Privacy policy
NeevCloud Technologies Private Limited (“ai.ml”, “we”), Indore, Madhya Pradesh, India. Last updated 10 September 2026.
Two roles: for the people who sign in to the console we are the data fiduciary / controller; for the prompts and responses your application sends we are a processor acting on your instructions.
What we collect about console users
- Account: name, email, organisation, role, sign-in events and the IP address they came from.
- Billing: legal name, GSTIN or PAN, billing address and email. Card and bank details never reach us; Razorpay and Stripe hold them.
- Support: what you write to us.
We use it to run your account, issue invoices the tax law requires, prevent abuse and answer you. Legal bases under GDPR: contract, legal obligation and legitimate interest; under the DPDP Act, consent given at sign-up and the legitimate uses the Act permits.
What we process for you
Requests and responses pass through the gateway to the provider you selected. We keep usage metadata (tokens, cost, latency, model, request id) for billing and analytics. Payload archiving is off unless your data policy turns it on, in which case payloads are stored encrypted under a per-organisation key for the retention you chose, redacted per your presets, and crypto-shredded when the retention ends or on erasure request. Zero-data-retention mode disables archiving and restricts routing to providers that do not retain data.
Sharing
Model providers you route to and the infrastructure vendors listed on the sub-processor page. Payment aggregators for payments. Authorities where the law requires. No advertising, no sale of data.
Transfers
Providers outside India process data under the DPDP Act’s permitted transfers; for EU personal data we rely on Standard Contractual Clauses. Choose India-only regions in your data policy to keep processing in the India cell.
Retention
Account data for the life of the account and as long as tax law requires afterwards (invoices and the ledger: eight years). Request metadata 400 days. Payloads per your policy. System logs 180 days within India (CERT-In).
Your rights
Access, correction, erasure, portability and objection: from the console (account, data export, erasure) or by writing to the grievance officer. We answer within 30 days. You may also complain to the Data Protection Board of India or your EU supervisory authority.
Security and breaches
Encryption in transit and at rest, per-organisation keys, least-privilege access and audit logs. We notify affected organisations and the Data Protection Board within the statutory window (72 hours) of confirming a breach.
Cookies
The console uses a session cookie. This website sets none.