Legal
Privacy Policy
Last updated: January 2025
Effective: January 2025
DPDP Act 2023 · IT Act 2000
1. Data Fiduciary
This Privacy Policy is published by Servyn.AI ("we", "our", "us"), a software product operated from Dadar, Mumbai, Maharashtra — 400014, India, in compliance with the Digital Personal Data Protection Act 2023 ("DPDP Act"), the Information Technology Act 2000, and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021.
For all privacy matters, contact our Grievance Officer as detailed in Section 10.
2. Scope
This policy applies to all personal data collected through the Servyn.AI website (servynai.in), the ERP platform, demo registration, contact forms, and any communication with our team.
3. Data We Collect & Purpose
- Account data — name, business email, phone number, company name, and role. Purpose: account creation, authentication, and service delivery.
- Business operational data — jobs, invoices, client records, employee records, inventory, and any data entered into the ERP. You are the Data Principal; we are the processor.
- Usage data — pages visited, features used, session duration, browser and device type. Purpose: improving platform performance.
- Communication data — emails and messages sent to our support or grievance channels. Purpose: resolving support requests.
- Payment data — billing name and address only. Card numbers and UPI handles are not stored by us. Payments processed by PCI-DSS compliant third-party gateways.
4. Legal Basis for Processing
- Contract — processing necessary to deliver the subscribed service.
- Consent — for marketing communications. Withdraw at any time by emailing grievance@servynai.in.
- Legal obligation — where required by Indian law, court order, or government authority.
- Legitimate interest — for fraud prevention, security, and product improvement.
5. Data Sharing & Sub-Processors
We do not sell your data. We do not share data with advertisers. Sharing occurs only with:
- Amazon Web Services (AWS) — cloud infrastructure, AWS Mumbai (ap-south-1), 100% within India.
- Transactional email providers — for invoice delivery, password reset, and service notifications.
- Payment gateways — billing data only, PCI-DSS compliant.
- Legal and regulatory authorities — only when required by applicable Indian law or a valid court order.
We do not transfer personal data outside India.
6. Data Storage & Security
- All data stored on AWS Mumbai (ap-south-1) — 100% within India.
- Data in transit encrypted via TLS 1.2+. Data at rest encrypted using AES-256.
- Two-Factor Authentication (2FA) available on Business and Enterprise plans.
- Role-based access control limits access to authorised personnel only.
- All user and admin actions recorded in a tamper-evident audit log.
- Daily automated backups. Enterprise includes dedicated database and cloud backup.
7. Data Retention
- Data retained while your account is active.
- On cancellation: data accessible for 90 days for export, then permanently deleted.
- Backup copies may persist up to 30 additional days after primary deletion.
- Support communication records retained for 2 years for dispute resolution.
8. Your Rights (DPDP Act 2023)
- Access — obtain a summary of personal data we hold and how it is processed.
- Correction — correct inaccurate or incomplete personal data.
- Erasure — request deletion, subject to legal retention obligations.
- Withdraw consent — where processing is consent-based, withdraw at any time.
- Nomination — nominate a person to exercise rights on your behalf.
- Grievance redressal — file a complaint with our Grievance Officer. Unresolved complaints may be escalated to the Data Protection Board of India once operational.
To exercise any right, email grievance@servynai.in with subject "Data Rights Request". We acknowledge within 48 hours and resolve within 30 days.
9. Cookies
We use only essential cookies required for authentication and session management. No advertising or third-party tracking cookies. Disabling cookies in your browser will prevent login functionality.
10. Grievance Officer
In compliance with the IT (Intermediary Guidelines) Rules 2021 and DPDP Act 2023, we have designated a Grievance Officer:
Grievance Officer — Servyn.AI
Designation: Grievance Officer
Organisation: Servyn.AI
Email: grievance@servynai.in
General queries: servynai.info@gmail.com
Address: Dadar, Mumbai — 400014, Maharashtra, India
Response time: Acknowledgement within 48 hours · Resolution within 30 days
11. Children's Privacy
Servyn.AI is a B2B software product not directed at individuals under 18. We do not knowingly collect data from minors. Contact grievance@servynai.in immediately if you believe a minor has submitted personal data.
12. Changes to This Policy
We will notify active users by email at least 14 days before material changes take effect. Continued use after the effective date constitutes acceptance.
13. Contact
Privacy questions: grievance@servynai.in · General: servynai.info@gmail.com · Dadar, Mumbai — 400014, Maharashtra, India.