Page header background

Privacypolicy

Last Updated: 07-08-2026

This Privacy Policy describes how Hello Power Private Limited (‘Hello Power’, ‘we’, ‘us’, or ‘our’) collects, uses, stores, shares, and protects your personal data when you use the HelloPower mobile application, website (hellopower.in), and related services.

This notice is available in English. Upon request, we will endeavour to provide this policy in any of the 22 languages listed in the Eighth Schedule of the Constitution of India.

1. Identity of the Data Fiduciary

Hello Power Private Limited is the Data Fiduciary as defined under Section 2(i) of the DPDP Act. We determine the purpose and means of processing your digital personal data.

FieldDetail
Registered NameHello Power Private Limited
CINU41000KA2024PTC187175
Registered Address#26, 1st Floor, Sudarshan Auto Mobile Building,
Near Sandal Soap Factory Metro Station, Rajajinagar,
Bengaluru, Karnataka 560055
Contactreachus@hellopower.in
080-23322669
Grievance Officersee Section 11
2. Scope and Applicability

This policy applies to all users (‘Data Principals’) who:

  • Download or use the HelloPower mobile application (Android / iOS).
  • Visit or interact with our website at hellopower.in
  • Contact us via phone, email, WhatsApp, or any other channel.
  • Register as a customer, electrician, vendor, or service partner on our platform.

This policy does not apply to third-party websites or services linked from our platform. We are not responsible for the privacy practices of those entities.

3. Personal Data We Collect

We collect only the personal data necessary for the specified purposes (data minimisation). The following table provides an itemised description as required under Rule 3 of the DPDP Rules, 2025:

Data CategorySpecific Data PointsLegal BasisRetention Period
Identity DataFull name, profile photoConsent (S.6)Duration of account + 3 years
Contact DataMobile number, email addressConsent (S.6)Duration of account + 3 years
Location DataCity, pincode, precise GPS (for service matching)Consent (S.6)Session-based; aggregate retained 1 year
Device DataDevice type, OS version, app version, device IDLegitimate Use (S.7)1 year from last login
Booking & Transaction DataService bookings, order history, payment statusLegitimate Use (S.7) / Contract7 years (GST/accounting compliance)
Financial DataPayment instrument type (NOT card numbers; processed by Razorpay)Legitimate Use (S.7)7 years (statutory requirement)
Communication DataCustomer support messages, complaint recordsLegitimate Use (S.7)3 years from resolution
Usage DataApp navigation patterns, feature usage, crash logsConsent (S.6)1 year
Vendor / Electrician DataTrade licence, Aadhaar (verification only), GSTIN, skillsConsent (S.6) + Legal ObligationDuration of contract + 7 years

We do not collect Sensitive Personal Data such as biometric data, health records, financial passwords, or political/religious beliefs. Aadhaar numbers collected for electrician verification are processed as per applicable UIDAI guidelines and are not stored in raw form.

4. Purpose of Processing

We process your personal data strictly for the following specified purposes. We do not use your data for any purpose beyond what is listed here without obtaining fresh consent:

  • Account creation, authentication, and profile management.
  • Matching customers with qualified electricians and vendors based on location and service type.
  • Processing service bookings, orders, payments, and generating GST-compliant invoices.
  • Facilitating vendor onboarding, document verification, and KYC compliance.
  • Providing real-time delivery and job tracking via in-app features.
  • Sending transactional communications (booking confirmations, OTPs, invoices).
  • Sending promotional communications — only with your explicit consent, which you may withdraw at any time.
  • Detecting and preventing fraud, abuse, and security threats.
  • Improving app functionality, fixing bugs, and optimising user experience (using anonymised analytics).
  • Resolving customer grievances and providing support.
  • Complying with applicable laws, including GST, labour, and consumer protection regulations.
5. Consent and Legal Basis for Processing

We process your personal data only on two lawful bases as defined under the DPDP Act:

5.1 Consent (Section 6, DPDP Act)

Where we rely on consent, it is obtained through a free, specific, informed, unconditional, and unambiguous affirmative action by you (such as ticking a checkbox or tapping ‘I Agree’). Where processing is based on consent, users may withdraw consent through:

  • Account settings.
  • Contacting the Grievance Officer
  • Other mechanisms provided within the Platform.
5.2 Legitimate Use (Section 7, DPDP Act)

Certain processing is carried out on legitimate use grounds without consent, specifically for: performing services you have voluntarily requested, complying with statutory obligations (GST filing, labour law compliance), fraud prevention, and safety of the platform and its users.

Existing Users: If you registered with HelloPower before the effective date of this Policy, we will, as soon as reasonably practicable, notify you via in-app notification or email describing the personal data we hold and its purpose, and seek your reconfirmation of consent where required under Section 6(2) of the DPDP Act.
6. Sharing of Personal Data

We do not sell your personal data. We share personal data only to the extent necessary and only with the following categories of recipients:

Recipient CategoryPurpose of SharingSafeguards
Electricians / VendorsFulfilling your booked service (name, address, contact shared only)Contractual obligation; purpose-limited disclosure
Razorpay India Pvt. Ltd.Payment processing and settlementPCI-DSS compliant; processes payment data directly
Amazon Web Services (AWS)Cloud infrastructure hosting (EC2, RDS, S3)Data Processing Agreement; ISO 27001 certified
Redis Cloud (Upstash/Redis Labs)Session management and real-time featuresData Processing Agreement in place
Borzo (logistics partner)Delivery tracking and logistics coordinationContractual obligation; location data only
SMS / Communication ProvidersOTP delivery, booking notificationsPurpose-limited; no data retention beyond delivery
Government / RegulatorsCompliance with court orders, tax authorities, law enforcementOnly as mandated by applicable law

All third-party data processors are bound by contractual data processing agreements that restrict their use of your data to the stated purpose and require equivalent security standards.

7. Cross-Border Data Transfers

Our primary servers are located in India (AWS Mumbai region). Certain service components — including cloud infrastructure (AWS), Redis Cloud, and communication providers — may involve processing outside India. Such transfers are conducted only to countries and entities not restricted by the Central Government under Section 16 of the DPDP Act, and subject to data processing agreements incorporating appropriate safeguards. Personal data may be processed by service providers located outside India.

Where cross-border transfers occur, HelloPower shall implement appropriate contractual, organizational, and technical safeguards to ensure that personal data receives protection consistent with applicable Indian law.

Cross-border transfers shall not be undertaken to jurisdictions restricted by the Government of India.

8. Data Retention and Erasure

We retain personal data only for as long as necessary to fulfil the specified purpose or as required by applicable law. Specific retention periods are specified in Section 3 of this policy.

8.1 Automatic Erasure Triggers
  • Account deletion request by you.
  • Withdrawal of consent (data erased within 30 days of withdrawal).
  • Expiry of the retention period.
  • Reasonable determination that you are no longer an active user (i.e., no interaction for 3 years).
8.2 Pre-Erasure Notification

As required under the DPDP Rules 2025, we will notify you at least 48 hours before erasing your personal data on grounds of inactivity, giving you the opportunity to resume use of the platform.

Certain data may be retained beyond the standard period if required for pending legal proceedings, regulatory audits, or statutory obligations (e.g., GST records for 7 years as mandated by the GST Act).
9. Your Rights as a Data Principal

Under Chapter III of the DPDP Act, you have the following rights. We will respond to all requests within 30 days:

RightWhat It MeansHow to ExerciseTimeline
Right to Access (S.11)Know what personal data we hold about you and its purposeEmail grievance officer; request data summaryWithin 30 days
Right to Correct (S.12)Correct inaccurate or incomplete personal dataEmail with corrected details and supporting docsWithin 30 days
Right to Erase (S.12)Delete your account and associated personal dataRequest via app Settings > Delete Account or emailWithin 30 days
Right to Withdraw Consent (S.13)Withdraw consent for processing at any timeEmail grievance officer; automatic erasure triggeredImmediately; data erased within 30 days
Right to Grievance Redressal (S.13)Raise a complaint about data handlingContact Grievance Officer (Section 11)Response within 30 days
Right to Nominate (S.14)Nominate a person to exercise rights in case of death/incapacitySubmit nomination form via emailProcessed within 30 days

To exercise any of these rights, contact our Grievance Officer as described in Section 11. We may verify your identity before processing your request to prevent misuse.

Right to Complain to the Data Protection Board of India (DPBI): If your grievance is not resolved to your satisfaction within 30 days, you may escalate your complaint to the Data Protection Board of India (DPBI). The Board’s contact details and complaint submission process are available at: https://www.meity.gov.in
10. Children’s Personal Data

Our services are intended for users who are 18 years of age or older. We do not knowingly collect personal data from children (individuals under 18 years of age).

In compliance with Section 9 of the DPDP Act:

  • We will not process the personal data of a child without verifiable consent from a parent or legal guardian.
  • We will not process personal data in a manner that may cause harm to a child.
  • We do not engage in behavioral monitoring, tracking, or targeted advertising directed at children.

If you believe a child has provided us with personal data without parental consent, please contact our Grievance Officer immediately. We will delete such data promptly upon verification.

11. Grievance Officer

In accordance with Section 8(9) and Section 8(10) of the DPDP Act, we have designated a Grievance Officer responsible for addressing Data Principal concerns:

FieldDetail
DesignationGrievance Officer — HelloPower Privacy
Contact Emailreachus@hellopower.in
Phone080-23322669
Mailing Address#26, 1st Floor, Sudarshan Auto Mobile Building,
Near Sandal Soap Factory Metro Station, Rajajinagar,
Bengaluru, Karnataka 560055
Response TimeframeWithin 30 days of receipt of complaint

If you remain dissatisfied after completion of HelloPower’s grievance process, you may seek remedies available under applicable law, including filing complaints with competent authorities designated under the Digital Personal Data Protection Act, 2023.

12. Security of Your Personal Data

We implement a layered combination of administrative, technical, and physical security measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
  • Access controls and role-based permissions for all internal staff.
  • Secure cloud infrastructure on AWS (Mumbai region) with VPC isolation.
  • Regular security assessments and vulnerability scanning.
  • Incident response procedures aligned with the DPDP Act breach notification obligations.
12.1 Personal Data Breach Notification

In the event of a personal data breach, we will, as required under Section 8(6) of the DPDP Act:

  • Notify the Data Protection Board of India within 72 hours of becoming aware of the breach.
  • Notify affected Data Principals promptly, describing the nature of the breach, likely consequences, and remedial measures taken.
  • Contain and mitigate the breach and conduct a post-incident audit.
No method of data transmission or storage is completely secure. While we implement industry-standard safeguards, we cannot guarantee absolute security. We encourage you to use strong, unique passwords and keep your account credentials confidential.
13. Cookies and Tracking Technologies

Our mobile app does not use browser cookies. Our website hellopower.in uses the following:

Cookie TypePurposeMandatory
Essential CookiesAuthentication, security, session managementYes
Analytics CookiesUsage analytics and performance monitoringNo
Marketing CookiesPersonalized marketing and advertisingNo

You may manage your cookie preferences through the cookie settings banner displayed on first visit to our website, or by adjusting your browser settings.

14. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable law. When we make material changes:

  • We will notify you via in-app notification and/or email at least 30 days before the changes take effect.
  • The updated policy will be posted on hellopower.in/privacypolicy/ with the revised effective date.
  • Continued use of our services after the effective date constitutes acceptance of the updated policy

For material changes that affect your rights or the basis of processing, we will seek fresh consent where required under the DPDP Act.

15. Regulatory References

This Privacy Policy is drafted in compliance with and in reference to:

  • Digital Personal Data Protection Act, 2023 (No. 22 of 2023).
  • Digital Personal Data Protection Rules, 2025 (notified November 13, 2025).
  • Information Technology Act, 2000 and IT (Amendment) Act, 2008.
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
  • Consumer Protection Act, 2019.
  • Goods and Services Tax Act, 2017 (for data retention obligations).