Anweshna AI Due Diligence Platform
Version 1.0 — Effective 23 July 2026The Anweshna platform is operated by Anweshna AI Due Diligence, registered office E46 Mahadevpur 4, Namsai-792105, Arunachal Pradesh, India ("Anweshna", "we"). Privacy enquiries: privacy@anweshna.com.
We act in two distinct roles:
| Processing | GDPR basis | Notes |
|---|---|---|
| Account, engagement analysis, billing | Contract — Art. 6(1)(b) | Needed to deliver the service you purchased |
| Security logging, rate limiting, audit trail, error telemetry | Legitimate interests — Art. 6(1)(f) | Fraud/abuse prevention, service integrity; assessed as not overriding your rights |
| Consent log retention | Legal obligation / legitimate interests | Evidence of contract formation and consent |
| Tax and accounting records | Legal obligation — Art. 6(1)(c) | Statutory retention periods |
| Marketing emails, demo follow-ups | Consent — Art. 6(1)(a) | Withdrawable at any time; every email has an unsubscribe link |
| First-party page-view analytics | Legitimate interests — Art. 6(1)(f) | Cookie-less, first-party, aggregate reporting only |
Under India's DPDP Act 2023, we process personal data with consent or for legitimate uses recognised by the Act, and honour Data Principal rights (Section 10). For California residents, see Section 10.3 — we do not sell or share personal information as defined by the CCPA/CPRA.
Documents uploaded by clients may contain personal data of third parties (e.g. employees or directors of a target company). The uploading client, as controller, is responsible for its lawful basis; we process such data solely as processor per Section 1.
We do not use your documents or analysis results to train AI models, and we do not permit our AI sub-processor to do so. We do not sell personal data, and we do not run third-party advertising or tracking.
When a document is analysed, its extracted text (not the original file) is transmitted over encrypted channels to our AI inference provider, Anthropic, PBC (US), to generate risk scores and findings. This processing is governed by Anthropic's commercial API terms and data processing addendum, under which API inputs and outputs are not used to train Anthropic's models and are retained by Anthropic only for limited abuse-monitoring periods. Analysis output is stored encrypted in our database, attributed to your account.
Reports are labelled as AI-generated and carry provenance metadata identifying who downloaded them and when.
The authoritative, maintained list of sub-processors (with locations and roles) is Annex III of our DPA. As of this version it comprises:
We may also disclose data to professional advisers, and to authorities where legally compelled — in which case we will notify the affected client where the law permits.
Where personal data protected by the EU/UK GDPR is transferred to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum / IDTA), plus supplementary measures including application-level encryption. Details and copies are available on request via privacy@anweshna.com.
| Data | Retention |
|---|---|
| Engagement documents & analyses | Duration of subscription (or deal-room life for per-deal purchases) + 30-day export window after termination, then deleted |
| Account data (name, email, keys) | Subscription + up to 12 months (billing/legal defence) |
| Server/security logs & error telemetry | 90 days, then deleted or anonymised |
| Audit logs (uploads, analyses, report access) | 7 years (regulatory defensibility) |
| Consent records (clickwrap log) | 7 years |
| Billing & tax records | 7 years or as required by tax law |
| Demo/sales leads | 12 months from collection unless converted or consent renewed |
| Page-view analytics | Raw entries 12 months; aggregates indefinitely |
Measures include: application-level encryption of document content and analysis results at rest with per-client derived keys and a key-rotation procedure; TLS in transit; per-tenant isolation enforced on every query with database-level row security policies as a backstop; role-based team access; authenticated, rate-limited APIs with brute-force lockouts; append-only consent logging; audit logging of writes and report access; and report provenance watermarking. Full technical and organisational measures are in Annex II of the DPA. We notify affected clients of personal data breaches without undue delay (see DPA §8).
Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. Self-serve: GET /api/v1/account/export (portability) and DELETE /api/v1/account (erasure request), or email privacy@anweshna.com. We respond within 30 days. You may complain to your supervisory authority (UK: ICO; EU: your national DPA).
Data Principals may access a summary of processing, request correction and erasure, nominate a representative, and raise grievances with our Grievance Officer (Section 15), escalating to the Data Protection Board of India if unresolved.
Rights to know, delete, correct, and to non-discrimination. We do not sell or share personal information for cross-context behavioural advertising, and we do not use sensitive personal information beyond permitted service purposes. Submit requests to privacy@anweshna.com; we verify via your account email.
We honour equivalent statutory rights (e.g. Brazil LGPD, Canada PIPEDA, Australia Privacy Act) on request.
Note: erasure requests cannot override retention we are legally required to keep (tax, consent evidence, audit integrity); those records are retained per Section 8 and then deleted.
The platform produces AI-generated risk analyses of documents for professional review. We do not make automated decisions producing legal or similarly significant effects about natural persons (GDPR Art. 22). Our terms require clients to keep a qualified human in the loop before acting on any output.
The platform is a business tool and is not directed at anyone under 18. We do not knowingly collect children's data; if you believe we hold any, contact us and we will delete it.
We will notify registered users of material changes by email or in-platform notice at least 30 days before they take effect, and update the version and date below. Prior versions are available on request.