Legal · Draft
ALINKS Privacy Policy
How Artix collects, uses, stores, and protects personal data of ALINKS tenants (business owners).
- Version: 0.1-draft
- Data Fiduciary: Artix / Artix Private Limited
- Product: ALINKS
- DPDP Act 2023 alignment — lawyer review required
Draft v0.1 — for product implementation only. Lawyer review required before public launch. Placeholders in [brackets] will be replaced with final approved text.
1. Scope
This Policy explains how Artix collects, uses, stores, and protects personal data of tenants (business owners who register for ALINKS).
Important — end-customer data: Artix does not store your customers', patients', or buyers' personal data on Artix servers. That data is written to storage you own and control: your Google Account (Google Sheets / Drive), or your Supabase project (BYO model). See Data & Storage Addendum. For how you handle customer data, you must publish your own Privacy Policy on your mini-site.
2. Data We Collect (Tenants)
- Account: name, phone, email, business name, vertical, address, GSTIN (optional)
- Billing: subscription tier, payment history, invoices, Razorpay payment IDs
- Technical: IP address, device, browser, session logs, security logs
- Platform use: pages edited, products added, feature usage, AI credit balance
- OAuth tokens: encrypted Google/Supabase connection tokens (not sheet content)
- Gateway keys (optional): encrypted tenant Razorpay secret for BYO shop checkout — never logged in plain text
- Legal acceptances: which documents you agreed to, version, timestamp, IP
3. Data We Do Not Collect or Retain
- Customer names, phones, orders, appointments, patient details (permanent storage)
- Full contents of your Google Sheets or Supabase tables
- Card numbers (payments via tenant-hosted Razorpay checkout only)
- Clinical diagnoses or medical records
Transient processing: during a booking or checkout request, customer fields may exist in server memory only long enough to append to your Google Sheet or Supabase, then are discarded.
4. Purpose of Processing
- Provide and improve ALINKS services
- Billing and subscription management (Artix SaaS fees)
- Authentication and security
- Optional storefront checkout integration using your own payment gateway keys
- Support and abuse prevention
- Legal compliance and dispute resolution
- Aggregated analytics (no customer PII)
5. Legal Basis (DPDP)
- Consent: signup, optional features, marketing (if any)
- Contract: necessary to provide subscribed services
- Legal obligation: tax, fraud prevention, lawful requests
- Legitimate uses: security, platform integrity
7. International Transfers
Some sub-processors may process data outside India. We use appropriate safeguards as required by law.
8. Retention
- Active account: duration of subscription plus reasonable period
- Billing records: as required by tax law (typically 6–8 years)
- Security logs: 90 days [lawyer to confirm]
- Deleted account: tenant config removed; legal/billing records retained per law
- OAuth tokens: deleted on disconnect or account deletion
9. Your Rights (DPDP)
Tenants may request access, correction, erasure (subject to legal retention), grievance redressal, and nominate a contact for exercise of rights upon death or incapacity. Contact the Grievance Officer. Response within timelines per DPDP rules.
10. Security
HTTPS, encryption at rest for sensitive fields, access controls, PIN/biometric for dashboard (product feature). No system is 100% secure; report concerns promptly.
11. Breach Notification
We will notify affected tenants and authorities as required by DPDP and applicable law.
12. Children
ALINKS is for business users. Not directed at children under 18.
13. Changes
We will update this Policy with notice. Material changes may require re-consent.
14. Contact
- Data Protection / Grievance Officer: [NAME, EMAIL, ADDRESS]
- Email: privacy@alinks.online