Privacy Policy

How Gyanguru collects, uses, shares and protects personal data, and the rights you have under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.

Last updated 5 October 2026

1. Scope

1.1 This Policy applies to personal data that Gyanguru Consultancy LLP, a limited liability partnership registered in India under the Limited Liability Partnership Act, 2008 (LLPIN ACE-5076) ("Gyanguru", "we", "us") processes when you visit the Website, pay us for Timefolk in India, receive payouts from us as a Host, engage us for Consultancy Services, or contact us.

1.2 Timefolk, Inc. separately processes personal data to run the Timefolk apps, accounts and identity verification, under the Timefolk Privacy and Biometric Notice. This Policy explains how the two fit together where they overlap.

1.3 This Policy is published in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").

2. Definitions

2.1 Terms such as "personal data", "data principal", "data fiduciary", "data processor", "processing" and "consent manager" have the meanings given in the DPDP Act. "You" means the data principal whose personal data we process. Other capitalised terms have the meanings in our Terms and Conditions.

3. Who is responsible

3.1 Gyanguru is the data fiduciary for the personal data described in this Policy. For processing that Timefolk, Inc. carries out to run Timefolk, Timefolk, Inc. is a separate data fiduciary, and where it processes data on our instructions it acts as our data processor.

3.2 Questions about this Policy go to our Grievance Officer, whose details are in section 17.

4. Personal data we collect

We collect only what we need for the purposes below.

DataSourcePurposeLegal basisRetention
Name, email, phone numberYou, TimefolkPayments, invoices, support, noticesContract and legitimate use for a voluntary payment (s.7(a))Life of the relationship plus 8 years
Billing name, address, GSTINYouTax invoices, GST returnsLegal obligation (s.7(b), (d))At least 72 months from the due date of the annual return for the year
Payment details: amount, date, method type, transaction reference, last 4 digits of a cardPayment aggregatorProcessing, reconciliation, refunds, chargebacks, fraud preventionContract and legal obligation8 years
Session and membership records (requests, cancellations, refunds)TimefolkCollections, refunds, payouts, disputesContract8 years
Host payout details: bank account, IFSC, UPI ID, PANHostsPayouts, TCS and TDS reportingContract and legal obligation8 years after the last payout
Messages, complaints and call notesYouSupport and grievance handlingContract and legitimate use3 years after closure
Consultancy client contacts and engagement dataClientsDelivering Consultancy ServicesContract8 years after the engagement
Website logs: IP address, browser, pages, timestampsYour deviceSecurity and abuse preventionLegitimate use and consent180 days

4.1 We do not receive your identity document images or biometric data. Identity and liveness checks for Timefolk are run by Timefolk, Inc. and its verification provider. We may receive the result of a check (passed or not) where it affects a Payment or refund.

4.2 We do not collect full card numbers, CVV, UPI PINs or net banking passwords. These are handled only by the payment aggregator.

5. How we use personal data

5.1 We use personal data to:

  1. collect Payments, issue invoices and credit notes, process refunds and pay Hosts;
  2. meet our obligations under tax, payment, anti-money-laundering, consumer protection and information technology laws, and respond to lawful requests from authorities;
  3. prevent, detect and investigate fraud, chargeback abuse, security incidents and breaches of our Terms;
  4. respond to questions and resolve grievances;
  5. deliver Consultancy Services and manage client relationships;
  6. operate, secure and improve the Website; and
  7. establish, exercise or defend legal claims.

5.2 We do not sell personal data, and we do not use it for third-party advertising.

6. Consent and withdrawal

6.1 Where we rely on consent, we ask for it through a clear notice that sets out the data and purpose, as required by sections 5 and 6 of the DPDP Act. You may withdraw consent at any time by writing to support email, as easily as you gave it.

6.2 Withdrawing consent does not affect processing done before withdrawal, and does not affect processing we carry out on another lawful basis, such as a legal obligation. If you withdraw consent needed to provide a Service, we may be unable to continue providing it.

7. Legitimate uses

7.1 Under section 7 of the DPDP Act we may process personal data without separate consent where you have voluntarily provided it for a specified purpose (such as making a Payment) and not objected; to comply with any law or any judgment or order; to respond to a medical emergency or threat to safety; and for the other legitimate uses listed in that section.

8. Who we share personal data with

8.1 We share personal data only as needed for the purposes above, with:

  1. payment aggregators and banks authorised by the Reserve Bank of India, to process Payments, refunds and payouts;
  2. Timefolk, Inc. (United States), which operates the Timefolk platform, so that accounts, requests, Payments and refunds stay consistent;
  3. cloud hosting, email, SMS and messaging providers that host our systems and send our notices, acting as our data processors;
  4. the identity verification provider used by Timefolk, Inc., where a check affects a Payment;
  5. the other member in a session, only what they need, such as a public name and session details;
  6. chartered accountants, auditors, lawyers and other professional advisers, under duties of confidentiality;
  7. Government authorities, courts, regulators and law enforcement agencies, where required by law or a lawful order, including under rule 3(1)(j) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; and
  8. a successor in a merger, acquisition, restructuring or sale of all or part of our business, subject to this Policy.

8.2 Our data processors may process personal data only on our instructions and under written contracts that require them to keep it confidential and secure, as required by section 8(2) of the DPDP Act.

9. Transfers outside India

9.1 Some personal data is processed outside India, including by Timefolk, Inc. in the United States and by cloud and messaging providers in other countries. We transfer personal data abroad only as permitted under section 16 of the DPDP Act and will not transfer it to any country restricted by the Central Government. We require recipients to protect it to a standard comparable to this Policy.

10. Retention

10.1 We keep personal data only for as long as needed for the purposes in this Policy, or as required by law. The retention periods are shown in the table in section 4. When the period ends, we delete the data or anonymise it so it can no longer identify you, unless we must keep it to comply with law or for a pending claim, dispute or investigation.

10.2 Under section 8(7) of the DPDP Act, we erase personal data when you withdraw consent or when the purpose is no longer served, unless retention is required by law.

11. Security

11.1 We maintain reasonable security practices and procedures as required by section 43A of the Information Technology Act, 2000, the SPDI Rules and section 8(5) of the DPDP Act, including:

  1. encryption of data in transit using TLS;
  2. role-based access controls, multi-factor authentication for administrative access, and least-privilege access for staff;
  3. logging and monitoring of access to systems holding personal data;
  4. due diligence on, and written contracts with, data processors;
  5. secure backups and tested restoration; and
  6. card data handled only by payment aggregators certified under the Payment Card Industry Data Security Standard (PCI DSS).

11.2 No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we will act promptly on any incident.

12. Personal data breaches

12.1 If a personal data breach occurs, we will inform the Data Protection Board of India and each affected data principal in the form and manner prescribed under section 8(6) of the DPDP Act, and report cyber security incidents to CERT-In within the time required by its directions.

13. Your rights

13.1 Under the DPDP Act you have the right to:

  1. obtain a summary of the personal data we process about you, the processing activities, and the identities of the other data fiduciaries and processors we have shared it with (section 11);
  2. correct inaccurate or misleading data, complete incomplete data, and update data (section 12);
  3. erase personal data that is no longer needed, unless we must keep it by law (section 12);
  4. have a readily available means of grievance redressal (section 13); and
  5. nominate another person to exercise your rights if you die or become incapable (section 14).

13.2 To exercise a right, email support email from the address we hold for you, or write to our Grievance Officer. We may ask for information to verify your identity before acting, so that we do not disclose data to the wrong person. We respond within 30 days.

13.3 You also have duties under section 15 of the DPDP Act, including not to register a false or frivolous grievance and not to impersonate another person.

14. Children

14.1 Our Services are only for people aged 18 and over. We do not knowingly process personal data of children, and we do not offer verifiable parental consent. If we learn that we have collected personal data of a child, we will delete it.

15. Cookies and automated decisions

15.1 How we use cookies is explained in our Cookie Policy.

15.2 We use automated checks to screen Payments and payouts for fraud, which may delay or hold a transaction. No decision with legal or similarly significant effect on you is made solely by automated means without human review; you may ask for a person to review any automated decision by writing to support email.

16. Communications

16.1 We send service messages about Payments, refunds, invoices and your account. You cannot opt out of these while you use the Services.

16.2 We send marketing messages only with your consent. You can opt out at any time by using the unsubscribe link or writing to us. We comply with the Telecom Commercial Communications Customer Preference Regulations, 2018 and do not send promotional SMS or calls to numbers registered on the National Customer Preference Register (DND) without consent.

17. Grievance Officer

17.1 For any question, complaint or request about personal data, contact our Grievance Officer, appointed under rule 5(9) of the SPDI Rules and section 8(10) of the DPDP Act. We acknowledge grievances within 48 hours and resolve them within one month.

Grievance Officer
grievance officer name
Gyanguru Consultancy LLP
Email: support email
Phone: phone number
Address: registered office address

17.2 If you are not satisfied with our response, you may complain to the Data Protection Board of India under section 13(3) of the DPDP Act, after exhausting our grievance process.

18. Changes to this Policy

18.1 We may update this Policy from time to time. The date at the top shows when it last changed. We will tell you about material changes by email or on the Website before they take effect where we can.