Privacy Policy
Website legal policy
AVE Enterprises, an Indian partnership firm trading as Opvia
Effective date: 01 September 2026
1. About this policy, Opvia, and how to read it
● the websites at https://opvia.in, https://www.opvia.in, and https://opviahq.com, and any page that links to this Policy (collectively, the “Website”);
● enquiries, proposals, sales discussions, and client relationships;
● recruitment, candidate sourcing, screening, assessment, matching, and placement activities;
● HR, payroll, compliance, office, device, employee-engagement, and operational support that we provide where applicable; and
● Opvia’s own relationships with its employees, contractors, vendors, advisers, and other business partners.
How Opvia decides which law applies, and why this matters?
Opvia is an Indian partnership, operates from India, and employs its own staff in India. Opvia’s employment relationships with its India-based employees are governed by Indian law, principally the Digital Personal Data Protection Act, 2023 (“DPDPA”) for data protection, together with applicable Indian labour and employment legislation. That does not change because a client instructing Opvia is based in the United Kingdom, the United States, or elsewhere: a client’s location does not import that client’s country’s employment law into Opvia’s relationship with its own staff, and this Policy does not claim otherwise. Separately, and independently of employment law, a given piece of processing may also engage another country’s data-protection law where the processing itself has a real connection to that country, for example, because the personal information concerns an identifiable person located in the UK or the EEA, or because Opvia is offering services to, or monitoring the behaviour of, individuals there. Where that is true, the relevant sections below say so specifically (see sections 10 and 13) rather than assuming every law of every country where a client or visitor happens to be applied across the board. Cookie and similar tracking technology on the Website is a separate question again, addressed in the Cookie Policy, and is assessed on its own terms (who the visitor is and what the technology does), not by reference to employment law at all. Opvia’s registered address is 12th Floor, 8 Abanindra Nath Thakur Sarani, Kolkata, West Bengal 700017, India. Contact details for privacy requests appear in section 18. This Policy is a general public notice. A contract, candidate notice, employee notice, client privacy notice, or data-processing agreement may provide more specific information for a particular relationship. If a specific notice conflicts with this Policy, the more specific notice applies to that processing to the extent permitted by law.
2. Who this Policy covers
● visitors to the Website;
● people who enquire about, evaluate, buy, administer, or receive our services, including representatives of prospective and existing clients;
● candidates and other talent whom we source, contact, assess, introduce, support, or place;
● Opvia’s own employees and contractors, whose employment relationship with Opvia is governed by Indian law as described in section 1, to the extent a separate workforce privacy notice does not apply;
● representatives of vendors, advisers, landlords, technology providers, and other business partners; and
● other people whose information is provided to us in connection with these activities.
It does not govern a client’s independent handling of personal information after the client receives it (including the client’s own compliance with its own local employment or data-protection law for its own operations), nor third-party websites or services that have their own privacy notices.
3. Our role in processing personal information
4. Information we collect directly
● Identity and contact details: name, title, employer, business contact details, postal address, signature, and preferred means of contact.
● Enquiry and relationship details: the content of forms, emails, calls, meeting notes, preferences, requests, feedback, support history, and records of our interactions.
● Verification details: identity-verification records, authorisations, and information needed to prevent fraud or control access where relevant. The Website does not currently provide user accounts.
● Commercial and transaction details: proposals, contracts, purchase orders, billing contacts, invoices, payment status, tax information, and limited payment-related details. The Website does not currently accept online payment. Bank details or payment information used during client onboarding may be processed by banks or payment providers rather than stored directly by Opvia.
● Event and marketing details: registrations, attendance, communication preferences, and consent or opt-out records.
● Technical and cookie information collected through the Website, described in section 7 and, in full technical detail, in the Cookie Policy.
● Any other information you choose to provide, subject to applicable law.
Please do not provide sensitive or unnecessary personal information through a general Website form
5. Candidate and talent information
● contact details, location, languages, work authorisation, notice period, availability, and compensation expectations;
● CV/resume data, education, qualifications, employment history, skills, portfolios, work samples, professional profiles, and references;
● role preferences, interview availability, application history, and communications with Opvia or a client;
● screening, interview, test, assessment, scoring, recruiter notes, and client feedback;
● information reasonably needed for identity, right-to-work, education, employment, reference, criminal-record, sanctions, or other background checks, but only where lawful, proportionate, and appropriately disclosed;
● onboarding, employment or engagement, payroll, benefits, attendance, leave, performance, device, access, workplace, and compliance information, where Opvia employs, engages, or supports you, this information and Opvia’s obligations toward you as employer are governed by Indian law; and
● demographic, disability, health, biometric, financial, government-identifier, or other sensitive information, collected only where relevant to employment, workplace access, payroll, benefits, health and safety, or legal obligations under Indian law, and covered by appropriate safeguards.
If you are a candidate located in the UK or the EEA. Where a specific candidate is, personally, located in the UK or the EEA at the relevant time (rather than simply being introduced to a UK- or EU-based client), UK GDPR or EU GDPR may separately apply to Opvia’s processing of that candidate’s data because the processing concerns an identifiable person there, not because the client is UK- or EU-based. In that specific case, any health, disability, biometric, or similar special-category data described above is processed only where one of the following applies, and the specific one relied on will be confirmed to that candidate directly: it is necessary for carrying out obligations under employment, social security, or social protection law (Article 9(2)(b)); the candidate has given explicit consent (Article 9(2)(a)); it is necessary to assess working capacity on medical or occupational-health grounds (Article 9(2)(h)); or another Article 9(2) condition applies and is identified before collection. This paragraph does not apply, and UK/EU GDPR is not engaged, merely because the client receiving the candidate’s profile is based in the UK or the EU while the candidate themselves is in India, that scenario remains governed by Indian law as the candidate’s data protection framework. We may obtain candidate information directly, from referrals, recruitment partners, job boards, professional networking sites, public professional profiles, former employers or references, background-check providers, clients, and other lawful sources. If you provide information about a referee or another person, you should be authorised to do so.
6. Client and business information
● company and authorised-representative details;
● hiring plans, job descriptions, role requirements, budgets, team structures, location and office requirements, preferred skills, and delivery timelines;
● interview schedules, interview notes, hiring decisions, candidate feedback, and service performance information;
● information needed for proposals, onboarding, contracts, billing, tax, compliance, audits, due diligence, and account management;
● information concerning client systems, security requirements, device requirements, work processes, and authorised users; and
● communications involving candidates, team members, Opvia personnel, and client stakeholders.
Where a client representative is, personally, located in the UK or EEA, the data-protection points in section 10 (legal bases) and section 13 (international transfers) apply to Opvia’s processing of that representative’s own business contact details in the same targeted way as for candidates, because of where that individual is, not because of where their employer is headquartered. A client that gives Opvia personal information about its own staff or candidates must have the right and a lawful basis to do so under whatever law applies to the client’s own operations, and must give any notices its own law requires to the individuals concerned; that is the client’s responsibility, not something this Policy extends Opvia’s obligations to cover.
7. Information collected automatically, and cookies
● IP address, approximate location derived from IP, browser type, operating system, device type, language, and device identifiers;
● dates and times, pages requested, referring pages, security events, error records, and information used to diagnose or prevent misuse; and
● cookie, tag-management, and local-storage information used for Website operation, to remember a privacy choice, or, where you consent, for analytics.
This is assessed separately from employment law, and separately from the client-location points above. Cookie and tracking-technology consent requirements depend on where the visitor to the Website is and what the specific technology does, not on where Opvia’s clients or employees are based. The full, current, and accurate list of what actually runs on the Website, and the consent mechanism that gates it, is set out in the Cookie Policy, which as of the Last Updated date discloses Google Tag Manager and a website-builder analytics script. See the Cookie Policy for the current technology register; this Policy does not repeat it so that there is only one place it needs to be kept accurate.
8. Information from third parties
9. How and why we use personal information
● operate, secure, troubleshoot, and improve the Website;
● respond to enquiries, prepare proposals, verify representatives, and manage client and partner relationships;
● understand roles and team requirements; source, contact, screen, assess, shortlist, match, and introduce candidates; arrange interviews; collect feedback; and support offers and onboarding;
● maintain candidate and talent records for current and potentially suitable future opportunities, subject to applicable notice, choice, and retention requirements;
● deliver agreed recruitment, HR, payroll, compliance, office, infrastructure, IT/device, engagement, and other operational support, provided under Indian law as Opvia’s own employment framework;
● administer Opvia’s own employment or contractor relationships, payroll, benefits, leave, performance, security, equipment, access, and legal obligations, under Indian law;
● manage contracts, invoices, payments, taxes, accounting, audits, insurance, and corporate records under Indian law;
● communicate service, security, policy, contractual, or operational updates;
● send relevant B2B marketing, insights, invitations, and service information where permitted, and maintain suppression lists for people who opt out;
● with your consent, where cookie-based, measure Website and campaign performance, understand demand, conduct aggregated reporting, and improve services;
● protect people, systems, premises, devices, confidential information, and intellectual property; prevent or investigate fraud, misuse, and security incidents;
● establish, exercise, or defend legal claims; enforce agreements; respond to lawful requests; and comply with legal, regulatory, tax, labour, employment, and reporting duties under Indian law, or under another country’s law only where section 5, 6, 10, or 13 specifically says that law applies to the processing in question; and
● support a merger, financing, reorganisation, sale, or other corporate transaction, subject to appropriate confidentiality and legal safeguards.
We will not use personal information for a materially incompatible purpose without an appropriate legal basis and, where required, further notice or consent
10. Legal bases for processing, and which law supplies them
● For Opvia’s own employment relationships with its India-based staff, and for Opvia’s general business operations as an Indian entity: Indian law applies. Under the Digital Personal Data Protection Act, 2023, Opvia relies on consent, or another permitted “legitimate use” recognised under that Act and rules made under it, together with applicable Indian labour and employment legislation for the employment relationship itself.
● For a candidate or client contact who is personally located in the UK or EEA at the time of the relevant processing: UK GDPR or EU GDPR supplies the legal basis for that specific processing, which may include contract (steps taken at that person’s request, or performance of a contract with them), legitimate interests (matching talent to roles, managing the relationship, security, fraud prevention, provided those interests are not overridden by the individual’s rights), consent (for non-essential cookies or particular marketing, withdrawable at any time without affecting prior lawful processing), or legal obligation.
● Vital interests or other lawful grounds, under whichever law applies per the above, cover cases needed to protect someone’s life or safety, employment-related obligations, legal claims, or substantial public interest.
This Policy does not treat UK or EU GDPR as a general framework for Opvia’s business merely because Opvia has UK or EU clients; it applies UK/EU GDPR specifically to the processing of data belonging to individuals actually located there, and Indian law to everything else, including Opvia’s own workforce.
11. Recruitment, matching, assessments, and hiring decisions
Opvia does not use artificial-intelligence screening, automated scoring, or solely automated decision-making to make hiring or engagement decisions. Screening and matching are performed by people using role requirements, interviews, work samples, references, and other lawful information. Clients remain responsible for their own interviews, lawful decision-making under their own applicable law, and final hiring or engagement decisions
12. How we share information
● prospective and existing clients, including authorised hiring managers and interviewers;
● candidates and team members where needed to arrange interviews, onboarding, work, or service delivery;
● vendors that support hosting, cybersecurity, communications, CRM, recruitment, assessments, screening, payroll, HR, benefits, accounting, payments, document signing, office operations, IT/device management, analytics, or marketing;
● professional advisers, auditors, banks, insurers, and financing parties;
● group entities and delivery partners;
● Indian courts, regulators, and law-enforcement or tax/employment authorities, and, where a specific individual’s data is subject to a foreign law under sections 5, 6, or 10, the equivalent authorities in that jurisdiction;
● parties necessary to protect rights, safety, security, property, confidential information, or the integrity of services; and
● potential buyers, investors, lenders, or transaction advisers in connection with a proposed or completed corporate transaction.
We do not sell personal information for money. Opvia does not sell personal information, share it for crosscontext behavioural advertising, or process it for targeted advertising. Service providers are expected to process information for agreed purposes and under appropriate confidentiality, security, and data-protection terms.
13. International data transfers
14. Security
15. Retention
● enquiry and Website-contact records are generally kept for up to 24 months from the last interaction;
● unsuccessful candidate applications and talent-pool records are generally kept for up to 24 months from the last contact, unless you ask us to delete them sooner, or a client engagement requires a longer period;
● client and vendor contract, billing, and tax records are kept for the period required under Indian tax, companies, and labour recordkeeping law (currently up to 8 years for most financial records; and
● Opvia’s own employment and payroll records for its India-based team members are kept for the period required under applicable Indian employment and social-security law after employment ends.
When information is no longer required, we delete, anonymise, or securely isolate it in accordance with our retention procedures.
16. Your privacy rights
● receive information about processing and obtain access to personal information;
● correct or complete inaccurate information;
● request deletion or erasure;
● withdraw consent;
● object to or restrict certain processing;
● receive portable data in an applicable format;
● opt out of certain marketing;
● ask for information about recipients or international-transfer safeguards;
● request review of a decision based solely on automated processing, where such a right applies;
● nominate another person, or exercise grievance and complaint rights, under the Digital Personal Data Protection Act, 2023, if Indian law applies to your data; and
● complain to the competent authority for the law that applies to you (for example, India’s Data Protection Board once operational, for data governed by Indian law; or the UK Information Commissioner’s Office or an EU supervisory authority, only for data specifically governed by UK or EU GDPR under section 10).
Rights are not absolute. We may need to verify identity and authority, and may retain or continue processing information where the law that applies to you permits or requires. We will respond within the period required by that law. If Opvia processes information only for a client, we may refer the request to that client. To exercise a right, email with enough detail to identify the relevant relationship and request. Do not send unnecessary identity documents by ordinary email; we will explain any verification needed.
17. Marketing choices
You can stop marketing emails by using the unsubscribe link or contacting. You may still receive nonmarketing communications concerning enquiries, contracts, security, services, candidates, or legal matters.
We may keep minimal suppression information so that we honour an opt-out. Cookie choices are managed
using the consent banner and technology register described in the Cookie Policy, which is the single source of
truth for cookie-related matters, this Policy does not separately restate it. Withdrawing consent does not
affect processing that occurred before withdrawal.
18. Third-party websites, children, and contact
The Website may link to third-party sites or services. Opvia does not control their privacy practices, content,
or security, and a link is not an endorsement. Review their notices before providing information.
The Website and Opvia’s business services are not directed to children. We do not knowingly solicit personal
information through the Website from anyone under 18. If you believe a child has provided information,
contact us so we can assess and take appropriate action. Employment-related processing for lawful young
workers, if any, is governed by Indian law and covered by a specific notice and safeguards.
Questions, requests, or complaints may be sent to:
Email: contactopvia@gmail.com
Phone: +91 79800 74354
Postal address: 12th Floor, 8 Abanindra Nath Thakur Sarani, Kolkata, West Bengal 700017, India
19. Changes and disputes
We may update this Policy to reflect changes in our services, technology, or applicable law. We will post the
revised Policy with a new “Last updated” date and provide additional notice where required. Material
changes will not be applied retroactively where prohibited.
Privacy questions and disputes are subject to the law that actually applies to the relevant processing and
individual, as determined under section 10, not to every country’s law by default. A complaint or proceeding
may be brought before any regulator, court, tribunal, or other body that has jurisdiction under that applicable
law. Nothing in this Policy selects an exclusive governing law or forum beyond what is stated in section 10, or
limits a person’s non-waivable rights.