Legal

Privacy Notice

Last updated 3 October 2026

What personal data WOVENN collects, why, who helps us process it, how long we keep it and the rights you have — in plain language.

1.Who we are

WOVENN (“we”, “us”) operates wovenn.world and the WOVENN platform. For the personal data described in this notice we act as the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). For business records an organization keeps on the platform, we process personal data on that organization’s behalf and under its instructions.

2.What we collect

  • When you contact us or request a brand analysis: your name, work email, phone number, company, what you tell us in your message, and the brand you ask us to analyze.
  • When you use the platform: your name, email address, sign-in details (email and password, or your Google account’s basic profile), the roles you hold and when you last used them.
  • Business records: styles, samples, costs, production reports, shipments and similar records your organization and its partners enter. These may include names and contact details of people at those businesses.
  • Security information: to stop abuse of our public forms we count submissions per visitor using a one-way hash of your IP address (we do not store the address itself in that counter), and we may use Cloudflare Turnstile to check that a form is being sent by a person. Our hosting providers keep standard server logs.

We do not use advertising trackers and we do not sell personal data.

3.Why we use it

  • To reply to your enquiry and arrange a demo you asked for.
  • To run the brand analysis you requested and let you see it again when you sign in.
  • To provide the platform: sign-in, showing each person what their role allows, and keeping an audit trail.
  • To keep the service secure and prevent spam and misuse.
  • To meet legal obligations.

4.Consent and legitimate uses

When you submit a form you give us your data, with your consent, for the purpose stated on that form. Platform accounts are created by your organization’s administrator, and we use the data needed to provide the service you or your organization asked for, as the DPDP Act permits. You can withdraw consent at any time by writing to hello@wovenn.world; withdrawal does not affect processing that took place before it.

5.Brand analysis and public information

A brand analysis reads information a business has made public — its website, catalogue and marketplace listings — to describe the brand. It is about brands and their products, not about individual people, and every finding links to the public source it came from.

6.Who processes it for us

We use these service providers, each bound to protect the data and use it only to provide their service to us:

  • Google Cloud and Firebase — database, file storage, sign-in, background processing and AI models (Vertex AI).
  • Vercel — website hosting.
  • Cloudflare — form verification (Turnstile).
  • Resend — sending email notifications.

Some of these providers may process data outside India, as permitted under the DPDP Act.

7.How long we keep it

  • Enquiries: up to 24 months after our last contact with you, unless you ask us to delete them sooner.
  • Platform accounts: while your role is active, and for a reasonable period afterwards for audit and legal needs.
  • Business records: as your organization decides, for as long as it uses the platform.
  • Form rate-limit counters: no longer than 24 hours.

8.Your rights

Under the DPDP Act you can ask us:

  • for a summary of the personal data we hold about you and how we use it;
  • to correct, complete, update or erase it;
  • to address a grievance about how we handled it;
  • to let someone you nominate exercise these rights if you cannot.

Write to hello@wovenn.world. We will reply within the time the law requires. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

9.How we protect it

Data is encrypted in transit, each organization’s records are kept separate, every person sees only what their role allows, and access changes and key actions are recorded in an audit log. No system is perfectly secure; if a personal data breach occurs we will notify the Board and affected people as the law requires.

10.Children

WOVENN is a business service and is not meant for anyone under 18. We do not knowingly collect children’s data.

11.Changes and contact

We will update this notice when our practices change and show the new date at the top. Questions, requests and grievances: hello@wovenn.world.