This Privacy Policy ("Policy") describes how Arissa International Private Limited ("Arissa", "we", "us", or "our") collects, uses, stores, shares, and protects personal data of users ("you", "your", or "User") who access or use the networking platform available at networking.arissainternational.com (the "Platform").
The Platform is a professional networking service designed to help individuals connect, share referrals, and discover business opportunities through a structured Gives-and-Asks matching system.
We are committed to protecting your privacy in compliance with applicable data protection laws. Because our Users are located across multiple jurisdictions, this Policy applies to different legal frameworks depending on where you are located:
| User Location | Applicable Law | Key Rights Section |
|---|---|---|
| India | DPDP Act 2023 · IT Act 2000 · SPDI Rules | Sections 7, 12 |
| European Union / EEA | GDPR (EU) 2016/679 | Section 19A |
| United Kingdom | UK GDPR | Section 19A |
| California, USA | CCPA / CPRA | Section 19B |
| All other countries | GDPR-standard practices applied | Section 19A |
By accessing or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree, you must not use the Platform.
This Policy applies to:
The Platform is available to users located in India and internationally. Arissa International Private Limited is incorporated in India and processes all data on servers located in India (AWS Mumbai region). Users and Contact Record subjects located outside India acknowledge that their Personal Data is transferred to and processed in India.
Where applicable law in your jurisdiction provides specific rights or protections, those are addressed in Sections 19A and 19B.
| Legal Name | Arissa International Private Limited |
| Grievance Email | info@arissainternational.com |
| Website | networking.arissainternational.com |
We collect Personal Data in three distinct ways — through the pre-registration discovery form (Form 1), directly from Registered Users (Form 2 and account data), and through Contact Records entered by Registered Users or Arissa administrators.
Before creating an account or making any payment, individuals may submit a pre-registration discovery form on the Platform. This form collects:
Users should not enter sensitive personal data, financial account details, health information, government identification numbers, passwords, or confidential third-party information into meeting notes, Contact Records, Gives, Asks, or referral notes unless they have a lawful basis and the individual's permission.
How Form 1 data is used: Upon submission of Form 1, the Platform automatically cross-matches the submitter's declared Gives and Asks against all other Form 1 submitters in the database. A match report in PDF format — showing the names, Gives, Asks, and company details of matching individuals — is generated and sent to Arissa administrators by email. This PDF is for internal use only and is not shared with the Form 1 submitter or any other third party.
Consent at Form 1: Before submitting Form 1, individuals are required to confirm via a mandatory checkbox that they agree to the following:
Submission without checking this box is not permitted.
Retention of Form 1 data: If a Form 1 Submitter does not proceed to register on the Platform, their Form 1 data will be retained for a maximum of thirty (30) days from the date of submission, after which it will be permanently deleted. If the Form 1 Submitter proceeds to register, their Form 1 data is carried forward into their Registered User account. Form 1 Submitters may request deletion of their data at any time before the 30-day period expires by writing to info@arissainternational.com.
| Category | Examples | Source |
|---|---|---|
| Account & Registration | Name, email, mobile, title, organisation, city | You (direct) |
| Professional Profile | Gives, Asks, expertise, business categories, business description, website | You (direct — Form 2) |
| Networking Content | Meeting history, referrals, introductions, meeting notes | You (direct) |
| Contact Sphere Data | Customer names, job titles, company names, contact details of target audience | You (direct — Form 2) |
| Payment (India) | Billing name, address, GSTIN — card data held by Razorpay | You + Razorpay |
| Payment (International) | Remittance details: sender name, bank reference, amount | Bank wire / invoice |
| Technical & Device | IP address, device type, OS, browser, timezone | Automatic |
| Usage & Analytics | Pages visited, features used, session duration | Automatic |
| AI-Inferred Data | Contact sphere suggestions, connection scores, topic affinity, engagement patterns | Derived from your Gives |
The Platform enables both Registered Users and Arissa administrators to enter Contact Records of individuals they have personally met in a networking context. This works as follows:
When a Contact Record is created, we collect and store:
Important: Contact Records relate to individuals who have not registered on the Platform. If your details have been entered as a Contact Record, please read Section 5.3 and Section 12B below for your rights.
At the exact moment a Contact Record form is submitted — whether by a Registered User or an Arissa administrator — the Platform automatically sends a notification email to the contact's email address. This notification states:
Contact Records are visible only to the Registered User who entered them and to Arissa administrators. They are never shared with other Registered Users and are never used in AI matching or recommendation features.
The user or administrator entering a Contact Record is responsible for ensuring that the information is accurate, was collected in a lawful networking context, and is not entered for spam, harassment, profiling, or unlawful solicitation.
Failed Notification: If the notification email cannot be delivered because the email address entered is invalid or non-existent, the Contact Record will be flagged in the Arissa administrator panel as "notification undelivered." Arissa will delete the flagged Contact Record within forty-eight (48) hours of the failed delivery alert. The submitting user will be notified that the Contact Record has been deleted due to notification failure and asked to verify the contact's email address before re-entering the record.
For Indian subscribers, payments are processed by Razorpay Software Private Limited. Arissa does not store full card or UPI details. Razorpay's privacy policy is available at razorpay.com/privacy.
For international subscribers, payments are made via bank wire transfer against invoices issued by Arissa. We receive and retain inward remittance details, including sender name, bank reference, and transaction amount, solely for payment reconciliation and statutory accounting purposes.
Upon completion of payment — whether by Indian or international subscribers — an invoice is automatically generated and sent to the paying user's registered email address. This invoice contains transaction details, including the plan purchased, amount paid, applicable taxes, and payment reference number.
We process Form 1 data for the following purposes:
Form 1 data is not used for marketing, advertising, or any purpose beyond those listed above without separate consent.
We process your Personal Data for the following purposes:
We process Contact Record data for the following purposes:
Contact Record data is not used for AI matching, marketing, or any purpose beyond those listed above.
Consent for Form 1 data processing is obtained at the point of submission via a mandatory checkbox as described in Section 5.0. Submission of Form 1 without checking the consent box is not permitted.
Form 1 Submitters may withdraw consent and request deletion of their data at any time within the 30-day retention period by writing to info@arissainternational.com. Deletion will be actioned within forty-eight (48) hours of receipt.
We rely on your free, specific, informed, and unambiguous consent for processing your Personal Data, except where processing is permitted under legitimate uses as defined under the DPDP Act, or on another lawful basis as set out in Section 19A for EEA and UK users.
You provide consent at the time of registration by affirmatively accepting the applicable consent notice and acknowledging this Policy. For additional processing activities such as marketing communications or AI model training, we will obtain separate consent.
Withdrawing consent: You may withdraw your consent at any time through the in-app consent settings available under Account Settings, or by writing to our Grievance Officer (Section 18). Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. Withdrawing consent may result in our inability to provide certain Platform features or the deactivation of your account.
The in-app consent settings allow you to manage:
Withdrawal through in-app settings takes effect immediately. Withdrawal by email to the Grievance Officer will be actioned within forty-eight (48) hours of receipt.
In accordance with the DPDP Act and Rules, we provide a concise, standalone Consent Notice at the point of registration, separate from this full Policy. That notice itemizes:
The Consent Notice is available in English and, on request, in other Scheduled Languages as recognized under the Eighth Schedule of the Constitution of India. To request it in another language, write to info@arissainternational.com. In the event of any conflict between the Consent Notice and this Policy, the Consent Notice shall govern with respect to the specific processing activity described therein.
For individuals whose details are entered as Contact Records, the legal basis for initial processing is the legitimate networking interest of the Registered User or administrator who entered the record, combined with the immediate transparency notification email sent at the exact moment of entry. If a contact exercises their opt-out right via the one-click link, their record is deleted immediately and permanently.
Our AI systems process Personal Data of Registered Users to:
AI features use only data provided by Registered Users. Contact Records of non-registered individuals are never used in AI processing. Form 1 data of non-registrants is used only for internal match reporting as described in Section 5.0 and is not fed into the registered user AI system.
Our AI systems compute similarity, relevance, and complementarity scores between Registered Users based on explicit signals (declared Gives and Asks) and implicit signals (engagement patterns). For contact sphere suggestions, the AI maps your declared Gives against known professional networking patterns to identify the fifteen most relevant categories of contacts for your specific professional profile. AI outputs are suggestions only — not binding decisions. You retain full discretion to accept, ignore, or reject any AI-generated recommendation.
AI systems may produce results that are inaccurate, incomplete, or biased. We cannot guarantee that every match or contact sphere suggestion will be relevant, accurate, or result in a business outcome. Exercise independent professional judgment before acting on any AI-generated suggestion.
You may at any time:
We may use third-party AI/ML services for Insights features. We select providers that offer appropriate confidentiality commitments, transmit only the data necessary for the function, and do not authorize such providers to train their general-purpose models on identifiable Platform data.
We do not sell your Personal Data. We share Personal Data only as described below.
| Category | Provider | Purpose |
|---|---|---|
| Cloud Infrastructure | Amazon Web Services (AWS) — Mumbai region | Hosting and database |
| Payment (India) | Razorpay Software Private Limited | Subscription payment processing and automatic invoice generation to registered email |
| Payment (International) | Bank wire / invoice system | International subscription billing; invoice sent automatically to registered email on payment confirmation |
| Analytics | Google Analytics (Google LLC) | Usage analysis and reporting |
| CRM & Marketing | HubSpot, Inc. | Contact management and tracking |
| Email / Comms | HubSpot | Transactional emails including invoices, account notifications, contact record notifications, and Form 1 match report delivery to administrators |
Your professional profile, declared Gives and Asks, and networking activity are visible to other Registered Users and Arissa administrators in accordance with the Platform's design. After Form 2 submission, your profile becomes available to Arissa administrators and, where applicable, to other Registered Users for networking and referral matching purposes. Contact Records you enter are visible only to you and Arissa administrators — never to other Registered Users. Form 1 match reports are visible only to Arissa administrators and are never shared with other users.
Registered Users must use other Users' profile information, Gives, Asks, referrals, introductions, and networking activity only for legitimate networking purposes and must not copy, export, scrape, resell, or misuse such information.
We may disclose Personal Data to comply with applicable laws, court orders, or lawful directives from government authorities, including under the IT Act, the DPDP Act, the Code of Criminal Procedure, and CERT-In Directions, 2022.
In the event of a merger, acquisition, or sale of assets involving Arissa, your Personal Data may be transferred to the relevant successor entity, subject to the same protections under this Policy.
All Personal Data is stored on AWS servers in India (Mumbai region). For users and Contact Record subjects located outside India, processing in India constitutes a cross-border transfer.
For EEA and UK users, transfers are conducted under Standard Contractual Clauses (SCCs) approved by the European Commission, or on the basis of explicit consent at the point of Form 1 submission or registration, as described in Section 19A.3.
We do not rely on the EU-U.S. Data Privacy Framework (Arissa is not a U.S.-based entity) and do not rely on the now-invalid EU-U.S. Privacy Shield.
Form 1 data of individuals who do not proceed to register on the Platform will be retained for a maximum of thirty (30) days from the date of submission, after which it will be permanently deleted.
Form 1 data of individuals who proceed to register is carried forward into their Registered User account and retained in accordance with Section 11.2.
Form 1 Submitters may request deletion of their data at any time within the 30-day period by writing to info@arissainternational.com.
Deletion from active systems may occur immediately or within the stated period, but residual copies may remain in encrypted backups for a limited period until overwritten in the ordinary course of backup rotation.
Personal Data associated with your active account is retained for the duration of your subscription. Upon account closure or withdrawal of consent, we will erase your Personal Data within a reasonable period, subject to Sections 11.4 and 11.5.
Contact Records are retained for as long as the Registered User or administrator who entered them maintains an active account, or until:
In accordance with Rule 8 of the DPDP Rules and other applicable laws, we retain:
Prior to erasing your Personal Data at the end of the applicable retention period, we will notify you at least forty-eight (48) hours in advance by email to your registered address and via in-Platform notification. The Pre-Erasure Notice will state:
Subject to applicable law, you have the following rights:
To exercise any of these rights, contact our Grievance Officer (Section 18). We may require verification of your identity before we can action any request.
If you have submitted Form 1 but have not registered on the Platform, you have the following rights:
After thirty (30) days from submission, your Form 1 data will have been deleted and no further action is required.
If your details have been entered into the Platform as a Contact Record without your prior registration, you have the following rights:
We will action all Contact Record subject requests within forty-eight (48) hours of receipt.
We use cookies and similar tracking technologies to operate the Platform, enable session management, remember preferences, and analyse usage patterns.
| Category | Examples | Can it be disabled? | Consent required? |
|---|---|---|---|
| Strictly Necessary | Session, auth, security tokens | No | No |
| Functional | Language, layout, notification preferences | Yes | Yes |
| Performance & Analytics | Google Analytics, HubSpot tracking | Yes | Yes |
We use a cookie consent banner to obtain consent before setting non-essential cookies. You can manage your cookie preferences at any time via the Cookie Settings link in the Platform footer.
We do not use advertising pixels or permit third-party advertising networks to track users across the Platform. We do not run retargeting campaigns.
We implement reasonable security practices in compliance with Rule 8 of the SPDI Rules, the DPDP Rules, and CERT-In Directions, 2022, including:
In the event of a breach, we will notify the Data Protection Board of India and all affected individuals in the manner and within the timelines prescribed under the DPDP Rules. For EEA and UK users, we will notify the relevant supervisory authority within seventy-two (72) hours, as required under the GDPR.
The Platform is intended for individuals eighteen (18) years of age or older. We do not knowingly collect Personal Data of individuals under eighteen (18). If we become aware of such data, we will erase it without delay.
The Platform may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their policies before sharing any Personal Data.
We may update this Policy from time to time. Material changes will be notified through the Platform or by email. The "Last Updated" date indicates when it was last revised. Continued use after notification constitutes acceptance of the updated Policy.
| Grievance Officer | Arissa International Private Limited |
| info@arissainternational.com | |
| Phone | +1 (302) 404-2147 |
| Working Hours | Monday to Friday, 10:00 AM – 6:00 PM IST |
We will acknowledge receipt of grievances within twenty-four (24) hours. General grievances will be resolved within fifteen (15) days in accordance with IT Rules 2021. Grievances relating to the processing of Personal Data will be resolved within ninety (90) days as required under the DPDP Rules, 2025. If dissatisfied, you may approach the Data Protection Board of India.
| Company | Arissa International Private Limited |
| info@arissainternational.com | |
| Website | networking.arissainternational.com |
If you are located in the EEA, the UK, or Switzerland, the following provisions apply under the GDPR and the UK GDPR.
In addition to Sections 12, 12A, and 12B, EEA and UK users have:
India does not currently have an adequacy decision under GDPR. Transfers from the EEA or the UK to India are conducted under Standard Contractual Clauses (SCCs) pursuant to Article 46 GDPR, or on the basis of explicit consent upon submission of Form 1 or registration. We do not rely on the EU-U.S. Data Privacy Framework or the invalid EU-U.S. Privacy Shield.
We apply retention periods in Section 11. Where GDPR's storage limitation principle (Article 5(1)(e)) requires a shorter retention period, we apply the shorter period. For Form 1 Submitters in the EEA or UK who do not register, the 30-day retention period applies regardless.
We respond to GDPR requests within thirty (30) days, extendable by two further months for complex requests with prior notification.
Write to info@arissainternational.com. No fee is charged unless requests are manifestly unfounded or excessive.
In the preceding twelve (12) months, we have collected:
Submit a verifiable consumer request to info@arissainternational.com. We respond within forty-five (45) days, extendable by a further forty-five (45) days with prior notification.
We do not disclose Personal Information to third parties for direct marketing purposes. To make a Shine the Light request, write to info@arissainternational.com.