法律

Privacy Policy

最近更新:August 2026

This policy explains how Dewiride AI handles your information: what we collect, how we use it, who we share it with, and the choices you have. It is issued by Dewiride Technologies Private Limited, the data controller for Dewiride AI.

1. Information We Collect

We collect information you provide directly to us, such as when you create an account, make a purchase, subscribe to our newsletter, or contact us for support. This may include your name, email address, phone number, company information, and payment details.

We also automatically collect certain information about your device and usage of our services, including your IP address, browser type, operating system, and pages visited.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process transactions and send related information
  • Send technical notices, updates, and support messages
  • Respond to your comments and questions
  • Communicate with you about products, services, and events
  • Analyze usage patterns and trends

3. Parties We Share Your Information With

We do not sell, trade, or rent your personal information. We share it only with the following categories of recipient, only to the extent each one needs it, and only under a written contract that requires them to protect it and to use it solely on our instructions:

Payments are processed by Stripe, who act as an independent controller of the payment data you submit. Your full card number, expiry and security code are entered directly into the processor's secure fields and are never received or stored on our servers. We retain only the transaction reference, the amount, the currency, the payment status and the last four digits and brand of the card, so that we can issue receipts, provide support and handle refunds and disputes.

  • Payment processors (Stripe) — to take payment, issue receipts and handle refunds and disputes.
  • Cloud hosting and infrastructure providers (Microsoft Azure and our website hosting provider) — to run our websites, databases and backups.
  • AI and model providers (such as Azure OpenAI and OpenAI) — to process the prompts you send to Dewiride AI and return a response.
  • Speech providers (Microsoft Azure AI Speech) — to turn what you say into text when you speak to the assistant, and to turn its reply into a voice.
  • Push notification delivery (Google Firebase Cloud Messaging) — to deliver notifications to the Dewiride AI mobile app on your device.
  • Email, forms and communication providers (Microsoft 365) — to send transactional email and receive enquiries.
  • Analytics providers (Google Analytics) — to understand aggregate website usage, and only where you have consented to analytics cookies.
  • Professional advisers (accountants, auditors and lawyers) — where needed for tax, audit or legal purposes.
  • Government authorities, regulators, courts and law enforcement — where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims or to protect the rights, safety or property of any person.
  • An acquirer or successor entity — if we are ever involved in a merger, acquisition or sale of assets. We would notify you before your information became subject to a different privacy policy.

4. How and When We Disclose Information

Disclosure to the parties listed above happens in these ways only:

Every processor is bound by a written data processing agreement, is prohibited from using your data for its own purposes, and must delete or return it when our contract ends. We do not disclose your personal information for advertising or for sale to data brokers under any circumstances.

  • Automated, encrypted transmission — data passes to service providers over authenticated API calls encrypted in transit with TLS 1.2 or higher. This is the method used for payments, hosting, AI processing, transactional email and analytics.
  • Access by authorised personnel — a small number of our staff and contractors can access your data through access-controlled administrative tools, only where needed to deliver or support the service.
  • On your instruction — for example when you connect a third-party account to Dewiride AI or ask us to share information with someone.
  • Formal written disclosure — to advisers, authorities or courts, in response to a valid legal request. We review every request, limit what we disclose to what is legally required, and tell you unless we are prohibited from doing so.

5. Security Practices

We maintain technical and organisational measures designed to protect your personal information against unauthorised access, alteration, disclosure or destruction. These include:

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe your account has been compromised, contact us at support@dewiride.com immediately.

  • Encryption in transit — every page and API call is served over HTTPS using TLS 1.2 or higher.
  • Encryption at rest — databases, file storage and backups are encrypted on disk, and Dewiride AI conversations are encrypted in storage.
  • Card data isolation — full card details are captured by our PCI-DSS compliant payment processor and never traverse or rest on our systems.
  • Access control — role-based, least-privilege access, multi-factor authentication on all administrative and cloud accounts, and secrets held in a managed key vault rather than in code.
  • Network and platform hardening — managed cloud infrastructure with vendor security patching, firewalling and activity logging.
  • Monitoring, logging and backups — access and system logs are retained for review, and backups are taken regularly and tested.
  • People and process — confidentiality obligations for staff and contractors, periodic access reviews, and vendor due diligence before we share data with a new processor.
  • Incident response — we investigate suspected breaches immediately and, where a breach is likely to affect you, notify you and the relevant authority without undue delay and in line with applicable law.

6. Support Conversations

When you ask us for help — from the Help Center inside Dewiride AI, or from the contact form on this website — we open a support conversation and keep it until it is deleted under section 14. It is read and answered by people. Nothing you write to support is answered automatically.

  • What we hold: your name and email address, the subject you gave, every message on the conversation, any files you attach, and the rating and comment you leave afterwards.
  • What the app tells us about your session: the build you were running, the language and time zone you were using, your window size, the page you were on, and your browser's user-agent string. The Help Center shows you exactly what is attached before you send it. The contact form collects none of this beyond your browser's user-agent string.
  • How it is protected: message bodies, our internal notes, attached file names and the session details above are encrypted in our database. The subject line and your email address are not, so that the support queue can be searched and sorted.
  • Who can read it: our support team, while they are handling your conversation. It is not shown to other customers and it is not shared outside the recipients listed in section 3.
  • Where AI is involved: our support team can ask an AI assistant to summarise a conversation or draft a reply, which sends the messages on that conversation to the model provider named in section 3. A draft is only ever a suggestion — a person edits it and sends it. Our internal notes are never sent, and nothing reaches you without a person choosing to send it.

If you start a conversation without an account, we email you a private link to it. That link expires, is reissued each time we reply, and stops working once the conversation is closed. Treat it like a password: anyone holding it can read and reply to that conversation.

7. Speaking to the Assistant

You can talk to Dewiride AI instead of typing, in the browser or in the mobile app. Your microphone is only ever opened when you start a spoken conversation, and it is released the moment you end one.

  • What leaves your device: while a spoken conversation is open, the audio from your microphone is streamed to us over an encrypted connection and passed to the speech provider named in section 3, which turns it into text. The assistant's reply is turned back into a voice the same way.
  • What we keep: the text. The words you spoke and the assistant's answer are saved as an ordinary conversation, encrypted in our database and deleted with it on the timetable in section 14. We do not record, store or replay the audio itself, and neither the recording nor a voiceprint is retained by us once the text exists.
  • Silence is not sent as speech: your side of the conversation is only transcribed while you are speaking. The rest of the time the stream carries nothing that could be turned into words.
  • You are in control of when: nothing is captured unless you have granted the microphone permission and opened a spoken conversation, and both the browser and the phone show that the microphone is open the whole time it is.

8. The Dewiride AI Mobile App

The mobile app signs into the same account and shows the same conversations as the website. Two things are true of it that are not true of a browser, and this section covers both.

  • Notifications: to send one, we hold an identifier your device's copy of the app is issued by Google Firebase Cloud Messaging, together with the word "android". We store that identifier encrypted, use it for nothing but delivering your own notifications, and delete it when you sign out, when you turn notifications off, when your device stops accepting them, or with your account.
  • What a notification contains: we send the kind of event and the names involved — an agent's name, a reminder's title — never the text of a message and never a link that would let the holder approve anything. Your phone writes the sentence itself, in your language, and shows it under your lock screen's rules. Approving something always happens inside the app, behind your sign-in.
  • Your fingerprint or face: if you lock the app to biometrics, the check is performed by Android and the result is all the app ever sees. Your fingerprint and face never leave your device and are never sent to us.
  • What the app does not do: it carries no advertising identifier, no advertising or analytics SDK, and no third-party tracker. It does not ask for your location, your contacts, your photos or your files. It reads nothing on your device that you have not handed to it.

9. Connected Accounts

Dewiride AI can connect to accounts you already hold elsewhere — Google, Microsoft 365, GitHub, Azure and others — so that the assistant can look things up and act for you in those services. A connection is made only when you start one, and only with the permissions you tick on the connect screen before you are sent to the provider to sign in.

We hold an access token and a refresh token for each connected account, encrypted in our database, and we use them for nothing except carrying out the requests you make in Dewiride AI. Disconnecting an account in Integrations deletes those tokens immediately, and you can also withdraw the app's access from the provider's own account settings.

10. Google User Data and Limited Use

When you connect a Google account, Dewiride AI receives data from Google APIs. This section sets out exactly what we access, why, and what happens to it.

  • Gmail (gmail.modify, gmail.send) — we list your inbox, sent items or drafts with each message's sender, subject, date, read state and short preview; and, when you point us at one, we open a message or a whole conversation and read its recipients, its body as plain text, and the names and sizes of anything attached to it — never the contents of an attachment. That is what lets the assistant tell you what has arrived, find a message you describe, and summarise or answer questions about it.
  • Gmail, continued — when you ask, and only after you approve the action, we also mark messages read or unread, apply or remove your own labels, archive a message or put it back in your inbox, move one to the bin or restore it from it, and save a draft reply on the original conversation for you to read before you send it. We send a message only when you ask for one, and only after you approve the message we have drafted. We never delete mail permanently and we never change your Gmail settings: the permission we hold does not allow either, so neither is possible even by mistake.
  • Google Calendar (calendar.events) — we read the events on your calendars, including who was invited, how each person replied and any meeting link, to answer questions about your day. When you ask and approve it, we create an event, change or reschedule one, cancel one, or reply to an invitation on your behalf.
  • Google Tasks (tasks) — we read your task lists and what is on them to tell you what is outstanding. When you ask and approve it, we add a task, rename it, change its notes or its due date, tick it off or put it back, or delete it.
  • Google Analytics (analytics.readonly) — we list your GA4 properties, look up which metrics and dimensions each property supports so a report is built from fields that exist, and run the reports you ask for on traffic, engagement and conversions.
  • Google Search Console (webmasters.readonly) — we read your verified sites, search performance, sitemaps and URL index status.
  • Google Business Profile (business.manage) — we read your business accounts, locations, daily performance metrics, and the reviews customers have left you along with their star ratings, so the assistant can tell you how each location is doing and what people are saying. Google publishes no read-only Business Profile permission, so this is the only one that returns that data, and we use it to read and nothing else. We do not edit a listing, publish a post, reply to a review, or change your opening hours.

How it is used: only to produce the answer or carry out the action you asked for, in the conversation where you asked for it. To do that, the relevant content is sent to the AI model provider named in section 3, which processes it under a written contract, solely on our instructions, and not for its own purposes.

How it is stored: your request, the result, and the conversation they belong to are encrypted in our database, as are the tokens for the connection. They are kept while the conversation exists and are deleted with it, with your account, or when you disconnect the Google account, on the timetable in section 14.

What we never do: we do not sell Google user data, we do not use it for advertising or to build advertising profiles, and we do not use it to create, train or improve any general-purpose artificial intelligence or machine-learning model. No member of our staff reads it — except with your explicit permission, where it is necessary to investigate a security incident or abuse, or where the law requires it.

Dewiride AI's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can review and remove Dewiride AI's access to your Google Account at any time at myaccount.google.com/permissions, and you can disconnect it from Integrations inside Dewiride AI.

11. Your Rights

You have the right to:

  • Access and update your personal information
  • Request deletion of your personal information
  • Object to or restrict certain processing of your information
  • Withdraw consent where processing is based on consent
  • Data portability

12. Cookies and Tracking

We use cookies and similar tracking technologies to collect information about your browsing activities. You can control cookies through your browser settings, but disabling them may affect your experience on our website.

13. International Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your personal information in accordance with applicable data protection laws.

14. Data Retention

We keep personal information only for as long as we need it. Account and Dewiride AI conversation data is kept while your account is open and deleted within 90 days of closure, unless you ask us to delete it sooner. Order, invoice and payment records are kept for 8 years, as required by Indian tax and company law. Analytics data is retained in aggregated form only.

Support conversations follow whoever opened them. One opened from your account — with its messages, files and session details — is deleted with your account, on the same timetable. One opened without an account, from the contact form, is deleted 180 days after it is closed. Ratings and product feedback you leave are kept after your account goes, with you no longer attached to them, so that the aggregate scores they feed stay correct.

A mobile device's notification registration is shorter-lived than any of that. It is deleted the moment you sign out on that device, as soon as Google tells us the device has stopped accepting notifications, after nine months without one being delivered, and with your account.

15. Children's Privacy

Our products are not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy on our website and updating the "Last updated" date.

17. Contact Us

If you have any questions about this Privacy Policy, or wish to exercise any of your rights, please contact us — by email, or from the contact form on this website, which opens a conversation with the same team. We respond within 1 business day. If you are not satisfied with our response, you may escalate to our grievance officer, who will acknowledge within 48 hours and resolve within 15 days.

Dewiride Technologies Private Limited

Privacy & data requests: support@dewiride.com

Grievance officer: grievance@dewiride.com

Phone: +91 8955643412 (Monday to Friday, 9:00 AM – 6:00 PM IST)

Address: C/o Jagdish Kumawat, Village Tena, Tehsil Shergarh, Jodhpur – 342028, Rajasthan, India