Legal · Privacy
Your data, explained clearly.
This Privacy Policy explains how Anantya Labs (“Anantya”, “we”, “us”) collects, uses, shares, protects, retains, and deletes personal data when you use the Anantya Automation website, mobile applications, APIs, and related services (the “Service”).
1. Scope and roles
This Policy covers visitors, account holders, authorized team members, and people whose business contact information is processed in a customer workspace. For account and product data, Anantya acts as the data fiduciary/controller. When a customer uploads, discovers, or manages prospect data for its own outreach, the customer determines the purpose of that processing and is responsible for having a lawful basis; Anantya processes that data to provide the Service.
2. Data we collect
- Account and profile data: company name, account email, country, state, city, password hash, verification status, security preferences, and passkey metadata.
- Workspace configuration: company description, services, industries, locations, roles, outreach goals, sender details, campaign limits, integrations, and user-selected settings.
- Prospect and communication data: business names, public websites, public professional contact information, qualification notes, email drafts, delivery events, opt-out state, replies, and LinkedIn review-workspace records entered or generated by the user.
- Billing data: plan, transaction identifiers, payment status, and subscription state. Card, bank, or UPI credentials are handled by Razorpay or the applicable app store and are not stored by Anantya.
- Technical and security data: session identifiers, IP address, device and browser attributes, request logs, error diagnostics, authentication events, and abuse-prevention signals.
- Support data: messages, attachments, and information you provide when requesting help or exercising a privacy right.
3. How and why we use data
We use data to create and authenticate accounts; provide discovery, drafting, outreach, reply, billing, and security features; remember preferences; prevent fraud and misuse; troubleshoot and support the Service; meet legal obligations; enforce our Terms; and communicate important product, billing, security, or policy notices. Where consent is the appropriate basis, you may withdraw it, but this does not affect processing already lawfully completed.
4. AI-assisted features
The Service may send the minimum necessary company, prospect, campaign-goal, and draft context to the AI provider configured for your workspace. Do not submit sensitive personal data, confidential credentials, health data, financial-account data, or other information you are not authorized to process. AI output can be inaccurate and must be reviewed by a person before use.
5. When data is shared
We disclose data only as needed to operate the Service: hosting and infrastructure providers; email delivery and receiving services you configure; AI providers selected or configured for drafting; Razorpay and app-store payment providers; security, diagnostics, and support vendors; professional advisers; or authorities when legally required. Providers may use data only for the contracted purpose and are expected to apply appropriate confidentiality and security controls. We may also disclose data during a merger, financing, acquisition, or asset transfer, subject to this Policy and applicable law.
6. International processing
Some service providers may process data outside your state or country. Where required, we use contractual and organizational safeguards and assess whether the transfer is permitted. By selecting an external email, AI, hosting, or payment provider, you instruct us to transmit the data required for that integration.
7. Retention and deletion
- Account and workspace data is retained while the account is active and as needed to provide the Service.
- Operational logs are retained only for security, reliability, dispute resolution, and legal compliance, then deleted or de-identified.
- When you delete your account, access is revoked immediately. Workspace data enters restricted deletion staging and is scheduled for permanent removal within 30 days. Residual encrypted backups age out under the backup cycle, normally within 90 days.
- Transaction, fraud-prevention, tax, or legal records may be retained for the period required by law. Retained records are isolated and not used for marketing.
- Prospect suppression/opt-out records may be retained in minimal form to ensure a person who opted out is not contacted again.
8. Your choices and rights
Subject to applicable law, you may request access, correction, completion, export, restriction, withdrawal of consent, grievance review, or deletion. Account holders can update profile and security settings in the Service and can delete the account under Settings → Data and account → Delete account. You may also use our web deletion page or email sales@anantyalabs.com. We may verify identity before fulfilling a request.
9. Security
We use access controls, encrypted transport, password hashing, secure session storage, optional multi-factor authentication and passkeys, tenant separation, logging, and limited administrative access. No system is perfectly secure. You must protect credentials, use unique passwords, enable available security controls, and report suspected compromise promptly.
10. Children
The Service is a business product and is not intended for anyone under 18. We do not knowingly create accounts for children. Contact us if you believe a child has provided personal data.
11. Changes and contact
We may update this Policy when the Service, law, or our processing changes. Material changes will be highlighted in the Service or sent to the registered email before they take effect where required. Questions and grievances may be sent to sales@anantyalabs.com, Anantya Labs, Ahmedabad, Gujarat, India. Include “Privacy request” in the subject so we can route it promptly.
