eBodhya Studio Back to Studio

Security Statement

Platform: eBodhya Studio (studio.ebodhya.in) Effective Date: 15 July 2026 Version: 1.0 Document Owner: Anomaa Studio Legal & Compliance

1. Introduction

This Security Statement describes the technical and organizational measures Anomaa Studio applies to protect eBodhya Studio and the data within it. It is addressed to every User of the Platform and to any party evaluating the Platform's security posture, and exists to explain, in good faith, how we protect Content and Personal Data without overstating certifications we do not hold.

2. Definitions

3. Applicability

This Statement applies to the infrastructure, applications, and processes supporting studio.ebodhya.in, and to every User's Account, Content, and Personal Data handled through it.

4. Legal Entity

eBodhya™ is a trademark owned and used by Anomaa Studio, a sole proprietorship business based in Bengaluru, Karnataka, India ("Anomaa Studio," "eBodhya," "we," "us," or "our"). Anomaa Studio owns and operates the entire eBodhya suite of platforms, comprising:

(together, the "eBodhya Platforms").

Every account, subscription, order, listing, or agreement created or entered into through any eBodhya Platform is an agreement with Anomaa Studio directly. No eBodhya Platform is owned, operated by, or offered on behalf of any third party, franchisee, reseller, school district, or unrelated entity, unless we state so expressly and in writing. eBodhya™ and the eBodhya logo are trademarks of Anomaa Studio; no license to use them is granted except as expressly permitted in writing.

In this document, "the Platform" means eBodhya Studio (studio.ebodhya.in) specifically, and "eBodhya" or the "eBodhya Platforms" means the wider suite of products described above.

5. Our Security Measures

Encryption. Data in transit between your device and the Platform is encrypted using TLS. Data at rest, including uploaded source material, AI generation outputs, and Account data, is encrypted using industry-standard encryption on our cloud storage infrastructure.

Access controls and least privilege. Access to production systems and Personal Data is restricted to personnel who need it to perform their role, following a least-privilege model. We use role-based access control within the Platform itself so that Institution and Publisher Account administrators can scope sub-user permissions appropriately.

Environment segregation. Development, testing, and production environments are kept logically separate, and production Content and Personal Data are not used in development or testing environments except in de-identified or synthetic form.

Incident detection and response. We monitor Platform infrastructure for anomalous activity and maintain an internal incident response process to triage, contain, and remediate suspected Security Incidents.

Security incident notification. If we become aware of a Security Incident that is reasonably likely to have a material impact on your Personal Data or Content, we will notify affected Users without undue delay through the Platform, by email, or by another appropriate channel, and will comply with any notification timeline required by the DPDP Act or other Applicable Law.

Vulnerability disclosure. If you discover a potential security vulnerability in the Platform, report it in good faith to security@ebodhya.in, including enough detail for us to reproduce and assess it. We ask that you not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and remediate it, and we will not pursue action against good-faith researchers who follow this process.

Sub-processor security due diligence. Before engaging a sub-processor (cloud hosting, AI model providers, payment gateway, analytics), we review its security practices and require it to apply protections consistent with this Statement through contractual commitments.

We address confidentiality, integrity, and availability of the Platform through this ongoing security program, which we review and improve on an ongoing basis. We do not currently hold, and do not represent that we hold, specific third-party security certifications such as ISO 27001 or SOC 2; where such certifications are obtained in the future, we will update this Statement accordingly.

6. Privacy

Personal Data protected by these measures is described in our Privacy Policy.

7. AI

AI model providers that Process your prompts, uploaded material, and AI Output are sub-processors subject to the security due diligence described in Section 5, and to the responsible-use principles in our AI Usage Policy.

8. Data Processing

Personal Data is Processed in accordance with the Privacy Policy, the DPDP Act, 2023, and the technical measures described in this Statement.

9. Cookies

Authentication-related cookies are secured per Section 5; see the Cookie Policy for full detail on cookie categories.

10. Third-Party Services

Cloud hosting, AI model providers, our payment gateway, and analytics providers are reviewed for security as described in Section 5. Full sub-processor categories are listed in our Privacy Policy.

11. Security

This entire document addresses Platform security; there is no separate treatment beyond Sections 5–10.

12. Retention

Security logs and incident records are retained per our Data Retention Policy, subject to the legal-hold exception described there.

13. Deletion

Deleting your Account or Content does not retroactively remove security and audit logs that record system-level events, which are retained per our Data Retention Policy and Data Deletion Policy.

14. Intellectual Property

Not applicable to this Statement beyond the trademark notice in Section 4.

15. User Responsibilities

You must use a strong, unique password; enable any available account security features; avoid sharing login credentials; and promptly report suspected unauthorized access to support@ebodhya.in or security@ebodhya.in.

16. Prohibited Activities

You must not attempt to probe, scan, or test the security of the Platform outside the good-faith vulnerability disclosure process in Section 5, or attempt to gain unauthorized access to systems, Accounts, or data.

17. Limitation of Liability

To the maximum extent permitted by Applicable Law, Anomaa Studio's liability arising out of this Statement is limited as described in the Terms of Service. Nothing in this Statement limits liability for fraud, willful misconduct, or statutory rights that cannot be waived.

18. Disclaimer

No system is completely secure. While we apply the measures described in this Statement in good faith and on an ongoing basis, we cannot guarantee that a Security Incident will never occur.

19. Termination

Security obligations, including confidentiality of information learned during a vulnerability disclosure, survive termination of an Account or of these arrangements.

20. Governing Law and Dispute Resolution

This Security Statement and any dispute, claim, or controversy arising out of or relating to it, the Platform, or the Services (a "Dispute") is governed by the laws of India, without regard to its conflict-of-laws principles.

The parties will first attempt in good faith to resolve any Dispute through informal negotiation for thirty (30) days after one party gives the other written notice of the Dispute. If the Dispute is not resolved within that period, it will be referred to and finally resolved by arbitration in Bengaluru, Karnataka, under the Arbitration and Conciliation Act, 1996, before a sole arbitrator appointed by Anomaa Studio. The arbitration will be conducted in English, and the seat and venue of arbitration will be Bengaluru, Karnataka. The award of the arbitrator will be final and binding on the parties.

Nothing in this clause prevents either party from seeking urgent injunctive or equitable relief before a competent court at any time. Subject to the arbitration agreement above, the courts at Bengaluru, Karnataka shall have exclusive jurisdiction over any Dispute not subject to arbitration and over any proceeding to enforce an arbitral award.

21. Jurisdiction

Without prejudice to the arbitration agreement above, the Platform is directed at Users in India, and Anomaa Studio makes no representation that the Platform or its Content is appropriate or lawfully available in other locations. Users who access the Platform from outside India do so on their own initiative and are responsible for compliance with local law.

22. Changes to This Statement

We may update this Security Statement from time to time to reflect changes in the Services, Applicable Law, or our practices. We will post the revised version on the Platform with an updated "Effective Date" and, for material changes, will provide reasonable advance notice through the Platform, by email, or by an in-product notice.

23. Contact Information

If you have questions about this Statement, or wish to report a vulnerability, contact Anomaa Studio through the channel that matches your query:

Purpose Contact
General support support@ebodhya.in
Security vulnerability reports and responsible disclosure security@ebodhya.in
Grievances under the Information Technology Act, 2000 and rules made thereunder grievance@ebodhya.in

Registered office: Anomaa Studio, Bengaluru, Karnataka, India.

Grievance Officer

In accordance with Section 5 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the grievance redressal requirements of the DPDP Act, 2023, Anomaa Studio has designated a Grievance Officer for the eBodhya Platforms, reachable at grievance@ebodhya.in. The Grievance Officer will acknowledge a grievance within twenty-four (24) hours of receipt and will endeavor to redress it within fifteen (15) days, or such other period as Applicable Law prescribes.

If you are not satisfied with our response, you may escalate a Personal Data grievance to the Data Protection Board of India, or pursue any other remedy available to you under Applicable Law.