01. Introduction & Scope
This Privacy Policy governs the collection, handling, storage, and transfer of information by Grency AI Systems (hereinafter referred to as "GAS", "Company", "we", "us", or "our"), operating the website https://grencyaisystems.com and its affiliated SaaS applications, cloud microservices, software tools, client management portals, and proprietary enterprise software.
By visiting our website, signing up for an account, subscribing to any GAS SaaS product, integrating our software into your workflow, or engaging our engineering consultation services, you acknowledge that you have read, understood, and consented to the practices described in this Privacy Policy, in conjunction with our Terms and Conditions and Refund Policy.
02. Information We Collect
We collect only the minimum necessary information required to deliver enterprise-grade software solutions, process software subscriptions, maintain platform security, and provide technical customer support:
A. Information You Voluntarily Provide
- Account & Registration Details: Full name, business email address, phone number, company name, department, designation, and encrypted login credentials when registering for GAS SaaS applications or portals.
- Inquiries & Consultations: Project requirements, estimated budgets, selected software services, and communication records submitted via our contact forms or customer support channels.
- Billing & Invoicing Records: Company registered address, GST identification number (GSTIN, where applicable in India), contact billing address, and transaction identifiers.
B. Automatically Collected Technical Information
- Device & Network Data: IP address, device type, operating system version, browser user agent, preferred language, and timestamped log records.
- SaaS Telemetry & Operational Metrics: API endpoint latency, error traces, software version usage, feature adoption metrics, and crash diagnostics collected solely to ensure platform reliability.
03. PhonePe Payment Gateway Security
Grency AI Systems processes all recurring software subscriptions, one-time software licenses, and consultation fees through PhonePe Payment Gateway, a certified, Reserve Bank of India (RBI) authorized, and PCI-DSS Level 1 compliant payment aggregator.
GAS NEVER collects, sees, or stores your credit card numbers, debit card details, CVV codes, bank account passwords, or UPI personal identification numbers (PINs).
All payment transactions occur within PhonePe's encrypted environment using 256-bit TLS/SSL banking standards. PhonePe transmits to GAS only a tokenized transaction reference, timestamp, order status (Success/Failure), and payment mode for billing reconciliation and account activation.
04. Enterprise AI & Client Data Confidentiality
As an artificial intelligence and software engineering company, GAS treats client intellectual property, application codebases, and training sets with strict technical isolation:
- No Public Model Training: Any proprietary data, documents, database records, or business workflows processed through GAS SaaS software or custom AI integrations are NEVER used to train, fine-tune, or reinforce public foundational AI models without explicit, written bilateral authorization.
- Tenant Isolation: Client workspaces and database stores operate within logically or physically isolated environments, secured by role-based access control (RBAC) and tenant encryption keys.
- Confidentiality Agreements: All GAS engineers, architects, and staff are legally bound by strict Non-Disclosure Agreements (NDAs).
05. How We Use Collected Data
We process the collected data strictly for legitimate operational and business purposes:
- To provision, authenticate, and maintain your access to GAS SaaS platforms and software modules.
- To generate tax-compliant invoices and confirm software subscription lifecycles.
- To send critical transactional notifications, service maintenance advisories, and security alerts.
- To diagnose bugs, optimize cloud system performance, and enforce software licensing compliance.
- To fulfill our legal obligations under Indian regulatory frameworks and prevent fraudulent abuse.
06. Cookies & Google Analytics
Our website and web applications employ first-party session cookies and modern local storage mechanisms to remember user preferences (such as your Light/Dark visual theme selection) and maintain active login sessions.
In addition, the website may utilize third-party web analytics services, including Google Analytics 4 (GA4), to gather aggregated, non-identifying telemetry (such as session duration, device viewport sizes, geographic region, and navigation patterns). This data helps us understand user behavior to refine our interface and infrastructure performance.
You can configure your browser to block or alert you about cookies; however, disabling cookies may cause certain interactive features or authenticated sessions within our SaaS platforms to function improperly.
07. Data Storage & Infrastructure Security
GAS enforces multi-layered technical, physical, and organizational security controls designed in accordance with industry best practices:
- Data Encryption: All data in transit is encrypted using Modern Transport Layer Security (TLS 1.3/HTTPS). Data at rest in databases and object storage is encrypted using industry-standard AES-256 algorithms.
- Cloud Hosting: Our cloud environments leverage world-class infrastructure providers (Microsoft Azure, AWS) with Tier-IV data center physical security and SOC 2 Type II compliance certifications.
- Vulnerability Management: Routine static code analysis, dependency vulnerability scans, and continuous access logging to detect and mitigate unauthorized access attempts.
08. Data Retention & Deletion
We retain personal and corporate information only as long as necessary to fulfill the operational purposes for which it was collected, or to comply with statutory accounting, tax, and legal requirements under Indian law (such as the retention of transaction receipts for 7 years as mandated by tax authorities).
Upon termination of an account or cancellation of a SaaS subscription, tenant application data is held in a read-only archive for a grace period of 30 days to facilitate customer export requests, after which it is securely purged from production clusters.
09. User Rights & Data Protection Controls
Under applicable Indian Information Technology laws and global privacy principles, you have the right to:
- Right to Review & Correct: Review any personal data stored in your account profile and correct inaccuracies.
- Right to Portability & Export: Request an export of your enterprise tenant data in standard machine-readable formats (JSON, CSV).
- Right to Erasure: Request the deletion of non-essential personal information, subject to ongoing legal or contractual obligations.
- Right to Withdraw Consent: Unsubscribe from non-essential communication or marketing notifications at any time.
10. Third-Party Integrations & Transfers
GAS does not sell, rent, or trade your personal or organizational data to third-party advertisers or data brokers.
We disclose necessary data only to vetted third-party service providers acting on our behalf under strict confidentiality and data protection agreements, including:
- Payment Processors: PhonePe Payment Gateway (for subscription & license billing).
- Cloud Infrastructure: Microsoft Azure and AWS cloud hosting and compute providers.
- Transactional Messaging: Enterprise email and SMS notification gateways.
- Legal & Regulatory Authorities: Only when strictly required by a court order, valid law enforcement subpoena, or applicable Indian statute.
11. Amendments & Policy Updates
As our AI technologies, SaaS product catalog, and legal requirements evolve, GAS reserves the right to amend or update this Privacy Policy at any time. Material changes will be accompanied by an updated Effective Date at the top of this document, and registered SaaS customers will be notified via email or an in-app system announcement.
Continued access to or use of our websites, SaaS products, and services following the posting of modifications signifies your agreement to the updated Privacy Policy.
12. Grievance Officer & Contact Information
In accordance with the Information Technology Act, 2000 and the rules made thereunder, any privacy-related questions, concerns, data access requests, or grievances may be addressed to our designated Data Protection and Grievance Officer:
GAS Privacy & Grievance Office
Surat, Gujarat — 394105, India