Legal · Privacy

Privacy Policy

Last updated: 5 June 2026

This Privacy Policy explains how VyaptIX Technologies LLP (“VyaptIX”, “we”) collects, uses, and protects personal data in connection with the BharatTrade Copilot service. It is written to comply with India’s Digital Personal Data Protection Act 2023 (DPDP Act), and with the EU GDPR / UK GDPR where they apply to data we process about EU/UK residents.

1. Data Controller

VyaptIX Technologies LLP · Hyderabad, Telangana, India · Email: privacy@vyaptix.ai.

2. What we collect

3. How we use it

4. Legal basis

We process personal data on the basis of (i) contract — to deliver the Service you subscribed to, (ii) legitimate interest — to secure and improve the Service, and (iii) consent — for optional product analytics, where applicable. You can withdraw consent at any time without affecting prior processing.

5. Where it lives

Your data is stored securely in India, with strict per-company isolation so no other customer can ever see it. Trade documents and search indexes are held in the same region, and all backups are encrypted at rest.

6. Sub-processors

We use the following sub-processors to run the Service. The current list is maintained here and reflected in our Data Processing Addendum.

7. International transfers

Some sub-processors (LLMs, hosting edges) may process limited data outside India. Where EU personal data is involved, we rely on Standard Contractual Clauses (SCCs) and equivalent safeguards.

8. Retention

We retain Customer Content for the life of your subscription plus 30 days after termination to allow export. Billing records are retained for 8 years to comply with Indian tax law. Application logs are retained for 30 days; security event logs for 12 months. You can request earlier deletion subject to legal-hold exceptions.

9. Your rights

Subject to the DPDP Act, GDPR, and UK GDPR as applicable, you have the right to access, correct, delete, port, and restrict processing of your personal data, and to withdraw consent or object to certain processing. Email privacy@vyaptix.ai — we respond within 30 days.

10. Security

TLS in transit, AES-256 at rest, row-level security at the database, magic-link authentication, least-privilege internal access, audit logging, and regular dependency scanning. We will notify affected users and the relevant authority of any breach involving personal data within the timelines required by law.

11. Children

The Service is intended for use by businesses. We do not knowingly collect data from children under 18.

12. Cookies

We use first-party cookies strictly necessary for sign-in and session management, plus an opt-in analytics cookie (PostHog) you can decline. We do not use advertising cookies.

13. Changes

Material changes will be notified by email at least 14 days in advance. The current version is always available at /legal/privacy.

14. Contact

Grievance Officer: privacy@vyaptix.ai. We will acknowledge complaints within 7 days and resolve them within 30 days.