1. Who we are

ProminAI is operated by [to be confirmed before launch] (StartupFeed), India ("we", "us"). For the purposes of the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), we are the data fiduciary for the personal data described on this page. Contact for anything here: [to be confirmed before launch], or the Grievance Officer below.

2. The data we collect

Identity and contact data — name, email address, mobile number — when you send a form, message us or buy a plan. Business data — brand name, website, city, category, competitors you name — when you request a check or onboard. Payment metadata — order ID, amount, status, method — from Razorpay; we never receive or store your card number, CVV or UPI PIN. Technical and usage data — IP address, pages viewed, referrer (including whether you arrived from an AI tool) — from server logs and, only with consent, analytics. Uploaded assets — logos, photographs, documents — that you supply for publication.

3. Why we collect it (purposes and lawful basis)

We process personal data to reply to your enquiries, deliver the service you purchased, issue GST invoices, meet legal and tax obligations, secure the website, and — only with your consent — measure how the website is used. The lawful bases under the DPDP Act are your consent (forms, analytics) and legitimate uses connected with providing a service you have requested (delivery, invoicing, support) and complying with law (tax records).

We do not sell personal data. We do not share it for advertising. No exceptions.

4. Who processes it for us

Named by category, current at the date above: payments — Razorpay Software Pvt Ltd (order creation, payment capture, refunds); hosting — our web hosting provider, on servers configured by us; email — our transactional email/SMTP provider, used to send the emails this site describes; analytics — Google Analytics 4 and Meta Pixel, loaded only after you choose "Accept" in the consent banner. Each processor receives only what its function requires.

5. How long we keep it

Enquiries and leads: up to 24 months from last contact, then deleted or anonymised. Client records and deliverables: the engagement period plus 36 months, so you can request copies after membership ends. Invoices and payment records: 8 years, as Indian tax law requires. Server logs: up to 90 days. Analytics data: per the retention configured in the tool, not exceeding 26 months. When a period ends, the data is deleted or irreversibly anonymised.

6. Your rights, and exactly how to use them

Under the DPDP Act you may: access a summary of the personal data we hold about you; ask us to correct inaccurate or incomplete data; ask us to erase data we no longer need to keep by law; seek grievance redressal for anything on this page; and nominate a person to exercise these rights for you if you are unable to.

To exercise any of them: email [to be confirmed before launch] or WhatsApp us, with the subject "Data request", your name and the mobile/email you used with us. We verify it is you, act within 15 days, and confirm in writing what was done. There is no fee.

7. Grievance Officer

Grievance Officer: [to be confirmed before launch] · [to be confirmed before launch]. Complaints are acknowledged within 72 hours and answered within 15 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India as provided by the DPDP Act.

8. Children's data

Our service is for businesses and professionals. We do not knowingly collect personal data from anyone under 18. If you believe a minor has sent us personal data, tell us and we will delete it.

9. Where the data lives (cross-border note)

Our primary hosting is configured for India. Some processors (for example analytics, or email delivery networks) may store data on servers outside India; where they do, we rely on their published safeguards and the DPDP Act's provisions for transfers. We do not transfer personal data to any country restricted by the Government of India.

10. Cookies — every one, by name

This list matches the consent banner exactly. "Necessary" cookies are set without consent because the site cannot function without them; everything else waits for your "Accept".

Declining analytics changes nothing about what you can do on this site.

11. Security measures

HTTPS everywhere; payment processing isolated with Razorpay (PCI-DSS compliant); server-side sessions with CSRF protection on every form; rate limiting on every endpoint; secrets kept out of the web root; access to personal data limited to the people who need it to serve you.

12. If something goes wrong (breach notification)

If a personal data breach affects you, we will notify you and the Data Protection Board of India as the DPDP Act requires, without unreasonable delay, and tell you plainly what happened, what data was involved and what we are doing about it.

13. Changes to this policy

Changes are listed in the version history below with dates. Material changes are announced on this page and, for active clients, by email or WhatsApp. We never weaken your rights retroactively.

Questions about this document?

Ask before you agree, not after — WhatsApp us. Replies within one working day. The company details Razorpay and the law require are on the contact page.