Security & privacy

What happens to your data, in plain language

Conversations, calendars and contracts are trust. This page restates our published policies without the legal register — the formal documents govern, and every card below points back to them.

Policies last updated 2026-07-16

We never see your password

Sign-in is handled by Amazon Cognito. Your password is never seen or stored in Aivedha's own databases — one sign-in covers the whole suite.

Privacy policy §1

Card details never touch our systems

Card, UPI and wallet details are entered directly with Razorpay or PayPal and are not stored on Aivedha systems. We keep only plan, order and invoice records.

Privacy policy §1

Your workspace is tenant-scoped

Every workspace is scoped to its own tenant, and data access is isolated per tenant across AURA, ORBIT and SEAL.

Stated across the suite

Essential cookies only

A small set of essential cookies keeps you signed in: secure, HTTP-only session tokens plus one non-sensitive display cookie. No third-party advertising or cross-site tracking cookies on aivedha.io.

Privacy policy §3

Signatures carry their evidence

Every SEAL envelope records who viewed and signed, when and from where — a tamper-evident audit trail sealed with a signing certificate you can download any time.

SEAL product & terms §6

Hosted on AWS, moved over HTTPS

Our infrastructure — cloud servers, databases, file storage and email delivery — runs on Amazon Web Services, primary region US East (N. Virginia). Data is transmitted over HTTPS and documents live in cloud object storage in our AWS environment.

Privacy policy §4–5

Clear retention, clear exit

Your data is retained while your account is active. Delete your account and we delete or anonymise personal data within 90 days (invoices and tax records are kept as law requires). After termination you can export your content for 30 days.

Privacy policy §6 · Terms §10

Your rights, honoured on request

Access, correct, export or delete your personal data, object to or restrict processing, or withdraw consent — email us and we respond within 30 days. Written with the GDPR and India's DPDP Act, 2023 in mind.

Privacy policy §7

Who processes what

We never sell personal data

We share it only with the service providers that run the platform, under contracts that limit their use of it — the complete published list:

Sub-processorWhat they do for your data
Amazon Web ServicesCloud infrastructure, databases, file storage and email delivery — primary region US East (N. Virginia).
Amazon CognitoAccount authentication.
Razorpay Software Pvt LtdPayment processing, primarily INR (cards, UPI, netbanking, wallets).
PayPalPayment processing, primarily USD and other international currencies.

If you use the Services from India, the EU or elsewhere, your data is processed in the AWS US East region under our sub-processors' contractual safeguards, including standard contractual clauses where applicable. Disclosure beyond this list happens only where required by law.

Your content stays yours

You retain all rights to what you bring into the suite — conversations, contacts, calendars, documents and signatures. We take only the limited licence needed to host, process, transmit and display that content to run the Services for you. Completed SEAL envelopes stay downloadable, with their certificates, whenever you want them.

Terms of service §5 · Privacy policy §6

A person answers privacy requests

Questions, access requests or complaints go to support@aivedha.io — we respond within 30 days. If you are in India you may nominate someone to exercise your rights under the DPDP Act, and you can always approach your local supervisory authority or the Data Protection Board of India.

Privacy policy §7 & §10

Questions about any of this?

Write to us — privacy questions get the same one-business-day answer as everything else.

AiVibe Software Services Pvt Ltd · Chennai, Tamil Nadu, India