Privacy Policy
We build a tool for governing AI responsibly, so we hold ourselves to the same standard with your data: collect only what the service needs, be explicit about where it goes, and keep you in control.
1. Who we are
DoAIRight is a product of Halyon Tech LLP (“Halyon Tech LLP”, “we”, “us”), the data controller for the personal data described here. DoAIRight provides a readiness assessment and a subscription application that helps organizations build and sustain an ISO/IEC 42001 AI Management System. This policy explains what personal data we process and why. For privacy questions, contact [email protected].
2. Data we collect
- Account data — your name, work email, hashed password, and the organization (tenant) you belong to.
- Assessment data — the answers you provide in the free readiness assessment and the resulting score.
- AIMS content — the policies, risks, controls, documents, actions, audits and other records you create inside the application. This is your organization's content; you own it.
- Billing data — subscription status and identifiers. Card details are handled directly by our payment processor; we never see or store full card numbers.
- Usage & technical data — logs needed to operate the service securely (e.g. request metadata, error diagnostics).
3. How we use it
We process personal data to:
- Provide, secure and improve the assessment and the AIMS application.
- Authenticate you and isolate your organization's data from every other tenant.
- Generate AI-assisted drafts and recommendations you explicitly request.
- Send transactional and reminder emails related to your AIMS.
- Process subscriptions and comply with our legal obligations.
We do not sell your personal data, and we do not use your AIMS content or assessment answers to train third-party AI models.
4. Sub-processors
We rely on a small set of reputable providers to run the service. Each processes data only as needed to deliver its function:
- Railway — application hosting and managed database.
- Google (Gemini) & Groq — AI model inference for drafts and assistant responses you request.
- Razorpay — subscription billing and payment processing.
- Resend — transactional and reminder email delivery.
- An S3-compatible object store — evidence and document file storage.
AI providers process the specific prompt content you submit to generate a response and, per their API terms, do not use that content to train their models.
5. Legal basis & consent
Where the law requires a legal basis, we rely on your consent (given when you sign up or submit a form), the performance of our contract with you, and our legitimate interests in operating and securing the service. Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), we process personal data on the basis of your consent or applicable legitimate uses, and only for the purposes described here. You may withdraw consent at any time (see “Your rights”); withdrawal does not affect processing already carried out.
6. Retention
We keep account and AIMS data for as long as your organization maintains an active account, and for a limited period afterward to meet legal and operational needs. You can delete your workspace and its data yourself at any time from Settings → Data & privacy; otherwise we delete or anonymize data on request, except where retention is legally required.
7. Your rights
Subject to your jurisdiction (including the DPDP Act and, where applicable, the GDPR), you have the right to:
- Access — obtain a copy of your personal data, including a full self-service export in-app.
- Correction — correct or update inaccurate or incomplete data, directly in the app.
- Erasure — delete your workspace and personal data (subject to legal retention).
- Withdraw consent — at any time, without affecting prior processing.
- Grievance redressal — escalate a concern to our Grievance Officer (below).
- Nomination — nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act.
To exercise any right you can't complete in-app, email [email protected]. We respond within the timeframes required by applicable law.
8. Grievance Officer
In line with the DPDP Act and Indian IT rules, you may contact our Grievance Officer for any complaint about how your personal data is handled:
- Grievance Officer, Halyon Tech LLP
- Email: [email protected]
We acknowledge grievances promptly and aim to resolve them within the statutory period.
9. International data transfers
Some of our sub-processors (for example, AI inference and email delivery) may process data on servers outside your country, including outside India. Where we transfer personal data across borders, we do so only to the extent permitted by applicable law and rely on our providers' contractual safeguards. We do not transfer data to any jurisdiction restricted by an applicable government notification.
10. Children
The service is intended for organizational use by adults and is not directed to children. We do not knowingly process the personal data of children as defined under the DPDP Act. If you believe a child's data has been provided to us, contact us and we will delete it.
11. Security
Every organization's data is isolated at the database level, traffic is encrypted in transit, and access is scoped to the minimum required. See our Trust Center for how we secure the platform.
12. Breach notification
If a personal data breach is likely to affect you, we will notify the relevant Data Protection Board / supervisory authority and affected users without undue delay, as required by applicable law, and describe the steps we're taking in response.
13. Changes
We may update this policy as the service evolves. Material changes will be reflected by the “last updated” date above and, where appropriate, communicated to you directly.