Last updated 2026-07-16 · Aivedha Inc

Privacy Policy

This Privacy Policy explains how Aivedha Inc, operated by AiVibe Software Services Pvt Ltd, Chennai, India (“Aivedha”, “we”, “us”), collects, uses and protects personal data when you use aivedha.io, the customer portal at app.aivedha.io, and the AURA, ORBIT and SEAL products (together, the “Services”). It is written with the EU General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act) in mind.

1. Data we collect

We collect only what we need to provide and improve the Services:

  • Account data — name, email address and authentication identifiers created when you sign up. Authentication is handled by Amazon Cognito; we never see or store your password in our own databases.
  • Billing data — plan, subscription status, order history, invoice details (including GST information for Indian customers) and the transaction identifiers returned by our payment providers. Card, UPI and wallet details are entered directly with Razorpay or PayPal and are not stored on Aivedha systems.
  • Content you bring into the products — support conversations and contact details in AURA, event types, availability and booking details in ORBIT, and documents, recipients and signature events in SEAL. You control this content.
  • Usage and log data — IP address, browser type, pages visited and API activity, used for troubleshooting, capacity planning and abuse prevention.

2. How we use data

  • To provide the Services: authenticate you, run your workspaces, deliver conversations, bookings and signature requests.
  • To bill you: process subscription payments, issue invoices and apply credits.
  • To support you: respond when you write to us and investigate reported issues.
  • To send service communications: booking confirmations, signature requests, billing notices and important product or policy changes. These are not marketing messages.
  • To keep the platform safe: detect abuse, enforce our Terms of Service and comply with law.

Under the GDPR, our legal bases are performance of a contract (running the Services you signed up for), legitimate interests (security, service improvement) and consent where required. Under the DPDP Act, we process personal data for the legitimate uses connected to providing the Services you have requested.

3. Cookies

We use a small set of essential cookies on the .aivedha.io domain to keep you signed in across the suite:

  • aivedha_id_token, aivedha_access_token, aivedha_refresh_token — secure, HTTP-only session tokens used to authenticate you.
  • aivedha_user — a non-sensitive display cookie (your email and workspace identifiers) so pages can show your signed-in state.

These cookies are strictly necessary for the Services to function; we do not use third-party advertising or cross-site tracking cookies on aivedha.io.

4. Sharing and sub-processors

We never sell personal data. We share it only with the service providers that run the platform, under contracts that limit their use of it:

  • Amazon Web Services (cloud infrastructure, databases, file storage and email delivery; primary region US East, N. Virginia).
  • Amazon Cognito (account authentication).
  • Razorpay Software Pvt Ltd (payment processing, primarily INR).
  • PayPal (payment processing, primarily USD and other international currencies).

We may also disclose data where required by law, court order or governmental authority, or to protect the rights and safety of Aivedha, our customers or the public.

5. International transfers

Our infrastructure is hosted with AWS in the United States (us-east-1). If you use the Services from India, the EU or elsewhere, your data is transferred to and processed in that region under our sub-processors' contractual safeguards, including standard contractual clauses where applicable.

6. Retention

  • Account and workspace data is retained while your account is active.
  • If you delete your account or your subscription lapses, we delete or anonymise associated personal data within 90 days, except records we must keep longer (for example invoices and tax records, retained per Indian law).
  • Completed SEAL envelopes and their audit trails are retained while your account exists because they evidence signed agreements; you can download and delete them at any time.

7. Your rights

Depending on your jurisdiction (GDPR, DPDP Act or similar), you have the right to access, correct, export and delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights, email us — we respond within 30 days.

If you are in India, you may also nominate an individual to exercise your rights in the event of death or incapacity, as provided by the DPDP Act. If you believe we have not resolved your concern, you may approach your local supervisory authority or the Data Protection Board of India.

8. Children

The Services are business tools and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it.

9. Changes to this policy

We will post any changes on this page and update the date above. For material changes we will notify you by email or an in-product notice before they take effect.

10. Contact

Questions, requests or complaints: support@aivedha.io. Postal: AiVibe Software Services Pvt Ltd, Chennai, Tamil Nadu, India.

Need a hand with this document?

Write to support@aivedha.io — we respond within one business day (Mon–Fri, IST).