Privacy Policy
Effective 16 May 2026
This Privacy Policy explains how Kubereum Private Limited (“Kubereum”, “we”, “us”, “our”) collects, uses, discloses, and safeguards personal data when you visit kubereum.com or interact with us.
We act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (collectively, “DPDP Law”).
1. Who we are
Kubereum Private Limited is a company incorporated under the Companies Act, 2013, with CIN U62011DC2026PTC470885 and GSTIN 07AAMCK8251G1Z9. Our registered office is at Karol Bagh, New Delhi, India.
2. What data we collect
This website is currently a static information site. We do not run forms, accounts, payment flows, or other data-collection features on this domain.
The only data we may receive when you visit:
- Network metadata — IP address, user agent, referrer, requested URL, response code, timestamp. Used by our hosting provider (Cloudflare) for delivery, abuse prevention, and security analytics.
- Aggregate analytics — anonymous pageview counts via privacy-first analytics (no cookies, no cross-site tracking, no PII).
- Voluntary contact — if you email us at [email protected] or [email protected], we receive your email address and the contents of your message.
3. Why we process this data
- To deliver the website to your device and prevent abuse
- To understand aggregate traffic patterns and improve the site
- To respond to questions you send us by email
- To comply with applicable law and respond to lawful requests
4. Lawful basis
Under the DPDP Act, we rely on the following grounds:
- Legitimate use — security, abuse prevention, and delivery of the site (Section 7).
- Consent — when you voluntarily email us, you consent to us using that email to reply.
5. Cookies and trackers
This website does not set advertising or cross-site tracking cookies. Cloudflare may set strictly necessary cookies for security (e.g., __cf_bm) and bot mitigation. These cannot be disabled without breaking the site.
6. Sharing
We do not sell personal data. We share data only with:
- Cloudflare, Inc. — content delivery and DDoS protection (data processed under their published privacy commitments).
- Google LLC / Microsoft Corp. — limited interactions when you arrive via their search engines (Search Console / Bing Webmaster verification telemetry).
- Law enforcement — only when legally compelled and after our own verification of the request.
7. Cross-border transfer
Cloudflare may route requests through edge locations outside India for performance reasons. We do not transfer personal data to countries restricted by notification under the DPDP Act.
8. Retention
- Network logs: up to 30 days at our CDN, then deleted.
- Aggregate analytics: up to 12 months, anonymous from the start.
- Email correspondence: retained while the topic is open + up to 36 months thereafter for legal record-keeping.
9. Your rights as a Data Principal
Under the DPDP Act, you have the right to:
- Access a summary of your personal data we hold
- Request correction, completion, updating, or erasure
- Withdraw consent at any time (where consent is the basis)
- Nominate another person to exercise your rights upon death or incapacity
- Lodge a grievance with us (see below) and escalate to the Data Protection Board of India
To exercise any right, email [email protected]. We will respond within statutory timelines.
10. Grievance Officer
Under Rule 5 of the DPDP Rules, 2025, our Grievance Officer is:
Yashej Shah
Co-founder & CEO, Kubereum Private Limited
Email: [email protected]
Postal: Kubereum Private Limited, Karol Bagh, New Delhi, India
We will acknowledge complaints within 72 hours and aim to resolve them within 30 days.
11. Children
This website is not directed at children below the age of 18. We do not knowingly process personal data of children. If you believe we have collected a child's data without verifiable parental consent, please contact us immediately at [email protected].
12. Security
We use reasonable technical and organisational measures including TLS 1.2+ in transit, HSTS, restricted administrative access, and least- privilege controls. See our Security Policy for details and how to report vulnerabilities.
13. Changes
We may update this Privacy Policy as our business or the law evolves. Material changes will be announced on this page with a new effective date.
14. Contact
Privacy questions: [email protected]
General contact: [email protected]