


Enterprise Data & Privacy Policy
How EAGLE SORA TRANSCENDENT PRIVATE LIMITED protects your personal information, proprietary enterprise code, and AI workloads under the Digital Personal Data Protection Act, 2023 (DPDP Act, India) and international security standards.

DPDP Act 2023
Full compliance with Indian statutory privacy rights & consent mandates.
Zero AI Model Training
Client code & data are never used to train SoraAI™ or public foundational models.
AES-256 Vault Isolation
Air-gapped VPC options, encrypted at rest (AES-256) and in transit (TLS 1.3).
SLA Grievance Resolution
Statutory Grievance Redressal Officer with < 48-hour acknowledgment guarantee.
1. Scope & Legal Entity Overview
This Enterprise Privacy Notice ("Privacy Policy") applies to all websites, web platforms, APIs, software products (including SoraAI™, SoraCommerce™, and custom enterprise deployments), and digital services operated by:
By accessing our websites, contracting our custom software engineering teams, or deploying our software-as-a-service frameworks, you confirm that you have read, understood, and consented to the data collection and processing practices described herein.
2. Dual-Role Architecture: Data Fiduciary vs. Data Processor
In compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the European Union General Data Protection Regulation (GDPR), EAGLE SORA TRANSCENDENT operates under two distinct legal capacities:
We determine the purpose and means of processing when you interact directly with us—such as when you browse eaglesora.in, submit partnership inquiry forms, apply for open careers, or communicate with our executive leadership team.
- Contact form submissions and meeting telemetry
- Job applicant resumes and employment evaluations
- Direct billing, invoice history, and corporate contracts
When you license our SaaS platforms (e.g., SoraAI™ or SoraCommerce™) or engage our developers for custom code deployment, our client is the Data Fiduciary, and EAGLE SORA acts strictly as the Data Processor under a contractual Data Processing Agreement (DPA).
- Client customer data stored in multi-tenant databases
- Enterprise document vector embeddings
- Zero ownership claims over client end-user records
3. Categories of Personal Data Collected
We adhere strictly to the principle of Data Minimization under Section 6 of the DPDP Act. We only collect information essential for fulfilling business engagements and software performance:
Includes your full name, work email address, phone number, company/organization name, job title, project requirements, budget parameters, and any resume attachments uploaded during recruitment inquiries.
Includes IP address (anonymized at subnet level), browser type and version, device hardware specifications, operating system, API request headers, response latencies, and error stack logs for cyber threat prevention.
We do not collect government identity card numbers (such as Aadhaar, PAN, SSN) via public websites, nor do we ever process biometric information, health records (outside dedicated HIPAA-isolated VPC instances), or religious/political affiliations.
4. Lawful Grounds & Specific Purposes of Processing
Under Section 4 and Section 7 of the DPDP Act 2023, data is processed solely on explicit, informed consent or legitimate contractual uses:
| Processing Purpose | Lawful Basis (DPDP Act) | Retention Trigger |
|---|---|---|
| Custom Software Architecture Scoping & Quotes | Explicit Consent / Pre-contractual steps | Duration of sales cycle or upon withdrawal |
| Delivery of SoraAI™ & SoraCommerce™ SaaS APIs | Contractual Performance (SLA agreement) | Active subscription term + 30 days buffer |
| Infrastructure Security & DDoS Defense | Legitimate Use (Cybersecurity & Lawful Defense) | Rolling 90-day server access logs |
| Engineering Talent Hiring & Interviews | Candidate Consent | 180 days post-recruitment evaluation |
5. SoraAI™ & Enterprise Intelligence Privacy Safeguards
We recognize that proprietary business intelligence and source code are our clients' core competitive assets. We operate under an ironclad technical and legal commitment:
6. Data Principal Rights (Under DPDP Act 2023 & GDPR)
You possess absolute autonomy over your personal information. Under Chapter III of the DPDP Act, you can exercise the following statutory rights at zero cost:
Request an intelligible summary of all personal data being processed by us, including categories and identities of all sub-processors.
Correct misleading, outdated, or incomplete data, and demand the complete permanent deletion of data no longer required for statutory purposes.
File a direct grievance with our designated Resident Grievance Officer, with guaranteed statutory resolution timelines before approaching the Data Protection Board of India.
Withdraw previously granted consent at any time via an email to services.eaglesora@gmail.com with immediate effect on future processing.
7. Data Retention & Cryptographic Erasure Schedule
We do not maintain "indefinite data lakes". Personal and business data is subject to automated time-to-live (TTL) lifecycle schedules:
- Website Leads & Scoping Records: Deleted or anonymized within 90 days if no active commercial engagement proceeds.
- Active Enterprise Client Backups: Retained for the contract duration and securely overwritten via NIST 800-88 cryptographic wipe protocols within 30 days of contract conclusion.
- Financial & Statutory Invoices: Retained for 8 years strictly as mandated by the Indian Companies Act, 2013 and Goods & Services Tax (GST) laws.
8. Cross-Border Transfers & Sub-Processors
Under Section 16 of the DPDP Act 2023, data may be transferred outside India only to jurisdictions not specifically restricted by the Central Government of India, subject to stringent security equivalence.
Our infrastructure sub-processors include SOC-2 certified cloud providers (AWS Mumbai Region, Google Cloud Mumbai/Delhi regions) for domestic hosting, and dedicated isolated client VPCs for overseas enterprise partners. All third-party sub-processors are bound by strict bilateral non-disclosure agreements and Data Processing Addendums.
9. Technical & Cryptographic Safeguards
In compliance with ISO/IEC 27001 information security standards and Rule 8 of the Information Technology (Reasonable Security Practices) Rules, 2011, we employ industry-grade physical and digital defenses:
TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers across all endpoints.
AES-256 bit encryption applied to all relational databases, cache clusters, and file archives.
Mandatory hardware key/MFA authentication, zero-trust perimeter, and ephemeral bastion access.
11. Grievance Redressal Officer & Corporate Contact Details
In strict adherence to Section 13 of the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the Information Technology Rules, 2011, EAGLE SORA TRANSCENDENT PRIVATE LIMITED has designated a resident Grievance Redressal Officer:
Ajay Sanjayrao Gorle
Designated Grievance Redressal Officer & Director
