1.1 MOJO Network (“MOJO”, “we”, “us”, “our”) is a News Portal as a Service platform developed and owned by Seagull Venture Private Limited. This Privacy Policy explains how personal data is collected, used, stored, shared, retained and protected when you use our services.
1.2 This Policy applies to: Subscribers, being channel owners who register for our services; Users, being visitors to a MOJO-powered news portal; advertisers and their representatives; and anyone who contacts us.
1.3 This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 and the rules made under it, the Information Technology Act, 2000 and the rules made under it, and the platform terms of integrated third-party services including Meta, Google and X.
1.4 This Policy is available in English and Hindi. Where a translation is provided in any other language listed in the Eighth Schedule to the Constitution of India, it is provided for convenience and the English version prevails in the event of inconsistency.
1.5 This Policy should be read with the Terms and Conditions, the SaaS Service Agreement, the Advertising and Monetisation Policy and the Grievance Redressal Policy.
Personal Data: any data about an individual who is identifiable by or in relation to such data.
Data Principal: the individual to whom the Personal Data relates. Where the individual is a child, it includes the parent or lawful guardian; where the individual is a person with disability, it includes the lawful guardian.
Data Fiduciary: the person who alone or in conjunction with others determines the purpose and means of processing Personal Data.
Data Processor: a person who processes Personal Data on behalf of a Data Fiduciary.
Subscriber: a channel owner who registers for and uses our services to create and manage a news portal.
User: any individual who visits, reads or interacts with a news portal created by a Subscriber on our Platform.
Processing: any operation performed on Personal Data, including collection, recording, storage, use, sharing, disclosure and erasure.
Third-Party Services: external platforms and application programming interfaces integrated with the Platform, including Meta (Facebook and Instagram), Google, YouTube, X, WhatsApp and payment gateways.
3.1 For Personal Data of Subscribers, being registration, account, billing, support and communication data, MOJO is the Data Fiduciary and determines the purpose and means of processing.
3.2 For Personal Data of Users collected through a Subscriber's news portal, including comments, submissions and portal analytics, the Subscriber is the Data Fiduciary and MOJO acts as a Data Processor on the Subscriber's documented instructions. The Subscriber's own privacy policy governs the collection and use of that data.
3.3 For platform-level operational and security data collected across the Platform, including logs necessary to secure and operate the service, MOJO is the Data Fiduciary.
3.4 Where you are unsure which party is responsible for particular data, contact our Grievance Officer, who will identify the correct Data Fiduciary and route your request.
4.1 Where processing is based on consent, we give notice of the Personal Data sought, the purpose of processing, the manner in which a Data Principal may exercise their rights, and the manner of making a complaint to the Data Protection Board of India, before or at the time of seeking consent.
4.2 Consent is sought by a clear affirmative action. It is free, specific, informed, unconditional and unambiguous, and is limited to the Personal Data necessary for the specified purpose. Continued browsing alone is not treated as consent to non-essential processing.
4.3 Certain processing is carried out on the basis of legitimate uses permitted under the Digital Personal Data Protection Act, 2023, including where you voluntarily provide data for a specified purpose, for compliance with a legal obligation or a judgment, and for responding to a medical emergency or a threat to public health or safety.
4.4 You may withdraw consent at any time, with the same ease with which it was given, using the contact details in Clause 17. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. On withdrawal we will cease the relevant processing and erase the Personal Data unless retention is required by law.
4.5 Where you give consent through a Consent Manager registered with the Data Protection Board of India, you may give, manage, review and withdraw consent through that Consent Manager.
5.1 From Users visiting a Subscriber portal
5.2 From Subscribers
5.3 From advertisers and other contacts
5.4 We do not require you to provide any Personal Data that is not necessary for the purpose for which it is collected. We do not knowingly collect Personal Data that is not needed.
6.1 We and our Subscribers use cookies and similar technologies. Categories used are:
| Category | Purpose | Consent |
|---|---|---|
| Strictly necessary | Authentication, security, session management, load balancing | Not required |
| Functional | Language, layout and display preferences | Requested |
| Analytics | Traffic measurement, feature usage and performance | Requested |
| Advertising | Delivery, frequency capping and measurement of advertising | Requested |
6.2 You may accept or decline non-essential cookies through the consent banner, and may change your choice at any time through the same mechanism or through your browser settings. Declining non-essential cookies does not prevent access to editorial content.
6.3 Third-party analytics and advertising providers may set their own cookies. Their processing is governed by their own privacy policies.
| Purpose | Whose data | Basis |
|---|---|---|
| Creating and managing accounts and instances | Subscribers | Contract and consent |
| Processing payments and disbursing advertising revenue | Subscribers | Contract and legal obligation |
| Providing, securing and maintaining the Platform | Subscribers, Users | Contract and legitimate use |
| Service announcements, security alerts and support | Subscribers | Contract |
| Analytics, troubleshooting and product improvement | Subscribers, Users | Consent, and legitimate use for security |
| Delivery and measurement of advertising | Users | Consent |
| Marketing communications about new features and offers | Subscribers | Consent, withdrawable at any time |
| Detecting and preventing fraud and invalid activity | Subscribers, Users | Legitimate use and legal obligation |
| Compliance with law and response to lawful requests | All | Legal obligation |
7.1 We do not use Personal Data for any purpose materially different from those stated above without giving fresh notice and, where required, obtaining fresh consent.
7.2 We do not use Personal Data or Subscriber Content to train generative artificial intelligence models for the benefit of third parties.
8.1 We do not sell or rent Personal Data. We share it only in the following circumstances:
8.2 Where we disclose Personal Data in response to a legal request, we shall, where lawful and practicable, notify the affected Data Principal or Subscriber.
9.1 We integrate with Meta, Google, X and other platforms to enable Subscribers to cross-post their original hyperlocal news content and to distribute it to their audiences.
9.2 When a Subscriber connects a Meta account, we receive from Meta only the data necessary to provide the requested functionality, which may include the page identifier, an access token and public content data required to publish. We do not collect, store or use Personal Data from a Meta profile beyond what the requested functionality requires, and we do so only with express, informed consent.
9.3 A Subscriber may disconnect any integration at any time from the dashboard. On disconnection we cease using the associated tokens and delete them within [thirty (30)] days, save where retention is required by law.
9.4 A Subscriber or User may request deletion of data obtained through a third-party integration by writing to [email protected]. We shall action such requests within the timelines in Clause 12.
9.5 Our use of data received from a Third-Party Service complies with that service's platform terms and developer policies. Data received through one integration is not used to enrich or supplement data held for another purpose without consent.
10.1 We retain Personal Data only for as long as necessary for the purpose for which it was collected, or for such longer period as is required by law. Indicative retention periods are:
| Category | Retention |
|---|---|
| Subscriber account and contract data | For the term of the subscription and [eight (8)] years thereafter, for tax and statutory record purposes |
| Payment, invoice and payout records | [Eight (8)] years, as required under tax law |
| Verification documents | For the term of the subscription and [one (1)] year thereafter |
| Support and communication records | [Three (3)] years from closure of the matter |
| Grievance records | Not less than 180 days, and longer where a proceeding is pending |
| Server, access and security logs | [One hundred and eighty (180)] days |
| Analytics data at User level | [Twenty-six (26)] months, after which it is aggregated |
| Marketing consent records | Until consent is withdrawn, and [three (3)] years thereafter as proof of consent |
10.2 On expiry of the applicable period, or on withdrawal of consent where consent was the basis of processing, Personal Data is erased or irreversibly anonymised, unless retention is required for compliance with law or for the establishment or defence of a legal claim.
10.3 Personal Data contained in published editorial Content is retained by the Subscriber as publisher and is governed by the Subscriber's own retention practice and by the law applicable to news archives.
11.1 We implement reasonable technical, administrative and physical safeguards, including access controls, encryption in transit, role-based permissions, logging and periodic review, consistent with Section 43A of the Information Technology Act, 2000 and the rules made under it.
11.2 Personal Data is stored on servers located in India. Where a Third-Party Service selected by a Subscriber processes data outside India, that processing is governed by the terms of that service.
11.3 No internet transmission or storage system is entirely secure, and we cannot guarantee absolute security. You are responsible for protecting your own credentials.
11.4 On becoming aware of a personal data breach, we shall notify the Data Protection Board of India and each affected Data Principal in the form and within the time required under the Digital Personal Data Protection Act, 2023, and shall notify affected Subscribers without undue delay so that they may discharge their own obligations as Data Fiduciary.
11.5 We maintain an incident response process covering detection, containment, assessment, notification and remediation, and cooperate with the Indian Computer Emergency Response Team where required.
12.1 Subject to the Digital Personal Data Protection Act, 2023, you have the right to:
12.2 To exercise any right, write to [email protected] with sufficient particulars to identify you and the data concerned. We may seek verification of your identity before acting, in order to protect your data.
12.3 We shall acknowledge every request within twenty-four (24) hours and respond within [thirty (30)] days. Where a request concerns data for which a Subscriber is the Data Fiduciary, we shall route the request to that Subscriber within [seven (7)] days and inform you.
12.4 You shall furnish only verifiably authentic information when exercising a right, and shall not impersonate another person or raise false or frivolous complaints.
12.5 Where a request is refused, we shall inform you of the reason and of your right to escalate under Clause 16.
13.1 Our services are directed at adults. We do not knowingly collect Personal Data of a child except with the verifiable consent of a parent or lawful guardian.
13.2 We do not undertake tracking, behavioural monitoring or targeted advertising directed at children, and we do not process children's data in a manner likely to cause any detrimental effect on their wellbeing.
13.3 Subscribers publishing content likely to attract child readers shall configure their portals for contextual advertising only, and shall not enable behavioural targeting on such sections.
13.4 Where a Data Principal is a person with disability who has a lawful guardian, consent is obtained from that guardian.
13.5 If we become aware that we hold a child's Personal Data without the required consent, we shall delete it without undue delay. A parent or guardian may write to [email protected] to request deletion.
14.1 The Platform uses automated processing for content categorisation, tagging, search optimisation, fraud and invalid activity detection, and advertising delivery.
14.2 We do not take any decision producing a significant legal effect concerning you solely on the basis of automated processing without human review.
14.3 The Platform's artificial intelligence features process Content for the purpose of enhancement. Personal Data appearing within Content is processed only as necessary for that purpose, and neither Personal Data nor Subscriber Content is used to train generative models for the benefit of third parties.
14.4 Aggregated and de-identified usage data, from which no individual and no Subscriber can reasonably be identified, may be used to operate, secure and improve the Platform.
15.1 Every Subscriber is a Data Fiduciary in respect of Personal Data collected through its own news portal, and shall: publish its own privacy policy and give the notice required under the Digital Personal Data Protection Act, 2023; obtain and record valid consent where consent is the basis of processing; respond to Data Principal requests; appoint and publish the contact details of a person to answer questions about its processing; and notify breaches as required.
15.2 A Subscriber shall not instruct MOJO to process Personal Data in a manner that would breach applicable law, and shall indemnify MOJO against any claim arising from its own processing.
15.3 MOJO shall assist Subscribers, so far as reasonably practicable, in responding to Data Principal requests and in meeting their obligations, in accordance with the data processing terms of the SaaS Service Agreement.
16.1 Complaints and questions about this Policy or about our processing may be addressed to our Grievance Officer:
Name: Amit Shrivastava
Designation: Grievance Officer and person designated to answer questions about processing
Email: [email protected]
Address: 1st Floor, Plot No. 9, Rohit Nagar, Bawadiya Kalan, Gulmohar Colony, Bhopal, Madhya Pradesh 462039
16.2 Complaints are acknowledged within twenty-four (24) hours and disposed of within fifteen (15) days, in accordance with the Grievance Redressal Policy.
16.3 If you are not satisfied with the outcome, you may complain to the Data Protection Board of India. Where the complaint concerns a Subscriber's processing, you should first exhaust the grievance route published by that Subscriber.
17.1 We may update this Policy to reflect changes in law, regulatory guidance, third-party requirements or our own practices.
17.2 Material changes will be notified by email or by prominent notice on the Platform at least thirty (30) days before they take effect, and the revised Policy will be posted with a new effective date. Where a change requires fresh consent, we will seek it.
MOJO Network, c/o Seagull Venture Private Limited
Privacy: [email protected] Grievances: [email protected] Legal: [email protected]
Address: 1st Floor, Plot No. 9, Rohit Nagar, Bawadiya Kalan, Gulmohar Colony, Bhopal, Madhya Pradesh 462039
Website: www.mojonetwork.in