Legal
Privacy Policy
What personal data we collect, why, who we share it with, how long we keep it and your rights under the Digital Personal Data Protection Act, 2023.
Last updated 4 October 2026
1. Who is responsible for your data
Ragu and Lika IP Private Limited ("Ragulika IP", "we") is the Data Fiduciary for the personal data processed through ipvaluation.ragulikaip.com. Registered office: Y 2 E 120/2, Trivenipuram, Jhunsi, Prayagraj, Uttar Pradesh 211019, India.
For any question, request or complaint about your personal data, contact our Grievance Officer: Dr Rupalika, Grievance Officer, Ragu and Lika IP Private Limited, Y 2 E 120/2, Trivenipuram, Jhunsi, Prayagraj, Uttar Pradesh 211019, India. Email: rupalika@ragulikaip.com. Phone: +91 70119 60903 (Mon–Sat, 10:00 am – 6:00 pm IST · Sunday closed).
This policy follows the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025. Where the EU or UK GDPR applies to you, it also describes your rights under them.
2. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact | name, email, phone, organisation, designation | you |
| Account and security | sign-in method, password (stored only as a one-way hash), two-factor settings, sessions, device type, IP address (stored as a salted hash where possible), sign-in history | you, your browser, Google if you sign in with Google |
| Identity verification (KYC/KYB) | legal name, PAN, GSTIN, CIN, date of birth, address, the last four digits of Aadhaar or passport (never the full number), the documents you upload | you |
| Engagement data | IP details, documents, financial information and messages for valuation orders; specifications for invention summaries | you |
| Marketplace data | listings, ownership evidence, NDAs you sign (name, time, IP hash), offers, messages, data-room downloads | you and the other party |
| Enquiries | contact, quote, sample-report and calculator forms | you |
| Technical | browser and device data, pages visited, cookies (see the Cookie Policy) | your browser |
We do not knowingly collect data from anyone under 18. If you think a child has given us personal data, tell us and we will delete it.
3. Why we use it
- To provide the Services you ask for: run your account, prepare preliminary valuations, produce invention summaries and translations, run marketplace listings, NDAs, data rooms and negotiations. (Your consent, and use for the purpose you gave the data.)
- To verify identity and ownership and prevent fraud: KYC before orders, listings and data rooms; ownership checks; security monitoring, rate limiting and audit logs. (Legitimate use and legal obligations.)
- To communicate with you: service emails and in-app notices about your account, orders, summaries and listings. (Providing the Service.)
- To meet legal obligations: professional record-keeping, tax law, responding to lawful requests from authorities, handling grievances. (Legal obligation.)
- To improve the Services: aggregate statistics; analytics cookies only if you allow them. (Consent.)
- Marketing: newsletters and insights only if you opt in; you can opt out at any time in Account → Notification settings. (Consent.)
You can withdraw consent at any time, as easily as you gave it. Withdrawal does not affect processing already done, and we may then be unable to continue a Service that depends on that data.
4. AI processing
When you ask for an invention summary of a granted or published patent, or a translation, the text of the specification is sent to our AI provider, Anthropic PBC (Claude), through its commercial API. Under its commercial terms, API content is not used to train its models and is deleted within 30 days unless the law requires longer or it is needed to investigate misuse.
For unpublished inventions we do not use any AI service unless we have a signed zero-data-retention agreement with that provider; until then the draft is prepared automatically on our own servers.
If meaning-based marketplace search is switched on, the title and public teaser of published listings, and the words you type into search, are sent to Voyage AI to compute search vectors. Unpublished material and data-room documents are never sent.
We do not use your content to train any AI model, and no decision with legal or similarly significant effect on you is made by AI alone: a person reviews every report and moderates every listing.
5. Who we share it with
- Service providers acting on our instructions under contract: our hosting provider, Cloudflare (network security and delivery), our email provider, Google (only if you choose Google sign-in), Anthropic and Voyage AI (as described above), and malware scanning that runs on our own servers.
- People you choose: for example the valuation team on your order, buyers you allow into your data room, the counterparty in a negotiation, or anyone you share a report or summary with.
- Authorities where the law requires, such as a court order or a lawful request from a regulator or law-enforcement agency.
- A successor if our business is reorganised or sold, under the same protections.
We never sell personal data or share it for advertising.
6. Transfers outside India
Some providers (Anthropic, Voyage AI, Google and Cloudflare) may process data outside India, mainly in the United States. We transfer data only as allowed by the DPDP Act and any restrictions notified by the Government of India, and under contracts that require appropriate security.
7. How long we keep it
- Documents you upload for an engagement (invention disclosures, specifications, financial data): 90 days after final delivery, then permanently deleted.
- Specifications uploaded for an invention summary, and the text extracted from them: 90 days after you approve the summary, or immediately when you delete it.
- Invention summaries and their versions: Until you delete them.
- Final reports, engagement letters and our working papers: 8 years from delivery.
- Signed NDAs and marketplace term sheets: 8 years from signing.
- Invoices, payment and tax records: 8 years from the end of the financial year.
- KYC / KYB records for valuation orders and marketplace transactions: 5 years after the account or transaction ends.
- Marketplace data-room documents: 90 days after the deal closes or the listing is withdrawn.
- Enquiries, calculator submissions and quote requests that do not become engagements: 24 months, then deleted.
- Security and audit logs: 8 years.
- Your account profile: Until you close your account, plus up to 30 days in encrypted backups.
Security and audit logs, which record actions but not document contents, are kept for at least one year and up to 8 years. When a retention period ends, data is deleted or irreversibly anonymised.
8. Your rights
Under the DPDP Act you may: - access a summary of your personal data and how we process it, and the identities of those we have shared it with; - correct, complete or update it; - erase it, unless we must keep it by law; - withdraw consent for processing based on consent; - nominate another person to exercise your rights if you die or become incapable; - complain to us and, if you are not satisfied, to the Data Protection Board of India.
How: signed-in users can download a copy of their data and ask for erasure in Account → Privacy & my data; profile details can be corrected in Account → Profile. Anyone can also write to the Grievance Officer. We may need to verify your identity first. We respond as soon as we can and within 30 days (the law allows up to 90).
EU and UK residents also have rights to data portability, to object, and to restrict processing.
9. Security
We protect personal data with: encryption in transit (TLS) and at rest (AES-256-GCM for documents); two-factor authentication for every staff account; role-based access with every access to orders, reports, KYC documents and data rooms checked and logged in a tamper-evident audit trail; malware scanning of uploads; strict browser security policies; rate limits; encrypted, off-server backups; and regular security reviews. See Security.
If a personal data breach occurs, we will inform affected people without delay and report it to the Data Protection Board of India (with a detailed report within 72 hours) and, where required, to CERT-In.
10. Cookies
We use strictly necessary cookies to keep you signed in and secure. Analytics and marketing cookies load only if you agree. Details: Cookie Policy.
11. Changes
If we make material changes we will tell registered users by email or in the portal before they take effect. The date at the top shows the latest version.