email address set as the Reply-To header. Recipients who reply are directed to the Customer's actual inbox. The Customer's real email address is not transmitted in the From header in this mode but is disclosed via Reply-To.

7.6 Outbound Email Content Analysis

Campaign emails sent via Pingovo Mail are analysed by an on-premises content-scoring engine (Rspamd) before delivery. This analysis examines email headers, subject lines, and body content to calculate a spam-probability score. Emails exceeding the configured score threshold may be blocked or flagged before sending. This processing occurs entirely on Saproh's own infrastructure and content is not transmitted to any third party. The purpose of this processing is to protect IP pool reputation and comply with anti-spam regulations; it is based on Saproh's legitimate interests as an email infrastructure provider.

8. Our Rights to Use Data

This section describes important rights Saproh retains over data generated through use of the Platform. Please read carefully.

8.1 Aggregated & Anonymised Data — Unrestricted Use

Saproh shall have a perpetual, irrevocable, worldwide, royalty-free right to collect, compile, aggregate, anonymise, and de-identify data derived from usage of the Services — including Email Data, verification outcomes, SMTP response patterns, domain reputation data, campaign performance statistics, delivery rates, and user behaviour — and to use such aggregated, anonymised data without restriction for any commercial, research, development, or operational purpose. This right is not limited by any termination or expiry of this Agreement.

8.2 Verification Engine Improvement

Verification results, SMTP response classifications, disposable domain detections, and MX infrastructure analyses derived from Email Data may be incorporated into Saproh's internal verification engine, pattern databases, and machine learning models. The Customer grants Saproh a perpetual, irrevocable licence to use such derived, non-personally- identifiable technical data for this purpose.

8.3 Platform Analytics

Saproh may use Customer usage data, feature interaction data, and performance telemetry — without identifying the Customer — to analyse Platform usage, develop new features, optimise system performance, generate industry reports, and make business decisions.

8.4 Security & Abuse Prevention

Saproh may process Customer data, including content and usage patterns, to detect, investigate, and prevent fraud, spam, abuse, and security threats across the Platform and for all customers.

8.5 Testimonials & Case Studies

With the Customer's prior written consent, Saproh may reference the Customer's name and general use case in marketing materials, case studies, or testimonials.

8.6 No Sale of Personal Data

Saproh does not sell, rent, or trade identifiable Personal Data of Users or Contacts to third parties for their independent marketing purposes.

9. Data Retention

9.1 General Principle

Saproh retains Personal Data only for as long as is necessary for the purposes described in this Policy, or as required or permitted by applicable law.

9.2 Account Data

Account data is retained for the duration of the active account and for a period of 30 days following account deletion (to allow for account recovery). After 30 days, account data is permanently deleted, except where retention is required by law.

9.3 Email Data & Verification Results

Uploaded email files are stored encrypted and are accessible to the Customer for the duration set by the applicable subscription plan (1 day on Free, up to 365 days on Pro). Once that period ends, verification results are withdrawn from the Customer's account and are no longer visible to them, but are retained in our systems for a further period of up to 5 years from the date of verification. That extended retention serves our legitimate interests in support, dispute resolution, abuse and fraud investigation, and compliance; access to it is restricted to authorised Saproh administrators. Users may delete job results at any time. Anonymised or hashed verification results may be retained indefinitely in caches and derived databases.

9.4 Campaign Data

Campaign records and aggregate delivery statistics are retained for the duration of the active account. Per-recipient records and individual open, click and unsubscribe events are accessible to the Customer for the retention period set by their subscription plan (1 day on Free, up to 365 days on Pro), measured from the date the campaign finished sending. After that period they are withdrawn from the Customer's account and retained in our systems for up to 5 years from that date, on the same basis and with the same access restrictions described in §9.3. Campaign logs are retained for up to 24 months.

9.5 Financial Records

Transaction records, invoices, and billing data are retained for a minimum of 7 years from the transaction date, as required by Indian tax and accounting law.

9.6 Technical & Log Data

Server logs, API logs, and security logs are retained for up to 12 months and then deleted or anonymised.

9.7 Backup Systems

Data may persist in encrypted backup systems for a period of up to 90 days following deletion from primary systems. Such backup data is not accessible or recoverable by Customers but will be overwritten in the normal course of backup rotation.

9.8 Aggregated Data

Aggregated, anonymised, or de-identified data derived from any data category may be retained indefinitely.

10. Data Sharing & Disclosure

10.1 Service Providers (Sub-processors)

Saproh engages trusted third-party service providers who process data on our behalf. All sub-processors are bound by data processing agreements and are required to implement appropriate security measures:

Sub-processorPurposeData Shared
RazorpayPayment processingBilling information, transaction data
WorldstreamDedicated server infrastructure hostingAll application data — the database and cache described below run as software on this same infrastructure, not as a separate hosted service
HostingerDNS management for sending domainsSending subdomain and DKIM/SPF/A DNS records (no personal data)
Email infrastructure providersTransactional email deliveryRecipient email, name, notification content
DNSBL / IP reputation servicesSending IP blacklist and reputation checksSaproh-owned IP addresses (no personal data)
Rspamd (on-premises)Outbound email content scoring to prevent spam deliveryCampaign email body and headers (processed on Saproh infrastructure, not transmitted to third parties)

10.2 Legal Disclosure

Saproh may disclose Personal Data when required to do so by applicable law, court order, subpoena, regulatory authority, or governmental investigation. We will endeavour to provide reasonable advance notice to the affected Customer where legally permissible before complying with such requests.

10.3 Business Transactions

In connection with any merger, acquisition, joint venture, reorganisation, insolvency proceeding, or sale of all or substantially all of Saproh's assets, Customer data may be transferred to the acquiring or successor entity. Saproh will notify affected users by email or Platform notice at least 30 days in advance, and users will be given the opportunity to export their data.

10.4 Abuse & Security Reports

Saproh reserves the right to disclose information about Customer campaigns to internet service providers, spam reporting organisations, or law enforcement agencies where Saproh has reasonable grounds to believe that the Customer's use of the Platform constitutes abuse, spam, or illegal activity. No prior notice to the Customer will be given in such cases.

10.5 Aggregated Data

Saproh may share aggregated, de-identified data with third parties for industry research, product development, business analytics, or marketing purposes. Such data cannot reasonably be used to identify any individual or Customer.

10.6 Consent-Based Sharing

We may share Personal Data with additional third parties where You have given explicit, specific, and informed consent to such sharing.

11. International Data Transfers

11.1 Cross-Border Processing

Saproh is incorporated in India and operates primarily from India. Customer data may be stored and processed in India and in other countries where our cloud infrastructure providers operate (including but not limited to the United States, Singapore, and European Union member states).

11.2 Safeguards for International Transfers

When transferring Personal Data to countries that may not have equivalent data protection standards, Saproh implements appropriate safeguards including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA
  • Data processing agreements with sub-processors incorporating appropriate transfer mechanisms
  • Compliance with the DPDPA cross-border data transfer requirements, as notified by the Government of India

11.3 SMTP Connections

As part of the email verification process, the Platform initiates SMTP connections to mail servers located in jurisdictions around the world. This is a technical necessity of the Services. IP addresses associated with verification probes may be logged by receiving mail server operators in those jurisdictions.

12. Data Security

12.1 Technical Measures

Saproh implements the following technical security measures:

  • Encryption in transit — all data transmitted between your browser and the Platform is encrypted using TLS 1.2 or higher
  • Encryption at rest — SMTP passwords are encrypted using AES-256 before storage
  • Password hashing — user passwords are stored using bcrypt with an appropriate cost factor
  • JWT authentication — session tokens use signed JWTs with appropriate expiry
  • API key hashing — API keys are stored as hashed values; only the key prefix is retrievable after creation
  • Rate limiting — API endpoints and authentication routes are rate-limited to prevent brute force and denial-of-service attacks
  • Input validation — inputs are validated and sanitised to prevent NoSQL injection, XSS, and other injection attacks
  • Uploaded file isolation — bulk verification files are stored in isolated, encrypted storage with restricted access
  • PCI DSS-compliant payment processing — payment card data is processed entirely by Razorpay; Saproh never stores raw card data

12.2 Organisational Measures

  • Access to customer data is restricted to personnel who require it to perform their job functions
  • Internal security training for all team members with access to the production environment
  • Regular review of access permissions and security configurations

12.3 Limitation

Despite the measures described above, no method of data transmission over the internet or electronic storage is completely secure. Saproh cannot guarantee absolute security and shall not be liable for breaches resulting from factors outside its reasonable control. The Customer is encouraged to use strong passwords and to report any suspected security vulnerabilities through our Responsible Disclosure Policy.

13. Cookies & Tracking Technologies

13.1 What Are Cookies

Cookies are small text files stored on your device by your browser when you visit a website. We also use similar technologies such as localStorage, sessionStorage, and tracking pixels.

13.2 Essential Cookies

These are strictly necessary for the Platform to function and cannot be disabled. They include authentication tokens, CSRF protection tokens, and session management data.

13.3 Functional Cookies

These cookies remember your preferences and settings (such as language or currency selection) to enhance your experience.

13.4 Analytics Cookies

With your consent, we use analytics technologies to understand how users interact with the Platform — including which pages are most visited, where users drop off, and which features are most used. Third-party analytics (Google Analytics) receive this data in aggregated form only.

If you decline analytics cookies, Google Analytics is loaded in consent mode and collects nothing until consent is granted.

13.5 Website Visit Measurement

We do not measure the browsing of visitors who are not signed in. If you read this website without an account, we set no visit identifier and keep no record of the pages you viewed — with or without analytics consent.

Once you are signed in to your account, we record, on our own servers, the dates you visited, the page paths you landed on, the referring site, any campaign (UTM) parameters in the link you followed, your IP address and your browser user-agent string, against a first-party identifier (pv_vid) in your browser. We do not record query strings, and we do not share this data with third parties for advertising.

We use this to recognise account holders who return repeatedly and may be interested in a paid plan, so our sales team can follow up and so we can send you a short series of emails about our plans, features and offers.

This data is deleted automatically 180 days after your last visit. You can stop the resulting emails at any time using the unsubscribe link in any of them or the notification settings in your account.

13.6 Your Cookie Choices

You can control non-essential cookies through your browser settings. Disabling essential cookies may impair the functionality of the Platform. Most browsers provide instructions for managing cookies in their help documentation.

When you accept, reject, or customise cookies through our banner, we keep a record of that decision (which categories you chose, the date, and your IP address) on our own servers as proof of your choice, separate from the browser cookie itself. This record is distinct from — and unrelated to — the signed-in visit measurement described in §13.5.

14. Campaign & Email Tracking

14.1 Open Tracking

When a Customer enables open tracking for a campaign, Saproh injects a 1×1 transparent tracking pixel into the HTML body of each campaign email. When the recipient opens the email and their email client loads images, the tracking pixel is fetched from Saproh's servers, and an open event is recorded. The data captured includes: recipient email address (via campaign record lookup), timestamp, IP address, and user agent string of the email client.

14.2 Click Tracking

When click tracking is enabled, all hyperlinks in the campaign email are replaced with Saproh-hosted redirect URLs. When a recipient clicks a link, they are first redirected through Saproh's tracking endpoint, which records: recipient email address, link clicked (encoded), timestamp, IP address, and user agent. The recipient is then immediately forwarded to the original destination URL.

14.3 Responsibility for Tracking Compliance

The Customer is solely responsible for ensuring that their use of open and click tracking complies with applicable law, including GDPR, DPDPA, CAN-SPAM, and CASL. This includes providing appropriate disclosures in their privacy notices to email recipients and, where required, obtaining consent for such tracking.

14.4 Saproh's Role

With respect to campaign tracking data, Saproh acts as a Data Processor on behalf of the Customer (who is the Data Controller). Saproh stores this tracking data to provide analytics to the Customer and retains it for up to 24 months.

14.5 Unsubscribe Tracking

Saproh processes unsubscribe requests triggered by recipients clicking the unsubscribe link injected into campaign emails. Unsubscribe records are retained to ensure that unsubscribed contacts are not emailed again through the Platform by the same Customer.

15. Your Rights as a Data Subject

Depending on your location and the applicable data protection law, You may have the following rights with respect to your Personal Data:

Right of Access (Article 15 GDPR / Section 11 DPDPA)

You may request a copy of the Personal Data We hold about You, along with information about how it is processed.

Right to Rectification (Article 16 GDPR / Section 12 DPDPA)

You may request correction of inaccurate, incomplete, or outdated Personal Data.

Right to Erasure / Right to be Forgotten (Article 17 GDPR / Section 13 DPDPA)

You may request deletion of your Personal Data where it is no longer necessary for the purposes collected, you withdraw consent, or processing is unlawful. This right is subject to exceptions for legal obligations and ongoing legitimate interests.

Right to Restriction of Processing (Article 18 GDPR)

You may request that We restrict processing of your Personal Data in certain circumstances (e.g., while contesting accuracy or pending an objection).

Right to Data Portability (Article 20 GDPR)

Where processing is based on consent or contract and is carried out by automated means, You may request a machine-readable copy of your Personal Data for transfer to another controller.

Right to Object (Article 21 GDPR)

You may object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, You may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.

Right to Nominate (Section 14 DPDPA)

Under Indian law, You may nominate another individual to exercise your data protection rights on your behalf in the event of death or incapacity.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority — the Data Protection Board of India (for Indian residents) or the relevant EU/EEA supervisory authority.

How to Exercise Your Rights

For the Right of Access and Right to Data Portability, You can get an immediate copy of your Personal Data yourself via Settings → Security → Download My Data — no request needed. To exercise any other right (rectification, restriction, objection, erasure, or a request You'd prefer to make by email), please submit a written request to [email protected]. We will acknowledge your request within 72 hours and respond within 30 days. We may need to verify your identity before fulfilling a request.

Certain rights may be limited where processing is required for legal compliance, defence of legal claims, or other legitimate overriding interests.

16. India-Specific Provisions (DPDPA & IT Act)

16.1 Applicable Legal Framework

Saproh Private Limited is an Indian company and the primary applicable law governing this Privacy Policy is:

  • The Digital Personal Data Protection Act, 2023 (DPDPA) and rules thereunder
  • The Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • Any other applicable Indian legislation as amended from time to time

16.2 Consent

Where processing of your Personal Data is based on consent under the DPDPA, Saproh will seek your free, specific, informed, and unambiguous consent through a clear affirmative action. You may withdraw such consent at any time by contacting us at [email protected]. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.

16.3 Sensitive Personal Data

Saproh treats the following categories as Sensitive Personal Data requiring heightened protection under Indian law: financial information (payment credentials, transaction data), passwords, and any other category designated as sensitive under applicable Indian regulation. Such data is collected only with Your consent and is processed strictly for the purposes described in this Policy.

16.4 Grievance Officer

In accordance with the Information Technology Act and DPDPA, Saproh has designated a Grievance Officer for Indian users:

Grievance Officer — Saproh Private Limited / Pingovo

Email: [email protected]

Acknowledgement: within 48 hours  |  Resolution: within 30 days

16.5 Data Localisation

Saproh will comply with any applicable data localisation requirements notified by the Government of India from time to time, including requirements to store certain categories of Personal Data within India.

17. European / EEA-Specific Provisions (GDPR)

17.1 Applicability

Where individuals in the European Economic Area (EEA) use the Platform or where Saproh processes Personal Data of EEA residents, the General Data Protection Regulation (GDPR) applies.

17.2 Legal Bases

For EEA residents, Saproh relies on the following legal bases under Article 6 GDPR:

  • Article 6(1)(b) — Contract: Processing necessary to perform the Services subscribed to
  • Article 6(1)(c) — Legal obligation: Processing required for compliance with EU or Indian law
  • Article 6(1)(f) — Legitimate interests: Processing for security, fraud prevention, Platform improvement, and analytics, where such interests are not overridden by data subject rights
  • Article 6(1)(a) — Consent: Where Saproh has obtained explicit consent (e.g., marketing communications)

17.3 Data Protection Representative

As Saproh is established in India and not in the EEA, EEA residents may direct GDPR inquiries to: [email protected]. Saproh will appoint an EU representative as required by Article 27 GDPR if applicable thresholds are met.

17.4 Supervisory Authority

EEA residents have the right to lodge a complaint with their national data protection supervisory authority if they believe their GDPR rights have been violated.

18. Children's Privacy

The Services are not directed at, designed for, or intended to be used by individuals under the age of 18. Saproh does not knowingly collect Personal Data from persons under 18 years of age.

If Saproh becomes aware that it has inadvertently collected Personal Data from a person under 18 without verified parental or guardian consent, it will take prompt steps to delete such data from its systems.

If You are a parent or guardian and believe that Your child's Personal Data has been collected by Saproh, please contact us immediately at [email protected].

20. Data Breach Notification

20.1 Internal Response

Saproh maintains an internal incident response procedure for addressing security incidents, including suspected or confirmed data breaches. Upon becoming aware of a breach, Saproh will assess the nature, scope, and likely impact of the incident.

20.2 Notification to Authorities

Where a data breach is likely to result in a risk to the rights and freedoms of individuals, Saproh will notify the relevant supervisory authority within the timeframe required by applicable law (72 hours under GDPR; as prescribed under DPDPA).

20.3 Notification to Affected Users

Where a breach is likely to result in a high risk to affected individuals, Saproh will notify affected users without undue delay. Such notification will include a description of the nature of the breach, the data involved, likely consequences, and steps being taken to address the breach.

20.4 Limitation

Saproh's breach notification obligations apply to breaches of Saproh's own systems. Saproh is not responsible for breaches that occur due to Customer negligence, including compromised credentials or misconfigured integrations.

21. Changes to This Policy

Saproh reserves the right to update this Privacy Policy at any time. When We make material changes, We will notify Users by email and/or by a prominent notice on the Platform at least 30 days before the changes take effect, where reasonably practicable.

The "Effective Date" at the top of this document indicates when the current version took effect. Your continued use of the Services after the effective date of any change constitutes acceptance of the updated Privacy Policy.

We encourage You to review this Policy periodically. If You do not agree with any changes, You must cease use of the Services and, if applicable, delete Your account.

22. Contact & Grievance Information

For all privacy-related enquiries, data subject requests, or grievances regarding this Policy, please contact:

Saproh Private Limited

Operating as: Pingovo (pingovo.com)

Privacy & Data Protection: [email protected]

Grievance Officer: [email protected]

General Support: [email protected]

Legal: [email protected]

Response time: Within 72 hours for acknowledgement; within 30 days for resolution.

We use essential cookies to run this site, and optional functional/analytics cookies to improve it. See our Privacy Policy for details.