Privacy Policy
AIQ One helps Indian businesses run with confidence, and that confidence begins with how we treat your data. This policy explains what personal data we collect, why we collect it, how we protect it, and the choices and rights you have. It is written to comply with the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the rules made under it, and other applicable Indian law.
1. Scope of this policy
This policy applies to the AIQ One mobile and web applications, the website aiqtechlabs.com, and the related services we provide (together, the "Services"). It does not apply to third-party apps or websites that you reach through the Services; they have their own policies.
2. Who we are
The Services are provided by AIQ Research Labs Private Limited ("AIQ Research Labs", "we", "us" or "our"), a company incorporated in India (CIN U62013UW2026PTC258184), with its registered office at D-69, 1st Floor, Paramount Tulip, Delhi Road, Saharanpur, Uttar Pradesh 247001, India.
3. Our role and your business's role
- Your account. For the personal data needed to create and run your own AIQ One account, such as your name and mobile number, AIQ Research Labs is the Data Fiduciary.
- Business Data. When a business uses AIQ One to record the personal data of its own customers, staff, suppliers or partners, that business decides why and how the data is used, and is the Data Fiduciary for it. We process that data only on the business's behalf and in line with its instructions, as its Data Processor. If you are a customer or employee of a business that uses AIQ One, please contact that business first about its records; we will support it in responding to you.
4. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, mobile number, email address (optional), profile photo | You |
| Business profile | Business name and type, address, branches, GST and other registration numbers, licences | You |
| Business Data | Records of customers, staff, suppliers, sales, purchases, payments due and received, and accounts | The business and its authorised users |
| Documents and files | Bills, invoices, certificates, agreements, photos and PDFs you upload | You |
| Communications | Messages and chats sent through the Services, call notes, and your requests to our support team | You |
| Device and security | Device model, operating system and app version, a security key created on your device, sign-in history, IP address | Collected automatically |
| Service records | Access logs of who viewed or changed a shared record and when, and technical logs of errors | Collected automatically |
We collect only what is needed to provide the Services. You choose which records and documents to add.
5. Device permissions
AIQ One asks for a device permission only when you use a feature that needs it. You can refuse or withdraw a permission at any time in your device settings; only the related feature will stop working.
| Permission | Why it is used |
|---|---|
| Contacts | To pick or import a contact when you choose to add a customer, staff member or family member. |
| Location | To fill an address from your current location when you tap to do so. |
| Camera, photos and files | To scan or attach documents and photos. |
| Notifications | To deliver your reminders, due dates and updates. |
| Phone and call log | Only for businesses that use call tracking in our calling module: to log business calls with customers, and, where the business turns it on, to attach the recordings saved by the phone's own call recorder to the right customer. |
We do not read your SMS messages.
6. How we use personal data
- To create your account, verify your mobile number and keep your sign-in secure.
- To provide the Services: saving and syncing your records, sharing them with the people you choose, and generating documents and reports.
- To send service messages, such as one-time codes, reminders, due-date alerts and important notices.
- To respond to your questions and support requests.
- To keep the Services reliable and secure, and to detect and prevent fraud and misuse.
- To improve the Services, using information that does not identify you wherever possible.
- To meet our legal and regulatory obligations.
We do not sell personal data, and we do not use it for third-party advertising.
7. Our grounds for processing
We process personal data on the basis of your consent, which we request in clear terms, or for the legitimate uses permitted by the DPDP Act, such as providing a service you have asked for or complying with the law. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing that took place before it.
8. How personal data is shared
- Within your business. A business owner decides who in their team can see what. Each user sees only what their role and rights allow.
- Between connected users. When you connect with a business on AIQ One, that business sees only the records of its own dealings with you and, where you have linked your family, basic details such as family members' names, relationships and ages. It never sees your other records.
- Our staff. Our team accesses a business's data only with the owner's permission, for example to resolve a support request, and every such access is logged.
- Service providers. We use carefully selected providers who process data on our behalf under contract, only for the purposes set out in this policy:
Provider Purpose Amazon Web Services Hosting of our servers and databases in Mumbai, India Meta Platforms (WhatsApp Business Platform) Delivery of one-time codes and messages you ask us to send Google (Firebase Cloud Messaging) Delivery of app notifications Cloudflare Delivery and security of our website and email - Legal requirements. Where required by law, or by a lawful order of a court, regulator or government authority in India.
- Business transfers. If our business is reorganised, merged or sold, personal data may transfer to the successor, which will remain bound by this policy.
9. Where data is stored
Your data is stored on servers located in India. A working copy is kept on your device so that AIQ One works offline. Some service providers, such as those that deliver messages and notifications, may process limited data (for example, a mobile number or the text of a notification) outside India, as permitted under Indian law.
10. How we protect data
- All data in transit is encrypted using industry-standard TLS (HTTPS).
- Sign-in is bound to your own device, and access is controlled by role.
- Access to shared records is logged, and our staff access Business Data only with the owner's permission.
- Our servers are protected by firewalls and backed up daily.
No system can be guaranteed to be completely secure. If a personal data breach occurs, we will inform the affected users and the Data Protection Board of India as required by law.
11. How long we keep data
| Data | Retention |
|---|---|
| Account and Business Data | For as long as the account is active, or as the business decides |
| Call recordings in the calling module | 180 days by default, unless the business sets a shorter period |
| After an account is deleted | Deleted within 30 days, except where the law requires us to keep it longer; backup copies are overwritten within a further 14 days |
12. Your rights
Under the DPDP Act, you have the right to:
- obtain a summary of your personal data that we process, and of the parties it has been shared with;
- have your personal data corrected, completed or updated;
- have your personal data erased, where it is no longer needed or you withdraw consent, unless the law requires us to keep it;
- withdraw your consent at any time;
- have your grievances redressed; and
- nominate another person to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, write to us at [email protected]. We will verify your request with a one-time code sent to your registered mobile number and respond within the time allowed by law. A business owner can also export their business's data at any time.
13. Deleting your account
You may ask us to delete your AIQ One account at any time. Email [email protected] with the subject "Delete my account" and your registered mobile number. After verifying the request, we will delete your account and personal data as described in section 11. If you are a business owner, please export any data you wish to keep before deletion.
14. Children
The Services are intended for adults. Where a parent or lawful guardian keeps records about a child, or where the law otherwise requires it, we process a child's personal data only with the verifiable consent of the parent or guardian. We do not track or monitor the behaviour of children, and we do not direct advertising at them.
15. Cookies and this website
This website does not use advertising or tracking cookies. Our website host, Cloudflare, may use essential cookies and record basic technical information, such as IP addresses, to keep the website secure and available.
16. Changes to this policy
We may update this policy from time to time. We will change the date at the top of this page and, where the changes are significant, notify you in the app before they take effect.
17. Grievance Officer and contact
If you have any question, request or complaint about this policy or your personal data, please contact our Grievance Officer:
Grievance Officer
AIQ Research Labs Private Limited
D-69, 1st Floor, Paramount Tulip, Delhi Road, Saharanpur, Uttar Pradesh 247001, India
Email: [email protected] · Phone: +91 9012 6068 35
We will acknowledge your complaint promptly and resolve it within the time prescribed by law. If you are not satisfied with our response, you may approach the Data Protection Board of India.