Privacy Policy
Your data is yours. Here is exactly how we collect, use, and protect it — in plain language, not legal jargon.
Last updated: March 28, 2026
TL;DR
- We collect only what we need — your email, form responses, and payment references. Nothing more.
- We never sell your data. It is used only to deliver services you asked for and send emails you subscribed to.
- You are in control. Access, correct, or delete your data anytime by emailing automatewithpriya@gmail.com. We respond within 72 hours.
Who We Are
Automate with Priya is an enterprise L&D consulting practice operated by Vishnu Priya (“we,” “us,” or “our”), headquartered in India. Under the DPDP Act 2023, we are the Data Fiduciary — responsible for how your personal data is processed.
Website: automatewithpriya.com
Contact: automatewithpriya@gmail.com
What We Collect
| Data | Source | Purpose |
|---|---|---|
| Email address | Signup, newsletter, auth | Account creation, service delivery, marketing (with consent) |
| Name & professional role | Service questionnaires | Tailoring your deliverables (Audit, Blueprint, etc.) |
| Organisation details | Service questionnaires | Contextualizing service delivery |
| UPI transaction reference | WhatsApp confirmation | Payment verification & tax compliance |
| Questionnaire responses | Service intake forms | Creating your custom deliverables |
| Device & browser info | Automatic (analytics) | Website optimization |
We do NOT collect:
- Bank account numbers, credit/debit card details, or UPI IDs
- Aadhaar, PAN, or any government identity numbers
- Biometric data
- Data from anyone under 18
How We Use Your Data
- Service delivery: Processing your questionnaire responses to create Audits, Blueprints, Frameworks, or other deliverables
- Communication: Sending service updates, deliverables, and follow-ups via email or WhatsApp
- Newsletter: Weekly AI and L&D insights — only if you explicitly subscribe, with one-click unsubscribe in every email
- Improvement: Understanding which services are most valuable to improve our offerings
- Legal compliance: Meeting obligations under Indian law
We never sell, rent, or trade your personal data to third parties. Period.
Third-Party Services
We use these services to operate our platform. Each processes data on our behalf as a Data Processor under the DPDP Act:
| Service | What It Does | Data It Accesses |
|---|---|---|
| Supabase | Authentication & database | Email, auth tokens, questionnaire responses, service progress |
| Resend | Transactional & marketing email | Email address |
| Vercel (Hosting) | Website hosting | Server logs, IP address (standard hosting) |
| Vercel Speed Insights | Core Web Vitals performance telemetry | Anonymous page performance metrics (LCP, INP, CLS). No identifiers stored. |
| PostHog | Product analytics (page views, feature usage) | Anonymous session ID stored in browser localStorage. No PII. Used to measure which features help L&D leaders find what they need. |
| Sentry | Error tracking | Error stack traces, browser + OS info. Helps us fix bugs fast. |
| Cashfree Payments | Payment gateway (UPI, Cards, Net Banking, Wallets) | Transaction metadata. Cashfree is PCI-DSS compliant; we never store card/UPI credentials. |
| WhatsApp Business | Support & pre-launch drop reservations | Phone number, messages (operated by Meta) |
Data Storage & Cross-Border Transfers
Some of our third-party services store data on servers located outside India:
- Supabase: Data may be stored in AWS data centers (US/EU region, depending on project configuration)
- Resend: Email delivery infrastructure located in the United States
- Vercel & Vercel Speed Insights: Edge network with global distribution; performance telemetry aggregated in the US
- PostHog: Anonymous product-analytics data routed to PostHog's US region (
us.i.posthog.com) - Sentry: Error telemetry routed to Sentry's US infrastructure
Under the DPDP Act 2023, cross-border transfers are permitted to countries not restricted by the Central Government. As of March 28, 2026, no countries have been restricted. We will update this policy if regulations change.
Payments
All payments are processed via UPI QR code and confirmed through WhatsApp. This means:
- We are not a payment gateway — the transaction happens directly between your UPI app and our bank
- We never store your UPI ID, bank account number, or any payment credentials
- We do store: transaction reference numbers, payment amounts, and dates — for order fulfillment and tax compliance
- Payment confirmation screenshots sent via WhatsApp are used only for verification
Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Newsletter subscribers | Until you unsubscribe | Consent-based |
| Service questionnaire data | 12 months after delivery | Follow-up support & upgrades |
| Payment references | 7 years | Indian tax law requirement |
| Website analytics | Aggregated indefinitely | Anonymised, non-personal |
| Auth/session data | Until account deletion | Required for login |
After the retention period, data is permanently deleted. You can request early deletion at any time.
Your Rights Under the DPDP Act 2023
As a Data Principal, you have the right to:
Right to Access: Request a copy of all personal data we hold about you.
Right to Correction: Request correction of inaccurate or incomplete data.
Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
Right to Withdraw Consent: Withdraw consent for marketing emails at any time. One-click unsubscribe in every email.
Right to Grievance Redressal: Raise a complaint about our data practices — we respond within 72 hours.
Right to Nominate: Nominate another person to exercise your data rights on your behalf.
To exercise any right, email automatewithpriya@gmail.com. We respond within 72 hours and complete actions within 30 days.
You also have the right to lodge a complaint with the Data Protection Board of India.
Children's Privacy
Our services are designed for L&D professionals and enterprise teams. This website is intended for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with data, please contact us immediately and we will delete it.
Data Security
- All data transmission encrypted via HTTPS/TLS
- Database access restricted via Row-Level Security (RLS) policies
- API keys and service credentials are never exposed in client-side code
- Questionnaire responses stored in encrypted databases with access controls
- Regular security reviews of codebase and infrastructure
No system is 100% secure, but we take reasonable and appropriate measures to protect your information. In the event of a data breach, we will notify the Data Protection Board and affected users as required by the DPDP Act.
Changes to This Policy
We may update this privacy policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email to active clients and subscribers. The “Last Updated” date at the top of this page indicates when the policy was last revised.
Questions About Your Data
Name: Vishnu Priya
Role: Founder & Data Protection Contact
Email: automatewithpriya@gmail.com
Response time: Within 72 hours
Resolution time: Within 30 days
Still not resolved? You have the right to raise a complaint with the Data Protection Board of India.