Legal

Privacy Policy

We built Grovia Vault on a zero-knowledge foundation — we cannot read your backups even if we wanted to. This policy explains what we do collect, why, and how we protect it.

Last updated: 1 January 2026  ·  Effective: 1 January 2026  ·  Controller: Webzworld, India

The short version: Your backup data is encrypted on your device before it reaches us. We hold the ciphertext, not the plaintext. Your encryption passphrase never leaves your device. Not even Grovia Vault staff can read your files.

1. Who We Are

Grovia Vault is a product of Webzworld, a company registered in India. References to "Grovia Vault", "we", "us", or "our" in this policy refer to Webzworld operating the Grovia Vault service. Our primary contact email is info@groviavault.com.

2. Data We Collect

2.1 Account Data

  • Name and work email address (required to create an account)
  • Organisation / company name
  • Hashed password (bcrypt — we never store your password in plain text)
  • MFA secret (stored encrypted at rest)
  • Subscription and billing contact details

2.2 Agent Telemetry

  • Device hostname, OS, and agent version
  • Backup job status: start time, end time, bytes processed, file count
  • Threat detection events (e.g., ransomware score, extension anomalies) — metadata only, never file content
  • Agent heartbeat timestamps

2.3 Backup Data

Your files are encrypted on your device using AES-256-GCM before transmission. We receive and store only encrypted ciphertext chunks. We have no ability to decrypt or access your file contents. Encryption keys are derived from your passphrase using SHA-256 key derivation and never transmitted to our servers.

2.4 Website and API Usage Data

  • IP address (used for rate limiting and fraud prevention; not linked to backup data)
  • Browser type and referrer (collected via server access logs, retained for 30 days)
  • Contact form submissions (name, email, message — stored only long enough to respond)

3. How We Use Your Data

  • Providing the service — account management, backup orchestration, threat alerts, restore operations
  • Security and fraud prevention — rate limiting, anomaly detection, abuse prevention
  • Customer support — responding to enquiries and resolving issues
  • Product improvement — aggregated, anonymised usage metrics (no individual file content)
  • Legal compliance — meeting obligations under the DPDP Act 2023 and other applicable Indian laws

We do not sell, rent, or broker your personal data to any third party.

4. Data Storage and Residency

All customer data — including encrypted backup ciphertext, account records, and telemetry — is stored in India (AWS Mumbai, ap-south-1). No personal data is transferred outside India except where you explicitly configure an international storage destination in your backup policy.

Air-gap copies may be stored on Backblaze B2 (EU) by default for disaster-recovery isolation. These copies are encrypted before leaving India and the receiving provider holds only ciphertext.

5. Data Retention

  • Backup data — retained per your configured retention policy (7 days on Free, 90 days on Business, 7 years on Enterprise). Deleted within 30 days of account closure.
  • Account data — retained for the life of your account, then deleted within 60 days of closure.
  • Logs and telemetry — retained for 90 days, then automatically purged.
  • Contact form data — deleted within 90 days of last correspondence.

6. Your Rights Under the DPDP Act 2023

As a Data Principal under India's Digital Personal Data Protection Act 2023, you have the right to:

  • Access — request a summary of personal data we hold about you
  • Correction — request correction of inaccurate data
  • Erasure — request deletion of your account and all associated personal data
  • Grievance redressal — raise a complaint with our Data Protection Officer
  • Nomination — nominate another individual to exercise rights on your behalf in case of incapacity or death

To exercise any of these rights, email info@groviavault.com with the subject line "Privacy Request". We will respond within 30 days.

7. Cookies and Tracking

The Grovia Vault website uses only essential session cookies required for authentication and CSRF protection. We do not use advertising trackers, third-party analytics SDKs, or behavioural profiling cookies. You can disable cookies in your browser; note that this will prevent you from logging into the dashboard.

8. Third-Party Sub-Processors

We use the following sub-processors to deliver the service:

  • Amazon Web Services (Mumbai) — primary cloud infrastructure and hot-tier storage
  • Wasabi Technologies — secondary encrypted backup storage
  • Backblaze B2 — air-gap archival storage (encrypted ciphertext only)
  • Web3Forms — contact form submission routing (name + email + message only)

Each sub-processor is bound by a data processing agreement and may not use your data for their own purposes.

9. Security Measures

  • AES-256-GCM encryption of all backup data, performed client-side before transmission
  • TLS 1.3 in transit for all API and dashboard connections
  • AES-256 encryption at rest for all database tables containing personal data
  • JWT authentication with short expiry + refresh token rotation
  • TOTP-based multi-factor authentication available on all plans
  • PostgreSQL Row-Level Security for strict multi-tenant data isolation
  • Regular penetration testing and vulnerability assessments

10. Children's Privacy

Grovia Vault is a business service intended for organisations and professionals. We do not knowingly collect data from individuals under 18 years of age. If you believe we have inadvertently collected such data, contact us and we will delete it promptly.

11. Changes to This Policy

We will notify registered users by email at least 15 days before making material changes to this policy. The "Last updated" date at the top of this page will always reflect the current version. Continued use of the service after the effective date constitutes acceptance of the revised policy.

12. Contact and Grievance Officer

For privacy questions, data requests, or complaints:

Questions about privacy?

We're happy to walk you through how Grovia Vault handles your data in plain language.

Contact us