The short version. We collect the minimum we need to run your account: who you are, how to bill you, and how the service is being used. The assets you upload are yours — we store, version, and deliver them on your instruction and nothing else. We do not sell personal data, and we do not use your assets to train general-purpose AI models. You can export or delete your data at any time. This summary is for orientation only; the sections below are what actually governs.
Umber is a Digital Asset as a Service platform operated by Vyomr Private Limited, a company incorporated in India with its registered office at 1208, A-wing, Kanakia Silicon Valley, Powai, Mumbai 400076 (“Umber”, “we”, “us”). We operate umbercloud.io, app.umbercloud.io, api.umbercloud.io, and the Umber CLI (together, the “Service”).
Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we act as a Data Fiduciary for personal data about our own account holders, website visitors, and people who contact us. Where you upload assets that happen to contain personal data about your users, you are the Data Fiduciary and we act as a Data Processor handling that data solely on your documented instructions.
This policy covers personal data we handle as a Data Fiduciary through the Service, our marketing site, and our support and sales channels. It does not cover:
We collect only what a specific, stated purpose requires. If you decline to provide data marked as necessary, we may not be able to provide the relevant part of the Service.
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Name, work email address, password (stored only as a salted hash), organisation name, role, team members you invite | You, at sign-up and in account settings |
| Billing data | Plan, billing cycle, billing name and address, GSTIN if supplied, invoice and payment history, last four digits and brand of your card | You and our payment processor. We never receive or store full card numbers, CVV, or UPI credentials |
| Asset content and metadata | Files you upload (images, video, audio, PDFs, 3D models and similar), file names, versions, environment mappings, lifecycle states, tags and descriptions | You, via the dashboard, API, or CLI |
| Usage and log data | API requests and endpoints called, timestamps, response codes, bytes transferred, storage consumed, IP address, user agent, referring page, approximate location derived from IP (city or region level) | Automatically, as you use the Service |
| Security data | Login events, failed authentication attempts, API key creation and revocation, audit trail of administrative actions | Automatically |
| Support and sales data | Name, email, company, topic, and the content of messages you send through our contact form or by email | You, when you contact us |
| Marketing data | Email address and communication preferences, whether you opened or clicked an email we sent you | You, when you opt in |
We do not deliberately collect sensitive categories of data such as health, biometric, financial account, or government identifier data, and we ask you not to place such data in fields where it is not required. We do not buy personal data from data brokers.
Under the DPDP Act, we process personal data either with your consent or for a legitimate use permitted by the Act — including performance of a service you have voluntarily asked for, and compliance with law.
| Purpose | Data used | Basis |
|---|---|---|
| Create and administer your account, authenticate you, and enforce plan limits on storage, bandwidth, users, and environments | Account, usage | Performance of the service you requested |
| Store, version, map to environments, and deliver your assets when requested | Asset content and metadata | Performance of the service you requested |
| Charge you, issue invoices and credit notes, and meet tax obligations | Billing | Contract and legal obligation |
| Provide support, answer sales questions, and send service notices such as outage, billing, and security alerts | Support, account | Performance of the service you requested |
| Keep the Service secure — detect abuse, credential stuffing, fraud, and denial-of-service activity, and investigate incidents | Security, usage | Legitimate use under the DPDP Act |
| Diagnose faults, measure reliability, and improve performance and capacity planning, using data in aggregated or de-identified form wherever it will serve | Usage | Legitimate use under the DPDP Act |
| Power optional features you switch on, such as AI search over your own asset library | Asset metadata and content within your account only | Your consent, per feature |
| Send product announcements, newsletters, and offers | Marketing | Your consent — withdrawable at any time |
| Establish, exercise, or defend legal claims, and respond to lawful requests from authorities | Any of the above, as relevant | Legal obligation and legitimate use |
We do not sell personal data, and we do not share it with third parties for their own advertising. We do not carry out automated decision-making that produces legal or similarly significant effects on you.
Where processing rests on consent, you may withdraw it at any time from your account settings or by writing to privacy@umbercloud.io. Withdrawal is as easy as giving consent, takes effect going forward, and does not affect processing already carried out.
The assets you upload remain yours. We claim no ownership over them. We process them only to the extent needed to provide the Service — storing them, generating and retaining versions, applying the environment mappings you configure, delivering them over our asset delivery network when a request comes in, and creating derived files such as thumbnails or transcoded variants where a feature calls for it.
Specifically, we commit that:
If assets you upload contain personal data about your own users, you are responsible for having a lawful basis to collect and share it with us, and for informing those individuals. For customers who need one, we will enter into a Data Processing Agreement — write to privacy@umbercloud.io.
We primarily store and process data in India. Some of our sub-processors operate in other countries, so your data may be transferred outside India. The DPDP Act permits such transfers except to countries the Central Government restricts by notification; we monitor those notifications and will not transfer personal data to a restricted territory.
Wherever data goes, we require contractual protections at least equivalent to those in this policy, including confidentiality obligations, security standards, and deletion on termination. Enterprise customers with data residency requirements should contact sales@umbercloud.io — dedicated and on-premise deployments are available.
We keep personal data only as long as the purpose it was collected for still holds, and then erase it — except where a law requires us to retain it for longer.
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account, then erased within 30 days of account closure |
| Assets and versions | Until you delete them or close the account. Deleted items are purged from live systems immediately and from backups within 35 days |
| Invoices, payment records, and tax documents | Retained for the period required by Indian tax and company law — currently up to 8 years from the end of the relevant financial year |
| Access and API logs | 90 days, then deleted or irreversibly aggregated |
| Security and audit logs | 12 months, longer where needed for an open investigation |
| Support correspondence | 24 months from the last message in the thread |
| Marketing contacts | Until you unsubscribe, plus a permanent suppression record so we do not contact you again |
If your account sits inactive with no login and no API activity for 24 consecutive months on a free plan, we may notify you at your registered email and then erase the account and its contents if you do not respond within 30 days.
We take reasonable security safeguards to prevent personal data breaches, as the DPDP Act requires. These include:
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected user in the manner and within the timelines prescribed under the DPDP Act and its rules. You also have a part to play: choose a strong, unique password, keep API keys out of client-side code and public repositories, and rotate keys you suspect have leaked.
To report a vulnerability, write to security@umbercloud.io. We will acknowledge within two business days and will not pursue action against good-faith researchers who follow responsible disclosure.
As a Data Principal under the DPDP Act, you have the right to:
You can also export your account data, including your assets and their version history, through the API or the dashboard at any time.
To exercise a right, write to privacy@umbercloud.io from the email address on your account. We respond within 30 days. If a request is manifestly unfounded or repetitive we may explain why we are declining rather than act on it, and you retain the right to complain. Please note that the DPDP Act also places duties on you as a Data Principal, including not impersonating another person and not filing false or frivolous complaints.
If you are unhappy with how we have handled your personal data or a request about it, contact our Grievance Officer:
Grievance Officer — Shahnaz Khan
Vyomr Private Limited, 1208, A-wing, Kanakia Silicon Valley, Powai, Mumbai 400076, India
Email: grievance@umbercloud.io
We acknowledge every grievance within 48 hours and aim to resolve it within 30 days.
If we do not resolve your grievance to your satisfaction, you may lodge a complaint with the Data Protection Board of India established under the DPDP Act.
Umber is a business tool and is not directed at anyone under 18. We do not knowingly create accounts for children or for persons with a disability who have a lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children — all of which the DPDP Act prohibits.
If we learn that we hold personal data of a child without verifiable consent from a parent or lawful guardian, we will delete it promptly. If you believe a child has provided us data, write to privacy@umbercloud.io.
Umber is operated from India and this policy is written to the DPDP Act. If you are in the European Economic Area, the United Kingdom, or a US state with its own privacy statute, you may have additional rights — such as data portability, objection to processing, restriction of processing, or the right to opt out of “sale” or “sharing” as those terms are defined locally.
We honour such requests where those laws apply to us. We do not sell or share personal data as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. Write to privacy@umbercloud.io and tell us which jurisdiction you are writing from. Customers who need a GDPR-compliant Data Processing Agreement with standard contractual clauses should contact the same address.
We update this policy when the Service or the law changes. The effective date at the top always reflects the current version. For material changes — a new purpose, a new category of recipient, or a shorter route to your data — we will give notice by email to account holders and a notice in the dashboard at least 14 days before the change takes effect. Continuing to use the Service after that date means the updated policy applies to you. Superseded versions are available on request.
Questions about this policy, or about anything we hold on you:
Vyomr Private Limited, 1208, A-wing, Kanakia Silicon Valley, Powai, Mumbai 400076, India.
Ask us directly — a person reads every message.