Security Statement
Platform: eBodhya Studio (studio.ebodhya.in) Effective Date: 15 July 2026 Version: 1.0 Document Owner: Anomaa Studio Legal & Compliance
1. Introduction
This Security Statement describes the technical and organizational measures Anomaa Studio applies to protect eBodhya Studio and the data within it. It is addressed to every User of the Platform and to any party evaluating the Platform's security posture, and exists to explain, in good faith, how we protect Content and Personal Data without overstating certifications we do not hold.
2. Definitions
- "Anomaa Studio," "we," "us," "our" — has the meaning given in the Legal Entity section of this document.
- "the Platform" — the specific eBodhya Platform to which this document applies, as identified in the Legal Entity section.
- "User" / "you" — any individual or entity that accesses or uses the Platform.
- "Personal Data" — data about an individual who is identifiable by or in relation to such data, as defined in Section 2(t) of the DPDP Act.
- "Sub-processor" — a third-party service provider that Processes Personal Data on our behalf, and on our instructions, in order to operate the Services.
- "Security Incident" — an event that compromises the confidentiality, integrity, or availability of Content or Personal Data on the Platform.
3. Applicability
This Statement applies to the infrastructure, applications, and processes supporting studio.ebodhya.in, and to every User's Account, Content, and Personal Data handled through it.
4. Legal Entity
eBodhya™ is a trademark owned and used by Anomaa Studio, a sole proprietorship business based in Bengaluru, Karnataka, India ("Anomaa Studio," "eBodhya," "we," "us," or "our"). Anomaa Studio owns and operates the entire eBodhya suite of platforms, comprising:
- eBodhya Studio — studio.ebodhya.in
- eBodhya Marketplace — marketplace.ebodhya.in
- eBodhya Schools — schools.ebodhya.in
- eBodhya Workspace — workspace.ebodhya.in
(together, the "eBodhya Platforms").
Every account, subscription, order, listing, or agreement created or entered into through any eBodhya Platform is an agreement with Anomaa Studio directly. No eBodhya Platform is owned, operated by, or offered on behalf of any third party, franchisee, reseller, school district, or unrelated entity, unless we state so expressly and in writing. eBodhya™ and the eBodhya logo are trademarks of Anomaa Studio; no license to use them is granted except as expressly permitted in writing.
In this document, "the Platform" means eBodhya Studio (studio.ebodhya.in) specifically, and "eBodhya" or the "eBodhya Platforms" means the wider suite of products described above.
5. Our Security Measures
Encryption. Data in transit between your device and the Platform is encrypted using TLS. Data at rest, including uploaded source material, AI generation outputs, and Account data, is encrypted using industry-standard encryption on our cloud storage infrastructure.
Access controls and least privilege. Access to production systems and Personal Data is restricted to personnel who need it to perform their role, following a least-privilege model. We use role-based access control within the Platform itself so that Institution and Publisher Account administrators can scope sub-user permissions appropriately.
Environment segregation. Development, testing, and production environments are kept logically separate, and production Content and Personal Data are not used in development or testing environments except in de-identified or synthetic form.
Incident detection and response. We monitor Platform infrastructure for anomalous activity and maintain an internal incident response process to triage, contain, and remediate suspected Security Incidents.
Security incident notification. If we become aware of a Security Incident that is reasonably likely to have a material impact on your Personal Data or Content, we will notify affected Users without undue delay through the Platform, by email, or by another appropriate channel, and will comply with any notification timeline required by the DPDP Act or other Applicable Law.
Vulnerability disclosure. If you discover a potential security vulnerability in the Platform, report it in good faith to security@ebodhya.in, including enough detail for us to reproduce and assess it. We ask that you not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and remediate it, and we will not pursue action against good-faith researchers who follow this process.
Sub-processor security due diligence. Before engaging a sub-processor (cloud hosting, AI model providers, payment gateway, analytics), we review its security practices and require it to apply protections consistent with this Statement through contractual commitments.
We address confidentiality, integrity, and availability of the Platform through this ongoing security program, which we review and improve on an ongoing basis. We do not currently hold, and do not represent that we hold, specific third-party security certifications such as ISO 27001 or SOC 2; where such certifications are obtained in the future, we will update this Statement accordingly.
6. Privacy
Personal Data protected by these measures is described in our Privacy Policy.
7. AI
AI model providers that Process your prompts, uploaded material, and AI Output are sub-processors subject to the security due diligence described in Section 5, and to the responsible-use principles in our AI Usage Policy.
8. Data Processing
Personal Data is Processed in accordance with the Privacy Policy, the DPDP Act, 2023, and the technical measures described in this Statement.
9. Cookies
Authentication-related cookies are secured per Section 5; see the Cookie Policy for full detail on cookie categories.
10. Third-Party Services
Cloud hosting, AI model providers, our payment gateway, and analytics providers are reviewed for security as described in Section 5. Full sub-processor categories are listed in our Privacy Policy.
11. Security
This entire document addresses Platform security; there is no separate treatment beyond Sections 5–10.
12. Retention
Security logs and incident records are retained per our Data Retention Policy, subject to the legal-hold exception described there.
13. Deletion
Deleting your Account or Content does not retroactively remove security and audit logs that record system-level events, which are retained per our Data Retention Policy and Data Deletion Policy.
14. Intellectual Property
Not applicable to this Statement beyond the trademark notice in Section 4.
15. User Responsibilities
You must use a strong, unique password; enable any available account security features; avoid sharing login credentials; and promptly report suspected unauthorized access to support@ebodhya.in or security@ebodhya.in.
16. Prohibited Activities
You must not attempt to probe, scan, or test the security of the Platform outside the good-faith vulnerability disclosure process in Section 5, or attempt to gain unauthorized access to systems, Accounts, or data.
17. Limitation of Liability
To the maximum extent permitted by Applicable Law, Anomaa Studio's liability arising out of this Statement is limited as described in the Terms of Service. Nothing in this Statement limits liability for fraud, willful misconduct, or statutory rights that cannot be waived.
18. Disclaimer
No system is completely secure. While we apply the measures described in this Statement in good faith and on an ongoing basis, we cannot guarantee that a Security Incident will never occur.
19. Termination
Security obligations, including confidentiality of information learned during a vulnerability disclosure, survive termination of an Account or of these arrangements.
20. Governing Law and Dispute Resolution
This Security Statement and any dispute, claim, or controversy arising out of or relating to it, the Platform, or the Services (a "Dispute") is governed by the laws of India, without regard to its conflict-of-laws principles.
The parties will first attempt in good faith to resolve any Dispute through informal negotiation for thirty (30) days after one party gives the other written notice of the Dispute. If the Dispute is not resolved within that period, it will be referred to and finally resolved by arbitration in Bengaluru, Karnataka, under the Arbitration and Conciliation Act, 1996, before a sole arbitrator appointed by Anomaa Studio. The arbitration will be conducted in English, and the seat and venue of arbitration will be Bengaluru, Karnataka. The award of the arbitrator will be final and binding on the parties.
Nothing in this clause prevents either party from seeking urgent injunctive or equitable relief before a competent court at any time. Subject to the arbitration agreement above, the courts at Bengaluru, Karnataka shall have exclusive jurisdiction over any Dispute not subject to arbitration and over any proceeding to enforce an arbitral award.
21. Jurisdiction
Without prejudice to the arbitration agreement above, the Platform is directed at Users in India, and Anomaa Studio makes no representation that the Platform or its Content is appropriate or lawfully available in other locations. Users who access the Platform from outside India do so on their own initiative and are responsible for compliance with local law.
22. Changes to This Statement
We may update this Security Statement from time to time to reflect changes in the Services, Applicable Law, or our practices. We will post the revised version on the Platform with an updated "Effective Date" and, for material changes, will provide reasonable advance notice through the Platform, by email, or by an in-product notice.
23. Contact Information
If you have questions about this Statement, or wish to report a vulnerability, contact Anomaa Studio through the channel that matches your query:
| Purpose | Contact |
|---|---|
| General support | support@ebodhya.in |
| Security vulnerability reports and responsible disclosure | security@ebodhya.in |
| Grievances under the Information Technology Act, 2000 and rules made thereunder | grievance@ebodhya.in |
Registered office: Anomaa Studio, Bengaluru, Karnataka, India.
Grievance Officer
In accordance with Section 5 of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the grievance redressal requirements of the DPDP Act, 2023, Anomaa Studio has designated a Grievance Officer for the eBodhya Platforms, reachable at grievance@ebodhya.in. The Grievance Officer will acknowledge a grievance within twenty-four (24) hours of receipt and will endeavor to redress it within fifteen (15) days, or such other period as Applicable Law prescribes.
If you are not satisfied with our response, you may escalate a Personal Data grievance to the Data Protection Board of India, or pursue any other remedy available to you under Applicable Law.