Privacy Policy
Last updated 28 July 2026
Varevance Technologies Private Limited (operating the Tenacio platform at tenacio.io)
Effective Date: 28 July 2026 Last Updated: 28 July 2026 Version: 1.0
1. Introduction
Varevance Technologies Private Limited (“Varevance”, “Tenacio”, “Company”, “we”, “us”, “our”) is a company incorporated under the Companies Act, 2013, having its registered office at 3E 22 Kalpataru Aura, LBS Marg, Ghatkopar West, Mumbai – 400 086, Maharashtra, India. The Company operates the website located at https://tenacio.io and its sub-domains (the “Website”).
The Company respects your privacy and is committed to handling personal data lawfully, fairly and transparently. This Privacy Policy (the “Policy”) explains what personal data the Company collects when you visit or interact with the Website, why it is collected, how the Company uses and shares it, how long it is retained, and the rights available to you.
This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made thereunder, the Information Technology Act, 2000 and the rules made thereunder, and other applicable Indian law, each as amended from time to time.
Please read this Policy carefully. By accessing or using the Website, or by submitting your information to the Company through the Website, you acknowledge that you have read and understood this Policy.
2. Scope — What This Policy Covers and What It Does Not
2.1 What this Policy covers
This Policy applies to personal data that the Company collects in its own capacity as a Data Fiduciary, namely personal data of:
- visitors to and users of the Website;
- prospective customers, business contacts and representatives of organisations who complete forms on the Website, request a demonstration, download a resource, subscribe to communications, or otherwise contact the Company;
- individuals who correspond with the Company’s sales, support, partnership or compliance teams through channels published on the Website; and
- individuals who apply for roles with the Company, or who engage with the Company as partners, vendors or professional advisers, where their data is collected through the Website.
2.2 What this Policy does not cover
This Policy does not apply to personal data that the Company processes on the instructions of, and on behalf of, its enterprise customers in the course of delivering services to them (such data being referred to as “Customer Data”).
Where the Company processes Customer Data, the enterprise customer is the Data Fiduciary and determines the purposes and means of processing. The Company acts as a Data Processor and processes Customer Data solely in accordance with the master services agreement, data processing agreement, statement of work and related contractual instruments executed between the Company and that customer (collectively, the “Customer Agreement”), and in accordance with applicable law.
Consequently:
- The collection notice, consent, lawful basis, retention schedule, security commitments, sub-processing arrangements, breach notification obligations and data principal request handling in respect of Customer Data are governed by the Customer Agreement and by the customer’s own privacy notice — not by this Policy.
- If you are an individual whose personal data has been provided to the Company by one of its enterprise customers, and you wish to exercise rights in respect of that data, please contact that organisation directly in the first instance. If you approach the Company, the Company will, unless prohibited by law, refer your request to the relevant customer and support that customer in responding to it in accordance with the Customer Agreement.
- Nothing in this Policy expands, limits or overrides the obligations set out in any Customer Agreement. In the event of a conflict between this Policy and a Customer Agreement in respect of Customer Data, the Customer Agreement prevails.
2.3 Third-party websites
The Website may contain links to websites, platforms or resources operated by third parties. This Policy does not govern those properties. You are encouraged to review the privacy policy of any third-party website before providing personal data to it.
3. Definitions
Capitalised terms used in this Policy, including Personal Data, Processing, Data Principal, Data Fiduciary, Data Processor and Board, carry the meanings given to them under the DPDP Act. “Customer Data” and “Customer Agreement” have the meanings given in Clause 2.2.
4. Role of the Company
In respect of the Personal Data described in Clause 2.1, the Company acts as a Data Fiduciary. The Company determines the purposes for which and the means by which that Personal Data is processed, and is accountable for it under the DPDP Act.
In respect of Customer Data, the Company acts as a Data Processor, as described in Clause 2.2.
5. Personal Data Collected by the Company
5.1 Data you provide directly
When you complete a form on the Website, request a demonstration, download a resource, raise a support or partnership enquiry, or otherwise communicate with the Company, the Company may collect:
- Identity and contact details — full name, work email address, telephone or mobile number.
- Professional details — organisation name, job title or functional role, and the business function you represent.
- Enquiry details — the subject of your enquiry, the areas of the Company’s platform you have expressed interest in, the contents of your message, and any additional information you choose to include.
- Correspondence records — emails, support tickets, meeting notes and, where you have been informed in advance and applicable law permits, recordings or transcripts of calls and online meetings.
- Recruitment data — where you apply for a role with the Company, your curriculum vitae, employment and education history, and any other information you submit in support of your application.
The Company asks that you use an official work email address and that you provide only information necessary for the purpose of your enquiry. Please do not submit sensitive personal information, government identifiers, financial account details or third-party personal data through Website forms.
5.2 Data collected automatically
When you access the Website, the Company and its service providers may automatically collect:
- Device and technical identifiers — information collected through automatic tracking of your use of the Website and related Company systems, irrespective of whether you have created an account: your interactions with those systems, pages viewed, nature of searches performed, IP address, computer system and device details, device identifier, browser, operating system, language settings, approximate location derived from IP address, and connection details.
- Usage data — referring and exit pages, the date, time and duration of your visit, navigation paths, click and scroll interactions, and the search terms or campaign parameters that brought you to the Website.
- Inferred interest data — topic interests inferred from the pages, resources and campaigns you engage with (for example, identity verification, customer onboarding, risk and fraud, or data protection compliance).
- Cookies and similar technologies — cookies, pixels, tags, local storage and software development kits placed on or read from your device, some of which are operated by third-party providers under their own privacy policies. You may set your preferences through any cookie preference control made available on the Website, or block or delete cookies through your browser settings; doing so may affect parts of the Website.
5.3 Data received from third parties and public sources
The Company may also obtain Personal Data about you from:
- third parties it engages or works with, including analytics and marketing platforms, event and conference organisers, and channel, referral and integration partners;
- publicly available and licensed sources, including corporate registries, regulatory filings, company websites, press and industry publications, and subscription-based business information and lead intelligence databases; and
- professional and social media platforms, including publicly available profile and post content, and content you share with or through the Company’s pages.
Such Personal Data is typically limited to name, job title, organisation, business contact details and publicly stated professional interests, and is used to identify and qualify prospective business contacts, keep contact details current, and tailor relevant business communications. Social media and professional networking platforms operate under their own privacy policies, which you are encouraged to review. Where Personal Data is received from a provider, the Company requires by contract that it has been lawfully collected; you may object to this processing, or request erasure, by writing to the Company’s Grievance Officer under Clause 14.
5.4 Data relating to other individuals
If you provide the Company with Personal Data relating to another individual (for example, a colleague’s contact details), you confirm that you are authorised to do so and that the individual concerned is aware of, and has consented to, the processing described in this Policy.
6. Purposes of Processing
The Company processes Personal Data described in Clause 2.1 for the following purposes:
| # | Purpose |
|---|---|
| 1 | Responding to your enquiries, demonstration requests and support requests, and providing the resources you have requested |
| 2 | Business development, qualification of prospective customers, and relationship management |
| 3 | Sending service updates, product information, invitations and marketing communications, where you have consented or where applicable law otherwise permits |
| 4 | Operating, securing, maintaining and improving the Website, and measuring the effectiveness of the Company’s campaigns |
| 5 | Tailoring the content, resources and communications presented to you on the basis of inferred topic interests |
| 6 | Detecting, investigating and preventing fraud, misuse, unauthorised access and security incidents |
| 7 | Complying with applicable law, responding to lawful requests from courts, regulators and authorities, establishing or defending legal claims, and maintaining statutory, accounting and audit records |
| 8 | Assessing applications for employment or engagement with the Company |
The Company does not use Website Personal Data for automated decision-making that produces legal or similarly significant effects on you.
7. Lawful Basis, Notice and Consent
7.1 Consent
Where the Company relies on your consent, it will seek that consent through a clear, itemised notice presented to you at or before the point of collection, describing the Personal Data sought, the purpose of processing, the manner in which you may withdraw consent, the manner in which you may exercise your rights, and the manner in which you may make a complaint to the Board. Consent so obtained is free, specific, informed, unconditional and unambiguous, and is given by clear affirmative action.
7.2 Legitimate uses
Where permitted by Section 7 of the DPDP Act, the Company may process Personal Data for certain specified legitimate uses without separate consent — including where you have voluntarily provided Personal Data to the Company for a specified purpose and have not indicated that you object to its use for that purpose, and where processing is necessary to comply with a legal obligation, judgment or order.
7.3 Withdrawal of consent
You may withdraw your consent at any time, with the same ease with which it was given, by writing to the Company at the address in Clause 14 or by using the unsubscribe or cookie preference mechanisms described in this Policy.
Withdrawal of consent operates prospectively. The lawfulness of processing carried out before withdrawal is not affected. Following withdrawal, the Company will cease processing your Personal Data for the relevant purpose and will cause its processors to do the same, within a reasonable time, unless retention is required or authorised under applicable law (see Clause 10).
Withdrawal of consent may mean that the Company is unable to respond to your enquiry, provide requested materials, or continue certain communications with you.
8. Sharing and Disclosure of Personal Data
The Company shares Personal Data only where necessary, on a need-to-know basis, and subject to appropriate contractual and security safeguards. The Company may share Personal Data with:
(a) The Company’s personnel. Employees, officers and directors of the Company, limited to those who require access to perform their functions.
(b) Service providers and processors. Providers of cloud hosting and infrastructure, customer relationship management, marketing automation, email delivery, analytics, helpdesk and ticketing, communications, document execution and IT support services. These providers process Personal Data only on the Company’s documented instructions, under written contracts that impose confidentiality and security obligations consistent with the DPDP Act.
(c) Professional advisers. Legal counsel, auditors, insurers, accountants and consultants, where necessary for the establishment, exercise or defence of legal claims, or for compliance and assurance purposes.
(d) Partners. Channel partners, resellers and system integrators, where you have engaged with the Company through such a partner or have consented to such sharing.
(e) Courts, regulators and authorities. Where disclosure is required or authorised by applicable law, or in response to a valid legal process, court order, or a lawful request from a governmental, regulatory, statutory or law enforcement authority; or where necessary to protect the Company’s rights, property or safety, or those of its customers or the public.
(f) Corporate transactions. In connection with a merger, amalgamation, acquisition, restructuring, financing, or transfer of all or part of the Company’s business or assets, in which case Personal Data may be disclosed to the counterparty and its advisers, subject to confidentiality undertakings and to the continued application of protections no less protective than those in this Policy.
(g) With your consent. For any other purpose disclosed to you at the time and to which you have consented.
The Company does not sell Personal Data, and does not disclose Personal Data to third parties for their own independent marketing purposes without your consent.
9. Data Location
Personal Data collected through the Website is processed and stored on infrastructure located within India, in accordance with applicable regulatory requirements and Government of India norms on data localisation and residency.
Where the Company engages service providers to process Personal Data on its behalf, it contracts for such processing to be carried out within India, and it includes data residency requirements in its vendor due diligence and contracting process. The Company does not transfer Personal Data collected through the Website outside India.
10. Retention and Erasure
The Company retains Personal Data only for as long as is necessary for the purpose for which it was collected, or for such longer period as is required or authorised under applicable law.
In practice, this means:
- Enquiry, demonstration and resource-download data is retained for the duration of the enquiry or business relationship and for 12 months thereafter, to allow for follow-up and continuity of the commercial relationship.
- Marketing and communication preference data is retained until you withdraw consent or unsubscribe, following which the Company retains a minimal suppression record so that your opt-out can be honoured.
- Correspondence and support records are retained for 12 months from the date of last interaction.
- Recruitment data is retained for 12 months from the conclusion of the recruitment process, unless you ask the Company to retain it for future opportunities.
- Website technical and usage logs are retained for 180 days, and thereafter deleted or aggregated.
- Records required for statutory, accounting, tax, audit or regulatory purposes are retained for the period prescribed by the relevant law.
Where you withdraw consent, or where the specified purpose is no longer being served, the Company will erase the relevant Personal Data and will cause its processors to do the same, unless retention is necessary for compliance with any law for the time being in force.
The Company may retain and use data that has been aggregated or irreversibly anonymised, and which cannot reasonably be used to identify you, for statistical analysis, benchmarking and service improvement. Such data is not Personal Data.
11. Security
The Company implements reasonable security safeguards commensurate with the nature and volume of the Personal Data processed, and maintains an information security programme designed in alignment with the principles of ISO/IEC 27001 and with reasonable security practices and procedures under applicable Indian law.
Personal Data provided to the Company, subject to disclosure in accordance with this Policy, is maintained in a safe and secure manner, and is protected to a commercially reasonable extent against unauthorised access, use, alteration, disclosure, loss or destruction. The Company’s databases and information are stored on secure servers with appropriate firewalls and access controls, and access to Personal Data is restricted to those personnel and service providers who require it in order to perform their functions.
The Company employs procedures, including contractual obligations, requiring all third parties to respect the security of Personal Data relating to you and to treat it in accordance with applicable data protection laws. The Company does not grant permission for its third-party service providers to use Personal Data relating to you for their own purposes, and grants permission only for them to process such Personal Data for specified purposes and in accordance with the Company’s instructions.
Notwithstanding anything to the contrary in this Policy, while the Company will use all reasonable efforts to ensure that information collected from you, or generated by your use of the Website and related Company systems, is safe and secure, it offers no representation, warranty or other assurance that its security measures are adequate, safe, fool-proof or impenetrable. No method of transmission over the internet, and no method of electronic storage, is entirely secure, and any transmission of data to the Company over the internet is at your own risk. You are responsible for maintaining the confidentiality of any credentials issued to you and for the security of the device from which you access the Website.
12. Your Rights as a Data Principal
Subject to the DPDP Act and the rules made thereunder, you have the following rights in respect of Personal Data for which the Company is the Data Fiduciary:
(a) Right to access information. To obtain a summary of the Personal Data processed about you, the processing activities undertaken, and the identities of those with whom that Personal Data has been shared.
(b) Right to correction, completion, updating and erasure. To have your Personal Data corrected, completed, updated or erased, unless retention is required under applicable law.
(c) Right of grievance redressal. To register a grievance with the Company under Clause 14, which you must exhaust before approaching the Board.
(d) Right to nominate. To nominate another individual to exercise your rights in the event of your death or incapacity.
(e) Right to withdraw consent. As set out in Clause 7.3.
12.1 How to exercise your rights
Please write to the Company’s Grievance Officer at the address in Clause 14. The Company may need to verify your identity before acting on a request, and there is no fee for making one. The Company will respond within the timelines prescribed under applicable law and, in any event, without undue delay, and will inform you of the reason where a request is declined or limited as permitted or required under applicable law, including where it relates to Customer Data (see Clause 2.2).
12.2 Your duties
The DPDP Act places certain duties on Data Principals. In particular, you must not impersonate another person or suppress material information when providing Personal Data, must not register a false or frivolous grievance, and must furnish only verifiably authentic information when exercising the right to correction or erasure.
13. Children and Persons with Disabilities
The Website is a business-to-business platform intended for use by professionals and is not directed at, or intended for use by, individuals under the age of 18 years. The Company does not knowingly collect Personal Data of children through the Website, and does not undertake tracking, behavioural monitoring or targeted advertising directed at children.
Where the Company becomes aware that Personal Data of a child has been collected through the Website, it will erase that data promptly. Where processing of a child’s Personal Data, or of Personal Data of a person with a disability who has a lawful guardian, is required, the Company will obtain verifiable consent from the parent or lawful guardian in the manner prescribed under the DPDP Act.
If you believe that a child has provided Personal Data to the Company, please contact the Company’s Grievance Officer.
14. Grievance Redressal
If you have any question, concern, complaint or grievance regarding this Policy or the manner in which the Company processes your Personal Data, please contact the Company’s Grievance Officer. The Company will address the matter expeditiously.
Grievance Officer
- Email: [email protected]
- Address: Varevance Technologies Private Limited, 3E 22 Kalpataru Aura, LBS Marg, Ghatkopar West, Mumbai – 400 086, Maharashtra, India
Process
- The Company will acknowledge your grievance within 2 working days of receipt.
- The Company may contact you for further information or clarification necessary to investigate the matter.
- The Company will communicate its decision to you within 30 days of registration of the grievance, or within such shorter period as may be prescribed under applicable law.
Escalation to the Board
If you are not satisfied with the Company’s response, or if the Company does not respond within the applicable timeline, you may register a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act and the rules made thereunder. You are required to exhaust the grievance redressal process set out above before approaching the Board.
General contact
For general privacy queries that are not grievances, you may write to the Company at [email protected].
Registered office: Varevance Technologies Private Limited, 3E 22 Kalpataru Aura, LBS Marg, Ghatkopar West, Mumbai - 400 086, India
15. Changes to This Policy
The Company may amend this Policy from time to time to reflect changes in law, regulatory guidance, its practices, or the features of the Website. The revised Policy will be published on this page with an updated “Last Updated” date and version number, and will take effect from the date of publication.
You are encouraged to review this page periodically. Your continued use of the Website following publication of an amended Policy constitutes acknowledgement of the amended Policy.
16. Severability
Each clause of this Policy is severable. If any clause or part of a clause is held to be invalid, unlawful or unenforceable, that clause or part will be severed and the remainder of this Policy will continue in full force and effect.
17. Governing Law and Jurisdiction
This Policy is governed by and construed in accordance with the laws of India. Subject to Clause 14, the courts and tribunals at Mumbai, Maharashtra, India have exclusive jurisdiction over any dispute, claim or proceeding arising out of or in connection with this Policy.
© 2025 Varevance Technologies Private Limited. All rights reserved.