legal how we handle data
Privacy Policy
last updated May 12, 2026 · effective June 11, 2026 · definable ai technologies pvt. ltd., gurugram, india
This policy explains what personal data Definable collects, why we collect it, and the choices you have. We have tried to write it so you can actually read it — each section opens with a plain-language summary, and the summary is never allowed to contradict the full text.
01 Who this covers
in short This policy covers data we collect from you directly. Data your team puts into workspaces is governed by our DPA — we process it only on your instructions.
This Privacy Policy applies to definable.ai, our web application, APIs, and anything else that links to it (together, the “Services”). It is issued by Definable AI Technologies Private Limited (“Definable”, “we”, “us”), a company incorporated in India with its registered office in Gurugram, Haryana.
One distinction matters more than anything else in this document. For data about you — your account, your billing details, your usage of our site — Definable is the data fiduciary (in DPDP terms) or controller (in GDPR terms), and this policy governs. For content your organisation submits to its workspaces — prompts, documents, agent inputs and outputs, connected-app data — we act as a processor on your organisation’s instructions, and our Data Processing Addendum governs instead. If you use Definable through an employer’s workspace, your employer decides how that content is handled; their privacy policy applies to it.
02 What we collect
in short Account details you give us, usage data we observe, and data from integrations you connect. We never buy data about you.
Information you provide
- — Account data — name, work email, password hash, workspace name, profile preferences.
- — Billing data — plan, billing address, tax IDs. Card numbers go directly to our payment processors and never touch our servers.
- — Communications — messages you send to support or [email protected], survey responses, event registrations.
- — Workspace content — prompts, files, knowledge bases, workflow definitions, and agent outputs you create. Processed under the DPA, as described in Section 1.
Information collected automatically
- — Usage data — features used, workflows run, pages visited, referring URLs.
- — Device and log data — IP address, browser type, OS, timestamps, crash logs.
- — Cookies — see Section 5. We use a small set, and the analytics ones are optional.
Information from third parties
- — OAuth integrations — when you connect an app (Gmail, Slack, Notion, and ~1,000 others), we receive only the data and scopes you authorise. You can disconnect any integration at any time, which revokes our access.
- — Sign-in providers — if you sign up with Google or GitHub, we receive your name, email, and avatar.
We do not buy personal data from data brokers, and we do not collect data about you from social media or other public sources.
03 How we use it
in short To run the product, keep it secure, bill you, and improve it. Each purpose has a legal basis.
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Services | Running your workflows, syncing integrations, support | Contract performance |
| Secure the Services | Fraud and abuse detection, audit logs, incident response | Legitimate interest |
| Billing & accounts | Subscriptions, invoices, tax compliance | Contract / legal obligation |
| Improve the product | Aggregate feature analytics, debugging | Legitimate interest |
| Communicate | Service announcements, optional newsletter | Contract / consent |
| Comply with law | Responding to lawful requests, DPDP obligations | Legal obligation |
Where we rely on legitimate interest, we have weighed that interest against your rights and use the minimum data necessary. Marketing emails are always opt-in, and every one of them has a working unsubscribe link.
04 AI models and your data
in short We never train models on your content. The model providers we route to are contractually barred from training on it or retaining it.
This is the section most people open first, so here it is without hedging: your use of Definable does not grant us any right to use your workspace content — prompts, documents, knowledge bases, agent inputs or outputs — to train our models or anyone else’s. Not on free plans, not on paid plans, not “de-identified”. Never.
Definable routes agent tasks across more than fifty third-party foundation models, including models operated by OpenAI, Anthropic, Google, Meta licensees, and Mistral. Our agreements with these providers prohibit them from using your content to train their models, and require zero data retention where the provider offers it — meaning your content is not logged for human review and is not saved to disk on their side.
Content from different customers is never mixed during AI processing. Workspaces are tenant-isolated end to end.
We do use aggregate, non-identifying telemetry — counts, latencies, error rates — to improve routing and reliability. That telemetry contains no workspace content.
07 How long we keep data
in short Account data while your account exists. Deleted content is purged from production within 30 days, from backups within 90.
| Data | Retention |
|---|---|
| Account data | Life of the account, then deleted within 30 days of account deletion |
| Workspace content | Until you delete it or close the workspace; purged from production within 30 days, backups within 90 days |
| Billing records | 8 years (Indian Companies Act and tax requirements) |
| Support threads | 24 months after resolution |
| Server logs | 90 days, then aggregated or deleted |
| Newsletter list | Until you unsubscribe |
When you delete a conversation, document, or workflow in the product, it disappears from your workspace immediately and is removed from our backend within 30 days. Encrypted backups age out on a rolling 90-day window.
08 How we protect it
in short Encryption everywhere, tenant isolation, SOC 2 Type II and ISO 27001 audited controls.
All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Workspaces are tenant-isolated. Access by Definable staff is role-scoped, logged, and reviewed. Our controls are audited under SOC 2 Type II and ISO/IEC 27001.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data, we will notify you and the relevant authorities as required by law — and our DPA commits us to notifying business customers within 48 hours of becoming aware. The full picture, including how to report a vulnerability, lives on our Security page.
09 Where data lives and moves
in short You pick your hosting region — India, the US, or the EU. Cross-border transfers use recognised safeguards.
Workspaces are hosted in the region you choose at signup: India, the United States, or the European Union. Workspace content stays in that region.
Some supporting systems (billing, support tooling, model providers) operate across borders. Where personal data leaves the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses, supplemented by the UK Addendum and Swiss requirements as applicable. Transfers out of India comply with the Digital Personal Data Protection Act, 2023 and the rules notified under it.
10 Your rights
in short Access, correct, delete, export, object, complain. Email [email protected] and we act within 30 days.
Wherever you live, we extend the same baseline rights:
- — Access — get a copy of the personal data we hold about you.
- — Correction — fix inaccurate or incomplete data.
- — Deletion — erase your data, subject to the legal retention periods in Section 7.
- — Portability — export your data in a machine-readable format (also available self-serve in workspace settings).
- — Objection and restriction — object to processing based on legitimate interest, or ask us to pause it.
- — Withdraw consent — at any time, where processing is based on consent, without affecting prior processing.
To exercise any of these, email [email protected] from the address on your account, or use the controls in workspace settings. We respond within 30 days. If we refuse a request, we will tell you why, and you may appeal by replying to our decision; you may also complain to your supervisory authority — including the Data Protection Board of India, your EEA member-state authority, or the UK ICO.
11 Children
in short Definable is not for children under 18.
The Services are built for work and are not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we delete it. If you believe a child has provided us data, contact [email protected].
12 For users in India (DPDP)
in short Our home jurisdiction. DPDP rights honoured in full; grievance officer named below.
Definable is an Indian company and processes personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”). As a Data Principal you have the rights to access, correction, erasure, grievance redressal, and to nominate a person to exercise your rights in the event of death or incapacity.
Grievance Officer: Anandesh Sharma, Definable AI Technologies Pvt. Ltd., Gurugram, Haryana — [email protected]. We acknowledge grievances within 72 hours and resolve them within the timelines prescribed under the DPDP Act. If you are not satisfied with our response, you may approach the Data Protection Board of India.
13 For users in California and other US states
in short CCPA rights honoured. We don’t sell or share your data, so there is nothing to opt out of — but the rights are yours regardless.
If you are a resident of California or another US state with a comprehensive privacy law, you have rights to know, access, correct, delete, and port your personal information, and to opt out of its sale or sharing. In the twelve months preceding the date above, we collected the categories of personal information described in Section 2 (identifiers, commercial information, internet activity, and professional information), for the purposes in Section 3, disclosed only as described in Section 6.
We have not sold or shared personal information as those terms are defined in the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. We do not discriminate against you for exercising your rights. You may use an authorised agent to submit requests; we will verify the request through the email on your account. Appeals can be made by replying to any decision, and Californians may also contact the California Privacy Protection Agency.
14 Changes to this policy
in short Material changes get 30 days’ notice by email. Old versions stay available.
We update this policy as the product and the law evolve. For material changes we will email account owners at least 30 days before the new version takes effect — which is why the “effective” date above can trail the “last updated” date. Prior versions are available on request from [email protected]. Continuing to use the Services after the effective date constitutes acceptance of the updated policy.
Contact, for anything in this document: [email protected], or by post to Definable AI Technologies Private Limited, Gurugram, Haryana, India.