Privacy Policy

Anweshna AI Due Diligence Platform

Version 1.0 — Effective 23 July 2026

1. Who We Are & Our Roles

The Anweshna platform is operated by Anweshna AI Due Diligence, registered office E46 Mahadevpur 4, Namsai-792105, Arunachal Pradesh, India ("Anweshna", "we"). Privacy enquiries: privacy@anweshna.com.

We act in two distinct roles:

2. Data We Collect

2.1 Account and contact data

2.2 Engagement data (processed as Processor)

2.3 Technical and security data

2.4 Billing data

2.5 Consent records

2.6 Communications

3. Lawful Bases

ProcessingGDPR basisNotes
Account, engagement analysis, billingContract — Art. 6(1)(b)Needed to deliver the service you purchased
Security logging, rate limiting, audit trail, error telemetryLegitimate interests — Art. 6(1)(f)Fraud/abuse prevention, service integrity; assessed as not overriding your rights
Consent log retentionLegal obligation / legitimate interestsEvidence of contract formation and consent
Tax and accounting recordsLegal obligation — Art. 6(1)(c)Statutory retention periods
Marketing emails, demo follow-upsConsent — Art. 6(1)(a)Withdrawable at any time; every email has an unsubscribe link
First-party page-view analyticsLegitimate interests — Art. 6(1)(f)Cookie-less, first-party, aggregate reporting only

Under India's DPDP Act 2023, we process personal data with consent or for legitimate uses recognised by the Act, and honour Data Principal rights (Section 10). For California residents, see Section 10.3 — we do not sell or share personal information as defined by the CCPA/CPRA.

Documents uploaded by clients may contain personal data of third parties (e.g. employees or directors of a target company). The uploading client, as controller, is responsible for its lawful basis; we process such data solely as processor per Section 1.

4. How We Use Data

We do not use your documents or analysis results to train AI models, and we do not permit our AI sub-processor to do so. We do not sell personal data, and we do not run third-party advertising or tracking.

5. AI Processing Disclosure

When a document is analysed, its extracted text (not the original file) is transmitted over encrypted channels to our AI inference provider, Anthropic, PBC (US), to generate risk scores and findings. This processing is governed by Anthropic's commercial API terms and data processing addendum, under which API inputs and outputs are not used to train Anthropic's models and are retained by Anthropic only for limited abuse-monitoring periods. Analysis output is stored encrypted in our database, attributed to your account.

Reports are labelled as AI-generated and carry provenance metadata identifying who downloaded them and when.

6. Sub-processors & Recipients

The authoritative, maintained list of sub-processors (with locations and roles) is Annex III of our DPA. As of this version it comprises:

We may also disclose data to professional advisers, and to authorities where legally compelled — in which case we will notify the affected client where the law permits.

7. International Transfers & Data Residency

Where personal data protected by the EU/UK GDPR is transferred to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA), plus supplementary measures including application-level encryption. Details and copies are available on request via privacy@anweshna.com.

8. Retention

DataRetention
Engagement documents & analysesDuration of subscription (or deal-room life for per-deal purchases) + 30-day export window after termination, then deleted
Account data (name, email, keys)Subscription + up to 12 months (billing/legal defence)
Server/security logs & error telemetry90 days, then deleted or anonymised
Audit logs (uploads, analyses, report access)7 years (regulatory defensibility)
Consent records (clickwrap log)7 years
Billing & tax records7 years or as required by tax law
Demo/sales leads12 months from collection unless converted or consent renewed
Page-view analyticsRaw entries 12 months; aggregates indefinitely

9. Security

Measures include: application-level encryption of document content and analysis results at rest with per-client derived keys and a key-rotation procedure; TLS in transit; per-tenant isolation enforced on every query with database-level row security policies as a backstop; role-based team access; authenticated, rate-limited APIs with brute-force lockouts; append-only consent logging; audit logging of writes and report access; and report provenance watermarking. Full technical and organisational measures are in Annex II of the DPA. We notify affected clients of personal data breaches without undue delay (see DPA §8).

10. Your Rights

10.1 EU/UK GDPR

Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Self-serve: GET /api/v1/account/export (portability) and DELETE /api/v1/account (erasure request), or email privacy@anweshna.com. We respond within 30 days. You may complain to your supervisory authority (UK: ICO; EU: your national DPA).

10.2 India DPDP Act 2023

Data Principals may access a summary of processing, request correction and erasure, nominate a representative, and raise grievances with our Grievance Officer (Section 15), escalating to the Data Protection Board of India if unresolved.

10.3 California (CCPA/CPRA)

Rights to know, delete, correct, and to non-discrimination. We do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information beyond permitted service purposes. Submit requests to privacy@anweshna.com; we verify via your account email.

10.4 Other jurisdictions

We honour equivalent statutory rights (e.g. Brazil LGPD, Canada PIPEDA, Australia Privacy Act) on request.

Note: erasure requests cannot override retention we are legally required to keep (tax, consent evidence, audit integrity); those records are retained per Section 8 and then deleted.

11. Automated Decision-Making

The platform produces AI-generated risk analyses of documents for professional review. We do not make automated decisions producing legal or similarly significant effects about natural persons (GDPR Art. 22). Our terms require clients to keep a qualified human in the loop before acting on any output.

12. Cookies, Storage & Analytics

13. Children

The platform is a business tool and is not directed at anyone under 18. We do not knowingly collect children's data; if you believe we hold any, contact us and we will delete it.

14. Changes

We will notify registered users of material changes by email or in-platform notice at least 30 days before they take effect, and update the version and date below. Prior versions are available on request.

15. Contact & Grievance Officer

Anweshna AI Due Diligence — E46 Mahadevpur 4, Namsai-792105, Arunachal Pradesh, India
Privacy requests: privacy@anweshna.com (acknowledged within 72 hours; substantive reply within 30 days)
Grievance Officer (DPDP Act): Compliance Team Lead grievance@anweshna.com
EU/UK representative: Not applicable — Anweshna does not regularly offer services to, or monitor the behaviour of, data subjects in the EU/UK and has not appointed a representative there