Skip to content
IjyaLabs logo
IjyaLabs

Privacy Policy

Effective 24 June 2026. How IjyaLabs collects, uses, and protects your information.

IjyaLabs ("IjyaLabs", "we", "us") operates the website at ijyalabs.in and the IjyaLabs advisory platform (the "Service"). This policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding that data.

Our approach, in plain terms

IjyaLabs does not proactively collect, scrape, or independently gather customer engagement content — about you, your employees, or your organisation — from public or third-party sources. The substantive content on the platform — compliance evidence, documents, and assessment answers — is submitted by you, at your discretion, for the sole purpose of your own readiness assessment. We process that content only to run the tool you asked for (extraction, control mapping, AI analysis, and report generation) and never for any other purpose, including model training or benchmarking against other customers. Separately, we collect a limited, standard set of operational data — account, session, payment, analytics, and contact-form information — that is necessary to run any secure online account. That data is fully described below; with one exception it is not sourced from anywhere but your own direct interactions with us. The exception is a workspace invitation: if an administrator invites a colleague, we hold that colleague’s email address before that person has used the platform, because it is the only way to route them to the right workspace when they first sign in. Section 2.1 sets out exactly what that means and how long it lasts.

1. Who this policy covers

This policy applies to anyone who visits ijyalabs.in, creates an account on the IjyaLabs platform, or uses any advisory readiness tools we provide, including ISO 27001, SOC 1, and SOC 2 readiness workflows.

2. Information we collect

2.1 Account and identity data

When you create an account or sign in, we collect:

  • Email address — required to identify your account and deliver transactional messages such as sign-in codes and session notifications.
  • Display name and profile picture — provided by your identity provider (Google or LinkedIn) when you sign in using one of those services, or entered by you during registration.
  • Organisation name — collected when you first set up your workspace.

When you sign in with Google or LinkedIn, those providers send us a verified email address, your display name (if permitted by your privacy settings), and a profile photo URL. We do not receive your password from any third-party provider.

Workspace invitations. A workspace administrator can invite a colleague by email address so that person can join as, for example, an independent reviewer of evidence. In that one case we hold an email address before its owner has used the platform, and it reaches us from the administrator rather than from them. We hold nothing else about an invited person — no name, no profile, no activity — and we send them no email; the administrator tells them themselves. If the invitation is withdrawn before it is taken up, the address is deleted outright rather than retained. If they do sign in, the ordinary account terms in this section apply from that point.

2.2 Session data

We create a session record when you sign in. Sessions are identified by a cryptographic token stored in your browser's local storage. We store only a secure hash of this token — the raw token is never written to any persistent store. Session records include the time of creation, expiry, and approximate country inferred from Cloudflare's network at sign-in time. We do not log or store raw IP addresses or User-Agent strings beyond what Cloudflare retains as part of infrastructure operation. Once a session expires, its record is deleted rather than merely refused (section 6).

2.3 Evidence and compliance files

To use the advisory platform, you may upload documents, screenshots, exports, and other files as evidence for compliance controls. These files are processed to extract text and metadata, which is stored in our self-hosted PostgreSQL database. File contents are used solely to assess control readiness within your engagement and are not used for any other purpose, including training machine-learning models.

Reading the file. Extraction is done either in your own browser or by a document reader running on our own system — whichever is available where the platform is deployed. The reader tells you which one read your file, beside the file itself. Where our reader is used, the file reaches our system so that it can be read: it is held only for the length of that read, is deleted as soon as the read finishes whether it succeeded or not, and no record of it is kept unless you go on to upload it. In neither case is the original file sent to any third party — only the extracted text is, and only to the AI sub-processor named in section 5.

2.4 Readiness assessment responses

Answers you provide to assessment questions, declared control statuses, and findings generated during your engagement are stored and associated with your organisation.

2.5 Payment and billing information

Payment transactions are processed by Razorpay. IjyaLabs receives confirmation of payment status, plan type, transaction reference, and amount — we do not store card numbers, bank account details, or any other payment instrument data. Separately, we retain your name, email, and tax identity/billing details (where provided, e.g. for a GST-compliant invoice) in encrypted form, for as long as required for tax and legal compliance — this billing record is kept independently of, and is not affected by, deleting your evidence data or purging an engagement.

2.6 Website analytics

This website uses Cloudflare Web Analytics — a cookieless, privacy-friendly service that provides aggregate statistics such as page views, approximate geographic region, referrer, and device type. It does not use cookies or persistent identifiers to track individual visitors across sessions or sites. Depending on your jurisdiction's consent requirements, this may or may not require a consent banner; we keep this under review as regulatory guidance evolves.

2.7 Contact form

If you contact us through the website contact form, we collect the name, company, email, phone, the service you select, and the message you submit. The email we receive also records the browser user-agent string and the site the submission came from; we use those to tell genuine enquiries from automated ones, alongside a hidden field that real visitors never fill in. A submission that fills it is discarded and never reaches us.

The contact form has no database behind it. Your enquiry is relayed straight to our inbox and is held there as ordinary email, under the retention described in section 6 — it does not enter the advisory platform, and it is not linked to an advisory account.

3. How we use your information

  • To authenticate your identity and maintain your session.
  • To operate, personalise, and improve the advisory platform and your engagement workspace.
  • To process file uploads and generate readiness assessments, control mappings, and reports within your engagement.
  • To send transactional messages — sign-in codes, session alerts, and notifications about your engagement (evidence processed, findings created, deadlines approaching). We do not send unsolicited marketing email.
  • To process payments and manage your subscription entitlement.
  • To respond to support or contact enquiries.
  • To maintain security logs that allow investigation of unauthorised access and to satisfy legal obligations.

4. Legal basis for processing (GDPR / DPDP)

Where applicable law requires a legal basis for processing personal data:

  • Contract — account identity, session data, assessment responses, and evidence files are necessary to provide the Service you have agreed to use.
  • Legitimate interests — security logging and aggregate analytics, balanced against your rights.
  • Legal obligation — records required by applicable tax or financial regulation.

5. Sub-processors and third parties

We share the minimum necessary data with the following sub-processors to operate the Service:

  • Cloudflare — hosts the public marketing site (Pages), the edge network, and cookieless Web Analytics. The advisory platform and its data are not stored on Cloudflare. Data is processed under Cloudflare's Data Processing Agreement.
  • Anthropic — AI inference used to analyse evidence and map it to control criteria. What is sent depends on the file. For documents (PDF, Office, text), only the extracted text is sent — the original file is not, and who extracts it is described in section 2.3. For image evidence(screenshots, photographs of records), the image itself is sent, because reading the image is the analysis. Nothing beyond what appears in the document or image is sent. Anthropic does not use data submitted through its API to train its models by default.
  • Google (Gmail API) — transactional email delivery: sign-in codes, and the messages sent when you use the contact form. Mail is sent from a Google mailbox we operate, so your address and the content of the message pass through Google’s systems and are governed by Google’s terms as well as this policy. This is separate from Google’s role as a sign-in provider below.
  • Razorpay — payment processing (India). Payment data is governed by Razorpay's own privacy and PCI DSS policies.
  • ipwho.is — ASN and geolocation lookup used by the free network tools at /apps. When you ask those tools to analyse a host, the IP that host resolves to is sent to ipwho.is so the report can say which network and country it sits on. What is sent is the address of the machine you asked us to look at, not yours, and nothing else about you accompanies it. These tools need no sign-in, so this happens whether or not you have an account.
  • Cloudflare (public DNS resolver) — named separately from Cloudflare’s hosting role above because it is a different relationship with different data. The same network tools resolve records through Cloudflare’s public DNS-over-HTTPS resolver, so every hostname you type into them is sent there. Again: no sign-in is required for those tools.
  • Google, LinkedIn — identity providers used when you choose social sign-in. Each provider's privacy policy governs the data they collect from your interaction with their sign-in screen. (The Service also contains a working Apple sign-in endpoint, which is not offered anywhere in the interface and which no sign-in flow reaches; if it is ever offered, Apple will be named here first.)

We do not sell personal data to any third party, and we do not share it for advertising purposes.

6. Data retention

  • Active accounts — account and engagement data is retained for as long as your account remains active.
  • Uploaded files — purged automatically 30 days after your last sign-in, and sooner than that if you ask: you can purge every file, its extracted text and every verdict about it in one click, at any time, from the evidence library. Signing in resets the 30 days, and while files are held your dashboard shows the date they go. This is a shorter period than the rest of your account, deliberately — evidence is material you handed us so it could be read, and holding it after you have stopped using the Service would be holding it for our convenience. Your assessments, answers and registers are not affected. Files still held when an account is closed are covered by the closure grace period below (see our Company Policy for the full retention schedule). Deletion is complete: the file, its extracted text, every AI verdict about it, every cross-match it produced and the review trail recording who decided what about it are all removed. We do not keep a tombstone, a hash, or a residual record of a deleted file.
  • After account closure — everything the account holds is erased once a 90-day grace period has elapsed from the date of closure. The grace period is yours, not ours: it exists so a closure made in error, or by one administrator without the others, can be undone before anything is destroyed. Reopening the account before the period expires cancels the erasure. Your dashboard shows the date while the account is closed.
  • Assessments started without an account — most modules can be used without signing in, and an engagement started that way is attached to no account. Because nobody can prove it is theirs, nobody — including us — can ask for it to be deleted on request, so it is deleted on a schedule instead: 90 days after it was created, along with every answer, profile, finding and report belonging to it. Sign in before you start, or at any point during an assessment, and the engagement is attached to your organisation and covered by the account terms above instead.
  • Session records — a session expires 30 days after it is created, and the record itself is then deleted: when an expired session is next presented, by a sweep each time any session is created, and by a daily scheduled job so that deletion does not depend on anyone signing in. Signing out revokes and deletes the session immediately. We keep no session record beyond its 30-day life.
  • Contact form messages — retained only as long as needed to respond and manage ongoing communication.
  • Workspace activity records — who invited, removed or changed the role of a member, and who erased an engagement, evidence or a workspace. These are kept for as long as the account is open and are deliberately not removed by an evidence purge: a record of an erasure that is deleted by the erasure is not a record. They contain the action, the person who took it and when — never the content of anything that was deleted. An organisation admin can read them in the workspace members screen, and they go with full account deletion.
  • Security and audit logs — retained for a minimum of 12 months, or longer if required by applicable law.

7. Your rights and controls

Depending on your jurisdiction, you may have rights to access, correct, export, restrict, object to, or delete your personal data. Within the platform you can:

  • Delete individual uploaded files from the evidence library.
  • Purge all evidence data immediately, in one click, from your account dashboard — every uploaded file, its extracted text, every AI verdict, and every cross-match for your organisation, deleted on the spot with no waiting period. Any assessment score that depended on that evidence reverts to unevidenced until you re-upload.
  • Permanently erase a single engagement, from your account dashboard — its answers, findings, report revisions, saved profile, processing activities and audit trail, for that engagement only. Uploaded evidence is not part of an engagement: one file is checked against every module you use, so it belongs to your organisation's library and is erased separately with the one-click purge above.
  • View every device signed in to your account and sign any of them out, from your account page — individually, or all devices other than the one you are using. A revoked session stops working immediately.
  • View and update the display name on your account.

To request deletion of your entire account and data, contact privacy@ijyalabs.in. We will respond within 30 days. Some records (billing, audit trails) may be retained where required by law.

8. Security

Data is encrypted at every phase: in transit (TLS 1.3, for upload and for every request to and from the platform), during processing (evidence text extraction and AI analysis happen over encrypted connections to our sub-processors), and at rest (disk-level encryption on our own storage for everything in our database). Session tokens are stored as cryptographic hashes; raw tokens are never persisted. Access to production systems requires separate privileged authentication and is logged. No production access is used to view customer evidence content without a distinct logged action.

Evidence content is used only to serve your own assessment — never to train any model, never shared with other organisations, and never repurposed beyond the specific analysis you requested. You may delete it at any time; see the one-click purge option in Section 7.

9. Children

The Service is intended for business use by individuals 18 or older. We do not knowingly collect data from children. If you believe a child has submitted information, contact us and we will delete it promptly.

10. International transfers, and what we do not offer

IjyaLabs is based in India. The public website is served from Cloudflare’s global network; the advisory platform and its data run on our own self-hosted infrastructure. By using the Service, you acknowledge that your data may be processed in jurisdictions outside your country of residence.

We do not offer data residency or jurisdiction pinning. We cannot commit to storing or processing your data in a particular country or region, and nothing in the Service should be read as such a commitment. If your organisation is subject to a data-localisation requirement — sectoral rules, a regulator’s direction, or a contract with your own customers — this Service is not suitable for that workload as it stands. Write to privacy@ijyalabs.in before relying on it, and we will tell you plainly whether we can help rather than discovering the constraint later.

11. Changes to this policy

We may update this policy. Material changes will be reflected by a new effective date at the top. We will notify active platform users by email for material changes affecting how their data is used.

12. Raising a complaint, and reporting a security incident

One address, and it is monitored. Privacy enquiries, requests to access, correct or erase your data, complaints about how we have handled any of that, and reports of a security problem all go to privacy@ijyalabs.in. You do not need to know which category your message falls into.

We have not appointed a Data Protection Officer. The DPDP Act 2023 requires a Significant Data Fiduciary to appoint one, and its obligations do not commence until 13 May 2027; IjyaLabs is a sole proprietorship and has not been designated one. We say this plainly rather than describing the proprietor as a DPO, because that title carries statutory duties that have not been assumed. The address above reaches the proprietor directly.

What happens when you write. We acknowledge your message, tell you what we are doing about it, and tell you the outcome. Where a request is refused — some are, and the reasons are in section 9 — we say which request was refused and why, rather than closing it silently.

If there is a personal data breach. We will investigate and contain it, and we will inform the administrators of every affected workspace by email, without undue delay, describing what happened, what data was involved, and what we have done. We will do this whether or not a notification duty is in force at the time, and we will notify the Data Protection Board of India where the Act requires it once those duties commence. We do not commit to a fixed number of hours: this is a sole proprietorship, and a deadline we could miss is not a protection.

13. Contact

For privacy enquiries, data requests, or concerns:

  • Email: privacy@ijyalabs.in
  • Post: IjyaLabs (sole proprietorship of Arun R Kaushik), 2nd Floor, 6A, Yashoda Nagar, Hingna Road, Nagpur, Maharashtra, India. GSTIN 27BFMPK2514K2Z9.