Privacy Policy

Last updated: 2026-04-04 · Effective date: 2026-04-04

This document explains how ChetnaAI Private Limited (“Company”, “we”, “us”, “our”) processes personal data when you use chetanaai.com, contact us, or use our products and services (including AdvocateAI, ShaadiShubhMuhurat, AIRoboVein, LocalRush, Mute Marker, and any future offerings). It is designed to meet common expectations under the Digital Personal Data Protection Act, 2023 (India) and to inform international users; it does not replace legal advice.

1. Scope & data controller

Controller: ChetnaAI Private Limited, Noida Sector 16, 201301, Uttar Pradesh, India. Brand: ChetanaAI. For product-specific processing (e.g. a mobile app with its own account system), the same entity typically acts as controller unless we tell you otherwise in that product’s terms or in-app notice.

Scope: This policy applies to personal data collected through our public website, contact forms, email, phone, demos, trials, marketing pages, events, social channels we operate, and our software products and APIs. It does not govern third-party websites or services that we link to or that embed our content.

2. Definitions

  • Personal data / personal information: Information that identifies or can reasonably be linked to an identifiable individual.
  • Processing: Any operation on personal data (collection, storage, use, disclosure, erasure, etc.).
  • You / your: Visitors, prospects, customers, end-users of our products where we process data on behalf of our business relationship.

3. Categories of data we collect

Depending on how you interact with us, we may process:

  • Identity & contact: Name, email, phone, company, job title, postal address, social handles, government or tax identifiers only where legally required for billing or compliance.
  • Account & profile (products): Credentials (hashed passwords), preferences, organisation membership, roles, uploaded profile or portfolio content where the product allows it.
  • Commercial: Plan type, purchase history, quotes, invoices, payment references. Card payments are typically handled by regulated payment processors; we do not store full card numbers.
  • Content you submit: Messages, attachments, support tickets, feedback, form fields, documents you upload to products (e.g. legal or educational materials in relevant apps), and metadata (timestamps, file types).
  • Technical & usage: IP address, device identifiers, browser and OS, approximate location derived from IP, pages viewed, clicks, referring URL, session duration, crash logs, API usage, feature telemetry where enabled.
  • Communications: Records of email, chat, or call interactions with our team, including quality and training notes where permitted.
  • Marketing: Newsletter subscriptions, event registrations, campaign engagement (opens / clicks where measured), consent logs.

4. Sources of personal data

  • Directly from you (forms, product UI, email, phone, contracts).
  • Automatically when you use our website or products (logs, cookies, SDKs).
  • From your organisation (e.g. admin invites you to a workspace).
  • From public sources or partners where allowed (e.g. lead lists with consent, professional networks).

5. Purposes of processing & legal bases

We process personal data for purposes including:

  • Providing services: Operating the website, authenticating users, delivering product features, support, billing, security monitoring.
  • Improving products: Analytics, debugging, A/B tests, aggregated usage statistics, feedback analysis.
  • Communications: Transactional notices, service announcements, optional marketing (where consent or soft opt-in applies).
  • Legal & compliance: Tax, accounting, fraud prevention, enforcing terms, responding to lawful requests from authorities.
  • Business operations: Planning, corporate transactions (e.g. merger — with appropriate safeguards and notice where required).

India: We rely on consent where required under the DPDP Act, and on other permitted grounds such as legitimate uses for provision of services, employment, safety, or compliance with law, as applicable.

EEA/UK/Switzerland (if applicable): We may rely on contract, legitimate interests (balanced against your rights), consent, or legal obligation. You may request details of our balancing test for legitimate interests where relevant.

6. India — Digital Personal Data Protection Act, 2023

If you are in India, you are a Data Principal under the DPDP Act. We commit to processing digital personal data in line with that law as it comes into full effect and as rules are notified. In particular:

  • We collect data for specified, clear purposes and handle it fairly and reasonably.
  • Where consent is required, we seek it free, specific, informed, unconditional, and unambiguous.
  • You may withdraw consent where processing is consent-based, subject to legal or contractual retention needs.
  • You may access information about processing and request correction or erasure as the law allows.
  • You may nominate another person to exercise rights on your death or incapacity as prescribed.
  • You may lodge a grievance with us (see below) and, if unresolved, approach the Data Protection Board of India as the framework permits.

Certain exemptions may apply to startups or specific processing contexts as notified by the Government of India; we will align our practices with applicable notifications.

7. Cookies, local storage & similar technologies

We use cookies and similar technologies for:

  • Strictly necessary: Security, load balancing, authentication sessions, cookie consent state, accessibility or language preferences.
  • Functional: Remembering choices (e.g. dark mode) where not strictly necessary.
  • Analytics: Understanding traffic and product usage (may be first-party or via vendors).
  • Marketing: Only where allowed and, where required, after consent (e.g. ad pixels).

You can control cookies through browser settings. Blocking strictly necessary cookies may break login or security features. Where we use a consent banner, you can change preferences through it when available.

8. Analytics, email & marketing

We may use analytics tools to collect aggregated or pseudonymous usage data. Marketing emails include an unsubscribe link where required. We do not sell your personal data for money. We may use data for targeted advertising only where permitted by law and, where required, with your consent.

9. Artificial intelligence & automated processing

Some products use machine learning or large language models to generate suggestions, summaries, classifications, or search. In those cases we may process prompts, documents, or usage context you submit to provide the feature. We do not use your confidential product data to train public models unless we obtain explicit permission or provide a separate product-specific disclosure.

Outputs may be inaccurate; you should verify important results. Where a decision with legal or similarly significant effects is automated, we will provide information as required by applicable law and a path for human review where mandated.

10. Disclosure to third parties & subprocessors

We may share personal data with:

  • Infrastructure & hosting: Cloud providers, CDNs, databases, backup services.
  • Communications: Email delivery, SMS, video conferencing, customer support platforms.
  • Payments & accounting: Payment gateways, invoicing tools, auditors.
  • Security & fraud: DDoS protection, bot management, identity verification where used.
  • Professional advisers: Lawyers, accountants, insurers under confidentiality.
  • Authorities: When required by law, court order, or to protect rights, safety, and integrity of users or the public.
  • Business transfers: Successors in a merger, acquisition, or asset sale, subject to continuity of protections where feasible.

We contractually require subprocessors to protect personal data appropriately. A current list of subprocessor categories is available on request at support@chetanaai.com; we may update subprocessors and notify customers where our agreements require it.

11. International transfers

Our primary operations are in India. We may process or store data in other countries where our providers host services (e.g. United States, European Economic Area, Singapore). Where cross-border transfer is restricted, we use appropriate mechanisms such as standard contractual clauses, adequacy decisions, or other lawful transfer tools, and we assess impact as required.

12. Retention

We retain personal data only as long as needed for the purposes above, including statutory retention (tax, accounting, litigation hold), and then delete or anonymise it. Typical examples: marketing consent logs for the duration of consent plus audit period; account data until deletion request plus legal hold; server logs on a rolling window unless security investigation requires longer retention.

13. Security measures

We implement administrative, technical, and organisational measures appropriate to the risk, including access controls, encryption in transit where standard for the service, vulnerability management, staff training, and vendor due diligence. No method of transmission or storage is 100% secure; we encourage strong passwords and MFA where offered.

14. Personal data breach

If we become aware of a breach that poses risk to individuals, we will assess notification duties under applicable law and notify regulators and/or affected users as required. If you discover a vulnerability, please report it responsibly to support@chetanaai.com.

15. Your privacy rights

Subject to applicable law, you may have the right to:

  • Access a copy or summary of your personal data we hold.
  • Correct inaccurate or incomplete data.
  • Request deletion or restriction of processing in defined cases.
  • Object to certain processing based on legitimate interests or direct marketing.
  • Data portability in a structured, machine-readable format where technically feasible.
  • Withdraw consent without affecting prior lawful processing.
  • Lodge a complaint with a supervisory authority or the Data Protection Board of India, as applicable.

To exercise rights, email support@chetanaai.com with your name, contact detail, and request. We may verify identity before acting. We will respond within timelines required by law (often 30 days for many frameworks, subject to extension for complex requests).

16. United States — state privacy laws (summary)

Residents of certain US states (e.g. California, Virginia, Colorado, Connecticut, Utah, and others with comprehensive laws) may have additional rights such as: knowing categories of personal information collected, deleting personal information, correcting inaccuracies, opting out of “sale” or “sharing” for cross-context behavioural advertising, and limiting use of sensitive personal information. We do not “sell” personal information in the traditional sense; some analytics or ad cookies may constitute “sharing” under California law — where required we honour opt-out signals such as Global Privacy Control (GPC) at the browser level for applicable jurisdictions once technically implemented site-wide.

You may designate an authorised agent under applicable state rules; we may require proof of authorisation. Non-discrimination: we will not deny services solely for exercising privacy rights, except where permitted (e.g. reasonable loyalty programme differences).

17. EEA, United Kingdom & Switzerland

If you are in the EEA, UK, or Switzerland, the controller is ChetnaAI Private Limited unless we appoint a local representative where required. Legal bases are described in Section 5. You may contact us to exercise GDPR/UK GDPR/FADP rights. Supervisory authority contacts depend on your residence (e.g. ICO in the UK, lead authority in the EEA).

18. Children

Our marketing website and B2B products are not directed at children under 16 (or higher age where local law requires). We do not knowingly collect personal data from children for those services. Educational products may be used by schools with appropriate institutional consent; if you believe a child has provided data improperly, contact us for prompt review and deletion where appropriate.

19. Sensitive or special categories of data

Some products (e.g. legal or health-adjacent workflows) may process data you classify as sensitive under local law. We process such data only where necessary for the service, with applicable consent or exemption, and with enhanced access controls. Do not upload special-category data to products not intended for it.

20. Third-party links & embedded content

Our site may link to GitHub, app stores, social networks, or partner sites. Their privacy policies govern their processing. Embedded widgets (e.g. maps, videos) may set third-party cookies; review their policies.

21. Changes to this Privacy Policy

We may update this policy to reflect legal, technical, or business changes. We will revise the “Last updated” date and, where required, provide additional notice (e.g. email, in-app banner, or consent refresh for material changes). Continued use after notice where permitted constitutes acceptance; where consent is required, we will obtain it.

22. Contact, grievance officer & questions

For privacy requests, grievances under Indian law, or general questions about this policy, contact:

We will acknowledge grievances and handle them in line with applicable timelines under the DPDP Act and rules once notified. For product-specific data processing, also see our Terms of Service.