Privacy Policy
How ARIA collects, uses, shares and protects personal data, and the rights you have over it under Indian law.
Draft pending legal review
This policy has been prepared for review by Indian legal counsel and is not yet final. Highlighted items in brackets are company details still to be added.
The short version
- We collect what we need to answer enquiries, run the Platform and bill for it, and nothing more.
- For the leads, applicants and staff records brokerages keep in ARIA, the brokerage decides; we process that data only on its instructions.
- We never sell personal data. This Website sets no cookies and runs no third-party trackers.
- You can access, correct and erase your data, withdraw consent, and contact our Grievance Officer at any time.
Looking for quick actions? Visit Data Privacy.
1.Who we are and what this policy covers
ARIA is a customer relationship management (CRM) and operations platform for real-estate brokerages, operated by [Registered company name] (“ARIA”, “we”, “us” or “our”), a company with its registered office at [Registered office address].
This Privacy Policy explains how we collect, use, share, store and protect personal data when you:
- visit our website, including when you book a demo or request a free trial (the “Website”);
- use the ARIA platform, its mobile and web applications, and related services (the “Platform”); or
- otherwise communicate with us, for example about sales, support or billing.
It is published in accordance with Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the “SPDI Rules”), and is intended to serve as the notice required under section 5 of the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the Digital Personal Data Protection Rules, 2025 as their provisions come into force.
By using the Website or the Platform, or by giving us your personal data, you acknowledge that you have read this policy. Where we rely on your consent, we ask for it separately and clearly, as described in section 6.
2.Key terms
- Personal data
- Any data about an individual who is identifiable by or in relation to that data.
- Sensitive personal data or information (SPDI)
- As defined in Rule 3 of the SPDI Rules: passwords; financial information such as bank account, credit card, debit card or other payment instrument details; physical, physiological and mental health condition; sexual orientation; medical records and history; and biometric information. Information that is freely available or accessible in the public domain is not SPDI.
- Data Principal
- The individual to whom personal data relates. In this policy, “you”.
- Data Fiduciary
- The person who alone or with others decides the purpose and means of processing personal data.
- Data Processor
- A person who processes personal data on behalf of a Data Fiduciary.
- Customer
- A brokerage or other business that subscribes to the Platform, including its authorised users.
- Customer Data
- Personal data that a Customer, or a service the Customer connects, puts into the Platform: for example, details of the Customer’s leads, buyers, job applicants and employees.
3.Our role: Data Fiduciary and Data Processor
We handle personal data in two different capacities, and your rights are exercised differently in each.
When we are the Data Fiduciary
We decide why and how personal data is processed for: visitors to the Website; people who book a demo or request a trial; the account, contact and billing details of Customers and their authorised users; support conversations; and the security and operation of our own services. For this data, contact us directly using the details in section 18.
When we are a Data Processor
For Customer Data, the Customer is the Data Fiduciary. We process Customer Data only on the Customer’s documented instructions, under our agreement with that Customer and its data processing terms, and for no other purpose. If you are a lead, buyer, job applicant or employee of a brokerage that uses ARIA, that brokerage decides how your data is used; please direct requests about it to the brokerage. If you contact us instead, we will pass your request to the relevant Customer and help it respond.
4.Personal data we collect
Information you give us
- Demo and trial requests: your name, work email address, phone number, brokerage name, role, sales team size, the product areas you are interested in, and any message you write.
- Account details: name, email address, phone number, role, branch and login credentials of each authorised user a Customer creates.
- Billing details: billing contact, company name and address, GSTIN and payment records. Card and bank payment details are processed by our payment service provider; we do not store full card numbers.
- Communications: the content of emails, support tickets, calls and feedback you send us.
Information collected automatically
- On the Website: when you submit a form, we record your IP address, browser user agent, the page you first arrived on, the referring website and any campaign tags (such as UTM parameters) in the link you followed, so we know which campaigns bring enquiries. See section 14 for what is stored in your browser.
- On the Platform: log-in times, IP addresses, device and browser information, and records of actions taken in the Platform (audit logs), used for security, troubleshooting and accountability.
Information from third parties
- Leads delivered to a Customer’s account by property portals, advertising platforms or website forms that the Customer has connected.
- Business contact details from publicly available sources, used for business-to-business outreach.
Customer Data we process on a Customer’s behalf
Depending on the features a Customer uses, Customer Data may include:
- contact details, property preferences, budgets, site visits and notes about the Customer’s leads and buyers;
- call recordings, call transcripts and summaries, and WhatsApp and call logs;
- resumes, application details and assessment results of job applicants;
- employee records, timesheets, attendance check-ins including the location at check-in, and commission records;
- advertising and campaign performance data linked to leads.
Sensitive personal data or information
We collect SPDI only where it is necessary for a lawful purpose connected with our services, and with consent in writing (including electronic form) as required by Rule 5(1) of the SPDI Rules. In practice this is limited to: account passwords, which are stored only in a salted, one-way hashed form and never in readable form; and financial information needed for billing, handled as described above. Customers must not upload other categories of SPDI, such as health or biometric information, into the Platform unless it is strictly necessary and they have a lawful basis for doing so.
5.How we use personal data
We use personal data only for the purposes below, and only to the extent necessary for them, in line with Rule 5(2) and 5(5) of the SPDI Rules and sections 4 to 7 of the DPDP Act.
| Purpose | Personal data used | Basis |
|---|---|---|
| Responding to demo and trial requests, and arranging demos | Demo request details, campaign tags | Your consent, given when you submit the form |
| Providing, maintaining and supporting the Platform | Account details, usage and audit logs, Customer Data (as processor) | Our contract with the Customer; the Customer’s instructions |
| Billing, invoicing, tax and accounting | Billing details and payment records | Contract; compliance with the Companies Act, 2013 and GST laws |
| Security, fraud prevention and incident response | IP addresses, device information, logs | Legitimate uses under section 7 of the DPDP Act; legal obligations, including CERT-In Directions |
| Service and product communications | Contact details | Contract; your consent for marketing, which you can withdraw at any time |
| Improving the Website and Platform | Aggregated or de-identified usage information | Consent where required; otherwise de-identified data |
| Complying with law and responding to lawful requests | Any relevant data | Legal obligations and legitimate uses under section 7 of the DPDP Act |
We do not sell personal data. We do not use Customer Data for our own marketing, and we do not use it for any purpose other than providing the Platform to that Customer.
6.Your consent
Where we rely on consent, we ask for it through a clear affirmative action, such as submitting a form after being shown what we will do with the information, and only for the specific purpose described. Consent under the DPDP Act must be free, specific, informed, unconditional and unambiguous, and limited to the data necessary for that purpose.
- Withdrawing consent. You may withdraw consent at any time, as easily as you gave it, by writing to info@airainfotech.com or using the unsubscribe link in any marketing email. Withdrawal does not affect processing already carried out. As permitted by Rule 5(7) of the SPDI Rules, if you withdraw consent needed to provide a service, we may be unable to continue providing it.
- Choosing not to provide data. You may decline to give us any personal data. If you do, we may not be able to respond to your enquiry or provide the service you asked for.
- Consent managers. Where consent is given or managed through a Consent Manager registered with the Data Protection Board of India, we will act on it as the DPDP Act requires.
- Children. The Website and Platform are intended for businesses and are not directed at anyone under 18. We do not knowingly process the personal data of children. If we learn that we have done so without verifiable parental consent as required by section 9 of the DPDP Act, we will delete it.
7.AI features and automated processing
Some Platform features use artificial intelligence to process Customer Data on the Customer’s instructions, including call transcription and summaries, drafted follow-up messages, sales pitch suggestions, landing-page generation and resume assessment.
- AI output is a draft or a suggestion for a person to review, not a final decision.
- In hiring, applications that our checks flag are always routed to a human reviewer. No applicant is rejected solely because of an automated flag.
- AI processing may be carried out by specialised service providers acting as our sub-processors, under contracts that limit them to providing the service. We do not permit these providers to use Customer Data to train their own general-purpose models.
9.Where your data is stored and transfers outside India
We primarily store personal data in [Primary data storage location]. Some service providers may process data in other countries.
Consistent with Rule 7 of the SPDI Rules, we transfer personal data (including SPDI) to another person or country only where it ensures the same level of data protection that we adhere to, and only where necessary to perform our contract with you or with your consent. Transfers outside India are also subject to section 16 of the DPDP Act, and we will not transfer personal data to any country or territory that the Central Government has restricted by notification.
10.Third-party integrations
Customers can connect the Platform to third-party services such as WhatsApp Business, telephony providers, advertising platforms (for example, Google and Meta) and property portals (for example, 99acres, MagicBricks and NoBroker). When a Customer connects an integration:
- data flows between the Platform and that service as the Customer configures it;
- the third party’s own terms and privacy policy govern its handling of the data, and we are not responsible for its practices; and
- the Customer can disconnect the integration at any time, which stops further data flowing through it.
Links on our Website to other websites are provided for convenience; their privacy practices are their own.
11.Data storage and security
We implement reasonable security practices and procedures, as required by section 43A of the Information Technology Act, 2000 and Rule 8 of the SPDI Rules, and reasonable security safeguards under section 8(5) of the DPDP Act, proportionate to the nature of the data we hold. These include a documented information security programme with managerial, technical, operational and physical controls. Our measures include:
- encryption of data in transit using TLS, and encryption of stored data;
- role-based access controls, so each user sees only what their role requires, and least-privilege access for our staff;
- hashing of passwords, and support for strong authentication;
- audit logs of significant actions in the Platform, including changes to commission records;
- regular backups, monitoring for unusual activity, and vulnerability management;
- confidentiality obligations and privacy training for employees and contractors; and
- security and confidentiality commitments from every sub-processor.
Personal data breaches
If a personal data breach occurs, we will act to contain it and, as required by section 8(6) of the DPDP Act and the Rules made under it, inform the Data Protection Board of India and each affected Data Principal in the manner and within the time prescribed. We will report cyber security incidents to CERT-In within six hours of noticing them, as required by the CERT-In Directions of 28 April 2022. Where we act as a Data Processor, we will notify the affected Customer without undue delay so that it can meet its own obligations.
No method of transmission or storage is completely secure. You are responsible for keeping your Platform credentials confidential and for telling us promptly if you suspect unauthorised access.
12.Data retention
We keep personal data only for as long as it is needed for the purpose it was collected for, or as required by law, in line with Rule 5(4) of the SPDI Rules and section 8(7) of the DPDP Act. When it is no longer needed, we delete it or irreversibly anonymise it.
| Data | How long we keep it |
|---|---|
| Demo and trial requests that do not become customers | Up to 24 months after our last contact with you, unless you ask us to delete it sooner |
| Account details of Customers and their users | For as long as the account is active, and then as described in section 13 |
| Customer Data | As instructed by the Customer. After the subscription ends, deleted from active systems within 90 days, and from backups when those backups expire |
| Backups | Up to 35 days on a rolling basis |
| Security, access and system logs | At least one year, and at least 180 days within India, as required by the DPDP Rules and the CERT-In Directions |
| Invoices, billing and accounting records | Up to 8 years, as required by the Companies Act, 2013 and GST laws |
13.Account deletion
- Customers can ask for their workspace and all Customer Data to be deleted by having an account administrator write to info@airainfotech.com from a registered address, or at the end of the subscription. Before deletion, administrators can export their data.
- Individual users are managed by their organisation. An administrator can deactivate or remove a user; to have a user’s personal data erased, the user or administrator can contact us.
- Timing. We confirm the request, verify the requester’s authority, and then delete the data from active systems within 30 days of verification, with copies in backups removed as those backups expire.
- Exceptions. We may keep limited records where the law requires it (for example, invoices and security logs, as set out in section 12) or to establish, exercise or defend legal claims. Such records are kept secure and used for no other purpose.
15.Your rights
Subject to applicable law, including sections 11 to 14 of the DPDP Act and Rules 5(6) and 5(7) of the SPDI Rules, you have the right to:
- Access a summary of the personal data we process about you, the processing activities, and the identities of other Data Fiduciaries and Data Processors we have shared it with, along with a description of the data shared;
- Correct, complete or update personal data that is inaccurate, incomplete or out of date;
- Erase personal data that is no longer necessary for the purpose it was collected for, unless we must keep it by law;
- Withdraw consent you have given, as described in section 6;
- Grievance redressal through our Grievance Officer (section 18), and, once you have used that route, to complain to the Data Protection Board of India; and
- Nominate another individual to exercise your rights if you die or become unable to do so.
How to exercise your rights
Write to info@airainfotech.com or to our Grievance Officer. We may ask you to verify your identity before acting. We aim to respond within 30 days, and in any event within the time the law allows. Exercising your rights is free.
If your data is Customer Data (for example, you are a lead or job applicant of a brokerage that uses ARIA), the brokerage is responsible for your request. We will forward requests we receive to it and help it respond.
Under section 15 of the DPDP Act, Data Principals must not register false or frivolous grievances or impersonate others when exercising these rights.
16.Using the ARIA platform: Customer responsibilities
Customers decide what Customer Data enters the Platform and how it is used. As Data Fiduciaries, Customers are responsible for their own compliance, including:
- having a lawful basis and giving any required notice before collecting and uploading the personal data of their leads, buyers, job applicants and employees;
- informing people before calls are recorded or transcribed, and obtaining their consent where required;
- complying with the Telecom Commercial Communications Customer Preference Regulations, 2018 (including Do Not Disturb preferences) when calling or messaging leads, and with WhatsApp Business policies, including obtaining opt-in before sending messages;
- informing employees about location-verified attendance and limiting its use to attendance purposes;
- complying with the terms of any property portal or advertising platform they connect;
- keeping login credentials confidential, granting access only to authorised personnel, and removing access for people who leave; and
- not uploading SPDI or other data into the Platform unless it is necessary and lawful.
The Platform is provided under our Terms of Service and each Customer’s agreement with us, including data processing terms. If those documents conflict with this policy on how we process Customer Data, the Customer agreement prevails.
17.Limitation of liability
To the fullest extent permitted by applicable law, we are not liable for any loss arising from: the acts or omissions of third-party services that a Customer or user chooses to connect; a Customer’s use of Customer Data in breach of its own legal obligations; or unauthorised access resulting from a user’s failure to keep their credentials secure.
Our total liability to Customers in connection with the Platform is set out in, and limited by, the Terms of Service and the applicable Customer agreement.
Nothing in this policy excludes or limits any liability that cannot be excluded or limited under Indian law, including our obligations under section 43A of the Information Technology Act, 2000 and the DPDP Act, or any right you have as a Data Principal.
18.Grievance Officer and contact
In accordance with Rule 5(9) of the SPDI Rules and section 8(9) of the DPDP Act, we have designated the Grievance Officer below to address grievances and answer questions about how we process personal data. We will address any grievance within one month of receiving it.
[Grievance Officer name]
[Grievance Officer designation], Grievance Officer
- info@airainfotech.com
- Phone
- [Grievance Officer phone]
- Address
- [Grievance Officer address]
- Hours
- Monday to Friday, 10:00 to 18:00 IST, excluding public holidays
For general privacy questions and requests, write to info@airainfotech.com. Our registered office is at [Registered office address].
If you are not satisfied with our response, you may complain to the Data Protection Board of India once you have used our grievance process.
19.Changes to this policy
We may update this policy to reflect changes in our services, practices or the law. The date at the top shows when it was last updated. If we make material changes, we will tell Customers by email or in the Platform before the changes take effect, and where a change requires fresh consent, we will ask for it. Previous versions are available on request.
20.Governing law and jurisdiction
This policy is governed by the laws of India. Subject to any rights you have to approach the Data Protection Board of India or another statutory authority, the courts at [City for jurisdiction] have exclusive jurisdiction over any dispute arising from it.