EFFECTIVE DATE: 16 June 2026
This notice is provided under Section 5 of the Digital Personal Data Protection Act, 2023 (DPDP Act). It is written in clear language so you can understand exactly what we do with your personal data.
Gevox (operated by Suryansh Sagar, trading as Gevox, registered at 3/200 Rakshapuram, Mawana Road, Meerut, Uttar Pradesh, [250001]) provides a software platform that helps Indian businesses and professionals comply with the DPDP Act. In this policy, "we", "us" and "Gevox" mean Suryansh Sagar, trading as Gevox, and "you" means any individual whose personal data we process.
Gevox handles personal data in two different ways, and your rights depend on which applies:
(a) As a Data Fiduciary — for the personal data of your own account (your email, name, company details and phone number), we decide the purposes and means of processing. This policy governs that data.
(b) As a Data Processor — when you enter personal data about other people into our tools (for example, details of individuals affected by a breach, or the name and email of a customer who has made a rights request), you are the Data Fiduciary for that data and Gevox merely processes it on your instructions, under our Data Processing Agreement. We do not use that data for our own purposes.
• Account data you give us at sign-up: work email, password (stored only in encrypted/hashed form), company name, industry, and phone number (optional).
• Company profile data you choose to add: legal entity name, registered address, website, grievance officer details, and your significant-data-fiduciary self-assessment answers.
• Content you generate: compliance scans, generated documents, records of processing, and evidence you save to your vault.
• Technical and usage data needed to run the service securely (for example, log-in events and security logs).
• Payment data when you buy a plan. Payments are handled by Razorpay; we never see or store your full card number, UPI PIN or bank credentials. We keep the payment reference, and a record that your account has claimed its one-time Starter Pass. That record is held against your account and nothing else, and it is erased when your account is erased.
• The IP address recorded when you buy a Starter Pass, kept as a security log. Rule 6(e) of the DPDP Rules 2025 requires logs of this kind to be retained for one year so that unauthorised access can be detected, investigated and remedied. We keep it for one year from the day it is recorded and then erase it. Because Rule 6(e) obliges us to hold it for that full year, this one record is kept even if you close your account before the year is up; everything else we hold about you is erased as normal. We may review these records by hand to spot unusual purchase patterns; we never use them to refuse anyone access automatically.
We do not knowingly collect more than we need for the purposes below.
We process your account data on the basis of your consent (Section 6, DPDP Act), which you give at sign-up, for these purposes: to create and operate your account; to provide the compliance tools you request; to send you service and security communications; and to keep the platform secure and prevent misuse.
We keep your account data for as long as your account is active. If you close your account, or ask us to delete your data, we erase it within 30 days, unless we are required to retain specific records to meet a legal obligation. Content you create about other people stays under your control — you can delete it from within the product, and it is erased when you close your account.
There is one exception to the 30 days. If you have paid us, we issue a Bill of Supply for that payment, and Indian tax law requires us to keep it for six years from the end of the financial year it belongs to. That document is kept even if you close your account before the six years are up, because the law obliges us to. It holds only your billing details: your name, your email address, the amount, the plan and the payment reference. It holds none of your compliance work, none of your clients’ data, and no card or bank details, which we never see. Everything else we hold about you is erased as normal.
We do not sell your personal data. We use a small number of trusted service providers who process data only on our instructions:
• Supabase — database and authentication, hosted in India (Mumbai region).
• Anthropic (USA) — the AI engine that generates your documents and analyses your scans. See Section 7 on cross-border transfer.
• Railway and Vercel — application and website hosting.
• Google — for sending service emails.
• Razorpay (India) — for payment processing, only when you subscribe to a paid plan.
Our current list of processors is kept up to date on this page.
Your data is primarily stored in India. The one exception is that, when you generate a document or run an AI analysis, the relevant content is sent to our AI provider's servers in the United States for processing, and is not retained by them for training. We make this transfer in line with Section 16 of the DPDP Act. If you would prefer not to use the AI features, you can simply not use them.
Under the DPDP Act, you have the right to:
• Access a summary of the personal data we hold about you and how we process it (Section 11).
• Correct or erase your personal data (Section 12).
• Grievance redressal — have your complaints addressed (Section 13).
• Nominate another person to exercise your rights if you are unable to (Section 14).
• Withdraw consent at any time (Section 6). Withdrawing is as easy as giving consent.
To exercise any of these, contact our Grievance Officer (Section 11). If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Gevox is a business tool and is not directed at children. We do not knowingly collect the personal data of anyone under 18. If you believe a child has provided us data, contact our Grievance Officer and we will erase it.
We apply reasonable security safeguards as required by Section 8(4), including encrypted authentication, strict access controls so that each account can only reach its own data, protection against common attacks, and limits to prevent abuse. No system is perfectly secure, but we treat your data with the care our product is built to demand.
For any question or complaint about your personal data, contact:
• Name: Suryansh Sagar
• Email: grievance@gevox.in
• Acknowledgement: within 48 hours
• Resolution: within 30 days
If we make material changes, we will update the effective date above and, where appropriate, notify you. Please check this page from time to time.
Suryansh Sagar, trading as Gevox · gevox.in · Compliant with the Digital Personal Data Protection Act, 2023