Privacy Policy
How Nadi Oracle handles your personal data under the Digital Personal Data Protection Act, 2023.
Version privacy-2026.06-v1 · Effective June 2026
1. Who we are (Data Fiduciary)
This Privacy Policy explains how Nadi Oracle / Nadi AI, operated by Pratiiksha Raj (Sole Proprietor), collects, uses, stores, shares and protects your personal data when you use our KP (Krishnamurti Paddhati) astrology service at nadioracle.com and the portal at nadiai.nadioracle.com. We are the Data Fiduciary for your personal data under the Digital Personal Data Protection Act, 2023 (DPDP), and we apply the safeguards required by the Information Technology Act, 2000 §43A and the SPDI Rules, 2011 to your sensitive data.
Contact: Pratiiksha Raj, #1108 Riverdale Suites, Thite Nagar, Kharadi, Pune 411014, India · +91 (0) 738 739 6176 · pratiiksha@nadioracle.com. It is not GST-registered (GST is not applicable); invoices are issued against PAN CATPP2528R and no GSTIN.
2. What we collect & why
We collect only what the service needs:
- Identity & contact — your name, email, and phone — to create your account, communicate with you, and deliver your consultation.
- Birth details — date, time, and place of birth — which are required to cast your KP chart. We treat these as sensitive and apply our strictest safeguards.
- Your questions and consultation content — the matters you raise and the advice recorded — to deliver and document your reading.
- Payment records — invoices, receipts, and payment proofs — for our statutory books (no card numbers are stored by us).
- Consent records — proof of the consents you give, with the exact wording and timestamp, as the lawful-basis evidence the law requires.
2a. What we do NOT collect
We do not collect biometric data (no palm-prints, fingerprints, or facial data), and we do not require your corporate or detailed financial structures.
3. Our lawful basis — your consent (DPDP §6)
Our lawful basis for processing your personal data is your consent, given by a clear affirmative action (an un-pre-ticked tick-box) at signup, at your first portal login, and at the relevant capture points. The exact wording you agree to is recorded and version-stamped. You can withdraw your consent at any time — it is as easy to withdraw as it was to give. Where finance or tax records must be kept by law, that retention rests on the applicable statutory obligation rather than your consent.
4. Your rights as a Data Principal (DPDP §11–14)
Under the DPDP Act you have the following rights, which you may exercise by contacting our grievance officer (below) or using the in-portal request control. We respond within the timelines required by law.
- Access and portability — obtain a summary of your data and how it is processed (§11).
- Correction — correct, complete, or update inaccurate or incomplete data (§12).
- Erasure — ask us to delete your personal data (§12). Note: finance and tax records that the law requires us to keep are retained, and pseudonymized where possible, rather than deleted.
- Nominate — name another person to exercise your rights if you die or become incapacitated (§14). Naming a nominee is optional, gives them no access now, and you can change or remove them at any time; they never log in as you.
- Withdraw consent — withdraw your consent at any time, as easily as you gave it (§6(4)); we then stop processing for that purpose going forward.
- Grievance redressal — raise a grievance about how your data is handled (§13).
5. How long we keep it (retention)
We keep your personal data only as long as needed for the purpose, then delete or de-identify it. The exact windows are being finalised with our lawyer. As a current draft:
- Birth data and charts — kept while your account is active and for a period afterwards, then deleted or anonymized.
- Consultation records — kept for a defined period.
- Financial records — kept for approximately 8 years to meet statutory (Income-tax Act) obligations, which override erasure; then deleted or pseudonymized.
- Consent proof — retained as long as needed to evidence lawful basis.
6. Who we share it with — sub-processors
We do not sell your data and do not share it with advertisers or data brokers. We use a small number of trusted service providers ("processors") strictly on our instructions, under data-processing terms. The complete list of service providers, with each provider's role and location, is maintained in our Sub-Processor Register and disclosed on request.
- Google / Firebase — secure hosting, database, and storage; your data is held in India (Mumbai region).
- Google Workspace — to send you service emails (e.g. OTP, "report ready").
- Automated drafting assistance — we may use automated tools that process only non-identifying astrological data (such as house numbers, sub-lord codes, and the verdict) to help prepare a first draft of report wording. Your name, contact details, date/time/place of birth, and email are never sent. Your report is authored and reviewed by your practitioner, Pratiiksha Raj — the automated tool never writes your final report.
7. Cross-border processing (DPDP §16)
Some of these providers process data on servers outside India (for example, email delivery and the report-drafting AI). DPDP §16 permits transfers outside India except to countries the Government of India restricts; we do not transfer your data to any such restricted country. Where data leaves India it is minimised and protected as described here. Your birth data and core chart/consultation data are held in India (the asia-south1 / Mumbai region of our cloud infrastructure).
8. Where your data lives & how we protect it
Your personal data — including your birth date, time, and place, and your KP charts — is stored in India, in our Firestore (Firebase) database hosted in the asia-south1 (Mumbai) region. We follow a documented security programme: encryption in transit and at rest, strict access controls (only you can see your data; only your practitioner can act on it), server-side verification of every privileged request, India data-residency, and append-only audit logging of sensitive actions. Our full Reasonable Security Practices policy (IT Act §43A) backs this summary.
9. If something goes wrong — breach (DPDP §8(6))
In the unlikely event of a personal-data breach that affects you, we will inform the Data Protection Board of India and you, in the manner the law requires, and tell you what happened and what to do.
10. Grievance officer & contact (DPDP §13)
If you have any question or complaint about your data, or to exercise any of the rights above, contact our grievance officer: Pratiiksha Raj — pratiiksha@nadioracle.com — +91 (0) 738 739 6176.
This report provides KP astrological analysis for guidance and reflection only. It is high-level predictive analysis, not a guarantee or a substitute for professional medical, legal, financial, or psychological advice. All outcomes depend on many factors beyond any chart. Nadi Oracle and its practitioners accept no liability for any decision or action taken based on this content. Always consult a qualified professional before making important decisions. © Nadi Oracle.
NADI ORACLE · Engineering Logic · Vedic Rigor