IjyaLabs logo
IjyaLabs

Privacy Policy

Effective 24 June 2026. How IjyaLabs collects, uses, and protects your information.

IjyaLabs ("IjyaLabs", "we", "us") operates the website at ijyalabs.in and the IjyaLabs advisory platform (the "Service"). This policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding that data.

Our approach, in plain terms

IjyaLabs does not proactively collect, scrape, or independently gather customer engagement content — about you, your employees, or your organisation — from public or third-party sources. The substantive content on the platform — compliance evidence, documents, and assessment answers — is submitted by you, at your discretion, for the sole purpose of your own readiness assessment. We process that content only to run the tool you asked for (extraction, control mapping, AI analysis, and report generation) and never for any other purpose, including model training or benchmarking against other customers. Separately, we collect a limited, standard set of operational data — account, session, payment, analytics, and contact-form information — that is necessary to run any secure online account. That data is fully described below; it is not sourced from anywhere but your own direct interactions with us.

1. Who this policy covers

This policy applies to anyone who visits ijyalabs.in, creates an account on the IjyaLabs platform, or uses any advisory readiness tools we provide, including ISO 27001, SOC 1, and SOC 2 readiness workflows.

2. Information we collect

2.1 Account and identity data

When you create an account or sign in, we collect:

  • Email address — required to identify your account and deliver transactional messages such as sign-in codes and session notifications.
  • Display name and profile picture — provided by your identity provider (Google or LinkedIn) when you sign in using one of those services, or entered by you during registration.
  • Organisation name — collected when you first set up your workspace.

When you sign in with Google or LinkedIn, those providers send us a verified email address, your display name (if permitted by your privacy settings), and a profile photo URL. We do not receive your password from any third-party provider.

2.2 Session data

We create a session record when you sign in. Sessions are identified by a cryptographic token stored in your browser's local storage. We store only a secure hash of this token — the raw token is never written to any persistent store. Session records include the time of creation, expiry, and approximate country inferred from Cloudflare's network at sign-in time. We do not log or store raw IP addresses or User-Agent strings beyond what Cloudflare retains as part of infrastructure operation.

2.3 Evidence and compliance files

To use the advisory platform, you may upload documents, screenshots, exports, and other files as evidence for compliance controls. These files are processed to extract text and metadata, which is stored in our database (Cloudflare D1). File contents are used solely to assess control readiness within your engagement and are not used for any other purpose, including training machine-learning models.

2.4 Readiness assessment responses

Answers you provide to assessment questions, declared control statuses, and findings generated during your engagement are stored and associated with your organisation.

2.5 Payment and billing information

Payment transactions are processed by Razorpay. IjyaLabs receives confirmation of payment status, plan type, transaction reference, and amount — we do not store card numbers, bank account details, or any other payment instrument data. Separately, we retain your name, email, and tax identity/billing details (where provided, e.g. for a GST-compliant invoice) in encrypted form, for as long as required for tax and legal compliance — this billing record is kept independently of, and is not affected by, deleting your evidence data or purging an engagement.

2.6 Website analytics

This website uses Cloudflare Web Analytics — a cookieless, privacy-friendly service that provides aggregate statistics such as page views, approximate geographic region, referrer, and device type. It does not use cookies or persistent identifiers to track individual visitors across sessions or sites. Depending on your jurisdiction's consent requirements, this may or may not require a consent banner; we keep this under review as regulatory guidance evolves.

2.7 Contact form

If you contact us through the website contact form, we collect the name, company, email, phone, and message you submit.

3. How we use your information

  • To authenticate your identity and maintain your session.
  • To operate, personalise, and improve the advisory platform and your engagement workspace.
  • To process file uploads and generate readiness assessments, control mappings, and reports within your engagement.
  • To send transactional messages — sign-in codes, session alerts, and notifications about your engagement (evidence processed, findings created, deadlines approaching). We do not send unsolicited marketing email.
  • To process payments and manage your subscription entitlement.
  • To respond to support or contact enquiries.
  • To maintain security logs that allow investigation of unauthorised access and to satisfy legal obligations.

4. Legal basis for processing (GDPR / DPDP)

Where applicable law requires a legal basis for processing personal data:

  • Contract — account identity, session data, assessment responses, and evidence files are necessary to provide the Service you have agreed to use.
  • Legitimate interests — security logging and aggregate analytics, balanced against your rights.
  • Legal obligation — records required by applicable tax or financial regulation.

5. Sub-processors and third parties

We share the minimum necessary data with the following sub-processors to operate the Service:

  • Cloudflare — infrastructure, database (D1), file storage, edge network, and analytics. Data is processed under Cloudflare's Data Processing Agreement.
  • Groq — AI inference used to analyse evidence text and map it to control criteria. Only the extracted text of uploaded files — not the original file or any personal data beyond what appears in the document — is sent. Groq does not use customer data to train its models.
  • Resend — transactional email delivery (sign-in codes and notifications).
  • Razorpay — payment processing (India). Payment data is governed by Razorpay's own privacy and PCI DSS policies.
  • Google, LinkedIn — identity providers used when you choose social sign-in. Each provider's privacy policy governs the data they collect from your interaction with their sign-in screen.

We do not sell personal data to any third party, and we do not share it for advertising purposes.

6. Data retention

  • Active accounts — account and engagement data is retained for as long as your account remains active.
  • Uploaded files — stored for the duration of your active subscription or engagement, plus a 90-day grace period after account closure, unless you delete them earlier (see our Company Policy for the full retention schedule). After the grace period or an earlier permanent purge, file content is deleted and only a tombstone record (hash, dates, and deletion audit trail) is retained.
  • Session tokens — expire after 30 days from creation; signing out revokes the session immediately.
  • Contact form messages — retained only as long as needed to respond and manage ongoing communication.
  • Security and audit logs — retained for a minimum of 12 months, or longer if required by applicable law.

7. Your rights and controls

Depending on your jurisdiction, you may have rights to access, correct, export, restrict, object to, or delete your personal data. Within the platform you can:

  • View and update your profile name.
  • Delete individual uploaded files from the evidence library.
  • Purge all evidence data immediately, in one click, from your account dashboard — every uploaded file, its extracted text, every AI verdict, and every cross-match for your organisation, deleted on the spot with no waiting period. Any assessment score that depended on that evidence reverts to unevidenced until you re-upload.
  • Permanently purge an engagement and all associated content.
  • View active sessions and revoke any session.

To request deletion of your entire account and data, contact privacy@ijyalabs.in. We will respond within 30 days. Some records (billing, audit trails) may be retained where required by law.

8. Security

Data is encrypted at every phase: in transit (TLS 1.3, for upload and for every request to and from the platform), during processing (evidence text extraction and AI analysis happen over encrypted connections to our sub-processors), and at rest (Cloudflare's infrastructure-level encryption for everything stored in our database). Session tokens are stored as cryptographic hashes; raw tokens are never persisted. Access to production systems requires separate privileged authentication and is logged. No production access is used to view customer evidence content without a distinct logged action.

Evidence content is used only to serve your own assessment — never to train any model, never shared with other organisations, and never repurposed beyond the specific analysis you requested. You may delete it at any time; see the one-click purge option in Section 7.

9. Children

The Service is intended for business use by individuals 18 or older. We do not knowingly collect data from children. If you believe a child has submitted information, contact us and we will delete it promptly.

10. International transfers

IjyaLabs is based in India. Data is stored on Cloudflare's global infrastructure. By using the Service, you acknowledge that your data may be processed in jurisdictions outside your country of residence. We use contractual safeguards (Cloudflare's DPA) where required.

11. Changes to this policy

We may update this policy. Material changes will be reflected by a new effective date at the top. We will notify active platform users by email for material changes affecting how their data is used.

12. Contact

For privacy enquiries, data requests, or concerns:

  • Email: privacy@ijyalabs.in
  • Post: IjyaLabs (sole proprietorship of Arun R Kaushik), 2nd Floor, 6A, Yashoda Nagar, Hingna Road, Nagpur, Maharashtra, India. GSTIN 27BFMPK2514K2Z9.