Privacy Policy Your Data, Protected.
Last updated: March 28, 2026
01. Information We Collect
AirOne collects information necessary to deliver, maintain, and improve our SaaS platform across the following categories:
Personal Data
- • Organization name and industry, provided when you register your workspace
- • Your first and last name, username, contact email, and contact phone (phone is optional)
- • Your account password, stored only as a salted one-way hash — we never see or store it in plain text
- • Billing address, GST number, and company registration details, used for invoicing
- • Job title, profile photograph, and other profile details you choose to add later
- • Government-issued identification only where legally required
Usage & Technical Data
To operate, secure, and meter the service, we record technical metadata for API requests (in our request log) and for metered API calls (in our billing-usage log):
- • The date and time, the URL path and full request URL, the HTTP method, the response status, and how long the request took
- • The request and response sizes, your IP address, your browser/device user-agent, and the referring page
- • The account and organization associated with each request, and a server-health snapshot (host CPU load and server memory) taken as the request completes — a machine-level reading, not a measurement of your individual request
- • For each metered API call: the endpoint and method, the response status and time, and the bytes sent and received (flagged as regular API traffic or media/file transfer) so we can meter bandwidth and usage for billing
- • Error logs, performance metrics, and crash reports
These logs do not store request or response bodies. We do not use third-party advertising or cross-site tracking cookies — see our Cookie Policy.
Any business data you or your team enter into AirOne modules — employee records, financial transactions, project details, CRM contacts — is processed on your behalf. You remain the data controller for this information.
02. How We Use Your Information
We use the data we collect for the following purposes:
Service Provision
Create and manage your account, authenticate logins, and deliver all platform features.
Billing & Payments
Process subscription payments, generate GST-compliant invoices, and manage tax compliance.
Product Improvement
Analyse usage patterns, prioritise feature development, and fix bugs faster.
Customer Support
Respond to helpdesk tickets, resolve issues, and improve support quality.
Communication
Send security alerts, onboarding guidance, product updates, and service announcements.
Legal Compliance
Meet obligations under Indian law including tax, audit, and regulatory requirements.
We will never use your data for purposes incompatible with those listed above without obtaining your explicit prior consent.
03. Data Storage & Security
Your data is stored in a self-managed YugabyteDB distributed-SQL cluster running on Amazon Web Services (AWS) EC2 in the Asia Pacific (Mumbai) region ap-south-1, with user-uploaded files held in Cloudflare R2 — keeping your data within India wherever technically feasible.
- AES-256 encryption at rest for all stored data including Cloudflare R2 objects and YugabyteDB volumes
- TLS 1.3 encryption in transit for all browser-server communication
- Multi-factor authentication (MFA) enforced for all AirOne administrator accounts
- Identity & access management (IAM) with roles, policies, and fine-grained permissions ensuring staff access only necessary data
- SOC 2 Type II aligned controls and ISO 27001 security framework (certifications in progress)
- Distributed-SQL database (YugabyteDB) with synchronous replication across nodes and automatic failover in seconds — committed data survives a node failure with no loss (RPO = 0)
- Automated daily backups with 30-day retention and point-in-time recovery
- DDoS mitigation via Cloudflare on the frontend, plus rate-limiting at the HAProxy API load balancer and the application layer
Security Incident Response: In the event of a confirmed data breach, we will notify you and CERT-In within 72 hours as required by applicable Indian law.
04. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data to any third party.
We share data only with a small set of vetted sub-processors under strict contractual obligations, each bound by a Data Processing Agreement — for example our payment gateway, cloud hosting and storage, email delivery, and error-monitoring providers. The current, authoritative list — with each processor’s purpose, the data it handles and its region — is maintained on our Sub-processors page.
We may also disclose personal data when required by law, court order, or lawful request by Indian government authorities (e.g., under Section 69 of the IT Act 2000).
05. Your Rights Under Indian Law
AirOne is built to operate in line with the Digital Personal Data Protection Act, 2023 (DPDPA) and the IT Act 2000, and is actively implementing the controls they require. As a data principal, you have:
Right of Access
Request a copy of all personal data we hold about you, including the purposes for processing.
Right to Correction
Request correction of inaccurate, incomplete, or outdated personal data without undue delay.
Right to Erasure
Request deletion of your personal data when no longer necessary, subject to legal retention obligations.
Right to Data Portability
Request your data in machine-readable format (JSON/CSV) for transfer to another service provider.
Right to Withdraw Consent
Withdraw consent at any time where processing is based on consent, without affecting prior processing.
Right to Nominate
Under DPDPA 2023, nominate another individual to exercise your rights in case of death or incapacity.
Right to Grievance Redressal
Raise a grievance with our Data Protection Officer and expect a response within 30 days.
To exercise these rights, write to dpo@airavadwebsolutions.com. We will respond within 30 days. To delete your account and associated data — from our mobile apps or the web — see Account & Data Deletion.
07. Data Retention
We retain personal data only for as long as needed for the purpose it was collected — typically for the life of your account plus a limited period after closure — or as required by law (for example, billing records are kept for 8 years under Indian tax law). The full schedule, with each data category, its retention period and the legal basis, is published on our Data Retention page.
After the retention period, data is securely deleted or anonymised so it can no longer be linked to any individual.
08. Contact for Privacy
If you have any questions, concerns, or complaints regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:
Airavad Web Solutions Pvt. Ltd.
Data Protection Officer
dpo@airavadwebsolutions.comFirst floor, South Facing, Sarveswaran Towers Door No. 7, 18, Sahadevepuram road Rajaram Nagar, Salem Tamil Nadu 636007
We aim to respond to all privacy-related requests within 30 days. If unsatisfied with our response, you may escalate your complaint to the Data Protection Board of India under DPDPA 2023.