Who we are and how to contact us
AAVKIRA is an invitation design studio based in India, serving clients worldwide. For privacy assistance, contact [email protected]. This policy describes our current website and project workflow; it is not a claim of certification or blanket compliance with every privacy regime.
Information we receive
The enquiry form collects your name, email, occasion, requested service and message. You may optionally provide a phone number and calling code, event date, reference links, and uploaded images or PDFs. It records your agreement to be contacted about the enquiry.
In the course of a project, we may receive wedding/event information, invitation wording, voluntarily supplied family information, photographs, design references, files, communications and billing/invoice details needed for the agreed work. Do not supply unnecessary personal information, government IDs, passport details, passwords, financial account credentials or highly sensitive information. Include only details reasonably needed for your project, and obtain appropriate permission for other people’s content and information.
How we use information
Information is used to respond to enquiries, prepare quotations, provide design services, build invitations, host invitation webpages, communicate with clients, manage billing and projects, provide support, protect website security, prevent misuse, meet applicable legal/accounting obligations and improve our service. We use information only for relevant purposes and an appropriate basis under applicable law.
We do not use client content for unrelated marketing without an appropriate legal basis or permission where required. Completing an enquiry or purchasing design work is not portfolio consent.
Private projects and public demonstrations
Client projects are private by default for portfolio and promotional use. Original design rights are separate from permission to disclose personal information. Public display needs separately recorded permission for approved original details or an anonymised version; no response means private.
For anonymised presentations we remove or replace identifying details such as names, dates, family details, contact information, home/private venue addresses, RSVP details, QR codes, private links and maps. Personal photographs require appropriate separate approval. Fictional demonstrations are labelled and must not be mistaken for actual client work.
Private invitation webpages are not included in the marketing sitemap or public project listings and should carry noindex instructions. Noindex does not make a link secret, prevent screenshots or guarantee removal from every search engine. Unprotected invitations may be accessible to anyone with the link. Share links carefully and discuss sensitive content or genuine access control before publication.
Website analytics, technical data and cookies
Our public marketing code sends an aggregate page-load event for recognised public pages to our own endpoint. It does not use Google Analytics, Meta Pixel, advertising cookies or browser local/session storage. The event uses the page path, not query parameters or enquiry content. The collector ignores supported Do Not Track / Global Privacy Control signals and simple bot indicators.
Cloudflare makes the connecting IP address available to server-side code. For the aggregate-view abuse limit, the code stores a daily rotating, secret-salted IP hash and a count; it does not store the raw IP in that analytics table. Old daily view-limit hashes are removed on subsequent collection; aggregate daily page counts remain stored. This is not a guarantee of anonymity.
Enquiry and admin-login rate limiting also uses secret-salted IP hashes; these are separate from the daily analytics hash. Enquiry hashes remain with enquiry records unless those records are removed. Cloudflare and email providers may process network, device or service/security logs under their own arrangements; we do not claim a specific physical storage location.
The restricted owner dashboard uses essential HttpOnly, Secure, SameSite session/OAuth cookies for sign-in and email connection. These are not advertising cookies. The invitation demo is embedded from demowebpage.aavkira.com; loading or following external links can involve the relevant host’s technical processing. The marketing-site audit does not establish that every hosted invitation or third-party destination has identical cookies or storage.
Cloudflare analytics and performance
The live site also loads a Cloudflare Web Analytics/performance beacon, injected by the hosting service rather than our source files. It collects website usage and performance measurements, such as page-load and browser information. Cloudflare describes Web Analytics as cookie-free; this does not make every infrastructure request free of technical data processing. You can read Cloudflare’s Web Analytics description. Our own collector’s Do Not Track / Global Privacy Control behavior described above should not be assumed to apply to this separately managed beacon.
Service providers and international processing
Confirmed technical services include Cloudflare Pages/Functions for hosting and request handling, Cloudflare D1 for project records, Cloudflare R2 for reference uploads, Cloudflare Web Analytics/performance reporting, and Google Gmail/API for email notifications and communications. GitHub is used for website source/deployment collaboration, not as an intended store for private client uploads. We may use relevant domain, email, infrastructure and professional service providers as required for the project. No direct payment gateway is integrated into this public enquiry site.
Service providers may process information outside your country. Exact storage locations and deployment settings are not established by this source-code audit. We consider applicable requirements for such processing; this statement is not a claim of worldwide certification. We do not unnecessarily upload private material to external AI/design tools; identifiable confidential content requiring such a workflow should be discussed with you, with permission obtained where appropriate.
Retention and invitation expiry
An AAVKIRA-hosted invitation webpage normally remains publicly available until one month after the relevant event date unless otherwise agreed in writing; it may then be deactivated or removed. This is separate from internal retention and is not a promise of automatic permanent deletion of all personal information.
Project files, enquiry records, communications, approval evidence, invoices and other business records are kept only as reasonably required for service delivery, project records, accounting, legal obligations, disputes, security and legitimate business administration. Retention is reviewed according to those needs; we do not prescribe an unsupported universal deletion period. Records in recoverable archive/trash are not yet permanently deleted, and provider backups may have separate lifecycles.
Security and limits
The owner dashboard requires authenticated access before exposing enquiry and business data. Uploaded enquiry references are retrieved through an authenticated endpoint, rather than public gallery links. Server-side secrets are not intended to be included in public website code.
We use reasonable technical and organisational precautions, but no website or transmission can be guaranteed completely secure. Do not send unnecessary sensitive details. If you believe information has been exposed or mishandled, contact us promptly so we can investigate and respond according to applicable requirements.
Your requests and international rights
Depending on applicable law and your circumstances, you may request access, correction, deletion, withdrawal of consent or privacy assistance through [email protected]. We may need proportionate information to verify your identity, without asking for unnecessary identification documents. We explain any lawful reason we cannot fully fulfil a request. Withdrawal does not undo lawful processing already carried out and may affect services requiring that information.
Mandatory privacy rights vary by location and will be respected where applicable. Nothing in this policy excludes rights that cannot lawfully be excluded. You may use relevant complaint or regulatory channels available under applicable law. Contact us with concerns; we will assess applicable rights and obligations without claiming certification under GDPR, UK GDPR, CCPA or other regimes.
Changes and related terms
We may update this policy to reflect actual changes to our services or data handling. The update date appears above. Where applicable, material changes require appropriate notice or consent. Project payment, design rights and hosting terms are described in our Terms & Conditions.
Questions? Contact [email protected].
