Who we are and what this covers
Reposha is offered by Rhizomatic Artificial Intelligence Private Limited (CIN U26209PN2026PTC254954), Warje, Pune, Maharashtra 411058, India, under the brand PreceptsAI (“we”, “us”). This policy covers reposha.com, app.reposha.com, upload.reposha.com and any custom upload domain a User connects.
It is written under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, “DPDP law”), and the Information Technology Act, 2000 and its rules.
Our two roles
- We are the Data Fiduciary for data about Users, Team members and website visitors. We decide why and how it is used. This policy explains that use.
- We are a Data Processor for documents and details that Clients upload to a User. The User, such as your CA or consultant, is the Data Fiduciary and decides why it is collected and how long it is kept. We process it only on the User’s instructions, under the data processing terms in our Terms of Use.
If you are a Client: please contact the business that sent you the upload link about your documents. You can also ask for deletion from your upload link, or through our privacy request page. We will pass your request to that business.
What we collect
Users and Team members
- Name, work email, role, firm name, practice type and city.
- Password (stored only as a one-way hash), login codes, trusted-browser and session records.
- Billing name, billing address and GSTIN, if you provide them for invoices.
- Logo and brand colour, if you add them.
- Activity in the app, including the access record of what each Team member viewed or did.
- Technical data: IP address, browser and device type, and time of access.
Payments
Our payment partner collects your card, UPI or bank details. We receive only the payment status, the amount, a reference number and the last four digits or the UPI handle where provided. We never see or store full card numbers.
Clients (on behalf of Users)
- Details the User enters: name, mobile number, email, and optionally PAN and tags.
- Documents the Client uploads, with file name, size, type, fingerprint and upload time.
- Access-code entries, with time, IP address and device, so each upload is tied to a request.
- Deletion requests and the User’s responses.
Website visitors
- What you type into contact, demo, privacy-request or notify-me forms.
- Basic technical and usage data, and cookies as explained in section 5.
Why we use it
| Purpose | Basis under DPDP law |
|---|---|
| Create and secure accounts, run the Service, give support | Consent you give when you sign up, and use for the purpose you provided the data |
| Billing, invoices, tax and company records | Legal obligations, and the purpose you provided the data |
| Security, fraud and abuse prevention, the access record | Legitimate uses, and protecting Users and Clients |
| Service emails: login codes, upload alerts, Monthly Security Report, billing notices | Needed to provide the Service you asked for |
| Product news and offers | Consent, which you can withdraw at any time |
| Processing Client documents | On the User’s instructions, as their Data Processor |
We do not sell personal data. We do not use Client documents for advertising, analytics or to train any artificial intelligence model, and we never send them to outside AI services.
Where your data is stored
Client documents, the database and backups are stored in secure data centres in India, with verified and trusted service providers. Emails to Team members may be delivered through a provider outside India; they carry no Client documents or Client names. If you choose Google sign-in, Google processes that login under its own policy. We do not transfer Client documents outside India, except when you or your Team members open them from abroad.
How long we keep it
| Data | How long |
|---|---|
| Client documents and Client details | For the retention period you choose: 6 months, 1 year or 3 years after a Client’s last request closes, and never more than 3 years. Also erased when you delete them or close your account (Terms section 9). Backups clear within 35 days. |
| Access record (activity log) | 12 months in the app, older months archived per User. Erased with the account. |
| Team member accounts | While the User account is active, plus the closure windows. |
| Invoices and payment records | As tax and company law require, generally 8 years. |
| Upload records (code entry, IP, device) | With the related request, as part of the access record. |
| Support emails | Up to 3 years after the conversation ends. |
| Website contact and notify-me forms | Up to 2 years, or until you ask us to delete them. |
| Security logs (server and login attempts) | Up to 12 months. |
How we protect it
We use reasonable security safeguards, including encryption in transit and at rest, storage in India, private storage with no public file links, role-based access, two-step verification for Owners, a record of every access, and encrypted backups. See our Security page. No system is perfectly secure, and we will tell you if something goes wrong, as described in section 12.
Your rights
Where we are the Data Fiduciary, you can ask us to:
- give you a summary of your personal data we hold and how we use it, and who we have shared it with;
- correct, complete or update it;
- erase it, unless we must keep it by law or for a legitimate use;
- withdraw consent you gave, with effect for the future;
- nominate another person to exercise your rights if you die or become unable to;
- hear and resolve a grievance.
Email support@reposha.com with “Privacy request” in the subject. We may ask you to confirm your identity. We respond within 30 days, and sooner where we can.
Clients should send requests about their documents to the business that collected them. Reposha passes on any request we receive.
Children
The Service is for businesses and is not meant for children. Users who collect documents about a child are responsible for obtaining verifiable consent from the parent or lawful guardian, as DPDP law requires. We do not knowingly track children or target advertising at them.
If there is a breach
If a personal data breach affects data for which we are the Data Fiduciary, we will inform the Data Protection Board of India and affected people as DPDP law requires. If it affects Client documents, we will tell the User without undue delay, aiming for 24 hours, so they can meet their own duties.
Emails from us
Service emails, such as login codes, upload alerts and billing notices, are part of the Service. Product news and offers are sent only with your consent, and every such email has an unsubscribe link. We never email or message your Clients for marketing.
Changes to this policy
We may update this policy. For material changes, we will email Owners at least 30 days before they apply and update the date at the top of this page.
Grievance Officer and contact
- Grievance Officer: Premanshu
- Email: support@reposha.com (subject: Grievance)
- Escalation: founder@precepts.ai
- Postal address: Rhizomatic Artificial Intelligence Private Limited, Warje, Pune, Maharashtra 411058, India
We acknowledge grievances within 48 hours and aim to resolve them within 15 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India once it accepts complaints under DPDP law.
