After8 — Privacy Policy

Effective Date: [Insert Date]

DRAFT prepared to the standard of Indian data protection and consumer law (DPDP Act 2023, IT Act 2000, IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and Consumer Protection Act, 2019). This document must still be executed/reviewed by a licensed advocate before publication — placeholders in red require entity-specific input.

1. Introduction and Scope

This Privacy Policy ("Policy") is published in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 ("IT Act"), and the rules framed thereunder, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. It describes how Third Room LLP, a limited liability partnership incorporated under the laws of India, having its registered office at 5/1401, Vasant Lawns, Thane, Mumbai, Maharashtra, India ("After8", "we", "us", "our", the "Data Fiduciary"), collects, processes, stores, discloses, and protects the personal data of individuals ("Data Principal", "you") who access the After8 website, dashboard, or attend After8 events, including Strangers Dinner, Lectures on Tap, Business Coaching, and Founders Circle (collectively, the "Platform").

This Policy forms part of, and must be read together with, our Terms and Conditions. Your use of the Platform constitutes your consent to the collection and processing of personal data as described herein.

2. Personal Data We Collect2.1 Data provided directly by you
  • Identity data: full name, gender, age, occupation
  • Contact data: mobile number (verified via One-Time Password), email address
  • Authentication data: Google sign-in credentials or email/password combination
  • Behavioural/preference data: personality test responses, collected once per account and reused for future event curation
  • Financial data: payment instructions processed by our payment aggregator, Razorpay Software Private Limited ("Razorpay"); After8 does not itself store full card, UPI, or bank account details
  • Correspondence: any information you submit via customer support, feedback, or event check-in
2.2 Data collected automatically
  • Device, browser, and log data, including IP address
  • Cookies and similar tracking technologies (Section 6)
  • Advertising identifiers where you arrive via a Meta (Facebook/Instagram) advertisement
2.3 Sensitive personal data

Certain data points collected — including personality test responses used for behavioural curation — may constitute sensitive personal data or profiling under applicable law. We process such data only with your explicit, informed consent, obtained at the point of collection, and for the specific purpose of event curation described in Section 3.

3. Purpose and Lawful Basis of Processing

In accordance with Section 4 of the DPDP Act, we process personal data only for the following specified purposes, on the basis of your consent or as necessary for performance of a contract with you:

  • Account creation, authentication, and OTP-based identity verification
  • Curation of event groupings and personalised recommendations using personality test data
  • Processing of RSVPs, one-off ticket payments, and subscription billing (including auto-renewal)
  • Transactional communication: confirmations and reminders via email and WhatsApp
  • Platform security, fraud prevention, and enforcement of our Terms and Conditions
  • Compliance with applicable law, regulatory requests, or court orders

We do not use your personal data for any purpose beyond what is disclosed in this Policy without obtaining your fresh, specific consent.

4. Disclosure of Personal Data to Third Parties

We do not sell, rent, or trade your personal data. We disclose personal data strictly on a need-to-know basis to the following categories of Data Processors, each bound by contractual confidentiality and data protection obligations:

  • Razorpay — for processing one-off event payments and subscription auto-renewal
  • Google LLC — where you elect to authenticate via Google sign-in
  • SMS/OTP gateway and WhatsApp Business API providers — for identity verification and transactional messaging
  • Meta Platforms, Inc. — where you interact with our advertisements, subject to Meta's own privacy practices, which we do not control
  • Venue partners — limited identity data (e.g., name) strictly for event check-in purposes
  • Government authorities, law enforcement, or regulators, where disclosure is mandated under applicable law or in response to a valid legal process

[List any additional data processors: analytics tools (e.g. Google Analytics), CRM, email service provider, WhatsApp Business Solution Provider name.]

We do not knowingly transfer personal data outside India except where a service provider's infrastructure requires it (e.g., cloud hosting); in such cases, transfer is subject to the restrictions, if any, notified by the Central Government under Section 16 of the DPDP Act.

5. Data Retention

We retain personal data only for as long as reasonably necessary to fulfil the purposes described in Section 3, or as required by applicable law, whichever is longer. Personality test data is retained for the lifetime of your account and is deleted upon account closure, save for anonymised aggregate data retained for analytics.

[Insert a defined retention schedule, e.g. "Account and transaction data: retained for 3 years post account-closure to meet accounting/tax obligations under the Income Tax Act, 1961 and Companies Act, 2013 (as applicable)."]

6. Cookies and Tracking Technologies

The Platform may deploy cookies, pixels (including the Meta advertising pixel), and similar technologies to measure advertising performance, remember preferences, and improve user experience. You may disable cookies through your browser settings; doing so may affect functionality of the Platform.

7. Your Rights as a Data Principal

In accordance with Chapter III of the DPDP Act, you have the right to:

  • Obtain a summary of the personal data being processed and the processing activities undertaken
  • Request correction, completion, or updating of your personal data
  • Request erasure of your personal data, unless retention is required for a legal purpose
  • Withdraw consent at any time, with effect prospective from the date of withdrawal, without affecting the lawfulness of processing carried out prior to withdrawal
  • Nominate an individual to exercise these rights on your behalf in the event of death or incapacity
  • Register a grievance with our Grievance Officer (Section 11) and, if unresolved, escalate to the Data Protection Board of India

We will endeavour to respond to a verified request within the timeline prescribed under the DPDP Act and its rules.

8. Data Security

In accordance with Section 8(5) of the DPDP Act and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we implement reasonable security safeguards appropriate to the nature of the data processed, including OTP-based authentication, encrypted transmission, and PCI-DSS compliant payment processing via Razorpay. In the event of a personal data breach that is likely to affect you, we will notify you and the Data Protection Board of India as required under Section 8(6) of the DPDP Act.

9. Children's Data

The Platform is intended solely for individuals aged 18 years and above. We do not knowingly collect or process personal data relating to any individual below the age of 18. If we become aware that we have inadvertently collected such data, we will take immediate steps to delete it and, where applicable, terminate the associated account.

10. Automated Processing and Profiling

We use your personality test responses to algorithmically curate event groupings. This constitutes a limited form of automated decision-making. It does not produce any legal or similarly significant effect concerning you, and you may contact our Grievance Officer to seek clarification on, or object to, this processing.

11. Grievance Officer

In accordance with the IT Act, the rules thereunder, and the DPDP Act, After8 has appointed the following Grievance Officer to address your queries and complaints regarding this Policy:

  • Name: Sonam Thakkar
  • Email: hello@after8.in
  • Address: Third Room LLP, 5/1401, Vasant Lawns, Thane, Mumbai, Maharashtra, India

We will endeavour to acknowledge grievances within 24-48 hours and resolve them within 15-30 days, in accordance with applicable timelines under the IT Rules and DPDP Act.

12. Governing Law

This Policy is governed by the laws of India. Any dispute arising under this Policy shall be subject to the dispute resolution mechanism and jurisdiction clause set out in our Terms and Conditions.

13. Changes to This Policy

We may revise this Policy periodically to reflect changes in our data practices or applicable law. Material changes will be notified to you through the Platform or via email, together with a revised Effective Date.

social iconsocial iconsocial icon
© 2025 GujaratAfter8 All rights reserved.