Studio OS
DPDP Act, 2023 ComplianceLast updated: September 25, 2026

Privacy Policy

How Studio OS collects, uses, encrypts, and processes personal data. We do not sell data to third-party advertisers.

Section 01

Commitment & Statutory Compliance

Studio OS ("we", "us", or "our", hosted at business-online.in) is committed to protecting your personal data and privacy. This Privacy Policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) of India and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

By accessing the Service, you consent to the collection, processing, and storage of your personal data as strictly outlined in this Policy.

Section 02

Categories of Personal Data We Collect

Account Identity Data: Full Name, personal Gmail address, and 10-digit Indian mobile number (+91).

Studio Business Profile Data: Studio Brand Name, Subdomain handle, studio WhatsApp contact number, UPI ID (VPA), primary photography craft, and portfolio biography.

Telemetry & Security Logs: IP addresses, browser user-agent, session cookies, rate-limiting counters, and HTTP access timestamps required for intrusion detection and fraud prevention.

User-Uploaded Gallery Media: Event photographs, video previews, and associated EXIF camera metadata uploaded strictly for private gallery presentation.

Section 03

Lawful Grounds & Specific Purpose of Processing

Authentication & Verification: Transmitting 6-digit OTP verification codes via Indian telecom gateways (Fast2SMS) to authenticate account ownership and prevent unauthorized access.

Service Delivery: Provisioning your customized white-label subdomain portfolio and client gallery presentation website.

Payment Utilities: Generating NPCI-standard UPI QR codes for your studio invoices.

Platform Security: Enforcing multi-tier sliding-window rate limiting, DDoS mitigation, and anti-fraud protections.

Section 04

Third-Party Processors & Infrastructure Infrastructure

Studio OS engages vetted, ISO-27001 and SOC 2 certified cloud infrastructure providers:

Cloudflare Inc.: Edge CDN delivery, DNS routing, and Cloudflare R2 object storage.

Supabase / Neon Inc.: Hosted PostgreSQL relational database with automated backups and AES-256 encryption at rest.

Fast2SMS: Indian DLT-registered telecom SMS gateway for transactional OTP delivery.

Vercel Inc.: Serverless edge computing runtime and Anycast global CDN.

ZERO DATA BROKERING: Studio OS does NOT sell, rent, monetize, trade, or share user or client personal data with third-party advertisers, data brokers, or marketing networks.

Section 05

Data Security, Encryption & Storage Standards

Data in Transit: All communications between your browser, Studio OS edge servers, and APIs are encrypted using TLS 1.3 encryption protocols.

Data at Rest: Database volumes, user records, and cloud storage buckets are encrypted using industry-standard AES-256 bit encryption.

Tenant Isolation: PostgreSQL schemas implement strict Row-Level Security (RLS) policies ensuring complete data isolation between different photography studios.

Section 06

Your Rights Under the DPDP Act, 2023

Right to Access & Summary: You may access and review your stored personal and studio profile data at any time via your Studio OS Dashboard.

Right to Correction: You may update or correct incomplete, inaccurate, or outdated profile details directly in your account settings.

Right to Erasure (Account Deletion): You have the right to request permanent account deletion. Upon verification, all your profile data, media files, and subdomain bindings will be permanently expunged within thirty (30) business days, subject to legally mandated financial audit retention.

Section 07

Cookies & Tracking Telemetry

Studio OS utilizes only strictly necessary functional and security session cookies required to keep you authenticated and protect against Cross-Site Request Forgery (CSRF).

We do not deploy third-party advertising tracking cookies, Facebook pixels, or cross-site tracking scripts.

Section 08

Grievance Redressal & Contact Officer

In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines) Rules, 2021, and the DPDP Act, 2023, the designated Grievance Officer details are:

Designation: Grievance & Compliance Officer, Studio OS

Official Grievance Email: legal@business-online.in / support@business-online.in

Address: Republic of India

Response Time: Grievances are acknowledged within 24 hours and resolved within fifteen (15) business days.