Anweshna AI Due Diligence Platform
Version 1.1 — Effective 28 September 2026The Anweshna platform is operated by Anweshna AI Due Diligence, registered office E46 Mahadevpur 4, Namsai-792105, Arunachal Pradesh, India ("Anweshna", "we"). Privacy enquiries: privacy@anweshna.com.
We act in two distinct roles:
| Processing | GDPR basis | Notes |
|---|---|---|
| Account, engagement analysis, billing | Contract — Art. 6(1)(b) | Needed to deliver the service you purchased |
| Security logging, rate limiting, audit trail, error telemetry | Legitimate interests — Art. 6(1)(f) | Fraud/abuse prevention, service integrity; assessed as not overriding your rights |
| Consent log retention | Legal obligation / legitimate interests | Evidence of contract formation and consent |
| Tax and accounting records | Legal obligation — Art. 6(1)(c) | Statutory retention periods |
| Marketing emails, demo follow-ups | Consent — Art. 6(1)(a) | Withdrawable at any time; every email has an unsubscribe link |
| First-party page-view analytics | Legitimate interests — Art. 6(1)(f) | Cookie-less, first-party, aggregate reporting only |
Under India's DPDP Act 2023, we process personal data with consent or for legitimate uses recognised by the Act, and honour Data Principal rights (Section 10). For California residents, see Section 10.3 — we do not sell or share personal information as defined by the CCPA/CPRA.
Documents uploaded by clients may contain personal data of third parties (e.g. employees or directors of a target company). The uploading client, as controller, is responsible for its lawful basis; we process such data solely as processor per Section 1.
We do not use your documents or analysis results to train AI models, and we do not permit our AI sub-processor to do so. We do not sell personal data, and we do not run third-party advertising or tracking.
When a document is analysed, its extracted text (not the original file) is transmitted over encrypted channels to our AI inference provider, Anthropic, PBC (US), to generate risk scores and findings. This processing is governed by Anthropic's commercial API terms and data processing addendum, under which API inputs and outputs are not used to train Anthropic's models and are retained by Anthropic only for limited abuse-monitoring periods. Analysis output is stored encrypted in our database, attributed to your account.
Reports are labelled as AI-generated and carry provenance metadata identifying who downloaded them and when.
The in-portal Kai assistant (Pro and above) answers product questions. Your message is sent to the same AI inference provider, Anthropic, PBC (US), under the same commercial API terms as above — not used to train Anthropic's models, retained by them only for limited abuse-monitoring periods. Kai answers only from our own published product documentation. It has no access to your documents, analyses, or reports, and this is enforced rather than assumed: the assistant runs on a separate, restricted database role granted access to two tables — its own chat log and its escalation queue — and to nothing else.
Please do not paste confidential deal content into the assistant. Unlike your uploaded documents, chat messages are not encrypted at rest, and a message escalated to a human is read by our staff. We are the Controller for these messages — they are support communications, not Engagement Data — so the processor protections in the DPA do not apply to them. They are deleted on the schedule in Section 8. If you need to discuss a specific document, use the analysis and report features, where content is encrypted per-client and covered by the DPA.
The authoritative, maintained list of sub-processors (with locations and roles) is Annex III of our DPA. As of this version it comprises:
We may also disclose data to professional advisers, and to authorities where legally compelled — in which case we will notify the affected client where the law permits.
Where personal data protected by the EU/UK GDPR is transferred to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA), plus supplementary measures including application-level encryption. Details and copies are available on request via privacy@anweshna.com.
| Data | Retention |
|---|---|
| Engagement documents & analyses | Duration of subscription (or deal-room life for per-deal purchases) + 30-day export window after termination, then deleted on a reviewed basis — normally within 30 days of the window closing, in any event within 90 days |
| Extracted text of analysed documents | Deleted 30–31 days after the document's analysis completes. The analysis and its reports are kept for the period above; asking questions about the document or re-analysing it after that requires uploading it again |
| Cross-Doc comparison results (file names and findings) | Until you delete them, or until Engagement Data is deleted after termination (above). Files uploaded for a comparison are deleted when you leave Cross-Doc, and in any event within 6 hours |
| Account data (name, email, keys) | Subscription + up to 12 months (billing/legal defence) |
| Server/security logs & error telemetry | 90 days, then deleted or anonymised |
| Kai support assistant chat logs and escalations | 90 days, then deleted |
| Audit logs (uploads, analyses, report access) | 7 years (regulatory defensibility) |
| Consent records (clickwrap log) | 7 years |
| Billing & tax records | 7 years or as required by tax law |
| Demo/sales leads | 12 months from collection unless converted or consent renewed |
| Public demo uploads and reports | Deleted when you start a new analysis or close the page, and in any event within 48 hours |
| Public demo usage records (the demo email recorded against each demo analysis) | 7 years, with the audit logs above |
| Page-view analytics | Raw entries 12 months; aggregates indefinitely |
Measures include: application-level encryption of document content and analysis results at rest with per-client derived keys and a key-rotation procedure; TLS in transit; per-tenant isolation enforced on every query with database-level row security policies as a backstop; role-based team access; authenticated, rate-limited APIs with brute-force lockouts; append-only consent logging; audit logging of writes and report access; and report provenance watermarking. Full technical and organisational measures are in Annex II of the DPA. We notify affected clients of personal data breaches without undue delay, and in any event within 48 hours of becoming aware (see DPA §7).
Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Self-serve: GET /api/v1/account/export (portability) and DELETE /api/v1/account (erasure request), or email privacy@anweshna.com. We respond within 30 days. You may complain to your supervisory authority (UK: ICO; EU: your national DPA).
Data Principals may access a summary of processing, request correction and erasure, nominate a representative, and raise grievances with our Grievance Officer (Section 15), escalating to the Data Protection Board of India if unresolved.
Rights to know, delete, correct, and to non-discrimination. We do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information beyond permitted service purposes. Submit requests to privacy@anweshna.com; we verify via your account email.
We honour equivalent statutory rights (e.g. Brazil LGPD, Canada PIPEDA, Australia Privacy Act) on request.
Note: erasure requests cannot override retention we are legally required to keep (tax, consent evidence, audit integrity); those records are retained per Section 8 and then deleted.
The platform produces AI-generated risk analyses of documents for professional review. We do not make automated decisions producing legal or similarly significant effects about natural persons (GDPR Art. 22). Our terms require clients to keep a qualified human in the loop before acting on any output.
The platform is a business tool and is not directed at anyone under 18. We do not knowingly collect children's data; if you believe we hold any, contact us and we will delete it.
We will notify registered users of material changes by email or in-platform notice at least 30 days before they take effect, and update the version and date below. Prior versions are available on request.
Offline copies of the Anweshna legal documents, generated from these pages. The published web page remains the authoritative version.