Privacy Policy
Effective date: June 29, 2026
1. Introduction
This Privacy Policy (“Policy”) describes how Huddle (“Huddle”, “we”, “our” or “us”) collects, uses, discloses, transfers, retains and protects personal data of users (“User”, “you” or “your”) of the Huddle event-networking service (the “Service”). This Policy is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, where applicable to Users in the European Economic Area or the United Kingdom, the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) and the UK GDPR.
2. Data Fiduciary / Controller
The data fiduciary under the DPDP Act and the data controller under the GDPR is Abhinav Ayyagari, sole proprietor, having its principal place of operation in India. All correspondence relating to this Policy or to the processing of personal data shall be addressed to ayyagariabhinav21@gmail.com.
3. Grievance Officer
In accordance with Rule 5 of the Digital Personal Data Protection Rules, 2025 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the following individual has been designated as the Grievance Officer:
- Name: Abhinav Ayyagari
- Designation: Founder and Grievance Officer
- Electronic mail: ayyagariabhinav21@gmail.com
- Jurisdiction: Republic of India
The Grievance Officer shall acknowledge receipt of any complaint within seventy-two (72) hours and shall dispose of the complaint within thirty (30) days of its receipt, or such shorter period as may be prescribed by applicable law. A User may also lodge a complaint with the Data Protection Board of India once it accepts public complaints, or, in the case of a User resident in the European Economic Area or the United Kingdom, with the supervisory authority of the User’s habitual residence, place of work or place of the alleged infringement.
4. Categories of Personal Data Collected
4.1 Data received from LinkedIn via OpenID Connect
Where a User authenticates using the “Sign in with LinkedIn” flow, LinkedIn Corporation (or LinkedIn Ireland Unlimited Company, in the case of Users in the European Economic Area or the United Kingdom) transmits the following data to Huddle:
- Full name;
- Electronic mail address;
- Profile picture (URL hosted by LinkedIn);
- The OpenID Connect “sub” identifier (a stable internal identifier issued by LinkedIn).
Huddle does not receive, request or store any further information from LinkedIn, including (without limitation) the User’s connections, employment history, education, posts, messages or LinkedIn vanity URL.
4.2 Data provided directly by the User
- LinkedIn vanity username (mandatory; entered manually during onboarding);
- Biographical statement of up to a short paragraph (optional);
- Replacement profile photograph uploaded by the User (optional);
- Usernames or URLs for X (Twitter), Instagram, GitHub and a personal portfolio (each optional);
- Event participation requests, including event join code, requested classification and consent thereto.
4.3 Data generated through use of the Service
- Records of clicks on LinkedIn profile links presented within event rooms, including the identifier of the clicking User, the identifier of the User whose link was clicked, and the timestamp;
- Membership approval status assigned by the event organizer;
- Attendance status marked by the event organizer;
- Announcements authored by the User (where the User is an event organizer);
- System timestamps recording the creation and most recent modification of the User’s profile.
4.4 Data supplied by event organizers
An event organizer may upload, by means of a comma-separated-values file, the team-lead electronic mail address, team name and group identifier of participants. Such data is processed solely for the purpose of allocating the participant to the correct team room within the relevant event. The event organizer warrants and represents that it has a lawful basis under applicable law to disclose such data to Huddle.
5. Purposes and Legal Bases of Processing
Huddle processes personal data only for purposes specified in this Policy and only to the extent necessary for those purposes. The legal bases relied upon are stated below:
- Account creation and authentication; profile display within event rooms; service-related communications — performance of a contract with the User pursuant to Article 6(1)(b) GDPR; consent of the User pursuant to Section 6 of the DPDP Act.
- Display of aggregated profile-view metrics (LinkedIn click counts) — legitimate interests pursued by Huddle and by Users in facilitating professional networking, pursuant to Article 6(1)(f) GDPR; consent under the DPDP Act. A User may object to such processing at any time by contacting the Grievance Officer.
- Security, fraud-prevention and platform integrity — legitimate interests pursuant to Article 6(1)(f) GDPR; compliance with statutory obligations under Indian law.
- Compliance with legal obligations — Article 6(1)(c) GDPR and applicable Indian law.
Huddle does not engage in behavioural advertising, does not sell personal data, and does not carry out automated decision-making producing legal or similarly significant effects on the User within the meaning of Article 22 GDPR.
6. Disclosure and Sharing
6.1 Disclosure to other Users of an event
Upon a User’s admission to an event room, the User’s full name, profile picture, biographical statement, LinkedIn link and any optional social-media identifiers shall become visible to other approved members of the same event. This processing is integral to the Service.
6.2 Disclosure to event organizers
Event organizers shall have access, in respect of their own events only, to the participant’s name, LinkedIn username, classification, approval status, attendance status and the metadata of the participant’s membership record. Event organizers shall not have access to a participant’s authentication credentials or to any data relating to other events.
6.3 Data processors and sub-processors
Huddle engages the following processors, each of whom processes personal data under written instructions and, where applicable, under Standard Contractual Clauses approved by the European Commission:
- Supabase Inc., a Delaware corporation, providing database, authentication, object storage and realtime services. Hosting region: Asia Pacific (Seoul, Republic of Korea). Data-processing addendum: supabase.com/legal/dpa.
- Vercel Inc., a Delaware corporation, providing application hosting and content-delivery services. Data-processing addendum: vercel.com/legal/dpa.
- LinkedIn Corporation (or, for European Economic Area and United Kingdom Users, LinkedIn Ireland Unlimited Company), acting as identity provider in respect of the OpenID Connect authentication flow. Privacy Policy: linkedin.com/legal/privacy-policy.
- GoDaddy Operating Company, LLC, providing domain-name registration services only; no personal data of Users is disclosed to GoDaddy.
6.4 International transfers
Personal data is stored on infrastructure operated by Supabase Inc. in the Seoul (ap-northeast-2) region and is delivered via Vercel’s global edge network. Transfers from the European Economic Area or the United Kingdom to non-adequate countries are governed by the Standard Contractual Clauses incorporated into the data-processing addenda referenced in clause 6.3. As at the effective date of this Policy, the Central Government of India has not notified any country as restricted under Section 16 of the DPDP Act, and accordingly no restriction under that Section presently applies to Huddle’s transfers.
6.5 Disclosure required by law
Huddle may disclose personal data where compelled to do so by a valid order of a court of competent jurisdiction or by a binding requirement of applicable law, or where disclosure is necessary to protect the rights, property or safety of Huddle, its Users or the public. Huddle does not sell, rent, lease or trade personal data.
7. Retention
Personal data shall be retained for the following periods:
- Profile data, event memberships, click history and avatar files: for the duration of the account, and deleted within thirty (30) days of an erasure request, or immediately upon the User exercising the in-app account-deletion function;
- System audit timestamps: for the duration of the account, and purged together with the account;
- Aggregated and irreversibly anonymized statistics: may be retained indefinitely as they no longer constitute personal data;
- Records required to be retained by law (including for taxation or security-incident investigation): for the minimum period prescribed by such law.
8. Rights of the Data Principal / Data Subject
Subject to applicable law, every User has the following rights and may exercise them through the in-app controls or by writing to the Grievance Officer:
- The right of access and to obtain a copy of personal data in a portable format (available in-app via “Export my data”);
- The right to rectification of inaccurate or incomplete data;
- The right to erasure (available in-app via “Delete my account”);
- The right to withdraw consent at any time, which Huddle shall make as easy to exercise as the giving of consent;
- The right to object to processing carried out on the basis of legitimate interests;
- The right to restriction of processing, where applicable under the GDPR;
- The right to nominate another individual to exercise these rights, in accordance with Section 14 of the DPDP Act;
- The right to lodge a complaint with the Data Protection Board of India or with the User’s supervisory authority.
Huddle shall respond to requests within thirty (30) days. Where a request is submitted by electronic mail, Huddle may require the User to send the request from the electronic-mail address associated with the User’s account for the purpose of identity verification.
9. Security Measures
Huddle has implemented reasonable security practices and procedures within the meaning of Section 43A of the Information Technology Act, 2000 and Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including transport-layer encryption, row-level security at the database layer, per-user isolation of uploaded files, and periodic review of access policies. Huddle does not have access to the User’s LinkedIn credentials. Notwithstanding the foregoing, no system can be guaranteed to be entirely secure. In the event of a personal-data breach, Huddle shall notify the Data Protection Board of India and the affected Users without undue delay, in accordance with Rule 7 of the Digital Personal Data Protection Rules, 2025 and, where applicable, Articles 33 and 34 GDPR.
10. Cookies and Local Storage
Huddle uses only storage which is strictly necessary for the provision of the Service, namely:
- Authentication cookies issued by Supabase (session and refresh tokens), exempt from the consent requirement under Article 5(3) of Directive 2002/58/EC as amended (ePrivacy Directive);
- A limited use of browser local storage for the persistence of user-interface preferences.
Huddle does not employ third-party advertising cookies, third-party analytics cookies, tracking pixels or session-replay technologies.
11. Minimum Age
The Service is not directed to, and is not intended for use by, persons under the age of sixteen (16). Where Huddle becomes aware that personal data of a person below the age of sixteen has been collected, such data shall be deleted without undue delay. Reports of suspected underage use should be sent to the Grievance Officer.
12. Amendments
Huddle may revise this Policy from time to time. Where a revision materially affects the categories of data collected, the purposes of processing, the recipients of data, the retention period or the rights of the User, Huddle shall provide not less than seven (7) days’ prior notice by in-application notification or by electronic mail. The effective date at the head of this Policy reflects the date of the most recent revision.
13. Contact
All correspondence relating to this Policy, including the exercise of rights and the submission of grievances, shall be addressed to: ayyagariabhinav21@gmail.com.