Aphelion Pvt. Ltd.
Jurisdiction Addenda
Effective Date: 3 July 2026
This is the reusable module for country-specific rules. The global-core policies (02–16) state defaults and point here; each addendum below carries the local overrides that apply where RÆDIUS has users in that market. To add a new market as RÆDIUS expands, copy the Blank Addendum Template at the end and fill it in before actively offering the Platform to users located there.
Each addendum uses the same slots so the core policies can reference them consistently:
- A. Operator/representative details (local entity, DPO, EU/UK rep, agents)
- B. Minimum age / children
- C. Legal bases & consent specifics
- D. Data-subject rights & response deadlines
- E. Cross-border transfer mechanism
- F. Breach notification (regulator + individuals + deadline)
- G. Content/intermediary & notice-and-action specifics
- H. Copyright process specifics
- I. Advertising/endorsement disclosure specifics
- J. Consumer-protection / unfair-terms carve-outs
- K. Governing law / venue / dispute resolution overrides
- L. Crisis & child-safety reporting bodies
- M. Regulator(s) & complaint routes
Addendum — India (primary market, active today)
- A. Aphelion Pvt. Ltd., registered office at Hyderabad, Telangana, India; India-resident Grievance Officer Dharantej Reddy Poduvu (
fuy.aphelion@gmail.com), who also acts as the Data Protection Officer / consent-manager contact point. - B. 18+; DPDPA parental-consent rules for children apply if under-18 processing ever occurs.
- C. DPDPA 2023 consent + "legitimate uses"; IT Act 2000; SPDI rules to the extent applicable.
- D. Rights of access/correction/erasure/grievance/nomination per DPDPA and its rules; requests are handled per the timelines in the Grievance Redressal Policy.
- E. Cross-border transfer to our US/global processors is permitted subject to any government restrictions notified under DPDPA s.16.
- F. We report personal-data breaches to the Data Protection Board of India and to affected Data Principals as required under the DPDPA.
- G. IT Rules 2021: published rules/policies, a named Grievance Officer, 24-hour acknowledgement / 15-day resolution, 24-hour NCII takedown, record retention, and law-enforcement cooperation. Users may escalate to the Grievance Appellate Committee route where applicable.
- H. Copyright Act 1957 + Copyright Rules 2013 (36-hour and 21-day timelines) alongside the IT Rules 2021 notice-and-action process.
- I. ASCI code; Consumer Protection Act 2019 and its e-commerce/endorsement rules; "misleading advertisement" and endorser due-diligence duties apply to Creator and Business commercial content.
- J. Consumer Protection Act 2019 unfair-contract-terms and e-commerce rules apply to our consumer-facing terms.
- K. Governing law is India; courts of Hyderabad, Telangana, subject to consumer forum rights available under Indian law.
- L. Cyber Crime Cell / cybercrime.gov.in / 1930; iCall, Vandrevala Foundation, NIMHANS helplines; emergency services 112. We operate under the POCSO Act 2012 posture for child safety.
- M. Data Protection Board of India; consumer commissions; MeitY.
Addendum — United States
- A. Contact
fuy.aphelion@gmail.com. We will register a DMCA agent with the U.S. Copyright Office at the point we begin actively offering the Platform to users located in the United States; until then, U.S. copyright notices are still handled under the general IP & Copyright Policy process. - B. COPPA posture — no under-13 users; on actual knowledge of an under-13 user we remove the account and delete the data; we do not knowingly collect data from children under 13. Certain U.S. states add teen-specific protections we monitor as we grow there.
- C./D. There is no single federal privacy law; we comply with applicable state laws (e.g. California CCPA/CPRA, and comparable laws in states such as Virginia, Colorado, Connecticut, and Utah once applicable thresholds are met): access, deletion, correction, opt-out of sale/sharing and targeted advertising, and honoring the Global Privacy Control signal, with a 45-day response target.
- E. No adequacy-decision concept applies; we rely on contractual protections with our processors.
- F. We follow applicable state breach-notification laws — notifying affected individuals and state Attorneys General per each state's thresholds and timelines.
- G. We operate consistent with the Section 230 intermediary framework, and we treat NCMEC CyberTipline reporting as mandatory for confirmed CSAM once we actively serve U.S. users, per the Notice-and-Action Policy.
- H. DMCA §512 notice-and-takedown, counter-notice, and repeat-infringer termination.
- I. FTC Act §5 and the FTC Endorsement Guides (clear "#ad"/"sponsored" disclosure); state UDAP laws.
- J. State consumer-protection/UDAP laws apply; we do not currently impose mandatory arbitration or a class-action waiver on U.S. users.
- K. For U.S. users, the governing-law and venue provision in the Terms of Service §12 applies without prejudice to any mandatory U.S. state consumer-protection venue rights.
- L. 911; 988 Suicide & Crisis Lifeline; NCMEC.
- M. FTC; state Attorneys General; California Privacy Protection Agency.
Addendum — European Union / EEA (including Germany, France)
- A. We will appoint a GDPR Article 27 EU representative and a Data Protection Officer at the point we begin actively offering the Platform to users located in the EEA; until then, EEA users may direct privacy requests to
fuy.aphelion@gmail.com. - B. GDPR Article 8 digital-consent age applies (13–16 depending on member state; 16 in Germany, 15 in France).
- C. GDPR Article 6 legal bases (not consent-only, per Privacy Policy §6); Article 9 for special-category data such as face-verification images; ePrivacy rules for any future cookies/analytics consent.
- D. Rights of access, rectification, erasure, restriction, objection, and portability, with a one-month response target; automated-decision transparency under Article 22 applies to our interest-based ad selection, and EEA users may object to it via the in-app ad/brand hide controls or by contacting us directly.
- E. Chapter V transfers to our US/global processors rely on Standard Contractual Clauses plus a transfer impact assessment; we track our processors' participation in the EU-US Data Privacy Framework as an additional safeguard where available.
- F. 72-hour breach notification to the lead supervisory authority, and to affected individuals where the breach is high-risk.
- G. Digital Services Act posture: statement of reasons for content actions (Art. 17), internal complaint-handling (Art. 20), out-of-court dispute settlement (Art. 21), trusted flaggers, transparency reporting, and notice-and-action (Art. 16); no dark patterns; ad transparency (Arts. 26/39).
- H. DSM Directive Article 17 and its national transpositions; Article 4 text-and-data-mining opt-out is respected for our Content.
- I. Unfair Commercial Practices Directive and national influencer-marketing rules (in Germany, the Telemedien/UWG framework; in France, the influencer-marketing law) apply to Creator and Business commercial disclosures.
- J. Unfair Contract Terms Directive; consumer withdrawal rights will apply once any paid feature launches; in Germany, standard-terms control (AGB-Kontrolle) applies to our liability cap and other standard clauses, which we apply narrowly for EEA consumers as described in Terms §9.3.
- K. For EEA consumers, mandatory consumer-protection law and venue of their home country prevails over the India-exclusive forum clause to the extent required by that law.
- L. Emergency services 112; national child-safety hotlines (e.g. the INHOPE network); local crisis lines.
- M. The lead supervisory authority under the one-stop-shop mechanism, plus relevant national data-protection authorities; DSA Digital Services Coordinators.
Addendum — United Kingdom
- A. We will appoint a UK GDPR representative and confirm DPO coverage at the point we begin actively offering the Platform to users located in the UK; until then, UK users may direct privacy requests to
fuy.aphelion@gmail.com. - C./D. UK GDPR and the Data Protection Act 2018 apply; we will follow the ICO's Age Appropriate Design Code if the Platform becomes accessible to under-18s in the UK, and the Online Safety Act 2023 duties that correspond to the EU DSA posture above.
- E. Transfers rely on the UK International Data Transfer Addendum.
- F. 72-hour breach notification to the ICO.
- I. CAP Code / ASA rules and CMA influencer guidance apply to commercial disclosures.
- K./M. UK governing-law considerations apply alongside Terms §12; the ICO, ASA, and Ofcom (for Online Safety Act matters) are the relevant regulators.
Addendum — Japan
- A. Contact
fuy.aphelion@gmail.comfor APPI-related requests. - C./D. APPI applies: we specify the utilisation purpose for personal data, obtain consent for sensitive ("special-care-required") data including face/biometric verification data, and honour individual rights of disclosure, correction, and suspension of use.
- E. Cross-border transfer to our processors relies on APPI-compliant consent or equivalent safeguards, with information provided to the individual about the transfer.
- F. We report qualifying data leaks to the Personal Information Protection Commission (PPC) and to affected individuals per APPI thresholds.
- I. The Act against Unjustifiable Premiums and Misleading Representations applies, including its stealth-marketing disclosure rules (effective 2023), to Creator and Business commercial content.
- M. The PPC and the Consumer Affairs Agency are the relevant regulators.
Addendum — Other Asian and expansion markets
Where RÆDIUS becomes available in additional markets (for example Singapore, Indonesia, South Korea, the Philippines, Malaysia, or Gulf states), the operative local rules — data-localisation, consent, advertising, and platform/content requirements — will be documented using the Blank Addendum Template below before the Platform is actively offered there, referencing that market's data-protection law (e.g. Singapore PDPA, Indonesia's PDP Law, South Korea's PIPA, the Philippines Data Privacy Act, Malaysia's PDPA) and consumer/advertising regulator.
Blank Addendum Template (copy for each new market)
## Addendum — [Country]
- A. Operator / local entity / representative / agents:
- B. Minimum age / children:
- C. Legal bases & consent specifics:
- D. Data-subject rights & response deadline:
- E. Cross-border transfer mechanism:
- F. Breach notification (regulator + individuals + deadline):
- G. Content / intermediary / notice-and-action specifics:
- H. Copyright process specifics:
- I. Advertising / endorsement disclosure specifics:
- J. Consumer-protection / unfair-terms carve-outs:
- K. Governing law / venue / dispute resolution overrides:
- L. Crisis & child-safety reporting bodies:
- M. Regulator(s) & complaint routes:Jurisdiction Matrix
Which parts of the policy set apply everywhere (Global core) and which need a country addendum. "Addendum" = the core states a default but the local rule in document 17 governs. IN=India, US=United States, EU=EU/EEA (incl. DE/FR), UK=United Kingdom, JP=Japan, Other=other Asian/expansion markets.
| Policy area | Global core? | IN | US | EU | UK | JP | Other |
|---|---|---|---|---|---|---|---|
| Terms structure, roles, licence, moderation rights | ✅ | — | — | — | — | — | — |
| Minimum age / children | default 18+ | DPDPA child rules | COPPA <13 | Art. 8 (13–16) | AADC | APPI minors | Addendum |
| Legal bases for processing | framework | DPDPA legit-uses | state laws | Art. 6/9 | UK GDPR | APPI purpose | Addendum |
| Consent (location, face, ads, sensitive) | explicit-consent default | ✅ | opt-out model | ✅ + ePrivacy | ✅ | ✅ sensitive | Addendum |
| Data-subject rights & deadlines | list of rights | per rules | 45 days | 1 month | 1 month | without delay | Addendum |
| Cross-border transfers | disclosed | s.16 | contractual | SCCs+TIA | IDTA | consent/equiv | Addendum |
| Breach notification | commit to notify | DPB India | state AGs | 72h SA | ICO 72h | PPC | Addendum |
| Content/community standards | ✅ | — | — | — | — | — | — |
| Notice-and-action / appeals | baseline + appeal | IT Rules 2021 | §230 posture | DSA 16/17/20/21 | OSA 2023 | local | Addendum |
| CSAM reporting body | commit to report | Cyber Crime | NCMEC (mandatory) | INHOPE/local | local | local | Addendum |
| Copyright notice process | notice + counter | 36h/21d + IT Rules | DMCA + agent | DSM Art.17 | local | local | Addendum |
| Advertising/endorsement disclosure | must disclose | ASCI/CPA | FTC Guides | UCPD/national | CAP/ASA | stealth-mktg | Addendum |
| Verification / face verification | ✅ minimised, opt-in | — | BIPA-type | Art. 9 + DPIA | UK GDPR | APPI sensitive | Addendum |
| Retention schedules | ✅ by category | storage-limit | state law | Art. 5/17 | UK GDPR | APPI | Addendum |
| Liability cap / unfair terms | default cap | CPA 2019 | UDAP/arb. | UCTD/AGB | UCT | consumer | Addendum |
| Governing law / venue | India default | India | US venue/arb? | consumer home | UK | JP | Addendum |
| Cookies / trackers (site) | app minimal | — | GPC/opt-out | ePrivacy banner | PECR | — | Addendum |
| Crisis/helpline resources | listed | India lines | 988/911 | 112/local | local | local | Addendum |
| Grievance officer / representatives | ✅ | GO required | agent | Art. 27 rep | UK rep | contact | Addendum |
Reading the matrix: ✅ = the global-core text is sufficient (still confirm with counsel). A named regime/deadline = the core defers to that jurisdiction's addendum. Cells marked in bold are the highest-priority local items before launching in that market.
© 2026 Aphelion Pvt. Ltd. All rights reserved.