Privacy Policy
PRIVACY POLICY The Tribal Node — a brand of Aurelian Vulcan Group Private Limited Effective date: 31 August 2026Version: 1.0Last reviewed: 31 August 2026
1. Who we are
1.1 This Privacy Policy is issued by Aurelian Vulcan Group Private Limited, a company incorporated under the Companies Act, 2013, bearing Corporate Identity Number U62090WR2026PTC293034, with its registered office at C/O Indranil Basu, Ground Floor, 95/1, Gouripur Bye Road, Birati, Kolkata, North 24 Parganas, West Bengal – 700051, India ("the Company", "we", "us", "our").
1.2 The Tribal Node is a brand owned and operated by the Company. All services offered under the brand The Tribal Node, and all personal data collected through the website www.thetribalnode.com and any associated customer portal, application or ordering system (together, the "Platform"), are provided and controlled by the Company.
1.3 For the purposes of the Digital Personal Data Protection Act, 2023, the Company is the Data Fiduciary in respect of the personal data described in this Policy. If you are an individual whose personal data we process, you are a Data Principal.
2. Scope of this Policy
2.1 This Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, how we protect it, and the rights available to you.
2.2 This Policy applies to visitors to the Platform, persons who submit enquiries to us through any channel, and clients who purchase services from us. It also applies to authorised representatives and employees of business clients whose personal details are shared with us in the course of a project.
2.3 This Policy does not apply to any third-party website, platform or application that you may reach through a link on our Platform. Those services are governed by their own privacy policies.
3. The legal framework we operate under
3.1 We process personal data in accordance with the laws of India, in particular:
(a) the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (notified on 13 November 2025 and being brought into force in phases, with full compliance required by 13 May 2027);
(b) the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which remain in force until they are superseded;
(c) the Consumer Protection (E-Commerce) Rules, 2020; and
(d) the Directions under Section 70B(6) of the Information Technology Act, 2000 issued by the Indian Computer Emergency Response Team (CERT-In) on 28 April 2022.
3.2 We have adopted the standards of the Digital Personal Data Protection Act, 2023 ahead of the date on which they become fully enforceable. Where a provision of that Act is not yet in force, we apply it as a matter of policy.
4. The personal data we collect
4.1 Information you give us directly
(a) Enquiry and consultation data. Your name, business name, mobile number, email address, city, the service you are interested in and any message you send us, whether submitted through a form on the Platform, by telephone, by email, or through WhatsApp.
(b) Account and order data. Where the Platform offers a customer account or ordering facility: your login credentials, the services you add to your cart or order, the scope agreed with you, order status, and the messages you exchange with us on an order.
(c) Project requirement data. The brief, specification, brand material, credentials, content, images, copy or other material you provide to enable us to deliver a service. You should not send us any personal data of third parties in a brief unless you are lawfully entitled to do so.
(d) Billing and statutory data. Billing name, billing and place-of-supply address, Goods and Services Tax Identification Number where you provide one, Permanent Account Number where a statutory deduction applies, invoice records and payment records.
4.2 Information collected automatically
(a) Server and access logs. Your Internet Protocol address, browser type and version, device and operating system, referring page, pages accessed, and the date and time of access. These are generated by our hosting infrastructure and are used for security, fraud prevention, diagnostics and statutory log retention.
4.3 Payment information
4.3.1 Payments on the Platform are processed by Razorpay Software Private Limited, a payment aggregator authorised by the Reserve Bank of India. Card numbers, card verification values, expiry dates, net banking credentials and Unified Payments Interface credentials are entered on Razorpay's systems and are never collected, stored, processed or seen by us.
4.3.2 We receive from Razorpay only the transaction identifier, the amount, the date and time, the payment status and the payment method used. We retain these for accounting, reconciliation, taxation and refund purposes.
4.4 Information we do not collect
4.4.1 We do not knowingly collect biometric information, health information, sexual orientation, financial account credentials, passwords to third-party systems, Aadhaar numbers, or any other category of sensitive personal data beyond that described above.
4.4.2 We do not build behavioural profiles, we do not run advertising or analytics tracking on the Platform, and we do not sell, rent or trade personal data to any person for any consideration.
5. Why we process your personal data
5.1 We process personal data only for the following specified purposes:
(a) to respond to your enquiry and provide a quotation or proposal;(b) to negotiate, conclude and perform a contract for services with you;(c) to procure and coordinate delivery of the services through our specialist partners;(d) to communicate with you about the status, progress, delivery and support of your order;(e) to raise proforma invoices, receipt vouchers, tax invoices, credit notes and debit notes, and to collect payment;(f) to comply with our obligations under the Companies Act, 2013, the Central Goods and Services Tax Act, 2017, the Income-tax Act, 1961 and other applicable law;(g) to maintain the security and integrity of the Platform, to prevent fraud and misuse, and to investigate incidents; and(h) to establish, exercise or defend a legal claim, or to respond to a lawful direction of a court, tribunal or governmental authority.
5.2 We process personal data on the basis of your consent, given at the point of collection, or on the basis of a legitimate use recognised under Section 7 of the Digital Personal Data Protection Act, 2023, including where you have voluntarily provided your personal data to us for a specified purpose, and where processing is necessary to comply with a legal obligation.
5.3 We do not use your personal data for any purpose that is incompatible with the purpose for which it was collected, and we do not send you promotional or marketing communications unless you have separately asked us to. Communications relating to your enquiry, your order, your invoices and your support requests are service communications and are not marketing.
6. Disclosure of personal data
6.1 Our delivery team
6.1.1 Services under The Tribal Node brand are contracted, managed and delivered by the Company. Delivery is carried out by our personnel together with a network of engaged specialists, contractors and production partners working under our direction and to our specification. The Company is the sole contracting party, retains control of the engagement, and is solely accountable to you for the services delivered.
6.1.2 Where a member of our delivery team requires access to personal data in order to work on your project, we disclose only what is necessary for that purpose. This is typically limited to your name or business name, a single coordination contact, and the brief and material you have supplied. We do not disclose your billing details, payment records, tax identifiers, invoices or account credentials to any member of the delivery team.
6.1.3 Every person or entity engaged by us is bound by written terms of confidentiality which restrict them to processing your personal data solely on our instructions and solely for the purpose of your project, require them to apply reasonable security safeguards, and prohibit them from retaining, disclosing or using your personal data for any other purpose. Access is withdrawn on completion of the engagement.
6.1.4 A member of our delivery team may be located in India or outside India. Clause 7 applies to any such transfer.
6.1.5 You may at any time exercise your right under Clause 12.1(a) to obtain details of the persons with whom your personal data has been shared.
6.2 Other recipients
6.2.1 We also disclose personal data to: our payment aggregator, Razorpay Software Private Limited, for the purpose of processing payments and refunds; our banking partner, for settlement; our hosting and communications providers, for the operation of the Platform and our email; and our chartered accountant, company secretary and legal advisers, under professional duties of confidentiality.
6.2.2 We will disclose personal data to a governmental authority, court, tribunal or law enforcement agency where we are required or authorised to do so by law, and we will make such disclosure to the minimum extent required.
6.2.3 In the event of a merger, amalgamation, restructuring or transfer of the business or any part of it, personal data may be transferred to the successor entity, which will remain bound by this Policy or by a policy no less protective.
7. Transfer of personal data outside India
7.1 Some of our infrastructure providers and delivery partners may store or process personal data outside India.
7.2 Under Section 16 of the Digital Personal Data Protection Act, 2023, personal data may be transferred outside India except to a country or territory that the Central Government has restricted by notification. We do not transfer personal data to any country or territory so restricted. Where a transfer takes place, we require the recipient to apply security safeguards no less protective than those described in this Policy, and we remain accountable to you for that personal data.
8. Cookies and similar technologies
8.1 We do not use analytics cookies, advertising cookies, tracking pixels, social media pixels or any similar technology that profiles you or follows you across websites. We do not operate a consent banner because we do not deploy any cookie that would require your consent.
8.2 The Platform uses only strictly necessary cookies and equivalent browser storage, where these are required to keep your session active, to remember the contents of your cart, to protect against cross-site request forgery and similar attacks, and to complete a payment. These are exempt from the requirement of consent because the Platform cannot function without them.
8.3 During checkout, Razorpay may set its own cookies on its own pages in order to process your payment securely. Those cookies are controlled by Razorpay and are governed by Razorpay's privacy policy.
8.4 You may block or delete cookies through your browser settings. If you block strictly necessary cookies, parts of the Platform, including checkout, may not function.
9. Retention of personal data
9.1 We retain personal data only for as long as is necessary for the purpose for which it was collected, or for such longer period as is required by law.
9.2 In particular:
(a) Enquiries that do not result in an order are retained for twenty-four months from the date of last contact, after which they are erased.
(b) Project records, briefs and delivery correspondence are retained for three years from completion of the project, in order to service warranty, support and dispute obligations.
(c) Invoices, receipts, payment records and books of account are retained for eight financial years, as required by Section 128(5) of the Companies Act, 2013, and for the periods required under the Central Goods and Services Tax Act, 2017 and the Income-tax Act, 1961.
(d) Server and access logs are retained for one hundred and eighty days, as required by the CERT-In Directions dated 28 April 2022.
9.3 On expiry of the applicable period, personal data is erased or irreversibly anonymised, except where retention is required for the establishment, exercise or defence of a legal claim.
10. Security
10.1 We implement reasonable security practices and procedures commensurate with the nature of the personal data we hold and the risk to which it is exposed. These include access control on a need-to-know basis, encryption of data in transit using Transport Layer Security, restriction of administrative access, secure credential handling, logging of access to systems, and contractual security obligations imposed on our partners and service providers.
10.2 No method of transmission or storage is entirely secure, and we do not represent that our systems are immune from compromise. You are responsible for keeping any account credentials confidential and for notifying us immediately if you believe they have been compromised.
11. Personal data breach
11.1 In the event of a personal data breach, we will inform each affected Data Principal without delay, describing the nature, extent and timing of the breach, its likely consequences, the measures we have taken, and the steps you may take to protect yourself.
11.2 We will intimate the Data Protection Board of India without delay and will furnish the further particulars required by Rule 7 of the Digital Personal Data Protection Rules, 2025 within seventy-two hours.
11.3 Where the incident is a cyber security incident of a category specified by CERT-In, we will report it to CERT-In within six hours of noticing it, as required by the Directions dated 28 April 2022.
12. Your rights
12.1 As a Data Principal you have the following rights:
(a) Right to information. To obtain a summary of the personal data of yours that we are processing, the processing activities undertaken, and the identities of the Data Fiduciaries and Data Processors with whom it has been shared.
(b) Right to correction, completion, updating and erasure. To have inaccurate or misleading personal data corrected, incomplete data completed, data updated, and data erased where it is no longer required for the purpose for which it was collected and where retention is not required by law.
(c) Right to withdraw consent. To withdraw your consent at any time, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect processing that we are required by law to continue.
(d) Right of grievance redressal. To have your grievance addressed through the mechanism in Clause 13.
(e) Right to nominate. To nominate any other individual to exercise these rights on your behalf in the event of your death or incapacity.
12.2 To exercise any right, write to us at the address in Clause 13, stating your name, the contact details you provided to us, and the right you wish to exercise. We may ask you for information reasonably necessary to verify your identity before acting on a request, in order to protect you against unauthorised disclosure.
13. Grievance Officer and how to contact us
13.1 In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, Rule 4(5) of the Consumer Protection (E-Commerce) Rules, 2020, and Section 13 read with Rule 9 of the Digital Personal Data Protection Rules, 2025, the following officer has been designated to receive and redress your grievances:
Grievance Officer: Ms. Chandana BasuDesignation: Director, Aurelian Vulcan Group Private LimitedEmail: hello@thetribalnode.comTelephone: +91 62908 24487Address: C/O Indranil Basu, Ground Floor, 95/1, Gouripur Bye Road, Birati, Kolkata, North 24 Parganas, West Bengal – 700051, India
13.2 We will acknowledge every grievance within forty-eight hours of receipt and will redress it within thirty days, and in any event within the period prescribed by law.
13.3 If your grievance is not resolved to your satisfaction, you may make a complaint to the Data Protection Board of India in the manner prescribed under the Digital Personal Data Protection Act, 2023 and the Rules made thereunder.
14. Children
14.1 Our services are offered to businesses and to adults. We do not knowingly collect the personal data of any individual below the age of eighteen years.
14.2 We do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If we become aware that we have collected the personal data of a child without verifiable consent of a parent or lawful guardian, we will erase it promptly.
15. Your obligations as a Data Principal
15.1 In accordance with Section 15 of the Digital Personal Data Protection Act, 2023, you are required to provide authentic and accurate information, not to impersonate another person, not to suppress material information when providing personal data for any document issued by the State, and not to register a false or frivolous grievance or complaint.
16. Data processed on behalf of our clients
16.1 We do not currently receive, access or process personal data belonging to the customers, subscribers or end users of our clients. Our engagements are performed on the basis of briefs, specifications and creative material supplied by the client.
16.2 Should any future engagement require us to process personal data on a client's behalf and on the client's instructions, we will do so only as a Data Processor under a written agreement recording the purpose, the security safeguards, the restrictions on further disclosure, and the obligation to erase or return that data on completion of the engagement. In such an engagement the client remains the Data Fiduciary.
17. Changes to this Policy
17.1 We may amend this Policy from time to time. The revised Policy will be published on the Platform with a new version number and effective date, and will take effect from that date.
17.2 Where an amendment materially changes the purposes for which we process your personal data or the recipients to whom it is disclosed, we will inform you by email or through the Platform, and where the law requires it, we will obtain your fresh consent.
18. Governing law and jurisdiction
18.1 This Policy is governed by and construed in accordance with the laws of India.
18.2 Subject to the statutory rights available to you as a consumer and to your right of complaint to the Data Protection Board of India, the courts at Kolkata, West Bengal shall have exclusive jurisdiction.
Aurelian Vulcan Group Private LimitedOperating the brand The Tribal NodeCIN: U62090WR2026PTC293034 | GSTIN: 19ABFCA2560A1Z3www.thetribalnode.com | hello@thetribalnode.com | +91 62908 24487

