Aashray AI Labs
Enterprise Privacy Policy
Effective Date: June 23, 2026
Subject to updates upon Private Limited incorporation.
1. Introduction & Compliance Scope
This Enterprise Privacy Policy ("Policy") explains how Aashray AI Labs ("we", "us", or "our") collects, uses, processes, and protects your information. This Policy is designed in strict compliance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act (DPDPA), 2023 of India, the General Data Protection Regulation (GDPR) of the European Union, and the California Consumer Privacy Act (CCPA/CPRA).
2. Zero-Training Data Sovereignty
2.1 Foundational Guarantee: Aashray AI Labs operates under a strict Zero-Training policy regarding Customer Data. We do not, under any circumstances, utilize proprietary enterprise data, user inputs, or deterministic inference outputs to train, fine-tune, or improve our foundational AI models. Your data remains strictly isolated within your sovereign tenant boundary.
3. Data Collection & Processing
We process the following categories of data:
- Account Information: Names, enterprise email addresses, and organizational affiliations necessary for SaaS provisioning.
- System Telemetry: Anonymized API request logs, latency metrics, and error tracing strictly utilized to ensure 99.99% system uptime and operational security.
- Inference Data: Inputs provided dynamically to our orchestration layer, which are processed transiently to generate outputs and subsequently purged or encrypted at rest based on your configuration.
4. Subprocessors & Cloud Infrastructure
Our orchestration layer utilizes global cloud infrastructure to guarantee high availability. A full list of our current cloud subprocessors (e.g., AWS, Azure, GCP) and API providers is available upon request. We ensure all subprocessors are contractually bound by Standard Contractual Clauses (SCCs) matching or exceeding our internal security benchmarks. Data localization requirements under Indian law will be strictly adhered to where applicable.
5. Data Subject Rights (DPDPA & GDPR)
Depending on your jurisdiction, you possess specific rights regarding your personal data:
- Right to Access & Portability: Obtain a structured, commonly used export of your data.
- Right to Erasure ("Right to be Forgotten"): Request cryptographic deletion of your account and associated PII, subject to legal retention mandates.
- Right to Nominate (DPDPA): Under the Indian DPDPA, you possess the right to nominate another individual to exercise your rights in the event of death or incapacity.
To exercise these rights, submit a formal Data Subject Access Request (DSAR) to our Data Protection Officer.
6. Security & Breach Notification
6.1 Enterprise Security: All Customer Data is encrypted at rest using AES-256 and in transit using TLS 1.3 or higher. We enforce Role-Based Access Control (RBAC) and maintain immutable audit logs.
6.2 Incident Response: In the event of a verified data breach impacting unencrypted Customer Data, we commit to notifying affected enterprises and the Indian Computer Emergency Response Team (CERT-In) / relevant global regulators within 72 hours, in accordance with applicable cybersecurity directives.
7. Grievance Redressal & Contact
For privacy inquiries, DSARs, or to contact our Data Protection Officer (DPO) and Grievance Officer, please reach out via:
- Email: legal@aashrayailabs.com
- Location: Hyderabad, Telangana, India