🔒Legal & Security

Global Privacy Policy

How we collect, use, store, and protect your personal and organizational data.

Version 1 · Effective 28 July 2026

🔒Global Privacy Policy
Published v1

Global Privacy Policy

Effective Date: 2026-07-28
Platform: SAVHN AgencyOS · https://agencyos.savhn.in
Data Controller Contact: legal@savhn.in


Legal Notice: This document is a comprehensive boilerplate reflecting the actual data practices of SAVHN AgencyOS. It must be reviewed and approved by qualified legal counsel before publication.


1. Scope & Our Commitment

This Global Privacy Policy ("Policy") describes how SAVHN AgencyOS ("we", "us", "our") collects, processes, stores, shares, and protects personal data submitted by enterprise Customer organizations ("Customers") and individual users ("Users") of our Platform at https://agencyos.savhn.in.

We are committed to transparent, lawful data processing. We operate as a Data Processor for Customer-submitted business data and as a Data Controller for account registration and platform telemetry data.


2. What Data We Collect

2.1 Account & Identity Data (Data Controller)

When a Customer organization registers or a user is invited:

  • Full name (first name, last name)
  • Work email address
  • Job title and designation
  • Organization name and billing address
  • User role assignment (Super Admin, Admin, HR, Employee, etc.)
  • Profile avatar (if uploaded)
  • Hashed password (bcrypt, never stored in plaintext)

2.2 Employee & HR Data (Data Processor — Customer controls)

Within Customer organizations, the following HR-related data may be processed:

  • Employee identification numbers, national IDs (Customer's responsibility to minimize)
  • Salary and payroll information (only for organizations with payroll enabled and employee opt-in)
  • Attendance timestamps, GPS coordinates (only when GPS check-in is enabled by Customer)
  • Leave requests, approval history, and balance summaries
  • Performance appraisal notes and review cycles
  • Emergency contact information (if provided by Customer)

2.3 Work & Project Data (Data Processor — Customer controls)

  • Client names, emails, phone numbers, company details (CRM data)
  • Lead pipeline stages, deal values, and follow-up notes
  • Project names, task descriptions, subtasks, time logs, and Kanban board data
  • Invoice details, line items, payment records, and financial summaries
  • Support ticket descriptions and resolution notes
  • Team chat messages (channels, DMs, and project channels)
  • Notice board announcements

2.4 Focus Session Data (Opt-In — Employee-initiated only)

  • Screen capture screenshots (taken at employee-selected fixed intervals: 5, 10, 15, or 30 minutes)
  • Session start/end timestamps
  • Employee-verified consent record (browser Screen Capture API permission prompt)
  • Screenshot data is accessible to both the employee and authorized administrators equally

2.5 Telemetry & Platform Data (Data Controller)

  • IP addresses (anonymized after 30 days for analytics)
  • Browser type, operating system, device screen resolution
  • Session duration, feature usage frequency, error logs
  • JWT token metadata (expiry, role at issuance — not payload content)
  • API request/response latency metrics (no request body content is logged)

2.6 Communication Data

  • In-app notification read/unread status
  • Weekly automated report content (system-generated, not human-authored)
  • Daily EOD report content (system-generated task completion summaries)
  • AI recommendation interaction (accepted/dismissed — not the underlying business data)

3. Lawful Basis for Processing

We process personal data under the following legal bases:

Data Category Legal Basis
Account registration data Contractual necessity — required to provide the Service
Employee HR & payroll data Contractual necessity + Employee explicit consent (double opt-in payroll)
CRM & project data Contractual necessity — Customer's legitimate business operations
Attendance & GPS check-in Explicit consent — employee-disclosed, always visible to the employee
Focus session screenshots Explicit consent — employee-initiated via browser permission prompt
Platform telemetry & logs Legitimate interests — platform security, fraud prevention, performance
Marketing emails (if any) Explicit consent — with unsubscribe on every communication

4. How We Use Your Data

4.1 Providing & Operating the Platform

  • Authenticating users and enforcing role-based access control
  • Rendering role-appropriate dashboards, reports, and module views
  • Processing payroll runs for opted-in employees
  • Generating automated weekly (Monday 8am) and daily EOD (weekdays 6:30pm) reports

4.2 AI & Intelligence Features

Customer data is processed by AI providers solely for inference tasks (generating report narratives, lead scoring hints, smart calendar suggestions, cash flow projections). We use:

  • OpenAI (GPT models) — under zero-data-retention API agreements
  • Anthropic (Claude models) — under zero-data-retention API agreements
  • Google Gemini — under enterprise privacy agreements

Customer data is never used to train third-party AI models.

4.3 Security & Fraud Prevention

  • Detecting unauthorized cross-tenant access attempts
  • Monitoring for anomalous API request patterns
  • Verifying device trust for Admin and Super Admin sessions

4.4 Platform Improvement (Anonymized Only)

  • Aggregate, anonymized feature usage statistics
  • Error frequency and performance bottleneck analysis
  • No individual user behavior profiling for platform improvement

5. Data Sharing & Sub-Processors

We do not sell, rent, or trade personal data to advertisers or data brokers under any circumstances. Data is shared only with bound sub-processors necessary to deliver the Service:

Sub-Processor Purpose Data Transferred
Cloud / Database Hosting (AWS, Neon, Cloudflare) Platform infrastructure All Customer data at rest
Stripe / Razorpay Payment processing Billing contact, plan, and amount
OpenAI / Anthropic / Google AI inference Anonymized content snippets for AI features
Mailgun / SendGrid Transactional email Email address, notification content
Prisma Data Proxy Database query optimization Encrypted database credentials

All sub-processors are contractually bound to appropriate data protection agreements.


6. Multi-Tenant Data Isolation

Every Customer organization is assigned a unique organizationId at onboarding. All database queries, API endpoints, and dashboard views are enforced to scope data by this identifier. Technical controls prevent any user (including Super Admin users of other tenants) from accessing another organization's data. The Developer-level account (platform maintainer only) has read access to system telemetry but not to Customer business data.


7. Data Retention

Data Type Retention Period
Active account data Duration of subscription + 30 days post-termination export window
Payroll records 7 years (statutory minimum in most jurisdictions)
Attendance logs 2 years or as required by local labor law
Focus session screenshots 90 days, then permanently deleted
Chat messages Duration of subscription
Invoice & financial records 7 years (statutory minimum)
Platform error logs 30 days
Anonymized telemetry Up to 24 months

Customers may request early deletion of non-statutory data through the Super Admin → Settings panel or by emailing legal@savhn.in.


8. Data Subject Rights

Users within Customer organizations have the following rights, exercisable through their Super Admin or directly at legal@savhn.in:

  • Right of Access — Request a copy of all personal data we hold about you
  • Right to Rectification — Request correction of inaccurate or incomplete data
  • Right to Erasure ("Right to be Forgotten") — Request deletion of personal data where no statutory retention obligation applies
  • Right to Portability — Export personal data in JSON or CSV format via Super Admin → Settings → Data Export
  • Right to Restriction — Request restriction of processing while a dispute is under review
  • Right to Object — Object to processing based on legitimate interests (telemetry analytics)
  • Right to Withdraw Consent — Withdraw consent for opt-in features (payroll, GPS check-in, focus sessions) at any time without penalty

We will respond to verifiable requests within 30 days.


9. International Data Transfers

SAVHN AgencyOS infrastructure may be hosted in data centers across the US, EU, and Asia-Pacific regions. Cross-border data transfers are protected by:

  • Standard Contractual Clauses (SCCs) for EU/EEA to non-EEA transfers
  • UK International Data Transfer Agreements (IDTAs) where applicable
  • Equivalent contractual safeguards for other jurisdictions

10. Children's Privacy

SAVHN AgencyOS is an enterprise B2B platform. We do not knowingly collect personal data from individuals under 16 years of age. If you believe a minor's data has been submitted, contact legal@savhn.in immediately.


11. Changes to This Policy

We will notify Customers of material changes to this Policy via email and in-platform announcement at least 30 days before the changes take effect. The "Effective Date" at the top of this document reflects the date the current version applies from.


12. Contact & DPO

For privacy inquiries, data subject requests, or to reach our Data Protection Officer:

Email: legal@savhn.in
Platform: https://agencyos.savhn.in

Last Updated: 2026-07-28
Document Version: 3.0 (Platform-Specific)

Last published: 28 July 2026

Questions? Contact legal@savhn.in →