Skip to main content
DPDP Act 2023 Compliant

Privacy Policy

Your data is yours. Here is exactly how we collect, use, and protect it — in plain language, not legal jargon.

Last updated: March 28, 2026

TL;DR

  • We collect only what we need — your email, form responses, and payment references. Nothing more.
  • We never sell your data. It is used only to deliver services you asked for and send emails you subscribed to.
  • You are in control. Access, correct, or delete your data anytime by emailing automatewithpriya@gmail.com. We respond within 72 hours.

Who We Are

Automate with Priya is an enterprise L&D consulting practice operated by Vishnu Priya (“we,” “us,” or “our”), headquartered in India. Under the DPDP Act 2023, we are the Data Fiduciary — responsible for how your personal data is processed.

What We Collect

DataSourcePurpose
Email addressSignup, newsletter, authAccount creation, service delivery, marketing (with consent)
Name & professional roleService questionnairesTailoring your deliverables (Audit, Blueprint, etc.)
Organisation detailsService questionnairesContextualizing service delivery
UPI transaction referenceWhatsApp confirmationPayment verification & tax compliance
Questionnaire responsesService intake formsCreating your custom deliverables
Device & browser infoAutomatic (analytics)Website optimization

We do NOT collect:

  • Bank account numbers, credit/debit card details, or UPI IDs
  • Aadhaar, PAN, or any government identity numbers
  • Biometric data
  • Data from anyone under 18

How We Use Your Data

  • Service delivery: Processing your questionnaire responses to create Audits, Blueprints, Frameworks, or other deliverables
  • Communication: Sending service updates, deliverables, and follow-ups via email or WhatsApp
  • Newsletter: Weekly AI and L&D insights — only if you explicitly subscribe, with one-click unsubscribe in every email
  • Improvement: Understanding which services are most valuable to improve our offerings
  • Legal compliance: Meeting obligations under Indian law

We never sell, rent, or trade your personal data to third parties. Period.

Third-Party Services

We use these services to operate our platform. Each processes data on our behalf as a Data Processor under the DPDP Act:

ServiceWhat It DoesData It Accesses
SupabaseAuthentication & databaseEmail, auth tokens, questionnaire responses, service progress
ResendTransactional & marketing emailEmail address
Vercel (Hosting)Website hostingServer logs, IP address (standard hosting)
Vercel Speed InsightsCore Web Vitals performance telemetryAnonymous page performance metrics (LCP, INP, CLS). No identifiers stored.
PostHogProduct analytics (page views, feature usage)Anonymous session ID stored in browser localStorage. No PII. Used to measure which features help L&D leaders find what they need.
SentryError trackingError stack traces, browser + OS info. Helps us fix bugs fast.
Cashfree PaymentsPayment gateway (UPI, Cards, Net Banking, Wallets)Transaction metadata. Cashfree is PCI-DSS compliant; we never store card/UPI credentials.
WhatsApp BusinessSupport & pre-launch drop reservationsPhone number, messages (operated by Meta)

Data Storage & Cross-Border Transfers

Some of our third-party services store data on servers located outside India:

  • Supabase: Data may be stored in AWS data centers (US/EU region, depending on project configuration)
  • Resend: Email delivery infrastructure located in the United States
  • Vercel & Vercel Speed Insights: Edge network with global distribution; performance telemetry aggregated in the US
  • PostHog: Anonymous product-analytics data routed to PostHog's US region (us.i.posthog.com)
  • Sentry: Error telemetry routed to Sentry's US infrastructure

Under the DPDP Act 2023, cross-border transfers are permitted to countries not restricted by the Central Government. As of March 28, 2026, no countries have been restricted. We will update this policy if regulations change.

Payments

All payments are processed via UPI QR code and confirmed through WhatsApp. This means:

  • We are not a payment gateway — the transaction happens directly between your UPI app and our bank
  • We never store your UPI ID, bank account number, or any payment credentials
  • We do store: transaction reference numbers, payment amounts, and dates — for order fulfillment and tax compliance
  • Payment confirmation screenshots sent via WhatsApp are used only for verification

Cookies

CookieTypePurposeConsent Required
Supabase auth tokenEssentialKeeps you logged inNo (required for function)
Session cookieEssentialMaintains your session stateNo (required for function)
awp_doorFunctionalRemembers which audience door you selected (individual / teams / enterprise) so navigation stays coherentNo (legitimate use under DPDP)

We do not use advertising cookies, cross-site tracking pixels, or marketing trackers.

Analytics storage: PostHog (product analytics) and Vercel Speed Insights (performance telemetry) use browser localStorage to store anonymous identifiers — not cookies. This data is aggregated, contains no PII, and is used solely to understand which pages and features help L&D leaders. You can clear this by clearing your browser's site data.

Data Retention

Data TypeRetention PeriodReason
Newsletter subscribersUntil you unsubscribeConsent-based
Service questionnaire data12 months after deliveryFollow-up support & upgrades
Payment references7 yearsIndian tax law requirement
Website analyticsAggregated indefinitelyAnonymised, non-personal
Auth/session dataUntil account deletionRequired for login

After the retention period, data is permanently deleted. You can request early deletion at any time.

Your Rights Under the DPDP Act 2023

As a Data Principal, you have the right to:

Right to Access: Request a copy of all personal data we hold about you.

Right to Correction: Request correction of inaccurate or incomplete data.

Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.

Right to Withdraw Consent: Withdraw consent for marketing emails at any time. One-click unsubscribe in every email.

Right to Grievance Redressal: Raise a complaint about our data practices — we respond within 72 hours.

Right to Nominate: Nominate another person to exercise your data rights on your behalf.

To exercise any right, email automatewithpriya@gmail.com. We respond within 72 hours and complete actions within 30 days.

You also have the right to lodge a complaint with the Data Protection Board of India.

Children's Privacy

Our services are designed for L&D professionals and enterprise teams. This website is intended for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with data, please contact us immediately and we will delete it.

Data Security

  • All data transmission encrypted via HTTPS/TLS
  • Database access restricted via Row-Level Security (RLS) policies
  • API keys and service credentials are never exposed in client-side code
  • Questionnaire responses stored in encrypted databases with access controls
  • Regular security reviews of codebase and infrastructure

No system is 100% secure, but we take reasonable and appropriate measures to protect your information. In the event of a data breach, we will notify the Data Protection Board and affected users as required by the DPDP Act.

Changes to This Policy

We may update this privacy policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email to active clients and subscribers. The “Last Updated” date at the top of this page indicates when the policy was last revised.

Questions About Your Data

Name: Vishnu Priya

Role: Founder & Data Protection Contact

Email: automatewithpriya@gmail.com

Response time: Within 72 hours

Resolution time: Within 30 days

Still not resolved? You have the right to raise a complaint with the Data Protection Board of India.

Email Priya
Chat with Priya