Data Processing Policy
Last updated: March 28, 2026
01. Data Controller
The data controller responsible for your personal data is:
Airavad Web Solutions Pvt. Ltd.
Registered under the Companies Act, 2013
First floor, South Facing, Sarveswaran Towers Door No. 7, 18, Sahadevepuram road Rajaram Nagar, Salem Tamil Nadu 636007
CIN: U62013TZ2024PTC031856
As a SaaS provider, Airavad Web Solutions acts as both a data controller (for your account and contact data) and a data processor (for the business data your organisation enters into the platform).
02. Types of Data Processed
We process three broad categories of data on and through the AirOne platform:
Personal Data
- Name, email, phone number
- Job title and company name
- Billing address and GST number
- Login credentials (hashed)
Business Data
- Employee records and payroll
- Financial transactions
- CRM contacts and deals
- Project and task data
Technical Data
- IP address and device info
- Session logs and event data
- Error logs and crash reports
- API request and response logs
We apply data minimisation principles — we only collect data that is necessary for the specific processing purpose. Sensitive data (health, biometric, financial account details) is handled with additional technical and organisational safeguards.
03. Legal Basis for Processing
Under the Digital Personal Data Protection Act, 2023 (DPDPA) and the IT Act 2000, we process data on the following legal bases:
Contract Performance
Processing necessary to fulfil your subscription contract and deliver all platform features and services you have paid for.
Consent
Where you have given explicit consent, such as for marketing communications and optional integrations.
Legal Obligation
Where we are required to process data to comply with Indian law, including GST Act, Companies Act, and regulatory requirements.
Legitimate Interests
For fraud prevention, platform security, product improvement, and customer support — where these interests do not override your rights.
04. Sub-processors Table
We engage a small set of sub-processors that may process personal data on our behalf, each bound by a Data Processing Agreement (DPA). The current, authoritative list — with each sub-processor’s purpose, the data it processes and its region — is maintained on our Sub-processors page, where we also commit to at least 30 days’ notice of any change that may materially affect the processing of your personal data.
05. Data Subject Rights
Under DPDPA 2023 and the IT Act 2000, you have the following rights as a data principal. Submit requests to dpo@airavadwebsolutions.com:
Right of Access
Obtain a copy of your personal data and the purposes for which it is processed.
Right to Correction
Request correction of inaccurate or incomplete personal data.
Right to Deletion
Request erasure of personal data where no longer necessary or legally required.
Right to Portability
Receive your personal data in a structured, machine-readable format (JSON/CSV).
Right to Object
Object to processing based on legitimate interests, including profiling.
Right to Nominate
Under DPDPA 2023, nominate another individual to exercise rights on your behalf.
We will respond to all data subject requests within 30 days. If your request is refused, we will explain the legal basis for refusal. You may then escalate to the Data Protection Board of India under DPDPA 2023.
06. Data Breach Notification
Breach Notification Window
We will notify you and CERT-In within 72 hours of discovering a confirmed data breach that affects your personal data, as required by Indian law.
Our breach response procedure includes:
- Immediate containment and investigation upon breach discovery
- Assessment of the nature, scope, and likely consequences of the breach
- Notification to affected data principals with details of the breach and remediation steps
- Report to CERT-In and relevant Indian regulatory authorities within 72 hours
- Post-incident review and implementation of additional security measures
- Maintenance of a breach register as required by applicable law
07. Cross-Border Transfers
AirOne primarily stores and processes data within India — the YugabyteDB cluster on AWS EC2 in ap-south-1 (Mumbai) and user files in Cloudflare R2 (India region). Our payment processor Razorpay is India-based. However, some of our other sub-processors — such as our email-delivery, analytics, and domain/DNS providers — may process data outside India; the current providers are listed on our Sub-processors page.
Where international transfers occur, we ensure adequate safeguards through Standard Contractual Clauses (SCCs), adequacy decisions, or sub-processor adherence to globally recognised security frameworks such as ISO 27001 and SOC 2 Type II.
We comply with the DPDPA 2023 provisions regarding cross-border data flows and will update our practices as the Government of India notifies permissible countries for data transfer under DPDPA. The sub-processors on our Sub-processors page represent all current cross-border transfer destinations.
08. Data Protection Officer
Airavad Web Solutions has appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and compliance with applicable law.
Data Protection Officer
Airavad Web Solutions Pvt. Ltd.
dpo@airavadwebsolutions.comFirst floor, South Facing, Sarveswaran Towers Door No. 7, 18, Sahadevepuram road Rajaram Nagar, Salem Tamil Nadu 636007
The DPO is also available to handle grievances and requests under DPDPA 2023 and the IT Act 2000. See our Privacy Policy for full details.