iCubes Studios | Game Development & Outsourcing Company

iCube Studios is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, share, and protect personal data when you visit our website www.icubestudios.com, use our products and services, or otherwise interact with us.

This Policy is designed to comply with the laws that apply to you depending on where you are:

  • If you are in India: The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025. Under the DPDP Act, iCube Studios acts as the “Data Fiduciary” and you are the “Data Principal”.
  • If you are in the European Economic Area or the United Kingdom: the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”) [and the UK GDPR and Data Protection Act 2018]. Under the GDPR, iCube Studios acts as the “data controller”.
  • If you are in the United States: applicable U.S. state consumer privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and federal laws such as the CAN-SPAM Act and COPPA.

Where this Policy states different rules for different regions, the rules of your region apply to you. If you have questions, contact us using the details in Section 17.

Who We Are (Data Controller / Data Fiduciary)

The entity responsible for your personal data is:

  • Legal entity: Nexvo Tech LLP [Full legal name of iCube Studios entity]
  • Registered address: 25 P R NO 92/1 HORAMAVU K R PURAM BANGALORE 560016
  • Company registration number: ACY-3094
  • Email: privacy@icubestudios.com
  • Telephone: +91 70260 96360

[Where required under Article 27 GDPR, our EU representative is: [Name and contact details].]

Data Protection and Grievance Contact

iCube Studios is not required to appoint, and has not appointed, a Data Protection Officer under Article 37 GDPR. All privacy questions and requests should be directed to our privacy team at privacy@icubestudios.com.

For users in India, as required by the DPDP Act and the DPDP Rules, our designated contact person / Grievance Officer for data protection matters is:

  • Name / designation: Supritha – Grievance Officer
  • Email: privacy@icubestudios.com
  • Postal address: Brigade IRV 9th Floor Nallurhalli Road Whitefield Bengaluru 560 066

We will acknowledge and respond to grievances within the timelines prescribed under the DPDP Rules and in any event within 2 days.

Personal Data We Collect

We may collect and process the following categories of personal data:

  • Identity data: name, title, date of birth, username or similar identifier.
  • Contact data: email address, postal address, telephone numbers.
  • Account data: login credentials, preferences, settings.
  • Transaction data: details of products and services purchased, order history.
  • Financial data: payment details (processed by our payment providers), billing information.
  • Technical data: IP address, browser type and version, device identifiers, operating system, time-zone setting.
  • Usage data: information about how you use our website, products, and services.
  • Marketing and communications data: your preferences for receiving marketing and your communication preferences.
  • Correspondence: records of your communications with us, including customer support enquiries.

We do not intentionally collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or data concerning sexual orientation) and do not knowingly collect data relating to criminal convictions and offences.

How we collect your data
  • Directly from you — when you create an account, purchase services, complete forms, or correspond with us.
  • Automatically — through cookies and similar technologies when you use our website (see Section 12).
  • From third parties — such as [payment providers, analytics providers, publicly available sources, business partners].
Purposes and Legal Bases for Processing

We process personal data only where we have a lawful basis to do so. The table below sets out our purposes and the corresponding basis under each law:

Purpose of processing

Categories of personal data

GDPR legal basis (EU/UK users)

DPDP basis (Indian users)

Providing our products and services; managing your account

Identity, contact, account, transaction data

Performance of a contract (Art. 6(1)(b))

Consent (s. 6); voluntary provision for a specified purpose (s. 7(a))

Processing payments and billing

Contact, financial, transaction data

Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))

Consent (s. 6); compliance with law (s. 7(c))

Responding to enquiries and customer support

Identity, contact data, correspondence

Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))

Voluntary provision for a specified purpose (s. 7(a))

Sending marketing communications

Contact data, marketing preferences

Consent (Art. 6(1)(a)); legitimate interests for existing customers, where permitted

Consent (s. 6), which you may withdraw at any time

Internal purposes: service improvement, internal analytics, quality assurance, record-keeping, business planning and reporting, staff training, and audits

Technical, usage, transaction data, correspondence (aggregated or minimised where possible)

Legitimate interests (Art. 6(1)(f))

Consent obtained at collection for these stated purposes (s. 6); aggregated / anonymised data falls outside the Act

Research and development: developing, testing, and launching new products, services, and features; market and trend analysis

Technical, usage, transaction data (aggregated or minimised where possible)

Legitimate interests (Art. 6(1)(f))

Consent obtained at collection for these stated purposes (s. 6); aggregated / anonymised data falls outside the Act

Securing our website and services; fraud prevention

Technical, usage data

Legitimate interests (Art. 6(1)(f))

Consent (s. 6); legitimate uses (s. 7), including compliance with law

Complying with legal and regulatory obligations

Identity, transaction, financial data

Legal obligation (Art. 6(1)(c))

Compliance with law or court order (s. 7(b)–(c))

Establishing, exercising, or defending legal claims

Any relevant categories

Legitimate interests (Art. 6(1)(f))

Legitimate uses (s. 7); compliance with law

Where we rely on legitimate interests under the GDPR, we have carried out a balancing test to ensure our interests are not overridden by your rights and freedoms; you can request details using the contact information in Section 17. Where processing is based on consent (under either law), you may withdraw it at any time, with the same ease with which it was given, without affecting the lawfulness of processing carried out before withdrawal.

Internal Use of Your Data

In addition to delivering our services, we sometimes use personal data for our own internal purposes. These include:

  • Analysing how our website, products, and services are used, so we can improve them;
  • Internal record-keeping, reporting, business planning, and financial administration;
  • Quality assurance, testing, and troubleshooting;
  • Training our staff [and improving our internal processes and tools];
  • Internal audits, security monitoring, and fraud prevention;
  • Research and development, including designing, testing, and improving new products, services, and features;
  • Market, trend, and performance analysis to inform our business strategy.

We apply safeguards to internal use: access is limited to staff who need it for their role, and wherever practicable we use aggregated, de-identified, or anonymised data rather than data that identifies you. Fully anonymised data is no longer personal data and may be used for internal research and statistics without further notice to you.

Flexibility for new and compatible purposes

Our business evolves, and we may need to use personal data for purposes not listed above. We reserve the flexibility to do so within the limits of the law: we may process your personal data for any new purpose that is compatible with the purposes described in this Policy (taking into account the link between the purposes, the context of collection, the nature of the data, the possible consequences for you, and the safeguards applied). Where a new purpose is not compatible with those originally notified, we will inform you and, where required by the GDPR or the DPDP Act, obtain your fresh consent before proceeding. In addition, we may freely use aggregated, de-identified, or anonymised data — which no longer identifies you — for any lawful business purpose, including analytics, benchmarking, research, and product development, without further notice.

For users in the EU/UK, internal use is based on our legitimate interests in running, improving, and securing our business (Art. 6(1)(f) GDPR), and you may object to it at any time (see Section 9). For users in India, internal use is among the specified purposes for which we obtain your consent at the point of collection, and you may withdraw that consent at any time (see Section 10). We do not use your personal data for internal purposes that are incompatible with the purposes described in this Policy.

Sharing Your Personal Data

We may share your personal data with the following categories of recipients, in each case only to the extent necessary:

  • Service providers (processors): hosting, IT support, payment processing, email delivery, analytics, and customer support providers acting on our documented instructions under written contracts, as required by Article 28 GDPR and the DPDP Rules.
  • Group companies: [list affiliates] for internal administration and the purposes described in this Policy.
  • Professional advisers: lawyers, auditors, accountants, and insurers where necessary.
  • Authorities and regulators: where disclosure is required by law, court order, or to protect our legal rights.
  • Business transfers: prospective buyers or sellers in connection with a merger, acquisition, or sale of assets, subject to appropriate confidentiality safeguards.

We do not sell your personal data.

International Transfers

Your personal data may be transferred to, and processed in, countries other than your own.

For users in the EEA/UK

Where we transfer personal data outside the EEA [or the UK], we ensure a similar degree of protection through at least one of the following safeguards: transfer to countries covered by a European Commission adequacy decision (Art. 45 GDPR); the European Commission’s Standard Contractual Clauses (Art. 46 GDPR), supplemented where necessary by additional measures; [the EU-U.S. Data Privacy Framework for certified U.S. recipients;] or Binding Corporate Rules. You may request a copy of the relevant safeguards by contacting us.

For users in India

Under the DPDP Act, we may transfer personal data outside India except to any country or territory restricted by the Central Government by notification. We will comply with any such restrictions and with any additional conditions on cross-border transfer prescribed under the DPDP Rules or other applicable Indian law.

Your Rights — Users in the EEA/UK (GDPR)

Subject to certain conditions and exemptions, if the GDPR applies to you, you have the following rights:

  • Right of access (Art. 15) — obtain confirmation of whether we process your data and receive a copy of it.
  • Right to rectification (Art. 16) — have inaccurate data corrected and incomplete data completed.
  • Right to erasure (Art. 17) — request deletion of your data in certain circumstances.
  • Right to restriction of processing (Art. 18) — request that we limit how we use your data in certain circumstances.
  • Right to data portability (Art. 20) — receive data you provided to us in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21) — object to processing based on legitimate interests (including our internal-use processing described in Section 6), and to direct marketing at any time.
  • Right to withdraw consent (Art. 7(3)) — where processing is based on consent.
  • Rights related to automated decision-making (Art. 22) — we do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects.

You also have the right to lodge a complaint with your local supervisory authority (see Section 16).

Your Rights — Users in India (DPDP Act)

If you are in India, you have the following rights as a Data Principal under the DPDP Act:

  • Right to access information (s. 11) — obtain a summary of the personal data we process about you, our processing activities, and the identities of Data Fiduciaries and Data Processors with whom your data has been shared.
  • Right to correction and erasure (s. 12) — have your personal data corrected, completed, updated, or erased where it is no longer necessary for the purpose for which it was processed, unless retention is required by law.
  • Right to grievance redressal (s. 13) — raise a grievance with our Grievance Officer (Section 3), which we will address within the prescribed timelines, before approaching the Data Protection Board of India.
  • Right to nominate (s. 14) — nominate another individual who may exercise your rights in the event of your death or incapacity.
  • Right to withdraw consent (s. 6(4)) — withdraw your consent at any time, with ease comparable to that with which you gave it. You may also manage consent through a registered Consent Manager, where available.

As a Data Principal you also have duties under s. 15 of the DPDP Act, including not to impersonate another person, not to suppress material information, and not to register false or frivolous grievances.

How to exercise your rights (all users)

To exercise any right under any of these laws, contact us at privacy@icubestudios.com, stating your request and your country of residence. We may need to verify your identity. For GDPR requests, we will respond within one month (extendable by up to two further months for complex requests, in which case we will inform you). For DPDP requests, we will respond within the timelines prescribed under the DPDP Rules. Exercising your rights is free of charge, although we may refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive.

Your Rights — Users in the United States

There is currently no comprehensive federal privacy law in the United States; instead, a number of states have enacted comprehensive consumer privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”) and similar laws in Virginia, Colorado, Connecticut, Texas, and other states. Depending on our size and activities, some of these laws may not strictly apply to us; nevertheless, we extend the following rights to all U.S. residents whose personal information we hold, subject to applicable law:

  • Right to know / access — request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom it is shared.
  • Right to delete — request deletion of personal information we have collected from you, subject to legal exceptions.
  • Right to correct — request correction of inaccurate personal information.
  • Right to data portability — receive your personal information in a portable and readily usable format.
  • Right to opt out — opt out of the “sale” or “sharing” of personal information, targeted advertising, and certain profiling. We do not sell personal information, and we do not share it for cross-context behavioural advertising [; if this changes, we will provide a “Do Not Sell or Share My Personal Information” link and honour opt-out requests].
  • Right to limit sensitive personal information — limit our use of sensitive personal information to purposes permitted by law. We do not intentionally collect sensitive personal information.
  • Right to non-discrimination — we will not discriminate against you (for example, by denying services or charging different prices) for exercising any of these rights.

We honour opt-out preference signals such as the Global Privacy Control (GPC) browser setting as a valid request to opt out, where required by applicable state law. You may submit rights requests to privacy@icubestudios.com or via [web form link]. You may authorise an agent to act on your behalf, and we may take steps to verify your identity (and the agent’s authority) before responding. We will respond within 45 days, extendable by a further 45 days where reasonably necessary, with notice to you. If we decline a request, you may appeal by replying to our decision, and we will respond to your appeal within the period required by your state’s law; if the appeal is denied, you may contact your state Attorney General.

Our marketing emails comply with the CAN-SPAM Act: every message identifies us, includes our postal address, and contains an unsubscribe mechanism that we honour promptly.

Cookies and Similar Technologies

Our website uses cookies and similar technologies to make the site work, analyse usage, and [personalise content]. We use:

  • Strictly necessary cookies — required for the operation of the website (no consent required).
  • Analytics/performance cookies — help us understand how visitors use the site, including for the internal purposes in Section 6 (used only with your consent).
  • Functionality cookies — remember your preferences (used only with your consent).
  • Marketing/targeting cookies — deliver relevant advertising (used only with your consent).

You can manage your preferences through our cookie banner at any time or through your browser settings. For full details, see our separate Cookie Policy at [link].

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements, after which we securely delete or anonymise it. Indicative retention periods are:

Category of data

Retention period

Account and profile data

Duration of the relationship plus [X] years

Transaction, billing, and tax records

[X] years, as required by applicable tax and accounting law

Marketing data and preferences

Until consent is withdrawn or [X] years after last interaction

Customer support correspondence

[X] years from resolution of the enquiry

Technical logs and analytics data

[X] months; thereafter retained only in aggregated or anonymised form for internal purposes

Recruitment data (unsuccessful candidates)

[X] months after conclusion of the recruitment process, unless consent is given to retain longer

We may retain personal data for longer than the periods above where reasonably necessary to comply with a legal obligation, resolve disputes, enforce our agreements, establish or defend legal claims, or maintain business records required for audits — in each case only for as long as that need continues. For users in India, where the DPDP Rules prescribe specific retention or erasure timelines for our class of Data Fiduciary, we comply with those timelines, and we erase personal data when you withdraw consent or when the specified purpose is no longer being served, unless retention is required by law.

Data Security and Breach Notification

We have implemented appropriate technical and organisational measures, as required by Article 32 GDPR and the reasonable security safeguards required by the DPDP Act and DPDP Rules, to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These include [encryption in transit and at rest, access controls and role-based permissions, staff training, regular security testing, and vendor due diligence].

In the event of a personal data breach: for EU/UK users, we will notify the competent supervisory authority within 72 hours where the breach is likely to result in a risk to your rights and freedoms and notify you without undue delay where the risk is high. For users in India, we will notify the Data Protection Board of India and each affected Data Principal in the form, manner, and timelines prescribed under the DPDP Rules.

Children’s Data

Our services are not directed at children. We do not knowingly collect personal data from anyone under 18 years of age in India, under [16] years of age in the EU/UK [adjust per member-state law], or under 13 years of age in the United States (in line with COPPA), without verifiable parental consent where the law permits such processing at all. In line with the DPDP Act, we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us with personal data, please contact us and we will delete it.

Complaints
  • Users in the EEA/UK: you may lodge a complaint at any time with your local supervisory authority (a full list of EU authorities is available at https://edpb.europa.eu; in the UK, the ICO at https://ico.org.uk).
  • Users in India: if you are not satisfied with our response to a grievance, you may complain to the Data Protection Board of India in accordance with the DPDP Act and the DPDP Rules.
  • Users in the United States: you may contact your state Attorney General or, in California, the California Privacy Protection Agency.

We would appreciate the opportunity to address your concerns before you approach a regulator, so please contact us in the first instance.

Third-Party Links, Changes, and Contact

Our website may contain links to third-party websites, plug-ins, and applications. We do not control these third parties and are not responsible for their privacy practices; please read the privacy policy of every website you visit.

We may update this Privacy Policy from time to time. The latest version will always be available at [link], with the “Last updated” date shown at the top. Where changes are material, we will notify you by [email / prominent notice on our website] before they take effect.

If you have any questions about this Policy or our handling of your personal data, please contact:

  • Email: privacy@icubestudios.com
  • Post: [Supritha – Grievance Officer, iCube Studios – Address: Brigade IRV 9th Floor Nallurhalli Road Whitefield Bengaluru 560 066]