Effective 1 September 2026
Who this policy covers
This policy applies when you visit a RohitAI site, create or use an account, contact us, book a meeting, engage us for consulting, subscribe, read or watch paid content, buy physical goods, sign a document, or otherwise use the platform. RohitAI is responsible for the processing described here unless a signed agreement explains that we process particular information only on another organization's instructions.
The service is intended for adults. You must be at least 18 years old to create an account or make a purchase. We do not knowingly request personal data from children or use it for interest-based advertising; contact us if you believe a child has provided data.
Data we collect and where it comes from
We collect information you provide, including identity and contact details, verified email, account and security settings, organization membership, billing and shipping addresses, communication preferences, consulting or meeting intake, contracts and project communications, support messages, product choices, and content you submit. We also receive transaction status, payment references, refunds, disputes, subscription state, delivery and fulfillment events from the providers used to complete your request.
We create records needed to operate and secure the service, including sessions, sign-in and security events, consent and policy receipts, access rights, invoices and payment records, bookings, video progress, order history, service-delivery outcomes, and security logs. We may receive information from an organization that invites you, calendar or conferencing services you connect, electronic-signing providers, payment providers, email providers, carriers, and other providers you ask us to use.
Payment card, bank-account, or UPI credentials are entered with the selected payment provider and are not stored by RohitAI. We retain provider references and financial evidence needed to reconcile a payment, issue a refund, respond to a dispute, maintain accounts, and comply with law.
Why we use personal data
We use personal data to provide and administer the service you request; verify identity; create and protect accounts; quote, contract, invoice, take payment, reconcile, refund, fulfill, and grant access; schedule meetings; deliver consulting and support; publish preferences; operate subscriptions; prevent fraud and misuse; preserve system integrity; maintain records; and comply with legal, tax, accounting, consumer-protection, and dispute obligations.
Where applicable, the legal basis is performance of a contract or steps you request before a contract, compliance with a legal obligation, consent for an optional activity, or our legitimate interests in operating, securing, improving, and defending the service without overriding your rights. Marketing email is based on a separate opt-in and can be withdrawn. Optional advertising technologies are disabled until the applicable consent choice permits them.
We do not sell personal data for money. If interest-based advertising is enabled, disclosures to advertising technology providers may be treated as a sale, sharing, or targeted advertising under some laws; you can reject optional advertising or use a recognized opt-out preference signal as described below.
Recipients and service providers
We disclose only what is needed to providers that host or protect the platform; store private or public files; process payments; deliver transactional email; manage opted-in marketing; provide calendar, conferencing, signing, media, analytics, or advertising functions; fulfill or deliver orders; provide professional advice; or support legal and security obligations. Some recipients, such as payment networks or advertising providers, may also process information under their own terms and legal responsibilities.
We may disclose information to an organization connected to your project, contract, or account according to its membership and permissions; to authorities when lawfully required; to protect people, rights, or the platform; or as part of a business reorganization subject to appropriate confidentiality and notice. We do not give an organization access merely because email domains match.
International transfers
RohitAI is operated from India and service providers may process information in India, the United States, the European Economic Area, or other countries. Privacy protections can differ from those where you live. Where law requires a transfer mechanism, we use an applicable adequacy decision, contractual safeguards, provider data-protection terms, or another lawful mechanism, and apply technical and organizational safeguards proportionate to the data and service.
Retention and deletion
We keep personal data only as long as needed for the purpose collected, an active account or service, security, recordkeeping, or a legal claim. Retention depends on the record type, contract and subscription lifecycle, statutory tax and accounting periods, payment or dispute windows, safety and fraud needs, backup schedules, and any valid legal hold. We then delete, de-identify, or restrict the data where technically and legally appropriate.
A privacy export is private and expires after seven days. Account erasure does not delete immutable invoices, payment and ledger evidence, contracts, orders, consent or policy receipts, fraud-prevention evidence, or consequential audit records that must be preserved; those records are minimized or pseudonymized where possible. Encrypted backups age out under their retention schedule rather than being selectively rewritten, and restored data remains subject to the recorded deletion state.
Your rights and choices
Depending on where you live and whether an exemption applies, you may request access, a copy, correction, completion, deletion, restriction, portability, withdrawal of consent, or information about processing and recipients. You may object to certain legitimate-interest processing, opt out of sale, sharing, targeted advertising, or profiling, and appeal or complain to an applicable data-protection authority. You will not receive discriminatory service for exercising an applicable privacy right, although data needed to provide a requested product cannot always be deleted while that product is active.
Use the account privacy center when available or the privacy contact details below. We verify requests in a proportionate way and may ask for information needed to prevent disclosure to the wrong person. An authorized agent must provide valid authority and we may still verify the person. If we deny or limit a request, we explain the reason and available appeal route where required.
You can unsubscribe from marketing email using the message link or account preferences without affecting transactional messages needed for an account, purchase, security alert, contract, or service. Cookie & ad choices controls optional advertising, and supported Global Privacy Control signals are honored as an opt-out. You may also complain to the Data Protection Board of India or another competent regulator once and where the applicable process is available.
Security and incidents
We use access controls, encryption in transit, protected storage, session and MFA controls, least-privilege service identities, upload scanning, logging restrictions, backups, and audit evidence designed to protect the platform. No internet service is risk-free. If a personal-data incident requires notice, we will notify affected people and authorities in the form and time required by applicable law.
Changes and complaints
We publish a new version and effective date when this policy changes. Material changes may also be notified through the service or email when appropriate. A later version does not rewrite the policy acceptance evidence attached to an earlier transaction.
Contact the grievance officer listed below first so the issue can be investigated and recorded. Consumer or privacy rights that cannot lawfully be waived remain available, including the right to approach an applicable regulator, consumer forum, or court.
Contact
General questions: [email protected]. Customer care: +919999999999. Privacy grievances: [email protected] (Rohit Ramachandran).
RohitAi
Bangalore, Karnataka, India
Account holders can also use the privacy center.