GARUDHUB | PRIVACY POLICY
Page 1
PRIVACY POLICY
GarudHub / DroneHub - ChandraGhanshyam & Associates LLP
Effective date: 27 August 2026
Last updated: 27 August 2026
Website: https://garudhub.com/
Operator: ChandraGhanshyam & Associates LLP
Plain-language summary. We collect only the information reasonably needed to answer enquiries, arrange drone-related services, process or refer applications, protect the Platform, and meet legal duties. We do not sell personal data. Where a request requires a lender, insurer, employer, training institute, seller, repair centre, logistics provider, recycler, consultant, or government portal, we share relevant information only as described below.
Important: This Policy describes the Platform's current public website and the connected services advertised on it. Some features may be introduced in stages. If a feature is not yet active, the related collection will begin only when that feature is offered and an appropriate notice or consent is presented.
1. About this Policy
This Privacy Policy explains how ChandraGhanshyam & Associates LLP ("CGA", "we", "us", or "our") collects, uses, stores, discloses, and protects personal data through garudhub.com and related pages, forms, communications, dashboards, and services (together, the "Platform"). The website uses the names "GarudHub" and "DroneHub"; both names refer to the Platform operated by CGA unless a page states otherwise.
This Policy is intended to be read with the Platform's Terms of Service, Refund Policy, any service-specific notice, consent request, partner terms, and the terms of the relevant third-party provider.
2. Scope and our role
This Policy applies when you browse the Platform, submit an enquiry, request a quote, create or use a profile, upload documents or photographs, purchase or request products, seek training, compliance, repair, recycling, finance, insurance, career, professional, partner, or government-scheme support, or communicate with us.
For personal data collected directly by CGA for Platform operations, CGA generally decides why and how the data is processed and acts as the data fiduciary. A lender, insurer, payment provider, employer, seller, training institute, repair centre, logistics provider, recycler, professional adviser, government authority, or other partner may independently decide how to process data it receives. That partner's own privacy notice and legal obligations will then apply in addition to this Policy.
The Platform is not a government portal, bank, non-banking financial company, insurer, credit bureau, employer, DGCA authority, or training-certification authority merely because it provides information, matching, tracking, or application support. Final decisions are made by the relevant authorised third party.
GARUDHUB | PRIVACY POLICY
Page 2
3. Personal data we may collect
The exact data depends on the service you request. We seek to collect only information necessary for the stated purpose and will provide a more specific notice where a form or service requires additional data.
Category
Contact and enquiry data
Examples
Name, email address, mobile number, address, city, state, country, pincode, remarks, service requested, preferred contact method, and correspondence.
Identity and compliance data
Age or date of birth where relevant; PAN, Aadhaar or other identity/address proof where lawfully required; business identifiers; signatures; DGCA/UIN records; Remote Pilot Certificate; licences; permits; insurance and compliance documents.
We will not ask for passwords, OTPs, PINs, or full payment-card credentials.
Account and profile data
User or partner identifier, login/contact details, profile information, preferences, saved items, application or service status, and account activity, if account features are introduced.
Drone and equipment data
Make, model, category, serial or identification number, purchase date, warranty, specifications, photographs, condition, issue description, location, ownership records, service history, and accessory compatibility details.
Purchase, payment, and order data
Products or services requested, quotation, price, invoice, tax details, payment status, refund or dispute information, delivery/pickup address, and transaction reference. Full payment credentials should be handled by the authorised payment provider.
Finance and insurance data
Applicant and co-applicant details, employment or business data, income, turnover, bank statements, tax returns, loan purpose and amount, repayment preferences, credit/KYC information, existing liabilities, policy requirements, claim documents, and partner decisions where lawfully received.
Training and career data
Course interests, education, certificates, practical reports, training progress, skills, flight hours, drone types, experience, location, availability, resume, portfolio, employment preferences, application status, and employer feedback where provided.
Business, partner, and tender data
Entity name and type, registrations, ownership/contact details, service capabilities, professional credentials, pricing, project proposals, eligibility records, financial documents, tender/scheme documents, declarations, bank details where necessary, and due-diligence information.
Repair, logistics, and recycling data
Pickup/drop address, contact person, diagnostic details, estimates and approvals, warranty claim data, service-centre records, photographs, valuation, payout details, recycling status, and completion certificate.
GARUDHUB | PRIVACY POLICY
Page 3
Category
Technical and usage data
Examples
IP address, browser and device type, operating system, timestamps, referring page, page or feature usage, error and security logs, approximate location derived from IP, cookie identifiers, and similar online activity data.
3.1 Data from other sources
We may receive information from:
• a person or organisation submitting a request on your behalf, where authorised;
• sellers, training institutes, repair centres, logistics partners, recyclers, consultants, lenders, insurers, employers, payment providers, KYC/verification providers, credit-information companies, or government authorities involved in your request;
• public or official registers and portals, including DGCA, corporate, tax, tender, scheme, or professional registers, where lawful and relevant;
• referral, affiliate, or business partners; and
• fraud-prevention, security, analytics, or technical service providers.
If you provide personal data about another person, such as a co-applicant, employee, parent, nominee, director, beneficial owner, authorised representative, pickup contact, or referee, you must have authority to do so and should direct that person to this Policy.
4. How we collect personal data
• directly from you through enquiry, application, profile, upload, order, booking, quote, eligibility, claim, support, or feedback interactions;
• automatically when you use the Platform, through server logs, cookies, security tools, and similar technologies;
• from third parties participating in a service or referral; and
• from public or official sources where permitted by law.
5. Why we use personal data
We may process personal data for the following specified purposes:
• responding to enquiries and providing customer support;
• creating and managing profiles, applications, service requests, orders, quotations, bookings, and status tracking;
• matching users with verified sellers, institutes, trainers, technicians, logistics providers, recyclers, professional advisers, lenders, insurers, employers, affiliates, or government opportunities;
• checking product compatibility, service availability, location, eligibility, documents, or application completeness;
GARUDHUB | PRIVACY POLICY
Page 4
• facilitating purchases, payments, invoices, delivery, pickup, refunds, warranties, repairs, valuations, payouts, claims, and dispute handling;
• supporting DGCA compliance, training documentation, business setup, partner onboarding, proposals, schemes, tenders, and administrative processes;
• communicating service, application, security, expiry, renewal, deadline, or regulatory updates;
• preventing fraud, abuse, unauthorised access, and other security or legal risks;
• improving accessibility, performance, reliability, navigation, content, and service design;
• maintaining records, enforcing agreements, establishing or defending legal claims, and complying with tax, accounting, regulatory, court, law-enforcement, and other lawful obligations; and
• sending promotional communications only where permitted and subject to your opt-out choices.
6. Consent and other permitted processing
Where consent is required, we will seek free, specific, informed, unconditional, and unambiguous consent through a clear affirmative action. A service-specific notice may identify the exact data and purpose before submission. You may refuse optional data or withdraw consent, but we may be unable to provide a service that genuinely requires it.
We may also process personal data without fresh consent where applicable law permits, including for certain voluntarily provided data, compliance with law, responding to emergencies, employment-related purposes, fulfilment of legal obligations, or establishment and defence of legal claims. We will limit such processing to what the applicable provision permits.
Withdrawing consent does not invalidate lawful processing already completed. It also does not require deletion where retention is necessary for an active service, legal obligation, fraud/security control, dispute, or legal claim.
7. When we disclose personal data
We may disclose relevant personal data to the following recipients for the stated purpose:
7.1 Service and marketplace partners
Sellers, manufacturers, training institutes, trainers, repair centres, technicians, logistics providers, recyclers, consultants, affiliates, or other providers may receive data needed to quote, verify, deliver, track, support, or complete the requested service.
7.2 Finance, insurance, and verification partners
With your request and any required consent, lenders, banks, NBFCs, insurers, intermediaries, KYC/identity verification providers, credit-information companies, fraud-prevention providers, claims administrators, and professional advisers may receive the data needed to assess, issue, service, or administer a financial or insurance product.
GARUDHUB | PRIVACY POLICY
Page 5
7.3 Career and business-opportunity recipients
Verified employers, recruiters, project owners, tendering bodies, government departments or portals, and professional-service providers may receive selected profile, qualification, proposal, eligibility, or application data when you apply, request a referral, or authorise a submission.
7.4 Platform processors and professional advisers
Hosting, cloud, email, communication, cybersecurity, database, document-management, analytics, mapping, customer support, accounting, audit, legal, and other vendors may process data on our instructions and under appropriate obligations.
7.5 Authorities, legal processes, and business changes
We may disclose data where reasonably necessary to comply with law, court or regulatory process, investigate wrongdoing, protect users or the public, enforce agreements, or establish or defend legal rights. If CGA or a relevant business is reorganised, financed, sold, merged, or transferred, data may be reviewed or transferred subject to confidentiality, lawful notice, and applicable rights.
We do not sell or rent personal data. We also do not permit a partner to use referred data for unrelated marketing unless that partner separately obtains the permission required by law.
8. Finance, insurance, KYC, and credit information
Financial and identity information can be especially sensitive. The Platform should collect such information only where necessary for a clearly identified application and through an appropriately secured method. Do not send us passwords, OTPs, PINs, security answers, CVV values, or unrequested full payment credentials.
• Submitting a finance or insurance enquiry is not approval, disbursal, issuance, coverage, or a guarantee of terms.
• A lender or insurer may conduct KYC, credit, underwriting, fraud, sanctions, affordability, eligibility, or claim checks under its own notice and applicable law.
• Where a credit report or similar regulated record requires consent, it will be accessed only by an authorised entity with the required consent.
• CGA will not change a lender's, insurer's, credit bureau's, DGCA authority's, employer's, or government body's independent decision.
• Bank account information for refunds or recycling payouts should be collected only when needed and verified through a secure process.
9. Payments
Payments may be processed by banks, payment gateways, UPI providers, card networks, or other authorised payment providers. They may collect payment credentials directly under their own terms and privacy notices. We may receive transaction references, status, amount, payer details, refund
GARUDHUB | PRIVACY POLICY
Page 6
status, or limited masked information needed for reconciliation. Unless expressly stated, CGA does not store full card numbers, CVV values, UPI PINs, banking passwords, or OTPs.
10. Cookies, maps, and similar technologies
The Platform may use essential cookies or similar technologies to operate pages, remember choices, maintain security, prevent abuse, and improve performance. With appropriate notice or consent, it may also use functional, measurement, or analytics technologies. You can block or delete cookies through browser settings, but some features may not work correctly.
Public pages currently load or link to third-party resources that may receive technical data such as IP address, browser details, referring page, and timestamps. These include Google Maps/Google, Google Fonts, JSDelivr, cdnjs, unpkg, and the linked site-management provider VistarKriya. Their processing is governed by their own notices. Embedded Google Maps may process location or interaction information when the map loads or you open it.
The current public pages reviewed for this Policy did not display a dedicated advertising tracker. If advertising, profiling, or new analytics tools are added, this Policy and the Platform's cookie controls should be updated before deployment.
11. Matching, filters, and automated tools
The Platform may use rules, filters, calculators, or automated tools to display products, estimate EMI, check basic eligibility, suggest compatible accessories, rank nearby providers, flag missing documents, or match a profile to a service or opportunity. These outputs are informational and may be incomplete. They do not constitute a final credit, insurance, employment, regulatory, certification, tender, valuation, or legal decision.
Material decisions are made or confirmed by the relevant authorised person or third party. You may ask us to explain or correct the personal data used in a Platform-generated match or recommendation.
12. Data quality and your responsibilities
We take reasonable steps to keep personal data complete, accurate, and consistent where it may be used to make a decision or disclosed to another data fiduciary. You should provide authentic information, promptly correct errors, avoid impersonation, and not submit false or frivolous requests or grievances.
Do not upload unnecessary identity documents, confidential third-party records, prohibited content, or passwords and access codes. Where possible, mask information that is not needed for the stated purpose.
13. Retention and deletion
We retain personal data only for as long as reasonably necessary for the specified purpose, an active account or relationship, legal compliance, security, accounting, audit, dispute resolution, fraud
GARUDHUB | PRIVACY POLICY
Page 7
prevention, or legal claims. After the retention period, data is deleted, anonymised, or securely isolated unless law requires continued retention.
Unless a service-specific notice or law requires a different period, our operational target periods are:
• general enquiries and support correspondence: up to 3 years after the last meaningful interaction;
• active user, partner, career, service, or drone profiles: while active, followed by up to 3 years of inactivity after appropriate notice where required;
• orders, invoices, payments, tax, and material service records: the period required by applicable accounting, tax, consumer, and legal-record rules, which may extend to 8 financial years or longer where a proceeding is pending;
• finance or insurance referral files held by CGA: until the referral/application purpose concludes and then up to 3 years, unless a longer legal, contractual, complaint, audit, or claim period applies;
• repair and drone service histories: while the profile/service remains active and up to 3 years thereafter, subject to warranty, safety, dispute, or legal needs;
• recycling assessment photographs and pickup records: up to 1 year after completion, unless needed for payout, certificate, dispute, or legal compliance;
• technical, security, access, and processing logs: normally at least 1 year where required under applicable data-protection rules, or longer where needed to investigate an incident; and
• backup copies: overwritten on a rolling schedule, normally within 90 days after deletion from active systems, unless technically or legally required for longer.
A lender, insurer, employer, payment provider, government authority, or other independent recipient may retain data for a different period under its own legal duties and privacy notice.
14. Security safeguards
We use reasonable technical and organisational safeguards appropriate to the nature and risk of the data. These may include encryption in transit, access controls, role-based permissions, secure configuration, malware and abuse protection, logging and monitoring, backups, vendor due diligence, confidentiality duties, incident procedures, staff awareness, and periodic review.
No website, transmission, or storage system can be guaranteed completely secure. You should use trusted devices and networks, protect your email and account access, and notify us promptly if you suspect unauthorised use.
15. Personal data breaches
If we become aware of a personal data breach, we will investigate, contain, document, and remediate it. We will notify affected individuals and the competent authority in the form and time required by applicable law, including information about the nature and likely consequences of the breach, mitigation measures, protective steps, and a contact point.
GARUDHUB | PRIVACY POLICY
Page 8
16. Your privacy rights
Subject to applicable law and verification, you may request:
• a summary of personal data being processed and the related processing activities;
• information about other data fiduciaries and processors with whom relevant personal data has been shared, except where law limits disclosure;
• correction of inaccurate or misleading data, completion of incomplete data, and updating of outdated data;
• erasure where the purpose is complete and retention is not otherwise necessary or legally required;
• withdrawal of consent through a method reasonably comparable to the method used to give it;
• grievance redressal concerning our processing or handling of a rights request; and
• nomination of another individual to exercise applicable rights in the event of death or incapacity, where the law and our verified process permit.
16.1 How to submit a request
Email connectwithcga@gmail.com with the subject "Privacy Rights Request" or write to the address in Section 24. Include your name, the email or mobile number used with us, any application/service reference, and the right you wish to exercise. Do not email identity documents unless we specifically request a secure verification method.
We may ask for proportionate information to verify identity or authority and to locate records. We aim to acknowledge requests promptly and resolve ordinary requests or grievances within 30 days. Where a longer period is permitted, our published grievance period will not exceed 90 days. Complex or legally restricted requests may take longer, and we will explain the reason where required.
If you are dissatisfied, first allow us a reasonable opportunity to resolve the grievance. You may then complain to the Data Protection Board of India or another competent authority when the relevant legal procedure is available and applicable.
17. Children and parental consent
The Platform's marketplace, business, finance, insurance, tender, partner, and professional-service features are intended for adults. A person under 18 should not independently submit financial, identity, career, location, or service-application data. If a training or other service lawfully permits a person under 18 to participate, a parent or lawful guardian should contact us first so that age, eligibility, and verifiable parental consent can be handled appropriately.
We do not knowingly undertake tracking or behavioural monitoring of children or targeted advertising directed at children. If you believe a child provided personal data without the required consent, contact us so we can review and delete it where appropriate.
GARUDHUB | PRIVACY POLICY
Page 9
18. Cross-border processing
Some hosting, cloud, communication, mapping, security, or support providers may process data outside India. Where this occurs, we will apply contractual and security measures appropriate to the service and comply with restrictions or requirements notified by the Government of India or imposed by another applicable law.
19. Service and marketing communications
We may send communications necessary to answer an enquiry, complete a transaction, provide status or security updates, deliver a requested service, or meet legal duties. These are not optional marketing messages.
Where permitted, we may send offers, newsletters, or opportunity alerts. You may opt out using the method in the message or by contacting us. An opt-out will not stop essential service, transaction, safety, or legal communications.
20. Third-party websites and services
The Platform may link to DGCA, Digital Sky, government departments, tender portals, maps, lenders, insurers, employers, sellers, institutes, service providers, or other websites. We do not control their privacy or security practices. Review the third party's notice before submitting personal data. A link, listing, or referral does not by itself make CGA responsible for that third party's processing.
21. Changes to this Policy
We may update this Policy to reflect new features, partners, technologies, legal requirements, or business practices. The updated version will be posted on the Platform with a revised date. Where a change materially affects an existing purpose or consent, we will provide additional notice or obtain fresh consent where required.
22. Governing privacy framework
This Policy is designed with reference to applicable Indian law, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as their provisions come into force, and other applicable information-technology, cybersecurity, consumer, financial, insurance, identity, tax, and sector-specific requirements. If a mandatory rule conflicts with this Policy, the mandatory rule will prevail to the extent of the conflict.
23. Complaints concerning a partner
If a privacy issue concerns a lender, insurer, employer, payment provider, training institute, seller, repair centre, government portal, or other partner, contact that organisation using its privacy or grievance
GARUDHUB | PRIVACY POLICY
Page 10
channel. You may also contact us if the issue concerns a referral or data sharing by CGA; we will assist with routing or investigation where reasonably possible.
24. Privacy and grievance contact
For questions, rights requests, consent withdrawal, or complaints, contact:
Privacy and Grievance Contact
ChandraGhanshyam & Associates LLP
310/104-C, Alopibagh, Prayagraj - 211006, Uttar Pradesh, India
Email: connectwithcga@gmail.com
Alternative email: chandraghanshyamdrone@gmail.com
Phone: +91 99357 60540
For faster handling, use the subject line "Privacy Request" and include the email/mobile number or application reference associated with your request. Do not send passwords, OTPs, PINs, CVV values, or unnecessary identity documents.
GARUDHUB | PRIVACY POLICY
Page 11
Publication checklist - not part of the public Privacy Policy
Remove this checklist before posting the policy on the website. It records operational items that CGA should confirm so the published statements match actual practice.
• Confirm whether the public brand should consistently be GarudHub, DroneHub, or both, and update the website footer/title accordingly.
• Formally designate the Privacy and Grievance Contact, confirm the two email addresses, and ensure the inbox is monitored with a documented response workflow.
• Map every live and planned form to the exact data fields, purposes, recipients, retention period, and consent text. Avoid requesting documents through ordinary email where a secure upload is appropriate.
• Use separate, unbundled consent controls for service processing, lender/insurer/credit checks, partner referrals, marketing, and parental consent. Do not pre-check optional consent boxes.
• Add a short just-in-time notice beside the enquiry submit button that links to this Policy and states the enquiry purpose and response channel.
• Confirm which hosting, email, database, analytics, mapping, payment, KYC, communication, and document-storage vendors are actually used; execute processor/confidentiality clauses and update this Policy if the list materially changes.
• Validate the retention targets and configure deletion, inactivity notices, backup expiry, legal holds, and minimum log retention consistently across systems and processors.
• Confirm actual security controls before making stronger claims. At minimum address TLS, access control, staff/vendor access, encryption or masking for sensitive documents, backups, logging, patching, incident response, and secure deletion.
• Create a breach-response plan that supports prompt affected-user notice and regulator reporting within applicable time limits, with named owners and evidence preservation.
• Implement a rights-request register, identity verification method, nomination process, withdrawal mechanism, 30-day operating target, and published grievance period not exceeding the applicable legal maximum.
• Do not collect or transmit Aadhaar, PAN, bank statements, tax returns, credit reports, payment data, health data, or children's data until a necessity, secure channel, retention rule, and authorised recipient are confirmed.
• For lenders, insurers, employers, sellers, institutes, repair centres, recyclers, logistics providers, and professional partners, identify when each is a processor versus an independent data fiduciary and provide the partner's notice before handoff.
• Review the site's finance, insurance, DGCA, marketplace, training, job, tender, consumer, and e-commerce statements with qualified Indian counsel and relevant sector specialists before launch or material expansion.
• Maintain a cookie/third-party asset inventory. If analytics, profiling, advertising, chat, or remarketing tools are added, deploy appropriate consent controls before loading non-essential technologies.
GARUDHUB | PRIVACY POLICY
Page 12
Drafting references
• GarudHub public website reviewed 27 August 2026
• Digital Personal Data Protection Act, 2023 - India Code
• Digital Personal Data Protection Rules, 2025 - MeitY
• Information Technology Act, 2000 - India Code
Drafting note: This document is a comprehensive operational draft, not a substitute for advice from qualified Indian legal counsel. The published policy must accurately describe CGA's implemented systems, contracts, forms, partners, and retention practices.
