GDPR Compliance

AllAI is committed to protecting your data and ensuring compliance with the General Data Protection Regulation (GDPR) and other European data protection laws.

Last updated: December 20, 2024

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018, across the European Union (EU) and European Economic Area (EEA). It gives EU citizens greater control over their personal data and imposes strict obligations on organizations that collect, process, or store personal data.

Even though AllAI is based in India, we are committed to GDPR compliance because we serve users from the EU/EEA and believe in the highest standards of data protection.

Your GDPR Rights

Under GDPR, you have several important rights regarding your personal data. Here's how you can exercise them:

Right of Access

You have the right to request confirmation of whether we process your personal data and, where we do, access to the personal data.

Request a copy of your data:
privacy@allai.co.in

Right of Rectification

You have the right to have inaccurate personal data rectified and incomplete personal data completed.

Update your information:
Update through your account settings

Right to Erasure

You have the right to have your personal data erased in certain circumstances, also known as the "right to be forgotten".

Request data deletion:
privacy@allai.co.in

Right to Restrict Processing

You have the right to restrict the processing of your personal data in certain circumstances.

Request processing restriction:
privacy@allai.co.in

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format.

Request data export:
privacy@allai.co.in

Right to Object

You have the right to object to the processing of your personal data in certain circumstances.

Submit objection:
privacy@allai.co.in

Legal Basis for Data Processing

Under GDPR, we must have a legal basis for processing your personal data. Here are the bases we rely on:

Contract Performance

Processing is necessary for the performance of our contract with you (providing AI services).

Examples:

  • Account management
  • Service delivery
  • Payment processing
  • Customer support

Legitimate Interest

Processing is necessary for our legitimate interests, provided these interests do not override your fundamental rights.

Examples:

  • Service improvement
  • Security measures
  • Fraud prevention
  • Analytics

Consent

You have given clear consent for us to process your personal data for a specific purpose.

Examples:

  • Marketing communications
  • Newsletter subscriptions
  • Cookie preferences
  • Third-party integrations

Legal Obligation

Processing is necessary for compliance with a legal obligation to which we are subject.

Examples:

  • Tax compliance
  • Regulatory reporting
  • Legal proceedings
  • Data retention

International Data Transfers

Your data may be transferred to and processed in countries outside the EU/EEA. We ensure all transfers comply with GDPR requirements:

United States

Low Risk
Purpose: AI model integration (OpenAI, Anthropic, Google)
Safeguards: Standard Contractual Clauses, Privacy Shield (where applicable)

India

Low Risk
Purpose: Primary data processing and storage
Safeguards: Adequacy decision, local data protection laws

European Union

Low Risk
Purpose: Customer support and regional operations
Safeguards: GDPR compliance, local data protection authorities

Note: All international data transfers are conducted in compliance with GDPR Chapter V requirements, using appropriate safeguards such as Standard Contractual Clauses and adequacy decisions.

Data Protection Officer (DPO)

We have appointed a Data Protection Officer to ensure GDPR compliance and handle your data protection inquiries:

Email: dpo@allai.co.in
Phone: +91-80-1234-5678
Address: AllAI Technologies Pvt Ltd, Bangalore, Karnataka, India

You can contact our DPO directly for any GDPR-related questions, concerns, or to exercise your rights.

Data Breach Notification

In the unlikely event of a data breach that affects your personal data, we are committed to:

  • Detecting and investigating breaches within 72 hours
  • Notifying the relevant supervisory authority within 72 hours
  • Informing affected individuals without undue delay
  • Taking immediate steps to contain and remediate the breach
  • Documenting all breach incidents and our response

If you suspect a data breach, please contact us immediately at security@allai.co.in.

Data Retention and Deletion

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Account Data: Retained while your account is active, deleted within 30 days of account closure
  • Usage Data: Retained for 2 years for service improvement, then anonymized
  • Payment Data: Retained for 7 years for legal and tax compliance
  • Chat History: Retained for 1 year, can be deleted upon request
  • Marketing Data: Retained until consent withdrawal or account deletion

You can request deletion of your data at any time, and we will process your request within 30 days.

Supervisory Authority

If you believe we have not addressed your GDPR concerns adequately, you have the right to lodge a complaint with your local data protection supervisory authority. In the EU, you can find your authority at:

We encourage you to contact us first to resolve any issues, but you have the right to contact supervisory authorities directly.

GDPR Compliance Measures

We have implemented comprehensive measures to ensure GDPR compliance:

  • Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Privacy by Design and Default principles in our development process
  • Regular staff training on data protection and GDPR requirements
  • Comprehensive data processing agreements with all third-party processors
  • Regular audits and compliance monitoring
  • Incident response and breach notification procedures
  • Data subject rights management system
  • Secure data processing and storage practices

Our commitment to GDPR compliance is ongoing, and we regularly review and update our practices to ensure continued compliance.

Contact Information

For GDPR-related inquiries, data subject requests, or any privacy concerns, please contact us:

General Privacy: privacy@allai.co.in
Data Protection Officer: dpo@allai.co.in
Security Issues: security@allai.co.in
Phone: +91-80-1234-5678

We aim to respond to all GDPR-related inquiries within 48 hours during business days.

Our Commitment to GDPR

At AllAI, we view GDPR compliance not just as a legal requirement, but as a fundamental commitment to protecting your privacy and data rights. We are dedicated to maintaining the highest standards of data protection and will continue to evolve our practices to meet and exceed GDPR requirements.