Data Policy
Adiuvo is committed to ensuring its services, data, and infrastructure security, confidentiality, integrity, and availability. This Service Security Policy outlines the security measures, protocols, and legal considerations to protect user data, systems, and applications in compliance with Indian laws, including the Information Technology Act, 2000 (IT Act) and emerging data protection regulations.
This policy applies to all users, employees, contractors, and third-party service providers engaged with Adiuvo. It covers data security, system protection, application security, and user confidentiality while ensuring compliance with relevant data protection laws and regulations.
Data Security
- Only necessary user data is collected for service execution, in accordance with the IT Act and related rules. Personal data is processed lawfully, fairly, and transparently. Users have the right to access, modify, or request deletion of their personal data, as per applicable laws.
- All user data is encrypted using industry-standard encryption algorithms. Sensitive information is stored in secure, access-controlled environments. Backup systems are regularly tested to ensure data availability.
- User data is not shared with third parties without explicit consent, except as required by law.
- Role-based access control (RBAC) is enforced to limit data access to authorized personnel only
- Multi-factor authentication (MFA) is required for access to sensitive systems.
System Security
- Adiuvo services are hosted on secure, monitored cloud environments.
Firewalls, intrusion detection systems (IDS), and anti-malware solutions are implemented. Regular security audits and vulnerability assessments are conducted. - A dedicated incident response team monitors and addresses security threats. Users are notified in case of security breaches affecting their data. Forensic investigations are conducted to mitigate and prevent future risks
- Vendors providing critical services must comply with Adiuvo security policies.
- Third-party integrations are subject to regular security assessments. Data Processing Agreements (DPAs) are established with vendors handling user data to ensure compliance with Indian legal requirements.
Application Security
- Security is integrated into the software development lifecycle (SDLC).
- Secure coding practices, penetration testing, and automated security scans are enforced.
- Strong password policies and MFA are enforced for user accounts.
- Unauthorized access attempts are logged and monitored. User sessions are time-limited for operational security and fair usage.
Confidentiality & Privacy Protection
- Users must secure their login credentials.
- Suspicious activities should be reported to Adiuvo immediately.
- Adiuvo ensures compliance with the IT Act and other applicable regulations.
- Employees handling user data are trained and knowledgeable about the nuances of data protection regulations.
Compliance & Legal Considerations
- Adiuvo adheres to Indian cybersecurity laws and standards, including the IT Act and CERT-In guidelines. Data Protection Impact Assessments (DPIA) are conducted periodically to ensure compliance.
- Users agree to Adiuvo’s Terms of Service and Privacy Policy before using the service. Adiuvo is not liable for security breaches resulting from user negligence.
- Any legal disputes shall be governed by Indian law and adjudicated in Indian courts, specifically within Jabalpur, Madhya Pradesh.
Policy Updates & Revisions
This policy is reviewed and updated annually or as needed in compliance with Indian laws. Users will be notified of significant changes affecting their rights or security.
Contact Information
For security-related inquiries or incident reports, users may contact Adiuvo’s Security Team at adiuvo.in@gmail.com
User Agreement
By using Adiuvo, users acknowledge and agree to the security measures outlined in this policy.