BR
Business RoadmapDirection · Strategy · Growth
Privacy Policy
Effective Date: April 1, 2026 DPDP Act, 2023 Compliant DPDP Rules 2025 Aligned IT Act, 2000 Compliant
Table of Contents
  1. Who We Are
  2. Definitions
  3. Data We Collect
  4. Purpose & Legal Basis
  5. Consent
  6. How We Use Your Data
  7. Data Sharing & Disclosure
  8. Data Retention
  9. Your Rights
  10. Data Security
  11. Children's Data
  12. Cross-Border Transfers
  13. Intellectual Property
  14. Limitation of Liability
  15. Governing Law & Jurisdiction
  16. Grievance Redressal
  17. Policy Updates
  18. Contact Us
This Privacy Policy ("Policy") governs the collection, processing, storage, and protection of your personal data by Business Roadmap (Sector 52, Noida, Uttar Pradesh – 201301, India). This Policy is prepared in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and the Information Technology Act, 2000 along with rules thereunder. By accessing businessroadmap.in, submitting any form, making any payment, or availing any service of Business Roadmap, you unconditionally accept this Policy in its entirety. If you do not agree with any provision of this Policy, you must immediately discontinue use of our platform and services.
1
Who We Are
About Us & Our Authority

Business Roadmap is an AI-powered business consultancy platform headquartered at Sector 52, Noida, Uttar Pradesh – 201301, India. We operate through businessroadmap.in and provide services including Feasibility Studies, Due Diligence Reports, and Detailed Project Reports (DPR) across 786 districts of India in 9 Indian languages, powered by an AI automation framework with expert human oversight.

Business Roadmap exercises full and exclusive authority over the collection, use, storage, and deletion of personal data submitted through our platform. We determine the purpose and manner of all data processing, and all such decisions vest solely with Business Roadmap. By using our services, you acknowledge and accept this authority.

Registered Office: Business Roadmap, Sector 52, Noida, Uttar Pradesh – 201301, India  |  Website: businessroadmap.in  |  Privacy Email: Contact@businessroadmap.in
2
Definitions
Key Terms — DPDP Act §2

The following terms carry the meanings defined under the DPDP Act, 2023 and shall be read accordingly throughout this Policy:

TermMeaning
Data Principal ("You")The individual whose personal data is being collected or processed — i.e., the user, visitor, or client of Business Roadmap who has voluntarily accessed the platform or availed services.
Business Roadmap ("We / Us / Our")Business Roadmap — the entity that solely determines the purpose and manner of processing your personal data, with full authority over all data decisions.
Data ProcessorThird-party service providers who process personal data strictly on our behalf and under our instructions (e.g., payment gateways, cloud storage providers, OTP delivery services).
Personal DataAny digital data by which you can be identified directly or indirectly, including name, phone number, email address, location, business details, and any information voluntarily submitted while availing our services.
ProcessingAny operation performed on personal data — collection, storage, use, analysis, sharing, transfer, archival, or deletion.
ConsentYour free, specific, informed, unconditional, and unambiguous agreement expressed through a clear affirmative act (e.g., OTP verification or checkbox confirmation) prior to data collection.
ServicesAll products, reports, consultancy services, AI-generated outputs, and digital content offered by Business Roadmap through businessroadmap.in or any associated communication channel.
Data Protection BoardThe Data Protection Board of India, constituted under §18 of the DPDP Act, 2023.
3
Data We Collect
Itemized Description — DPDP Rules 2025, Rule 3

We collect personal data that is necessary and proportionate for the delivery of our services. All data is voluntarily provided by you at the time of using our platform. The following categories may be collected:

CategoryData Points CollectedCollection Mode
Identity DataFull name, business name, designationEnquiry form, onboarding form
Contact DataMobile number, email address, city/district, state, PIN codeWeb forms, OTP verification
Business DataBusiness idea, industry sector, investment range, language preference, project description, business model inputsFeasibility Study / DPR intake form
Payment DataTransaction ID, payment status, coupon code used. Card/bank credentials are NOT collected or stored by Business Roadmap — processed exclusively by our payment gateway partners.Payment gateway (third-party processed)
Usage DataPages visited, session duration, device type, browser, IP address, referral sourceCookies, server logs, Google Analytics
Communication DataEmails, WhatsApp messages, and support queries voluntarily sent to usDirect communication channels

We do not collect sensitive personal data pertaining to religion, caste, political opinions, health conditions, sexual orientation, or biometric identifiers. You are responsible for ensuring that any data submitted by you is accurate, complete, and lawfully provided. Business Roadmap shall not be liable for any consequences arising from inaccurate or misleading data submitted by you.

4
Purpose of Processing & Legal Basis
DPDP Act §5, §6, §7

We process your personal data only for specified, explicit, and legitimate purposes under the DPDP Act, 2023. The legal bases applicable are Consent (§6) and Certain Legitimate Uses (§7):

PurposeLegal Basis
User registration, OTP-based authentication, and identity verificationConsent
Delivery of Feasibility Study, Due Diligence, and DPR reportsConsent / Contractual Service
Payment processing, invoicing, and transaction record maintenanceConsent / Legal Obligation
Customer support, query resolution, and grievance handlingConsent / Legitimate Use
Service updates, report delivery alerts, and status notificationsConsent
Promotional communications, newsletters, and business insights (opt-in only)Consent (withdrawable)
Platform improvement, AI model quality enhancement, and analyticsConsent (aggregated/anonymized)
Legal compliance, fraud prevention, audit requirements, and enforcement of our rightsLegal Obligation / Legitimate Use
Protecting the rights, property, and safety of Business Roadmap, its team, and other usersLegitimate Use / Legal Obligation
Purpose Limitation: Business Roadmap will not use your personal data for purposes materially different from those stated above without obtaining your consent. However, anonymized or aggregated data that cannot be used to identify you may be used by Business Roadmap for research, benchmarking, product development, and business intelligence without restriction.
5
Consent Mechanism
DPDP Act §6 — Free, Specific, Informed, Unconditional, Unambiguous

We obtain your consent through clear affirmative acts prior to collecting and processing your personal data. Our consent mechanism operates through:

a) Email OTP Verification — via our email service provider at the time of service request submission, confirming ownership of the email address provided.
b) Phone OTP Verification — via Firebase Authentication (SMS OTP) to validate your mobile number.
c) Explicit Checkbox Confirmation — a distinct, pre-unchecked checkbox on our intake forms confirming your acceptance of this Privacy Policy before form submission.

By completing any of the above verification steps and submitting your service request, you provide informed and unambiguous consent for the collection and processing of your personal data for the purposes stated in this Policy.

Right to Withdraw Consent: You may withdraw your consent for future processing at any time by writing to Contact@businessroadmap.in. Withdrawal of consent shall not affect the lawfulness of any processing carried out prior to such withdrawal. Importantly, if you withdraw consent after a service has been initiated or delivered, Business Roadmap shall have no obligation to issue a refund, and the withdrawal of consent shall not entitle you to cancel a delivered or in-progress service. We will process consent withdrawal requests within a reasonable timeframe as operationally feasible.

Important: Accessing our website, submitting a query, or initiating a payment constitutes implicit acceptance of this Policy even in the absence of an explicit checkbox, to the extent permitted under applicable law. We strongly advise you to read this Policy before engaging with our platform.
6
How We Use Your Data
Internal Processing Activities

Your personal data is processed by our internal AI-powered framework and authorized human oversight team strictly for the following activities:

1. Report Generation: Business information submitted by you is processed by our AI agents to generate Feasibility Study Reports, Due Diligence Reports, or Detailed Project Reports — delivered via a secure, unique URL to your registered email. The content and quality of AI-generated reports is subject to our standard terms and conditions.

2. Service Communication: Your mobile number and email address are used for OTP delivery, report notifications, and support communications. WhatsApp may be used as a supplementary channel where you have provided consent, and we reserve the right to communicate with you through any channel for which you have provided contact details in connection with our services.

3. Quality Assurance & Training: Your submitted data (anonymized where practicable) may be reviewed by our internal team and used to enhance the performance, accuracy, and quality of our AI systems and service delivery. By using our services, you acknowledge and consent to this use.

4. Business Intelligence & Analytics: Aggregated and anonymized usage patterns are analyzed to improve our platform and service offerings. Business Roadmap reserves the right to publish aggregated, non-identifiable market insights derived from collective user data.

5. Legal, Compliance & Protection: Your data may be used to fulfill legal obligations, respond to governmental or judicial orders, enforce our contractual rights, prevent fraud, and protect the interests of Business Roadmap and its users.

7
Data Sharing & Disclosure
DPDP Act §8(3) — Data Processor Obligations

Business Roadmap does not sell, rent, or trade your personal data to any third party for their independent commercial purposes. However, we share data with trusted service providers and as required by law, as set out below:

RecipientPurposeSafeguard
Google LLCOTP authentication, report storage, automated report generation and deliveryGoogle's enterprise security standards and data processing terms
Standard Service ProviderOTP email delivery and report notificationStandard Data Processing Agreement
Payment Gateway PartnersSecure payment processing and transaction verificationRBI-compliant, PCI-DSS certified processors
TinyURLURL shortening for report delivery linksNo personal data shared beyond URL string content
Government / Legal / Regulatory AuthoritiesCompliance with applicable laws, court orders, regulatory directives, law enforcement requests, or to defend Business Roadmap's legal rightsMandatory legal basis; disclosure limited to what is required
Business SuccessorsIn the event of a merger, acquisition, restructuring, or sale of Business Roadmap's assets, your data may be transferred to the successor entity as part of business assetsSuccessor bound by equivalent privacy obligations

All data processors engaged by Business Roadmap are contractually obligated to process your data solely as per our instructions and to maintain security standards consistent with the DPDP Act, 2023. Business Roadmap is not responsible for the independent privacy practices of any third-party platforms you may navigate to from our website.

8
Data Retention
DPDP Act §8(7) — Storage Limitation

We retain your personal data for as long as is necessary to fulfill the purpose for which it was collected, to comply with applicable legal obligations, to resolve disputes, and to enforce our agreements. The following retention schedule applies as a general guideline:

Data CategoryRetention PeriodPost-Retention Action
OTP and Authentication Logs180 days from generationAutomatic deletion
Feasibility Study / Report & Business Data5 years from delivery dateArchived securely; purged thereafter
Payment & Transaction Records8 years (Income Tax Act, 1961 and GST compliance)Archived; no active processing post-service period
Communication Records (Email / WhatsApp)3 years from last interactionDeleted at end of retention unless legally required
Website Usage / Analytics Data26 monthsAggregated or auto-deleted per analytics platform settings
Inactive User Records5 years from last activityAnonymized or deleted after reasonable notice

Business Roadmap reserves the right to retain data beyond the periods specified above where required by law, ongoing legal proceedings, regulatory investigations, or to protect our legitimate legal interests. Retention periods are subject to review and may be revised by Business Roadmap without prior notice.

9
Your Rights as a Data Principal
DPDP Act §11–§14 — Statutory Rights & Operational Limitations

Under Chapter III of the DPDP Act, 2023, you have the following statutory rights with respect to your personal data held by Business Roadmap. These rights are subject to the limitations, exceptions, and operational constraints described herein:

Right to Access Information (§11)

Request a summary of the personal data we hold about you and the categories of processing carried out. We will provide this within a reasonable timeframe, subject to verification of your identity.

Right to Correction & Erasure (§12)

Request correction of inaccurate data or erasure of data no longer required for the purpose collected — subject to our legal retention obligations and operational requirements. Erasure of data does not entitle you to a refund for services already rendered.

Right to Grievance Redressal (§13)

Lodge a complaint with our designated Grievance Officer. If unresolved to your satisfaction, you may escalate to the Data Protection Board of India.

Right to Nominate (§14)

Nominate another individual to exercise your data rights on your behalf in the event of death or incapacity. Nomination requests must be submitted in writing with supporting documentation.

Right to Withdraw Consent

Withdraw consent for future processing at any time. Business Roadmap will act on the withdrawal within a reasonable operational timeframe. Withdrawal does not apply retrospectively to data already processed or services already delivered.

Right to Know — AI Processing

Where our AI systems are used to process your business data for report generation, you are hereby informed of this at the time of service purchase. Human oversight is applied as part of our quality assurance process.

How to Exercise Your Rights: Submit your request in writing to Contact@businessroadmap.in with your registered email/mobile number for identity verification. We will respond within 30 days for standard requests. Complex or high-volume requests may require up to 60 days, with notice to you. Business Roadmap reserves the right to decline requests that are frivolous, repetitive, technically infeasible, or that would compromise our legal obligations or the rights of other data principals.
10
Data Security
DPDP Rules 2025 — Reasonable Security Safeguards

Business Roadmap implements reasonable and appropriate technical and organizational security measures consistent with industry standards and the DPDP Rules, 2025. Our security framework includes:

Technical Safeguards: HTTPS encryption (TLS 1.2+) for data in transit; Google Firebase enterprise-grade encryption at rest; OTP-based two-factor authentication; role-based access controls; automated session management and token expiry.

Organizational Safeguards: Only authorized personnel within Business Roadmap have access to personal data on a strict need-to-know basis. AI-assisted monitoring is in place for anomalous access patterns. Periodic internal reviews of data handling procedures are conducted.

Data Breach Response: In the event of a personal data breach that poses a material risk to Data Principals, Business Roadmap will notify the Data Protection Board of India in accordance with applicable provisions of the DPDP Act and DPDP Rules. Affected Data Principals will be informed as appropriate and as directed by the Data Protection Board.

Limitation of Security Liability: While Business Roadmap employs industry-standard security safeguards, no digital system can guarantee absolute protection against all threats. Business Roadmap shall not be liable for any unauthorized access, data breach, or loss of data arising from: (a) your own disclosure of credentials or OTPs to any person; (b) use of our services from unsecured networks or devices; (c) actions of third-party platforms beyond our control; or (d) force majeure events including cyberattacks by state or non-state actors. You are responsible for maintaining the confidentiality of your account credentials and OTPs at all times.
11
Children's Data
DPDP Act §9 — Protection of Minors

Business Roadmap's services are directed exclusively at adults aged 18 years and above. By using our platform or availing our services, you represent and warrant that you are at least 18 years of age. We do not knowingly collect or process personal data of individuals under 18 years of age.

If we determine that personal data of a minor has been collected, we will take reasonable steps to delete such data promptly. Business Roadmap shall not be liable for any consequences arising from misrepresentation of age by any user. If you suspect that a minor has accessed our services, please notify us immediately at Contact@businessroadmap.in.

We do not engage in behavioral monitoring, targeted advertising, or profiling of children, consistent with §9 of the DPDP Act, 2023.

12
Cross-Border Data Transfers
DPDP Act §16 — International Processing

Certain third-party data processors engaged by Business Roadmap are headquartered outside India and may process your data on servers located in other countries, including the United States.

Business Roadmap ensures such transfers are made only to jurisdictions not restricted under §16 of the DPDP Act, 2023. All such transfers are governed by applicable contractual safeguards and the security obligations under the DPDP Rules, 2025. By using our services, you consent to the transfer of your personal data to these jurisdictions to the extent necessary for service delivery.

Business Roadmap will monitor and update its data processor arrangements in accordance with any restricted country list published by the Government of India under the DPDP Act.

13
Intellectual Property & Report Ownership
Protection of Business Roadmap's Proprietary Assets

All reports, analyses, frameworks, methodologies, AI-generated outputs, content, branding, and documentation created or delivered by Business Roadmap — including Feasibility Study Reports, Due Diligence Reports, and Detailed Project Reports — are the exclusive intellectual property of Business Roadmap, unless expressly stated otherwise in a separate written agreement.

Upon payment and delivery of a report, you are granted a limited, non-exclusive, non-transferable, personal license to use the delivered report for your own private business evaluation purposes only. You may not reproduce, redistribute, resell, publish, modify, sub-license, or commercially exploit any report or content delivered by Business Roadmap without our prior written consent.

Any business ideas, inputs, or data you submit to Business Roadmap for the purpose of report generation are processed by us on a confidential basis for service delivery. Business Roadmap does not claim ownership over your underlying business idea. However, aggregated market patterns and insights derived from collective user data remain the property of Business Roadmap and may be used for research and product development.

Confidentiality Commitment: Business Roadmap treats the specific business details submitted by each client as confidential and will not disclose individual client business ideas to other clients or third parties except as required by law or as specified in this Policy.
14
Limitation of Liability
Disclaimer & Indemnification

Business Roadmap's reports, analyses, and AI-generated outputs are provided for informational and advisory purposes only and do not constitute legal, financial, investment, regulatory, or professional advice. Business Roadmap does not guarantee the accuracy, completeness, or fitness of any report for any specific commercial purpose.

To the maximum extent permitted by applicable law, Business Roadmap, its directors, employees, agents, and AI systems shall not be liable for:

(a) Any business decision made by you in reliance on our reports or data;
(b) Any loss of profit, revenue, business opportunity, or goodwill arising from use of our services;
(c) Any data loss, unauthorized access, or breach arising from your own actions or third-party systems;
(d) Any inaccuracies in AI-generated content resulting from erroneous or incomplete data submitted by you;
(e) Any delay in report delivery beyond our standard timelines due to technical failures, third-party outages, or force majeure events;
(f) Any regulatory, legal, or financial consequences arising from business decisions made using our reports.

In any event, the maximum aggregate liability of Business Roadmap to you under this Policy or in connection with our services shall not exceed the amount actually paid by you for the specific service in question.

Indemnification: You agree to indemnify and hold harmless Business Roadmap, its officers, directors, employees, and agents from any claims, damages, losses, liabilities, or expenses (including legal fees) arising out of: (a) your breach of this Policy; (b) your misuse of our services; (c) your submission of inaccurate, false, or misleading data; or (d) your violation of any applicable law.

15
Governing Law & Jurisdiction
Dispute Resolution

This Privacy Policy and all matters arising out of or in connection with it shall be governed by and construed in accordance with the laws of India, including but not limited to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the Indian Contract Act, 1872.

Any dispute, claim, or controversy arising out of or relating to this Policy, your use of our services, or the collection or processing of your personal data shall be subject to the exclusive jurisdiction of the courts located in Gautam Buddh Nagar (Noida), Uttar Pradesh, India. By using our platform, you irrevocably submit to this jurisdiction and waive any objection to proceedings in these courts on grounds of inconvenient forum.

Before initiating any formal legal proceedings, you agree to first attempt resolution by writing to Business Roadmap at Contact@businessroadmap.in with a detailed description of your grievance. Business Roadmap will make reasonable efforts to resolve the matter within 30 days of receiving such notice.

Applicable Statutory Framework: Digital Personal Data Protection Act, 2023 · DPDP Rules, 2025 · Information Technology Act, 2000 · IT (Reasonable Security Practices & SPDI) Rules, 2011 (transitional) · Indian Contract Act, 1872 · Consumer Protection Act, 2019
16
Grievance Redressal
DPDP Act §13 — Complaint & Escalation Mechanism

Business Roadmap has designated a Grievance Officer to handle all complaints and requests related to personal data processing under this Policy. You may contact the Grievance Officer at:

Grievance Officer
Designated Privacy Officer
Business Roadmap
Email
Contact@businessroadmap.in
Registered Address
Business Roadmap, Sector 52
Noida, Uttar Pradesh – 201301
Response Timeline
Within 30 days of receipt
(complex cases: up to 60 days)

If your grievance is not resolved to your satisfaction after following the above process, you may escalate your complaint to the Data Protection Board of India. The Telecom Disputes Settlement and Appellate Tribunal (TDSAT) serves as the appellate authority.

Note: Business Roadmap will not be responsible for complaints filed directly with the Data Protection Board without first allowing our Grievance Officer a reasonable opportunity to resolve the matter. We recommend exhausting the internal grievance mechanism before escalating.
17
Policy Updates
Version Control & Notification

Business Roadmap reserves the absolute right to update, modify, or replace this Privacy Policy at any time, at its sole discretion, to reflect changes in applicable law, business practices, service offerings, or data processing activities. The revised Policy will be posted at businessroadmap.in/privacy-policy with an updated effective date.

For material changes — defined as changes that substantively alter your rights or our data processing practices — we will make reasonable efforts to notify registered users via email or a website notice. However, it is your responsibility to periodically review this Policy. Continued use of our website or services following any update constitutes your acceptance of the revised Policy.

Business Roadmap shall not be liable for any consequences arising from your failure to review updated versions of this Policy. If you disagree with any revision, your sole remedy is to discontinue use of our services. No revised Policy shall affect transactions already completed or reports already delivered prior to the effective date of the revision.

18
Contact Us
Privacy Queries & Requests

For any queries, requests, or concerns regarding your personal data or this Privacy Policy, please contact us through the following channels:

Privacy Email
Contact@businessroadmap.in
Office Address
Sector 52, Noida
Uttar Pradesh – 201301, India
Business Hours
Mon – Sat: 10:00 AM – 6:00 PM IST
Identity Verification: All requests relating to your personal data must be submitted from your registered email address or include your registered mobile number for verification purposes. Business Roadmap reserves the right to decline requests that cannot be verified or that are otherwise not actionable under applicable law.