1. Introduction
This Security Statement describes how Anomaa Studio protects Account, payment, and Payout data on eBodhya Marketplace, and how we respond to security incidents and vulnerability reports. It exists so Buyers, Sellers, and Institution/School purchasers can understand the safeguards protecting their money and data when they transact on the Marketplace.
2. Definitions
This document uses the shared definitions in Anomaa Studio's canonical definitions list and the Marketplace-specific terms defined in the Privacy Policy Section 2, together with:
- "Payment Processor" — the third-party, PCI-DSS-compliant payment gateway that Anomaa Studio uses to process card, UPI, and net-banking payments and Seller Payouts.
- "Security Incident" — an actual or reasonably suspected unauthorized access to, or acquisition, disclosure, alteration, or destruction of, Personal Data or Marketplace systems.
3. Applicability
This Statement applies to every Account, Order, and Payout processed through the Marketplace.
4. Legal Entity
eBodhya™ is a trademark owned and used by Anomaa Studio, a sole proprietorship business based in Bengaluru, Karnataka, India ("Anomaa Studio," "eBodhya," "we," "us," or "our"). Anomaa Studio owns and operates the entire eBodhya suite of platforms, comprising:
- eBodhya Studio — studio.ebodhya.in
- eBodhya Marketplace — marketplace.ebodhya.in
- eBodhya Schools — schools.ebodhya.in
- eBodhya Workspace — workspace.ebodhya.in
(together, the "eBodhya Platforms").
Every account, subscription, order, listing, or agreement created or entered into through any eBodhya Platform is an agreement with Anomaa Studio directly. No eBodhya Platform is owned, operated by, or offered on behalf of any third party, franchisee, reseller, school district, or unrelated entity, unless we state so expressly and in writing. eBodhya™ and the eBodhya logo are trademarks of Anomaa Studio; no license to use them is granted except as expressly permitted in writing.
In this document, "the Platform" means eBodhya Marketplace (marketplace.ebodhya.in) specifically, and "eBodhya" or the "eBodhya Platforms" means the wider suite of products described above. Where this document imposes obligations on "Anomaa Studio," those obligations are undertaken by Anomaa Studio in its capacity as operator of the Platform.
5. Payment Data Handling
Anomaa Studio does not itself store, process, or transmit full payment card numbers, and Anomaa Studio is not itself PCI-DSS certified. Instead, all card, UPI, and net-banking payment data you enter at checkout is collected and processed directly by our Payment Processor, which is independently certified as compliant with the Payment Card Industry Data Security Standard (PCI-DSS). Anomaa Studio receives only a tokenized payment reference, a payment status, and transaction metadata sufficient to confirm and reconcile your Order — never your raw card or bank credentials. Refunds and Seller Payouts are likewise executed through the Payment Processor's secure infrastructure.
6. Account Security
- Passwords are stored using industry-standard hashing; we never store passwords in plain text.
- We support secure session management, including session expiry and the ability to sign out of active sessions.
- We apply automated monitoring to detect anomalous login activity (for example, logins from unusual locations) and may require re-verification where suspicious activity is detected.
- You are responsible for choosing a strong, unique password, keeping your credentials confidential, and enabling any additional verification step we offer.
7. Seller Payout Security
Sellers' KYC, tax, and bank/payout instrument details are collected and verified through the Payment Processor or a comparable verification service, encrypted in transit and at rest, and accessible internally only on a need-to-know basis. Payouts are released only to the verified payout instrument on file for a Seller's Account, and a change to payout details triggers additional verification before it takes effect, as described in the Seller Agreement and Creator Revenue Policy.
8. Infrastructure Security
We use reputable cloud hosting providers, apply encryption in transit (TLS) for data flowing to and from the Marketplace, apply encryption at rest for sensitive stored data, and restrict internal access to Personal Data and payment metadata on a role and need-to-know basis.
9. AI
Automated fraud-detection systems described in the AI Usage Policy contribute to account and transaction security by flagging anomalous behavior for review.
10. Data Processing
Security-related data (login logs, fraud signals) is Processed under the Privacy Policy.
11. Cookies
Essential/Session cookies used for authentication are described in the Cookie Policy.
12. Third-Party Services
Our Payment Processor, cloud hosting provider, and any fraud-detection or identity-verification vendor are contractually bound to apply security safeguards consistent with this Statement; see the Privacy Policy for sub-processor categories.
13. Retention
Security logs and incident records are retained as described in the Data Retention Policy.
14. Deletion
Security and fraud-investigation records may be retained after Account deletion where necessary to detect and prevent re-registration by a repeat offender, consistent with the Data Deletion Policy.
15. Intellectual Property
Not separately applicable; see the Intellectual Property Policy.
16. User Responsibilities
You must notify us immediately at security@ebodhya.in if you suspect unauthorized access to your Account, a compromised payout instrument, or any other Security Incident affecting your use of the Marketplace.
17. Prohibited Activities
You may not attempt to probe, scan, or test the vulnerability of the Marketplace without authorization; attempt to bypass authentication or payment controls; or use another User's credentials or payout instrument without authorization.
18. Incident Response
If we confirm a Security Incident affecting your Personal Data, we will: (a) contain and investigate the incident; (b) assess the categories of data and Users affected; (c) notify affected Users and, where required by Applicable Law, the Data Protection Board of India or other competent authority, without undue delay; and (d) take corrective action to prevent recurrence. Notification will describe the nature of the incident and the steps you can take to protect yourself.
19. Vulnerability Disclosure
If you discover a potential security vulnerability in the Marketplace, please report it responsibly to security@ebodhya.in with enough detail for us to reproduce and assess it. Please do not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and remediate it, and do not access, modify, or exfiltrate data beyond what is necessary to demonstrate the issue. We will acknowledge a good-faith report within a reasonable time and will not pursue legal action against a reporter who follows this responsible-disclosure process.
20. Limitation of Liability
Our liability in connection with security matters is limited as described in the Terms of Service. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse of data will never occur.
21. Disclaimer
Security measures described in this Statement are provided on a reasonable-efforts, "as is" basis and may be updated as threats and technology evolve.
22. Termination
This Statement continues to apply to any Personal Data or transaction records we hold after Account closure, for as long as we retain them under the Data Retention Policy.
23. Governing Law, Jurisdiction, and Changes
Governing Law and Dispute Resolution
This Security Statement and any dispute, claim, or controversy arising out of or relating to it, the Platform, or the Services (a "Dispute") is governed by the laws of India, without regard to its conflict-of-laws principles.
The parties will first attempt in good faith to resolve any Dispute through informal negotiation for thirty (30) days after one party gives the other written notice of the Dispute. If the Dispute is not resolved within that period, it will be referred to and finally resolved by arbitration in Bengaluru, Karnataka, under the Arbitration and Conciliation Act, 1996, before a sole arbitrator appointed by Anomaa Studio. The arbitration will be conducted in English, and the seat and venue of arbitration will be Bengaluru, Karnataka. The award of the arbitrator will be final and binding on the parties.
Nothing in this clause prevents either party from seeking urgent injunctive or equitable relief before a competent court at any time. Subject to the arbitration agreement above, the courts at Bengaluru, Karnataka shall have exclusive jurisdiction over any Dispute not subject to arbitration and over any proceeding to enforce an arbitral award.
Jurisdiction
Without prejudice to the arbitration agreement above, the Platform is directed at Users in India, and Anomaa Studio makes no representation that the Platform or its Content is appropriate or lawfully available in other locations. Users who access the Platform from outside India do so on their own initiative and are responsible for compliance with local law.
Changes to This Security Statement
We may update this Security Statement from time to time to reflect changes in the Services, Applicable Law, or our practices. We will post the revised version on the Platform with an updated "Effective Date" and, for material changes, will provide reasonable advance notice through the Platform, by email, or by an in-product notice, as appropriate to the change and the audience of the Platform. Continued use of the Platform after the revised Security Statement takes effect constitutes acceptance of the changes. Where Applicable Law requires your express consent to a change (for example, a material change to how we Process Personal Data of a Child), we will seek that consent before the change takes effect.
24. Contact Information
| Purpose | Contact |
|---|---|
| Security vulnerability reports and responsible disclosure | security@ebodhya.in |
| Suspected unauthorized Account access | security@ebodhya.in |
| General support | support@ebodhya.in |
| Grievances under Applicable Law | grievance@ebodhya.in |
Registered office: Anomaa Studio, Bengaluru, Karnataka, India.
Grievance Officer
Anomaa Studio has designated a Grievance Officer for the eBodhya Platforms, reachable at grievance@ebodhya.in, in accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. The Grievance Officer will acknowledge a grievance within twenty-four (24) hours and endeavor to redress it within fifteen (15) days.