Privacy Policy
TrinetraEdu-AI (trinetraedu-ai.com) • Effective Date: 15-07-2026 • Last Updated: 14-07-2026
A note before you read this: We have written this policy to be read by an actual person, not just filed away. If you have a question that this document does not answer, our Grievance Officer contact is in Section 16 and we will respond within 72 hours.
Table of Contents
1. Introduction and Scope
1.1 — Who We Are
TrinetraEdu-AI (“Platform,” “we,” “us,” or “our”) is a zero-code artificial intelligence platform for Indian MSMEs, startups, and businesses. The Platform is currently operated as a proprietary concern by its founding team and is in the process of registering as a Limited Liability Partnership (LLP) under the Limited Liability Partnership Act, 2008. This Policy will be updated with the registered entity's legal name, registration number, and address upon completion of incorporation. Until that time, references to “TrinetraEdu-AI” refer to the entity operating the Platform as a proprietary concern.
The Platform is accessible at trinetraedu-ai.com and all associated subdomains, including but not limited to msme.trinetraedu-ai.com, and any additional tools or subdomains launched under the TrinetraEdu-AI brand in the future (collectively, the “Platform”).
1.2 — What This Policy Covers
This Privacy Policy (“Policy”) describes:
- What personal data we collect from you and why
- How we process that data and on what legal basis
- Who we share it with and under what conditions
- Exactly how long we keep it before deleting it
- The security measures we have implemented to protect it
- Your rights under Indian data protection law and how to exercise them
- How to contact us if something goes wrong
This Policy applies uniformly across all tools, subdomains, features, and services offered under the TrinetraEdu-AI Platform, regardless of whether you access them through the main domain or any subdomain. If a specific tool operates under terms that differ materially from this Policy, those differences will be disclosed to you at the point of access to that tool.
1.3 — Applicable Law
This Policy is designed to comply with:
- Digital Personal Data Protection Act, 2023 (“DPDP Act”) — primary governing statute for personal data processing in India
- Information Technology Act, 2000 (“IT Act”) — including Section 70B (CERT-In reporting obligations) and Section 43A (reasonable security practices)
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) — governing sensitive personal data
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — applicable to our community forum and blog
- CERT-In Directions dated April 28, 2022 — governing cybersecurity incident reporting timelines
As the Platform expands globally, this Policy will be updated to address the requirements of applicable international frameworks, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Singapore Personal Data Protection Act (PDPA), and the UAE Personal Data Protection Law (PDPL), for users in those jurisdictions. When such expansion occurs, jurisdiction-specific addenda will be published alongside this Policy.
1.4 — Your Agreement
By registering for an account, accessing any feature of the Platform, or clicking “I Agree” on any consent interface, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, you should not access or use the Platform.
If you are accessing the Platform on behalf of a business entity (which is our primary use case), you represent that you have authority to bind that entity to this Policy and that the entity accepts this Policy on behalf of all individuals whose data you may submit to the Platform through your account.
2. Definitions
The following definitions apply throughout this Policy. Where terms appear in the DPDP Act 2023, we use them in the same sense as defined in that Act.
“Data Principal” means the natural person to whom the personal data relates. In this Policy, we also refer to the Data Principal as “you,” “your,” or “User.”
“Data Fiduciary” means the entity that determines the purpose and means of processing personal data. TrinetraEdu-AI is the Data Fiduciary in respect of all personal data collected through the Platform, as defined under Section 2(i) of the DPDP Act.
“Data Processor” means any entity that processes personal data on behalf of the Data Fiduciary, under a contract and solely on the instructions of the Data Fiduciary, as defined under Section 2(k) of the DPDP Act. Our third-party service providers listed in Section 6 are Data Processors.
“Personal Data” means any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDP Act.
“Sensitive Personal Data or Information” or “SPDI” has the meaning assigned to it under Rule 3 of the SPDI Rules, 2011, and includes financial information (bank account details, credit/debit card details, payment instrument details), passwords, biometric information, and health information. Where we collect SPDI, we apply heightened security controls as described in Section 9.
“Processing” means any operation or set of operations performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, transmission, or erasure.
“Consent” means the free, specific, informed, unconditional, and unambiguous indication of agreement by a Data Principal to the processing of their personal data for a specified purpose, as defined under Section 6 of the DPDP Act. Consent on our Platform is recorded in the manner described in Section 9.4.
“Consent Manager” has the meaning assigned under Section 2(g) of the DPDP Act, referring to a registered entity through which a Data Principal may give, manage, review, and withdraw consent.
“Breach” or “Personal Data Breach” means any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises the confidentiality, integrity, or availability of such data.
“Nominated Person” means an individual nominated by a Data Principal under Section 14 of the DPDP Act to exercise the rights of the Data Principal in the event of the Data Principal's death or incapacity.
“Platform” means the TrinetraEdu-AI website, all subdomain tools, mobile applications (if any), APIs, and any other services offered under the TrinetraEdu-AI brand.
“CERT-In” means the Indian Computer Emergency Response Team, constituted under Section 70B of the IT Act.
“Data Protection Board” means the Data Protection Board of India, to be constituted under Section 18 of the DPDP Act.
3. What Data We Collect
We collect only the personal data that is necessary to provide the specific service you are using. We do not collect data speculatively or in excess of what is required for the stated purpose. Below is a complete account of every category of personal data we collect, organized by the service or context in which it is collected.
3.1 — Account and Registration Data
When you create an account on the Platform, we collect:
| Data Item | How It Is Collected | Notes |
|---|---|---|
| Full name | Registration form | Used for account identification and communication |
| Email address | Registration form | Used for login, communication, and service notifications |
| Mobile phone number | Registration form | Used for account security and service-related communication |
| Company name | Registration form | Used to personalize your experience and for MSME Navigator services |
| Password | Registration form | Stored exclusively in hashed form using bcrypt. We cannot read, recover, or share your password. We have no access to your plaintext password at any time. |
We do not collect your date of birth, gender, home address, or national identity number during registration, unless you voluntarily provide such information through a support communication or a specific service feature that requires it.
3.2 — Voice Agent Data
When you use the Platform's voice agent tools, we collect:
| Data Item | Retention | Auto-Deleted? |
|---|---|---|
| Call recordings (audio files) | 10 days from date of recording | Yes — permanently deleted |
| Call transcripts (text) | 10 days from date of call | Yes — permanently deleted |
| Call analytics (duration, sentiment scores, outcome tags) | 90 days, then anonymized | Yes — identifying elements removed after 90 days |
Important: Call recordings and transcripts are retained for 10 days to allow you to review, download, or use them within your account. After 10 days, they are permanently and irretrievably deleted from our systems and from the systems of our voice infrastructure processors. This deletion is automated and irreversible.
Voice recordings may capture the voices of third parties who participate in calls made using your voice agent. If you deploy a voice agent that interacts with your customers, you are responsible for ensuring that those third parties are informed that their voice may be recorded and for obtaining any consents required under applicable law before initiating or enabling such calls. The Platform provides you with the ability to include consent disclosures at the start of calls; it is your responsibility to activate and configure these features appropriately.
3.3 — Document Structuring Tool Data
When you use the Document Structuring Tool:
| Data Item | Retention | Auto-Deleted? |
|---|---|---|
| Uploaded documents (raw files) | 7 days from upload date; maximum of 3 most recent documents retained at any time | Yes — older documents and all documents after 7 days are permanently deleted |
| Extracted data (structured output from document processing) | 30 days from the date of extraction | Yes — permanently deleted after 30 days |
Documents you upload may contain personal data about third parties (your customers, employees, or business partners). You are responsible for ensuring you have the authority or consent to upload such documents to the Platform. We process the content of your documents solely to provide the document structuring service you have requested. We do not read, review, or retain the content of your documents beyond what is technically necessary for processing and the retention periods stated above.
3.4 — MSME Navigator Data
When you use the MSME Scheme Navigator:
| Data Item | Retention | Auto-Deleted? |
|---|---|---|
| Business profile data (sector, annual turnover, company type, registration status, and similar MSME profile attributes) | Retained while your account is active; deleted when you delete your account or your account is closed for inactivity | As applicable |
| Scheme match results (which schemes your business profile matched, and the basis for the match) | 90 days from the date of the match | Yes — permanently deleted after 90 days |
| Consent records (your record of consent to process business profile data for scheme matching) | Permanently retained | Never deleted — this is a legal compliance requirement under the DPDP Act |
Why we retain consent records permanently: Section 6 of the DPDP Act and the compliance requirements applicable to Data Fiduciaries require us to be able to demonstrate that we had valid consent for each processing activity. Consent records are not personal data in the operational sense — they are legal compliance records that establish the fact, timing, and scope of your consent. We retain these records in our immutable audit log. Retention of consent records does not mean your business profile data or scheme results are retained — those are deleted on the schedule above.
3.5 — Payment Data
When you upgrade to a paid tier, your payment is processed by a third-party, PCI-DSS compliant payment gateway:
- Indian users: Razorpay
- International users (upon launch): Stripe
We do not receive, store, or have access to your raw card number, CVV, UPI PIN, bank account number, or any other raw payment credential.These are entered directly into and processed by Razorpay or Stripe's secure payment interface. We receive a transaction confirmation and a payment reference ID from the gateway, which we retain for billing record purposes.
Payment records (transaction references, amounts, dates, and subscription status) are retained for 8 years from the date of the transaction, as required under the Income Tax Act, 1961 and applicable Indian financial record-keeping obligations.
3.6 — Cookie Data
We use only essential authentication cookies. We do not use advertising cookies, third-party tracking cookies, or traditional analytics cookies that track individual behavior. The full details of our cookie practices are in Section 13.
3.7 — Community Forum and Blog Data
| Data Item | Retention | Notes |
|---|---|---|
| Post content and comments | Until you delete them or your account is closed | Visible to other Platform users |
| Display name associated with posts | As above | You may use a display name different from your registered name |
| Timestamp of each post | As above | Shown alongside your posts |
We do not collect any personal data beyond what you voluntarily submit in a post or comment. Be aware that information you share publicly in the forum is visible to other users and should not include sensitive personal or financial information.
3.8 — Technical and Security Logs
For security, fraud prevention, and compliance purposes, we maintain:
| Log Type | Retention | Purpose |
|---|---|---|
| Security event logs (failed login attempts, suspicious activity flags, consent action logs including IP address and user-agent at time of consent) | 180 days | Fraud detection, breach investigation, legal compliance |
| Processing activity logs (records of which processing activities were performed on which data, without the data itself) | Permanent | DPDP Act compliance record-keeping |
Security logs are not used for any marketing, profiling, or commercial purpose. They are accessed only by the founding team for security and compliance purposes.
3.9 — Data We Do Not Collect
For transparency, we explicitly confirm that we do not collect the following:
- Aadhaar numbers (unless voluntarily submitted in a document you upload, in which case we process but do not store them beyond the document retention period)
- Biometric data
- Religion, caste, political opinion, or trade union membership
- Health or medical data
- GPS location data
- Data from social media accounts or third-party login providers (we do not offer social login)
- Any data from users under 18 (see Section 14)
4. How We Use Your Data
We operate under a strict purpose limitation principle: we process your personal data only for the specific purpose for which it was collected. We do not repurpose your data for secondary uses without obtaining fresh consent from you.
4.1 — Purposes of Processing
| Data Category | Specific Purposes |
|---|---|
| Account data (name, email, phone, company name) | Creating and maintaining your account; verifying your identity when you contact support; sending you service notifications (e.g., retention warnings, policy updates, feature changes); enabling login and authentication |
| Voice agent data (recordings, transcripts, analytics) | Delivering the voice agent service you have configured; generating transcripts for your review within the retention window; producing call outcome analytics for your account dashboard; investigating service errors or bugs you report |
| Document data (uploaded files, extracted data) | Performing the AI-based document structuring or extraction you have requested; displaying results in your account dashboard; retaining outputs for your access within the retention window |
| MSME Navigator data (business profile, match results) | Matching your business profile against available government schemes; displaying relevant scheme information and eligibility indicators; improving the accuracy of matching results for your profile over time |
| Payment data (transaction references) | Confirming payment and activating your subscription; maintaining billing records as required by Indian financial law; issuing receipts and invoices |
| Cookie data | Maintaining your authenticated session across the Platform and its subdomains; preventing repeated login prompts across Platform tools |
| Community data (forum posts, blog comments) | Displaying your contributions in the community forum and blog for other users to read and engage with |
| Security logs | Detecting and preventing unauthorized access, fraud, and abuse; investigating security incidents; demonstrating compliance with CERT-In and DPDP Act requirements |
4.2 — What We Explicitly Do Not Do With Your Data
We make the following commitments clearly and without qualification:
- We do not sell your personal data. We have never sold personal data, and we will never sell personal data to any third party, under any circumstances.
- We do not use your data to train AI models. Your voice recordings, documents, business profiles, call transcripts, and any other content you submit are not used to train, fine-tune, or improve any artificial intelligence or machine learning model — whether operated by us or by any third-party processor. When we send your data to AI processing providers (listed in Section 6), it is transmitted solely to obtain a single response and is not retained by those providers for model training under our data processing agreements with them. You should review those providers' own terms if you have concerns about their independent data practices.
- We do not perform automated decision-making with legal or significant effects. The MSME Navigator uses AI to suggest matching schemes, but these are suggestions for your review — no automated system makes any final determination about your eligibility for any government scheme or benefit. All outputs require your assessment and independent verification.
- We do not profile you for marketing or advertising purposes.
- We do not share your data with any party not listed in Section 6, except where we are required to do so by law.
- We distinguish between processing and training. When you use our AI tools, your data is transmitted to AI processors solely to generate responses for you in real-time (“inference processing”). This is not model training. We do not use your data to fine-tune, retrain, or permanently modify any AI model's behavior for other users. However, we do store certain outputs and interaction history within your account to personalize your experience — for example, remembering your learning progress, weak areas, or preferences. This data is stored in your account profile and is never used to train models that serve other users.
5. Legal Basis for Processing
Every processing activity we conduct must have a valid legal basis. Under the DPDP Act 2023 and the SPDI Rules, our legal bases are as follows:
5.1 — Consent (Section 6, DPDP Act 2023)
The primary legal basis for most of our processing activities is your free, specific, informed, unconditional, and unambiguous consent, obtained before we begin processing. We obtain consent:
- At registration, for processing your account data
- At the point of first use of each tool, for processing tool-specific data (e.g., voice agent data, document data, MSME Navigator data)
- Through a clear consent interface that describes, in plain language, exactly what data will be processed and why, before asking for your agreement
Each consent record is cryptographically signed using SHA-256 and stored in an immutable log that records your consent text, the timestamp of consent, your IP address, and the user-agent string of your browser. This record is retained permanently and cannot be altered after the fact.
You may withdraw any consent at any time as described in Section 12. Withdrawal of consent does not affect the lawfulness of processing that occurred before the withdrawal.
5.2 — Performance of a Contract (Section 7, DPDP Act 2023 / General Contract Law)
Some processing is necessary to perform the contract between you and TrinetraEdu-AI — specifically, to provide the services you have subscribed to. This includes maintaining your account, processing payments, and delivering service notifications. You cannot opt out of this processing while remaining a user of the Platform; however, you may close your account at any time.
5.3 — Legal Obligation
We process certain data because we are required to do so by law. This includes:
- Retaining consent records permanently (as a compliance record under the DPDP Act)
- Retaining payment records for 8 years (as required under Indian financial and tax law)
- Retaining security logs for 180 days (as required under CERT-In Directions, 2022)
- Retaining processing activity logs permanently (as a Data Fiduciary accountability record under the DPDP Act)
- Providing personal data to government authorities, courts, or law enforcement where required by a valid legal order
5.4 — Legitimate Uses (Section 7, DPDP Act 2023)
For specific, limited purposes, we rely on the legitimate uses provision of the DPDP Act, including:
- Operating security monitoring systems (rate limiting, failed login tracking, suspicious activity detection) to protect the integrity of the Platform and the safety of user accounts
- Investigating and responding to security incidents
- Fraud detection and prevention
We do not rely on this basis for any marketing, profiling, or commercial data processing activity.
6. Data Sharing and Third-Party Processors
6.1 — Our Approach to Data Sharing
We share your personal data with third parties only where it is necessary to provide the services you have requested. Every third party to whom we transmit personal data acts as a Data Processor under a written agreement that:
- Prohibits them from processing your data for any purpose other than what we have specified
- Requires them to implement appropriate technical and organisational security measures
- Requires them to delete your data upon termination of the agreement or our instruction
- Prohibits them from disclosing your data to sub-processors without our authorisation
- Requires them to assist us in meeting our obligations under applicable data protection law
We do not sell personal data. We do not share personal data for advertising purposes. We do not disclose personal data to any party not listed below, except where required by law.
6.2 — Complete List of Third-Party Data Processors
| Processor | Country of Operation | Purpose | Categories of Data Shared | Their Privacy Policy |
|---|---|---|---|---|
| Supabase, Inc. | Database hosted in Mumbai, India (AWS ap-south-1) | Primary database and file storage for all Platform data; authentication services | All categories of personal data collected through the Platform, as applicable to your account and the features you use | supabase.com/privacy |
| Vercel, Inc. | United States (Washington D.C. edge network) | Frontend hosting and delivery of the Platform's web interface | Technical request data (IP addresses, request headers) processed in serving the Platform interface; your personal data is not stored on Vercel's servers — it is stored in Supabase | vercel.com/legal/privacy-policy |
| Vapi AI | United States | Voice AI infrastructure — processing audio and generating call transcripts for the voice agent tools | Call audio recordings; call metadata | vapi.ai/privacy |
| Twilio, Inc. | United States | Telephony services — routing and connecting phone calls for paid voice agent features | Call routing data; phone numbers involved in calls | twilio.com/en-us/legal/privacy |
| Google LLC (Gemini API) | United States | Large language model (LLM) processing — generating AI responses for document structuring, scheme matching, and other AI features | The content of documents or queries you submit for AI processing — transmitted to obtain a response and not retained for model training under our agreement | policies.google.com/privacy |
| Mistral AI | France (EU) | Fallback LLM provider — used when Google Gemini is unavailable or when a specific processing task is better suited to Mistral's models | Document or query content, as above — transmitted solely to obtain a response | mistral.ai/privacy |
| Razorpay Software Pvt. Ltd. | India | Payment processing for Indian users (upon activation of paid tier) | Billing and transaction data — Razorpay independently collects and processes your payment credentials under their own privacy policy; we do not receive raw card or payment credential data | razorpay.com/privacy |
| Stripe, Inc. | United States | Payment processing for international users (upon activation of paid tier for international users) | Billing and transaction data — as above, Stripe processes payment credentials independently | stripe.com/in/privacy |
Note on AI processors:When your data is transmitted to Google Gemini or Mistral AI for processing, it is sent solely to generate a single response to your request. Our data processing agreements with these providers (or their applicable API terms of service) prohibit them from using your data to train or improve their models. However, you should independently review these providers' terms of service and privacy policies to satisfy yourself about their independent data practices. If you have concerns about a specific provider, contact our Grievance Officer and we will provide you with details of the applicable contractual restriction.
6.3 — Disclosures Required by Law
We may disclose personal data to courts, law enforcement agencies, government authorities, or regulatory bodies where we are required to do so by a valid and binding legal order issued under applicable Indian law. Where we receive such an order:
- We will review the order for legal validity before complying
- We will notify you of the order to the extent we are legally permitted to do so
- We will disclose only the minimum personal data required to satisfy the legal obligation
- We will document the disclosure in our processing activity log
We will not voluntarily share your personal data with law enforcement without a legal order unless we believe, in good faith, that such disclosure is necessary to prevent imminent serious harm to a person.
7. Data Retention Periods
We retain personal data for the minimum period necessary to fulfil the purpose for which it was collected, or as required by law. The following table sets out our complete, exact data retention schedule. “Auto-Delete” means the deletion is performed automatically by our systems on a scheduled basis without manual intervention.
| Data Type | Retention Period | Auto-Delete? | Basis for Retention Period |
|---|---|---|---|
| Voice call recordings (audio) | 10 days from date of recording | ✅ Yes | Minimum necessary for you to access and use your recordings; permanent deletion thereafter |
| Voice call transcripts (text) | 10 days from date of call | ✅ Yes | As above |
| Call analytics (identifying elements) | Identifying elements deleted at 90 days; anonymized aggregate data retained indefinitely | ✅ Yes (identifying elements) | 90-day window allows meaningful account-level analytics; anonymized data does not constitute personal data |
| Uploaded documents (raw files) | 7 days from upload date; maximum 3 most recent documents retained at any time regardless of date | ✅ Yes | Minimum necessary for processing and review; automatic rolling deletion of older files |
| Extracted document data (structured outputs) | 30 days from extraction date | ✅ Yes | Allows you sufficient time to retrieve and use outputs |
| MSME Navigator business profile | Retained while your account is active | ❌ No (manual — deleted on account closure or inactivity process) | Necessary for ongoing scheme matching services |
| Scheme match results | 90 days from date of match | ✅ Yes | Sufficient window for you to review and act on results |
| Account profile data (active accounts) | Until you request deletion or your account is closed | ❌ No | Necessary for service delivery |
| Account profile data (inactive accounts — no login for 12 consecutive months) | 30 days after written warning is sent, then permanently deleted | ✅ Yes | Balanced against your right not to have stale data retained indefinitely |
| Consent records | Permanently | ❌ Never deleted | Mandatory legal compliance record under DPDP Act 2023; establishes the fact and scope of consent for each processing activity |
| Processing activity logs | Permanently | ❌ Never deleted | Data Fiduciary accountability record under DPDP Act 2023 |
| Payment records (transaction references, amounts, dates) | 8 years from transaction date | ❌ No | Required under Income Tax Act, 1961 and Indian financial record-keeping law |
| Security logs (failed logins, security events, IP/user-agent on consent actions) | 180 days | ✅ Yes | Required under CERT-In Directions dated April 28, 2022 |
| Community forum posts and blog comments | Until you delete them or your account is closed | ❌ No | Visibility is at your discretion; you may delete your own posts at any time |
| Support and grievance records (support emails, complaint records, resolution documentation, data rights requests, and related correspondence) | Retained for the duration of your account plus 3 years from the date of resolution or account closure, whichever is later | ❌ No | Required for legal defense, regulatory compliance, and to demonstrate compliance with DPDP Act grievance response obligations |
7.1 — Inactive Account Procedure
If your account shows no login activity for 12 consecutive months, we will:
- Send you an email notification to your registered email address, warning that your account and associated data will be deleted in 30 days unless you log in
- Send a reminder at 15 days and 7 days before the deletion date
- Permanently delete your account and all associated non-exempt data on the 30th day, if no login is recorded
Payment records, consent records, and processing activity logs are not deleted as part of the inactive account process, as these are subject to independent legal retention requirements.
7.2 — What “Permanent Deletion” Means
When we say data is permanently deleted, we mean:
- The data is removed from our primary database (Supabase)
- The data is removed from any backup systems within the next scheduled backup cycle (maximum 7 days from scheduled deletion)
- Deletion instructions are propagated to all relevant Data Processors (Vapi, etc.) as part of our processor agreements
- The data cannot be recovered, restored, or accessed by us or any processor after deletion is confirmed
We do not maintain shadow copies, undisclosed backups, or any other secondary store of deleted data.
8. Data Storage Location and International Transfers
8.1 — Primary Data Storage
All personal data collected through the Platform is stored on database servers located in Mumbai, India, operated by Supabase, Inc. on Amazon Web Services infrastructure in the ap-south-1 (Asia Pacific — Mumbai) region. This means that your personal data, at rest, is stored within Indian territory.
8.2 — Data Transmission to AI Processors Outside India
When you use AI-powered features on the Platform (document structuring, scheme matching, voice agent AI responses), your query content or document content is transmitted to AI processing providers — specifically Google LLC (United States) and Mistral AI (France) — for the sole purpose of generating a response. This constitutes a cross-border transfer of data.
Current status:We acknowledge that the specific rules governing cross-border personal data transfers under the DPDP Act 2023 are subject to the Central Government's notification of permitted countries and additional conditions under Section 16 of the DPDP Act, which has not yet been fully operationalized at the time this Policy was drafted. We are monitoring regulatory developments and will update this Policy to reflect any new requirements as they come into effect.
Safeguards currently in place for AI processing transfers:
- Data transmitted to AI processors is limited to the minimum content necessary to generate a response (we do not transmit your account profile or identifying account data alongside document content where this can be avoided)
- AI processors are bound by contractual terms or API terms of service that prohibit use of your data for independent model training
- Processed responses are returned to our systems in India (Supabase) and the transmitted content is not retained by the AI processor beyond the immediate request-response cycle, to the extent provided by their applicable terms
8.3 — Vercel Frontend Hosting
The Platform's web interface is served through Vercel's global edge network, with infrastructure including servers in Washington D.C. and other locations. Your personal data (account data, voice recordings, documents, etc.) is not stored on Vercel's servers — it is stored in Supabase (Mumbai). Vercel processes technical request data (IP addresses and request headers) in the course of serving the Platform's web interface.
8.4 — Future International Expansion
When the Platform begins actively serving users outside India, this Policy will be updated to:
- Identify the additional jurisdictions and applicable data protection laws
- Describe the cross-border transfer mechanisms in place (such as Standard Contractual Clauses for EU users or equivalent safeguards for other jurisdictions)
- Appoint local representatives or Data Protection Officers where required by applicable law
- Update the list of processors if new processors are engaged for international operations
We will provide 30 days' prior notice of any material changes to our data transfer practices.
9. Security Measures
We have implemented the following specific technical and organisational security measures to protect your personal data. We describe each measure in specific technical terms so you can assess its adequacy.
9.1 — Encryption
In Transit: All data transmitted between your browser and the Platform, and between the Platform and our processors, is encrypted using TLS 1.3 (Transport Layer Security version 1.3). We do not support TLS 1.0 or TLS 1.1, which are deprecated protocols. HTTP Strict Transport Security (HSTS) is enabled, meaning your browser will refuse to connect to the Platform over an unencrypted connection.
At Rest: All data stored in Supabase is encrypted at rest using AES-256 (Advanced Encryption Standard with a 256-bit key), implemented at the database storage layer.
Sensitive Fields: For particularly sensitive structured data fields — including PAN numbers, GSTIN, and bank account details where these appear in structured data you provide — we apply an additional layer of AES-256-GCM encryption at the application level before writing to the database, using the pgcrypto extension. This means these fields are encrypted twice: once at the application level and once at the storage layer.
9.2 — Database Access Controls
Row-Level Security (RLS): We have enabled Row-Level Security on all database tables that contain user data. RLS is a PostgreSQL feature that enforces, at the database engine level, that each query can only return rows belonging to the authenticated user making the request. This means that even if an application-layer bug caused an incorrect query to be executed, the database itself would block unauthorized row access.
Parameterized Queries: All database queries executed by the Platform use parameterized queries (also called prepared statements). We do not construct SQL queries by concatenating user-supplied input. This eliminates SQL injection as an attack vector.
Access Limitation: Direct database access is restricted to the two founding team members only, both of whom have multi-factor authentication (MFA) enabled on their database access credentials.
9.3 — Authentication and Session Security
- Passwords are hashed using bcrypt with an appropriate work factor. Plaintext passwords are never stored, logged, or transmitted to our servers after initial hashing.
- Authentication sessions are managed using Supabase JWT (JSON Web Tokens) with automatic refresh token rotation — each time a session token is refreshed, the old refresh token is invalidated.
- Sessions automatically expire after 30 minutes of inactivity, requiring re-authentication.
- Failed login attempts are logged and flagged for security review.
9.4 — Consent Record Integrity
Consent records are protected against tampering as follows:
- Each consent record is cryptographically signed using SHA-256 hashing, producing a unique fingerprint of the consent at the time it was given
- Consent records are stored in an immutable append-only log — they are never updated or deleted after creation
- Every consent action logs your IP address and browser user-agent string at the time of consent, creating a verifiable record of the device and network from which consent was given
- Any attempt to alter a consent record would produce a SHA-256 hash mismatch, making tampering detectable
9.5 — Network and Application Security
- DDoS Protection: The Platform's web interface is protected against distributed denial-of-service attacks through Vercel's infrastructure-level protection.
- Rate Limiting: All API endpoints implement rate limiting to prevent brute-force attacks, credential stuffing, and abuse. Requests exceeding defined thresholds are automatically blocked.
- CORS Configuration: Cross-Origin Resource Sharing (CORS) is configured to allow requests only from authorised Platform domains.
- Security Headers: The Platform implements the following HTTP security headers:
Content-Security-Policy (CSP)— restricts which resources the browser may loadX-Frame-Options: DENY— prevents the Platform from being embedded in iframes (clickjacking protection)X-Content-Type-Options: nosniff— prevents MIME-type sniffingStrict-Transport-Security (HSTS)— enforces HTTPS connections
9.6 — Monitoring and Alerting
- Security events (failed logins, unusual query volumes, consent actions, access to restricted resources) are logged to an immutable security event log retained for 180 days
- Suspicious activity patterns (such as large volumes of database reads within a short time window) are flagged for review
- Rate limiting violations are logged and reviewed
9.7 — Security Review Program
- Quarterly security reviews of infrastructure configuration, RLS policies, credential status, and dependency vulnerability status
- Annual penetration testing by an external security professional, targeting OWASP Top 10 vulnerability categories (upon reaching 100+ active users or within 12 months of paid tier launch, whichever is earlier)
- Continuous dependency scanning using
npm auditand equivalent tools, with critical and high-severity vulnerabilities patched on a priority basis - Breach response plan: We maintain a documented internal breach response plan specifying exact procedures, timelines, and responsibilities for detecting, containing, investigating, and notifying breaches. This plan is tested quarterly through tabletop exercises.
9.8 — Important Limitation
While we have implemented the measures described above, no security system is impenetrable, and no method of data transmission or storage is 100% secure. We cannot guarantee that your personal data will never be accessed, disclosed, or altered by an unauthorized third party. We commit to notifying you promptly and taking all reasonable remedial steps if a breach occurs, as described in Section 10.
10. Breach Notification Policy
10.1 — Our Commitment
We maintain a documented internal breach response plan. In the event of a personal data breach that is likely to result in harm to you, we commit to notifying you within 72 hours of our becoming aware of the breach.
This commitment is not conditional on completing a full investigation. If we are aware of a potential breach affecting your data, we will notify you with the information available at the time, and provide updates as our investigation progresses.
10.2 — What We Will Tell You
Our breach notification to you will include, to the extent the information is known at the time:
- A description of what happened (in plain language, without technical jargon that obscures the facts)
- The categories and approximate volume of personal data affected
- The period during which your data was exposed
- The steps we have taken or are taking to contain and remedy the breach
- The specific steps, if any, we recommend you take to protect yourself (such as changing your password or monitoring for phishing contact)
- The contact details of our Grievance Officer for further questions
10.3 — Regulatory Notifications
In parallel with user notification:
- We will notify the Indian Computer Emergency Response Team (CERT-In) at incident@cert-in.org.in within 6 hours of discovering a breach, as required under Section 70B of the IT Act and the CERT-In Directions dated April 28, 2022
- We will notify the Data Protection Board of India within 72 hours of discovering a breach, as required under the DPDP Act 2023, through the official reporting mechanism established by the Board
10.4 — Evidence Preservation
In the event of a breach, we will preserve all relevant logs, system state records, and forensic evidence for a minimum of 180 days from the date of discovery, in compliance with CERT-In requirements, and will make this evidence available to authorized regulatory authorities upon request.
11. Your Rights Under the DPDP Act 2023
As a Data Principal under the DPDP Act 2023, you have the following rights in respect of your personal data processed by TrinetraEdu-AI. These rights are available to you free of charge, subject to the conditions and exceptions described below.
11.1 — Right to Access Information (Section 11, DPDP Act 2023)
You have the right to obtain from us:
- Confirmation of whether we are processing your personal data
- A summary of the personal data we hold about you
- A description of the processing activities we are performing on your data, and the purposes for which each activity is conducted
- The identities of any Data Processors (third parties) to whom your data has been disclosed
We will provide this information within 30 days of receiving a verified request. This right is available to you free of charge.
11.2 — Right to Correction and Completion (Section 12, DPDP Act 2023)
You have the right to request that we:
- Correct any personal data we hold about you that is inaccurate or misleading
- Complete any personal data we hold about you that is incomplete
- Update any personal data we hold about you that is outdated
For account profile data, you may make corrections directly in your account settings without submitting a formal request. For data that cannot be corrected through self-service, submit a request to our Grievance Officer as described in Section 12.
11.3 — Right to Erasure (Section 12, DPDP Act 2023)
You have the right to request deletion of your personal data. Upon receiving a verified erasure request:
- We will delete your account and all associated personal data within 30 days
- Automatic deletions on the schedules described in Section 7 will continue in parallel
- Consent records and processing activity logs will not be deleted, as these are legal compliance records retained under Section 5.3 of this Policy. However, these records do not contain your operational personal data — they contain only the fact, timing, and scope of your consent.
- Payment records will not be deleted to the extent retention is required by Indian law (8-year retention)
- Security logs will be retained for the remainder of their 180-day retention period
If you request erasure of your personal data, your account will be closed and you will no longer be able to access the Platform using that account.
11.4 — Right to Withdraw Consent (Section 6, DPDP Act 2023)
You may withdraw your consent to any specific processing activity at any time, without providing a reason. Withdrawal of consent:
- Takes effect from the date of withdrawal and does not retroactively invalidate processing that occurred while consent was valid
- For consent that relates to a specific tool (e.g., the voice agent tool), withdrawal will result in deletion of the data collected under that consent, in accordance with the retention schedule in Section 7
- For consent that relates to account registration, withdrawal is equivalent to a request for account closure and erasure
We will process consent withdrawal requests within 30 days.
11.5 — Right to Nominate (Section 14, DPDP Act 2023)
You have the right to nominate another individual (a “Nominated Person”) to exercise your rights under the DPDP Act in the event of your death or incapacity. To register a nominee, contact our Grievance Officer with the nominee's name and contact details. We will maintain a record of your nomination securely linked to your account.
11.6 — Right to Grievance Redressal (Section 13, DPDP Act 2023)
You have the right to a readily accessible means of grievance redressal for any concern or complaint related to your personal data. Our grievance mechanism is described in detail in Section 16.
11.7 — Right to Data Portability
You have the right to request an export of your personal data in a structured, machine-readable JSON format. The export will include your account profile data, MSME Navigator business profile, and scheme match results within their retention windows. Data that has already been automatically deleted under the schedule in Section 7 cannot be included in a portability export.
11.8 — Limitations on Rights
The following limitations apply to the exercise of rights under this Section:
- Rights are available only to the verified account holder. We will verify your identity before processing any rights request.
- Rights are not available for data that we are legally required to retain (consent records, payment records, processing activity logs).
- The right to erasure does not apply to data that has already been automatically deleted — there is nothing remaining to delete.
- Exercise of rights is subject to applicable exceptions and qualifications under the DPDP Act 2023 and other applicable Indian law.
12. How to Exercise Your Rights
12.1 — Submission of a Request
To exercise any right described in Section 11, submit a written request to our Grievance Officer at:
Email: grievance@trinetraedu-ai.com
Subject line:“Data Rights Request — [Your Full Name] — [Type of Request]”
Your request should include:
- Your full name and registered email address
- A clear description of the right you wish to exercise
- For correction requests: the specific data that is incorrect and the correct information
- For erasure or withdrawal requests: confirmation that you understand the consequences (account closure for erasure; service impact for consent withdrawal)
- Any other information that would help us identify the specific data at issue
12.2 — Identity Verification
To protect your data from unauthorised access requests, we will verify your identity before processing any request. Verification will be conducted by confirming:
- That the request comes from the registered email address associated with the account; or
- Where this is not possible, by requesting reasonable additional verification information
We will not require you to provide any additional sensitive personal data beyond what is reasonably necessary for verification purposes.
12.3 — Our Response Timeline
| Step | Timeline |
|---|---|
| Acknowledgment of your request | Within 72 hours of receipt |
| Identity verification (if required) | Within 5 business days of receipt of verification information |
| Resolution and completion of your request | Within 30 days of receipt of a complete and verified request |
| Notification if we are unable to fulfil the request | Within 30 days, with reasons |
12.4 — Escalation to the Data Protection Board
If you are not satisfied with our response to your rights request or grievance, you have the right to escalate your complaint to the Data Protection Board of India, to be constituted under Section 18 of the DPDP Act 2023. Information on how to file a complaint with the Board will be available at the Ministry of Electronics and Information Technology's official portal (meity.gov.in) upon operationalization of the Board.
13. Cookie Policy
13.1 — What Cookies We Use
The Platform uses only essential authentication cookies. We do not use any of the following:
- Third-party tracking cookies
- Advertising or remarketing cookies
- Behavioral analytics cookies (Google Analytics, Hotjar, Mixpanel, or equivalent services that track individual user behavior)
- Social media cookies or pixels (including Facebook Pixel, LinkedIn Insight Tag, or equivalent)
- Cross-site tracking mechanisms of any kind
The essential cookies we do use serve one purpose: keeping you securely logged in as you navigate between tools on the Platform.
We do use privacy-respecting analytics tools (Google Search Console and Vercel Analytics) that measure aggregate traffic and page performance without placing cookies on your device, without tracking you across websites, and without collecting personal identifiers. Full details are in our standalone Cookie Policy.
13.2 — Details of Essential Cookies
| Cookie Name | Purpose | Duration | Attributes |
|---|---|---|---|
| Authentication session cookie (managed by Supabase Auth) | Maintains your authenticated session across Platform tools and subdomains so you do not need to log in repeatedly | Session-based — deleted when you close your browser; refresh tokens have a longer lifespan to enable persistent login if you choose | HttpOnly (not accessible to JavaScript); Secure (transmitted only over HTTPS); SameSite=Strict (not sent in cross-site requests) |
HttpOnly, Secure, and SameSite=Strict are specific security attributes that protect your session cookie from common attack types including cross-site scripting (XSS) and cross-site request forgery (CSRF).
13.3 — Cookie Consent
Because we use only essential cookies strictly necessary for the operation of the Platform, we do not require your specific consent to set these cookies under current Indian law. However, you may disable cookies in your browser settings. Disabling cookies will prevent you from logging in and using the Platform, as authentication requires cookies to function.
13.4 — Full Cookie Policy
A standalone Cookie Policy document with full technical details, including information about our privacy-respecting analytics tools, is available at trinetraedu-ai.com/cookies and is incorporated into this Privacy Policy by reference.
14. Children's Privacy
14.1 — Age Restriction
The Platform is designed for use by businesses and business owners, and is not intended for use by individuals under the age of 18 years. We do not knowingly collect personal data from anyone under 18.
14.2 — If We Discover a Minor's Data
If we become aware or have reason to believe that we have collected personal data from a person under 18, whether through registration or through data submitted by an account holder, we will:
- Immediately suspend access to the relevant account pending review
- Permanently delete all personal data associated with the minor upon confirmation
- Notify the account holder of the deletion
14.3 — Parental or Guardian Reporting
If you believe a person under 18 has created an account or submitted personal data through the Platform, please contact our Grievance Officer immediately at grievance@trinetraedu-ai.com with the subject line “Minor's Data — Urgent.” We will treat all such reports as a priority matter and respond within 24 hours.
14.4 — DPDP Act Obligations Regarding Children
The DPDP Act 2023 imposes specific obligations on Data Fiduciaries in respect of children's data, including the requirement to obtain verifiable parental consent. As our Platform is not intended for children, we treat the discovery of any minor's data as a compliance matter requiring immediate deletion rather than a situation requiring parental consent processing.
15. Changes to This Policy
15.1 — How We Update This Policy
We may update this Policy from time to time to reflect:
- Changes in the services we offer
- New or changed third-party processors
- Changes in applicable law or regulatory guidance (including as the DPDP Act's subordinate rules are notified)
- Changes in our data retention or security practices
- The results of our periodic security audits
15.2 — How We Will Notify You
For material changes — changes that expand the categories of data we collect, change the purposes for which we use data, add new third-party processors, reduce your rights, or otherwise materially affect your interests — we will:
- Send you an email notification to your registered email address at least 30 days before the change takes effect
- Display a prominent notice on the Platform's main page for at least 30 days
- Where the change requires fresh consent under applicable law, present a consent interface and obtain your agreement before the change takes effect for your account
For non-material changes (corrections of typographical errors, clarifications that do not change the substance of our practices, updates to reflect operationalized provisions of the DPDP Act that do not affect your rights) — we will update the “Last Updated” date and publish the revised Policy without advance notice.
15.3 — Versioning
This Policy carries a version number (currently Version 2.0). Each materially revised version will carry an incremented version number. Prior versions of this Policy will be archived and made available on request to our Grievance Officer.
15.4 — Your Continued Use
If you continue to use the Platform after a material change takes effect, we will treat this as acceptance of the revised Policy for non-consent-based processing activities. For processing activities that require consent, we will obtain fresh consent before processing under the new terms.
16. Grievance Officer and Contact
16.1 — Grievance Officer
In accordance with Section 13 of the DPDP Act 2023, Rule 5 of the SPDI Rules 2011, and Rule 3(2) of the IT Intermediary Guidelines 2021, TrinetraEdu-AI has designated a Grievance Officer to receive and address complaints and queries related to this Policy and the processing of personal data.
- Grievance Officer: The Grievance Officer
- Designation: Co-Founder / Grievance Officer, TrinetraEdu-AI
- Email: grievance@trinetraedu-ai.com
- Platform Address: trinetraedu-ai.com
- Registered Address: Currently operating remotely. Registered address will be updated upon company incorporation.
Note on Grievance Officer Designation:Upon LLP incorporation, the designated Grievance Officer's full legal name and the registered address of the entity will be inserted in this Section. As required by the DPDP Act and the IT Intermediary Guidelines, the Grievance Officer is a natural person based in India who is authorised to receive, acknowledge, and respond to complaints on behalf of TrinetraEdu-AI.
16.2 — Grievance Process
| Step | Timeline |
|---|---|
| You submit a complaint or query to grievance@trinetraedu-ai.com | — |
| We acknowledge receipt of your complaint | Within 72 hours |
| We investigate and respond substantively | Within 30 days |
| If unresolved or unsatisfactory: you escalate to the Data Protection Board of India | As per Board procedures (see meity.gov.in) |
16.3 — What to Include in Your Complaint
To help us resolve your complaint efficiently, please include:
- Your full name and registered email address
- A clear description of your complaint or concern
- The specific provision of this Policy or legal right that you believe has been violated (if applicable)
- The relevant dates and events
- Any supporting information you consider relevant
16.4 — Data Protection Board Escalation
If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India, once constituted under Section 18 of the DPDP Act 2023. Information on filing a complaint will be published at the Ministry of Electronics and Information Technology portal (meity.gov.in). We will cooperate fully with any investigation or inquiry by the Board.
17. Effective Date and Jurisdiction
17.1 — Effective Date
This Privacy Policy is effective as of 15-07-2026 and applies to all personal data collected on or after this date by TrinetraEdu-AI across all Platform tools, subdomains, and services, including msme.trinetraedu-ai.com and any tools or subdomains launched in the future under the TrinetraEdu-AI brand.
17.2 — Governing Law and Jurisdiction
This Policy and all matters arising from it are governed by the laws of the Republic of India. Any dispute arising from this Policy or the processing of personal data that is not resolved through our grievance mechanism shall be subject to the jurisdiction of the courts in Kanpur, Uttar Pradesh, India, without prejudice to the right of either party to seek injunctive relief in any competent court.
17.3 — Language
This Policy is drafted in English, which is the governing version. In the event of any translation being provided for the convenience of users in other languages, the English version shall prevail in case of any conflict or ambiguity.
17.4 — Severability
If any provision of this Policy is found to be invalid, unlawful, or unenforceable under applicable law, that provision shall be modified to the minimum extent necessary to make it valid, lawful, and enforceable, and the remaining provisions of this Policy shall continue in full force and effect.
This Privacy Policy was drafted for TrinetraEdu-AI and should be reviewed by qualified Indian legal counsel prior to publication — specifically to: (a) confirm and insert the final registered entity name, registration number, and address upon LLP incorporation; (b) finalize the name of the designated Grievance Officer; (c) confirm the applicable court of jurisdiction; (d) verify the terms of service / data processing agreements with all AI processors (Google Gemini and Mistral AI) with respect to the prohibition on model training using submitted data; and (e) monitor and incorporate any subordinate rules, regulations, or Board decisions issued under the DPDP Act 2023 after the date of this draft.
TrinetraEdu-AI | trinetraedu-ai.com | grievance@trinetraedu-ai.com
