Privacy Policy

Your privacy is important to us. It is Studio 216 Inc. together with its affiliates, namely Altoura India Private Limited and Altoura EMEA Limited’s (hereinafter referred to as the ‘Company’, ‘Us’, and/or ‘Altoura’) policy to respect your privacy regarding any information we may collect from you across our Website, http://www.altoura.com, other sites, App, etc., we own and operate, and other communications that you are offered by the Company through their communication channel and services we offer in line (‘Service/s’). This privacy policy document contains types of information that is collected and recorded by the Company and how we use it. If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us on privacy@altoura.com. This privacy policy applies only to our online activities and is valid for visitors to our website/App and event attenders with regards to the information that they shared and/or collected by the Company. This policy is not applicable to any information collected offline or via channels other than the website/App or Service/s we offer. References to ‘you’, ‘your’ or ‘user’ means the end user utilizing or accessing the Services.

1. Consent

PLEASE READ THIS PRIVACY POLICY CAREFULLY. BY ACCESSING OR USING THE SERVICE/S AND BY ATTENDING EVENTS ORGANISED AND HOSTED BY US, YOU AGREE TO BE LEGALLY BOUND BY THIS POLICY AND ALL TERMS INCORPORATED BY REFERENCE. THE COMPANY RESERVES THE RIGHT TO ALTER, AMEND AND MODIFY THIS POLICY AT ITS SOLE DISCRETION. ALL SUCH AMENDMENTS AND MODIFICATIONS WILL BE DULY NOTIFIED ON WEBSITE. YOUR CONTINUED USE AND ACCESS OF OUR SERVICE/S AFTER WE PUBLISH THE CHANGES TO THIS POLICY MEANS THAT YOU HAVE CONSENTED TO THE UPDATED TERMS NOTIFIED BY US FROM TIME TO TIME. IF YOU ARE NOT AGREEABLE TO THIS POLICY, WE REQUEST YOU NOT TO ACCESS OR USE THE SERVICE/S. For our Terms and Conditions, please visit Altoura.


2. Overview

We are committed to maintaining your privacy and we value and appreciate your trust in us. We let you retain as much control as possible over your personal information. However, you may not visit and use our Service/s at any time without telling us who you are or revealing the required information about yourself. To the Company, our most important asset is our relationship with you.

We are dedicated to maintaining the confidentiality, integrity and security of any personal information about our users. We are proud of our privacy practices and the strength of our Website and App security and want you to know how we protect your information and use it to provide to you the Service/s.

This Policy does not cover the privacy practices of third parties that we do not own or control. The Company may provide third-party content or links to web sites or

applications or include features that allow you to connect with third parties, such as financial institutions or other service providers. When you interact with a third-party, you should read that party's privacy policy and terms of use to understand the practices that it follows in relation to the access, storage, processing, use etc. of data collected by that party.

3. Data Controller

The Company and its Affiliates, having its registered office/principal place of business at 10878 Skinner Road NE, Bainbridge Island, WA 98110, United States of America, will be the controller of your personal data and other data provided to, or collected by or for, or processed in connection with our Services.


4. Data Processors (Sub-processors or Service Providers)

Data Processor (Sub Processors or Service Provider) means any natural or legal person who processes the data on behalf of the Company. We may use the services of various Service Providers/Sub processors in order to process your data more effectively. The list of the Sub-processors that the Company currently is engaged with can be found at Annexure A attached hereto.

5. Information we collect

a) Personal information

We may ask for personal information, such as your

  • Name
  • Email
  • Phone number
  • Content of the message or attachment that you may choose to send us

When you register for an Account, we may ask for your contact information, including items such as name, company name, address, email address, and telephone number.

Further, we may also collect certain digital data from you, which include photographs, video recordings, audio recordings, screen captures and related digital media, primarily in connection with events organised and hosted by us which you attend (“Event Content”). Event Content may be edited or modified, and used in perpetuity, without additional approval from you. If you prefer not to be recorded or featured, please notify us prior to the event or contact us after the event, to request reasonable removal, where feasible and appropriate.


b) How we use your information:

We use the information we collect in various ways, including to:

  • Provide, operate, and maintain our Website
  • Improve, personalize, and expand our Website
  • Understand and analyze how you use our Website
  • Develop new products, Service/s, features, and functionality
Communicate with you, either directly or through one of our partners, including for customer service, to provide you with updates and other information relating to the website, and for marketing and promotional purposes
  • Send you emails
  • Find and prevent fraud

Additionally, we may specifically use Event Content that we collect from you for several purposes, including but not limited to the following purposes:

  • Marketing and Promotion on our social media platforms, websites, blogs, email campaigns, and digital or print advertising;
  • Sales and Business Development, including client presentations, case studies, and investor materials;
  • Training and Education, for both internal employee onboarding and external customer support or product training;
  • Public Relations and Media, such as press kits, award submissions, and conference materials;
  • Product Development and User Experience Research, including showcasing real-world use cases and user interactions.

c) Log Files

The Company follows a standard procedure of using log files. These files log visitors when they visit websites. All hosting companies do this and a part of hosting services' analytics. The information collected by log files include internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date and time stamp, referring/exit pages, and possibly the number of clicks. These are not linked to any information that is personally identifiable. The purpose of the information is for analyzing trends,

administering the site, tracking users' movement on the website, and gathering demographic information.

d) Device data

We may also collect data about the device you’re using to access our website. This data may include the device type, operating system, unique device identifiers, device settings, and geo-location data. What we collect can depend on the individual settings of your device and software. We recommend checking the policies of your device manufacturer or software provider to learn what information they make available to us.

e) Business data

Business data refers to data that accumulates over the normal course of operation on our platform. This may include transaction records, stored files, user profiles, analytics data and other metrics, as well as other types of information, created or generated, as users interact with our services.


6. Legal bases for processing

We will process your personal information lawfully, fairly, and in a transparent manner. We collect and process information about you only where we have legal bases for doing so.

These legal bases depend on the services you use and how you use them, meaning we collect and use your information only where:

  1. it’s necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract (for example, when we provide a service you request from us);
  2. it satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote our services, and to protect our legal rights and interests;
  3. you give us consent to do so for a specific purpose (for example, you might consent to us sending you our newsletter); or
  4. we need to process your data to comply with a legal obligation.

Where you consent to our use of information about you for a specific purpose, you have the right to change your mind at any time (but this will not affect any processing that has already taken place).

We don’t keep personal information for longer than is necessary or as is legally stipulated. While we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use, or modification. That said, we advise that no method of electronic transmission or storage is 100% secure and cannot guarantee absolute data security. If necessary, we may retain your personal information for our compliance with a legal obligation or in order to protect your vital interests or the vital interests of another natural person/entity connected either directly or indirectly to you.

7. Collection and use of information

We may collect, hold, use and disclose information for the following purposes and personal information will not be further processed in a manner that is incompatible with these purposes:

  1. to provide you with our platform's core features; to enable you to access and use our website, associated applications; to contact and communicate with you; for internal record keeping and administrative purposes; for analytics, market research and business development, including to operate and improve our website, associated applications and associated social media platforms; and to comply with our legal obligations and resolve any disputes that we may have.


8. Disclosure of personal information to third parties

We may disclose personal information to:

  1. third party service providers and/or sub processors, if and to the extent necessary, for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, analytics, error loggers, maintenance or problem-solving providers, professional advisors (for example to resolve disputes, and enforce our legal agreements and policies), and payment systems operators; and third parties to collect and process data.
  2. our employees, where required;
  3. our business partners, being our customers and clients who purchase our products or services or who are interested in purchasing our products or services, as well as our investors.

Additionally, Event Content specifically would be made available to third parties by way of publishing on our social media platforms, websites, blogs, or by way of email campaigns, and digital or print advertising, as well as press kits, award submissions, and conference materials.


9. International transfers of personal information

The personal information we collect is stored and processed in United States, or where we or our partners, affiliates and third-party providers maintain facilities. By providing

us with your personal information, you consent to the disclosure to these overseas third parties.

We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.

Where we transfer personal information from a non-EEA country to another country, you acknowledge that third parties in other jurisdictions may not be subject to similar data protection laws to the ones in our jurisdiction. There are risks if any such third party engages in any act or practice that would contravene the data privacy laws in our jurisdiction and this might mean that you will not be able to seek redress under our jurisdiction’s privacy laws.


10. Your rights and controlling your personal information

  1. Choice and consent: By providing personal information to us, you consent to us collecting, holding, using and disclosing your personal information in accordance with this privacy policy.
  2. Neither our Website nor our Services are intended for children under the age of 18 nor do we knowingly collect personal or any other kind of information from children under 18. If you are under 18 years of age, you must have, and warrant to the extent permitted by law to us, that you have your parent or legal guardian’s permission to access and use the website and they (your parents or guardian) have consented to you providing us with your personal information. You do not have to provide personal information to us, however, if you do not, it may affect your use of this website or the products and/or services offered on or through it.
  3. Information from third parties: If we receive personal information about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person’s consent to provide the personal information to us.
  4. Restrict: You may choose to restrict the collection or use of your personal information. If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us using the details below. If you ask us to restrict or limit how we process your personal information, we will let you know how the restriction affects your use of our website or products and services.
  5. Access and data portability: You may request details of the personal information that we hold about you. You may request a copy of the personal information we hold about you. Where possible, we will provide this information in CSV format or other easily readable machine format. You may request that we erase the personal information we hold about you at any time. You may also request that we transfer this personal information to another third party.
  6. Correction and Updates: If you believe that any information, we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us using the details below. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading or out of date. You can add or update your information. When you update the information, we usually keep a copy of the prior version for our records.
  7. Notification of data breaches: We will comply laws applicable to us in respect of any data breach.
  8. Complaints: If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.
  9. Unsubscribe: To unsubscribe from our e-mail database or opt-out of communications (including marketing communications), please contact us using the details below or opt-out using the opt-out facilities provided in the communication.


11. How we use the personal and other information that we collect

The usage of certain data that we collect, is limited to fulfill your requests for our services or otherwise complete a transaction that you initiate; to deliver confirmations, account information, notifications, and similar operational communications; to improve your user experience and the quality of our products and services; to comply with legal and/or regulatory requirements; this restricted data will never be used to serve ads, and will only be accessed by humans with user permission, to investigate a security issue, to comply with applicable law, or for internal operations in an aggregated and anonymized manner.

We use the other information that we collect for such purposes as counting and recognizing visitors to the site; analyzing how visitors use the site and various site features; improving the site and enhancing users’ experiences with the site; creating new products and services or improving our existing products and services; enabling additional website analytics and research concerning the site, and managing our business. The Company may link other information gathered using cookies and web beacons with Personal Information. But in that event, we will treat the combined information as Personal Information.


12. Aggregate Anonymised Data and Usage

We may/will monitor the use of the Services by all of our customers and use the information gathered in an aggregate and anonymous manner. You agree that we may use and publish such information, provided that such information does not incorporate any of Your data in a personally identifiable manner. Notwithstanding the restrictions above and elsewhere in this Privacy policy, You expressly agree that the Company retains the right to use, sell, disclose, transfer, or rent any user data as long as such user data is in an aggregate anonymised form that does not include any individually identifiable user data, and/or identify you. Further, the Company retains all rights on use of statistical information, as well as on data and related analysis in aggregate anonymised form, deriving from the use of the Services by its Users. For sake of clarity, such aggregate anonymised data does not include personal data and the User expressly authorizes the Company to use same in order to improve the functionality of the Services, or to publish the statistical information in aggregate form or for any other requirement that the Company deems fit.


13. Cookies

We use “cookies” to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit, so we can understand how you use our site. This helps us serve you content based on preferences you have specified. For more general information on cookies, please read "What Are Cookies" from Cookie Consent.


14. Business transfers

If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may continue to use your personal information according to this policy. In such a case, we will intimate you of the same and ensure the protection of your information as per this Policy.


15. Third Party Privacy Policies

The Company's Privacy Policy does not apply to other advertisers or websites. Thus, we are advising you to consult the respective Privacy Policies of these third-party ad servers for more detailed information. It may include their practices and instructions about how to opt-out of certain options. You can choose to disable cookies through your individual browser options. To know more detailed information about cookie management with specific web browsers, it can be found at the browsers' respective websites. CCPA Privacy Rights (Do Not Sell My Personal Information).

Under the CCPA, among other rights, California consumers have the right to: (i) Request that a business that collects a consumer's personal data disclose the categories and specific pieces of personal data that a business has collected about consumers; (ii) Request that a business delete any personal data about the consumer that a business has collected; (iii) Request that a business that sells a consumer's personal data, not sell the consumer's personal data.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.


16. GDPR Data Protection Rights

We would like to make sure you are fully aware of all of your data protection rights. Every user is entitled to the following:

  1. The right to access – You have the right to request copies of your personal data. We may charge you a small fee for this service.
  2. The right to rectification – You have the right to request that we correct any information you believe is inaccurate. You also have the right to request that we complete the information you believe is incomplete.
  3. The right to erasure – You have the right to request that we erase your personal data, under certain conditions.
  4. The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.
  5. The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.
  6. The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us.


17. The Company’s Stance on Privacy

The Company aims to provide an excellent, trusted product and service to our customers. We do plan on using anonymized aggregate data to improve the product for those same customers. Moreover, we will never sell our customer’s data, identity, or contact information to third parties or vendors, as that would be a violation of our promise and trust. Any feature that requires the sharing of personally identifiable information will be strictly opt-in.


18. Security of Information

We work to protect the security of your information during transmission of data by using Secure Sockets Layer (SSL) software, which encrypts information you input. We constantly re-evaluate our privacy and security processes and adapt them as necessary to deal with new challenges.

We make every effort to allow you to retain the anonymity of your personal identity and you are free to choose a login ID, email address and password that keep your personal identity anonymous. Access to your registration information and your personal data is strictly restricted to our employees and contractors, on a need-to-know basis, in order to operate, develop or improve the Services.

You agree and understand that you are responsible for maintaining the confidentiality of all information provided to the Company while registering yourself, which includes your login ID, e-mail address and the passwords for the same. You are fully responsible for all activities that occur under your e-mail address, password or account and you shall ensure to exit from your account at the end of each use. The Company will send all

correspondences, notices and any other communication to the e-mail address furnished by you.

In the event of your becoming aware of any unauthorized access or misuse of your account/ information, you must forthwith notify the Company at info@altoura.com. The Company cannot and will not be liable for any loss or damage arising from your failure to comply with this provision.

The rest of this privacy policy goes into more specific legal details, and if you have questions, feel free to reach out at info@altoura.com.


19. Other Uses and Legal Disclosures

We do not and will not sell or rent your personal information to anyone, for any reason, at any time, unless you have explicitly consented to the same. We may need to disclose information about you when required by law or legal process or if we have a good faith belief that disclosure is reasonably necessary to (a) investigate, prevent, or take action regarding suspected or actual illegal activities or to assist government enforcement agencies; (b) enforce our agreements with you, (c) investigate and defend ourselves against any third-party claims or allegations, (d) protect the security or integrity of our Services (such as by sharing with companies facing similar threats); or (e) exercise or protect the rights and safety of the Company, our users, personnel, or others. In addition to the circumstances described above, we may utilize the data for some statistical or other representational purposes without any disclosure of your personal data.

We will attempt to notify you about legal demands for your personal data when appropriate in our judgment, unless prohibited by law or court order or when the request is an emergency.


20. Limits of our policy

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites and cannot accept responsibility or liability for their respective privacy practices.


21. Changes to this policy

At our discretion, we may change our privacy policy to reflect current acceptable practices. We will take reasonable steps to let users know about changes via our website. Your continued use of this site after any changes to this policy will be regarded as acceptance of our practices around privacy and personal information.

If we make a significant change to this privacy policy, for example changing a lawful basis on which we process your personal information, we will ask you to re-consent to the amended privacy policy.


22. Governing Law and Jurisdiction

a) For users in the Asia region: If you choose to access or use our Services, your visit, use and any dispute over privacy are subject to this Privacy Policy. Any disputes arising out of this Privacy Policy and the Services shall be governed by the laws of India and the courts of Bangalore, India shall have the exclusive jurisdiction. Any dispute arising out of or in relation to the Privacy Policy shall be resolved through arbitration/Courts in accordance with Indian Arbitration and Conciliation Act, 1996. The venue and seat for arbitration shall be Bangalore. The proceedings shall be in English.

b) For users in the other region: If you choose to access or use our Services, your visit, use and any dispute over privacy are subject to this Privacy Policy. Any disputes arising out of this Privacy Policy and the Services shall be governed by the laws of the State of Washington and the courts of the State of Washington shall have the exclusive jurisdiction. The proceedings shall be in English.

Studio 216 Inc.

Data Controller

Annexure A

List of sub-processors

Studio 216 Inc (“Altoura”) uses the following third-party service providers (“subprocessors”) to process personal data on our behalf:

1. Microsoft Azure

  • Purpose: Cloud hosting, infrastructure, storage, backups, security, networking, and database operations (including Azure SQL Database).
  • Location: United States.
  • Data processed: All customer data, files, account information, and communications stored or processed in our platform.

2. Microsoft 365 (Office 365, SharePoint Online, Exchange Online)

  • Purpose: Collaboration, email communication, document storage, and internal support operations.
  • Location: United States.
  • Data processed: Support emails, account communications, shared documents and files.

3. SendGrid (Twilio)

  • Purpose: Transactional email delivery (e.g., account confirmations, password resets, service notifications).
  • Location: United States.
  • Data processed: Email addresses, notification content, communications logs.

4. HubSpot

  • Purpose: Customer relationship management (CRM), marketing automation, and communications management.
  • Location: United States.
  • Data processed: Contact information, communications, support requests, marketing activity.

 

Purpose

Studio216 dba Altoura is committed to protecting the privacy and security of personal data. This Data Privacy Policy outlines how we collect, use, disclose, and safeguard your personal data in compliance with applicable data protection laws.

By accessing or using our services and by attending events organised and hosted by us, you agree to the collection and use of information in accordance with this policy.

Scope of this document

This policy is applicable to all Studio216 dba Altoura employees, contractors, vendors, interns, customers, business partners and event attenders who provide information to Studio216 dba Altoura.

Information We Collect

We may collect the following types of personal data:

  • Personal Identification Information: Name, email address
  • Financial Information: Payroll Information, Payment information, billing address, etc.
  • Usage Data: Information about how you access and use our portal or services (e.g., device type and application related information).
  • Cookies and Tracking Technologies: We may use cookies to track user action within the application to improve user experience.
  • Digital Data: Photographs, video recordings, audio recordings, screen captures and related digital media, primarily in connection with events organised and hosted by us which you attend (“Event Content”). Event Content may be edited or modified, and used in perpetuity, without additional approval from you. If you prefer not to be recorded or featured, please notify us prior to the event or contact us after the event, to request reasonable removal, where feasible and appropriate.

How We Use Your Information

We may use the personal data we collect for the following purposes:

  • For Analytics: To provide reports to the customers based on the trainings done on the platform. Also to analyse usage patterns and trends to improve the overall user experience.
  • For Customer Support Requests:  To debug action undertaken to be able to respond to inquiries, provide customer support, send product release updates.
  • To comply with legal obligations: To fulfil legal requirements, such as tax, accounting, and regulatory obligations.

We may specifically use Event Content that we collect from you for several purposes, including but not limited to the following purposes:

  • Marketing and Promotion on our social media platforms, websites, blogs, email campaigns, and digital or print advertising;
  • Sales and Business Development, including client presentations, case studies, and investor materials;
  • Training and Education, for both internal employee onboarding and external customer support or product training;
  • Public Relations and Media, such as press kits, award submissions, and conference materials;
  • Product Development and User Experience Research, including showcasing real-world use cases and user interactions.

Sharing Your Information

We may share your personal data with the following entities:

  • Service Providers: Third-party vendors who assist us in delivering services, including our employees, where required.
  • Business Partners: Our customers and clients who purchase our products or services or who are interested in purchasing our products or services, as well as our investors.
  • Legal Compliance: We may disclose personal data to law enforcement or other authorities if required by law or in response to valid legal processes.
  • Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred as part of the transaction.
  • We ensure that any third-party service providers maintain the same level of data protection as we do and are compliant with applicable privacy laws.

Additionally, Event Content specifically would be made available to third parties by way of publishing on our social media platforms, websites, blogs, or by way of email campaigns, and digital or print advertising, as well as press kits, award submissions, and conference materials.

Data Security

We use a variety of security measures, including encryption and access controls, to protect your personal data. We are an ISO/IEC 27001:2022 certified organization and have the necessary security controls to protect Studio216 dba Altoura’s and our customer’s information.

Your Rights

Depending on your location and applicable laws, you may have the following rights regarding your personal data:

  • Access: The right to request a copy of the personal data we hold about you.
  • Correction: The right to correct any inaccurate or incomplete data we hold about you.
  • Deletion: The right to request the deletion of your personal data, subject to legal limitations.
  • Restriction: The right to restrict or object to certain processing activities.
  • Portability: The right to request your data in a structured, commonly used format to transfer it to another entity.
  • Withdrawal of Consent: The right to withdraw your consent where processing is based on consent.

To exercise these rights, please contact us at support@altoura.com

Data Retention

We retain your personal data for as long as necessary to fulfil the purposes outlined in this policy and Studio216 dba Altoura’s retention policy or as required by law. When your data is no longer needed, we will securely dispose of it.

Changes to This Policy

We may update this Data Privacy Policy from time to time to reflect changes in our practices or legal obligations. Any updates will be posted on this page with the updated date. Please review this policy regularly to stay informed about how we are protecting your personal data.

Enforcement

Violation of this policy may be grounds for disciplinary action up to and including termination of employment. This policy is approved by the company management and shall be reviewed by the management team annually.