Privacy Policy

1. Introduction

This Privacy Policy ("Policy") describes how Arissa International Private Limited ("Arissa", "we", "us", or "our") collects, uses, stores, shares, and protects personal data of users ("you", "your", or "User") who access or use the networking platform available at networking.arissainternational.com (the "Platform").

The Platform is a professional networking service designed to help individuals connect, share referrals, and discover business opportunities through a structured Gives-and-Asks matching system.

We are committed to protecting your privacy in compliance with applicable data protection laws. Because our Users are located across multiple jurisdictions, this Policy applies to different legal frameworks depending on where you are located:

User LocationApplicable LawKey Rights Section
IndiaDPDP Act 2023 · IT Act 2000 · SPDI RulesSections 7, 12
European Union / EEAGDPR (EU) 2016/679Section 19A
United KingdomUK GDPRSection 19A
California, USACCPA / CPRASection 19B
All other countriesGDPR-standard practices appliedSection 19A

By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree, you must not use the Platform.

2. Definitions
  • "Personal Data" means any data about an individual who is identifiable by or in relation to such data, in digital form, as defined under the DPDP Act. Under GDPR, this includes any information relating to an identified or identifiable natural person.
  • "Form 1 Submitter" means an individual who has submitted the pre-registration discovery form on the Platform but has not yet created a registered account.
  • "Registered User" means an individual who has created an Account on the Platform.
  • "Contact Record" means a profile of a third-party individual entered into the Platform by a Registered User or Arissa administrator, where that individual has not themselves registered on the Platform.
  • "Data Principal" / "Data Subject" means the individual to whom the Personal Data relates — in this Policy, this refers to you, whether you are a Form 1 Submitter, a Registered User, or a Contact Record subject.
  • "Data Fiduciary" / "Controller" means the entity that determines the purpose and means of processing of Personal Data — in this Policy, this refers to Arissa.
  • "Data Processor" means any person or entity that processes Personal Data on behalf of a Data Fiduciary.
  • "Processing" means any operation performed on Personal Data, including collection, recording, organisation, storage, retrieval, use, disclosure, or erasure.
  • "Consent" means the free, specific, informed, unconditional, and unambiguous indication of your wishes by clear affirmative action.
  • "Gives and Asks" means the professional services, referrals, or resources a User can offer (Gives) and the professional connections, services, or resources a User is seeking (Asks).
  • "Contact Sphere" means one of the fifteen (15) categories of professional contacts suggested by the Platform's AI based on a Registered User's declared Gives.
  • "Sensitive Personal Data" has the meaning ascribed to it under Rule 3 of the SPDI Rules, including financial information, passwords, and biometric information.
  • "DPDP Act" means the Digital Personal Data Protection Act, 2023 (India).
  • "DPDP Rules" means the Digital Personal Data Protection Rules, 2025.
  • "GDPR" means the General Data Protection Regulation (EU) 2016/679.
  • "CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CPRA").
3. Applicability and Scope

This Policy applies to:

  • Form 1 Submitters who complete the pre-registration discovery form, regardless of whether they proceed to register;
  • Registered Users who sign up for the Platform, regardless of their country of residence;
  • Individuals whose Contact Records are entered into the Platform by Registered Users or Arissa administrators;
  • Visitors to networking.arissainternational.com.

The Platform is available to users located in India and internationally. Arissa International Private Limited is incorporated in India and processes all data on servers located in India (AWS Mumbai region). Users and Contact Record subjects located outside India acknowledge that their Personal Data is transferred to and processed in India.

Where applicable law in your jurisdiction provides specific rights or protections, those are addressed in Sections 19A and 19B.

4. Identity of the Data Fiduciary / Controller
Legal NameArissa International Private Limited
Grievance Emailinfo@arissainternational.com
Websitenetworking.arissainternational.com
5. Personal Data We Collect

We collect Personal Data in three distinct ways — through the pre-registration discovery form (Form 1), directly from Registered Users (Form 2 and account data), and through Contact Records entered by Registered Users or Arissa administrators.

5.0 Pre-Registration Data — Form 1 (Discovery Form)

Before creating an account or making any payment, individuals may submit a pre-registration discovery form on the Platform. This form collects:

  • Basic personal information: full name, email address, phone number, city
  • Professional information: job title, company name, industry
  • Gives: the professional services, referrals, or resources the individual can offer
  • Asks: the professional connections, services, or resources the individual is seeking
  • Companies they refer: names of businesses or individuals they are willing to refer

Users should not enter sensitive personal data, financial account details, health information, government identification numbers, passwords, or confidential third-party information into meeting notes, Contact Records, Gives, Asks, or referral notes unless they have a lawful basis and the individual's permission.

How Form 1 data is used: Upon submission of Form 1, the Platform automatically cross-matches the submitter's declared Gives and Asks against all other Form 1 submitters in the database. A match report in PDF format — showing the names, Gives, Asks, and company details of matching individuals — is generated and sent to Arissa administrators by email. This PDF is for internal use only and is not shared with the Form 1 submitter or any other third party.

Consent at Form 1: Before submitting Form 1, individuals are required to confirm via a mandatory checkbox that they agree to the following:

Submission without checking this box is not permitted.

Retention of Form 1 data: If a Form 1 Submitter does not proceed to register on the Platform, their Form 1 data will be retained for a maximum of thirty (30) days from the date of submission, after which it will be permanently deleted. If the Form 1 Submitter proceeds to register, their Form 1 data is carried forward into their Registered User account. Form 1 Submitters may request deletion of their data at any time before the 30-day period expires by writing to info@arissainternational.com.

5.1 Data Collected from Registered Users

CategoryExamplesSource
Account & RegistrationName, email, mobile, title, organisation, cityYou (direct)
Professional ProfileGives, Asks, expertise, business categories, business description, websiteYou (direct — Form 2)
Networking ContentMeeting history, referrals, introductions, meeting notesYou (direct)
Contact Sphere DataCustomer names, job titles, company names, contact details of target audienceYou (direct — Form 2)
Payment (India)Billing name, address, GSTIN — card data held by RazorpayYou + Razorpay
Payment (International)Remittance details: sender name, bank reference, amountBank wire / invoice
Technical & DeviceIP address, device type, OS, browser, timezoneAutomatic
Usage & AnalyticsPages visited, features used, session durationAutomatic
AI-Inferred DataContact sphere suggestions, connection scores, topic affinity, engagement patternsDerived from your Gives

5.2 Data Collected as Contact Records

The Platform enables both Registered Users and Arissa administrators to enter Contact Records of individuals they have personally met in a networking context. This works as follows:

  • Registered Users may enter the details of individuals they have met at networking events, meetings, or other professional interactions outside the Platform.
  • Arissa administrators may also enter the details of individuals they or the platform team have met in a networking context, on their own behalf.
  • Visibility: A Registered User can see only the Contact Records they have personally entered. Arissa administrators can see all Contact Records entered by all users and administrators across the Platform.

When a Contact Record is created, we collect and store:

  • Full name
  • Contact information (email address, phone number)
  • Company name and professional title
  • Areas of expertise, Gives and Asks as described by the entering user or administrator
  • Any notes added by the entering user or administrator

Important: Contact Records relate to individuals who have not registered on the Platform. If your details have been entered as a Contact Record, please read Section 5.3 and Section 12B below for your rights.

5.3 How Contact Record Subjects Are Notified

At the exact moment a Contact Record form is submitted — whether by a Registered User or an Arissa administrator — the Platform automatically sends a notification email to the contact's email address. This notification states:

  • Who added them and the networking context in which they were met;
  • What personal data was entered into the Platform, including their name, contact details, company, job title, and Gives and Asks as described by the entering user;
  • That this data is stored on Arissa's Platform at networking.arissainternational.com;
  • Their right to access, correct, or request deletion of their record;
  • A one-click opt-out link that permanently and immediately deletes their Contact Record from the Platform upon clicking, with no login or account creation required.

Contact Records are visible only to the Registered User who entered them and to Arissa administrators. They are never shared with other Registered Users and are never used in AI matching or recommendation features.

The user or administrator entering a Contact Record is responsible for ensuring that the information is accurate, was collected in a lawful networking context, and is not entered for spam, harassment, profiling, or unlawful solicitation.

Failed Notification: If the notification email cannot be delivered because the email address entered is invalid or non-existent, the Contact Record will be flagged in the Arissa administrator panel as "notification undelivered." Arissa will delete the flagged Contact Record within forty-eight (48) hours of the failed delivery alert. The submitting user will be notified that the Contact Record has been deleted due to notification failure and asked to verify the contact's email address before re-entering the record.

5.4 Payment Data — Important Note

For Indian subscribers, payments are processed by Razorpay Software Private Limited. Arissa does not store full card or UPI details. Razorpay's privacy policy is available at razorpay.com/privacy.

For international subscribers, payments are made via bank wire transfer against invoices issued by Arissa. We receive and retain inward remittance details, including sender name, bank reference, and transaction amount, solely for payment reconciliation and statutory accounting purposes.

Upon completion of payment — whether by Indian or international subscribers — an invoice is automatically generated and sent to the paying user's registered email address. This invoice contains transaction details, including the plan purchased, amount paid, applicable taxes, and payment reference number.

6. Purposes of Processing

6.1 For Form 1 Submitters

We process Form 1 data for the following purposes:

  1. To assess whether the individual's Gives and Asks match with other Form 1 submitters in our networking database;
  2. To generate an internal match report in PDF format for review by Arissa administrators;
  3. To follow up with the individual regarding registration on the Platform;
  4. To comply with applicable laws and lawful requests from government authorities.

Form 1 data is not used for marketing, advertising, or any purpose beyond those listed above without separate consent.

6.2 For Registered Users

We process your Personal Data for the following purposes:

  1. To create and manage your User account;
  2. To enable core Platform functionality including Business Connect, Meetings, Referrals and Introductions, Reports, and AI-assisted Insights;
  3. To match you with relevant connections using AI-assisted analysis of your declared Gives, past interactions, and behavioral signals;
  4. To generate AI-suggested contact spheres — specifically, to suggest fifteen (15) relevant contact categories based on your declared Gives;
  5. To process subscription payments, generate invoices, and manage your subscription lifecycle;
  6. To send transactional communications, including welcome emails, payment receipts, invoices, and account notifications;
  7. To send promotional and marketing communications, subject to your consent and right to opt out;
  8. To improve, secure, and optimize the Platform;
  9. To improve our AI models using aggregated, anonymized, or de-identified data. We do not use identifiable Personal Data for AI model training unless we obtain separate consent where required by applicable law.
  10. To respond to your queries, support requests, and grievances;
  11. To comply with applicable laws and lawful requests from government authorities;
  12. To establish, exercise, or defend legal claims;
  13. To retain logs and records as required under applicable law.

6.3 For Contact Records

We process Contact Record data for the following purposes:

  1. To store networking contact information on behalf of the Registered User or administrator who entered it;
  2. To send the mandatory notification email to the contact at the exact moment of record creation;
  3. To enable the contact to exercise their rights, including access, correction, and deletion;
  4. To comply with applicable laws and lawful requests from government authorities.

Contact Record data is not used for AI matching, marketing, or any purpose beyond those listed above.

7. Consent and Point-of-Collection Notice

7.1 Form 1 Submitters

Consent for Form 1 data processing is obtained at the point of submission via a mandatory checkbox as described in Section 5.0. Submission of Form 1 without checking the consent box is not permitted.

Form 1 Submitters may withdraw consent and request deletion of their data at any time within the 30-day retention period by writing to info@arissainternational.com. Deletion will be actioned within forty-eight (48) hours of receipt.

7.2 Registered Users

We rely on your free, specific, informed, and unambiguous consent for processing your Personal Data, except where processing is permitted under legitimate uses as defined under the DPDP Act, or on another lawful basis as set out in Section 19A for EEA and UK users.

You provide consent at the time of registration by affirmatively accepting the applicable consent notice and acknowledging this Policy. For additional processing activities such as marketing communications or AI model training, we will obtain separate consent.

Withdrawing consent: You may withdraw your consent at any time through the in-app consent settings available under Account Settings, or by writing to our Grievance Officer (Section 18). Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Withdrawing consent may result in our inability to provide certain Platform features or the deactivation of your account.

The in-app consent settings allow you to manage:

  • Marketing communication preferences
  • AI-assisted processing opt-in/opt-out
  • Cookie preferences via the Cookie Settings link in the Platform footer

Withdrawal through in-app settings takes effect immediately. Withdrawal by email to the Grievance Officer will be actioned within forty-eight (48) hours of receipt.

7.3 Point-of-Collection Consent Notice

In accordance with the DPDP Act and Rules, we provide a concise, standalone Consent Notice at the point of registration, separate from this full Policy. That notice itemizes:

  • The categories of Personal Data being collected;
  • The specific purposes for which it is collected;
  • How to exercise your rights as a Data Principal;
  • How to withdraw consent; and
  • How to raise a complaint with the Data Protection Board of India.

The Consent Notice is available in English and, on request, in other Scheduled Languages as recognized under the Eighth Schedule of the Constitution of India. To request it in another language, write to info@arissainternational.com. In the event of any conflict between the Consent Notice and this Policy, the Consent Notice shall govern with respect to the specific processing activity described therein.

7.4 Contact Record Subjects

For individuals whose details are entered as Contact Records, the legal basis for initial processing is the legitimate networking interest of the Registered User or administrator who entered the record, combined with the immediate transparency notification email sent at the exact moment of entry. If a contact exercises their opt-out right via the one-click link, their record is deleted immediately and permanently.

8. AI-Assisted Processing and Automated Decision-Making

8.1 What the AI Systems Do

Our AI systems process Personal Data of Registered Users to:

  • Suggest 15 contact spheres: Based on your declared Gives, the AI analyses your professional profile and suggests fifteen (15) relevant contact categories — types of people or businesses you should connect with to maximise your networking outcomes;
  • Match connections: Analyse declared Gives, Asks, professional profile, and past interactions to suggest other Registered Users you may benefit from connecting with;
  • Surface insights and recommendations to widen your contact sphere and identify networking opportunities;
  • Prioritise introductions, referrals, and meeting opportunities based on relevance to your Gives and Asks;
  • Generate reports summarising your networking activity and outcomes.

AI features use only data provided by Registered Users. Contact Records of non-registered individuals are never used in AI processing. Form 1 data of non-registrants is used only for internal match reporting as described in Section 5.0 and is not fed into the registered user AI system.

8.2 Logic and Significance

Our AI systems compute similarity, relevance, and complementarity scores between Registered Users based on explicit signals (declared Gives and Asks) and implicit signals (engagement patterns). For contact sphere suggestions, the AI maps your declared Gives against known professional networking patterns to identify the fifteen most relevant categories of contacts for your specific professional profile. AI outputs are suggestions only — not binding decisions. You retain full discretion to accept, ignore, or reject any AI-generated recommendation.

8.3 AI Output Limitations

AI systems may produce results that are inaccurate, incomplete, or biased. We cannot guarantee that every match or contact sphere suggestion will be relevant, accurate, or result in a business outcome. Exercise independent professional judgment before acting on any AI-generated suggestion.

8.4 Your Rights in Relation to AI Processing

You may at any time:

  • Opt out of AI-generated recommendations via Account Settings or by writing to our Grievance Officer;
  • Request human review of any AI-generated outcome that materially affects your use of the Platform;
  • Request correction of the underlying data inputs the AI relies upon;
  • Request information about the categories of data used to generate your recommendations.

8.5 Use of Third-Party AI Models

We may use third-party AI/ML services for Insights features. We select providers that offer appropriate confidentiality commitments, transmit only the data necessary for the function, and do not authorize such providers to train their general-purpose models on identifiable Platform data.

9. Disclosure and Sharing of Personal Data

We do not sell your Personal Data. We share Personal Data only as described below.

9.1 Data Processors and Service Providers

CategoryProviderPurpose
Cloud InfrastructureAmazon Web Services (AWS) — Mumbai regionHosting and database
Payment (India)Razorpay Software Private LimitedSubscription payment processing and automatic invoice generation to registered email
Payment (International)Bank wire / invoice systemInternational subscription billing; invoice sent automatically to registered email on payment confirmation
AnalyticsGoogle Analytics (Google LLC)Usage analysis and reporting
CRM & MarketingHubSpot, Inc.Contact management and tracking
Email / CommsHubSpotTransactional emails including invoices, account notifications, contact record notifications, and Form 1 match report delivery to administrators

9.2 Within the Platform

Your professional profile, declared Gives and Asks, and networking activity are visible to other Registered Users and Arissa administrators in accordance with the Platform's design. After Form 2 submission, your profile becomes available to Arissa administrators and, where applicable, to other Registered Users for networking and referral matching purposes. Contact Records you enter are visible only to you and Arissa administrators — never to other Registered Users. Form 1 match reports are visible only to Arissa administrators and are never shared with other users.

Registered Users must use other Users' profile information, Gives, Asks, referrals, introductions, and networking activity only for legitimate networking purposes and must not copy, export, scrape, resell, or misuse such information.

9.3 Legal and Regulatory Disclosures

We may disclose Personal Data to comply with applicable laws, court orders, or lawful directives from government authorities, including under the IT Act, the DPDP Act, the Code of Criminal Procedure, and CERT-In Directions, 2022.

9.4 Business Transfers

In the event of a merger, acquisition, or sale of assets involving Arissa, your Personal Data may be transferred to the relevant successor entity, subject to the same protections under this Policy.

10. Cross-Border Transfer of Personal Data

All Personal Data is stored on AWS servers in India (Mumbai region). For users and Contact Record subjects located outside India, processing in India constitutes a cross-border transfer.

For EEA and UK users, transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, or on the basis of explicit consent at the point of Form 1 submission or registration, as described in Section 19A.3.

We do not rely on the EU-U.S. Data Privacy Framework (Arissa is not a U.S.-based entity) and do not rely on the now-invalid EU-U.S. Privacy Shield.

11. Data Retention

11.1 Form 1 Data

Form 1 data of individuals who do not proceed to register on the Platform will be retained for a maximum of thirty (30) days from the date of submission, after which it will be permanently deleted.

Form 1 data of individuals who proceed to register is carried forward into their Registered User account and retained in accordance with Section 11.2.

Form 1 Submitters may request deletion of their data at any time within the 30-day period by writing to info@arissainternational.com.

Deletion from active systems may occur immediately or within the stated period, but residual copies may remain in encrypted backups for a limited period until overwritten in the ordinary course of backup rotation.

11.2 Registered User Data

Personal Data associated with your active account is retained for the duration of your subscription. Upon account closure or withdrawal of consent, we will erase your Personal Data within a reasonable period, subject to Sections 11.4 and 11.5.

11.3 Contact Record Data

Contact Records are retained for as long as the Registered User or administrator who entered them maintains an active account, or until:

  • The contact exercises their one-click opt-out, in which case the record is deleted immediately and permanently; or
  • The Registered User deletes the record manually; or
  • The Registered User's account is closed, in which case all their Contact Records are deleted within thirty (30) days; or
  • If the notification email fails to deliver, the record is deleted within forty-eight (48) hours of the failed delivery alert.

11.4 Mandatory Retention Periods

In accordance with Rule 8 of the DPDP Rules and other applicable laws, we retain:

  • Processing logs and associated records: retained for at least one (1) year, or for such period as required under applicable law, for audit, investigation, security, and accountability purposes.
  • Tax, accounting, and corporate records: For periods specified under the Income Tax Act, 1961, the Companies Act, 2013, and applicable GST laws.
  • Cyber-security logs: A minimum of one hundred and eighty (180) days as required under CERT-In Directions, 2022.
  • Litigation-related records: For the duration of any pending or anticipated legal proceedings.

11.5 Advance Notice Before Erasure

Prior to erasing your Personal Data at the end of the applicable retention period, we will notify you at least forty-eight (48) hours in advance by email to your registered address and via in-Platform notification. The Pre-Erasure Notice will state:

  • That your Personal Data is scheduled for erasure on a specified date;
  • The categories of data to be erased;
  • That you may log in or re-engage before that date to retain your data;
  • That if no action is taken, erasure will proceed as scheduled.
12. Your Rights as a Registered User

Subject to applicable law, you have the following rights:

  • Right to Access: To obtain a summary of the Personal Data being processed by us.
  • Right to Correction and Erasure: To request correction of inaccurate data or erasure of data no longer necessary.
  • Right to Data Portability: To request a copy of your Personal Data in a structured, machine-readable format.
  • Right to Grievance Redressal: To register a grievance, addressed within ninety (90) days.
  • Right to Nominate: To nominate another individual to exercise these rights in the event of death or incapacity.
  • Right to Withdraw Consent: Via in-app Account Settings or by writing to the Grievance Officer — see Section 7.2.
  • Rights in Relation to AI Processing: As described in Section 8.4.

To exercise any of these rights, contact our Grievance Officer (Section 18). We may require verification of your identity before we can action any request.

12A. Rights of Form 1 Submitters

If you have submitted Form 1 but have not registered on the Platform, you have the following rights:

  • Right to Know: You were informed at the point of Form 1 submission how your data would be used — see Section 5.0.
  • Right to Delete: Write to info@arissainternational.com at any time within thirty (30) days of your Form 1 submission to request immediate deletion of your data. We will action this within forty-eight (48) hours.
  • Right to Access: Write to info@arissainternational.com to request details of what data is stored about you.
  • Right to Correct: Write to info@arissainternational.com to request correction of any inaccurate details in your Form 1 submission.

After thirty (30) days from submission, your Form 1 data will have been deleted and no further action is required.

12B. Rights of Contact Record Subjects

If your details have been entered into the Platform as a Contact Record without your prior registration, you have the following rights:

  • Right to Know: You will be notified by email immediately upon entry of your record — see Section 5.3.
  • Right to Delete: Use the one-click opt-out link in the notification email to permanently delete your record immediately, with no login required.
  • Right to Access: Write to info@arissainternational.com to request details of what data is stored about you.
  • Right to Correct: Write to info@arissainternational.com to request correction of any inaccurate details in your record.
  • Right to Object: If you believe your data has been entered without a legitimate networking basis, write to info@arissainternational.com, and we will review and delete the record within forty-eight (48) hours.

We will action all Contact Record subject requests within forty-eight (48) hours of receipt.

13. Cookies and Similar Technologies

We use cookies and similar tracking technologies to operate the Platform, enable session management, remember preferences, and analyse usage patterns.

CategoryExamplesCan it be disabled?Consent required?
Strictly NecessarySession, auth, security tokensNoNo
FunctionalLanguage, layout, notification preferencesYesYes
Performance & AnalyticsGoogle Analytics, HubSpot trackingYesYes

13.1 Third-Party Trackers Currently Active on the Platform

13.2 Cookie Consent and Management

We use a cookie consent banner to obtain consent before setting non-essential cookies. You can manage your cookie preferences at any time via the Cookie Settings link in the Platform footer.

13.3 Third-Party Tracking

We do not use advertising pixels or permit third-party advertising networks to track users across the Platform. We do not run retargeting campaigns.

14. Security Safeguards

We implement reasonable security practices in compliance with Rule 8 of the SPDI Rules, the DPDP Rules, and CERT-In Directions, 2022, including:

  • Encryption of Personal Data in transit (TLS/HTTPS) and at rest;
  • Role-based access controls and least-privilege access;
  • Multi-factor authentication for administrative access;
  • Regular vulnerability assessments and penetration testing;
  • Logging and monitoring of access to Personal Data;
  • Periodic backups and disaster recovery arrangements;
  • Vendor due diligence and contractual security safeguards;
  • Employee training on data protection and confidentiality.

14.1 Personal Data Breach Notification

In the event of a breach, we will notify the Data Protection Board of India and all affected individuals in the manner and within the timelines prescribed under the DPDP Rules. For EEA and UK users, we will notify the relevant supervisory authority within seventy-two (72) hours, as required under the GDPR.

15. Children's Data

The Platform is intended for individuals eighteen (18) years of age or older. We do not knowingly collect Personal Data of individuals under eighteen (18). If we become aware of such data, we will erase it without delay.

16. Third-Party Links

The Platform may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their policies before sharing any Personal Data.

17. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified through the Platform or by email. The "Last Updated" date indicates when it was last revised. Continued use after notification constitutes acceptance of the updated Policy.

18. Grievance Redressal and Grievance Officer
Grievance OfficerArissa International Private Limited
Emailinfo@arissainternational.com
Phone+1 (302) 404-2147
Working HoursMonday to Friday, 10:00 AM – 6:00 PM IST

We will acknowledge receipt of grievances within twenty-four (24) hours. General grievances will be resolved within fifteen (15) days in accordance with IT Rules 2021. Grievances relating to the processing of Personal Data will be resolved within ninety (90) days as required under the DPDP Rules, 2025. If dissatisfied, you may approach the Data Protection Board of India.

19. Contact Us
CompanyArissa International Private Limited
Emailinfo@arissainternational.com
Websitenetworking.arissainternational.com
19A. Additional Rights for EEA and UK Users (GDPR / UK GDPR)

If you are located in the EEA, the UK, or Switzerland, the following provisions apply under the GDPR and the UK GDPR.

19A.1 Lawful Basis for Processing

  • Performance of a contract (Article 6(1)(b)): To create and manage your account, enable Platform features, process payments, and deliver subscribed services.
  • Legitimate interests (Article 6(1)(f)): To prevent fraud, ensure platform security, improve our services, for Form 1 internal match reporting where the submitter has consented, and for Contact Record processing where the entering user or administrator has a legitimate networking basis.
  • Consent (Article 6(1)(a)): For Form 1 data processing, marketing communications, non-essential cookies, and AI-assisted processing. Withdrawable at any time.
  • Legal obligation (Article 6(1)(c)): Where processing is required by applicable law.

19A.2 Your Rights Under GDPR

In addition to Sections 12, 12A, and 12B, EEA and UK users have:

  • Right to object: To processing based on legitimate interests or for direct marketing.
  • Right to restriction: To restrict processing in certain circumstances.
  • Right to lodge a complaint: With your local supervisory authority. For EEA users, your national data protection authority. For UK users — the Information Commissioner's Office (ico.org.uk).
  • Right not to be subject to solely automated decisions: Where a decision produces significant effects, you may request human review — see Section 8.4.

19A.3 International Data Transfers

India does not currently have an adequacy decision under GDPR. Transfers from the EEA or the UK to India are conducted under Standard Contractual Clauses (SCCs) pursuant to Article 46 GDPR, or on the basis of explicit consent upon submission of Form 1 or registration. We do not rely on the EU-U.S. Data Privacy Framework or the invalid EU-U.S. Privacy Shield.

19A.4 Retention for EEA / UK Users

We apply retention periods in Section 11. Where GDPR's storage limitation principle (Article 5(1)(e)) requires a shorter retention period, we apply the shorter period. For Form 1 Submitters in the EEA or UK who do not register, the 30-day retention period applies regardless.

19A.5 Response Times

We respond to GDPR requests within thirty (30) days, extendable by two further months for complex requests with prior notification.

19A.6 Contact for EEA / UK Requests

Write to info@arissainternational.com. No fee is charged unless requests are manifestly unfounded or excessive.

19B. Additional Rights for California Residents (CCPA / CPRA)

19B.1 Categories of Personal Information Collected

In the preceding twelve (12) months, we have collected:

  • Identifiers: Name, email, mobile, IP address, username;
  • Commercial information: Subscription and payment records;
  • Internet activity: Usage data, session information, cookie data;
  • Professional information: Job title, organisation, industry, expertise, Gives and Asks, business description;
  • Contact sphere data: Customer names, job titles, company names, contact details of the target audience;
  • Inferences: AI-generated contact sphere suggestions, connection scores, and networking preferences.

19B.2 Your Rights Under CCPA

  • Right to Know: Categories and specific pieces of Personal Information collected, sources, purposes, and third parties.
  • Right to Delete: Request deletion subject to legal exceptions.
  • Right to Correct: Request correction of inaccurate Personal Information.
  • Right to Opt Out of Sale: Arissa does not sell Personal Information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising CCPA rights.
  • Right to Limit Sensitive Personal Information: We limit use to purposes specified in this Policy.

19B.3 Exercising California Rights

Submit a verifiable consumer request to info@arissainternational.com. We respond within forty-five (45) days, extendable by a further forty-five (45) days with prior notification.

19B.4 Shine the Light

We do not disclose Personal Information to third parties for direct marketing purposes. To make a Shine the Light request, write to info@arissainternational.com.