Privacy Policy
This policy is short in the places our architecture makes it possible to be short. We'd rather that than pad it out.
Draft notice: This is a structural template covering the standard elements required under India's DPDP Act, 2023, and general HIPAA-readiness language. It has not been reviewed by a lawyer and should not be published as-is. Every bracketed item needs a real, verified answer before this goes live.
1. Who we are
This policy is issued by Diviniel Technologies Private Limited (“Diviniel,” “we,” “us”), a company incorporated in India with its registered office in Maharashtra. Under India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), Diviniel acts as a Data Fiduciary for the personal data described below.
2. The short version
We do not receive, store, or process the content of documents you use our tools on. Document processing happens entirely within your browser, using client-side code. Your files are never transmitted to our servers — see our Proof section for how to verify it yourself.
3. What personal data we collect
- Account data: name, email address, and authentication identifiers if you create an account with any Diviniel product.
- Contact data: information you provide when emailing us or submitting a contact form.
- Usage data: only if you consent via the cookie banner — aggregate, non-document-related analytics.
- Payment data: processed by our third-party payment provider (Razorpay); Diviniel does not store full card details.
- What we explicitly do not collect: the content of any document you process through our tools.
4. Why we process it
Consistent with the DPDP Act's purpose-limitation principle, we process personal data only for the specific purpose it was collected: providing the service you requested, responding to your inquiry, or (with your consent) understanding aggregate site usage.
5. Cookies
We use three categories of cookies, matching the choices in the cookie banner on every page:
- Necessary — session and security cookies required for the site to function. Cannot be disabled.
- Analytics — off by default. Enabled only if you opt in.
- Marketing — off by default and currently unused in practice.
You can change your choice anytime via Cookie Settings in the footer.
6. Your rights as a Data Principal (DPDP Act)
- Access a summary of the personal data we hold about you
- Request correction or erasure of your personal data
- Withdraw consent at any time, as easily as it was given
- Nominate another individual to exercise these rights on your behalf
- File a complaint with the Data Protection Board of India
To exercise any of these rights, contact our Grievance Officer at privacy@diviniel.com. [Grievance Officer name and registered address to be added before publishing.]
7. HIPAA-ready architecture
Diviniel's products are architected to support HIPAA-aligned workflows because document content is never transmitted to or stored on our servers. This is a statement about architecture, not a claim of HIPAA certification. Diviniel is not currently a signed Business Associate under HIPAA; organizations with HIPAA obligations should conduct their own compliance assessment.
8. Data retention
Account data is retained for as long as your account is active, plus a limited period for legal and accounting requirements. Document content is never retained, because it is never received.
9. Third-party processors
- Authentication: Google, Microsoft (sign-in only)
- Payments: Razorpay
- Integrity anchoring: Hedera Consensus Service (only a cryptographic hash is anchored, never document content)
- Hosting: Vercel
10. International data transfers
[To confirm: whether any of the above processors store data outside India, and the applicable safeguard under DPDP Act Section 16.]
11. Changes to this policy
We'll update the “last updated” date whenever this policy changes, and for material changes, we'll notify account holders directly.
12. Contact
Questions about this policy: privacy@diviniel.com. Security-specific disclosures: security@diviniel.com.