Page Hero Background Artwork
Floating Leaf Left
Floating Leaf Right
STATUTORY DATA GOVERNANCE & PRIVACY

Enterprise Data & Privacy Policy

How EAGLE SORA TRANSCENDENT PRIVATE LIMITED protects your personal information, proprietary enterprise code, and AI workloads under the Digital Personal Data Protection Act, 2023 (DPDP Act, India) and international security standards.

DPDP Act 2023 Aligned
Zero AI Data Training
ISO/IEC 27001 Standards
100% Client IP Isolation
Enterprise Data & Sphere
DPDP Act 2023 Compliant
Zero AI Model Training
AES-256 Vault Encryption
ISO 27001 Standards

DPDP Act 2023

Full compliance with Indian statutory privacy rights & consent mandates.

Zero AI Model Training

Client code & data are never used to train SoraAI™ or public foundational models.

AES-256 Vault Isolation

Air-gapped VPC options, encrypted at rest (AES-256) and in transit (TLS 1.3).

SLA Grievance Resolution

Statutory Grievance Redressal Officer with < 48-hour acknowledgment guarantee.

GOVERNING NOTICE: V2.4 (2026 RELEASE)Effective Date: October 1, 2026 • Jurisdiction: Republic of India
Legally Enacted
CLAUSE 1.0

1. Scope & Legal Entity Overview

This Enterprise Privacy Notice ("Privacy Policy") applies to all websites, web platforms, APIs, software products (including SoraAI™, SoraCommerce™, and custom enterprise deployments), and digital services operated by:

Legal NameEAGLE SORA TRANSCENDENT PRIVATE LIMITED
Incorporation & JurisdictionRegistered under the Companies Act, 2013 (Ministry of Corporate Affairs, India)
Corporate Registered OfficeDhole Lay Out, Visawa colony, Pimpalgaon, Yavatmal, Maharashtra 445001
Corporate Email & Legal Inquiriesservices.eaglesora@gmail.com

By accessing our websites, contracting our custom software engineering teams, or deploying our software-as-a-service frameworks, you confirm that you have read, understood, and consented to the data collection and processing practices described herein.


CLAUSE 2.0

2. Dual-Role Architecture: Data Fiduciary vs. Data Processor

In compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the European Union General Data Protection Regulation (GDPR), EAGLE SORA TRANSCENDENT operates under two distinct legal capacities:

When We Act as Data Fiduciary

We determine the purpose and means of processing when you interact directly with us—such as when you browse eaglesora.in, submit partnership inquiry forms, apply for open careers, or communicate with our executive leadership team.

  • Contact form submissions and meeting telemetry
  • Job applicant resumes and employment evaluations
  • Direct billing, invoice history, and corporate contracts
When We Act as Data Processor

When you license our SaaS platforms (e.g., SoraAI™ or SoraCommerce™) or engage our developers for custom code deployment, our client is the Data Fiduciary, and EAGLE SORA acts strictly as the Data Processor under a contractual Data Processing Agreement (DPA).

  • Client customer data stored in multi-tenant databases
  • Enterprise document vector embeddings
  • Zero ownership claims over client end-user records

CLAUSE 3.0

3. Categories of Personal Data Collected

We adhere strictly to the principle of Data Minimization under Section 6 of the DPDP Act. We only collect information essential for fulfilling business engagements and software performance:

A. Information Provided Voluntarily by You

Includes your full name, work email address, phone number, company/organization name, job title, project requirements, budget parameters, and any resume attachments uploaded during recruitment inquiries.

B. System & Technical Diagnostic Telemetry

Includes IP address (anonymized at subnet level), browser type and version, device hardware specifications, operating system, API request headers, response latencies, and error stack logs for cyber threat prevention.

C. What We Never Collect (Strictly Excluded)

We do not collect government identity card numbers (such as Aadhaar, PAN, SSN) via public websites, nor do we ever process biometric information, health records (outside dedicated HIPAA-isolated VPC instances), or religious/political affiliations.


CLAUSE 4.0

4. Lawful Grounds & Specific Purposes of Processing

Under Section 4 and Section 7 of the DPDP Act 2023, data is processed solely on explicit, informed consent or legitimate contractual uses:

Processing PurposeLawful Basis (DPDP Act)Retention Trigger
Custom Software Architecture Scoping & QuotesExplicit Consent / Pre-contractual stepsDuration of sales cycle or upon withdrawal
Delivery of SoraAI™ & SoraCommerce™ SaaS APIsContractual Performance (SLA agreement)Active subscription term + 30 days buffer
Infrastructure Security & DDoS DefenseLegitimate Use (Cybersecurity & Lawful Defense)Rolling 90-day server access logs
Engineering Talent Hiring & InterviewsCandidate Consent180 days post-recruitment evaluation

CLAUSE 5.0

5. SoraAI™ & Enterprise Intelligence Privacy Safeguards

The Eagle Sora Zero-Model-Training Guarantee

We recognize that proprietary business intelligence and source code are our clients' core competitive assets. We operate under an ironclad technical and legal commitment:

1. No Third-Party TrainingYour query prompts, database records, and vector embeddings are never sold, shared, or used to fine-tune public LLMs or external artificial intelligence models.
2. Dedicated Private EmbeddingsEach enterprise SoraAI™ deployment uses cryptographically isolated tenant indices. Client A can never access or infer vectors belonging to Client B.

CLAUSE 6.0

6. Data Principal Rights (Under DPDP Act 2023 & GDPR)

You possess absolute autonomy over your personal information. Under Chapter III of the DPDP Act, you can exercise the following statutory rights at zero cost:

Right to Access Summary (Section 11)

Request an intelligible summary of all personal data being processed by us, including categories and identities of all sub-processors.

Right to Correction & Erasure (Section 12)

Correct misleading, outdated, or incomplete data, and demand the complete permanent deletion of data no longer required for statutory purposes.

Right to Grievance Redressal (Section 13)

File a direct grievance with our designated Resident Grievance Officer, with guaranteed statutory resolution timelines before approaching the Data Protection Board of India.

Right to Withdraw Consent (Section 6)

Withdraw previously granted consent at any time via an email to services.eaglesora@gmail.com with immediate effect on future processing.


CLAUSE 7.0

7. Data Retention & Cryptographic Erasure Schedule

We do not maintain "indefinite data lakes". Personal and business data is subject to automated time-to-live (TTL) lifecycle schedules:

  • Website Leads & Scoping Records: Deleted or anonymized within 90 days if no active commercial engagement proceeds.
  • Active Enterprise Client Backups: Retained for the contract duration and securely overwritten via NIST 800-88 cryptographic wipe protocols within 30 days of contract conclusion.
  • Financial & Statutory Invoices: Retained for 8 years strictly as mandated by the Indian Companies Act, 2013 and Goods & Services Tax (GST) laws.

CLAUSE 8.0

8. Cross-Border Transfers & Sub-Processors

Under Section 16 of the DPDP Act 2023, data may be transferred outside India only to jurisdictions not specifically restricted by the Central Government of India, subject to stringent security equivalence.

Our infrastructure sub-processors include SOC-2 certified cloud providers (AWS Mumbai Region, Google Cloud Mumbai/Delhi regions) for domestic hosting, and dedicated isolated client VPCs for overseas enterprise partners. All third-party sub-processors are bound by strict bilateral non-disclosure agreements and Data Processing Addendums.


CLAUSE 9.0

9. Technical & Cryptographic Safeguards

In compliance with ISO/IEC 27001 information security standards and Rule 8 of the Information Technology (Reasonable Security Practices) Rules, 2011, we employ industry-grade physical and digital defenses:

In Transit Encryption

TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers across all endpoints.

At Rest Vaulting

AES-256 bit encryption applied to all relational databases, cache clusters, and file archives.

Access Control & MFA

Mandatory hardware key/MFA authentication, zero-trust perimeter, and ephemeral bastion access.


CLAUSE 10.0

10. Cookies & Telemetry Governance

We do not employ intrusive behavioral tracking or commercial ad retargeting cookies. We use only:

  • Strictly Necessary Cookies: Required to maintain CSRF token security and load-balancer route persistence.
  • Telemetry & Performance: Privacy-first, cookieless aggregated metrics to identify API latency and broken hyperlinks without storing identifying cookies.

STATUTORY COMPLIANCE

11. Grievance Redressal Officer & Corporate Contact Details

In strict adherence to Section 13 of the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the Information Technology Rules, 2011, EAGLE SORA TRANSCENDENT PRIVATE LIMITED has designated a resident Grievance Redressal Officer:

AG

Ajay Sanjayrao Gorle

Designated Grievance Redressal Officer & Director

Statutory DPO
Email (Statutory SLA)services.eaglesora@gmail.com
Direct Phone Line+91 9307807516
Registered HQ AddressDhole Lay Out, Visawa colony, Pimpalgaon, Yavatmal, Maharashtra 445001
Statutory Redressal Timeline:All grievances submitted to the Grievance Officer will receive a formal acknowledgment ticket within 48 hours and substantive resolution within 30 days. If not resolved satisfactorily, you may file an appeal before the Data Protection Board of India.
Submit Data Subject Request