Privacy by design Version 1.0 Updated 12 July 2026

Your data. Clear purpose. Meaningful control.

This centre explains how Aerlinked approaches digital personal data, consent, user rights, security, retention and grievance support under India’s Digital Personal Data Protection framework.

Framework: DPDP Act, 2023 DPDP Rules, 2025 Phased commencement applies
Aerlinked Privacy Centre

Simple notices. Secure systems. Actionable rights.

Purpose firstData linked to a defined use
ChoiceConsent can be managed
ProtectionTechnical and organisational safeguards
SupportClear grievance route
Hello@aerlinked.com

Questions, rights requests and grievances.

Online request centre

Access, correction, erasure and consent support.

🛡
Layered safeguards

Access controls, logging, encryption and backups.

Phased implementation

Controls are reviewed as provisions commence.

Overview Data we handle Purposes Your rights Retention Security Grievance
Our approach

Privacy information that is understandable and usable

Aerlinked aims to process digital personal data for defined business purposes, limit access, keep information accurate where it affects decisions and provide practical ways for individuals to exercise applicable rights.

Public version 1.0
Important legal status

India’s DPDP framework is subject to phased commencement. Aerlinked will review this notice and its operational controls as additional provisions become effective, official guidance develops or our processing activities change.

1

Purpose limitation

We connect data collection and use to identified platform, security, billing, support or business-service purposes.

2

Data minimisation

We seek to process information that is reasonably needed for the relevant service or lawful operational requirement.

3

Accountability

Privileged actions, important changes, consent choices and rights requests are designed to be recorded and reviewable.

Data inventory

Digital personal data Aerlinked may handle

The exact data depends on how you use Aerlinked, your organisation settings and whether you use lead search, CRM, billing, referrals or support.

Data categoryExamplesTypical use
Account and identityName, business email, mobile number, login identifiers and verification status.Registration, authentication, account administration and communication.
Organisation informationBusiness name, verified domain, role, team membership and organisation policies.Organisation grouping, shared access and duplicate-protection controls.
Lead-directory activitySearch filters, viewed records, unlock activity, credit source and organisation-sharing history.Delivering lead search, preventing repeated unlocks and maintaining an access history.
CRM contentContacts, notes, deal stages, task details, follow-up history and ownership.Providing contact, deal, task and sales-workflow features.
Billing and taxPlan, payment status, billing address, GST information, invoices and refund references.Payment processing, invoices, accounting, tax and dispute resolution.
Support and communicationTicket messages, attachments, complaints, replies and notification preferences.Support, grievance redressal, service communication and quality improvement.
Device and securityIP address, device, browser, session, timestamps, request identifiers and risk signals.Authentication, fraud prevention, audit, security monitoring and incident response.
Consent and preferencesConsent records, withdrawals, marketing choices and cookie preferences.Honouring choices and demonstrating when and how a preference changed.
Specified purposes

Why we process personal data

We process personal data where consent has been provided, where information is voluntarily provided for a specified purpose, or where another use is permitted by applicable law.

Provide the service

Create accounts, verify users, deliver lead search, unlock records, manage CRM and support collaboration.

Manage billing

Process subscriptions, allocate credits, generate GST invoices, reconcile payments and handle refunds.

🛡

Protect Aerlinked

Detect unauthorised access, investigate suspicious activity, preserve audit trails and maintain service continuity.

?

Provide support

Respond to enquiries, resolve lead-quality complaints, investigate issues and manage grievances.

Improve the platform

Understand feature use, diagnose errors and improve usability using aggregated or appropriately controlled information.

Communicate

Send service, security, billing and support messages, and marketing updates where permitted and selected.

Data sources

Where information may come from

You

Directly from you

Information entered during registration, billing, CRM use, support, consent or a privacy request.

Org

Your organisation

Team invitations, domain verification, ownership assignments and organisation-level access settings.

Web

Lawful business sources

Business information from lawful public or authorised third-party sources, subject to applicable law and source terms.

Sys

Automatically

Technical, usage, session and security data created when the service is used.

Pay

Service providers

Payment status, delivery confirmations and technical events from authorised processors or integrations.

Req

Rights and grievances

Identity verification and supporting information submitted to resolve a request or complaint.

Data Principal rights

Ways to understand and control your personal data

Available rights may depend on commencement, the processing context, identity verification and lawful retention requirements.

01

Access information

Request a summary of personal data being processed and relevant information about processing or sharing.

02

Correct or update

Ask us to correct inaccurate or misleading information and complete or update relevant records.

03

Request erasure

Request deletion where the purpose is complete and retention is not required for law or another permitted purpose.

04

Withdraw consent

Change or withdraw applicable consent choices through available account or privacy controls.

05

Raise a grievance

Tell us about a privacy concern and receive a tracked response through the grievance process.

06

Nominate an individual

Where applicable, nominate another individual to exercise rights in the event of death or incapacity.

Retention and deletion

We do not intend to keep personal data indefinitely

Retention is linked to the service purpose, account relationship, security needs, legal requirements, disputes and configured deletion processes.

InformationGeneral retention approachDeletion trigger
Account and organisationDuring the account relationship and for a limited period needed for security, recovery, disputes or legal compliance.Verified account deletion, completion of lawful retention and closure of unresolved matters.
CRM contentWhile the user or organisation maintains the CRM record, subject to account and backup controls.User or authorised organisation deletion, account closure or configured retention policy.
Billing and invoice dataFor the period needed for accounting, taxation, payment disputes and applicable legal obligations.Expiry of the applicable financial and legal retention period.
Support and grievancesUntil the issue is resolved and for a limited period needed for audit, recurrence prevention or legal defence.Closure of the matter and expiry of the relevant retention period.
Security and processing logsAt least one year where the applicable DPDP Rules require it, or longer where another law or active investigation requires.Expiry of the applicable period and absence of a security, legal or investigation hold.
Consent recordsFor as long as needed to demonstrate the consent choice, withdrawal and related processing history.When no longer needed for accountability or a legal requirement.
Backups and legal holds

Deleted data may remain temporarily in restricted backups until the backup lifecycle completes. Deletion may also be delayed where information is subject to a lawful hold, fraud review, dispute or other statutory requirement.

Processors and disclosures

Who may receive or process personal data

Cloud

Technology providers

Hosting, storage, monitoring, email delivery, support and other infrastructure providers operating under contractual controls.

Payment providers

Payment gateways, banks, tax and accounting services needed to process payments and financial records.

API

Authorised integrations

Services connected by Aerlinked or by an authorised user, based on the integration scope and configured permissions.

Law

Legal and regulatory recipients

Authorities, courts or professional advisers where disclosure is required or permitted by applicable law.

Org

Your organisation

Authorised organisation members where shared access, ownership or collaboration is enabled.

Deal

Business transition

Appropriately protected disclosures during a merger, acquisition, financing or transfer of business assets.

Security safeguards

Layered controls to protect confidentiality, integrity and availability

EEncryption and masking

Appropriate encryption, masking, obfuscation or token-based controls depending on the system and risk.

AAccess control

Authentication, role permissions, least-privilege access and privileged action controls.

LLogging and monitoring

Audit logs, security signals, review processes and investigation support for unauthorised access.

BBackup and resilience

Encrypted backups, continuity measures and controlled restore testing.

VVendor controls

Security and confidentiality requirements for processors and relevant service providers.

RIncident response

Detection, containment, investigation, remediation and communication workflows.

TTraining and review

Operational procedures, administrator accountability and periodic control reviews.

DData lifecycle

Purpose-linked collection, restricted access, retention controls and secure deletion processes.

Children’s data

Aerlinked is designed for business users

Aerlinked is not intended for individuals under 18. We do not knowingly seek to provide accounts to children or use children’s data for tracking, behavioural monitoring or targeted advertising.

Report a child-data concern

Where you believe a child has submitted personal data to Aerlinked, contact Hello@aerlinked.com. We may request appropriate verification before taking corrective action.

Personal data breach response

Contain, investigate, communicate and improve

1Detect and contain

Validate the incident, restrict exposure and preserve evidence.

2Assess impact

Identify affected data, people, systems, timing and likely consequences.

3Notify where required

Provide clear information to affected individuals and the Board in the applicable manner and timeframe.

4Remediate

Reduce risk, prevent recurrence and document corrective measures.

Breach communications

Where notification is required, Aerlinked aims to explain the nature and extent of the breach, likely consequences, mitigation measures, steps individuals can take and a business contact for questions.

International processing

Cross-border processing with appropriate controls

Aerlinked may use vetted service providers in India or other jurisdictions. Where personal data is processed outside India, we aim to apply contractual, technical and organisational safeguards and comply with restrictions notified by the Central Government or other applicable laws.

1

Provider review

Assess the service, data scope, security controls and intended processing location.

2

Contractual protection

Define confidentiality, security, sub-processing, incident and deletion obligations.

3

Government restrictions

Review applicable notifications or restrictions concerning transfers to a country or territory.

Grievance redressal

A tracked path for privacy concerns

Please contact Aerlinked first so that we can investigate and provide a response. Applicable law may require this internal grievance opportunity to be exhausted before approaching the Data Protection Board.

1Submit

Use the privacy request centre or email Hello@aerlinked.com.

2Verify

We may verify identity, authority and the request scope.

3Investigate

The Privacy & Grievance Team reviews systems, records and applicable exceptions.

4Respond

Receive a decision, action taken, limitations and available next steps.

Aerlinked Privacy & Grievance Team

For questions about this notice, processing of personal data, a rights request or a privacy grievance.

Hello@aerlinked.comSubject: DPDP Privacy RequestIndia
Legal references

Official DPDP framework documents

These government publications are provided for reference. The official text, commencement notifications and subsequent amendments prevail over this summary.

Not legal advice

This page is a public-facing explanation of Aerlinked’s intended privacy approach. It does not replace the official law or constitute legal advice. The final production notice should remain aligned with Aerlinked’s actual legal entity, systems, vendors and data flows.

Frequently asked questions

Privacy answers in plain language

Aerlinked acts as a Data Fiduciary when it determines why and how personal data is processed for its platform, security, billing and support purposes. In some user-controlled CRM situations, the user or organisation may also have independent responsibilities for the data they enter and manage.
You may submit an erasure or account-deletion request. Aerlinked will assess the request, verify identity where appropriate and explain any information that must remain for billing, security, disputes, legal compliance or another permitted purpose.
The active record may be removed or placed into a recoverable deletion workflow. Restricted backup copies may persist temporarily until the relevant backup lifecycle completes. Audit or legal records may be retained separately where required.
Yes. Marketing preferences are intended to be managed separately from essential service, billing, security and support communications.
Aerlinked’s security approach includes access controls, role-based permissions, encryption or masking where appropriate, audit logging, monitoring, backups, incident-response processes and processor controls.
Provide the email or account identifier connected to Aerlinked, the right you want to exercise, enough information to locate the relevant data and any supporting context. Do not send unnecessary identity documents unless requested through a secure channel.