Privacy Policy

📅 Effective: August 2026🏢 Swaran Soft Support Solutions Pvt. Ltd.⚖️ Governed by DPDP Act 2023
Contents
  1. Who We Are and What This Covers
  2. Our Role — and Why the Distinction Matters
  3. Personal Data We Process as a Data Fiduciary
  4. Lawful Basis
  5. How We Obtain Personal Data
  6. Who We Share Personal Data With
  7. International Transfers
  8. Retention
  9. Security
  10. Your Rights
  11. If You Are Outside India
  12. Children
  13. Automated Decision-Making
  14. Cookies
  15. Changes
  16. Contact and Grievances

1. Who We Are and What This Covers

Consiva.ai is a product and technology platform operated by Swaran Soft Support Solutions Private Limited ("we", "us", "our"), Tower A, Unit No. 2, 2nd Floor, The Cityscape, Sector-66, Golf Course Extension Road, Gurugram, Haryana – 122102, India. CIN: U72200DL2005PTC136405.

This policy explains how we handle personal data:

It does not cover the personal data our customers process through the platform about their own data principals. For that data our customer is the Data Fiduciary and we act as a Data Processor on their instructions. See section 2.

2. Our Role — and Why the Distinction Matters

This is the most important section of this policy, and it is the one most privacy policies get wrong.

We are a Data Fiduciary — determining purposes and means, and directly accountable to you — for:

We are a Data Processor — acting on our customer's instructions — for:

If you are an individual whose data was collected by a business using Consiva, we are not the right party to ask. Contact that business — they hold the relationship, the purposes and the decision. If you're not sure who to contact, write to us and we will try to point you in the right direction, but we cannot act on your rights request in respect of another organisation's data.

3. Personal Data We Process as a Data Fiduciary

3.1 Website Visitors

DataPurpose
IP addressSecurity, abuse prevention, approximate location for content relevance
Browser type and version, device type, operating system, screen sizeRendering the site correctly, diagnostics
Pages visited, time on page, referring URL, exit pageUnderstanding which content is useful
Cookie and tracker dataSee our Cookie Policy

We use Google Analytics 4 and Google Tag Manager for website analytics. Retention periods for this data are set out in section 8.

3.2 Enquiries, Walkthroughs and Marketing

Name, work email, organisation, role, sector, number of properties, and what you tell us in a free-text field.

Purposes: responding to your enquiry, arranging and preparing for a walkthrough, following up on that conversation, and — separately and only where you have opted in — sending updates about DPDP developments and Consiva.

The marketing opt-in is separate from the enquiry and is never a condition of us responding to you. You can withdraw it at any time using the link in any message or by writing to privacy@consiva.ai.

3.3 Customers and Authorised Users

Name, work email, role, organisation, credentials in hashed form, authentication events, in-product activity, preferences and settings, and support correspondence.

Purposes: providing and administering the Service, authenticating users, providing support, security monitoring, service communications, billing, and improving the Service.

3.4 Billing

Organisation name, billing address, GSTIN, contact details, invoice and payment history, and transaction identifiers from our payment provider.

We do not store full payment card details. Card payments are processed by our payment provider, Razorpay Software Private Limited, which is PCI DSS compliant.

Purposes: invoicing, payment collection, tax compliance, and financial record-keeping.

3.5 Security and Audit

Access logs, IP addresses, authentication attempts and failures, administrative actions, and incident records.

Purposes: securing the Service, investigating suspected misuse, meeting our own accountability obligations.

A note on Data Discovery. Where a customer connects a database, the Service records the location and classification of personal-data findings — which table, which column, which category — in order to build their inventory and ROPA. Database credentials supplied for this purpose are encrypted at rest and write-only. Where an example value is stored against a finding to help the customer verify the classification, it is always stored in masked form — the underlying raw value is never persisted.

4. Lawful Basis

Under the DPDP Act, processing of digital personal data requires consent or must fall within a specified legitimate use. Where the Act applies to our processing:

ProcessingBasis
Responding to an enquiry you initiatedProcessing for the purpose for which you voluntarily provided your data and have not indicated objection
Providing the Service to a customerPerformance of the contract with the customer organisation, and processing voluntarily provided for that purpose
Marketing communicationsYour consent, separately obtained and withdrawable
Security, fraud and abuse preventionOur legitimate operational requirement to secure the Service, and compliance with applicable law
Tax and statutory record-keepingCompliance with law
Non-essential cookies and analyticsYour consent → Cookie Policy

Where you are located outside India and another law applies to our processing of your data, we will handle it in accordance with that law to the extent it applies. Section 11 addresses this.

The DPDP Act's substantive consent and lawful-use provisions come into force in phases under notifications issued by the Government of India. Where a specific provision referred to above is not yet in force, we follow it as a matter of our own practice pending commencement, and this table will be read consistently with the law as it stands from time to time.

5. How We Obtain Personal Data

Directly from you; from your colleagues where they add you as an Authorised User; automatically through your use of the site and platform; from our payment provider in respect of transactions; and, for business contact details used in outbound sales prospecting, from third-party business data providers.

Where your business contact details reached us through a third-party provider rather than directly from you, you may object to further contact at any time by writing to privacy@consiva.ai, and we will stop and record your objection.

6. Who We Share Personal Data With

We do not sell personal data. We do not share it for third-party advertising.

We share it with:

Service providers and subprocessors — hosting, transactional email, payment processing and analytics. Our current subprocessor list, with categories of data and processing locations, is below.

Subprocessor List

CategoryVendorPurposeData processedLocation
Hosting / infrastructureOur own infrastructureApplication and database hostingAll platform dataHyderabad, India
Transactional emailGoDaddy.com, LLCAccount, billing, and consent-related notificationsName, email addressUnited States
Payment processingRazorpay Software Private LimitedSubscription billingBilling contact details, transaction metadata (no card numbers stored)India
AnalyticsGoogle LLC (Google Analytics 4 / Google Tag Manager)Website usage analyticsUsage/device metadata, no direct identifiersUnited States

Professional advisers — lawyers, accountants and auditors, under confidentiality obligations, where necessary.

Authorities — where we are legally required to disclose, or where necessary to establish, exercise or defend legal claims. Where we are lawfully able to notify you of such a request before complying, we will.

A successor entity — in connection with a merger, acquisition, reorganisation or transfer of the business, subject to the successor being bound by obligations no less protective than these.

7. International Transfers

The Consiva platform is hosted in a data centre in Hyderabad, India.

Some of our service providers process limited personal data outside India — our transactional email provider and our website analytics provider are each headquartered in the United States, as set out in the subprocessor list above.

We do not claim that no data ever leaves India. Where transfers occur, we rely on contractual protections with the provider and take account of restrictions applicable under the DPDP Act and any government notification restricting transfers to specified countries.

8. Retention

We retain personal data only as long as necessary for the purposes described, or as required by law.

CategoryRetention
Website analytics (aggregated)14 months
Raw web server logs, including IP address180 days
Cookie consent records3 years from the consent event or its withdrawal, whichever is later
Enquiry and walkthrough-request data24 months from last contact
Marketing contact dataUntil you withdraw consent. We then keep a minimal suppression record — a hashed identifier and the withdrawal date — so that we do not contact you again
Customer account and Authorised User dataDuration of the subscription plus 90 days
Support correspondence3 years from closure
Security and access logs1 year
Billing, invoice and tax records8 years from the end of the relevant financial year, as required by the Companies Act, 2013 and tax law
Backups35 days, on a rolling cycle

About erasure and backups. When we erase your personal data, we do so in our production systems within our response period. Residual copies may persist in encrypted backups until they are overwritten in the ordinary backup cycle, which completes within 35 days. During that window those copies are not used for any processing purpose.

Two periods are legal minimums rather than our choice. Rule 8(3) of the DPDP Rules, 2025 requires us to retain personal data, associated traffic data and processing logs for at least one year from the date of processing. Separately, the CERT-In directions of April 2022 require logs of ICT systems to be maintained for a rolling 180 days. Where these overlap with an erasure request, we suppress the data from active use and retain only what the law requires, and we tell you that is what we have done.

Personal data our customers process through the platform is retained according to their configuration and their agreement with us, not this table.

9. Security

We maintain technical and organisational measures designed to protect personal data. Swaran Soft maintains an ISO/IEC 27001:2022 certified Information Security Management System within the certified scope of providing software development services. For details of our platform security posture and its current limits, contact us.

No system is completely secure, and we do not claim otherwise.

10. Your Rights

Where we are the Data Fiduciary for your personal data, you may:

How to exercise these, and our response process → Privacy Rights & Grievance

11. If You Are Outside India

Consiva is designed for compliance with Indian law and is marketed principally to organisations in India. Where another privacy law applies to our processing of your personal data — for example the GDPR or UK GDPR where we offer services to individuals in those territories — we will handle your data in accordance with it to the extent it applies, and you may exercise the rights it gives you by contacting us.

We are deliberately not making a general claim of GDPR, UK GDPR, CCPA/CPRA or LGPD compliance, because the accurate statement is narrower than such a claim would suggest. If you require a specific assessment for your jurisdiction, contact us and we will tell you what we can and cannot support.

12. Children

The Consiva platform is a business tool and is not directed at children. We do not knowingly collect personal data of children through our website or in connection with account registration. If you believe we have, contact privacy@consiva.ai and we will delete it.

Where our customers use the platform to process children's data with verifiable parental consent, that processing is theirs, and we act as processor.

13. Automated Decision-Making

We do not make decisions producing legal effects about you by solely automated means. Where the platform uses automated processing to assist with classification or suggestions, those outputs require human review — see our Disclaimers & AI Notice.

14. Cookies

Set out separately → Cookie Policy

15. Changes

We may update this policy. We will change the "last updated" date and, for material changes, give notice by email or in-product before they take effect.

16. Contact and Grievances

Privacy queries and rights requests: privacy@consiva.ai

Contact for questions about our processing — the person able to answer questions about our processing of your personal data on our behalf, as required by Rule 9 of the DPDP Rules, 2025:

Saurabh K
Privacy Officer & Grievance Officer
Email: saurabhk@swaransoft.com
Swaran Soft Support Solutions Private Limited, Tower A, Unit No. 2, 2nd Floor, The Cityscape, Sector-66, Golf Course Extension Road, Gurugram, Haryana – 122102, India

Post: Swaran Soft Support Solutions Private Limited, Tower A, Unit No. 2, 2nd Floor, The Cityscape, Sector-66, Golf Course Extension Road, Gurugram, Haryana – 122102, India
Telephone: +91 9220313650

If you are not satisfied with our response, you may complain to the Data Protection Board of India.