Privacy Policy
Overview
This Privacy Policy ("Policy") describes how Huzzler ("Company," "we," "our," or "us") collects, uses, stores, shares, and protects your personal data when you access or use our website, mobile application, and related services (collectively, the "Platform"). We are committed to protecting your privacy and handling your information in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and all applicable Indian data protection laws. Zuntra Digital Private Limited acts as the Data Fiduciary under the DPDP Act, and any third-party service providers engaged by us act as Data Processors under written contracts ensuring equivalent protection. This Policy forms part of, and shall be read with, the Huzzler Terms of Service (effective 31 October 2025). By using the Platform, you consent to the practices described in this Policy.
Introduction
- a)This Policy describes how we collect, use, store, share, and protect your personal data when you access or use our website, mobile application, and related services (the "Platform").
- b)We are committed to handling your information in compliance with the DPDP Act, 2023, the IT Act, 2000, and all applicable Indian data protection laws.
- c)Zuntra Digital Private Limited acts as the Data Fiduciary under the DPDP Act; third-party service providers we engage act as Data Processors under written contracts ensuring equivalent protection.
- d)This Policy forms part of, and should be read with, the Huzzler Terms of Service (effective 31 October 2025).
- e)By using the Platform, you consent to the practices described in this Policy.
Scope & Applicability
This Policy applies to:
- a)All users of the Platform, including Freelancers, Clients, and visitors.
- b)All personal data collected, processed, or stored by the Company in India.
- c)Any personal data transferred or accessed from outside India, as permitted by law.
- d)This Policy does not apply to third-party websites or services linked from our Platform — we encourage you to review their privacy policies independently.
Data We Collect
We may collect the following categories of data:
- 1.Full name, contact number, email address.
- 2.Age/date of birth (for eligibility verification).
- 3.Address, city, state, and country.
- 4.Profile photo or avatar (optional).
- 1.Login credentials.
- 2.Freelancer skills, portfolio, and service details.
- 3.Client project descriptions.
- 4.Communication logs between Freelancers and Clients.
- 1.IP address, browser type, device ID, and operating system.
- 2.Access time, pages visited, and referral links.
- 3.Cookies, analytics, and tracking technologies.
- 1.Government identification (e.g. PAN, Aadhaar) only for verification purposes.
We do not collect biometric or financial data, since the Platform does not process payments.
We receive your information when you provide it to us while using our Services, completing a transaction via our Services, or otherwise using our Services, including:
- i.Account creation: we may collect information when you create an account, such as name, email/business address, password, location, and photograph.
- ii.Verification of identity: we may use third parties to verify your identity, comply with "Know Your Customer" (KYC) and Anti-Money Laundering (AML) requirements, and/or prevent fraud. These third parties may collect your name, birthdate, address and government identification pursuant to the terms of their privacy policies. If you choose to use our Services, you consent to the processing of your data by these third parties.
- iii.Your communications with us: we may collect personal information, such as email address, phone number, or mailing address (home or work) when you request information about our Services, request customer or technical support, apply for or post an opportunity, or otherwise communicate with us.
- iv.Surveys & interviews: we may contact you to voluntarily participate in surveys or user interviews. If you decide to participate, you may be asked to provide certain information which may include personal information.
- v.Imported external network information: we may collect information that you voluntarily and optionally provide about your existing professional network from other internet platforms, through product features to import existing contacts and connections. This information is used to expedite migrating your existing professional relationships to our platform.
- vi.User content: we and others who use our Services may collect personal information that you submit or make publicly available through the Platform. Any information you provide using the public sharing features of the Services ("User Content") will be considered "public," unless otherwise required by applicable law, and is not subject to the privacy protections referenced herein.
- vii.Live events: we may collect personal information from individuals when we host in-person events.
- viii.Business development and strategic partnerships: we may collect personal information from individuals and third parties to assess and pursue potential business opportunities.
We automatically collect data about you when you visit our website and use our Services. The types of data we automatically collect include:
- 1.Device and network information: we may collect certain information automatically when you use our Services, such as your Internet protocol (IP) address, user settings, cookie identifiers, browser or device information, and location information (including approximate location derived from IP address).
- 2.Usage information: we may also automatically collect information regarding your use of our Services, such as pages that you visit before, during and after using our Services, information about the links you click, the types of content you interact with, the frequency and duration of your activities, and other information about how you use our Services. We may also collect information that other people provide about you when they use our Services, including information about you when they tag you and/or provide referrals and/or feedback regarding your work performance and project results and/or other interactions between you and a Client or Freelancer.
- 3.Cookies, pixel tags/web beacons, and other technologies: we, as well as third parties that provide content, advertising, or other functionality on our Services, may use cookies, pixel tags, local storage, and other technologies ("Technologies") to automatically collect information through your use of our Services. Our uses of these Technologies fall into the following general categories: (i) Operationally necessary — Technologies that allow you access to our Services, applications, and tools required to identify irregular website behavior, prevent fraudulent activity, and improve security, or that allow you to make use of our functionality; (ii) Performance-related — used to assess the performance of our Services as part of our analytics practices, including tracking website activity and recordings of interactions; (iii) Functionality-related — used to offer enhanced functionality, such as identifying you when you sign in or keeping track of your specified preferences, interests, or past items viewed; and (iv) Advertising- or targeting-related — first-party or third-party Technologies used to deliver content, including ads relevant to your interests, on our Services or on third-party websites.
How We Collect Data
We collect data through:
- a)Direct input from users during registration, profile setup, or communication.
- b)Automated collection via cookies and analytics tools.
- c)Information shared voluntarily through emails, forms, or surveys.
Purpose of Data Processing
We process your personal data for the following lawful purposes:
| Purpose | Legal Basis under DPDP Act |
|---|---|
| Account creation and management | Performance of contract / User consent |
| Displaying freelancer profiles and projects | User consent |
| Matching clients and freelancers | Legitimate use for service delivery |
| Communication and notifications | Consent / legitimate business interest |
| Security, fraud prevention, and compliance | Legal obligation |
| Data analytics and platform improvement | Legitimate business interest |
| Responding to legal or government requests | Legal obligation |
Consent & User Rights
By using the Platform and providing your personal data, you consent to:
- •The collection and processing of your information.
- •Communication via email, SMS, or in-app notifications.
- •Data transfers and disclosures as described in this Policy.
You have the right to:
- •Access your personal data.
- •Correct or update inaccurate data.
- •Withdraw consent.
- •Request erasure of your data.
- •Nominate another person to exercise your rights in case of death or incapacity.
Requests may be sent to us at support@huzzler.io.
Storage & Retention
- a)All personal data is stored securely on servers located within India, unless otherwise specified for backup or analytics.
- b)We retain user data only for as long as necessary to fulfil the purposes described in this Policy or as required by law — 180 days for safety purposes under India's IT Rules, 2021.
- c)Upon deletion of an account, we anonymise or securely erase personal data unless retention is legally mandated.
Data Security
We implement reasonable security practices and procedures as required under Rule 8 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including:
- i.Encryption of stored and transmitted data.
- ii.Secure access control and authentication.
- iii.Regular vulnerability assessments.
- iv.Limited employee access on a need-to-know basis.
While we take all reasonable steps to protect your data, no electronic transmission or storage system can guarantee absolute security.
Cross-Border Data Transfers
- a)Personal data may be transferred to or processed in other jurisdictions only where compliant with Section 16 of the DPDP Act, 2023.
- b)Any cross-border transfer will ensure the receiving country or entity provides adequate data protection safeguards.
- c)By using the Platform, you consent to such international transfers as necessary for service provision (e.g., cloud hosting, analytics).
Force Majeure & Cyber Incidents
The Company shall not be held liable for any delay, failure, loss, or disclosure of personal data resulting from events beyond its reasonable control, including but not limited to:
- i.Natural disasters (fire, flood, earthquake, storm, or other acts of God).
- ii.War, terrorism, sabotage, civil unrest, or political disturbances.
- iii.Pandemic, epidemic, or governmental restrictions.
- iv.Power outages, network failures, or telecommunications disruptions.
- v.Widespread ransomware attacks, zero-day exploits, denial-of-service (DoS) incidents, or similar malicious cyber intrusions affecting the Company's or its vendors' infrastructure.
- vi.Cloud service provider outages or third-party data centre failures.
- vii.Any act, omission, or circumstance which is not reasonably foreseeable or preventable despite implementation of industry-standard security measures.
Zuntra Digital Private Limited ("the Company") has always maintained and will continue to maintain the highest standards of information security, privacy protection, and data-governance compliance. The Company operates in full adherence to Section 43A of the Information Technology Act, 2000, Rule 8 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the DPDP Act, 2023. All internal controls, policies, and infrastructure are designed and periodically reviewed in accordance with ISO/IEC 27001 or equivalent global standards to ensure confidentiality, integrity, and availability of information assets.
In the event of a ransomware or similar encryption-based cyberattack, the Company will immediately isolate affected systems, engage certified cybersecurity specialists, and notify the Indian Computer Emergency Response Team (CERT-In) as mandated under the Cyber Security Directions, 2022 (issued under s.70B of the IT Act) within six (6) hours of detection. The Company will also notify the Data Protection Board of India and affected Users under Section 8(6) and Section 33 of the DPDP Act, 2023, disclosing the nature of the breach, likely impact, and remedial measures taken. No ransom or unlawful demand will be paid by the Company unless legally mandated or approved by competent authorities.
The Company will make commercially reasonable efforts to restore systems, recover encrypted data (where possible), and prevent recurrence through patching, system hardening, and security upgrades. Users will be informed about measures taken and any required user-side actions (e.g., password resets).
While the Company will exercise due diligence, it shall not be liable for any consequential, incidental, or indirect loss of data, goodwill, or reputation caused by such force majeure or ransomware incidents, provided that: (i) it has complied with its legal obligations of prompt notification and mitigation under the DPDP Act and IT Act; and (ii) the event could not reasonably have been prevented by available security technologies or practices.
A post-incident forensic report will be documented within 30 days of containment, recording root cause, remedial steps, and timelines. Such reports will be preserved as required by Rule 7 of the CERT-In Directions, 2022, and may be shared with regulators upon request.
Data Sharing & Disclosure
We may share your personal data with:
Third-party vendors providing IT, hosting, analytics, communication, or verification services — under strict confidentiality obligations.
When required by law, regulation, or valid legal process.
In case of merger, acquisition, or asset sale, user data may be transferred to the new entity, subject to this Policy.
Your personal data is never sold or rented to advertisers or third parties.
Cookies & Tracking Technologies
We use cookies and similar technologies to:
- •Enable core platform functions.
- •Analyse site traffic and user behaviour.
- •Remember preferences and login sessions.
You can manage cookie preferences through your browser settings, but disabling cookies may limit certain Platform features.
Third-Party Links & Integrations
- a)The Platform may contain links to third-party websites or plugins (e.g., LinkedIn, company websites, or communication tools).
- b)We are not responsible for the privacy practices or content of those external sites.
Grievance Redressal & DPO
- a)Zuntra Digital Private Limited has appointed a Data Protection Officer (DPO) under Section 10(5) of the DPDP Act, 2023, read with Rule 3(1)(b) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- b)The DPO is the single point of contact for user grievances, privacy-related inquiries, and communications from the Data Protection Board of India or other lawful authorities.
- c)Name: Varadharaja Perumal Janakiraman
- d)Email: grievance@huzzler.io
- e)Address: Zuntra Digital Private Limited, Developed Plot Estate, Plot No 61, Perungudi, Kanchipuram, Saidapet, Tamil Nadu, India, 600096
- f)Complaints will be acknowledged within 24 hours and resolved within 15 business days.
Updates to This Policy
- a)We may amend this Policy periodically to reflect legal or technological changes.
- b)Any updates will be posted on this page with a revised "Last Updated" date.
- c)Continued use of the Platform after such changes constitutes your acceptance of the updated Policy.
Governing Law & Jurisdiction
- a)This Policy is governed by and construed in accordance with the laws of India.
- b)Disputes arising under this Policy are subject to the exclusive jurisdiction of the courts of Chennai, Tamil Nadu, India.
Account Deletion
Users may request deletion of their account at any time as follows:
Freelancers can delete their account directly through the Account Settings section within the app.
Clients may request account deletion by raising a support ticket through the Help Center available within the app.
Upon receiving a verified deletion request, we will delete or anonymise personal data in accordance with applicable laws, unless retention is legally required.
This Privacy Policy is a legally binding part of your agreement with Huzzler. Please read it carefully before using the Platform.