Lorem ipsum dolor sit amet, consectetur adipiscing elit,
How InsideHunt collects, uses, stores, shares, and protects personal data — written to satisfy the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and to tell you plainly what happens to your information on an AI-powered platform.
This Privacy Policy (the "Policy") is issued by InsideHunt ("InsideHunt," "we," "us," or "our"), a company incorporated under the laws of the Republic of India with its registered office in Ahmedabad, Gujarat, CIN [CIN — to be inserted upon issuance].
InsideHunt operates a growth-intelligence software platform. We apply proprietary analytical frameworks and artificial-intelligence systems to market data, publicly available information, and information supplied by our clients, in order to produce structured intelligence for founder-operators and marketing leadership.
For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025 (the "DPDP Rules"), InsideHunt acts as a Data Fiduciary in respect of the personal data described in this Policy: we determine the purpose and means of its processing, and we carry responsibility for it. You are the Data Principal.
This Policy should be read alongside our Terms of Service. Where a more specific notice is given at the point of collection, that notice prevails for the data collected there.
InsideHunt was previously operated under the name "Blueberry," including as a dual agency-and-reports model. That model has been retired. This Policy replaces the Blueberry Privacy Notice in full. Personal data collected under the Blueberry name continues to be held by the same legal entity and is now governed exclusively by this Policy.
This Policy applies to personal data we process in connection with the InsideHunt platform, website, and business operations, in respect of the following categories of individuals:
This Policy does not govern personal data processed in our capacity as an employer, nor the practices of any third-party website, agency, vendor, or platform referenced in our intelligence outputs or linked from our website. Those operate under their own policies.
We process only such personal data as is proportionate and necessary for the purposes described in this Policy. The table sets out each category, the data points involved, and the lawful basis on which we rely under the DPDP Act — which recognises processing on the basis of consent and on the basis of certain legitimate uses, including performance of a contract with you and compliance with a legal obligation.
| Category | Data Points | Lawful Basis |
|---|---|---|
| Identity | Full name, professional designation, role, organisation | Contract performance |
| Contact | Work email, phone or WhatsApp number, city | Contract performance; consent for marketing |
| Account | Username, hashed password, seat and role assignment, authentication events, preferences | Contract performance; security |
| Organisation | Company name, website, sector, stage, headcount band, GSTIN and billing address | Contract performance; legal obligation |
| Subscription & billing | Plan, billing period, invoices, payment reference and status, e-mandate reference, refund records | Contract performance; legal obligation |
| Client Content | Brand, campaign, channel and performance information submitted for analysis, including uploads and integration data | Contract performance (see § 07) |
| Usage & platform | Modules run, outputs generated, feature usage, session duration, in-product navigation | Legitimate use — service operation and improvement |
| Technical | IP address, device and browser type, operating system, timestamps, referring URL, error logs | Legitimate use — security and diagnostics |
| Analytics & marketing | Cross-session behaviour, campaign attribution, ad interaction | Consent, via cookie preferences |
| Communications | Emails, form submissions, support tickets, meeting notes, and — where you are told in advance — call recordings | Contract performance; legitimate use |
| Consent records | Opt-in and opt-out records, timestamps, consent version, withdrawal history | Legal obligation under the DPDP Act |
We do not collect government identification numbers (Aadhaar, PAN of individuals, passport, driving licence), biometric data, health or medical information, card numbers or bank credentials, or data concerning religious belief, caste, political affiliation, or sexual orientation. Payment instruments are handled entirely by regulated payment service providers; we receive only a transaction reference and status. Where a business PAN or GSTIN is required for tax invoicing, it is processed as organisational data, not as individual identification.
InsideHunt will never request your password, one-time password, or payment credentials by email, phone, or message. If you receive such a request purporting to come from us, do not respond — report it to support@insidehunt.com.
We process personal data only for the purposes set out below. We do not repurpose data beyond the purpose for which it was collected without giving notice and, where required, obtaining fresh consent.
| Purpose | What This Involves | Lawful Basis |
|---|---|---|
| Service delivery | Provisioning access, running modules, generating and storing outputs, refreshing intelligence | Contract performance |
| Account management | Registration, authentication, seat management, preference settings | Contract performance |
| Billing | Charging fees, managing e-mandates and renewals, issuing invoices, processing refunds, tax reporting | Contract performance; legal obligation |
| Transactional communication | Order confirmations, pre-debit notifications, renewal reminders, output-ready alerts, service and security notices | Contract performance; legal obligation |
| Support | Responding to queries, troubleshooting, onboarding assistance | Contract performance |
| Product improvement | Diagnosing errors, measuring feature performance, improving frameworks using aggregated and de-identified data | Legitimate use |
| Security & fraud prevention | Detecting unauthorised access, abuse, credential sharing, and payment fraud; maintaining audit logs | Legitimate use; legal obligation |
| Marketing | Sending briefings, product news, and offers through channels you have opted into | Consent |
| Legal & regulatory | Complying with the DPDP Act, the Information Technology Act, the Companies Act, GST law, and any lawful order | Legal obligation |
| Corporate | Investor reporting and due diligence using aggregated, non-identifying metrics | Legitimate use |
InsideHunt's outputs are generated using artificial-intelligence and machine-learning systems, some of which are operated by third-party providers under contract. This section explains what that means for your data. We consider it the most important section in this Policy.
Do not submit personal data to the platform beyond what a module actually requires, and never submit special-category or sensitive personal data — identification numbers, financial account details, health information, or data about identified consumers — into analysis fields. If you must analyse customer data, aggregate or pseudonymise it first. Where you upload personal data relating to others, you confirm you have a lawful basis to do so.
Our role under data protection law depends on whose data is at issue.
Where we act as a processor, we do not use Client Content for our own purposes, do not disclose it except as instructed or required by law, and will assist the client organisation in responding to rights requests and breach obligations. Client organisations with regulatory requirements may request a separate Data Processing Agreement by writing to support@insidehunt.com.
If you are an individual whose personal data was uploaded to the platform by a client organisation and you wish to exercise rights over it, you should contact that organisation directly. Where you contact us, we will refer your request to them and support their response.
We use cookies and comparable technologies — including local storage, pixels, and session identifiers — to run the platform, understand how it is used, and measure our marketing. On your first visit, a consent banner lets you accept all, reject all non-essential, or choose by category. You can change or withdraw your choice at any time through the cookie preferences link on the site or through your browser settings.
| Category | What It Does | Consent |
|---|---|---|
| Strictly necessary | Session management, authentication, security tokens, load balancing, consent state. The platform cannot function without these. | Not required |
| Functional | Remembers language, display, and workspace preferences between visits. | Required |
| Analytics | Measures page and feature usage, journey mapping, and drop-off, in aggregated form. | Required |
| Marketing | Attributes conversions and supports advertising audiences across platforms. | Required |
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, but may reduce functionality. A current inventory of the cookies in use is maintained in our consent manager and updated as our integrations change. Third-party cookies are governed additionally by the policies of the providers concerned.
We do not sell, rent, licence, or trade personal data. There is no exception to this commitment. Personal data is disclosed only in the defined circumstances below.
| Function | Why They Receive Data | Data Involved |
|---|---|---|
| Cloud hosting & infrastructure | Running the platform, storage, backups | All categories, encrypted |
| AI model providers | Generating analytical outputs | Analysis payloads, minimised for personal data |
| Payment gateways | Collecting fees, managing e-mandates | Billing identity, transaction data |
| Email & messaging delivery | Transactional and opted-in marketing messages | Name, email, phone, engagement events |
| Analytics & product telemetry | Usage measurement and error diagnostics | Technical and usage data |
| CRM & sales tooling | Managing enquiries, pipeline, and client relationships | Professional contact and organisational data |
| Support tooling | Handling and tracking support requests | Communications data |
| Professional advisers | Accounting, audit, tax, and legal advice | Billing and contractual records |
A current list of named processors is available on request from support@insidehunt.com. Every processor is assessed before engagement, bound by a written agreement, restricted to processing on our instructions, and prohibited from any independent commercial use of the data.
We maintain reasonable technical and organisational security safeguards proportionate to the nature and volume of the data we hold, in line with Rule 6 of the DPDP Rules and the Information Technology (Reasonable Security Practices) Rules, 2011. These include:
No method of transmission or storage over the internet is completely secure. While we apply rigorous safeguards, we cannot guarantee absolute security. You also carry a share of this: keep your credentials confidential, enable available account protections, and notify us immediately if you suspect unauthorised access.
If we become aware of a personal data breach affecting your data, we will act on the following basis, consistent with the DPDP Act and the DPDP Rules:
Where we act as a processor for a client organisation, we will notify that organisation without undue delay and provide the assistance it needs to meet its own obligations.
We retain personal data only for as long as the purpose for which it was collected requires, or for as long as a legal, tax, or contractual obligation requires. When a retention period expires, data is securely deleted or irreversibly anonymised.
| Data | Retention | Reason |
|---|---|---|
| Account & profile | For the life of the account, then 90 days after closure | Contract; dispute window |
| Client Content & outputs | For the life of the subscription, then 30 days' export access and deletion within a further 60 days | Contract; client access |
| Billing, invoices & tax records | 8 years from the end of the relevant financial year | Companies Act; GST and income-tax law |
| Consent records | Duration of consent plus 3 years after withdrawal | Demonstrating DPDP compliance |
| Technical & usage logs | Up to 18 months, then aggregated or deleted | Security; product analytics |
| Security & access logs | Minimum 1 year | DPDP Rules; incident investigation |
| Support & correspondence | 3 years from last contact | Service continuity; disputes |
| Marketing & prospect data | Until consent is withdrawn or 24 months of no engagement | Consent; data minimisation |
| Aggregated, de-identified data | Indefinitely | No longer personal data |
Where the DPDP Rules prescribe erasure after a defined period of user inactivity, we will notify you at least 48 hours before erasure so that you can log in, re-engage, or exercise your rights. Erasure may be deferred where retention is required by law, or where the data is needed to establish, exercise, or defend a legal claim; where that applies, we will tell you.
Under the DPDP Act you hold the following rights in respect of personal data we process about you. These are exercised free of charge.
Obtain a summary of the personal data we process about you, the purposes of processing, and the identities of other Data Fiduciaries and processors with whom it has been shared.
Have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated.
Have your personal data erased where it is no longer needed for the purpose it was collected for, or where you withdraw the consent it rested on — subject to legal retention obligations.
Withdraw consent at any time, as easily as it was given. Withdrawal does not affect processing carried out before it, and may limit the services we can provide.
Raise a complaint with our Grievance Officer and receive a substantive response, before approaching the Data Protection Board of India.
Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, under Section 14 of the DPDP Act.
Receive personal data you have provided in a structured, commonly used, machine-readable format, where technically feasible. We offer this as a matter of practice.
Opt out of marketing communications at any time, with immediate effect on receipt of your request.
Write to support@insidehunt.com, or use the in-account privacy controls where available, stating the right you wish to exercise and enough detail for us to identify your records. We may verify your identity before acting, to prevent unauthorised disclosure of someone else's data.
Your duties. Section 15 of the DPDP Act places duties on you as well: to provide accurate and complete information, not to impersonate another person, not to suppress material information where legally required to disclose it, and not to register a false or frivolous grievance.
If you are dissatisfied with our response, you may escalate to the Data Protection Board of India. We will provide reasonable assistance with that escalation on request.
We are incorporated in India and prefer infrastructure located in India where practicable. However, several of the services we depend on — cloud infrastructure, AI model providers, analytics, and email delivery — operate globally. Your personal data may therefore be transferred to, stored in, or accessed from jurisdictions outside India, including the United States, the European Union, and Singapore.
Under the DPDP Act, transfers outside India are permitted except to countries restricted by the Central Government. Where a transfer occurs, we maintain safeguards including contractual data protection clauses with each recipient, assessment of the recipient's security posture before engagement, minimisation of the data transferred, and equivalent standards of protection to those described in this Policy. We will not transfer personal data to any jurisdiction the Central Government notifies as restricted, and will re-architect affected processing where such a notification is issued.
We send intelligence briefings, product updates, and offers by email, WhatsApp, and SMS to people who have opted in. Consent for marketing is collected separately and distinctly from acceptance of our Terms, through a clearly labelled opt-in. We do not pass your contact details to any third party for their own marketing.
The platform is a business tool intended exclusively for individuals aged 18 or above. We do not knowingly collect or process the personal data of children, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children — all of which are prohibited under Section 9 of the DPDP Act.
If we become aware that we hold a child's personal data without verifiable parental consent, we will delete it promptly. Parents or guardians who believe this has occurred should contact support@insidehunt.com.
Where an account has no login, subscription, or substantive platform activity for 24 continuous months, we will write to the registered email address describing the intended action and the data affected. If we receive no response within 30 calendar days, we may archive or delete the account and its associated personal data, subject to mandatory retention obligations. Archived data is isolated from active systems and accessed only for legal, audit, or regulatory purposes.
You may close your account at any time from account settings or by writing to support@insidehunt.com. Closure triggers the retention periods set out in § 12.
We may revise this Policy to reflect changes in our services, technology, processors, or legal obligations. Where a change materially affects how your personal data is processed or the rights available to you, we will:
Where a change requires fresh consent under the DPDP Act, we will seek it rather than rely on continued use. Continued use of the platform after the notice period expires constitutes acknowledgement of the revised Policy. If you do not accept a revision, you may close your account and submit an erasure request under § 13.
| Instrument | How We Apply It |
|---|---|
| DPDP Act, 2023 | India's principal data protection statute. We operate as a Data Fiduciary, observing notice, consent, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, breach reporting, and grievance redressal. |
| DPDP Rules, 2025 | Notified in November 2025 and commencing in phases, with substantive Data Fiduciary obligations applying from May 2027. We are building to those obligations ahead of the deadline — itemised notice, consent records, retention schedules, security logging, and breach procedures are already reflected in this Policy. |
| Information Technology Act, 2000 | Including the Reasonable Security Practices Rules, 2011, and the requirement to publish a Grievance Officer. |
| Consumer Protection (E-Commerce) Rules, 2020 | Transparent disclosure of identity, pricing, cancellation, refund, and grievance mechanisms. |
| RBI E-Mandate Framework | Recurring subscription collections are processed through registered e-mandates with pre-debit notification and additional-factor authentication where required. |
| GDPR-aligned practice | Where we process the personal data of individuals in the EEA or the United Kingdom, we maintain GDPR-consistent standards, including documented lawful bases, contractual transfer safeguards, and data subject rights workflows. |
We are not presently designated a Significant Data Fiduciary. Should the Central Government designate us as one, we will appoint a Data Protection Officer resident in India, commission independent data audits, and conduct Data Protection Impact Assessments and algorithmic due diligence as required, and we will update this Policy accordingly.
As required by the DPDP Act and the Information Technology Act, we have designated a Grievance Officer to handle privacy complaints, rights requests, and any concern about how we process personal data. Grievances must be submitted in writing; we do not accept verbal submissions.
| Name & Designation | Shainik Jain, Grievance Officer |
| support@insidehunt.com | |
| Phone | +91 90816 10511 · Working Days, 10:00–19:00 IST |
| Privacy & Data Rights | support@insidehunt.com |
| Security Reports | support@insidehunt.com |
| Support & Billing | support@insidehunt.com |
| Registered Office | InsideHunt, Ground Floor, B/07, Ghuma, Ahmedabad, Gujarat 380058, India |
On receipt of a valid written request, the Grievance Officer will acknowledge it within 72 hours, provide a substantive response or resolution within 30 calendar days and in any event within 90 days, and state clearly where any data must be retained by law notwithstanding a deletion request. If you remain dissatisfied, you may escalate to the Data Protection Board of India.
This Policy is the complete and authoritative statement of InsideHunt's privacy practices and supersedes all prior privacy notices issued by this entity, including those published under the Blueberry name.
© 2026 [InsideHunt Technologies Private Limited]. All rights reserved. Privacy Notice v3.0, effective 10 September 2026. Supersedes all prior documents issued under the Blueberry name.