Last updated: 2026-04-04 · Effective date: 2026-04-04
This document explains how ChetnaAI Private Limited (“Company”, “we”, “us”, “our”) processes personal data when you use chetanaai.com, contact us, or use our products and services (including AdvocateAI, ShaadiShubhMuhurat, AIRoboVein, LocalRush, Mute Marker, and any future offerings). It is designed to meet common expectations under the Digital Personal Data Protection Act, 2023 (India) and to inform international users; it does not replace legal advice.
Controller: ChetnaAI Private Limited, Noida Sector 16, 201301, Uttar Pradesh, India. Brand: ChetanaAI. For product-specific processing (e.g. a mobile app with its own account system), the same entity typically acts as controller unless we tell you otherwise in that product’s terms or in-app notice.
Scope: This policy applies to personal data collected through our public website, contact forms, email, phone, demos, trials, marketing pages, events, social channels we operate, and our software products and APIs. It does not govern third-party websites or services that we link to or that embed our content.
Depending on how you interact with us, we may process:
We process personal data for purposes including:
India: We rely on consent where required under the DPDP Act, and on other permitted grounds such as legitimate uses for provision of services, employment, safety, or compliance with law, as applicable.
EEA/UK/Switzerland (if applicable): We may rely on contract, legitimate interests (balanced against your rights), consent, or legal obligation. You may request details of our balancing test for legitimate interests where relevant.
If you are in India, you are a Data Principal under the DPDP Act. We commit to processing digital personal data in line with that law as it comes into full effect and as rules are notified. In particular:
Certain exemptions may apply to startups or specific processing contexts as notified by the Government of India; we will align our practices with applicable notifications.
We use cookies and similar technologies for:
You can control cookies through browser settings. Blocking strictly necessary cookies may break login or security features. Where we use a consent banner, you can change preferences through it when available.
We may use analytics tools to collect aggregated or pseudonymous usage data. Marketing emails include an unsubscribe link where required. We do not sell your personal data for money. We may use data for targeted advertising only where permitted by law and, where required, with your consent.
Some products use machine learning or large language models to generate suggestions, summaries, classifications, or search. In those cases we may process prompts, documents, or usage context you submit to provide the feature. We do not use your confidential product data to train public models unless we obtain explicit permission or provide a separate product-specific disclosure.
Outputs may be inaccurate; you should verify important results. Where a decision with legal or similarly significant effects is automated, we will provide information as required by applicable law and a path for human review where mandated.
We may share personal data with:
We contractually require subprocessors to protect personal data appropriately. A current list of subprocessor categories is available on request at support@chetanaai.com; we may update subprocessors and notify customers where our agreements require it.
Our primary operations are in India. We may process or store data in other countries where our providers host services (e.g. United States, European Economic Area, Singapore). Where cross-border transfer is restricted, we use appropriate mechanisms such as standard contractual clauses, adequacy decisions, or other lawful transfer tools, and we assess impact as required.
We retain personal data only as long as needed for the purposes above, including statutory retention (tax, accounting, litigation hold), and then delete or anonymise it. Typical examples: marketing consent logs for the duration of consent plus audit period; account data until deletion request plus legal hold; server logs on a rolling window unless security investigation requires longer retention.
We implement administrative, technical, and organisational measures appropriate to the risk, including access controls, encryption in transit where standard for the service, vulnerability management, staff training, and vendor due diligence. No method of transmission or storage is 100% secure; we encourage strong passwords and MFA where offered.
If we become aware of a breach that poses risk to individuals, we will assess notification duties under applicable law and notify regulators and/or affected users as required. If you discover a vulnerability, please report it responsibly to support@chetanaai.com.
Subject to applicable law, you may have the right to:
To exercise rights, email support@chetanaai.com with your name, contact detail, and request. We may verify identity before acting. We will respond within timelines required by law (often 30 days for many frameworks, subject to extension for complex requests).
Residents of certain US states (e.g. California, Virginia, Colorado, Connecticut, Utah, and others with comprehensive laws) may have additional rights such as: knowing categories of personal information collected, deleting personal information, correcting inaccuracies, opting out of “sale” or “sharing” for cross-context behavioural advertising, and limiting use of sensitive personal information. We do not “sell” personal information in the traditional sense; some analytics or ad cookies may constitute “sharing” under California law — where required we honour opt-out signals such as Global Privacy Control (GPC) at the browser level for applicable jurisdictions once technically implemented site-wide.
You may designate an authorised agent under applicable state rules; we may require proof of authorisation. Non-discrimination: we will not deny services solely for exercising privacy rights, except where permitted (e.g. reasonable loyalty programme differences).
If you are in the EEA, UK, or Switzerland, the controller is ChetnaAI Private Limited unless we appoint a local representative where required. Legal bases are described in Section 5. You may contact us to exercise GDPR/UK GDPR/FADP rights. Supervisory authority contacts depend on your residence (e.g. ICO in the UK, lead authority in the EEA).
Our marketing website and B2B products are not directed at children under 16 (or higher age where local law requires). We do not knowingly collect personal data from children for those services. Educational products may be used by schools with appropriate institutional consent; if you believe a child has provided data improperly, contact us for prompt review and deletion where appropriate.
Some products (e.g. legal or health-adjacent workflows) may process data you classify as sensitive under local law. We process such data only where necessary for the service, with applicable consent or exemption, and with enhanced access controls. Do not upload special-category data to products not intended for it.
Our site may link to GitHub, app stores, social networks, or partner sites. Their privacy policies govern their processing. Embedded widgets (e.g. maps, videos) may set third-party cookies; review their policies.
We may update this policy to reflect legal, technical, or business changes. We will revise the “Last updated” date and, where required, provide additional notice (e.g. email, in-app banner, or consent refresh for material changes). Continued use after notice where permitted constitutes acceptance; where consent is required, we will obtain it.
For privacy requests, grievances under Indian law, or general questions about this policy, contact:
We will acknowledge grievances and handle them in line with applicable timelines under the DPDP Act and rules once notified. For product-specific data processing, also see our Terms of Service.