Privacy FAQ
Last updated: June 17, 2026 · Version 0.1 (DRAFT)
How do I exercise my data rights (access, correction, erasure)?
Use the Submit a Data Request page — from your account’s Privacy & Data centre if you have one, or by email if you don’t.
How do I withdraw consent?
From your account’s privacy settings, per purpose — as easily as you gave it. Withdrawal doesn’t affect processing already done. See the India DPDP Notice.
Where is my data stored?
Personal data of Indian users and our security logs are stored in India (AWS ap-south-1, Mumbai). See data localisation.
Who are your sub-processors?
We list every third party that processes data — purpose and region — on the Sub-processors page, with advance notice of changes.
How long do you keep my data?
Only as long as needed for the purpose or as required by law — see Data Retention. Security logs are kept in India for the period CERT-In requires.
What happens if there is a data breach?
We follow a breach runbook aligned to DPDP (notify the Data Protection Board + affected individuals) and CERT-In timelines, and keep an immutable breach register.
Who is your Grievance Officer?
Contact details are published in the India DPDP Notice and our footer.
Do you sell my personal data?
No. We do not sell personal data. Marketing is opt-in and separate from the consent needed to provide the service.