Privacy Policy
Last updated: [PLACEHOLDER: date of publication]
Brihat Lekha is a document drafting service operated by [PLACEHOLDER: legal entity name, e.g. Brihat Infotech Private Limited], CIN [PLACEHOLDER], with its registered office at [PLACEHOLDER: address] (“we”, “us”). This policy explains what personal data we process when you use Brihat Lekha, why, and the rights you have under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).
1. Two kinds of data
Account data is data about you as a user: your name, work email, password (stored only as a one-way hash), the organisations you belong to and your role in them. For account data we act as the Data Fiduciary.
Customer content is what your organisation puts into Brihat Lekha: Company Vault details, documents, comments, uploaded tender files and the personal data of other people inside them (for example employees named in an offer letter or a NOC). Your organisation decides what goes in and why; for customer content your organisation is the Data Fiduciary and we process it only on its instructions to provide the service.
2. What we collect and why
- Account data, to create and secure your account, let you sign in and show you the organisations you belong to.
- Customer content, to draft, store, version, share and export documents as you ask.
- Billing records (plan, payment status, invoice details), to charge for the service. Card and UPI details are entered on Razorpay’s checkout and are never received or stored by us.
- Usage and security logs (sign-ins, document actions, IP address), to keep an audit trail for your organisation, prevent abuse and investigate incidents.
- Email address, to send service emails: invites, password resets, approval requests and review comments. We do not send marketing email without your consent.
3. AI processing
When you use AI features (question cards, AI drafts, rewriting a passage, the Tender Analyzer), the relevant document text, the details you typed and your organisation’s Company Vault are sent to an AI model hosted on Amazon Web Services (Amazon Bedrock) to produce the result. Bank account numbers and IFSC codes stored in the Company Vault are never sent. Your content is not used to train AI models, by us or by the model provider. AI output can be wrong; review it before you rely on it.
4. Where data is stored
Brihat Lekha’s application, database and uploaded files are hosted on servers in India, and AI requests are sent to an AWS region in India ([PLACEHOLDER: confirm the Bedrock region and whether any cross-region inference applies before publishing this sentence]). We do not transfer customer content outside India except where you choose to, for example by sharing a review link with someone abroad or emailing an export.
5. Who we share data with
We use these service providers (“Data Processors”), each bound by a contract to process data only for us:
- Amazon Web Services: AI model hosting (Amazon Bedrock) and email delivery (Amazon SES).
- Razorpay: payment processing.
- [PLACEHOLDER: hosting provider of the India VPS].
We share data with others only when you ask (review links, exports), or when Indian law, a court or a government authority requires it.
6. Cookies and local storage
We set one cookie, an HTTP-only session cookie that keeps you signed in. Your browser’s local storage remembers your light or dark theme and the organisation you last opened. We do not use advertising or third-party tracking cookies.
7. How long we keep data
Customer content is kept for as long as your organisation keeps its account, and is deleted when the organisation is deleted. Deleting your account deletes your account data and any organisation where you are the only member. Backups are overwritten within [PLACEHOLDER: backup retention, e.g. 30 days]. Billing records are kept as long as Indian tax law requires.
8. Security
Data is encrypted in transit (HTTPS). Passwords are hashed with Argon2. Each organisation’s data is isolated, sign-in sessions rotate, and actions are recorded in an audit log. If a personal data breach occurs, we will notify the Data Protection Board of India and affected people as the DPDP Act requires.
9. Your rights
Under the DPDP Act you may:
- ask for a summary of the personal data we process about you and with whom it was shared;
- ask us to correct, complete, update or erase your personal data;
- withdraw consent where processing is based on consent;
- nominate another person to exercise your rights in case of death or incapacity;
- raise a grievance with us, and if it is not resolved, complain to the Data Protection Board of India.
You can change your name and password, and delete your account, from the Account page. For personal data inside your organisation’s documents, contact your organisation’s administrator first; we will help them respond.
10. Grievance Officer
[PLACEHOLDER: name], Grievance Officer, [PLACEHOLDER: address], email [PLACEHOLDER: grievance email]. We acknowledge grievances within [PLACEHOLDER: e.g. 48 hours] and aim to resolve them within [PLACEHOLDER: e.g. 30 days].
11. Changes
If we change this policy in a way that matters, we will tell you by email or in the app before the change takes effect.