Privacy policy
Last updated: May 5, 2026 · Effective: May 15, 2026
This Privacy Policy describes how Zeverio Animation technology Private Limited (“CineNote”, “Company”, “we”, “us”, “our”), with its registered office at D3 9th Floor, Manyata Tech Park, Venkateshapura, Bangalore, Bangalore North, Karnataka, India, 560045 collects, uses, stores, shares, and protects your personal data when you use the CineNote platform at https://www.cinenote.global and its subdomains, applications, and related services (the “Service”).
This Policy is published in compliance with the Information Technology Act, 2000; the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”); the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; and the Digital Personal Data Protection Act, 2023 (“DPDP Act”) together with rules framed thereunder, as and when brought into force.
For the purposes of the DPDP Act, the Company is the Data Fiduciary and you are the Data Principal.
By using the Service, or by providing your consent where sought, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.
1. Personal Data We Collect
1.1. Information you provide
- Account data: name, email address, password (stored in hashed form), profile photo (optional), and organisation/production details.
- Billing data: billing name, billing address, GSTIN (for business users), and transaction details. Full card/UPI credentials are collected and processed directly by RBI-authorised payment gateways; we do not store them.
- Workspace and content data: scripts, screenplays, beats, boards, notes, lighting plans, shot lists, comments, uploads, and other materials you create or upload (“User Content”), along with version history and snapshots.
- Collaboration data: workspace memberships, roles, permissions, invitations (invitee email addresses), and audit-trail entries.
- Communications: messages you send to support, feedback, and survey responses.
1.2. Information collected automatically
- Usage data: features used, pages visited, actions performed, timestamps, export activity.
- Device and log data: IP address, browser type and version, operating system, device identifiers, referral URLs, and error logs.
- Cookies and similar technologies: see Section 8.
1.3. Information from third parties
- Authentication providers (if you sign in via a third-party login), payment gateways (transaction status), and analytics providers.
We do not knowingly collect sensitive personal data (such as financial account passwords, health data, or biometric data) beyond what is stated above. Please do not upload such data to the Service.
2. Purposes of Processing
We process your personal data for the following purposes:
(a) creating and administering your account and workspaces;
(b) providing the Service, including hosting, syncing, versioning, and exporting your content;
(c) enabling collaboration — displaying your name, role, and activity to other members of your workspaces in accordance with configured permissions;
(d) processing payments, issuing GST-compliant invoices, and maintaining financial records;
(e) providing customer support and responding to your requests;
(f) sending service communications (security alerts, billing notices, changes to terms or features);
(g) sending marketing communications, only with your consent, which you may withdraw at any time;
(h) monitoring, securing, and improving the Service, including debugging, analytics, and fraud prevention;
(i) enforcing our Terms and Conditions and protecting our legal rights;
(j) complying with applicable law, court orders, and lawful requests of governmental authorities.
3. Lawful Basis and Consent
3.1. We process your personal data on the basis of your consent, given when you sign up, and for certain legitimate uses recognised under the DPDP Act, including voluntary provision of data for a specified purpose, compliance with law, and responding to medical or safety emergencies.
3.2. Your consent is free, specific, informed, unconditional, and unambiguous, given through clear affirmative action, and is limited to the purposes stated in this Policy.
3.3. Withdrawal of consent. You may withdraw your consent at any time by adjusting your account settings or writing to us at admin@zeverio.com. Withdrawal will not affect the lawfulness of processing carried out before withdrawal. Upon withdrawal, we may be unable to provide some or all of the Service, and we will cease processing your personal data within a reasonable time, unless retention is required or permitted by law.
3.4. Where consent is to be managed through a Consent Manager registered with the Data Protection Board of India, you may give, manage, review, or withdraw consent through such Consent Manager, as and when the relevant framework is operational.
4. Sharing and Disclosure
We do not sell your personal data. We share personal data only as follows:
(a) Workspace members: your name, profile information, role, and activity are visible to other members of workspaces you join, per configured permissions. Content in a workspace is accessible to members as per their roles. Read-only share links expose linked content to anyone holding the link.
(b) Data Processors / service providers: cloud hosting and storage providers, payment gateways, email and communication providers, analytics providers, and customer-support tooling — each bound by contractual obligations to process data only on our instructions and with appropriate safeguards.
(c) Legal and regulatory: where required under applicable law, or pursuant to court orders, or lawful requests from governmental or law-enforcement authorities, including under the IT Act and rules thereunder.
(d) Business transfers: in connection with a merger, acquisition, restructuring, or sale of assets, subject to this Policy or an equivalent standard of protection, and applicable law.
(e) Protection of rights: where necessary to enforce our Terms, protect the rights, property, or safety of the Company, our users, or the public.
5. Cross-Border Transfer of Data
Your personal data may be stored on, or processed by, cloud infrastructure located in India and/or in other countries. Transfers of personal data outside India are undertaken in compliance with the DPDP Act, and will not be made to any country or territory restricted by the Central Government by notification. Where data is transferred abroad, we ensure our processors provide a standard of protection comparable to that described in this Policy.
6. Data Retention
6.1. We retain personal data only for as long as necessary to fulfil the purposes stated in this Policy, to provide the Service, or as required under applicable law (including tax, accounting, and record-keeping obligations under Indian law).
6.2. Upon deletion of your account, or withdrawal of consent, we will delete your personal data and cause our processors to delete it, unless retention is necessary for compliance with law, for resolving disputes, or for enforcing agreements. Residual copies in encrypted backups are purged in the ordinary backup rotation cycle.
6.3. Where you have not used the Service or approached us for the performance of the specified purpose for such period as may be prescribed under the DPDP rules, we will erase your personal data unless retention is required by law.
7. Security of Your Data
7.1. We implement reasonable security safeguards and practices as required under Section 43A of the IT Act read with the SPDI Rules, and Section 8(5) of the DPDP Act, including:
- encryption of data in transit (TLS) and at rest;
- hashed storage of passwords;
- content-addressed, checksum-verified (SHA-256) versioning of documents;
- role-based access control enforced at the gateway, service, and database-row level;
- audit trails of workspace activity;
- access controls, logging, and periodic review of our systems and processes.
7.2. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the form and manner prescribed under the DPDP Act and rules.
7.3. No system is completely secure. You are responsible for keeping your credentials confidential and for the distribution of any share links you generate.
8. Cookies and Tracking
8.1. We use cookies and similar technologies for:
- Essential purposes: authentication, session management, security, and load balancing (these cannot be disabled without affecting the Service);
- Preferences: remembering settings such as editor preferences;
- Analytics: understanding usage patterns to improve the Service.
8.2. You can manage cookies through your browser settings. Disabling essential cookies may prevent you from using parts of the Service.
9. Your Rights as a Data Principal
Subject to the DPDP Act and applicable rules, you have the right to:
(a) Access: obtain a summary of your personal data being processed, the processing activities, and the identities of Data Fiduciaries and Processors with whom it has been shared;
(b) Correction and erasure: seek correction of inaccurate or misleading data, completion of incomplete data, updating of data, and erasure of data no longer necessary for the specified purpose;
(c) Grievance redressal: a readily available means of grievance redressal (see Section 11);
(d) Nomination: nominate another individual to exercise your rights in the event of your death or incapacity;
(e) Withdraw consent: as described in Section 3.3.
You may exercise these rights through your account settings (for self-service actions such as profile edits, exports, and account deletion) or by writing to admin@zeverio.com with sufficient details to verify your identity. We will respond within the timelines prescribed under applicable law.
Your duties: Under the DPDP Act, you must not impersonate another person, suppress material information, register false or frivolous grievances or complaints, or furnish false particulars while exercising your rights.
10. Children’s Data
The Service is intended for users aged 18 and above. We do not knowingly process the personal data of children (persons under 18 years of age). We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us personal data, contact us at admin@zeverio.com and we will delete it. Where processing of a child’s data is ever necessary, it will be undertaken only with verifiable consent of the parent or lawful guardian, in the manner prescribed under the DPDP Act.
11. Grievance Officer and Contact
In accordance with the IT Act, the SPDI Rules, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, you may contact:
Grievance Officer
Name: Subash kandasamy
Designation: Data Protection officer
Email: tech@zeverio.com
Grievances will be acknowledged within 24 hours and resolved within 15 days, or within such other period as may be prescribed under applicable law.
If you are not satisfied with our response, you may approach the Data Protection Board of India in the manner prescribed under the DPDP Act.
12. Third-Party Links and Services
The Service may contain links to third-party websites or integrate third-party services (including payment gateways and export destinations). This Policy does not apply to those third parties. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Policy from time to time to reflect changes in law, technology, or our practices. Material changes will be notified through the Service or by email, and the “Last Updated” date will be revised. Where required by law, we will seek fresh consent. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
14. Contact Us
Zeverio Animation technology Private Limited
D3 9th Floor, Manyata Tech Park, Venkateshapura, Bangalore, Bangalore North, Karnataka, India, 560045
Email: admin@zeverio.com
Website: https://www.cinenote.global/contact