Privacy Policy

Effective Date: September 23, 2026

1. Statutory Compliance and Scope

This Privacy Policy ("Policy") is published in strict compliance with Section 43A of the Information Technology Act, 2000 ("IT Act"), Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and in anticipation of the Digital Personal Data Protection Act, 2023. This Policy governs the aggregation, processing, syndication, and retention of personal and non-personal data by Grey Cult Studio ("the Firm", "We", "Us", or "Our"). By accessing our digital infrastructure and retaining our professional services, you hereby explicitly consent to the data practices delineated herein.

2. Age of Consent and Protection of Minors

The Firm strictly prohibits the procurement of our services by individuals under the age of eighteen (18) years ("Minors") without explicit, verifiable parental or guardian consent. The Firm does not knowingly or intentionally intercept, aggregate, or process Personally Identifiable Information from Minors. Should it come to the Firm's attention that data from a Minor has been aggregated unlawfully, such data shall be subjected to immediate digital obliteration.

3. Modalities of Data Collection

Pursuant to Rule 5 of the SPDI Rules, we algorithmically and manually intercept, aggregate, and process explicit and implicit data vectors. This encompasses Personally Identifiable Information (PII) such as nomenclature, electronic mail addresses, telephonic coordinates, and transactional metadata. Furthermore, our infrastructure autonomously aggregates non-PII telemetry, including cryptographic IP addresses, browser heuristics, and geospatial indicators to optimize operational throughput.

4. Financial Data Segregation and Limitation of Liability

The Firm explicitly disclaims the aggregation, storage, or processing of highly sensitive financial instruments, including but not limited to credit card CVV numbers, UPI PINs, or raw banking credentials. All digital transactions executed on our platform are instantly offloaded to Payment Card Industry Data Security Standard (PCI-DSS) compliant third-party payment gateways. The Firm accepts absolutely zero liability for data breaches, interceptions, or fraudulent activities originating within the independent infrastructure of said third-party financial institutions.

5. Biometric & Algorithmic (AI) Processing Consent

The Client expressly acknowledges that modern media production entails the utilization of advanced Artificial Intelligence (AI) algorithms, facial geometry mapping, and algorithmic culling softwares. The Client hereby grants irrevocable consent for their biometric data and visual likeness to be processed through third-party computational networks (including generative AI nodes) strictly for the execution and enhancement of the contracted services, waiving any claims of biometric privacy infringement under applicable jurisprudence.

6. Strategic Corporate Disclosures and Data Monetization

Without prejudice to the IT Act, Grey Cult Studio reserves the absolute prerogative to license, syndicate, transmit, or otherwise commercialize aggregated, anonymized, and/or specific segments of demographic and behavioral data to third-party affiliates, marketing syndicates, and strategic corporate partners. By engaging with our services, you expressly authorize the Firm to leverage such data assets for commercial monetization, targeted advertising deployments, and cross-platform promotional collaborations, provided such utilization does not breach statutory mandates regarding highly sensitive financial data.

7. Offshore Cloud Syndication & Cross-Border Data Transfer

Pursuant to Rule 7 of the SPDI Rules, the Client acknowledges that the Firm utilizes distributed global cloud infrastructure (e.g., AWS, Vercel, Adobe Cloud). Consequently, the Client's data, including high-fidelity media assets, may be dynamically transferred, routed, and archived on servers domiciled outside the territorial jurisdiction of the Republic of India. The Client hereby explicitly waives any objections to cross-border data localization requirements.

8. Judicial Subpoena and Law Enforcement Cooperation

Under the provisions of Section 69 of the IT Act, 2000 and Section 91 of the Code of Criminal Procedure, 1973 (or corresponding provisions of the Bharatiya Nagarik Suraksha Sanhita), the Firm reserves the unilateral right to intercept, decrypt, or surrender any aggregated data, communications, or unreleased media assets directly to statutory law enforcement agencies or judicial authorities upon receipt of a legitimate warrant, subpoena, or executive directive, entirely without prior intimation to or consent from the Client.

9. Data Retention and Cryptographic Security

The Firm deploys commercially reasonable cryptographic protocols to forestall unauthorized access. Data shall be retained exclusively for the duration necessitated by commercial exigencies and statutory archiving obligations, post which it shall be subjected to secure digital obliteration. Inherent vulnerabilities in global telecommunication networks preclude an absolute guarantee of digital invulnerability.

10. Grievance Redressal Mechanism

In strict accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and Rule 5(9) of the SPDI Rules, the Firm has appointed a Grievance Officer to address discrepancies and grievances with respect to the processing of information. Any such complaints may be directed to:

Grievance Officer: Team Grey Cult

Grey Cult Studio

Email: support@greycult.studio

11. Amendments to the Policy

The Firm reserves the unilateral right to amend, augment, or expunge provisions within this Policy at its sole discretion. Subsequent continued utilization of our services post-amendment shall constitute an irrevocable acceptance of the revised statutory framework.