Privacy Policy

Website legal policy
AVE Enterprises, an Indian partnership firm trading as Opvia
Effective date: 01 September 2026

1. About this policy, Opvia, and how to read it

This Privacy Policy explains how AVE Enterprises, an Indian partnership firm trading as Opvia (“Opvia”, “we”, “us”, or “our”) collects, uses, discloses, stores, and otherwise processes personal information in connection with:

● the websites at https://opvia.in, https://www.opvia.in, and https://opviahq.com, and any page that links to this Policy (collectively, the “Website”);

● enquiries, proposals, sales discussions, and client relationships;

● recruitment, candidate sourcing, screening, assessment, matching, and placement activities;

● HR, payroll, compliance, office, device, employee-engagement, and operational support that we provide where applicable; and

● Opvia’s own relationships with its employees, contractors, vendors, advisers, and other business partners.

How Opvia decides which law applies, and why this matters?

Opvia is an Indian partnership, operates from India, and employs its own staff in India. Opvia’s employment relationships with its India-based employees are governed by Indian law, principally the Digital Personal Data Protection Act, 2023 (“DPDPA”) for data protection, together with applicable Indian labour and employment legislation. That does not change because a client instructing Opvia is based in the United Kingdom, the United States, or elsewhere: a client’s location does not import that client’s country’s employment law into Opvia’s relationship with its own staff, and this Policy does not claim otherwise. Separately, and independently of employment law, a given piece of processing may also engage another country’s data-protection law where the processing itself has a real connection to that country, for example, because the personal information concerns an identifiable person located in the UK or the EEA, or because Opvia is offering services to, or monitoring the behaviour of, individuals there. Where that is true, the relevant sections below say so specifically (see sections 10 and 13) rather than assuming every law of every country where a client or visitor happens to be applied across the board. Cookie and similar tracking technology on the Website is a separate question again, addressed in the Cookie Policy, and is assessed on its own terms (who the visitor is and what the technology does), not by reference to employment law at all. Opvia’s registered address is 12th Floor, 8 Abanindra Nath Thakur Sarani, Kolkata, West Bengal 700017, India. Contact details for privacy requests appear in section 18. This Policy is a general public notice. A contract, candidate notice, employee notice, client privacy notice, or data-processing agreement may provide more specific information for a particular relationship. If a specific notice conflicts with this Policy, the more specific notice applies to that processing to the extent permitted by law.

2. Who this Policy covers

This Policy applies to personal information about:

● visitors to the Website;

● people who enquire about, evaluate, buy, administer, or receive our services, including representatives of prospective and existing clients;

● candidates and other talent whom we source, contact, assess, introduce, support, or place;

● Opvia’s own employees and contractors, whose employment relationship with Opvia is governed by Indian law as described in section 1, to the extent a separate workforce privacy notice does not apply;

● representatives of vendors, advisers, landlords, technology providers, and other business partners; and

● other people whose information is provided to us in connection with these activities.

It does not govern a client’s independent handling of personal information after the client receives it (including the client’s own compliance with its own local employment or data-protection law for its own operations), nor third-party websites or services that have their own privacy notices.

3. Our role in processing personal information

For Website operations, Opvia’s own recruitment and talent network, business development, supplier management, and administration, Opvia generally determines why and how personal information is processed and acts as a controller, data fiduciary, or equivalent role under Indian law. When Opvia processes personal information solely on a client’s documented instructions, for example, while administering a clientselected HR, payroll, IT, or operational workflow, Opvia may instead act as the client’s processor or service provider. In that case, the client’s own privacy notice and the applicable client agreement govern that processing, and the client, not Opvia, is responsible for identifying and complying with whatever law applies to its own instructions (including any employment law of the client’s own jurisdiction). Opvia may also act as an independent controller for its own legal, security, billing, workforce-management, and serviceimprovement obligations, which remain governed by Indian law as described in section 1.

4. Information we collect directly

Depending on your relationship with us, we may collect:

Identity and contact details: name, title, employer, business contact details, postal address, signature, and preferred means of contact.

Enquiry and relationship details: the content of forms, emails, calls, meeting notes, preferences, requests, feedback, support history, and records of our interactions.

Verification details: identity-verification records, authorisations, and information needed to prevent fraud or control access where relevant. The Website does not currently provide user accounts.

Commercial and transaction details: proposals, contracts, purchase orders, billing contacts, invoices, payment status, tax information, and limited payment-related details. The Website does not currently accept online payment. Bank details or payment information used during client onboarding may be processed by banks or payment providers rather than stored directly by Opvia.

Event and marketing details: registrations, attendance, communication preferences, and consent or opt-out records.

Technical and cookie information collected through the Website, described in section 7 and, in full technical detail, in the Cookie Policy.

● Any other information you choose to provide, subject to applicable law.

Please do not provide sensitive or unnecessary personal information through a general Website form

5. Candidate and talent information

If you are a candidate or potential team member, we may collect information such as:

● contact details, location, languages, work authorisation, notice period, availability, and compensation expectations;

● CV/resume data, education, qualifications, employment history, skills, portfolios, work samples, professional profiles, and references;

● role preferences, interview availability, application history, and communications with Opvia or a client;

● screening, interview, test, assessment, scoring, recruiter notes, and client feedback;

● information reasonably needed for identity, right-to-work, education, employment, reference, criminal-record, sanctions, or other background checks, but only where lawful, proportionate, and appropriately disclosed;

● onboarding, employment or engagement, payroll, benefits, attendance, leave, performance, device, access, workplace, and compliance information, where Opvia employs, engages, or supports you, this information and Opvia’s obligations toward you as employer are governed by Indian law; and

● demographic, disability, health, biometric, financial, government-identifier, or other sensitive information, collected only where relevant to employment, workplace access, payroll, benefits, health and safety, or legal obligations under Indian law, and covered by appropriate safeguards.

If you are a candidate located in the UK or the EEA. Where a specific candidate is, personally, located in the UK or the EEA at the relevant time (rather than simply being introduced to a UK- or EU-based client), UK GDPR or EU GDPR may separately apply to Opvia’s processing of that candidate’s data because the processing concerns an identifiable person there, not because the client is UK- or EU-based. In that specific case, any health, disability, biometric, or similar special-category data described above is processed only where one of the following applies, and the specific one relied on will be confirmed to that candidate directly: it is necessary for carrying out obligations under employment, social security, or social protection law (Article 9(2)(b)); the candidate has given explicit consent (Article 9(2)(a)); it is necessary to assess working capacity on medical or occupational-health grounds (Article 9(2)(h)); or another Article 9(2) condition applies and is identified before collection. This paragraph does not apply, and UK/EU GDPR is not engaged, merely because the client receiving the candidate’s profile is based in the UK or the EU while the candidate themselves is in India, that scenario remains governed by Indian law as the candidate’s data protection framework. We may obtain candidate information directly, from referrals, recruitment partners, job boards, professional networking sites, public professional profiles, former employers or references, background-check providers, clients, and other lawful sources. If you provide information about a referee or another person, you should be authorised to do so.

6. Client and business information

For prospective and existing clients, we may collect:

● company and authorised-representative details;

● hiring plans, job descriptions, role requirements, budgets, team structures, location and office requirements, preferred skills, and delivery timelines;

● interview schedules, interview notes, hiring decisions, candidate feedback, and service performance information;

● information needed for proposals, onboarding, contracts, billing, tax, compliance, audits, due diligence, and account management;

● information concerning client systems, security requirements, device requirements, work processes, and authorised users; and

● communications involving candidates, team members, Opvia personnel, and client stakeholders.

Where a client representative is, personally, located in the UK or EEA, the data-protection points in section 10 (legal bases) and section 13 (international transfers) apply to Opvia’s processing of that representative’s own business contact details in the same targeted way as for candidates, because of where that individual is, not because of where their employer is headquartered. A client that gives Opvia personal information about its own staff or candidates must have the right and a lawful basis to do so under whatever law applies to the client’s own operations, and must give any notices its own law requires to the individuals concerned; that is the client’s responsibility, not something this Policy extends Opvia’s obligations to cover.

7. Information collected automatically, and cookies

When you use the Website, our hosting, security, form-delivery, and website-analytics infrastructure may automatically collect limited technical information, including:

● IP address, approximate location derived from IP, browser type, operating system, device type, language, and device identifiers;

● dates and times, pages requested, referring pages, security events, error records, and information used to diagnose or prevent misuse; and

● cookie, tag-management, and local-storage information used for Website operation, to remember a privacy choice, or, where you consent, for analytics.

This is assessed separately from employment law, and separately from the client-location points above. Cookie and tracking-technology consent requirements depend on where the visitor to the Website is and what the specific technology does, not on where Opvia’s clients or employees are based. The full, current, and accurate list of what actually runs on the Website, and the consent mechanism that gates it, is set out in the Cookie Policy, which as of the Last Updated date discloses Google Tag Manager and a website-builder analytics script. See the Cookie Policy for the current technology register; this Policy does not repeat it so that there is only one place it needs to be kept accurate.

8. Information from third parties

We may receive personal information from clients, candidates, referrals, recruitment agencies, job boards, professional networking services, publicly available professional sources, screening and verification providers, event partners, vendors, advisers, group companies, and providers that lawfully supply business contact information. We may combine it with information already held by us and will use it consistently with this Policy and the law applicable to that processing (see section 1). Where required, we will tell you the source or categories of source. If we contact a candidate based on publicly available or third-party information, the candidate can ask us to stop and to delete or restrict the information where applicable.

9. How and why we use personal information

We may use personal information to:

● operate, secure, troubleshoot, and improve the Website;

● respond to enquiries, prepare proposals, verify representatives, and manage client and partner relationships;

● understand roles and team requirements; source, contact, screen, assess, shortlist, match, and introduce candidates; arrange interviews; collect feedback; and support offers and onboarding;

● maintain candidate and talent records for current and potentially suitable future opportunities, subject to applicable notice, choice, and retention requirements;

● deliver agreed recruitment, HR, payroll, compliance, office, infrastructure, IT/device, engagement, and other operational support, provided under Indian law as Opvia’s own employment framework;

● administer Opvia’s own employment or contractor relationships, payroll, benefits, leave, performance, security, equipment, access, and legal obligations, under Indian law;

● manage contracts, invoices, payments, taxes, accounting, audits, insurance, and corporate records under Indian law;

● communicate service, security, policy, contractual, or operational updates;

● send relevant B2B marketing, insights, invitations, and service information where permitted, and maintain suppression lists for people who opt out;

● with your consent, where cookie-based, measure Website and campaign performance, understand demand, conduct aggregated reporting, and improve services;

● protect people, systems, premises, devices, confidential information, and intellectual property; prevent or investigate fraud, misuse, and security incidents;

● establish, exercise, or defend legal claims; enforce agreements; respond to lawful requests; and comply with legal, regulatory, tax, labour, employment, and reporting duties under Indian law, or under another country’s law only where section 5, 6, 10, or 13 specifically says that law applies to the processing in question; and

● support a merger, financing, reorganisation, sale, or other corporate transaction, subject to appropriate confidentiality and legal safeguards.

We will not use personal information for a materially incompatible purpose without an appropriate legal basis and, where required, further notice or consent

10. Legal bases for processing, and which law supplies them

The legal basis for a given piece of processing, and which country’s law supplies that basis, depends on the specific processing, not on a blanket assumption that every country connected to Opvia’s business applies:

● For Opvia’s own employment relationships with its India-based staff, and for Opvia’s general business operations as an Indian entity: Indian law applies. Under the Digital Personal Data Protection Act, 2023, Opvia relies on consent, or another permitted “legitimate use” recognised under that Act and rules made under it, together with applicable Indian labour and employment legislation for the employment relationship itself.

● For a candidate or client contact who is personally located in the UK or EEA at the time of the relevant processing: UK GDPR or EU GDPR supplies the legal basis for that specific processing, which may include contract (steps taken at that person’s request, or performance of a contract with them), legitimate interests (matching talent to roles, managing the relationship, security, fraud prevention, provided those interests are not overridden by the individual’s rights), consent (for non-essential cookies or particular marketing, withdrawable at any time without affecting prior lawful processing), or legal obligation.

● Vital interests or other lawful grounds, under whichever law applies per the above, cover cases needed to protect someone’s life or safety, employment-related obligations, legal claims, or substantial public interest.

This Policy does not treat UK or EU GDPR as a general framework for Opvia’s business merely because Opvia has UK or EU clients; it applies UK/EU GDPR specifically to the processing of data belonging to individuals actually located there, and Indian law to everything else, including Opvia’s own workforce.

11. Recruitment, matching, assessments, and hiring decisions

Opvia may evaluate candidate information against a role’s stated requirements and share relevant candidate profiles, work samples, assessments, availability, and interview information with a prospective client. We aim to limit disclosure to information reasonably relevant to the opportunity and will provide appropriate notice or obtain confirmation before profile sharing where required by the law actually applicable to that candidate (see sections 5 and 10).

Opvia does not use artificial-intelligence screening, automated scoring, or solely automated decision-making to make hiring or engagement decisions. Screening and matching are performed by people using role requirements, interviews, work samples, references, and other lawful information. Clients remain responsible for their own interviews, lawful decision-making under their own applicable law, and final hiring or engagement decisions

12. How we share information

We may share personal information, only as reasonably necessary, with:

● prospective and existing clients, including authorised hiring managers and interviewers;

● candidates and team members where needed to arrange interviews, onboarding, work, or service delivery;

● vendors that support hosting, cybersecurity, communications, CRM, recruitment, assessments, screening, payroll, HR, benefits, accounting, payments, document signing, office operations, IT/device management, analytics, or marketing;

● professional advisers, auditors, banks, insurers, and financing parties;

● group entities and delivery partners;

● Indian courts, regulators, and law-enforcement or tax/employment authorities, and, where a specific individual’s data is subject to a foreign law under sections 5, 6, or 10, the equivalent authorities in that jurisdiction;

● parties necessary to protect rights, safety, security, property, confidential information, or the integrity of services; and

● potential buyers, investors, lenders, or transaction advisers in connection with a proposed or completed corporate transaction.

We do not sell personal information for money. Opvia does not sell personal information, share it for crosscontext behavioural advertising, or process it for targeted advertising. Service providers are expected to process information for agreed purposes and under appropriate confidentiality, security, and data-protection terms.

13. International data transfers

Opvia operates from India. Personal information is stored and processed in India as a matter of course, this is Opvia’s home jurisdiction, not an “international transfer.” A transfer question, and a transfer safeguard requirement, arises specifically where personal information belonging to an individual protected by UK or EU GDPR (per section 10) is sent from the UK/EEA, or is otherwise subject to that law, to Opvia in India or to a subprocessor elsewhere. Where that specific situation arises, Opvia uses an approved safeguard, such as the UK’s International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, an adequacy decision, or another lawful mechanism, and implements supplementary measures where appropriate. As of the Last Updated date, the countries where such a transfer safeguard may be relevant. Client agreements may separately allocate responsibility for controller-to-processor or controller-to-controller transfers arising from the client’s own instructions. You may contact us for information about applicable safeguards, subject to confidentiality restrictions. This section does not apply to Opvia’s own India-based employees (there is no “transfer” question for data that both originates and is processed in India under Indian law), and it does not apply merely because a client instructing Opvia is based outside India, only where an identifiable individual protected by a foreign dataprotection law is the actual subject of the data being moved.

14. Security

We use reasonable and appropriate administrative, technical, organisational, and physical safeguards designed to protect personal information against accidental or unlawful destruction, loss, alteration, disclosure, or access. Measures may include access controls, authentication, encryption, backups, logging, vendor due diligence, confidentiality obligations, staff training, incident response, and secure disposal, as appropriate to the risk. No system is completely secure. You should use appropriate caution when sending information online and notify us if you suspect unauthorised use. Security incidents will be assessed and notified to affected parties or authorities under Indian law, or under a foreign law only where section 10 or 13 specifically applies to the individuals affected.

15. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy. As a general guide, subject to legal holds, disputes, or a longer period required by applicable law:

● enquiry and Website-contact records are generally kept for up to 24 months from the last interaction;

● unsuccessful candidate applications and talent-pool records are generally kept for up to 24 months from the last contact, unless you ask us to delete them sooner, or a client engagement requires a longer period;

● client and vendor contract, billing, and tax records are kept for the period required under Indian tax, companies, and labour recordkeeping law (currently up to 8 years for most financial records; and

● Opvia’s own employment and payroll records for its India-based team members are kept for the period required under applicable Indian employment and social-security law after employment ends.

When information is no longer required, we delete, anonymise, or securely isolate it in accordance with our retention procedures.

16. Your privacy rights

Depending on which law actually applies to the processing of your data under section 10, you may have rights to:

● receive information about processing and obtain access to personal information;

● correct or complete inaccurate information;

● request deletion or erasure;

● withdraw consent;

● object to or restrict certain processing;

● receive portable data in an applicable format;

● opt out of certain marketing;

● ask for information about recipients or international-transfer safeguards;

● request review of a decision based solely on automated processing, where such a right applies;

● nominate another person, or exercise grievance and complaint rights, under the Digital Personal Data Protection Act, 2023, if Indian law applies to your data; and

● complain to the competent authority for the law that applies to you (for example, India’s Data Protection Board once operational, for data governed by Indian law; or the UK Information Commissioner’s Office or an EU supervisory authority, only for data specifically governed by UK or EU GDPR under section 10).

Rights are not absolute. We may need to verify identity and authority, and may retain or continue processing information where the law that applies to you permits or requires. We will respond within the period required by that law. If Opvia processes information only for a client, we may refer the request to that client. To exercise a right, email with enough detail to identify the relevant relationship and request. Do not send unnecessary identity documents by ordinary email; we will explain any verification needed.

17. Marketing choices

You can stop marketing emails by using the unsubscribe link or contacting. You may still receive nonmarketing communications concerning enquiries, contracts, security, services, candidates, or legal matters.
We may keep minimal suppression information so that we honour an opt-out. Cookie choices are managed
using the consent banner and technology register described in the Cookie Policy, which is the single source of
truth for cookie-related matters, this Policy does not separately restate it. Withdrawing consent does not
affect processing that occurred before withdrawal.

18. Third-party websites, children, and contact

The Website may link to third-party sites or services. Opvia does not control their privacy practices, content,
or security, and a link is not an endorsement. Review their notices before providing information.
The Website and Opvia’s business services are not directed to children. We do not knowingly solicit personal
information through the Website from anyone under 18. If you believe a child has provided information,
contact us so we can assess and take appropriate action. Employment-related processing for lawful young
workers, if any, is governed by Indian law and covered by a specific notice and safeguards.
Questions, requests, or complaints may be sent to:

Email: contactopvia@gmail.com

Phone: +91 79800 74354

Postal address: 12th Floor, 8 Abanindra Nath Thakur Sarani, Kolkata, West Bengal 700017, India

19. Changes and disputes

We may update this Policy to reflect changes in our services, technology, or applicable law. We will post the
revised Policy with a new “Last updated” date and provide additional notice where required. Material
changes will not be applied retroactively where prohibited.
Privacy questions and disputes are subject to the law that actually applies to the relevant processing and
individual, as determined under section 10, not to every country’s law by default. A complaint or proceeding
may be brought before any regulator, court, tribunal, or other body that has jurisdiction under that applicable
law. Nothing in this Policy selects an exclusive governing law or forum beyond what is stated in section 10, or
limits a person’s non-waivable rights.

Scroll to Top
Your team in India. Your culture.
Your control. Everything else is on us.

Follow on LinkedIn