1. Who we are
AY7 Technologies (“we”, “us”) is a sole proprietorship owned by Abhishek Yadav, based in Lucknow, Uttar Pradesh, India.
For our own applications and this website, we are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 - and the Data Controller under UK/EU GDPR where it applies.
Grievance Officer
Abhishek YadavAY7 Technologies, Lucknow, Uttar Pradesh, India
info@ay7.in
2. What we collect
2.1 If you sign in
We offer sign-in through Google, Microsoft, GitHub, and email with a one-time password (OTP).
Signing in with a provider. We receive a limited profile from your chosen provider. We request the minimum needed to create and identify your account:
| Provider | What we receive |
|---|---|
| Name, email address, profile picture, Google account identifier | |
| Microsoft | Name, email address, Microsoft object identifier, tenant identifier where applicable |
| GitHub | Username, name, email address, avatar, GitHub user identifier |
We never receive your password from any of these providers, and we do not request access to your files, contacts, repositories, mailbox or calendar.
Signing in with email and OTP. We collect your email address and send a single-use code. Codes are short-lived and stored only in hashed form - never in plain text.
In both cases we also store: your account identifier, sign-in timestamps, and the authentication session.
2.2 If you use the application
Where you use an application we operate, we store the content you create or upload in it - which may include documents and files you submit, records and entries you create, configuration and preferences you set, and the results the application generates from them. We store this content to provide the application to you, and for no other purpose.
Content about other people. If what you upload contains personal data belonging to your own customers, employees or other third parties, you remain responsible for having a lawful basis to process it and for meeting your own obligations to those people. In that situation we act as a Data Processor on your instructions, and the processing is governed by our agreement with you rather than by this policy.
2.3 If you contact us
Your name, email address, company if provided, and the content of your message.
2.4 Automatically
Standard server logs - IP address, browser type, pages requested, timestamps - kept for security and reliability.
Cookies. We use strictly necessary cookies only: in our applications, your authentication session and security tokens (CSRF). We do not use advertising or third-party tracking cookies. This website sets no cookies at all; your light or dark theme preference is stored in your own browser’s local storage and is never sent to us.
Fonts and assets. All fonts, styles and scripts are served from our own domain. We do not load them from third-party content networks, so visiting a page does not disclose your IP address to another company.
3. Why we use it
| Purpose | Legal basis (GDPR) | DPDP |
|---|---|---|
| Creating and securing your account | Contract | Consent / legitimate use |
| Authenticating you at sign-in | Contract | Consent |
| Providing the application’s features | Contract | Consent |
| Preventing abuse, fraud and unauthorised access | Legitimate interest | Legitimate use |
| Responding to your enquiries | Legitimate interest | Consent |
| Meeting tax, accounting and legal obligations | Legal obligation | Legal obligation |
We do not sell personal data, share it with advertisers, or send you marketing you did not ask for.
AI and model processing. We do not train machine-learning models on your data. No feature we currently operate sends your content to a third-party model provider. If we introduce one, we will name that provider in section 5, use only providers contractually committed not to train their models on your content, and update this policy before the feature goes live.
4. How we protect it
- Sensitive personal data fields are encrypted at the application layer before they are written to the database, so those values are not readable directly from the database. Server logs and operational metadata are protected by access control and encryption at rest rather than field-level encryption
- All traffic is served over TLS
- Secrets and encryption keys are held in a managed key store (Azure Key Vault), separate from the application database
- Passwords are never stored, because we never handle them - authentication is delegated to your provider or to a one-time code
- OTPs are hashed, single-use, and expire after 10 minutes
- Access to production systems is restricted and authenticated
No system is perfectly secure and we do not claim otherwise.
If a breach affects your personal data, we will notify you without undue delay and report it to the Data Protection Board of India within the time the DPDP Rules require. Where UK/EU GDPR applies, we will also notify the relevant supervisory authority within 72 hours of becoming aware of it.
5. Who we share it with
Only the service providers needed to run the service, and only what each one needs:
| Purpose | Provider |
|---|---|
| Authentication | Google, Microsoft, GitHub |
| Hosting and infrastructure | Microsoft Azure, Google Cloud, Amazon Web Services, Hostinger |
| Email delivery (OTP, notifications) | Zoho Mail (Zoho Corporation), sent from our own application |
| Payments | Razorpay (Razorpay Software Private Limited) |
We do not currently use a third-party AI or model inference provider, or a third-party error monitoring service. If that changes, this table is updated before the change goes live.
We also disclose information where required by law.
We do not sell personal data.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account is active |
| After account deletion | Erased within 30 days, except where law requires retention |
| OTP codes | Minutes - deleted immediately after use or expiry |
| Authentication sessions | Until sign-out or expiry |
| Enquiries that do not become projects | Up to 12 months |
| Client and billing records | As required by Indian tax and accounting law |
| Server logs | 90 days |
7. Your rights
You may:
- Access the personal data we hold about you
- Correct anything inaccurate or incomplete
- Erase your data and delete your account
- Port your data - receive it in a structured, machine-readable format, or have it sent to another provider where technically feasible (GDPR)
- Object to processing we base on legitimate interest (GDPR)
- Restrict processing while a dispute about its accuracy or lawfulness is resolved (GDPR)
- Withdraw consent at any time - and withdrawing is as easy as giving it
- Nominate another person to exercise your rights in the event of death or incapacity (DPDP)
- Complain and have your grievance addressed
How: use the controls in your account settings where available, or email info@ay7.in.
Deleting your account also removes the link to your Google, Microsoft or GitHub account. You can separately revoke our access from your provider’s own security settings at any time.
We respond within 30 days. Grievances are resolved within 90 days as required by the DPDP Rules.
If you are unsatisfied, you may escalate to the Data Protection Board of India. If you are in the EU or UK, you may also complain to your local data protection authority.
8. Where data is processed
We operate from India. Our providers may process data in other countries, including the EU and the United States.
Where we transfer personal data out of the UK or EU, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the technical measures described in section 4.
9. Children
Our services are not directed at children under 18 and we do not knowingly collect their personal data.
10. Changes
We may update this policy. Material changes will be notified in the application or by email, and reflected in the “Last updated” date above.
11. Contact
AY7 Technologies - Abhishek Yadav, ProprietorGrievance Officer: Abhishek Yadav
Lucknow, Uttar Pradesh, India
info@ay7.in
See also our Terms of Service.