Hello There!

Lorem ipsum dolor sit amet, consectetur adipiscing elit,

Follow Us

INSIDEHUNT


Privacy Policy

Privacy Policy

How InsideHunt collects, uses, stores, shares, and protects personal data — written to satisfy the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and to tell you plainly what happens to your information on an AI-powered platform.

Standing Commitments
  • NO SALE — We do not sell, rent, or licence personal data. There is no exception to this.
  • NO MODEL TRAINING — Identifiable client data is never used to train third-party foundation models.
  • MINIMUM NECESSARY — We collect what the service needs to run — and we tell you why, per field.
  • RIGHTS THAT WORK — Access, correction, erasure, and withdrawal, with defined response windows.
§ 01

Who We Are & What This Policy Governs

This Privacy Policy (the "Policy") is issued by InsideHunt ("InsideHunt," "we," "us," or "our"), a company incorporated under the laws of the Republic of India with its registered office in Ahmedabad, Gujarat, CIN [CIN — to be inserted upon issuance].

InsideHunt operates a growth-intelligence software platform. We apply proprietary analytical frameworks and artificial-intelligence systems to market data, publicly available information, and information supplied by our clients, in order to produce structured intelligence for founder-operators and marketing leadership.

For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025 (the "DPDP Rules"), InsideHunt acts as a Data Fiduciary in respect of the personal data described in this Policy: we determine the purpose and means of its processing, and we carry responsibility for it. You are the Data Principal.

This Policy should be read alongside our Terms of Service. Where a more specific notice is given at the point of collection, that notice prevails for the data collected there.

A NOTE ON THE NAME CHANGE

InsideHunt was previously operated under the name "Blueberry," including as a dual agency-and-reports model. That model has been retired. This Policy replaces the Blueberry Privacy Notice in full. Personal data collected under the Blueberry name continues to be held by the same legal entity and is now governed exclusively by this Policy.

§ 02

Scope & Who This Applies To

This Policy applies to personal data we process in connection with the InsideHunt platform, website, and business operations, in respect of the following categories of individuals:

  • Visitors — anyone who browses insidehunt.com or an associated digital property, whether or not they register.
  • Account holders and Authorised Users — individuals who create an account, activate a trial, or use the platform under a client organisation's subscription.
  • Billing contacts — individuals named for invoicing, tax, or payment purposes.
  • Business contacts and prospects — representatives of organisations we engage with for sales, partnership, investment, or vendor purposes.
  • Subscribers — individuals who opt in to receive intelligence briefings, product updates, or promotional communications.
  • Correspondents — anyone who contacts us by email, form, phone, or messaging channel.

This Policy does not govern personal data processed in our capacity as an employer, nor the practices of any third-party website, agency, vendor, or platform referenced in our intelligence outputs or linked from our website. Those operate under their own policies.

§ 03

Personal Data We Process

We process only such personal data as is proportionate and necessary for the purposes described in this Policy. The table sets out each category, the data points involved, and the lawful basis on which we rely under the DPDP Act — which recognises processing on the basis of consent and on the basis of certain legitimate uses, including performance of a contract with you and compliance with a legal obligation.

Category Data Points Lawful Basis
Identity Full name, professional designation, role, organisation Contract performance
Contact Work email, phone or WhatsApp number, city Contract performance; consent for marketing
Account Username, hashed password, seat and role assignment, authentication events, preferences Contract performance; security
Organisation Company name, website, sector, stage, headcount band, GSTIN and billing address Contract performance; legal obligation
Subscription & billing Plan, billing period, invoices, payment reference and status, e-mandate reference, refund records Contract performance; legal obligation
Client Content Brand, campaign, channel and performance information submitted for analysis, including uploads and integration data Contract performance (see § 07)
Usage & platform Modules run, outputs generated, feature usage, session duration, in-product navigation Legitimate use — service operation and improvement
Technical IP address, device and browser type, operating system, timestamps, referring URL, error logs Legitimate use — security and diagnostics
Analytics & marketing Cross-session behaviour, campaign attribution, ad interaction Consent, via cookie preferences
Communications Emails, form submissions, support tickets, meeting notes, and — where you are told in advance — call recordings Contract performance; legitimate use
Consent records Opt-in and opt-out records, timestamps, consent version, withdrawal history Legal obligation under the DPDP Act
WHAT WE DO NOT COLLECT

We do not collect government identification numbers (Aadhaar, PAN of individuals, passport, driving licence), biometric data, health or medical information, card numbers or bank credentials, or data concerning religious belief, caste, political affiliation, or sexual orientation. Payment instruments are handled entirely by regulated payment service providers; we receive only a transaction reference and status. Where a business PAN or GSTIN is required for tax invoicing, it is processed as organisational data, not as individual identification.

§ 04

How We Collect Personal Data

  • Directly from you — when you register, start a trial, purchase a plan or module, submit an enquiry or intake form, contact support, book a call, or subscribe to a communication.
  • Automatically through the platform — server logs and application telemetry capture technical and usage data whenever the platform is accessed.
  • Through cookies and similar technologies — subject to the preferences you set in our consent banner, as described in § 08.
  • From your organisation — where you are added as an Authorised User by an account administrator, that organisation provides your name, work email, and role.
  • Through integrations you authorise — where you connect a third-party account, we retrieve only the data covered by the permissions you grant, and only for as long as the connection remains authorised.
  • From public and licensed sources — for market intelligence and business-to-business outreach, we may process professional contact and company information from public web sources, company registries, and licensed data providers, limited to information relating to individuals in their professional capacity.
WE WILL NEVER ASK FOR YOUR PASSWORD

InsideHunt will never request your password, one-time password, or payment credentials by email, phone, or message. If you receive such a request purporting to come from us, do not respond — report it to support@insidehunt.com.

§ 05

Why We Process Personal Data

We process personal data only for the purposes set out below. We do not repurpose data beyond the purpose for which it was collected without giving notice and, where required, obtaining fresh consent.

Purpose What This Involves Lawful Basis
Service delivery Provisioning access, running modules, generating and storing outputs, refreshing intelligence Contract performance
Account management Registration, authentication, seat management, preference settings Contract performance
Billing Charging fees, managing e-mandates and renewals, issuing invoices, processing refunds, tax reporting Contract performance; legal obligation
Transactional communication Order confirmations, pre-debit notifications, renewal reminders, output-ready alerts, service and security notices Contract performance; legal obligation
Support Responding to queries, troubleshooting, onboarding assistance Contract performance
Product improvement Diagnosing errors, measuring feature performance, improving frameworks using aggregated and de-identified data Legitimate use
Security & fraud prevention Detecting unauthorised access, abuse, credential sharing, and payment fraud; maintaining audit logs Legitimate use; legal obligation
Marketing Sending briefings, product news, and offers through channels you have opted into Consent
Legal & regulatory Complying with the DPDP Act, the Information Technology Act, the Companies Act, GST law, and any lawful order Legal obligation
Corporate Investor reporting and due diligence using aggregated, non-identifying metrics Legitimate use
§ 06

Artificial Intelligence & Automated Processing

InsideHunt's outputs are generated using artificial-intelligence and machine-learning systems, some of which are operated by third-party providers under contract. This section explains what that means for your data. We consider it the most important section in this Policy.

  • What is sent to AI systems — the content you submit for analysis, together with market and public data assembled by the platform. We minimise personal data in these payloads: analysis operates on brand, category, channel, and performance information, not on individual profiles.
  • No training on your data — we do not use identifiable client content, outputs, or confidential information to train, fine-tune, or improve any general-purpose or third-party foundation model. Where we engage third-party AI providers, we contract for zero-retention or no-training handling wherever such terms are commercially available.
  • Human oversight — outputs are produced by automated systems and, for defined modules, reviewed by our analysts before release. No automated decision is taken that produces a legal effect on you or similarly significantly affects you as an individual.
  • Improving our own frameworks — we improve our methodologies using aggregated and de-identified signals from which no client, user, or individual can reasonably be identified.
  • Accuracy — AI systems are probabilistic and can produce inaccurate or incomplete statements. Outputs are analytical intelligence, not verified fact, and must be independently verified before being relied upon. This is addressed in full in our Terms of Service.
WHAT YOU SHOULD NOT UPLOAD

Do not submit personal data to the platform beyond what a module actually requires, and never submit special-category or sensitive personal data — identification numbers, financial account details, health information, or data about identified consumers — into analysis fields. If you must analyse customer data, aggregate or pseudonymise it first. Where you upload personal data relating to others, you confirm you have a lawful basis to do so.

§ 07

Client Content & Our Role as Processor

Our role under data protection law depends on whose data is at issue.

  • As Data Fiduciary — for personal data of account holders, users, billing contacts, subscribers, correspondents, and visitors. We determine why and how that data is processed, and this Policy governs it.
  • As Data Processor — for any personal data contained within Client Content that a client organisation uploads or connects to the platform. In that case the client organisation is the Data Fiduciary, decides the purpose of processing, and is responsible for having a lawful basis. We process such data solely on that client's documented instructions and for the purpose of delivering the service.

Where we act as a processor, we do not use Client Content for our own purposes, do not disclose it except as instructed or required by law, and will assist the client organisation in responding to rights requests and breach obligations. Client organisations with regulatory requirements may request a separate Data Processing Agreement by writing to support@insidehunt.com.

If you are an individual whose personal data was uploaded to the platform by a client organisation and you wish to exercise rights over it, you should contact that organisation directly. Where you contact us, we will refer your request to them and support their response.

§ 08

Cookies & Tracking Technologies

We use cookies and comparable technologies — including local storage, pixels, and session identifiers — to run the platform, understand how it is used, and measure our marketing. On your first visit, a consent banner lets you accept all, reject all non-essential, or choose by category. You can change or withdraw your choice at any time through the cookie preferences link on the site or through your browser settings.

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, but may reduce functionality. A current inventory of the cookies in use is maintained in our consent manager and updated as our integrations change. Third-party cookies are governed additionally by the policies of the providers concerned.

§ 09

Sharing, Disclosure & Our Processors

We do not sell, rent, licence, or trade personal data. There is no exception to this commitment. Personal data is disclosed only in the defined circumstances below.

Categories of processors we engage

Function Why They Receive Data Data Involved
Cloud hosting & infrastructure Running the platform, storage, backups All categories, encrypted
AI model providers Generating analytical outputs Analysis payloads, minimised for personal data
Payment gateways Collecting fees, managing e-mandates Billing identity, transaction data
Email & messaging delivery Transactional and opted-in marketing messages Name, email, phone, engagement events
Analytics & product telemetry Usage measurement and error diagnostics Technical and usage data
CRM & sales tooling Managing enquiries, pipeline, and client relationships Professional contact and organisational data
Support tooling Handling and tracking support requests Communications data
Professional advisers Accounting, audit, tax, and legal advice Billing and contractual records

A current list of named processors is available on request from support@insidehunt.com. Every processor is assessed before engagement, bound by a written agreement, restricted to processing on our instructions, and prohibited from any independent commercial use of the data.

Other disclosures

  • Legal and regulatory — where required by Indian law, a court order, or a competent authority. Where legally permitted, we will notify you before disclosing.
  • Enforcement and protection — where necessary to investigate fraud, enforce our Terms, or protect the rights, safety, and property of InsideHunt, our clients, or the public.
  • Corporate transactions — in a merger, acquisition, financing, restructuring, or sale of assets, personal data may transfer to the successor entity. We will give at least 15 days' notice and require equivalent protection from the recipient.
  • With your consent — in any other case, only with your express, informed consent.
§ 10

Security Safeguards

We maintain reasonable technical and organisational security safeguards proportionate to the nature and volume of the data we hold, in line with Rule 6 of the DPDP Rules and the Information Technology (Reasonable Security Practices) Rules, 2011. These include:

  • Encryption of data in transit using TLS 1.2 or above, and of data at rest using AES-256 or an equivalent standard.
  • Role-based access control on a least-privilege basis, with access to production data restricted to personnel who require it.
  • Multi-factor authentication for all internal access to production environments.
  • Password hashing with a salted, industry-standard algorithm; we cannot read your password.
  • Logging and monitoring of access to personal data, retained for at least one year to enable detection, investigation, and remediation of incidents.
  • Regular backups, tested restoration procedures, and business-continuity measures.
  • Written data processing agreements and security review for every processor.
  • Confidentiality obligations and security training for personnel and contractors.
  • A documented incident response plan, reviewed periodically.
HONEST LIMITATION

No method of transmission or storage over the internet is completely secure. While we apply rigorous safeguards, we cannot guarantee absolute security. You also carry a share of this: keep your credentials confidential, enable available account protections, and notify us immediately if you suspect unauthorised access.

§ 11

Personal Data Breach Response

If we become aware of a personal data breach affecting your data, we will act on the following basis, consistent with the DPDP Act and the DPDP Rules:

  • Containment — immediate steps to contain the breach, assess the scope, and prevent recurrence.
  • Notification to the Board — intimation to the Data Protection Board of India without delay on becoming aware, followed by detailed particulars within 72 hours, or such longer period as the Board may allow.
  • Notification to you — notification to affected Data Principals without delay, in plain language, describing the nature and extent of the breach, its likely consequences, the measures we have taken, the steps you can take to protect yourself, and where to reach us with questions.
  • Record — maintenance of a record of the breach and our response for regulatory and audit purposes.

Where we act as a processor for a client organisation, we will notify that organisation without undue delay and provide the assistance it needs to meet its own obligations.

§ 12

Retention & Erasure

We retain personal data only for as long as the purpose for which it was collected requires, or for as long as a legal, tax, or contractual obligation requires. When a retention period expires, data is securely deleted or irreversibly anonymised.

Data Retention Reason
Account & profile For the life of the account, then 90 days after closure Contract; dispute window
Client Content & outputs For the life of the subscription, then 30 days' export access and deletion within a further 60 days Contract; client access
Billing, invoices & tax records 8 years from the end of the relevant financial year Companies Act; GST and income-tax law
Consent records Duration of consent plus 3 years after withdrawal Demonstrating DPDP compliance
Technical & usage logs Up to 18 months, then aggregated or deleted Security; product analytics
Security & access logs Minimum 1 year DPDP Rules; incident investigation
Support & correspondence 3 years from last contact Service continuity; disputes
Marketing & prospect data Until consent is withdrawn or 24 months of no engagement Consent; data minimisation
Aggregated, de-identified data Indefinitely No longer personal data

Where the DPDP Rules prescribe erasure after a defined period of user inactivity, we will notify you at least 48 hours before erasure so that you can log in, re-engage, or exercise your rights. Erasure may be deferred where retention is required by law, or where the data is needed to establish, exercise, or defend a legal claim; where that applies, we will tell you.

§ 13

Your Rights as a Data Principal

Under the DPDP Act you hold the following rights in respect of personal data we process about you. These are exercised free of charge.

Access

Obtain a summary of the personal data we process about you, the purposes of processing, and the identities of other Data Fiduciaries and processors with whom it has been shared.

Correction & completion

Have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated.

Erasure

Have your personal data erased where it is no longer needed for the purpose it was collected for, or where you withdraw the consent it rested on — subject to legal retention obligations.

Withdraw consent

Withdraw consent at any time, as easily as it was given. Withdrawal does not affect processing carried out before it, and may limit the services we can provide.

Grievance redressal

Raise a complaint with our Grievance Officer and receive a substantive response, before approaching the Data Protection Board of India.

Nominate

Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, under Section 14 of the DPDP Act.

Portability

Receive personal data you have provided in a structured, commonly used, machine-readable format, where technically feasible. We offer this as a matter of practice.

Object to marketing

Opt out of marketing communications at any time, with immediate effect on receipt of your request.

How to exercise them

Write to support@insidehunt.com, or use the in-account privacy controls where available, stating the right you wish to exercise and enough detail for us to identify your records. We may verify your identity before acting, to prevent unauthorised disclosure of someone else's data.

  • We acknowledge requests within 72 hours.
  • We respond substantively to access, correction, and erasure requests within 30 calendar days, and in any event within the periods prescribed by the DPDP Rules.
  • We resolve grievances within 90 days of receipt at the latest, and normally far sooner.
  • We will not discriminate against you, or degrade your service, for exercising a right.

Your duties. Section 15 of the DPDP Act places duties on you as well: to provide accurate and complete information, not to impersonate another person, not to suppress material information where legally required to disclose it, and not to register a false or frivolous grievance.

If you are dissatisfied with our response, you may escalate to the Data Protection Board of India. We will provide reasonable assistance with that escalation on request.

§ 14

Cross-Border Transfers

We are incorporated in India and prefer infrastructure located in India where practicable. However, several of the services we depend on — cloud infrastructure, AI model providers, analytics, and email delivery — operate globally. Your personal data may therefore be transferred to, stored in, or accessed from jurisdictions outside India, including the United States, the European Union, and Singapore.

Under the DPDP Act, transfers outside India are permitted except to countries restricted by the Central Government. Where a transfer occurs, we maintain safeguards including contractual data protection clauses with each recipient, assessment of the recipient's security posture before engagement, minimisation of the data transferred, and equivalent standards of protection to those described in this Policy. We will not transfer personal data to any jurisdiction the Central Government notifies as restricted, and will re-architect affected processing where such a notification is issued.

§ 15

Marketing Communications

We send intelligence briefings, product updates, and offers by email, WhatsApp, and SMS to people who have opted in. Consent for marketing is collected separately and distinctly from acceptance of our Terms, through a clearly labelled opt-in. We do not pass your contact details to any third party for their own marketing.

  • You can opt out at any time by using the unsubscribe link in any marketing email, replying STOP to a marketing message, adjusting your notification preferences in-account, or writing to support@insidehunt.com.
  • Opt-out requests take effect immediately on receipt and in all cases within 5 Business Days.
  • Opting out of marketing does not stop transactional messages — order confirmations, pre-debit notifications, renewal reminders, security alerts, and service notices — which are necessary to operate your account.
§ 16

Children's Data

The platform is a business tool intended exclusively for individuals aged 18 or above. We do not knowingly collect or process the personal data of children, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children — all of which are prohibited under Section 9 of the DPDP Act.

If we become aware that we hold a child's personal data without verifiable parental consent, we will delete it promptly. Parents or guardians who believe this has occurred should contact support@insidehunt.com.

§ 17

Inactive & Closed Accounts

Where an account has no login, subscription, or substantive platform activity for 24 continuous months, we will write to the registered email address describing the intended action and the data affected. If we receive no response within 30 calendar days, we may archive or delete the account and its associated personal data, subject to mandatory retention obligations. Archived data is isolated from active systems and accessed only for legal, audit, or regulatory purposes.

You may close your account at any time from account settings or by writing to support@insidehunt.com. Closure triggers the retention periods set out in § 12.

§ 18

Changes to This Policy

We may revise this Policy to reflect changes in our services, technology, processors, or legal obligations. Where a change materially affects how your personal data is processed or the rights available to you, we will:

  • Update the "Effective" date and version number at the head of this Policy;
  • Give at least 15 days' advance written notice by email to registered account holders; and
  • Display a prominent notice on the platform for the duration of the notice period.

Where a change requires fresh consent under the DPDP Act, we will seek it rather than rely on continued use. Continued use of the platform after the notice period expires constitutes acknowledgement of the revised Policy. If you do not accept a revision, you may close your account and submit an erasure request under § 13.

§ 19

Compliance Framework

Instrument How We Apply It
DPDP Act, 2023 India's principal data protection statute. We operate as a Data Fiduciary, observing notice, consent, purpose limitation, data minimisation, accuracy, storage limitation, security safeguards, breach reporting, and grievance redressal.
DPDP Rules, 2025 Notified in November 2025 and commencing in phases, with substantive Data Fiduciary obligations applying from May 2027. We are building to those obligations ahead of the deadline — itemised notice, consent records, retention schedules, security logging, and breach procedures are already reflected in this Policy.
Information Technology Act, 2000 Including the Reasonable Security Practices Rules, 2011, and the requirement to publish a Grievance Officer.
Consumer Protection (E-Commerce) Rules, 2020 Transparent disclosure of identity, pricing, cancellation, refund, and grievance mechanisms.
RBI E-Mandate Framework Recurring subscription collections are processed through registered e-mandates with pre-debit notification and additional-factor authentication where required.
GDPR-aligned practice Where we process the personal data of individuals in the EEA or the United Kingdom, we maintain GDPR-consistent standards, including documented lawful bases, contractual transfer safeguards, and data subject rights workflows.

We are not presently designated a Significant Data Fiduciary. Should the Central Government designate us as one, we will appoint a Data Protection Officer resident in India, commission independent data audits, and conduct Data Protection Impact Assessments and algorithmic due diligence as required, and we will update this Policy accordingly.

§ 20

Grievance Officer & Contact

As required by the DPDP Act and the Information Technology Act, we have designated a Grievance Officer to handle privacy complaints, rights requests, and any concern about how we process personal data. Grievances must be submitted in writing; we do not accept verbal submissions.

Grievance Officer
Name & Designation Shainik Jain, Grievance Officer
Email support@insidehunt.com
Phone +91 90816 10511 · Working Days, 10:00–19:00 IST
Privacy & Data Rights support@insidehunt.com
Security Reports support@insidehunt.com
Support & Billing support@insidehunt.com
Registered Office InsideHunt, Ground Floor, B/07, Ghuma, Ahmedabad, Gujarat 380058, India

On receipt of a valid written request, the Grievance Officer will acknowledge it within 72 hours, provide a substantive response or resolution within 30 calendar days and in any event within 90 days, and state clearly where any data must be retained by law notwithstanding a deletion request. If you remain dissatisfied, you may escalate to the Data Protection Board of India.

This Policy is the complete and authoritative statement of InsideHunt's privacy practices and supersedes all prior privacy notices issued by this entity, including those published under the Blueberry name.

© 2026 [InsideHunt Technologies Private Limited]. All rights reserved. Privacy Notice v3.0, effective 10 September 2026. Supersedes all prior documents issued under the Blueberry name.

Chat with us