Legal · v2.0.0
Privacy Policy
Last updated 2026-09-04.
This Privacy Policy explains how The Deep Intelligence (also trading as Deepint AI; “we”, “us”, “our”), registered in India under GSTIN 29CKBPM5980N1ZD, collects, stores, uses and shares (together, “processes”) personal data when you use our services (the “Services”) - for example when you visit https://deepintshield.com or any other website of ours that links to this Policy, sign in to the DeepintShield dashboards at https://app.deepintshield.com, call our APIs, install our SDKs, or interact with us through sales, marketing or events. For the purposes of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) we are the Data Fiduciary for the personal data described in this Policy, except for Customer Data, which we process on your instructions as described in Section 1.
Reading this notice will help you understand your rights and choices. If you do not agree with our practices, please do not use the Services. For questions, write to legal@deepintshield.com or call +91 99726 63800.
Summary of key points
This summary captures the headline points; full detail follows the table of contents below.
- What we process. When you use the Services, we may process personal information depending on how you interact with us, the choices you make and the features you use. See Section 1.
- Sensitive categories. We do not routinely process sensitive personal data or information as defined under the SPDI Rules, 2011 or the DPDP Act, 2023.
- Third-party data. We do not buy personal information about you from third parties.
- How we use it. To provide, operate, secure, support and improve the Services, to comply with law, and (with your consent) for product communications. See Section 2.
- Where it is hosted. Our production systems run on Google Cloud Platform in the United States (region us-central1, Iowa); we operate from India. See Section 7.
- Sharing. Only with the sub-processors and categories of recipients described in Sections 4 and 17, under appropriate confidentiality and data-protection obligations.
- Cookies. Our website uses a consent banner; analytics cookies are set only if you allow them. See Section 5.
- Security and breaches. We use the safeguards described in Section 9 and notify you and the Data Protection Board of India of qualifying breaches within the statutory timelines.
- Your rights. Under the DPDP Act, 2023 you have rights of access, correction, erasure, withdrawal of consent, nomination and grievance redressal. See Section 11.
- How to exercise them. Write to legal@deepintshield.com from the email associated with your account. Our Grievance Officer is named in Section 15.
Table of contents
- What information do we collect?
- How do we process your information?
- What legal bases do we rely on to process your personal information?
- When and with whom do we share your personal information?
- Do we use cookies and other tracking technologies?
- How do we handle your social logins?
- Is your information transferred internationally?
- How long do we keep your information?
- How do we keep your information safe?
- Do we collect information from minors?
- What are your privacy rights?
- Controls for Do-Not-Track features
- Do Indian residents have specific privacy rights?
- Do we make updates to this notice?
- How can you contact us about this notice? (Grievance Officer)
- How can you review, update or delete the data we collect from you?
- Sub-processors
- Version history
1. What information do we collect?
Personal information you provide. We collect personal information that you voluntarily provide when you register for the Services, request information about us, take part in features, or otherwise contact us. The information we collect depends on how you interact with the Services and may include your name, email address, organisation, role, password (stored as a one-way hash), your confirmation at registration that you are at least eighteen (18) years old, and any other information you choose to share with us.
Sensitive information. We do not request and do not knowingly process sensitive personal data or information (as defined under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 - the “SPDI Rules”) for our own purposes. You should not submit sensitive personal data through the Services unless your use case strictly requires it; if you do, you remain the controller of that data and must have the lawful basis to do so.
Payment data. If you make a purchase, we may collect data needed to process the payment, such as a payment-instrument identifier and tokens issued by our payment processor, Razorpay Software Private Limited. We do not store full card numbers, CVVs or full bank-account details - these are handled by the processor under its own privacy notice. Indian customers may be asked for a GSTIN and PAN to enable tax invoicing under the Central Goods and Services Tax Act, 2017 and the Income-tax Act, 1961.
Purchase and consent records. When you accept our legal terms or purchase a paid plan we record your name, account email, the document versions you accepted, the date and time, your IP address, browser user agent and language setting, and the subscription details, and we generate a sealed PDF record of the agreement (see Section 23 of the Terms and Conditions). We keep these records to evidence the contract and to meet our legal obligations.
Social login data. Where you choose to sign in via Google, Microsoft Entra or another single sign-on (SSO) provider, we receive identity-provider data as described in Section 6.
All personal information you provide to us must be true, complete and accurate. Please notify us of any changes.
Customer Data. Prompts, completions, tool inputs and outputs, documents, embeddings and configuration that you or your users submit through the gateway (“Customer Data”) are processed on your instructions to provide the Services. You decide what Customer Data is submitted and remain responsible for it; where it contains personal data of your users, you are the Data Fiduciary (or controller) and we act as your Data Processor. We do not use Customer Data to train our models or any third party’s models.
Information we collect automatically. Some information is collected automatically when you visit or use the Services. It does not, by itself, identify you, but may include device and usage information, such as your Internet Protocol (IP) address, user agent, operating system, language preference, referring URLs, locale, approximate region, and information about how and when you use the Services. We collect this primarily to operate and secure the Services and for internal analytics. Categories include:
- Log and usage data. Service-related diagnostic, usage and performance information that our servers automatically collect when you access or use the Services and that we record in log files. Depending on how you interact with us, this may include your IP address, browser type and settings, the date and time of your activity, the pages or features used, error reports, and hardware settings.
- Device data. Information about the computer, phone, tablet or other device used to access the Services, which may include device identifiers, browser type, hardware model, internet-service or mobile-network operator, operating system and configuration.
- Approximate location. An approximate region derived from your IP address. We do not collect precise GPS location.
2. How do we process your information?
We process personal information for a variety of reasons, depending on how you interact with the Services, including:
- Account creation and authentication. So you can create and log in to your account and manage user provisioning.
- Service delivery. To deliver the Services you have requested, including routing, governance, virtual-key management and audit logging.
- Support. To respond to your enquiries and resolve issues you raise.
- Service messages. To send security alerts, billing notices, renewal reminders, receipts and tax invoices, password resets, changes to legal terms and other operational communications you cannot opt out of for as long as you have an account.
- Order management. To process payments, manage subscriptions, raise tax invoices and respond to refund or chargeback claims.
- Compliance records. To create, seal, store and email the record of your acceptance of our legal terms when you purchase a plan, and to retain consent and invoice records for the periods set out in Section 8.
- Feedback. To request feedback from you and to contact you about your experience with the Services.
- Marketing communications. To send product updates and event invitations where you have separately opted in. You can opt out at any time using the link in any marketing email.
- Security and abuse prevention. To detect, investigate and respond to fraud, abuse and security incidents.
- Product improvement. To compute aggregated, de-identified analytics that help us improve the Services. We do not use Customer Data to train our models or any third party’s models.
- Marketing effectiveness. To understand which campaigns are useful and to improve their relevance.
- Vital interests. Where necessary to save or protect a person’s vital interests, such as preventing imminent harm.
- Legal obligations. To comply with our obligations under Indian law, including the Information Technology Act, 2000, the DPDP Act, 2023, GST law and applicable record-retention rules.
3. What legal bases do we rely on to process your personal information?
We process personal information only when we have a valid lawful basis under applicable data-protection law. As a Data Fiduciary under the DPDP Act, 2023, we rely on the following grounds:
- Consent. Where you have given us specific, informed, free and unambiguous consent for a defined purpose - for example, to create an account, to opt in to marketing emails, or to enable a non-essential feature. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Legitimate uses. The DPDP Act, 2023 (§7) recognises specified “legitimate uses” including providing services or benefits explicitly requested, complying with law, performing functions under law and responding to medical or other emergencies. We rely on these where applicable.
- Contractual necessity. Where processing is required to deliver the features described in our Terms and Conditions.
- Compliance with legal obligations. Where we are required to process information to comply with Indian law (for example, tax-invoicing under §31 of the CGST Act, 2017, lawful interception under §69 of the Information Technology Act, 2000, or court orders).
- Vital interests. Where processing is necessary to protect the vital interests of you or another natural person.
If you are accessing the Services from the European Economic Area or the United Kingdom, we additionally rely on the lawful bases set out in the General Data Protection Regulation and the UK GDPR (consent, performance of a contract, legitimate interests, legal obligation and vital interests). Customers in Canada, Singapore or other regions may rely on equivalent local concepts including express and implied consent. Where we rely on legitimate interests, we have considered whether those interests are overridden by your fundamental rights and freedoms and can describe that assessment on request.
4. When and with whom do we share your personal information?
We share personal information only as needed to operate the Services and only with parties bound by appropriate confidentiality and data-protection obligations:
- Cloud hosting and database provider (Google Cloud Platform), which hosts the gateway, dashboards, audit logs, billing systems, backups and back-office tools.
- Identity providers (Google, Microsoft Entra and other SSO sources you choose to use).
- Model and tool providers you select to route traffic to. Your prompts and tool inputs flow to that provider on your instructions; we are not responsible for their independent processing under their own privacy notices.
- Payment and tax processors (Razorpay) for billing, refunds and statutory compliance.
- Email-delivery and customer-support tools we use to send transactional emails and respond to your tickets.
- Website analytics (Google Analytics 4 on deepintshield.com), only where you allow the Statistics category in the cookie banner.
- Observability and security tools used to monitor uptime, errors and abuse - typically receiving metadata only.
- Professional advisors (auditors, legal counsel, tax advisors) under confidentiality obligations.
- Acquirers and successors in the event of a merger, acquisition, reorganisation or sale of substantially all of our assets, with notice to you.
- Public authorities and courts where compelled by lawful order under Indian law (including §69 and §69A of the Information Technology Act, 2000, the Bharatiya Nagarik Suraksha Sanhita, 2023 and successor statutes) or by comparable foreign law.
- With your consent for any disclosure outside the cases described above.
Our current sub-processors are listed in Section 17. We will notify account owners by email at least thirty (30) days before we add or replace a sub-processor that processes personal data, so that you can object or terminate. We do not sell personal information.
5. Do we use cookies and other tracking technologies?
We use cookies and similar technologies (such as web-storage entries) as described below. On the Site (deepintshield.com) a consent banner lets you choose which optional categories to allow; you can change your choice at any time using the “Manage consent” control on the Site.
- Strictly necessary and functional cookies for session management, CSRF protection, load-balancer affinity and remembering your cookie choices (the consent cookie is kept for up to twelve (12) months). These cannot be disabled if you want to remain signed in.
- Preferences entries for theme, sidebar state, language and dismissal of UI prompts.
- Statistics. On the Site we use Google Analytics 4 (provided by Google LLC) to understand page-level usage. It is loaded only if you allow the Statistics category. Google Analytics 4 does not log or store IP addresses, and we have not enabled Google signals or advertising features. Inside the DeepintShield dashboards we use only first-party, page-view-level product analytics.
- Marketing. The consent banner offers a Marketing category for completeness; we do not currently set any marketing or advertising cookies, run retargeting pixels or use device fingerprinting. If that changes, we will list the vendors here and seek your consent through the banner first.
Most browsers allow you to refuse or clear cookies through their settings; doing so for strictly-necessary cookies will break login. We honour Global Privacy Control signals where the law of your region requires it.
6. How do we handle your social logins?
The Services may let you sign in or register using a social or enterprise identity provider, such as Google, Microsoft Entra or another SSO source. When you do, we receive certain profile information from that provider - typically your name, email address, profile picture (if available) and provider-issued user identifier.
We use the information we receive only to enable sign-in, to display your account profile and (where you have granted us specific permissions) to populate your workspace. We do not control the privacy practices of the identity provider; please review the provider’s own privacy notice to understand how they collect, use and share information.
7. Is your information transferred internationally?
We are established in India, and our production infrastructure - including the gateway, dashboards, databases, logs and backups - is hosted on Google Cloud Platform in the United States (region us-central1, Iowa). Personal data collected from you is therefore stored and processed in the United States and accessed by our team from India. Some sub-processors listed in Section 17 (for example our payment and email providers) process data in India or in other countries where they operate.
Transfers outside India are made in accordance with §16 of the DPDP Act, 2023, which permits transfer to any country not restricted by the Central Government; no such restriction applies to the United States at the date of this Policy. Our contracts with sub-processors include confidentiality, security and data-protection obligations. Enterprise customers who need their data to remain in India or in the European Union may choose a dedicated deployment in the India (asia-south1) or EU region under a separate written agreement.
If you are in the European Economic Area or the United Kingdom, transfers of your personal information outside that region are made under safeguards that meet the requirements of the GDPR and the UK GDPR - the EU Standard Contractual Clauses or the UK International Data Transfer Addendum in our agreements with sub-processors, with supplementary measures where needed.
EU and UK representative. We have not appointed a representative under Article 27 of the GDPR or Article 27 of the UK GDPR because our processing of personal data of individuals in the EEA and the UK is occasional, does not involve large-scale processing of special categories of data and is unlikely to result in a risk to their rights and freedoms. We will appoint a representative and update this Policy if that assessment changes.
8. How long do we keep your information?
We retain personal information only as long as necessary for the purpose for which it was collected, plus any additional period required by law. Indicative retention periods:
- Account records: for the life of the account and up to ninety (90) days after closure, unless statutory retention applies.
- Authentication and security logs: typically twelve (12) months, longer where investigation or legal hold is required.
- Billing records and tax invoices: at least eight (8) years, in line with §36 of the Central Goods and Services Tax Act, 2017.
- Signed subscription agreements and purchase-consent records: eight (8) years from the end of the subscription, aligned with tax-record retention, as evidence of the contract.
- Records of consent to legal terms: for the life of the account plus the limitation period under the Limitation Act, 1963.
- Customer Data: under your control and retained per your account configuration; deleted on your verified request or within ninety (90) days of account closure, subject to legal exceptions.
When we no longer need personal information, we will delete or anonymise it; if that is not feasible (for example, where data is held in backup) we will isolate it from further processing until deletion is possible.
9. How do we keep your information safe?
We use technical and organisational measures appropriate to the risk and consistent with industry practice to protect personal information, including encryption in transit, encryption at rest for primary data stores, hashed credential storage, role-based access control, audit logging, the principle of least privilege, network segmentation, vulnerability management and incident-response procedures.
However, no electronic transmission over the internet or storage technology can be guaranteed to be secure; we cannot promise that unauthorised third parties will not be able to defeat our security and improperly collect, access, steal or modify your information.
Breach notification. If a personal data breach occurs, we will: (a) notify each affected Data Principal without delay, describing the breach, its likely consequences, the measures we are taking and how to contact our Grievance Officer; (b) notify the Data Protection Board of India without delay and provide the detailed report required by rule 7 of the Digital Personal Data Protection Rules, 2025 within seventy-two (72) hours of becoming aware of the breach, or such longer period as the Board permits; and (c) report the incident to the Indian Computer Emergency Response Team (CERT-In) within six (6) hours of noticing it, as required by the CERT-In directions of 28 April 2022 issued under §70B(6) of the Information Technology Act, 2000. Where the GDPR or UK GDPR applies, we will also notify the competent supervisory authority within seventy-two (72) hours where required.
10. Do we collect information from minors?
The Services are not directed to children under eighteen (18). When you register we ask you to confirm, by ticking the acceptance box, that you are at least 18 years of age. We do not knowingly collect personal data from, market to, or track or profile the behaviour of anyone under 18. If we learn that personal data of a child has been collected without the verifiable consent of a parent or lawful guardian required by §9 of the DPDP Act, 2023 and rule 10 of the Digital Personal Data Protection Rules, 2025, we will delete it. If you believe a child has provided us with personal data, please contact legal@deepintshield.com.
11. What are your privacy rights?
Under the DPDP Act, 2023 and other applicable law, you have the following rights:
- Access. A summary of personal information we process about you and the categories of recipients with whom we have shared it.
- Correction. Correction of personal information that is inaccurate, incomplete or misleading.
- Updating and completion. Updating or completing personal information held about you.
- Erasure. Erasure of personal information that is no longer needed for the purpose for which it was collected, subject to legal retention obligations.
- Withdrawal of consent. Withdrawal of consent at any time, with effect from the time of withdrawal, through a process as easy as the one you used to give it.
- Nomination. Nomination of another individual to exercise your rights in the event of your death or incapacity, in line with §14 of the DPDP Act, 2023.
- Grievance redressal. A right to lodge a grievance with our Grievance Officer, whose details are in Section 15, and, if not satisfied, to escalate to the Data Protection Board of India.
- Consent Manager. Once Consent Managers registered with the Data Protection Board of India are operational, you may give, manage, review and withdraw consent through such a Consent Manager in addition to contacting us directly.
If you are in the European Economic Area or the United Kingdom and believe we are unlawfully processing your personal information, you also have the right to lodge a complaint with your local data-protection authority. To exercise any right, write to legal@deepintshield.com from the email associated with your account or by another verified channel we may reasonably request. We will respond within thirty (30) days of verifying your identity - within the maximum period permitted by the Digital Personal Data Protection Rules, 2025 - and, where a request is complex, we will tell you why and when to expect a full answer.
Withdrawing consent. Where we rely on consent, you may withdraw it at any time. You can also opt out of marketing emails through the unsubscribe link in any marketing email. Operational messages cannot be opted out of for as long as your account is active.
12. Controls for Do-Not-Track features
Most web browsers and some mobile operating systems include a Do-Not-Track (“DNT”) signal you can activate to express your preference not to have data about your online activities monitored and collected. There is currently no agreed technical standard for recognising and acting on DNT signals, and we do not currently respond to them. If a final standard is adopted in future, we will update this Policy to describe how we honour the relevant signal. Global Privacy Control signals are handled as described in Section 5.
13. Do Indian residents have specific privacy rights?
If you are a resident of India, you have specific privacy rights under the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the SPDI Rules, 2011, summarised below.
- Notice. A right to receive a clear notice of the personal data being processed and the purpose for which it is processed (§5 of the DPDP Act, 2023).
- Consent. A right to give and to withdraw free, informed, specific, unconditional and unambiguous consent (§6).
- Access, correction and erasure. Rights of access (§11), correction and erasure (§12) of your personal data.
- Grievance redressal. A right to grievance redressal (§13) and to escalate to the Data Protection Board of India.
- Nomination. A right to nominate another person to exercise your rights in the event of your death or incapacity (§14).
- Duties. The DPDP Act, 2023 also imposes duties on Data Principals (§15), including not registering false or frivolous grievances and providing authentic information when exercising rights of correction or erasure.
The contact details of our Grievance Officer are published in Section 15. If you are not satisfied with how a grievance is handled, you may approach the Data Protection Board of India.
Other regions. Customers located in the European Economic Area, the United Kingdom, California or other jurisdictions may have additional rights under their local law. Please contact us using the details below to exercise those rights.
14. Do we make updates to this notice?
We may update this Privacy Policy from time to time to reflect changes in our practices, in technology or in applicable law. The date at the top of this page tells you when it was last updated. Where the changes are material, we will notify you by email or through the Services at least fifteen (15) days before they take effect and, where required, request fresh acceptance the next time you sign in. We encourage you to review this Policy from time to time to stay informed about how we protect your information.
15. How can you contact us about this notice? (Grievance Officer)
In line with rule 5(9) of the SPDI Rules, 2011, rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, rule 4(4) of the Consumer Protection (E-Commerce) Rules, 2020 and §8(9), §8(10) and §13 of the DPDP Act, 2023, we have appointed the following Grievance Officer, who is also the person able to answer your questions about the processing of your personal data:
Grievance Officer and Nodal Officer, The Deep Intelligence
Alpine Fiesta, Hoodi Main Road
Saketha Nagar Layout, Hoodi
Bengaluru 560048, Karnataka, India
Email: legal@deepintshield.com
Telephone: +91 99726 63800
We acknowledge every grievance within twenty-four (24) hours of receipt and resolve it within fifteen (15) days, or within thirty (30) days at the latest where the matter is complex - well within the maximum period allowed under the Digital Personal Data Protection Rules, 2025. You will receive a reference number for each grievance. For general questions about this notice, write to legal@deepintshield.com; for operational support, write to support@deepintshield.com.
16. How can you review, update or delete the data we collect from you?
Based on applicable law, you have the right to request access to the personal information we hold about you, details of how we have processed it, correction of any inaccuracies, withdrawal of consent or erasure of your personal information, subject to legal retention obligations. To make any such request, please write to legal@deepintshield.com from the email associated with your account, or use the in-product controls where available. You can download your signed agreements and consent history from Account → Legal, and update your profile from Account settings. We may need to verify your identity before responding.
17. Sub-processors
We use the following third parties to process personal data on our behalf. Each is bound by a written agreement containing confidentiality, security and data-protection obligations. We will notify account owners by email at least thirty (30) days before we add or replace a sub-processor that processes personal data.
- Google Cloud Platform (Google LLC, United States) - cloud hosting of the gateway, dashboards, databases, logs and backups; region us-central1 (Iowa, United States).
- Razorpay Software Private Limited (Bengaluru, India) - payment processing, recurring billing and payment-instrument tokenisation; India.
- Hostinger International Ltd (European Union) - transactional email delivery (SMTP) for receipts, invoices, security alerts and legal notices.
- Google LLC (United States) - Google Sign-In, where you choose it as your identity provider, and Google Analytics 4 on deepintshield.com, only with your cookie consent.
- Microsoft Corporation (United States) - Microsoft Entra ID sign-in, only where your organisation chooses to use it.
Providers you select. Model, tool and infrastructure providers that you configure in the gateway (for example OpenAI, Anthropic, Google, Microsoft Azure, Amazon Web Services, a partner guardrail service or a self-hosted model) receive the prompts, tool inputs and content you route to them. They act on your instructions, not ours, and are not our sub-processors; their own privacy notices apply. Observability components (such as Langfuse) and the machine-learning safety detectors used by the Services run inside our own infrastructure and do not send data to a third party.
18. Version history
- v2.0.0 (2026-09-04). Named the Data Fiduciary’s proprietor and the Grievance Officer, with a telephone contact (Section 15); corrected the hosting location and cross-border transfer disclosure and added the EU/UK representative statement (Section 7); described the cookie categories, Google Analytics and the consent banner accurately (Section 5); added purchase and consent records and Customer Data (Section 1) and compliance-record purposes (Section 2); stated the breach-notification timelines under the DPDP Rules, 2025 and the CERT-In directions (Section 9); added the age confirmation and verifiable-consent statement (Section 10); fixed the grievance cross-reference and added Consent Managers and response times (Sections 11 and 15); added retention for signed agreements (Section 8); published the sub-processor list with a change-notice commitment (Section 17).
- v1.0.0 (2026-05-06). First published version.
The Deep Intelligence (also trading as Deepint AI) · GSTIN 29CKBPM5980N1ZD · Alpine Fiesta, Hoodi Main Road, Saketha Nagar Layout, Hoodi, Bengaluru 560048, Karnataka, India · Canonical URL: https://deepintshield.com/privacy-policy/