Privacy Policy — Convey U All

Convey U All

Privacy Policy

Effective Date: 1 March 2026

Last Reviewed: March 2026

Compliance Frameworks: India DPDP Act 2023 · EU/EEA GDPR (2016/679) · US CCPA/CPRA · IT Act 2000 (India)

Plain-Language Summary

We collect only the information we need to deliver our services to you. We do not sell your personal data. We protect your data using industry-standard security. You have rights to access, correct, or delete your data at any time. Indian law governs this Policy. EU and US residents have additional rights described in Sections 8 and 9 below.

1. Who We Are

This Privacy Policy describes how MG Ray Infotech (operating as Convey U All) (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you visit conveyuall.com (the “Platform”) or engage with our services.

Our registered office is at: 4th Floor, Bhamashah Techno Hub, Sansthan Path, Malviya Nagar, Jaipur, Rajasthan – 302017, India

Data Privacy Contact: info@conveyuall.com



2. Data We Collect

2.1 Information You Provide Directly

  • Identity data: full name, company name, job title
  • Contact data: email address, phone number, postal address
  • Project and communication data: enquiry details, project briefs, messages, and feedback you share with us
  • Payment data: billing address, invoice details (we do not store card or bank details directly; payment processing is handled by PCI-DSS compliant processors)

2.2 Information Collected Automatically

  • Technical data: IP address, browser type and version, operating system, device identifiers
  • Usage data: pages visited, time on page, clickstream data, referring URLs
  • Cookie and tracking data: see Section 6 (Cookies) for full details

2.3 Information from Third Parties

  • Business contact data from professional networks such as LinkedIn
  • Analytics aggregates from tools such as Google Analytics
  • Referral information from partners

We do not knowingly collect personal data from individuals under 18 years of age. If you believe we have done so inadvertently, please contact us immediately for deletion.

3. Purposes & Legal Bases for Processing

We process personal data only where we have a lawful basis to do so. The table below summarises our processing activities:

 

Purpose

Data Used

Lawful Basis

Respond to enquiries and provide services

Identity, contact, project data

Contract / Legitimate Interest

Account and project management

Identity, contact, project data

Contract

Invoicing and payment processing

Identity, contact, billing data

Contract / Legal Obligation

Service improvement and analytics

Usage, technical data

Legitimate Interest

Marketing communications (opt-in)

Identity, contact data

Consent

Legal compliance and regulatory obligations

Any relevant data

Legal Obligation

Security and fraud prevention

Technical, usage data

Legitimate Interest

4. How We Share Your Data

We do not sell, rent, or trade your personal data. We may share data in the following limited circumstances:

4.1 Service Providers & Sub-processors

We engage trusted third-party providers to assist in operating our business (e.g., cloud hosting, email delivery, analytics, payment processing). These providers access personal data only as necessary to perform their services and are bound by data processing agreements.

4.2 Legal Requirements

We may disclose personal data if required to do so by applicable law, court order, or regulatory authority, or where necessary to protect the rights, property, or safety of Convey U All, our clients, or the public.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity, who will be bound by this Privacy Policy or an equivalent level of protection.

4.4 With Your Consent

We may share data for other purposes with your prior explicit consent.

5. International Data Transfers

Our primary operations are based in India. If you access our services from the EU/EEA, UK, or US, your data may be transferred to and processed in India.

 

5.1 Transfers to/from the EU/EEA

Where we transfer personal data from the EEA to India or any other country not recognised as providing adequate protection, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission, or other mechanisms permitted under GDPR Chapter V.

5.2 Transfers within India

Data transfers within India comply with the Digital Personal Data Protection Act, 2023, and applicable government notifications regarding cross-border data flows.

5.3 US Transfers

Data from US users is processed primarily in India. We ensure contractual and technical safeguards are in place commensurate with US privacy standards.

 

6. Cookies & Tracking Technologies

Our Platform uses cookies and similar tracking technologies to enhance your experience and gather analytics. The categories of cookies we use are:

 

  • Strictly Necessary Cookies — essential for the Platform to function. Cannot be disabled.
  • Analytics Cookies — help us understand how visitors interact with the Platform (e.g., Google Analytics). These are only set with your consent.
  • Functional Cookies — remember your preferences and settings.
  • Marketing Cookies — used to deliver relevant communications. Only set with explicit consent.

 

You may manage your cookie preferences through our cookie consent banner or your browser settings. Disabling certain cookies may affect Platform functionality.

 

7. Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected, unless a longer retention period is required by law.

 

  • Client project data: retained for 7 years from project completion for legal and audit purposes
  • Enquiry and contact data: retained for 2 years from last interaction
  • Marketing data: until consent is withdrawn or opt-out is exercised
  • Server logs and technical data: up to 12 months
  • Financial and invoice records: 8 years (as required under Indian accounting law)

 

On expiry of the relevant retention period, data is securely deleted or anonymised.

 

8. Your Rights — EU/EEA Residents (GDPR)

If you are located in the European Economic Area, you have the following rights under GDPR:

 

  • Right of Access — request a copy of the personal data we hold about you (Article 15)
  • Right to Rectification — request correction of inaccurate or incomplete data (Article 16)
  • Right to Erasure — request deletion of your data (‘right to be forgotten’) where applicable (Article 17)
  • Right to Restriction of Processing — request that we limit how we use your data (Article 18)
  • Right to Data Portability — receive your data in a structured, machine-readable format (Article 20)
  • Right to Object — object to processing based on legitimate interests or for direct marketing (Article 21)
  • Right to Withdraw Consent — where processing is based on consent, you may withdraw at any time without affecting prior lawfulness
  • Right to Lodge a Complaint — you may lodge a complaint with your local data protection authority (e.g., the relevant EU Member State supervisory authority)

 

To exercise any of these rights, please contact us at info@conveyuall.com with the subject line ‘GDPR Rights Request’. We will respond within 30 days.

 

EU Representative

As our main establishment is in India, EU/EEA data subjects may contact us directly at info@conveyuall.com. If required by applicable law, we will appoint an EU representative and update this Policy accordingly.



9. Your Rights — Indian Residents (DPDP Act 2023)

Under India’s Digital Personal Data Protection Act, 2023, you have the following rights as a Data Principal:

 

  • Right to Access Information — request a summary of personal data processed and the processing activities undertaken
  • Right to Correction and Erasure — request correction of inaccurate data or erasure where data is no longer necessary
  • Right to Grievance Redressal — raise grievances with us; unresolved complaints may be escalated to the Data Protection Board of India
  • Right to Nominate — nominate another individual to exercise your rights in the event of death or incapacity

 

Grievance Officer (IT Act 2000 / DPDP Act 2023):

Name: Grievance Officer, Convey U All

Email: info@conveyuall.com (subject line: ‘India Privacy Grievance’)

Response time: within 72 hours for acknowledgment; resolution within 30 days

 

10. Your Rights — California Residents (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

 

  • Right to Know — request disclosure of the categories and specific pieces of personal information we have collected, the sources, purposes, and third parties with whom it is shared
  • Right to Delete — request deletion of personal information we have collected, subject to certain exceptions
  • Right to Correct — request correction of inaccurate personal information
  • Right to Opt Out of Sale/Sharing — we do not sell or share personal information for cross-context behavioural advertising
  • Right to Limit Use of Sensitive Personal Information — we do not use sensitive personal information for purposes beyond those permitted under CPRA
  • Right to Non-Discrimination — we will not discriminate against you for exercising your privacy rights

 

To submit a verifiable consumer request, email info@conveyuall.com with subject ‘CCPA/CPRA Rights Request’. You may also designate an authorised agent. We will respond within 45 days, extendable by a further 45 days where necessary.

 

11. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These measures include:

 

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Access controls and role-based permissions
  • Regular security assessments and vulnerability testing
  • Staff training on data protection and information security
  • Incident response procedures

 

No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a personal data breach, we will notify affected individuals and relevant authorities as required by applicable law.

 

12. Third-Party Links

Our Platform may contain links to third-party websites or services. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party services you access.

 

13. Marketing Communications

We will only send you marketing communications where you have opted in or where we have a legitimate interest in doing so (e.g., existing client updates). You may opt out at any time by:

 

  • Clicking the ‘unsubscribe’ link in any marketing email
  • Emailing info@conveyuall.com with the subject ‘Unsubscribe’

 

Opting out of marketing does not affect communications necessary for service delivery or legal purposes.

 

14. Children’s Privacy

Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If a parent or guardian believes their child has provided us with personal data, please contact us immediately and we will delete it.

 

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or services. We will notify you of material changes by email or prominent notice on our Platform. The ‘Last Reviewed’ date at the top of this Policy indicates when it was last updated. Continued use of our Platform after changes take effect constitutes acceptance of the revised Policy.

 

16. Contact & Complaints

For any privacy-related questions, requests, or complaints, please contact:

 

MG Ray Infotech (operating as Convey U All)

Address: 4th Floor, Bhamashah Techno Hub, Sansthan Path, Malviya Nagar, Jaipur, Rajasthan – 302017, India

Email: info@conveyuall.com

Phone: +91-9610964688

 

EU/EEA residents may also contact the supervisory authority in their country of residence. A list of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/board/members_en

 

Indian residents may escalate unresolved grievances to the Data Protection Board of India (once operationalised under the DPDP Act 2023).

This document constitutes the Privacy Policy of Convey U All and should be read in conjunction with the Terms and Conditions. It is intended as a good-faith compliance document and does not constitute legal advice. You are encouraged to seek independent legal counsel for jurisdiction-specific guidance.