Privacy Policy
Last updated 11 June 2026
PRIVACY POLICY
Beyondwork Ventures Private Limited
[CIN: U82300KA2025PTC206302 • GSTIN: 29AANCB8115F1ZI • Registered Office: Room no.2, Sai Ranjitha building, Kadugodi, Bangalore South, Bangalore- 560067]
Applicable to all the Brands operated by the Company
Beyondwork Ventures Private Limited (“Company”, “we”, “us”, or “our”) respects your privacy and is committed to protecting the personal data we collect, use, and process. This Privacy Policy (“Policy”) explains how we collect, use, share, store, and protect personal data, and the rights available to you in relation to such data.
This Policy applies to personal data processed by the Company across all its brands and business verticals, including “BeyondXP” (corporate events and experience marketing), “Saycheezz” (commercial and corporate video production, photography, and design), and “The Hamper House” (corporate gifting) (collectively, the “Brands”), and through our websites, applications, portals, social media pages, marketing communications, and offline interactions (collectively, the “Services” and “Channels”).
This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the directions issued by the Indian Computer Emergency Response Team (“CERT-In”), and, where applicable, the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and the laws of other jurisdictions where the Company offers Services.
By accessing our Channels, providing personal data to us, or availing of our Services, you acknowledge that you have read, understood, and agree to this Policy. If you do not agree with this Policy, please do not use our Channels or Services or provide personal data to us.
1. DEFINITIONS
For the purposes of this Policy, capitalised terms have the meanings set out below. Terms used and not defined herein shall have the meanings ascribed to them under the DPDP Act, the SPDI Rules, or the GDPR, as the context requires.
1.1 “Personal Data” means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act, including “personal data” under the GDPR where applicable.
1.2 “Sensitive Personal Data or Information” or “SPDI” means personal data consisting of information relating to passwords; financial information such as bank account, credit card, debit card, or other payment instrument details; physical, physiological, and mental health condition; sexual orientation; medical records and history; biometric information; and any detail relating to the above as provided to or received by the Company for processing or storage.
1.3 “Data Principal” or “Data Subject” means the individual to whom the Personal Data relates.
1.4 “Data Fiduciary” or “Data Controller” means the Company, which determines the purpose and means of processing of Personal Data.
1.5 “Data Processor” means any person or entity that processes Personal Data on behalf of the Data Fiduciary.
1.6 “Processing” means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, alignment, disclosure, transmission, dissemination, restriction, erasure, or destruction.
1.7 “Consent Manager” has the meaning given to it under the DPDP Act.
1.8 “Channels” means our websites, including the websites and microsites operated under the Brands; our mobile and web applications; client portals; social media pages; marketing communications; live chat and WhatsApp interfaces; and our offline points of interaction.
2. PERSONAL DATA WE COLLECT
We collect Personal Data in three principal ways: (a) directly from you when you interact with us; (b) automatically when you use our Channels; and (c) from our Clients and certain third-party sources, as described below.
2.1 Personal Data You Provide Directly. We collect Personal Data you submit to us through marketing and lead-generation forms, newsletter signups, account or login portals, the live chat and WhatsApp widgets on our Channels, requests for proposals or quotations, contractual interactions, and event or shoot participation. Such Personal Data may include:
• Identification data: name, designation, organisation, photograph
• Contact data: email address, telephone number, postal address, country of residence
• Account credentials: username, password (stored only in encrypted form), security questions
• Professional data: company name, role, industry, professional interests, business preferences
• Commercial data: GSTIN, billing address, PAN (where required for tax compliance), purchase order references
• Communication data: the content of messages, queries, and feedback you send to us via forms, email, chat, or WhatsApp
• Marketing preferences: subscription status, communication preferences, opt-in/opt-out indicators
• Sensitive Personal Data: in limited circumstances (e.g., dietary, allergen, or accessibility information for events or recipients of gifting; payment instrument details for invoice settlement)
2.2 Personal Data Collected Automatically. When you access our Channels, we and our service providers may automatically collect technical and usage data using cookies, web beacons, server logs, pixels, and similar technologies. Such data may include:
• Device data: device type, operating system, browser type and version, screen resolution, language settings, mobile network information
• Network data: IP address (which may be considered Personal Data in certain jurisdictions), Internet Service Provider information, approximate geolocation derived from IP
• Usage data: pages visited, time spent on pages, click paths, referring and exit URLs, search queries within our Channels, session duration, and interaction with content
• Tracking data: identifiers set by our cookies and by third-party analytics and advertising tools such as Google Analytics, Meta (Facebook) Pixel, LinkedIn Insight Tag, and similar technologies (see Clause 7 — Cookies and Tracking Technologies)
2.3 Personal Data We Receive from Clients (Recipient and Attendee Data). In the course of providing the Services, our corporate Clients frequently share Personal Data of third parties with us — including employees, attendees, customers, gift recipients, and other individuals — for purposes such as event registration and management, gifting fulfilment and dispatch, video and photography production, and post-event communication. Such Personal Data may include name, designation, organisation, contact details, postal address, photograph or likeness, dietary and allergen information, sizing details, and other information reasonably required to deliver the Services. Where we process such Personal Data, we do so on the instructions of the Client (acting as Data Fiduciary or Controller), in the capacity of a Data Processor, and in accordance with our contractual obligations to the Client and Applicable Law.
2.4 Personal Data from Third-Party Sources. We may also receive Personal Data from publicly available sources (e.g., LinkedIn, business directories); from referral partners and intermediaries; from advertising and analytics providers; and from credit reference, fraud prevention, and identity verification agencies where required for compliance purposes.
2.5 Children's Data. Our Services are not directed to children below the age of 18 years. We do not knowingly collect Personal Data from children. In respect of any Personal Data of a Data Principal who is a child or a person with a disability who has a lawful guardian, the Company shall, in accordance with Section 9 of the DPDP Act, obtain verifiable consent from the parent or lawful guardian before processing such data, and shall not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that we have inadvertently collected Personal Data from a child without such consent, we shall promptly delete the same.
3. PURPOSES FOR WHICH WE PROCESS PERSONAL DATA
We process Personal Data for the following specified, lawful, and legitimate purposes:
3.1 Service Delivery. To provide, perform, and administer the Services across our Brands, including responding to enquiries, preparing proposals and quotations, executing engagements, fulfilling gifting orders, producing video and photographic deliverables, managing event registration and execution, processing payments, raising invoices, and handling refunds and disputes.
3.2 Account Management. To create, maintain, authenticate, and secure accounts and login portals on our Channels.
3.3 Marketing and Communications. To send you marketing emails, newsletters, event invitations, product updates, and promotional offers, where you have provided consent or where such communication is permitted under Applicable Law. You may withdraw consent or unsubscribe at any time (see Clauses 8 and 10).
3.4 Analytics and Improvement. To analyse usage patterns, measure performance of our Channels, conduct surveys and research, develop new services, and improve user experience.
3.5 Personalisation. To personalise content, recommendations, and advertising shown to you on our Channels and on third-party platforms (subject to your consent for non-essential cookies).
3.6 Compliance and Legal Obligations. To comply with Applicable Laws, including tax, accounting, anti-money laundering, and statutory record-keeping obligations; to respond to lawful requests from courts, regulators, and government authorities; and to enforce our Terms of Service and other policies.
3.7 Security and Fraud Prevention. To protect the security and integrity of our Channels and Services, to detect, investigate, and prevent fraud, unauthorised access, and other malicious activity, and to maintain logs as required under CERT-In Directions and the SPDI Rules.
3.8 Corporate Transactions. To facilitate any corporate restructuring, merger, demerger, acquisition, sale of business, or financing transaction, in which case Personal Data may be disclosed to advisers and counterparties under appropriate confidentiality safeguards.
4. LAWFUL BASES FOR PROCESSING
We process Personal Data on one or more of the following lawful bases:
4.1 Consent. We rely on your free, specific, informed, unconditional, and unambiguous consent (in compliance with Section 6 of the DPDP Act and, where applicable, Article 6(1)(a) of the GDPR) for purposes such as marketing communications, non-essential cookies, and processing of any Sensitive Personal Data.
4.2 Legitimate Uses (DPDP) and Legitimate Interests (GDPR). We may process Personal Data for the “certain legitimate uses” recognised under Section 7 of the DPDP Act and, where the GDPR applies, on the basis of our legitimate interests under Article 6(1)(f), including provision of the Services, customer relationship management, security and fraud prevention, and corporate communications. We balance such interests against your privacy rights and reasonable expectations.
4.3 Performance of a Contract. Where processing is necessary to perform a contract with you, or to take steps prior to entering into a contract.
4.4 Legal Obligation. Where processing is necessary to comply with a legal obligation imposed on the Company under Applicable Law.
4.5 Processor Capacity. Where we process recipient or attendee data on behalf of our Clients, the lawful basis for such processing is determined by the Client as Data Fiduciary or Controller, and we process such data only on the Client's documented instructions.
4.6 Withdrawal of Consent. Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing prior to such withdrawal. Withdrawal may, however, affect our ability to provide certain Services.
5. DISCLOSURE OF PERSONAL DATA
We do not sell Personal Data. We disclose Personal Data only in the following circumstances and to the following categories of recipients:
5.1 Group Companies and Brands. To our affiliates, subsidiaries, and the Brands operated by us, for the purposes set out in this Policy.
5.2 Service Providers and Data Processors. To carefully selected service providers who process Personal Data on our behalf, including (a) cloud hosting and infrastructure providers; (b) email, CRM, and marketing automation providers; (c) payment processors and banks; (d) logistics, courier, and last-mile delivery partners (especially for The Hamper House dispatches); (e) analytics and advertising providers including Google Analytics, Meta, and LinkedIn; (f) customer support and live chat providers; (g) sub-contractors, freelancers, and on-ground execution partners; and (h) professional advisers including legal, tax, and audit advisers. Such service providers are contractually bound to confidentiality and data protection obligations consistent with this Policy and Applicable Law.
5.3 Our Clients. Where you are a recipient, attendee, employee, or guest of our Client, we may share Personal Data with the Client as part of our Service delivery and reporting.
5.4 Legal and Regulatory Authorities. To courts, tribunals, regulators, law enforcement, tax, and other governmental authorities, where required by Applicable Law, court order, or to protect our legal rights or those of our Clients or third parties.
5.5 Corporate Transactions. To prospective acquirers, investors, or counterparties (and their advisers) in connection with any merger, demerger, acquisition, sale, financing, or restructuring transaction, subject to confidentiality safeguards.
5.6 With Consent. To any other person to whom you have consented to disclosure of your Personal Data.
6. INTERNATIONAL TRANSFERS OF PERSONAL DATA
6.1 Transfers Outside India. We are headquartered in India and primarily store Personal Data on servers located in India and/or in countries that maintain adequate data protection standards. Where Personal Data is transferred outside India — including to cloud and analytics providers whose infrastructure is located in the United States, the European Union, or other jurisdictions — we ensure that such transfers comply with Section 16 of the DPDP Act and any restrictions notified by the Central Government in respect of permitted or non-permitted countries.
6.2 Transfers from the European Economic Area, United Kingdom, and Switzerland. Where we transfer Personal Data of EEA, UK, or Swiss Data Subjects to a country that does not benefit from an adequacy decision under the GDPR, we rely on appropriate safeguards permitted under Articles 44 to 49 of the GDPR, including the European Commission's Standard Contractual Clauses (SCCs), supplementary measures where necessary, and the data subject's explicit consent where applicable. A copy of the relevant transfer mechanism is available on written request to our Data Protection Officer (see Clause 12).
6.3 Onward Transfers. Our service providers and sub-processors that receive Personal Data outside India are contractually required to maintain confidentiality and apply protections consistent with this Policy and Applicable Law.
7. COOKIES AND TRACKING TECHNOLOGIES
7.1 What Are Cookies. Cookies are small text files placed on your device when you visit a website. We use cookies and similar technologies (including pixels, web beacons, local storage, and session storage) to operate our Channels, analyse usage, remember your preferences, and (where you have consented) deliver personalised content and advertising.
7.2 Categories of Cookies We Use:
• Strictly necessary cookies: essential for the operation of our Channels, including authentication, session management, security, and load balancing. These cannot be disabled without affecting site functionality.
• Performance and analytics cookies: help us understand how visitors interact with our Channels (for example, through Google Analytics). These cookies collect aggregated and pseudonymised information.
• Functional cookies: remember your preferences (such as language, region, or login state) to provide a more personalised experience.
• Marketing and targeting cookies: set by us or by third-party advertising partners (including Meta Pixel and LinkedIn Insight Tag) to deliver relevant advertising on our Channels and on other websites, and to measure the effectiveness of our marketing campaigns.
7.3 Cookie Consent. On your first visit to our Channels, you will see a cookie banner where you can accept, reject, or customise your cookie preferences (other than strictly necessary cookies, which are essential for the operation of our Channels). You may modify your preferences at any time through the cookie settings link on our website. Withdrawal of consent will not affect the lawfulness of processing prior to withdrawal.
7.4 Third-Party Tracking and Do-Not-Track. Some browsers offer “Do Not Track” signals. We currently do not respond to such signals, but you can manage cookies through your browser settings and through industry opt-out tools such as the Network Advertising Initiative opt-out and the Your Online Choices platform.
7.5 Live Chat and WhatsApp. Our website may host live chat or WhatsApp widgets that are operated by us or by third-party providers. Messages, contact details, and metadata exchanged through such channels are processed for customer support, sales, and Service delivery purposes, and may be retained as described in Clause 9. WhatsApp interactions are also subject to WhatsApp's own privacy practices and terms.
8. MARKETING COMMUNICATIONS
8.1 Opt-In. We send marketing emails, newsletters, and promotional communications only to those who have consented to receive them, or where permitted under Applicable Law (for instance, in the context of an existing business relationship, subject to your right to opt out).
8.2 Opt-Out. You may opt out of marketing communications at any time by (a) clicking the “unsubscribe” link in any marketing email; (b) updating your preferences through our account portal or preference centre; or (c) writing to us at the contact addresses set out in Clause 13.
8.3 Transactional Communications. Notwithstanding any opt-out, we may continue to send you operational and transactional communications relating to the Services (such as invoices, delivery updates, security alerts, and important policy or service announcements), as these are essential for the performance of our contractual obligations.
9. DATA RETENTION
9.1 Retention Principles. We retain Personal Data only for as long as is necessary for the purposes for which it was collected, including for the duration of any Engagement and for such period thereafter as required to (a) comply with our legal, accounting, tax, and statutory obligations under Applicable Laws (including the Companies Act, 2013; the Income Tax Act, 1961; the CGST/SGST/IGST Act, 2017; and the Prevention of Money Laundering Act, 2002, which may require retention periods of up to eight years or longer); (b) resolve disputes and enforce our agreements; (c) protect against fraud and abuse; and (d) preserve records of consent and our compliance with this Policy.
9.2 Indicative Retention Periods:
• Client account and engagement records: for the duration of the engagement plus 8 years from completion (for tax and statutory compliance)
• Marketing and newsletter subscriber data: until you withdraw consent, plus a reasonable archival period for evidencing consent
• Recipient and attendee data (processed on behalf of Clients): as instructed by the Client, and in any event no longer than reasonably necessary for the relevant Service
• Website analytics and cookie data: as per the retention period set in the underlying tool (typically 14 months to 26 months)
• Server logs and security logs: minimum 180 days as required under CERT-In Directions, 2022, or such longer period as required by Applicable Law
• Recruitment data: 12 months from the date of application, unless we obtain consent to retain for longer
9.3 Erasure on Expiry of Purpose. Upon expiry of the relevant retention period or upon your valid request for erasure (subject to legal exceptions), we shall delete, anonymise, or securely destroy your Personal Data.
10. YOUR RIGHTS AS A DATA PRINCIPAL / DATA SUBJECT
Subject to Applicable Law, you have the following rights in relation to your Personal Data. Some rights may not apply, or may apply differently, depending on your jurisdiction and the lawful basis on which we process your Personal Data.
Rights Under the DPDP Act (India)
10.1 Right to Information. You have the right to obtain a summary of the Personal Data we are processing about you, the processing activities, and the identities of other Data Fiduciaries and Data Processors with whom your Personal Data has been shared.
10.2 Right to Correction, Completion, Updating, and Erasure. You may request the correction of inaccurate or misleading Personal Data; completion of incomplete Personal Data; updating of Personal Data; and erasure of Personal Data that is no longer necessary for the purpose for which it was processed, subject to legal retention obligations.
10.3 Right to Grievance Redressal. You have the right to a readily available means of grievance redressal in respect of any act or omission relating to the performance of our obligations under the DPDP Act. See Clause 12 for our grievance redressal mechanism.
10.4 Right to Nominate. You may nominate, in such manner as may be prescribed, another individual to exercise these rights in the event of your death or incapacity.
10.5 Right to Withdraw Consent. Where processing is based on consent, you may withdraw consent at any time. Withdrawal of consent shall not affect the lawfulness of processing prior to such withdrawal.
Additional Rights Under the GDPR (EEA, UK, and Switzerland)
10.6 If you are located in the EEA, UK, or Switzerland, you have, in addition to the rights set out above, the following rights under the GDPR:
• Right of access: to obtain confirmation of, and a copy of, Personal Data we hold about you
• Right to rectification: to have inaccurate Personal Data corrected
• Right to erasure: (“right to be forgotten”) in certain circumstances
• Right to restriction of processing: in certain circumstances
• Right to data portability: to receive your Personal Data in a structured, commonly used, machine-readable format and to transmit it to another controller
• Right to object: to processing based on legitimate interests, and to object to direct marketing
• Right not to be subject to automated decision-making: (including profiling) that produces legal effects or similarly significantly affects you, except as permitted by law
• Right to lodge a complaint: with a competent data protection supervisory authority, including the supervisory authority of your habitual residence, place of work, or place of the alleged infringement
10.7 Exercising Your Rights. To exercise any of these rights, please contact our Data Protection Officer / Grievance Officer at the addresses set out in Clause 12. We may need to verify your identity before responding to your request. We will respond to your request within the timelines prescribed by Applicable Law (and in any event without undue delay). We do not charge a fee for responding to most requests, but we may charge a reasonable fee for manifestly unfounded or excessive requests.
10.8 Recipient and Attendee Data. Where your Personal Data is processed by us on behalf of a Client (for example, where you are a gift recipient or an event attendee), please direct your requests in the first instance to that Client, who is the Data Fiduciary / Controller in respect of such processing. We shall provide reasonable assistance to the Client to enable it to respond to your request.
11. SECURITY OF PERSONAL DATA
11.1 Security Practices. We implement reasonable security practices and procedures designed to protect Personal Data against unauthorised access, accidental or unlawful destruction, loss, alteration, disclosure, or use, in line with the standards prescribed under the SPDI Rules (including ISO/IEC 27001 or comparable industry standards), the DPDP Act, the CERT-In Directions, 2022, and the GDPR. These measures include access controls, encryption in transit and at rest where appropriate, multi-factor authentication, periodic security testing, employee training, confidentiality agreements with personnel and sub-contractors, and incident response procedures.
11.2 Limitations. While we take reasonable steps to protect Personal Data, no method of transmission over the internet or method of electronic storage is fully secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly of any unauthorised use or suspected breach of your account.
11.3 Personal Data Breach Notification. In the event of a Personal Data breach that affects your Personal Data, we shall: (a) notify the Data Protection Board of India in accordance with Section 8(6) of the DPDP Act and, where applicable, the competent supervisory authority under Article 33 of the GDPR; (b) notify affected Data Principals / Data Subjects as required by Applicable Law (including Article 34 of the GDPR where the breach is likely to result in a high risk to your rights and freedoms); and (c) report cybersecurity incidents to CERT-In within six (6) hours of becoming aware, as required under the CERT-In Directions, 2022.
12. GRIEVANCE OFFICER AND DATA PROTECTION OFFICER
12.1 Grievance Officer (India). In accordance with the SPDI Rules and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Grievance Officer designated by the Company is:
• Name: Dharshan S
• Designation: Director, Beyondwork Ventures Private Limited
• Email: info@beyondwok.co.in
• Postal Address: Room no 2, Sai Ranjitha Building, Opp to FCI Main Gate,Kadugodi Main Road, Channasandra, Bengaluru, KA, 560067, India
• Telephone (working hours): +91 72042 08229 (10:00 AM - 7:00 PM)
12.2 Data Protection Officer (under DPDP Act and GDPR, where applicable). The Data Protection Officer (“DPO”) designated by the Company for compliance with the DPDP Act (in case the Company is notified as a Significant Data Fiduciary) and the GDPR (where applicable) is:
• Name: Dharshan S
• Designation: Director, Beyondwork Ventures Private Limited
• Email: info@beyondwok.co.in
• Postal Address: Room no 2, Sai Ranjitha Building, Opp to FCI Main Gate,Kadugodi Main Road, Channasandra, Bengaluru, KA, 560067, India
12.3 Grievance Redressal Procedure. We endeavour to resolve all grievances expeditiously. We shall acknowledge receipt of your complaint within seventy-two (72) hours and shall resolve it within fifteen (15) days of receipt, or such other period as may be prescribed under Applicable Law. If you are not satisfied with the resolution, you may approach the Data Protection Board of India (once constituted under the DPDP Act) or, if you are located in the EEA, UK, or Switzerland, your local data protection supervisory authority.
13. CONTACT US
If you have any questions, comments, or requests regarding this Policy or our processing of your Personal Data, please contact us at:
• Company: Beyondwork Ventures Private Limited
• Brands: BeyondXP, Saycheezz, The Hamper House
• Email (general): info@beyondwork.co.in
• Postal Address: Room no 2, Sai Ranjitha Building, Opp to FCI Main Gate,Kadugodi Main Road, Channasandra, Bengaluru, KA, 560067, India
• Website: www.beyondwork.co.in
14. CHANGES TO THIS PRIVACY POLICY
14.1 Updates. We may update this Policy from time to time to reflect changes in our practices, the Services, or Applicable Law. The updated Policy will be posted on our Channels with a revised “Last Updated” date.
14.2 Material Changes. Where the changes are material, we shall notify you by email (if we have your email address) or by a prominent notice on our Channels prior to the changes taking effect. Your continued use of our Channels or Services following the effective date of any update shall constitute your acceptance of the updated Policy.
15. GOVERNING LAW AND JURISDICTION
15.1 Governing Law. This Policy shall be governed by and construed in accordance with the laws of India.
15.2 Jurisdiction. Subject to the rights of Data Subjects to approach the data protection authority of their habitual residence under Applicable Law, the courts at Bengaluru, India shall have exclusive jurisdiction over any matter arising out of or in connection with this Policy.