Skip to content
Soilo Essence - AI farming intelligence device for soil and water testing, from USD 499Learn more
Soilo

Privacy Policy

Effective Date: 29 June 2026Last Updated: 29 June 2026

DDverse Initiatives Private Limited ("we", "us", or "our") operates the Soilo mobile application, website, and related services. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the Soilo platform. By using the Services, you consent to the practices described in this Policy. If you do not agree, please discontinue use.

1. Company Information

Legal Entity: DDverse Initiatives Private Limited

Brand: Soilo

Registered Office: 19th Floor, WeWork Berger One Delhi, C-001/A2, Sector-16B, Noida, Uttar Pradesh – 201301, India

Email: soilo@ddverse.in

2. Data Controller and Legal Framework

When providing services directly to individual users (B2C), DDverse Initiatives Private Limited acts as the Data Controller (or Data Fiduciary under Indian law) and determines the purpose and means of processing your personal data.

When providing the Soilo Intelligence Dashboard to enterprise clients (B2B), DDverse Initiatives Private Limited acts as a Data Processor on behalf of the client organisation, who serves as the primary Data Controller. In those cases the client organisation's own privacy policy governs the processing of end-user data within their deployment.

For users in the European Economic Area (EEA), this Policy is designed to comply with the General Data Protection Regulation (GDPR). Under GDPR, you are a "data subject" and we are the "data controller".

For users in India, this Policy complies with the Digital Personal Data Protection (DPDP) Act, 2023. Under the DPDP Act, you are a "Data Principal" and DDverse Initiatives Private Limited is the "Data Fiduciary" responsible for processing your personal data in a lawful, fair, and transparent manner.

3. Information We Collect

We collect the following categories of information:

Account and Profile Data

Name, email address, organisation name, and role when you register. Authentication is handled exclusively via Google, Apple, or SSO email-based login. Phone numbers are not collected at registration. A phone number may optionally be provided in B2B billing contact fields where applicable.

Location and GPS Data

Coordinates of test sites, fields, and devices. We collect location data when you use field mapping and device location features. Location access can be controlled through your device settings.

Soil and Environmental Data

Soil parameter readings (NPK, pH, moisture, EC, temperature, organic carbon), field records, crop data, and any evidence documents you upload.

ESG and Compliance Data

ESG datapoints, emission activity records, filing references, and assurance outcomes you enter into the platform.

Device and Usage Data

Device identifiers, app version, operating system, crash reports, feature usage patterns, and session data.

Payment Data

Payment transactions processed through PayU. We do not store full card numbers or banking credentials: these are handled directly by PayU.

Communications

Messages you send to us via email or support channels.

4. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Soilo platform and its features
  • Process payments and manage subscriptions
  • Generate soil analysis, agronomic recommendations, and carbon estimates
  • Enable ESG reporting, filing, and compliance workflows
  • Send transactional communications including account notifications and support responses
  • Improve the App through usage analytics and crash reporting
  • Comply with legal obligations
  • Detect and prevent fraud and abuse
  • Process orders, returns, and warranty claims

5. Legal Basis for Processing

EEA Users (GDPR)

For users in the European Economic Area, our legal bases for processing are:

  • Contract performance: processing necessary to provide the services you have subscribed to
  • Legitimate interests: improving the App, preventing fraud, and ensuring security
  • Legal obligation: complying with applicable laws
  • Consent: for optional communications and marketing, where you have opted in

Indian Users (DPDP Act, 2023)

For users in India, processing of your personal data is carried out on the following bases as prescribed by the Digital Personal Data Protection Act, 2023:

  • Valid consent: you have given free, specific, informed, unconditional, and unambiguous consent for one or more specified purposes
  • Certain legitimate uses: processing necessary to perform a contract you are party to, comply with a legal obligation, respond to a medical emergency, carry out activities related to employment, or for purposes notified by the Central Government

6. Data Sharing and Third Parties

We do not sell your personal data. We share data only as follows:

  • PayU: payment processing. PayU's privacy policy governs their handling of payment data.
  • Google: Maps API for location services (device mapping features only).
  • Anthropic: AI language model API used for generating narrative summaries within the platform. Data sent is anonymised where possible and governed by Anthropic's data processing terms.
  • Cloud infrastructure providers: hosting and storage of the App and its data.
  • Logistics partners: for device order fulfilment and delivery.
  • Legal authorities: if required by law, court order, or to protect the rights and safety of the Company, its users, or the public.

We require all third-party processors to maintain appropriate data security standards and to use your data only as necessary to provide their services.

In the event of a merger, acquisition, or sale of assets, user information may be transferred to the acquiring entity.

7. International Data Transfers

Your data may be processed and stored in countries outside your country of residence, including India. For users in the EEA, we ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses where required.

8. Data Retention

We retain your personal data for as long as your account is active or as necessary to provide services. Specifically:

  • Account data: retained for the duration of your account plus 3 years after termination
  • Soil and environmental data: retained for the duration of your account. You may export your data at any time.
  • Tenant-private AI retrieval data: deleted within 30 days of account termination
  • Payment records: retained as required by applicable financial regulations (typically 7 years)
  • Usage and analytics data: retained for up to 24 months in aggregated or anonymised form

After the retention period, data may be deleted, anonymised, or securely archived.

9. Your Rights

Depending on your jurisdiction, you may have the following rights:

All Users

  • Access: request a copy of the personal data we hold about you
  • Correction: request correction of inaccurate or incomplete data
  • Deletion: request deletion of your personal data, subject to legal retention requirements
  • Portability: receive your data in a structured, machine-readable format
  • Withdraw consent: where processing is based on consent, withdraw it at any time

EEA Users (additional GDPR rights)

  • Restriction: request that we restrict processing of your data in certain circumstances
  • Objection: object to processing based on legitimate interests
  • Complaint: lodge a complaint with your local supervisory authority

Indian Users (additional DPDP Act rights)

  • Right to Nominate: nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity
  • Right to Grievance Redressal: raise a grievance with us regarding processing of your personal data and receive a timely response; if unresolved, escalate to the Data Protection Board of India

To exercise any of these rights, contact us at soilo@ddverse.in. We will respond within 30 days.

10. Data Security

We implement industry-standard technical and organisational measures to protect your data, including encrypted data transmission (TLS), access controls with authentication, audit logging of data access events, and regular security reviews.

While we take reasonable precautions, no system is completely secure. We cannot guarantee the absolute security of your data and are not liable for breaches beyond our reasonable control.

11. Cookies and Tracking Technologies

The Soilo website uses cookies and similar technologies to maintain functionality, improve user experience, analyse traffic, measure performance, and enhance security.

The mobile App does not use browser cookies. We use anonymised analytics SDKs (such as crash reporting tools) to understand App performance.

You may disable website cookies through your browser settings, though some features may become unavailable. You may opt out of app analytics by adjusting your device settings or contacting us.

12. Children's Privacy

Our Services are not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, contact us at soilo@ddverse.in and we will delete it promptly.

13. Third-Party Links

Our Services may contain links to third-party websites or applications. We are not responsible for their privacy practices, content, or policies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the App or by email. The updated Policy will be effective from the date indicated at the top of this document.

Continued use of the Services constitutes acceptance of the updated policy.

15. Contact Us

For privacy-related queries, requests, or complaints:

DDverse Initiatives Private Limited

Email: soilo@ddverse.in

We aim to respond to all privacy enquiries within 30 days.

Contact

DDverse Initiatives Private Limited

19th Floor, WeWork Berger One Delhi, C-001/A2, Sector-16B, Noida, Uttar Pradesh – 201301

soilo@ddverse.in

Attention: Aditi Mishra