Privacy Policy
Written to meet the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
1. Who we are and what this covers
- This policy is issued by [TODO: registered company name] ("DCS Predictive Intelligence", "we"), operating the DCS Predictive Intelligence System, a customer-retention platform for businesses in several sectors.
- For business owners and staff who hold a DCS Predictive Intelligence account, we are the Data Fiduciary: we decide why and how that data is processed.
- For business customers, the business is the Data Fiduciary and we are a Data Processor. We process customer data only on the business’s instructions. A customer exercising their rights should contact their business, which we then help fulfil.
- It is written to meet the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
2. What we collect
- Account data: name, email, phone, business name, billing address, and the role assigned to each staff login.
- Customer data entered by the business: name, contact details, date of birth, gender, membership or package terms, payments, visits, bookings and appointments, and any notes staff add. Depending on the sector this also includes sector records, such as vehicle and service history for auto workshops, and for dental clinics clinical records such as diagnoses, treatment plans and recall dates, which are health data and are visible only to clinical roles.
- Usage data: pages visited, features used, API requests, and timestamps.
- Technical data: browser type, and a salted one-way hash of the IP address. We do not store raw IP addresses.
- AI interaction data: prompts and responses exchanged with our AI features, and the tokens they consumed.
3. Why we process it, and on what basis
- To provide the service: managing customers, memberships and packages, payments, visits and appointments, and communications. Basis: performance of the contract with the business.
- To generate predictions and recommendations (renewal likelihood, disengagement risk, suggested actions). Basis: legitimate use for the purpose the business signed up for.
- To send messages to customers on the business’s behalf. Basis: the customer’s consent, recorded per channel. A customer who has not consented is never contacted, and this is enforced in code before any message is queued — not by policy alone.
- To improve our prediction models across customers. Basis: the customer’s explicit, separate consent. See section 5.
- To meet legal and security obligations, including keeping processing logs. Basis: legal obligation.
4. Consent, and what happens without it
- Consent is recorded per customer and per channel (WhatsApp, email, SMS, push). The business collects it when adding a customer.
- Customers imported from another system start with no consent recorded. The business must obtain it before we will send anything.
- Withdrawing consent is as easy as giving it: a customer can reply STOP to any WhatsApp message, use the unsubscribe link in any email, or ask the business directly.
- Withdrawing consent stops all outbound messaging immediately. It does not delete the customer’s record, because the business still needs it to run the membership the customer is paying for.
5. Model training across businesses
- We improve our prediction models using data from multiple businesses. This produces better predictions for every business than any one business’s data could, particularly for newer businesses with little history of their own.
- A customer’s data is used for this ONLY where that customer has given separate, explicit consent. This is a distinct permission from consent to be contacted, and refusing it has no effect on the service the customer receives — they are still scored and served by the models, they simply do not contribute to training them.
- Data of anyone under 18 is never used for model training, per section 9 of the DPDP Act.
- We do not sell data, and we do not share it with other businesses in identifiable form. Models learn patterns, not individuals.
- Consent can be withdrawn at any time. Withdrawal stops future use; a model already trained cannot un-learn one customer’s contribution, and we say so plainly rather than implying otherwise.
6. Who else processes data
- Razorpay — payment processing.
- WhatsApp Business API (Meta) — message delivery.
- OpenAI, and where configured Anthropic and Google — AI text generation. Prompts may include customer first names and membership context. They do not include payment details, and provider data is not used to train their models under our API terms.
- Email delivery providers — transactional email.
- Cloud hosting — servers located in India.
- Each is bound by contract to process data only on our instructions.
7. How long we keep it
- Customer and customer records: for as long as the business holds a DCS Predictive Intelligence account, then 90 days after closure, then deleted.
- Processing and audit logs: 400 days. DPDP Rule 6 requires at least one year; we keep slightly longer so an incident found near the boundary can still be investigated.
- AI interaction logs: 180 days.
- Financial records: as required by Indian tax law, which is longer than our own retention would be.
8. Your rights
- Access — a copy of your data and a summary of how it is processed.
- Correction — have inaccurate data fixed.
- Erasure — have data deleted where we are not required to keep it.
- Nomination — nominate someone to exercise your rights if you cannot.
- Grievance redressal — complain to us first; we respond within 90 days as the Rules require. If unsatisfied, you may complain to the Data Protection Board of India.
- Business owners and staff: write to privacy@[TODO: domain]. Business customers: contact your business, which is the Data Fiduciary for your data. We help businesses fulfil these requests.
9. Security
- Each business’s data lives in a separate database, so one business’s data cannot be reached from another business’s account by any code path.
- Passwords are hashed with bcrypt. API keys are stored as SHA-256 hashes and shown once at creation — we cannot recover a key, which means a breach of our database does not hand over working credentials.
- Every state-changing action is recorded with the actor, the time, and a hashed IP.
- A personal data breach will be reported to the Data Protection Board and to affected people without delay, and in any case within 72 hours of becoming aware.
10. Children
We do not knowingly process the data of anyone under 18 without verifiable parental consent, and we never use it for model training or targeted messaging, in line with section 9 of the DPDP Act. A business enrolling a minor must obtain and record parental consent.
11. Changes and contact
- Material changes will be notified by email at least 14 days before they take effect.
- Grievance Officer: [TODO: name of Grievance Officer], grievance@[TODO: domain].
- Data Protection Officer: dpo@[TODO: domain].
- Registered address: [TODO: registered address].
Last updated: 2 September 2026