Legal
Privacy Policy
This Privacy Policy explains how Navelo Software (“Navelo Software”, “we”, “us”, “our”) collects, uses, discloses, stores, and protects information when you visit www.navelosoftware.com, contact us, or engage us for software development, consulting, or related services. Each of our mobile applications is governed by its own product-specific privacy policy linked from the product page; this policy governs our corporate website and business operations only.
Last updated · January 2026
1. Who we are & scope
Navelo Software is a software development and IT services provider headquartered at Mohali, Punjab – 140301, India. For the purposes of the EU/UK GDPR and similar laws, Navelo Software acts as a “data controller” for personal data we collect through this website and our direct business communications, and as a “data processor” for personal data that our clients route through systems we build, host, or operate on their behalf.
This policy does not apply to third-party websites, services, app stores, or platforms that we do not own or control, even where linked from our site.
2. Information we collect
We collect only information we need for clearly defined business purposes:
- Information you provide directly — name, business email, company, phone number, project brief, and any other details you choose to share when submitting our contact form, requesting a proposal, signing an NDA, or corresponding with us by email.
- Contractual & billing information — entity name, signatory details, billing address, tax identifiers (GSTIN/VAT), purchase orders, and invoice records, where you engage us under a Statement of Work (SOW) or Master Services Agreement (MSA).
- Technical & log data — IP address, device and browser type, operating system, referring URL, pages viewed, and approximate region, collected through standard web server logs and aggregated, privacy-respecting analytics.
- Cookies & similar technologies — strictly necessary cookies used to operate the site and, where enabled, first-party analytics cookies. We do not deploy third-party advertising or cross-site tracking cookies.
- Recruitment data — if you apply for a role, the contents of your CV, cover letter, and application correspondence.
We do not knowingly collect special-category personal data (such as health, biometric, or political data) through this website. Please do not submit such information through our contact channels.
3. How we use information & legal bases
We use personal data for the following purposes, relying on the legal bases indicated:
- Responding to enquiries and providing proposals — performance of a contract or steps taken at your request before entering a contract.
- Delivering and administering client services — performance of a contract with the client entity.
- Billing, accounting, tax, and recordkeeping — compliance with legal obligations.
- Securing and improving the site — our legitimate interest in operating a safe, performant website.
- Marketing communications — only where you have opted in, or where permitted as a soft opt-in to existing business contacts. You can withdraw consent at any time.
- Recruitment — steps taken at your request and our legitimate interest in evaluating candidates.
We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on individuals.
4. Sharing & disclosure
We do not sell, rent, or trade personal data. We disclose personal data only:
- To vetted service providers acting on our behalf (e.g., email, hosting, analytics, accounting, CRM, payment processors) under written confidentiality and data-protection terms.
- To professional advisers (lawyers, auditors, insurers) under duties of confidentiality.
- To regulators, law-enforcement, or courts where required by applicable law, lawful order, or to establish, exercise, or defend legal claims.
- In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality and continuity-of-purpose safeguards.
5. International transfers
We are based in India and may transfer personal data to service providers in other jurisdictions. Where personal data of EU/UK/EEA residents is transferred outside their region, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms, and apply supplementary measures where reasonably necessary.
6. Data retention
We retain personal data only for as long as necessary for the purposes described, then delete or anonymise it. Indicative retention periods:
- Contact form submissions and prospective-client correspondence — up to 24 months from last interaction.
- Active client records — for the duration of the engagement and up to 8 years thereafter to meet tax, accounting, and statutory record-keeping requirements under Indian law.
- Web server and security logs — typically 30–180 days.
- Recruitment data — up to 12 months after a hiring decision, unless you ask us to keep it on file longer.
7. Security
We maintain reasonable technical and organisational measures appropriate to the risk, including TLS in transit, encrypted storage where supported, least-privilege access controls, MFA on administrative accounts, hardened endpoints, vendor due diligence, and confidentiality obligations on personnel. No internet-based service is perfectly secure; you transmit data to us at your own risk and should use strong, unique credentials in any client portal we provide.
8. Your rights
Subject to applicable law (including the EU/UK GDPR, India’s Digital Personal Data Protection Act, 2023, and the California Consumer Privacy Act/CPRA), you may have the right to:
- Access the personal data we hold about you and request a copy.
- Request correction of inaccurate or incomplete data.
- Request deletion (“right to be forgotten”), subject to legal retention obligations.
- Object to or restrict certain processing, including direct marketing.
- Request data portability of information you provided to us.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint with your local supervisory authority.
California residents have additional rights under the CCPA/CPRA, including the right to know categories of personal information collected and disclosed, and the right to opt out of any “sale” or “share” of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
To exercise any right, write to support@navelosoftware.com from the address associated with your data. We may need to verify your identity before responding and will reply within statutory timeframes.
9. Children’s privacy
This website and our corporate services are not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided personal data, please contact us and we will delete it.
10. Cookies
We use strictly necessary cookies to operate the site and may use first-party, privacy-respecting analytics to understand aggregate usage. You can control cookies through your browser settings; disabling strictly necessary cookies may impair site functionality.
11. Third-party links
Our site may contain links to third-party websites (including app store listings and partner sites). We are not responsible for their content or privacy practices. Please review their policies before providing personal data.
12. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with a revised “Last updated” date and, where appropriate, additional notice. Your continued use of the site after changes take effect constitutes acceptance of the updated policy.
13. Contact & grievance officer
Privacy questions, requests, or complaints should be sent to support@navelosoftware.com, marked “Privacy Request”. Postal correspondence may be sent to Mohali, Punjab – 140301, India.
For users in India, the same address and email serve as our contact point under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023.
See also our Terms of Use, Refund Policy, and Legal Information.