SattvaLok Emblem
SattvaLokCONNECTING YOU TO SANATAN

Trust, Privacy & Authenticity

Our commitment to protecting people, respecting knowledge, and building technology responsibly.

Trust is at the heart of SattvaLok.

When someone shares their date, time and place of birth, asks a deeply personal question, consults an astrologer, participates in a Puja or Seva, purchases a traditional product, or simply comes to SattvaLok looking for knowledge, they are placing a certain degree of trust in us.

We do not take that trust lightly.

SattvaLok is being designed around three fundamental responsibilities:

Protect the person.

Respect the knowledge.

Be transparent about the technology.

Our approach to trust combines privacy engineering, cybersecurity, responsible AI, knowledge governance, practitioner verification, product transparency and consumer protection.

We do not believe trust should be created by simply putting the word “verified” on a website.

Trust should be built into the systems behind the website.


01. Privacy by Design

Your personal information belongs to you.

SattvaLok may process personal information to provide certain services and experiences.

Depending on the product, this may include information such as:

  • Name
  • Email address
  • Mobile number
  • Account information
  • Date of birth
  • Time of birth
  • Place of birth
  • Location information where required for a service
  • Kundli-related information
  • Transaction information
  • Service history
  • Communication preferences
  • Customer-support information
  • Device and technical information
  • Information generated through use of SattvaLok services

Some of this information can be highly personal.

We therefore aim to follow a privacy-by-design approach rather than treating privacy as something added after a product is built.

Our approach is based on principles including:

  • Data minimisation
  • Purpose limitation
  • Transparency
  • Appropriate security
  • Access control
  • Controlled retention
  • Responsible third-party processing
  • User rights
  • Accountability

India's Digital Personal Data Protection Act, 2023 establishes a framework governing the processing of digital personal data and defines responsibilities for Data Fiduciaries and rights for Data Principals. The DPDP Rules, 2025 further specify requirements around notices, security safeguards, breach response, retention, children's data and related processes.


02. What We Collect — and Why

We do not believe that collecting more information automatically creates a better product.

For every category of personal information, our objective is to understand:

What information do we need?

Why do we need it?

What service requires it?

How long should we retain it?

Who needs access to it?

Can we provide the service without collecting it?

This is the foundation of responsible data collection.

For example, a Panchang experience may require very little personal information.

An account may require identity and contact information.

An astrological service may require birth details.

A transaction may require payment and delivery information.

Different services therefore require different data.

One service should not automatically receive access to information collected for another service.


03. Kundli & Birth Information

Astrological experiences may require:

  • Date of birth
  • Time of birth
  • Place of birth

These details can be used to calculate planetary positions and generate a Kundli or related astrological experience.

Because this information is personal, SattvaLok aims to apply appropriate technical and organisational safeguards to it.

We will clearly communicate the purposes for which such information is processed.

Where consent is the applicable basis for processing, the consent experience should be specific, informed and capable of being withdrawn through an accessible mechanism.

The DPDP Rules require notices to be understandable and separately accessible, and require mechanisms through which a Data Principal can withdraw consent and exercise applicable rights.

Your birth information should be treated as personal information — not as a commodity.


04. Security by Design

Security is not a single technology.

It is a system of controls.

SattvaLok's security architecture is intended to use appropriate safeguards based on the sensitivity and purpose of the information being processed.

Depending on the system and risk, these can include:

  • Encryption in transit
  • Encryption at rest where appropriate
  • Secure authentication
  • Strong password protection
  • Role-based access control
  • Least-privilege access
  • Administrative access controls
  • Secrets management
  • Secure API design
  • Input validation
  • Rate limiting
  • Security logging
  • Monitoring
  • Backup and recovery
  • Vulnerability management
  • Dependency management
  • Incident response
  • Security testing
  • Infrastructure hardening

The DPDP Rules, 2025 expressly identify safeguards such as encryption, masking, tokenisation, access controls, logging and monitoring, backups, processor-contract provisions and appropriate technical and organisational measures.

Security controls will evolve as SattvaLok evolves.


05. Encryption

Where encryption is used, it should be implemented according to the actual architecture of the service.

For appropriate systems, SattvaLok intends to use modern encryption practices for data transmitted between users and our services and for sensitive information stored within systems where appropriate.

We will not describe a service as “end-to-end encrypted” unless the technical architecture genuinely provides end-to-end encryption.

This distinction matters.

Encryption in transit, encryption at rest and true end-to-end encryption are different security properties.

We would rather describe our security accurately than use stronger terminology for marketing.


06. Access Control

Not every person working at SattvaLok should be able to access every piece of information.

Access should be based on:

Role

Business necessity

Minimum required privilege

Security controls

Where appropriate, access should be logged and reviewable.

Administrative access should receive additional protection because compromise of privileged accounts can create disproportionate risk.

Our objective is simple:

The people and systems that do not need access should not have access.

07. Data Processors and Technology Partners

SattvaLok may rely on specialised technology providers for infrastructure and services such as:

  • Cloud hosting
  • Databases
  • Authentication
  • Email
  • Payments
  • Analytics
  • Customer support
  • Communication
  • AI infrastructure
  • Security
  • Storage
  • Other technical services

Where a third party processes personal data on SattvaLok's behalf, the relationship should be governed by appropriate contractual and technical controls.

The DPDP Rules require appropriate provisions between Data Fiduciaries and Data Processors concerning security safeguards.

For global operations, other privacy regimes may also impose processor-contract, security and international-transfer requirements. Under GDPR, for example, controllers remain responsible for selecting processors that provide sufficient guarantees and for putting appropriate contractual safeguards in place.


08. Data Retention

Keeping personal information forever is not the same as protecting it.

The longer information exists, the longer it potentially remains exposed to:

  • Accidental disclosure
  • Unauthorised access
  • Security incidents
  • Misuse
  • Incorrect processing
  • Unnecessary duplication

SattvaLok therefore aims to establish retention periods based on the purpose for which information is processed and applicable legal obligations.

Where information is no longer required for its intended purpose and there is no legal reason to retain it, appropriate deletion or anonymisation processes may apply.

The DPDP Rules contain specific retention/deletion requirements for certain classes of Data Fiduciaries and purposes, while also recognising circumstances where another applicable law requires longer retention.

Data should have a reason to exist.


09. Your Privacy Rights

Subject to applicable law and the relevant circumstances, individuals may have rights relating to their personal data.

The DPDP Act provides for rights including:

  • Access to information about personal data
  • Correction of personal data
  • Erasure of personal data
  • Grievance redressal
  • Nomination

It also establishes duties for Data Principals.

SattvaLok intends to provide appropriate mechanisms for users to exercise applicable rights.

Where a request cannot be fulfilled because another legal obligation requires information to be retained or because an applicable exception applies, the relevant limitation should be communicated appropriately.


10. Consent Should Be Meaningful

Consent should not be hidden inside confusing language.

Where consent is required, we aim to make it:

Clear

You should understand what you are agreeing to.

Specific

The purpose should be identifiable.

Informed

Relevant information should be available before consent is given.

Voluntary

Consent should not be obtained through misleading or unnecessarily coercive design.

Withdrawable

Where consent is the applicable basis, withdrawing consent should be reasonably accessible.

The DPDP Rules specifically require the notice to be understandable and provide information about how consent can be withdrawn and how applicable rights can be exercised.


11. No Hidden Data Economy

SattvaLok's objective is not to build a business model around secretly monetising personal information.

We do not want users to feel that using a spiritual or knowledge platform means surrendering control of their personal information.

Where information is used for a commercial purpose, the applicable purpose should be communicated in accordance with applicable law.

Where third-party services are involved, their role should be reflected in the applicable privacy disclosures.

Personal data should support the service — not secretly become the product.


12. Privacy and Advertising

Advertising and privacy must be treated separately.

SattvaLok does not want sensitive personal information to become an invisible mechanism for commercial targeting.

Where advertising, analytics, personalisation or measurement technologies are used, they should be implemented consistently with applicable privacy requirements and the disclosures provided to users.

We aim to minimise unnecessary tracking and avoid collecting information simply because technology makes it possible.

More tracking does not automatically mean a better product.


13. Children's Privacy

Under the DPDP Act, a child is an individual who has not completed 18 years of age. The Act provides additional requirements for processing children's personal data.

The DPDP Rules provide mechanisms concerning verifiable parental consent and verification of the adult representing themselves as the parent, subject to the applicable framework and exceptions.

SattvaLok therefore intends to treat children's data with additional care.

Where children's personal data is processed, our systems will be designed to apply the requirements applicable to children under the relevant law.

We will not treat children as ordinary adult users for privacy purposes.


14. Data Breach Response

No organisation should assume that a security incident is impossible.

Responsible security means preparing for the possibility that something may go wrong.

SattvaLok intends to maintain an incident-response process covering areas such as:

1. Detection
2. Containment
3. Investigation
4. Assessment
5. Remediation
6. Recovery
7. Communication
8. Post-incident review

The DPDP Rules require specified actions following a personal data breach, including communication to affected Data Principals without delay and notification to the Data Protection Board according to the prescribed requirements and timelines.

Separately, CERT-In's directions require covered entities to report specified cyber incidents, including data breaches or data leaks, within the prescribed six-hour window from noticing or being informed of the incident.

Our objective is not merely to prevent incidents.

It is also to respond responsibly when incidents occur.


15. Cybersecurity and CERT-In

SattvaLok operates in a digital environment where cybersecurity obligations can arise independently of privacy obligations.

Privacy law asks questions such as:

How should personal data be processed?

Cybersecurity requirements also ask:

How should systems be protected, monitored and incidents reported?

These are related but not identical responsibilities.

SattvaLok therefore intends to maintain appropriate cybersecurity processes covering areas such as:

  • Security monitoring
  • Incident detection
  • Incident response
  • System logging
  • Access management
  • Infrastructure security
  • Vulnerability management
  • Backup and recovery
  • Security documentation

CERT-In's directions under the Information Technology Act framework include incident reporting obligations and other cybersecurity requirements applicable to covered entities.


16. Responsible AI

AI will be one of the most important technologies inside SattvaLok.

It will also be one of the areas requiring the greatest responsibility.

AI can:

  • misunderstand a question
  • generate inaccurate information
  • mix traditions
  • invent citations
  • produce fabricated explanations
  • overstate certainty
  • reproduce errors from training or retrieved sources

Therefore:

We do not believe that an AI answer becomes trustworthy merely because it sounds confident.

Our objective is to build AI systems that increasingly use:

  • Structured knowledge
  • Source-aware retrieval
  • Context
  • Provenance
  • Appropriate references
  • Evaluation
  • Human review where appropriate
  • Clear limitations
  • Uncertainty handling

  • 17. AI Guru — What It Should and Should Not Be

The SattvaLok AI Guru is intended to become a conversational gateway into the SattvaLok knowledge ecosystem.

It may help users explore subjects such as:

  • Sanatan philosophy
  • Scriptures
  • Festivals
  • Panchang
  • Tithi
  • Nakshatra
  • Muhurat
  • Traditions
  • Stories
  • Temple history
  • Cultural practices
  • Vedic astrology concepts
  • Related knowledge

But the AI Guru should not present itself as an infallible authority.

It should not claim divine authority.

It should not invent scriptural references.

It should not hide uncertainty.

It should not automatically treat one regional or sectarian interpretation as universal.

AI should help people explore knowledge.

It should not manufacture spiritual authority.


18. Source and Knowledge Governance

SattvaLok aims to build a structured approach to knowledge.

Where appropriate, information may be classified according to its nature, such as:

Primary source

Traditional interpretation

Scholarly interpretation

Regional practice

Contemporary explanation

Individual opinion

AI-generated synthesis

This helps prevent different categories of information from being presented as though they have exactly the same authority.

Context is part of authenticity.


19. When Traditions Disagree

Sanatan Dharma contains many traditions, schools and practices.

Sometimes they agree.

Sometimes they differ.

Sometimes they use different terminology.

Sometimes they interpret the same concept differently.

SattvaLok does not want to hide this complexity.

Where meaningful differences exist, our goal is to explain them responsibly.

Instead of forcing every subject into one answer, we can communicate:

“This is one established interpretation.”

or:

“Different traditions explain this differently.”

or:

“The available sources do not establish one universally accepted answer.”

Respecting diversity is part of respecting the tradition.


20. Astrologer Verification

SattvaLok may connect users with astrologers and other practitioners.

Trust in these individuals is therefore critical.

Our intended verification framework may include, depending on the role:

Identity verification

Establishing the identity of the person operating the account.

Profile verification

Reviewing professional information provided by the practitioner.

Qualification review

Reviewing claimed qualifications, training or relevant credentials where applicable.

Experience review

Considering relevant experience and professional background.

Platform standards

Requiring practitioners to comply with SattvaLok's service and conduct requirements.

Ongoing review

Considering user feedback, complaints and relevant platform signals.

However, verification must be described accurately.

A verified profile does not mean that every prediction, interpretation or opinion of the practitioner is guaranteed to be correct.

It means that the practitioner has passed the applicable SattvaLok verification process.


21. No False Authority

SattvaLok will not use verification language to create an impression of certainty that does not exist.

For example:

“Verified identity” is different from “guaranteed correct.”

“Credential reviewed” is different from “universally authoritative.”

“Product tested” is different from “spiritually guaranteed.”

“AI-generated explanation” is different from “scriptural truth.”

We believe these distinctions matter.


22. Authenticity of Traditional Products

If SattvaLok offers products such as Rudraksha, gemstones or other traditional items, authenticity claims should be supported by appropriate evidence.

Depending on the product, this may include:

  • Supplier documentation
  • Product provenance
  • Independent testing
  • Laboratory reports
  • Certificate numbers
  • Testing organisation
  • Testing date
  • Product identification
  • Applicable test parameters

We will not describe a product as independently lab-tested unless such testing has actually been performed.

We will not describe a certificate as proof of something that the certificate does not establish.

Authenticity should be demonstrated — not merely advertised.


23. Product Certificates

Where a certificate is provided, users should be able to understand what it represents.

A useful certificate may identify:

  • What was tested
  • Who performed the test
  • When it was tested
  • What was found
  • Which product or sample it relates to
  • How the certificate can be verified, where applicable

This helps turn:

“Trust us.”

into:

“Here is the evidence.”


24. Consumer Protection

SattvaLok may eventually facilitate digital services, bookings and commerce.

Those activities create responsibilities beyond privacy.

India's Consumer Protection Act, 2019 provides a framework for consumer protection and includes provisions addressing unfair trade practices, misleading advertisements, product liability and e-commerce-related matters.

Accordingly, SattvaLok aims to provide clear information concerning applicable:

  • Product descriptions
  • Service descriptions
  • Prices
  • Taxes where applicable
  • Delivery information
  • Cancellation terms
  • Refund policies
  • Terms of service
  • Provider information
  • Customer support
  • Complaint mechanisms
  • A customer should understand what they are buying before they pay for it.


    25. No Misleading Spiritual Claims

SattvaLok should not use technology or spirituality to create false certainty.

We will avoid presenting unsupported claims such as:

  • guaranteed future outcomes
  • guaranteed financial success
  • guaranteed health outcomes
  • guaranteed relationship outcomes
  • guaranteed supernatural results
  • unsupported claims of scriptural authority
  • fabricated credentials
  • fabricated certifications

Spiritual and astrological experiences should be represented honestly.

Faith deserves respect.

Trust should never be manufactured through fear or false promises.


26. Payments and Transactions

Where users purchase products or services, payment information may be processed through payment service providers.

SattvaLok should minimise the payment information it directly handles where appropriate and use established payment infrastructure designed for secure transactions.

Payment processing may involve third-party providers, whose own terms and privacy policies may also apply.

The exact architecture will determine which information is handled directly by SattvaLok and which is handled by the relevant payment provider.


27. International Users

SattvaLok is designed with a global vision.

That means privacy obligations may extend beyond India depending on:

  • where a user is located
  • what services are offered
  • where SattvaLok operates
  • what data is processed
  • where processing takes place
  • which legal regimes apply

For users in the European Economic Area, for example, GDPR requirements can apply in relevant circumstances, including requirements concerning lawful processing, individual rights, processors, security and international data transfers.

International transfers may require appropriate legal mechanisms and safeguards depending on the jurisdiction and circumstances.

Global accessibility requires global responsibility.


28. Data Residency and International Transfers

Where personal information is processed using infrastructure outside India or transferred across borders, SattvaLok will assess the applicable legal and contractual requirements.

The architecture may involve cloud providers or other technology partners operating across multiple jurisdictions.

Our approach is to understand:

  • Where information is stored
  • Where it is processed
  • Who processes it
  • Why it is transferred
  • What contractual protections apply
  • What legal requirements govern the transfer

For international users, additional requirements may apply under their local privacy laws.


29. Privacy Across the SattvaLok Ecosystem

SattvaLok is intended to become an ecosystem rather than one application.

Different products may have different purposes.

For example:

Panchang

may require limited personal information.

Astrology

may require birth information.

Puja and Seva

may require booking and contact information.

Commerce

may require transaction and delivery information.

Community

may involve profile and interaction information.

AI

may process conversation information depending on how the product is designed.

Because the purposes differ, the privacy architecture must also account for those differences.

One ecosystem does not mean one giant pool of personal data.


30. Data Separation

As SattvaLok grows, we aim to design systems so that information is appropriately separated according to:

  • Product
  • Purpose
  • User permissions
  • Service requirements
  • Internal access
  • Security requirements

This helps reduce unnecessary exposure.

For example, a team member working on a product catalogue should not automatically need access to a user's astrological information.

Access should follow purpose.


31. Privacy Is a Product Feature

We do not want privacy to exist only as a legal document that nobody reads.

Privacy should be reflected in the product itself.

That means designing:

  • Clear permission flows
  • Understandable notices
  • Account controls
  • Data-management options
  • Appropriate consent mechanisms
  • Security-conscious defaults
  • Transparent communication
  • Accessible support

The best privacy policy is not a replacement for good product design.


32. Trust by Default

Our long-term objective is to make responsible choices the default.

Where possible:

Collect less.

Explain more.

Protect better.

Retain only what is justified.

Give users meaningful control.

Make important information understandable.

Do not hide behind technical language.


33. Accountability

Trust also requires accountability.

As SattvaLok grows, we intend to establish appropriate internal processes for:

  • Privacy governance
  • Security governance
  • Data inventories
  • Vendor reviews
  • Access reviews
  • Incident response
  • Knowledge governance
  • AI evaluation
  • Practitioner verification
  • Product authenticity
  • Consumer complaints

Where the applicable legal framework requires designated roles or officers, SattvaLok will establish them as required.

The DPDP Rules also contemplate publication of appropriate contact information for questions concerning personal-data processing and rights.


34. Continuous Improvement

Security, privacy and authenticity are not projects that are completed once.

Technology changes.

Threats change.

Laws change.

Products change.

User expectations change.

Therefore, our policies and systems must change too.

SattvaLok intends to regularly review its:

  • Security architecture
  • Privacy practices
  • Data-retention approach
  • Vendor relationships
  • AI systems
  • Knowledge sources
  • Practitioner verification
  • Product verification
  • User-protection mechanisms
  • Trust is not a checkbox.

    It is a continuous process.


    35. Our Five-Layer Trust Model

Everything we build can be viewed through five layers.

01 — Source

Where did this information come from?

We seek to understand and communicate provenance where appropriate.

02 — Context

What does the source actually mean?

Information without context can easily be misunderstood.

03 — Verification

Can the relevant claim, person, product or process be checked?

We aim to replace unsupported claims with evidence wherever practical.

04 — Security

Is the person's information protected appropriately?

Technology must protect the information it handles.

05 — Accountability

What happens when something goes wrong?

Responsible systems require mechanisms for complaints, correction, investigation and improvement.


36. Our Privacy Principle

We believe privacy can be expressed simply:

Collect what you need. Explain why. Protect it carefully. Give people meaningful control. Keep it only as long as justified.

37. Our Authenticity Principle

Authenticity can also be expressed simply:

Do not claim more than the evidence supports.

If a source supports a claim, show the source where appropriate.

If a product has been tested, identify what was tested.

If a practitioner has been verified, explain what verification means.

If an AI answer is uncertain, communicate that uncertainty.

If traditions differ, acknowledge the difference.

If something is unknown, say so.


38. Our AI Principle

And our AI philosophy is:

AI should make knowledge easier to explore, not make uncertainty invisible.

We want technology to help people ask better questions, discover relevant knowledge and understand complex subjects.

But we do not want AI to manufacture authority.


39. Our Security Principle

Our security philosophy is:

Assume systems will be tested, design for failure, minimise access, monitor responsibly, and respond quickly when something goes wrong.

Security is therefore not only about preventing attacks.

It is also about:

  • Preparation
  • Detection
  • Response
  • Recovery
  • Learning

  • 40. Our Consumer Principle

Our consumer philosophy is:

People should understand what they are receiving before they decide to purchase it.

That means clear information, honest descriptions, transparent pricing and appropriate customer support.


41. What We Promise

We do not promise absolute security.

No responsible technology company should.

We do not promise that AI will never make mistakes.

It can.

We do not promise that every tradition has one universally accepted interpretation.

It does not.

We do not promise that every practitioner will always be right.

No verification process can establish that.

We do not promise that every product claim can be reduced to a simple certificate.

Different products require different forms of evidence.

Instead, we promise something more meaningful:

We will keep improving the systems that earn trust.

We will work to:

  • Protect personal information
  • Follow applicable privacy requirements
  • Build appropriate security controls
  • Respond responsibly to incidents
  • Respect traditional sources
  • Distinguish evidence from interpretation
  • Be transparent about AI limitations
  • Verify people and products according to defined standards
  • Give users meaningful information
  • Correct mistakes when identified

  • 42. Trust Is Earned

We do not expect people to trust SattvaLok simply because we say:

“Trust us.”

Trust has to be earned.

It is earned when:

A user understands what data is being collected.

A customer knows what they are purchasing.

A practitioner can demonstrate their credentials.

A product claim has supporting evidence.

An AI system acknowledges uncertainty.

A source can be identified.

A security incident is handled responsibly.

A mistake is corrected instead of hidden.

A user's privacy is respected even when nobody is watching.

That is the kind of trust we want SattvaLok to build.


The SattvaLok Standard

We want SattvaLok to stand for something simple:

Knowledge with context.

Technology with responsibility.

Privacy with respect.

Services with transparency.

Products with evidence.

AI with accountability.

And an ecosystem built on trust.


Trust Before Growth

Growth is important.

Innovation is important.

Technology is important.

But none of them matter if people cannot trust the ecosystem.

SattvaLok therefore believes:

Trust comes before scale.

Responsibility comes before convenience.

Transparency comes before marketing.

Evidence comes before claims.

People come before data.


Our Commitment to You

SattvaLok is being built for a world where ancient knowledge and modern technology increasingly meet.

We want that meeting to happen responsibly.

We want technology to make knowledge more accessible without making it less meaningful.

We want AI to make exploration easier without pretending to be infallible.

We want digital services to make traditional experiences more accessible without reducing them to transactions.

We want commerce to provide relevant products without turning spiritual trust into a marketing shortcut.

And above all:

We want people to know what they are trusting, why they are trusting it, and what safeguards exist behind that trust.

Because SattvaLok is not simply building another digital platform.

We are building an ecosystem where trust is part of the product.

SattvaLok

Ancient wisdom. Modern technology. Built on trust.