Legal

Privacy Policy

Effective Date
1 April 2026
Data Controller (India)
High On Innovation, a sole proprietorship registered in Ambala City, Haryana, India
Australian Operations
High On Innovation (AU), the Australian business operated under an Australian Business Number (ABN) in accordance with applicable Australian law
Jurisdiction Coverage
India (IT Act 2000 / DPDP Act 2023), Australia (Privacy Act 1988 + APPs), United Kingdom (UK GDPR), European Union (GDPR)
Privacy Contact
privacy@highoninnovation.com

1Our Commitment

High On Innovation is committed to protecting the personal information of clients, prospects, and website visitors. This Privacy Policy explains how we collect, use, disclose, and protect personal information across our operations in India and Australia, and in serving clients in the UK, US, Australia, and internationally.

Data Controller Identity

For the purposes of applicable privacy law:

  • India entity: High On Innovation, Ambala City, Haryana, India — registered sole proprietorship / partnership. Subject to the Information Technology Act 2000, the Information Technology (Amendment) Act 2008, and the Digital Personal Data Protection Act 2023 (DPDP Act) as notified.
  • Australian operations: High On Innovation (AU), ABN-registered business operating in Australia. Subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
  • For clients in the UK and EU: HOI acts as a data controller in respect of client personal data and processes it as described in this policy, subject to UK GDPR and GDPR respectively.

Information We Collect

Information You Provide

  • Contact details: name, email, phone number, company name, job title
  • Project and business information: briefs, goals, requirements shared with HOI
  • Payment information: billing address; card details are processed by Stripe or Razorpay and are not stored by HOI
  • Communications: emails, messages, meeting notes, survey responses

Information Collected Automatically

  • Technical data: IP address, browser type, device type, operating system
  • Usage data: pages visited, session duration, links clicked, referral source
  • Payment transaction data: transaction IDs, amounts, currency — collected by Stripe and Razorpay and shared with HOI for record-keeping

Information from Third Parties

  • Professional profiles from publicly available sources such as LinkedIn where relevant to a business engagement
  • Referral information from existing clients or partners

How We Use Your Information

Payment Processor Data

Payments are processed by Stripe (international clients) and Razorpay (Indian clients). These processors collect and process payment card data directly on behalf of HOI. By making a payment, you consent to your payment data being processed by the applicable processor:

  • Stripe: Stripe, Inc. / Stripe Payments Europe — privacy policy at stripe.com/privacy. PCI-DSS Level 1 certified.
  • Razorpay: Razorpay Software Private Limited, Bengaluru, India — privacy policy at razorpay.com/privacy. Licensed by the Reserve Bank of India.

HOI receives transaction confirmations and limited payment metadata (last four digits, billing address, transaction ID) for record-keeping. HOI does not store full card numbers, CVV codes, or bank account details.

Data Sharing

We do not sell personal data. We share it only with:

  • Payment processors: Stripe and Razorpay — for transaction processing only
  • Service providers: hosting, CRM, email delivery, analytics tools — bound by data processing terms
  • Professional advisors: lawyers, accountants, auditors — bound by confidentiality obligations
  • Regulatory authorities: where required by Indian, Australian, UK, or other applicable law
  • Business successors: in the event of a business transfer or restructure, with equivalent privacy protections

International Data Transfers

HOI's primary team is based in India. Client data may be accessed by HOI personnel in India in the course of providing services. For non-Indian clients:

  • Australian clients: transfers to India are governed by Australian Privacy Principle 8. HOI takes reasonable steps to ensure the Indian operations handle data consistently with the APPs, including through internal access controls and data handling policies
  • UK clients: transfers to India are protected by appropriate safeguards including standard contractual clauses where applicable under UK GDPR
  • EU clients: transfers are protected by standard contractual clauses approved by the European Commission

For Australian clients, HOI notes that by accepting these terms you consent to HOI disclosing your personal information to its India-based team for service delivery purposes, and acknowledge that Australian Privacy Law may not apply to those team members. HOI nonetheless contractually requires those personnel to handle data consistently with the APPs.

Data Retention

Client project data7 years from project completion (tax and legal compliance)
Payment records7 years (India: Income Tax Act 1961; Australia: tax law requirements)
Marketing contact data3 years from last engagement or until opt-out
Website analytics26 months
Correspondence and communications3 years from last interaction

Cookies

Our website uses essential, functional, analytics, and marketing cookies. You will be presented with a cookie consent banner on first visit. Non-essential cookies require your consent. See our Cookie Policy for full details.

Your Rights

RightDescriptionJurisdiction
AccessObtain a copy of your personal data held by HOIAll
Correction / RectificationCorrect inaccurate or incomplete dataAll
ErasureRequest deletion (subject to legal retention requirements)GDPR / UK GDPR / Australia
RestrictionRestrict processing in certain circumstancesGDPR / UK GDPR
PortabilityReceive data in a portable, machine-readable formatGDPR / UK GDPR
ObjectionObject to processing based on legitimate interestsGDPR / UK GDPR
Opt-out of marketingUnsubscribe from marketing at any timeAll
Withdraw consentWhere processing is consent-basedAll
Nomination (DPDP)Nominate a person to exercise rights on your behalfIndia (DPDP Act 2023)
ComplaintLodge a complaint with the relevant authorityAll

To exercise any right, email privacy@highoninnovation.com. We respond within thirty (30) days. Identity verification may be required.

Supervisory Authorities

  • India: Data Protection Board of India (once operational under the DPDP Act 2023); currently the Ministry of Electronics and Information Technology (MeitY)
  • Australia: Office of the Australian Information Commissioner — oaic.gov.au
  • United Kingdom: Information Commissioner's Office — ico.org.uk
  • European Union: Your national data protection authority

Security

HOI implements TLS/SSL encryption in transit, access controls, role-based permissions, and incident response procedures. In the event of a breach affecting personal data, we will notify affected individuals and relevant authorities within the timeframes required by applicable law (72 hours under GDPR/UK GDPR; as soon as practicable under Australian law and the DPDP Act).

Children's Data

Our services are not directed at persons under 18 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect data from minors. If you believe we have done so inadvertently, contact us immediately.