Privacy Notice
Last updated: 6 October 2026
This notice explains how Dhiraj Khanna, trading as AIAuditSense(“we”, “us”), the Data Fiduciary for AIAuditSense (“the Service”), processes your personal data under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the DPDP Rules, 2025. We ask for your consent separately from our Terms of Service, and only for the purposes listed here.
1. What we collect, and why
- Account details — name, email address, a password stored only as a one-way hash, or the basic profile Google or GitHub shares if you sign in with them. Purpose: to create and secure your account and let you sign in.
- Assessment inputs — your answers in the intake form, website and repository URLs, documents you upload, and notes. These may contain personal data about you or others. Purpose: to generate, review and deliver your compliance report.
- Reports and processing records — the reports we generate, reviewer corrections, messages with our reviewers, and records of each AI model call. Purpose: to deliver and correct your report, bill accurately, and diagnose faults.
- Enquiries — name, email, company, role and message from the contact and engagement forms. Purpose: to reply to you and, if you asked for one, prepare a proposal. Never used for marketing.
- Payment records — order and subscription identifiers and status from Razorpay. We never see or store your card or bank details. Purpose: to process payments and keep the records tax law requires.
- A hashed form of your IP address — never the address itself. Purpose: to limit spam on our public forms.
2. Who we share it with
We do not sell your personal data. We share it only with these processors, under contract, to run the Service:
- OpenRouter and the AI model providers it routes to — your assessment inputs, to generate reports. These providers may process data outside India.
- Razorpay — to take payments and manage subscriptions.
- Resend — to send account, order and enquiry emails.
- Google and GitHub — only if you choose to sign in with them.
- Our hosting and database provider — to run the application and store your data, located in Helsinki, Finland (Hetzner).
- Verhelm Advisory, which runs AIAuditSense — its reviewers read assessment inputs to check reports, and it answers enquiries.
- Government authorities, only where the law requires it.
Some processors are outside India. We transfer data abroad only to countries the Government of India has not restricted under section 16 of the DPDP Act.
3. How long we keep it
- Account data — until you delete your account, or three years after your last sign-in.
- Assessment inputs and reports — for the life of your account, so you can return to them.
- Prompts and responses in AI processing records — deleted after 90 days. Token and cost figures, which hold no personal data, are kept for billing.
- Intake submissions never linked to an account — 90 days.
- Contact and engagement enquiries — 24 months after you send them.
- Payment and invoice records — as long as Indian tax law requires, currently up to eight years.
- Security and access logs — one year, as the DPDP Rules require.
When a period ends, we delete or irreversibly anonymise the data. Where we delete because you have been inactive, we email you at least 48 hours beforehand.
4. Your rights
Under the DPDP Act you can:
- get a summary of the personal data we hold about you and who we have shared it with;
- have inaccurate or incomplete data corrected, and outdated data updated;
- have your data erased, except what we must keep by law;
- withdraw consent at any time, as easily as you gave it;
- nominate someone to exercise these rights if you die or become incapacitated;
- complain to us, and then to the Data Protection Board of India.
If you have an account, you can download your data, correct your name, withdraw consent and delete your account yourself on the Account & privacy page. For anything else, email support@aiauditsense.com from your account email. We will confirm your identity and respond within 30 days. Withdrawing consent stops future processing; it does not undo processing already done, and we may need to close your account if we can no longer provide the Service.
5. Security
We encrypt data in transit, store passwords only as hashes, never store raw IP addresses, restrict access to staff who need it, and keep access logs. If a breach affects your personal data, we will tell you without delay what happened, the likely consequences, and what we are doing about it, and we will report it to the Data Protection Board.
6. Cookies
We use only strictly necessary cookies, to keep you signed in and to secure your session. We use no analytics or advertising cookies.
7. Children
The Service is for people aged 18 and over, and we ask everyone to confirm their age when they consent. We do not knowingly collect children’s data; if we learn we have, we delete it.
8. Changes to this notice
If we change this notice in a way that affects how we use your data, we will ask for your consent again the next time you sign in.
9. Grievances and contact
Questions or complaints about your personal data go to Dhiraj Khanna, who handles data protection for AIAuditSense: support@aiauditsense.com, or by post to Dhiraj Khanna, trading as AIAuditSense, F118 Richmond Park, Sector 43, Gurugram, Haryana, 122009, India. We resolve grievances within 90 days. If you are not satisfied with our response, you can complain to the Data Protection Board of India.