Skip to content
Last updated17 August 2026

Legal

Privacy policy

What ObjectiveDone collects, why, who it goes to, how long it is kept, and what you can make us do about it.

Operated from Karnataka, IndiaNo cookies on this siteNo analytics in the app

The short version

This summary is here because almost nobody reads a privacy policy end to end, and the parts that matter are short. It is a summary of the sections below and adds nothing to them, where the two could be read differently, the numbered sections govern.

  • Your contacts, notes, voice memos and reminders are private to your account. The database enforces that on every row, not the app. Our staff do not read them in the course of support.
  • Your card is public on purpose. Anyone with its link can see what is on it, that is what a business card is. Nothing else about you is public, and you can pause a card and its link stops working.
  • We do not sell, rent or trade personal information, we run no advertising and there is no advertising identifier, ad network or third-party analytics SDK in the app. This website sets no cookies and runs no analytics.
  • Three features send data to an AI service, reading a photographed card, turning a voice memo into text, and the Concierge. Those providers are not permitted to train their models on it.
  • You can leave without asking us. Export your contacts to a spreadsheet and delete your account from inside the app, on your own.
  • You have rights wherever you are, India under the DPDP Act, the EEA and UK under the GDPR, California under the CCPA. Section 11 lists them and section 15 names the person to complain to.

1. Who we are, and what this policy covers

ObjectiveDone is built and operated from Karnataka, India by Invement Mentoring Private Limited, whose registered office is at No 26/A, 15th C Cross, 6th D Main, 2nd Stage, WOC Road, Mahalakshmipuram Layout, Bengaluru, Bengaluru Urban, Karnataka, 560086 and whose registration number is GSTIN 29AAFCI2138D1ZS. In this policy "we", "us" and "our" mean that company, and "you" means the person using our products.

It covers three things: this website at objectivedone.com, including the public card pages it serves; ObjectiveDone Connect, the personal networking app; and the organisation products, the ObjectiveDone CRM and the tools we run the platform with.

Who is responsible for what

For Connect and for this website, we decide why and how your information is processed. In Indian terms we are the Data Fiduciary; under the GDPR we are the controller. Requests under section 11 come to us.

For the CRM it is different, and the difference matters. When an organisation buys CRM seats, that organisation decides what goes into its CRM and why. It is the controller of the leads, deals, activities and notes its people create there; we process that data on its instructions to run the service for it. If you use the CRM at work, your own employer's privacy notice governs what it does with that data, and a request to see or delete it goes to them first. What we do as their processor is described here so they can rely on it.

And when you open somebody else's card page at objectivedone.com/t/…, or send your details back through it, we are handling that on behalf of the person whose card it is. They are the one who ends up with your details.

2. What we collect

Everything below is either something you typed in, something you chose to upload, or something the software needs in order to run on your phone. There is no fourth category.

2.1 What you give us

  • Account information. The email address or phone number you sign in with, and a password. Your password is sensitive personal information under the SPDI Rules: it is stored only as a cryptographic hash, is never visible to us, and cannot be recovered by us, only reset by you.
  • Profile and cards. Your name, company, job title, website, photo, and everything you choose to put on a card, phone numbers, email addresses, postal addresses, social profiles, a short bio, and the images and logos you upload.
  • Contacts and network data. The people you save: their details, a photo, your private notes, the tags you file them under, where and when you met, and voice memos you record about them together with any transcript and summary. You create and control this, and most of it is information about somebody else, see section 2.5.
  • Reminders. The follow-ups you set, when they are due, and any note attached.
  • Communications. If you write to support we keep your message, your address and any attachment, so we can reply and so we can find the thread again if you write back.
  • Interest in a paid plan. If you tell us you want to hear about Premium, we keep your name, email and phone number so we can contact you about it, and we use them for nothing else.

2.2 What is collected as you use the apps

  • Device information. A random identifier generated on first launch, used to enforce one signed-in phone per account; the app version your device is running; and, if you allow notifications, a push token.
  • How a contact reached you. Whether they were imported, scanned from a QR code, read from a photographed card, typed in, or shared back to you through your card link. This is how the app can tell you where somebody came from a year later.
  • Card activity. A count of how many times your public card page has been opened. We do not record who opened it, there is no visitor identity behind that number.
  • Feature usage counts. How many card reads and transcriptions you have used, because the free tier has a daily allowance and it has to be counted somewhere.
  • Diagnostics. Error and failure records needed to keep the service working, and an audit trail of significant actions on an account.

2.3 What this website collects

Less than almost any site you will read a policy on. There are no cookies, no analytics, no tag manager, no pixels and no advertising scripts on objectivedone.com. We do not build a profile of anyone who visits it, and there is no consent banner because there is nothing to consent to.

  • Our web server keeps ordinary request logs, IP address, time, the page requested, the browser's user agent, as any web server does. They are used to keep the site up and to investigate abuse, and nothing else.
  • If you fill in the share-back form on somebody's card page, the details you enter are sent to the owner of that card and wait for them to approve or decline. That form is the only anonymous write path in the whole system and it is capped at thirty submissions per card per hour.
  • If you ask to receive a card by email, we use the address you type to send that one message and keep it briefly to stop the same address being mailed repeatedly. We do not add it to a mailing list.

2.4 What we deliberately do not collect

  • We do not read your phone book. Importing runs on your phone and only the people you tick are sent to us.
  • We do not track your location. "Where we met" is text you type or a place you pick. If you tap "use current location", the phone reads its position once, in the foreground, and sends it to our maps provider to turn into a street address and a list of nearby venues; only the place you then choose is saved. The coordinates themselves are not stored, and the app never reads your position in the background.
  • We do not use advertising identifiers, ad networks or cross-app tracking, and there is no third-party analytics SDK in the app.
  • We do not read your camera roll, only the images you pick.
  • We do not collect financial information. There is no payment inside the app. No card number, UPI handle or bank detail is ever entered into it or stored by us.
  • We do not collect your biometrics. App lock uses your phone's own fingerprint, face or passcode check. The phone answers yes or no; the biometric never leaves the device and we never see it.

2.5 Information about other people

Most of what Connect holds is information about people who never signed up for anything: the people whose cards you scanned and whose numbers you saved. We hold it for you, as your record, and we do not use it for our own purposes, we do not market to your contacts, we do not add them to any list, and we do not use them to build a network graph across accounts.

Your side of that is section 4 of the terms of service: you are responsible for having a proper reason to store somebody's details, and for removing them when asked. If you are a person in somebody's Connect address book and want to be removed, ask them, they control it. If you cannot reach them, write to support@objectivedone.com and we will help.

Indian law is the law we operate under, and it works mainly on consent: the Information Technology Act, 2000 with the SPDI Rules today, and the Digital Personal Data Protection Act, 2023 as it comes into force. Because anyone can install the app once it is on the stores, the table below also states the GDPR basis for anyone in the EEA or the UK.

PurposeWhat it usesBasis (India)Basis (GDPR)
Running Connect, your cards, contacts, notes, reminders, and serving your public card pageAccount, profile, cards, contacts, remindersConsent, given at sign-up and renewed by useArt. 6(1)(b), performance of the contract with you
Delivering notifications and follow-up remindersPush token, reminder timesConsent, you allow notifications, and can turn them offArt. 6(1)(b) contract; Art. 6(1)(a) consent for device push
The paid AI features, card reading, transcription, the ConciergeThe card photo and the text read from it; the audio; your question and the contacts relevant to itConsent, given each time you use the featureArt. 6(1)(b), the feature you asked for
Supporting you when you write inYour message, address, account stateConsent / legitimate business purposeArt. 6(1)(b) contract; Art. 6(1)(f) legitimate interests
Keeping the service secure, rate limits, abuse investigation, fault diagnosisDiagnostics, audit records, request logs, device identifierLegitimate use under DPDP s.7; security duties under the IT ActArt. 6(1)(f), legitimate interests in a service that works and is not abused
Contacting you about a plan you asked aboutName, email, phone you gave for that purposeConsent, for that stated purpose onlyArt. 6(1)(a), consent
Meeting legal obligations and answering lawful demandsWhatever the obligation coversCompliance with lawArt. 6(1)(c), legal obligation

We do not use your contacts, notes, memos or transcripts to advertise to you, we do not profile you, and there is no automated decision-making that produces a legal or similarly significant effect on you. We do not sell, rent or trade personal information, and we have never done so.

Under the DPDP Act consent has to be free, specific, informed, unconditional and unambiguous, given for a stated purpose, and as easy to withdraw as it was to give. That is the standard we hold ourselves to now rather than from the day it is enforced.

  • Specific. You consent to the app running, storing your cards and contacts and sending your reminders, when you create an account. You consent separately to each AI feature by using it, to notifications through your phone's own permission prompt, and to being contacted about a plan by asking to be.
  • Withdrawable. Turn notifications off in your phone's settings. Delete a contact, a note, a recording or a transcript and it is gone. Delete your whole account from Profile → Delete account, which asks for your password and confirms once more. You do not need our permission or our help for any of that.
  • With honest consequences. Withdrawing consent stops the processing it covered, which means the feature stops working. That is the direct result of the withdrawal, not a penalty for it, and nothing else about your account is degraded because of it.

The DPDP Act creates a role called a Consent Manager, an entity registered with the Data Protection Board of India through which you can give, review, manage and withdraw consent across the services you use, from one place. We do not use a Consent Manager today, because the framework for registering them is still being stood up. When registered Consent Managers are operating, we will accept and act on consent requests routed through one, and we will say so here when we do.

What we are not claiming

The DPDP Act was passed in 2023 and its substantive provisions take effect on 13 May 2027. We are not pretending it already binds us. What this section describes is what we do today, written to the standard that Act sets, so that nothing has to change about how we behave when it does apply.

5. Who your information goes to

It goes to four places and no others: the companies below that run parts of the service for us, wherever you choose to send it yourself, where the law requires it, and in a form that can no longer identify you.

5.1 The companies that run parts of the service

Each one is named, with what it actually receives. Each is bound by contract to protect it to a standard no lower than this policy, to process it only on our instructions, and not to use it for its own purposes.

ProviderWhat it doesWhat it receives
SupabaseThe database, sign-in, and the server functionsEverything stored in your account, and the sign-in emails it sends on our behalf
Cloudflare (R2)Stores images and audio, card photos, logos, avatars, voice memosThe files you upload, under keys tied to your account
Cloudflare (Workers AI)Reads photographed cards, turns voice memos into text, answers Concierge questions, builds the search indexThe card photo and its text; the audio; your question and the contacts relevant to it
Google (Firebase Cloud Messaging)Delivers push notifications to your phoneYour device token and the text of the notification. Never your contacts.
MapboxPlace search and turning a location into an addressOnly what you type into that box, or one position fix if you tap "use current location"
AnthropicMay answer Concierge questions where that model is switched on instead of Workers AIThe same as Workers AI receives for the Concierge
HostingerHosts this website and sends our outbound email from noreply@objectivedone.comWebsite requests, and the contents of mail we send you
Logo lookup servicesOptional: finds a company logo from a website address you typed. Uses that company's own site, then icon.horse, DuckDuckGo or Google's favicon serviceThe domain name you typed. No account information, and nothing about you

Three companies you might expect to see here, and do not

There is no payment processor, because there is no payment in the app. There is no SMS provider, because sign-in codes go by email today. And there is no analytics or crash-reporting vendor, because the app carries no analytics SDK. If any of those changes, this table changes in the same release.

5.2 Because you chose to

A card link you send, a contact file you export, a spreadsheet you download, a contact you send across to a CRM you belong to, and any webhook you connect are all acts you take. Once information reaches somewhere you sent it, it is in a system we do not control and this policy no longer governs it. Webhooks go over HTTPS to an address you supply and are signed so the receiver can verify they came from us; deleting the endpoint stops any further sending.

5.3 Because the law requires it

Where disclosure is required by Indian law, or by a government agency lawfully entitled to it, or where it is necessary to investigate a credible report of abuse or an offence. We will tell you when we are permitted to.

5.4 In a form that is no longer about you

Aggregated or de-identified information, counts, totals, error rates, that cannot reasonably be used to identify you.

If we are ever part of a merger, acquisition or sale of assets, personal information may transfer with the business. We will say so here and in the app before that happens, and the buyer stays bound by this policy until you are told otherwise.

6. Where it is processed, and how transfers are protected

We operate from India. Our database and file storage are hosted in Tokyo, Japan (AWS ap-northeast-1), and several of the providers in section 5 run infrastructure outside India, so your information may be stored or processed in another country.

  • Under Indian law. The SPDI Rules permit transfer where the recipient maintains the same level of protection we are required to, and only for a lawful purpose connected with the service. Section 16 of the DPDP Act permits transfer to any country the Central Government has not restricted; if a country we use is restricted, we will move that processing.
  • For the EEA and the UK. Transfers out of the EEA or the UK rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where the UK GDPR applies), included in our agreements with the providers named above, alongside the technical measures in section 9. A copy of the relevant clauses is available on request to support@objectivedone.com.

7. What is public, and what is private

Your card is meant to be shared. Every card has a permanent web link and anyone holding that link can see what is on it, that is its entire purpose. Do not put anything on a card you would not hand to a stranger. You can pause a card at any time and its link stops working until you turn it back on.

Everything else is private to your account. Your contacts, notes, voice memos, transcripts, reminders and tags are visible only to you, and that is enforced by the database on every row rather than by the app alone, a bug in the app cannot expose another member's data, because the app is not what is holding the line.

What our own staff can see

Our support tooling shows the account and not the address book. That is a deliberate design rule, written down before the console was built, and it is the reason we can make this promise in plain words rather than hedging it.

Staff can seeStaff cannot see
Name, sign-in email or phone, sign-up dateYour contacts and their details
Plan, subscription status, period endYour private notes about a person
Counts, how many contacts, cards, memosVoice memos, transcripts or summaries
Card metadata: how many, active or paused, view countsThe contents of a card's fields
Which device holds the session, and when it was last seenReminders and their notes
Error and audit events, and your support messagesAnything you sent to the Concierge

There are two exceptions and they are narrow: where you ask us to look at something specific and give permission, and where the law requires it or we must act on a credible report of abuse. Access is limited to staff whose role needs it, and it is logged.

8. The AI features

Four things in the product involve an AI service. Each is described here because "we use AI" is not a disclosure, what leaves your phone is.

Reading a photographed business card

The text on the card is read on your phone, by the operating system's own text recognition. What that cannot do is tell a company name from a slogan, so the photograph, the recognised text and its layout are sent to our AI provider, which decides which line is the company and which is the job title. The result is checked against the text that was actually on the card, so the model can only choose among things that were printed, it cannot invent a company. It is used to fill in that one contact and for nothing else.

Turning a voice memo into text

The audio you recorded is sent to a speech-to-text model, and the resulting text is sent to a language model to produce a summary and a list of things you said you would do. All three artefacts are stored on that contact, and you can delete the audio while keeping the words, or delete all of it.

The Concierge

The Concierge answers from your own contacts and notes, so the ones relevant to your question are sent along with it. Your personal Connect data and any organisation you belong to are kept strictly apart, the Concierge is never given both at once. When it does not know, it is built to say so rather than to produce a plausible person who does not exist.

Search

To make your own address book searchable by meaning rather than only by exact words, the text of your contacts and notes is turned into a numeric representation by an embedding model and stored alongside your data. It is used to find your own records and is never pooled with anyone else's.

Google Calendar and Google Contacts

If you connect your Google account, Connect asks for two read-only permissions and nothing else: calendar.readonly, so the Concierge can tell you what is on your calendar when you ask about a meeting, and contacts.readonly, so you can import people you already have into your address book. Both are optional, neither is requested when you sign up, and the app works without either. We read; we never write to your Calendar or your Contacts, and we never delete anything in them. Calendar events are fetched at the moment you ask and are not stored by us; a contact you choose to import is copied into your own address book, where it is yours to edit or delete. Disconnecting from Profile then Connected accounts revokes the permission at Google and deletes the stored token.

Google user data, and the Limited Use requirements

The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. In plain terms: information from your Google Calendar or Google Contacts is used only to provide the features described directly above, at your request, and is never used, transferred or sold to create, train or improve any foundational or generalised machine-learning or artificial-intelligence model — ours or anybody else’s — whether that data is raw, aggregated or derived. When you ask the Concierge a question about your schedule, the events needed to answer that one question are sent to our AI provider under a contract that forbids training on them and does not retain them; nothing from your Calendar or Contacts is ever added to a training set.

Training

We do not permit these providers to use your data to train their models. Nothing you record, write or ask becomes training data for anybody, including us.

9. How we keep it safe

We follow reasonable security practices and procedures appropriate to the information we hold, as the Information Technology Act, 2000 and the rules under it require, and as section 8 of the DPDP Act will require.

  • Encryption. Traffic to our servers is encrypted in transit. Your sign-in token is stored encrypted on your phone with the key held in the phone's own secure hardware. Passwords are stored only as hashes.
  • Row-level access control. Separation between accounts is enforced by the database on every row. There is no query the app can make that returns another member's data.
  • Least privilege for staff. Staff access is role-based, limited to what a role actually needs, and logged. The support console does not render your contacts or notes at all, see section 7.
  • Signed, short-lived links for files. Images and audio are never public. They are reached through links that expire and that refuse any file not belonging to the account asking.
  • One device at a time. Only one phone can be signed in to an account; signing in elsewhere signs the first out. A stolen phone loses access the moment you sign in on a new one.
  • Update integrity. While the app is distributed outside an app store, each update is checked against a published checksum before it installs.

No system is perfectly secure, and we will not tell you otherwise. What we can tell you is where the line is held, in the database rather than in the app, and what happens if it fails, which is section 13.

10. How long we keep it

The general rule is that we keep your information for as long as your account exists, and delete it when the account is deleted. The exceptions are below.

WhatHow longWhy
Your account, cards, contacts, notes, remindersUntil you delete the item, or delete the accountIt is the service. Nothing here expires on its own
Voice recordings and transcriptsUntil you delete them, and they can be deleted independently of each otherSo you can keep what was said and discard the audio
A deleted accountRemoved on request. Copies inside encrypted backups age out within 30 days and are isolated from any further use until they doBackups cannot be edited in place without destroying their integrity
Declined share-backsKept as a record of the refusalSo the same unwanted submission cannot be sent to you again and again
Support correspondence24 months from the last message in the threadSo we can pick up a problem you wrote about last year
Security, audit and error recordsUp to 12 monthsInvestigating abuse and diagnosing faults
Web server request logs90 daysKeeping the site up, and abuse investigation
Records we are legally required to keepFor the period the law specifiesCompliance. This is the only reason anything outlives a deletion request

You can close your account yourself at Profile → Delete account. It asks for your password and confirms before anything is erased, because it cannot be undone, export your contacts first if you want to keep them.

11. Your rights

11.1 Rights everyone has, wherever you are

  • See and correct. Everything about you is visible and editable in the app. Ask us to correct anything that is wrong, incomplete or out of date and we will.
  • Get a copy. Export your contacts to a spreadsheet from Profile whenever you like, and export any single card or contact as a contact file. Ask us and we will send a copy of your account data in a portable format.
  • Delete. Delete any item, or the whole account, from inside the app.
  • Withdraw consent. See section 4.
  • Turn off notifications. In your phone's settings, at any time.
  • Complain. To our Grievance Officer in section 15, and then to a regulator.

11.2 India, the DPDP Act, 2023

When the Act is in force you will have these rights against us as a Data Fiduciary. We will honour them from the date they apply, and in practice the first three already work today.

  • Access, a summary of the personal data we process about you, the processing activities, and the identities of anyone we have shared it with.
  • Correction, completion, updating and erasure of your personal data.
  • Grievance redressal, a readily available means of raising a complaint with us, answered within the period the law prescribes, before you go to the Board.
  • Nomination, you may nominate another person to exercise these rights on your behalf if you die or become incapable of exercising them yourself. Write to us to record a nomination; we will build it into the app before the Act commences.
  • Complain to the Data Protection Board of India if we do not resolve your grievance.

The Act also places duties on you as a Data Principal, not to impersonate anyone, not to suppress material information, and not to file a false or frivolous complaint.

11.3 EEA and the UK, the GDPR

If you are in the European Economic Area or the United Kingdom you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests, together with the right not to be subject to a decision based solely on automated processing, which we do not carry out. Where processing rests on consent, you may withdraw it at any time without affecting what was lawful before you did.

You may complain to your national supervisory authority, in Ireland the Data Protection Commission, in the UK the Information Commissioner's Office, and elsewhere the authority for your country. We have not appointed an EU or UK representative under Article 27, because we do not currently target the EEA or UK market; if that changes, we will appoint one and name them here.

11.4 California, the CCPA as amended by the CPRA

In the twelve months before the date at the top of this policy we collected the following categories of personal information from California residents: identifiers (name, email address, phone number, a device identifier); customer records (job title, company, postal address); commercial information (which plan you are on and which paid features you used); internet activity (request logs, error records); audio and visual information (photos you upload and voice memos you record); and professional information (your role, and the roles of the people you save). The sources, purposes and recipients are in sections 2, 3 and 5.

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. We have not done so in the preceding twelve months, and we do not sell or share the personal information of anyone we know to be under 16.
  • We do not use or disclose sensitive personal information for purposes beyond those permitted without an opt-out right, so there is no "limit the use of my sensitive personal information" link.
  • You have the right to know what we collect and disclose, to delete it, to correct it, to opt out of sale or sharing, inapplicable here, since there is none, and not to be discriminated against for exercising any of them. We offer no financial incentives for personal information.
  • You may use an authorised agent; we will ask for proof of their authority and for you to verify your own identity directly.
  • Shine the Light: we do not disclose personal information to third parties for their own direct marketing purposes.

11.5 How to exercise any of this

Write to support@objectivedone.com, or to the Grievance Officer in section 15. We may ask you to verify your identity before we act on a request about an account, usually by asking you to write from the address the account signs in with. We answer within 30 days, sooner where the law requires it, and we do not charge for a first request.

If your request concerns data held inside an organisation's CRM, we will pass it to that organisation and tell you we have, because it is their data to decide about (section 1).

12. Children

ObjectiveDone is for working professionals. You must be 18 or older to hold an account, and we do not knowingly collect personal information from anyone under that age.

The DPDP Act treats anyone under 18 as a child and requires verifiable parental consent before processing their data, and forbids tracking, behavioural monitoring and targeted advertising directed at children. We meet that by not being a service for children at all, and by carrying no tracking or advertising for anyone. If you believe a child has given us personal information, write to support@objectivedone.com and we will delete it.

13. If something goes wrong

If a personal data breach occurs we will act on it, tell the people it affects, and tell the regulators that need to know, in plain language, saying what happened, what was exposed, what we have done and what you should do.

  • India, CERT-In. Cyber security incidents in the categories the CERT-In directions cover are reported to CERT-In within six hours of our noticing them.
  • India, DPDP. Once in force, we will intimate the Data Protection Board of India and every affected Data Principal, in the manner and timeframe the Act and its rules prescribe.
  • EEA and UK. Where the GDPR applies we notify the relevant supervisory authority within 72 hours of becoming aware, and notify affected individuals directly without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
  • California and elsewhere. We give the notice the applicable law requires.

If you think you have found a security problem, please tell us at support@objectivedone.com before telling anyone else. We will not pursue anyone who reports a genuine vulnerability to us in good faith and gives us a reasonable chance to fix it.

14. Cookies and tracking

objectivedone.com sets no cookies. It runs no analytics, no tag manager, no advertising pixels and no session tracking, and it does not respond differently to a Do Not Track or Global Privacy Control signal because there is no tracking here for such a signal to switch off.

The apps store a small amount of data on your own device, your sign-in token, the device identifier described in section 2.2, and your settings. That stays on the phone and is cleared when you sign out or uninstall.

If we ever add anything that does track, we will say so here first, ask for consent where consent is required, and it will be off until you say yes.

15. Grievance Officer, and how to complain

Indian law requires us to publish the name and contact details of a Grievance Officer, a named person, not a role inbox, who deals with complaints about how personal information is handled.

  • Grievance Officer: Kashyap Sreedharmurthy Karnala
  • Email: grievance@objectivedone.com
  • Post: Invement Mentoring Private Limited, No 26/A, 15th C Cross, 6th D Main, 2nd Stage, WOC Road, Mahalakshmipuram Layout, Bengaluru, Bengaluru Urban, Karnataka, 560086

We acknowledge a complaint within 24 hours and aim to resolve it within 15 days of receiving it, and in any case within the period the applicable rules require. If you are not satisfied with the outcome you may escalate: in India, to the Data Protection Board once it is constituted; in the EEA or the UK, to your supervisory authority; in California, to the California Privacy Protection Agency or the Attorney General.

For anything that is not a grievance, a question, a request under section 11, a bug, support@objectivedone.com reaches us and is read.

16. Changes to this policy

We update this policy when the product, our providers or the law changes. The Last updated date at the top changes with it.

If a change is material we will tell you in the app rather than quietly editing this page, and continuing to use ObjectiveDone after that means you accept the revised policy. If you do not, you can delete your account.

17. Contact us

Questions, requests and anything you think this document gets wrong: support@objectivedone.com. Complaints: the Grievance Officer in section 15.

Invement Mentoring Private Limited, No 26/A, 15th C Cross, 6th D Main, 2nd Stage, WOC Road, Mahalakshmipuram Layout, Bengaluru, Bengaluru Urban, Karnataka, 560086. Registration number GSTIN 29AAFCI2138D1ZS.