Legal Center

Privacy Policy

This policy outlines how AhuraSense Technologies Private Limited collects, uses, stores, and protects personal data for customer accounts, platform usage, security operations, AI workloads, and support.

Effective date: May 30, 2026

Last updated: May 30, 2026

Privacy Fundamentals

1. Overview

This Privacy Policy explains how AhuraSense Technologies Private Limited ("AhuraSense", "Company", "we", "us", or "our") collects, uses, stores, shares, protects, and otherwise processes personal data when you access or use our websites, portals, dashboards, APIs, cloud infrastructure services, AI inference services, AI training services, compute services, GPU pods, Kubernetes services, database services, object storage services, security services, domain services, application deployment services, support services, documentation, billing systems, and related offerings.

This Privacy Policy applies to:

  • Visitors to our websites.
  • Customers and prospective customers.
  • Account administrators, developers, and technical users.
  • Billing and support contacts.
  • Business contacts and users of our dashboards, APIs, and portals.
  • Individuals whose personal data may be processed through customer use of our services.

This Privacy Policy should be read together with our Terms of Service, Cookie Policy, and, where applicable, our Data Processing Agreement.

2. Our Role

Depending on the context, AhuraSense may act as a data fiduciary/controller or as a data processor/service provider.

When AhuraSense Acts as Data Fiduciary or Controller

We act as a data fiduciary/controller when we decide why and how personal data is processed. This includes processing for account registration, billing and payments, customer onboarding, identity verification, security monitoring, fraud prevention, product analytics, marketing, customer support, legal compliance, and business administration.

When AhuraSense Acts as Processor

We act as a processor when we process Customer Data on behalf of a customer according to the customer's instructions. Customers may upload, host, process, train, infer, store, or transmit data using our infrastructure services. In such cases, the customer is generally responsible for determining the purpose and means of processing.

Where legally required, our Data Processing Agreement governs this processing.

3. Personal Data We Collect

Account Information

When you create or manage an account, we may collect name, business name, email address, phone number, job title, username, password or authentication credentials, organization name, account role, team members, billing profile, business verification details, tax information, and communications preferences.

Identity and Verification Information

For certain services — especially high-value infrastructure, GPU resources, domain services, or compliance-sensitive products — we may collect business registration details, government-issued business identifiers, authorized representative details, billing verification information, use-case information, compliance certifications, sanctions screening information, and fraud risk signals.

Billing and Payment Information

We may collect billing name, billing address, tax registration details, purchase orders, invoices, payment status, payment method metadata, transaction history, usage records, and credit, deposit, prepaid balance, or commitment details. Payment card or bank details may be processed by third-party payment processors. We generally do not store full payment card numbers unless expressly stated.

Technical and Usage Data

When you use our services, we may collect IP address, device information, browser type, operating system, login events, API request metadata, dashboard activity, resource usage (compute, GPU, storage, bandwidth), region and product selections, error logs, security events, system telemetry, performance metrics, quota usage, rate-limit events, and audit logs.

Customer Data

Customer Data may include files, datasets, prompts, inputs, outputs, model weights, checkpoints, embeddings, containers, images, code, secrets, configuration data, databases, object storage contents, logs submitted by customers, application data, and end-user data processed through customer workloads.

Customers remain responsible for their workloads, data, software, identities, configurations, end users, compliance, and business decisions.

Support and Communications Data

When you contact us, we may collect support ticket content, chat messages, emails, call notes, troubleshooting information, screenshots or logs you provide, feedback, survey responses, commercial discussions, and contract and order communications.

Cookies and Similar Technologies

We collect information through cookies and similar technologies as described in our Cookie Policy, including session identifiers, consent preferences, analytics events, referral sources, device information, security tokens, and dashboard preferences.

4. How We Use Personal Data

To Provide the Services

We process personal data to create and manage accounts, authenticate users, provision cloud resources, provide dashboards and APIs, enable compute, GPU, database, Kubernetes, storage, domain, security, and deployment services, process AI inference and training workloads, provide support, and maintain service availability.

To Secure the Services

We use personal data and technical data to detect unauthorized access, prevent fraud, investigate abuse, protect infrastructure, monitor suspicious activity, enforce access controls, manage vulnerabilities, respond to security incidents, and protect customers and third parties.

To Bill and Manage Commercial Relationships

We use personal data to generate invoices, calculate usage-based charges, process payments, manage prepaid balances, apply taxes, resolve billing disputes, manage subscriptions and commitments, enforce payment obligations, and provide account notices.

To Improve and Develop Services

We may use personal data, usage data, aggregated data, and de-identified data to improve product functionality, develop new features, improve documentation, measure service performance, analyze product adoption, improve onboarding and customer support, plan capacity, and enhance reliability and security.

Unless separately agreed in writing, we do not use Customer Data to train foundation models for AhuraSense or third parties.

To Communicate With You

We may use contact information to send account notices, security alerts, billing notices, product updates, maintenance notices, support responses, contract notices, policy updates, service announcements, and marketing communications where permitted. You may opt out of non-essential marketing communications while still receiving transactional, security, legal, and service-related communications.

To Comply With Law

We may process personal data to comply with tax laws, accounting requirements, court orders, government and law-enforcement requests, export control obligations, sanctions screening, domain registry rules, data protection laws, security and incident reporting requirements, and legal claims and dispute resolution.

Data Handling

6. Sharing of Personal Data

Service Providers

We may share data with service providers for cloud infrastructure, data centers, network connectivity, payment processing, email delivery, analytics, security monitoring, customer support, error tracking, identity verification, CRM systems, and accounting and invoicing.

Infrastructure and Technology Partners

We may rely on third-party facilities, hardware vendors, connectivity providers, domain registries, DNS providers, cloud suppliers, and software providers. These parties may process data where required to provide the services.

Legal, Security, and Compliance Recipients

We may disclose data where necessary to comply with law, respond to valid legal requests, enforce our Terms, investigate abuse, protect security, prevent fraud, protect rights, property, and safety, or address sanctions and export-control concerns.

Business Transfers

If we are involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, personal data may be transferred as part of that transaction, subject to appropriate confidentiality and legal protections.

7. International Transfers

We may process and store data in India, the United Kingdom, and other countries where we, our service providers, infrastructure partners, or customers operate.

Where applicable law requires safeguards for cross-border transfers, we will use appropriate mechanisms such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, adequacy decisions, transfer impact assessments, documented customer instructions, or other lawful transfer tools.

For EU/EEA and UK personal data, GDPR Article 28 requires specific controller-processor terms, including documented instructions, confidentiality, security, subprocessor controls, assistance with data subject rights, deletion or return, and audit support. Those terms are set out in our Data Processing Agreement.

Transfers of digital personal data outside India are made in accordance with the Digital Personal Data Protection Act 2023 and any restrictions notified by the Central Government in respect of particular territories.

8. Security

We maintain administrative, technical, and organizational measures designed to protect personal data and the services, including:

  • Access controls and authentication.
  • Logging, monitoring, and network security.
  • Encryption where appropriate.
  • Vulnerability management and incident response processes.
  • Supplier review, backup, and recovery controls.
  • Segregation of environments and security reviews.

Our security programme is designed to align with recognised industry frameworks for information security management. Detailed technical and organisational measures are described in Schedule 2 of our Data Processing Agreement.

No security system is perfect. Customers must also secure their workloads, credentials, applications, containers, databases, APIs, models, secrets, storage buckets, and access policies.

9. Data Retention

We retain personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing services, maintaining accounts, billing and tax compliance, security monitoring, fraud prevention, legal compliance, dispute resolution, contract enforcement, and audit purposes.

Customer Data retention depends on the applicable service, order, configuration, and customer instructions. After termination or expiry, Customer Data may be deleted or disabled after the period stated in the Terms of Service or applicable agreement.

We may retain logs, billing records, security records, legal records, and backup copies for legitimate business, compliance, security, or dispute purposes.

10. Sale and Sharing of Personal Data

AhuraSense does not sell Customer Data. AhuraSense does not sell personal data for monetary consideration as part of its ordinary business model.

Where privacy laws define "sale", "sharing" or targeted advertising more broadly than a conventional monetary sale, certain advertising or analytics technologies may be treated as sharing under those laws. Where applicable, AhuraSense will provide legally required consent or opt-out mechanisms.

Customer workload content is not provided to advertising providers for targeted advertising.

Your Rights

11. Privacy Rights and Choices

Depending on applicable law, individuals may have rights to:

  • Access, correct, or delete personal data.
  • Withdraw consent and object to or restrict certain processing.
  • Receive a copy of personal data and file a complaint.
  • Nominate another person to exercise rights where applicable.
  • Request information about processing.

Individuals in the EU/EEA and the UK may exercise the rights provided under Articles 15 to 22 of the GDPR and UK GDPR, and may lodge a complaint with their supervisory authority. Data Principals in India may exercise the rights of access, correction, erasure, grievance redressal, and nomination provided under the Digital Personal Data Protection Act 2023, and may escalate an unresolved grievance to the Data Protection Board of India.

Where AhuraSense acts as a processor for Customer Data, we may direct requests to the relevant customer unless legally required to respond directly. To submit a request, email [email protected]. We may need to verify your identity before responding, and we will respond within the period required by applicable law.

12. Children’s Data

Our services are intended for business and developer use. They are not intended for children, and we do not knowingly collect personal data directly from children.

Customers must not use the services to collect or process children's personal data unless they have a lawful basis, required consents, appropriate safeguards, and written agreement from AhuraSense where required. Under India's Digital Personal Data Protection Act 2023, processing the personal data of a child generally requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring, and targeted advertising directed at children are prohibited.

If we become aware that we have collected personal data from a child without an appropriate legal basis, we will take reasonable steps to delete it.

13. Marketing Communications

We may send marketing communications about our products, services, events, updates, and offers where permitted by law.

You may opt out of marketing emails by using the unsubscribe link or contacting us. Opting out of marketing does not affect transactional, legal, billing, security, or service-related communications.

14. Automated Decision-Making, Fraud Detection and Profiling

AhuraSense may use automated tools to help detect fraud, account takeover, payment risk, abuse, malware, suspicious network activity, unusual resource consumption, sanctions risk and attempts to circumvent platform controls.

These systems may analyse technical and account information including IP addresses, authentication events, payment indicators, account history, resource usage, network behaviour, device characteristics, geographic signals and other relevant risk indicators. Automated tools may flag an account or transaction for further review, temporarily restrict particular actions, request additional verification, or prioritise an investigation.

Where Applicable Law provides a right concerning decisions based solely on automated processing that produce legal or similarly significant effects, AhuraSense will provide the rights required by that law. Where practicable and appropriate, material account restrictions based on risk signals are subject to human review before permanent adverse action is taken, except where immediate action is reasonably necessary to prevent fraud, active security threats, prohibited content, sanctions violations or imminent harm.

Customers may contact [email protected] or [email protected] to request review of an account decision where a review mechanism is legally required or otherwise available.

Cloud & AI

15. Customer Responsibilities

Customers are responsible for:

  • Ensuring they have the right to upload and process Customer Data.
  • Providing required notices to their users and obtaining required consents.
  • Selecting appropriate regions, services, access controls, and encryption choices.
  • Managing retention, deletion settings, and data subject requests concerning Customer Data.
  • Ensuring compliance with applicable laws.

Customers must not upload personal data, regulated data, health data, payment card data, government secrets, biometric data, children's data, or other sensitive data unless the applicable service, order, and data protection terms permit it and appropriate safeguards are implemented.

16. AI Workloads and Privacy

Customers may use AhuraSense services for AI inference, fine-tuning, training, embedding generation, evaluation, model hosting, and related workloads. Prompts, inputs, outputs, training and evaluation datasets, embeddings, checkpoints, adapters, and model weights that a customer submits to or generates on our infrastructure are Customer Data. We process them as a processor, on the customer's documented instructions, solely to provide, secure, and support the services.

Unless separately agreed in writing, AhuraSense does not use Customer Data — including prompts, outputs, datasets, or model weights — to train, fine-tune, or evaluate foundation models for AhuraSense or for any third party, and does not sell Customer Data or make it available to other customers.

Operating an inference or training platform necessarily produces logs. For hosted inference endpoints we record operational metadata such as timestamps, model identifier, endpoint, token and request counts, latency, error codes, and account identifiers, which we use for billing, capacity planning, abuse prevention, and troubleshooting. Prompt and output content is not retained in our operational logs by default; where a customer enables a logging, tracing, evaluation, or debugging feature that persists request content, that content is stored within the customer's own resources under the retention settings the customer selects. Content may be retained for a short period beyond a request only where necessary to deliver the service, investigate a specific incident the customer has reported, or comply with a legal obligation.

Customers using AI workloads remain responsible for:

  • Dataset rights, privacy notices, lawful bases, and consent for training and inference data.
  • Data minimisation, sensitive data safeguards, and de-identification where appropriate.
  • Bias, safety, and robustness testing, and model licence compliance.
  • Output review, human oversight where required, and downstream use of generated content.
  • End-user disclosures, retention and deletion settings, and applicable AI and sectoral regulation.

17. Sensitive and Regulated Data

Our standard services are not offered as a compliance-qualified environment for every category of regulated data. Customers must not upload or process highly sensitive or regulated data unless the applicable service description, Order Form, and data protection terms expressly permit it. Restricted categories include:

  • Health, medical, and genetic data, including data subject to sector-specific health privacy laws.
  • Biometric identifiers and biometric templates.
  • Children's personal data.
  • Payment card data within the scope of PCI DSS, and financial account credentials.
  • Government, defence, or classified information and authentication secrets belonging to third parties.
  • Special-category data under GDPR Article 9, criminal offence data under Article 10, and equivalent categories under other applicable laws.

Where such processing is expressly permitted, the customer must implement safeguards proportionate to the risk — including encryption in transit and at rest, strict access control and least privilege, comprehensive audit logging, defined retention and deletion schedules, a completed data protection impact assessment where required, and any sector-specific controls mandated by law or by the customer's own regulator.

AhuraSense may suspend or restrict processing where it reasonably believes that sensitive or regulated data is being processed outside the scope of the applicable agreement, or where continued processing would expose either party to material legal or security risk. Customers must notify us before introducing a new category of regulated data into an existing workload.

18. Third-Party Services

Our websites and services may link to or integrate with third-party websites, registries, payment processors, model providers, software repositories, documentation, marketplaces, or integrations.

Where you choose to enable a third-party integration, that provider processes data under its own terms and privacy policy, and as an independent controller in respect of the data it receives. We are not responsible for the privacy practices of third parties. You should review their privacy policies before using them.

19. Recruitment and Applicant Data

Where you apply for employment, internship, consulting work or another role with AhuraSense, we may process information contained in your application, CV or résumé, portfolio, professional profiles, communications, interview notes, technical assessments, employment history, education, compensation expectations, references and information you voluntarily provide during recruitment.

We process applicant information to evaluate suitability, communicate with applicants, arrange interviews, verify qualifications where appropriate, maintain recruitment records, comply with employment and legal obligations, protect our legitimate interests and, where permitted, consider candidates for future opportunities.

Access to applicant information is limited to personnel and service providers involved in recruitment, legal, compliance, human resources and hiring decisions. Applicant information is retained only for as long as reasonably required for the recruitment process, legal obligations, dispute management and future consideration where permitted.

Where Applicable Law gives an applicant access, correction, deletion or other privacy rights, those rights may be exercised through [email protected].

Legal

20. Changes to Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in law, services, security practices, or business operations.

We will post the updated policy on our website or otherwise notify you where required. Continued use of the services after the effective date means you accept the updated policy, where permitted by law.

21. Contact and Grievance Details

For privacy enquiries, Data Principal requests, Data Subject requests, complaints and data-protection matters, contact:

AhuraSense Technologies Private Limited

  • CIN: [INSERT MCA-REGISTERED CIN]
  • Registered Office: 2/26 Umiya Nagar, Nirnay Nagar, Ahmedabad, Gujarat 382481, India
  • Privacy and Data Protection: [email protected]
  • Legal: [email protected]
  • Grievance Contact / Officer: [INSERT NAME OR DESIGNATION REQUIRED BY APPLICABLE LAW]
  • Telephone: [INSERT BUSINESS CONTACT NUMBER]

AhuraSense will maintain a grievance mechanism and respond within the period required by applicable law. Where AhuraSense acts solely as a processor on behalf of a Customer, requests concerning Customer Personal Data may be referred to the Customer that determines the purpose and means of the processing.

Data Principals in India may exercise rights available under the Digital Personal Data Protection Act 2023 and applicable rules as those provisions come into force. Individuals in the EEA, UK and other jurisdictions may exercise rights available under the data-protection law applicable to them.

For UK and EEA enquiries, you may also contact our UK entity, AhuraSense Ltd, 20 Wenlock Road, London, England N1 7GU, United Kingdom, at [email protected].