Privacy Policy
Version 1.0 · Effective 28 August 2026
This policy explains what personal data InfiniteAI Technology Private Limited (“InfiniteAI”, “we”, “us”) collects when you use TechRP, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it.
We have tried to write it in plain language. Where a sentence has to be precise for legal reasons, we have said the plain-language version too. If anything here is unclear, write to privacy@infiniteai.io and we will explain it.
1.Who we are, and which law applies
InfiniteAI Technology Private Limited is an Indian company. Our primary obligations are under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 and rules made under them.
We also grant every user, wherever they are, the same substantive rights the EU and UK General Data Protection Regulation provide — access, correction, erasure, portability, objection and restriction. We do this as a matter of policy because we think it is right, not because we currently maintain an establishment in the EU or UK.
Two different roles, and why the difference matters
Which of us answers a privacy request depends on whose data it is:
- For your own account data — your name, email, mobile, sign-in and billing records — we are the Data Fiduciary (in GDPR terms, the controller). Ask us directly.
- For the content inside your workspace — your customers, employees, invoices, documents and connected files — you are the Data Fiduciary and we are a Data Processor acting on your instructions. If one of your employees or customers asks about their data, they should ask you; we will help you answer.
2.What we collect
Account and identity
- Your full name, business email address and mobile number, given at signup.
- The name of the workspace (your business) you create.
- A one-way scrambled form of your password. We never store your password in a form anyone can read, including us.
- One-time verification codes, stored only in scrambled form and only until they expire.
- Session and refresh tokens, held in cookies your browser will not expose to scripts, or in your device's secure storage on mobile.
Sign-in with Google or Microsoft (single sign-on)
Where you choose to sign in with a Google or Microsoft account, we receive from that provider only your unique account identifier, your email address, your name, and where available your profile picture. We use these to identify you and create or match your account. We never receive your password for that account.
What you put into your workspace
This is your business data, and it may contain personal data about other people — typically your employees, customers and suppliers. It includes customer and vendor records, invoices and payments, inventory, staff records and payroll inputs, documents and their signature records. We process it only to provide the service to you.
Connected sources — Google Drive, OneDrive and SharePoint
These connections are entirely optional. If you connect one, we receive the file metadata and file content that the permission you granted allows, so that you can find and search those documents inside TechRP. See section 6 for exactly what we request and what we will never do with it.
Electronic signatures
When a document is sent for signature, we record each signer’s name and email address, the time they opened and signed it, their IP address, and a cryptographic hash of the signed document. This audit trail exists so a signature can be proved later, as contemplated by the Information Technology Act, 2000. It is deliberately not deletable while the signed document exists.
Payments
Subscription payments are processed by our payment provider. We receive the billing name, email, amount, and whether the payment succeeded. We never receive or store your full card number, CVV, or UPI PIN.
Voice commands
If you speak a command to Cortex, the audio is sent to our speech provider, converted to text, and used to carry out that one command. The recording is not retained by us after transcription.
Technical and usage data
- Your IP address, browser and device type, operating system, and language.
- Which pages and features you used, and when — so we can see what works and what does not.
- Errors and crashes, including the technical context needed to reproduce them.
- Security and audit logs, including sign-in attempts and administrative actions.
We engineer our logs, metrics and traces so that personal data does not enter them. Where an error report could incidentally capture such data, it is configured to be stripped before storage.
3.Why we process it, and on what basis
| Purpose | Data used | Basis |
|---|---|---|
| Create and operate your account and workspace | Account and identity | Performance of our contract with you |
| Verify it is really you (codes, sign-in, SSO) | Identity and authentication | Contract, and our legitimate interest in security |
| Provide the ERP features you use | Workspace content | Contract — and your instructions, where we act as processor |
| Read connected Drive/OneDrive files you authorise | Connected source content and metadata | Your consent, given at the moment you connect |
| Draft and assist through Cortex | The request, and the records needed to answer it | Contract, and your consent for voice |
| Bill you and collect payment | Billing and payment records | Contract, and legal obligation (tax records) |
| Send transactional email you asked for | Name and email | Contract |
| Measure and improve the product | Usage and error data | Legitimate interest, and consent where cookies require it |
| Keep the service secure and prevent abuse | Technical, audit and security logs | Legitimate interest, and legal obligation |
| Meet statutory record-keeping duties | Billing, tax and audit records | Legal obligation |
4.What we never do
- We do not sell or rent personal data. Not to advertisers, data brokers, or anyone else, in any form.
- We do not share your data with vendors for those vendors’ own purposes. The companies listed in section 7 process data only on our documented instructions, under contract, and may not use it for themselves.
- We do not use your business content to train AI models — ours or anyone else’s — and our AI provider is contractually barred from doing so.
- We do not read your documents to build advertising or profiling products. Files from a connected drive are indexed so that you can search them, and for nothing else.
- We do not let Cortex act on its own. Sending an invoice, taking a payment, signing a document and running payroll each require a person to approve.
5.Analytics and cookies
Strictly necessary cookies. Signing in sets two cookies that your browser will not expose to scripts: a short-lived session cookie and a longer-lived refresh cookie. The service cannot work without them, so they are set without asking — this is permitted, because they are necessary to deliver a service you requested.
Product analytics. We record which features are used, and errors and performance problems, so we can improve the product and fix faults. Where this is done through a third-party tool, that provider is listed in section 7.
Analytics on our public pages. On our marketing pages we may use analytics cookies to understand how people find us. These are not strictly necessary, so where the law requires it we ask for your consent before they are set, and you can decline without losing access to anything.
We do not use advertising cookies, and we do not permit third-party advertising trackers anywhere in the product.
6.Connected Google and Microsoft accounts
Connecting a Google, Microsoft or SharePoint account is optional, and TechRP works without it. When you connect one, you are shown exactly what is being requested and you can refuse.
What we ask for, and why
- Google Drive —
drive.readonly. Read-only access to the Drive files you authorise, so TechRP can list, index and search them. This scope cannot create, modify or delete anything in your Drive. - Microsoft OneDrive and SharePoint —
Files.Read.All,User.Readandoffline_access. Read-only access to the files you authorise, your basic profile, and the ability to refresh the connection so you do not have to sign in repeatedly.
We request read-only access deliberately, even though a narrower per-file scope exists, because searching across your existing document library is the entire purpose of the feature and a per-file scope cannot do it. We do not request write access.
Google API Services — Limited Use
TechRP’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, data obtained from Google APIs is:
- — used only to provide or improve the user-facing features you connected it for;
- — never transferred to others except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with notice to you;
- — never used for advertising, and never sold;
- — never read by a human, except with your explicit consent for a specific support request, where it is necessary for security or to comply with law, or where the data has been aggregated and anonymised.
We apply the same commitments to data obtained from Microsoft APIs.
Disconnecting
You can disconnect a source at any time from within TechRP. On disconnection we stop syncing immediately and delete the stored access credentials. You can additionally revoke our access from your Google account permissions or your Microsoft account.
7.Who else processes your data
We use a small number of service providers to run TechRP. Each is bound by contract to process personal data only on our instructions, to protect it, and never to use it for their own purposes.
| Provider | What it does | Location |
|---|---|---|
| Hostinger International Ltd. | Cloud hosting and infrastructure for the TechRP application and databases.All service data, at rest on encrypted volumes. | India / EU |
| Groq, Inc. | Powers Cortex — drafting assistance and speech-to-text for voice commands. Prompts are sent only when you invoke an AI feature.The text or audio of the request, plus the specific records needed to answer it. | United States |
| Razorpay Software Private Limited | Payment processing for subscription billing and, where enabled, invoice collection.Billing name, email, amount and payment status. We never receive or store full card numbers. | India |
| Email delivery provider | Sends transactional email — verification codes, invitations, invoices and notifications.Recipient name and email address, and the content of that message. | India / United States |
| Google LLC / Microsoft Corporation | Only where YOU connect a Google Drive, OneDrive or SharePoint account, or sign in with Google or Microsoft. These are your own accounts at your own providers.The files and metadata you authorise us to read, and your basic profile on sign-in. | As determined by your own provider account |
We may also disclose data where the law compels us to — a valid order from a court or a competent authority — and, if our business is ever merged or acquired, to the acquirer, with notice to you and under the same commitments.
8.Where your data is held, and transfers abroad
Your workspace data is hosted on servers in India and the European Union. Some providers in section 7 operate outside India — most notably our AI provider, which processes requests in the United States. Where personal data leaves India or the EEA, we rely on contractual protections with the receiving provider, including the European Commission’s Standard Contractual Clauses where they apply, and we transfer only what that provider needs to perform its function.
9.How we protect it
- A separate database for every business. Each workspace has its own database — not a shared table with a customer column. One workspace’s data is not reachable from another, even by a faulty query.
- Encryption. Data is encrypted in transit using TLS, and at rest on encrypted storage. Sensitive stored values such as provider credentials are additionally encrypted at the application layer.
- Access control that fails closed. Permissions are checked on the server on every request. A hidden button is never what makes something safe.
- No personal data in logs. Our logging, metrics and tracing are built so personal data does not enter them.
- Audit trails. Administrative and security-relevant actions are recorded.
Our staff’s access — stated plainly
Operating a service means some of our personnel can, technically, reach production systems on which customer data is stored. We will not pretend otherwise.
That access is restricted to a small number of authorised personnel, granted on a least-privilege, need-to-know basis, and used only to operate, secure, support or repair the service. It is never used to browse your business content out of curiosity or for any commercial purpose. Personnel are bound by confidentiality obligations, and misuse is a disciplinary matter.
No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as the DPDP Act requires, without undue delay, and tell you what happened and what to do about it.
10.How long we keep it
- Account data — for as long as your account is open, and up to 90 days after you close it, so it can be restored if closure was a mistake.
- Workspace content — for as long as your workspace exists. On deletion we remove it within 30 days, except where the law requires us to keep specific records.
- Invoices, payments and tax records — for eight years, as Indian tax and companies law requires.
- Signature audit trails — for as long as the signed document exists, because the signature cannot be proved without them.
- Security and audit logs — up to 12 months.
- Verification codes — minutes. Voice recordings — not retained after transcription.
- Connected-source credentials — deleted immediately when you disconnect.
11.Your rights
Under the DPDP Act, and as a matter of our policy for everyone regardless of location, you may:
- Ask what personal data we hold about you and get a copy of it.
- Have inaccurate or incomplete data corrected or completed.
- Ask us to erase your personal data, where we are not required to keep it.
- Withdraw a consent you gave — as easily as you gave it. Withdrawal does not undo processing already carried out lawfully.
- Receive your data in a portable, machine-readable form, or ask us to send it onward.
- Object to, or ask us to restrict, processing we carry out on the basis of legitimate interests.
- Nominate another person to exercise your rights if you die or become incapacitated, as the DPDP Act provides.
Write to privacy@infiniteai.io. We will respond within 30 days. We do not charge for this, and exercising a right will never cause us to degrade your service.
If the request concerns data inside someone’s workspace — for instance, you are an employee of a business that uses TechRP — please ask that business first. They control that data; we will help them respond.
12.Complaints
If you are unhappy with how we have handled your data or your request, contact our Grievance Officer:
Vimal Kacha
Grievance Officer, InfiniteAI Technology Private Limited
C/O Vimal Bhimjibhai Kacha, Brahmani Krupa, Opp. Derasar, Krunagar Main Road, Rajkot, Gujarat 360004, India
We will acknowledge your complaint and aim to resolve it within 30 days. If you remain dissatisfied, you may complain to the Data Protection Board of India.
13.Children
TechRP is business software and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.
14.Changes to this policy
We will update this policy as the product changes. Every version carries a version number and an effective date at the top. If a change materially affects your rights or how we use your data, we will tell you before it takes effect and, where the law requires it, ask for your consent again.
Related: our Terms of Use.
InfiniteAI Technology Private Limited · C/O Vimal Bhimjibhai Kacha, Brahmani Krupa, Opp. Derasar, Krunagar Main Road, Rajkot, Gujarat 360004, India · CIN U74999GJ2021PTC127588