This Privacy Notice explains how 7Analytica Information Intelligence Pvt Ltd collects, uses, shares and protects personal data. In short: we collect what we need to run your account and the Service (section 3), we do not sell personal data (section 7), you can ask us to access, correct or delete your data (section 11), and you can reach our Grievance Officer at any time (section 12).
This notice is read together with our Terms of Use.
§ 1Who we are
- 1.1
This Privacy Notice explains how 7Analytica Information Intelligence Pvt Ltd (“7Analytica”, “we”, “us” or “our”), a company incorporated under the Companies Act, 2013, collects, uses, shares and protects personal data when you use our websites, applications and services (the “Service”).
- 1.2
To the extent each applies, we are the “Data Fiduciary” under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”); the “controller” under the EU General Data Protection Regulation 2016/679 (“GDPR”) and under the UK GDPR and the Data Protection Act 2018; and a “business” under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (“CCPA”).
- 1.3
Where the law requires a representative in the European Union or the United Kingdom, we appoint one: [TODO(legal): representative names and contact details].
- 1.4
Capitalised terms not defined in this notice have the meanings given in our Terms of Use.
§ 2Scope and how to read this notice
- 2.1
This notice applies to personal data we process about visitors, account holders, users of the Service (including business users and their authorised personnel), people who contact us and, to a limited extent, people mentioned in Sources. It does not apply to third-party websites, services or Sources that we link to (see section 20).
- 2.2
Where we process personal data on behalf of a business customer under a data processing agreement, that customer is the controller and we act as its processor. This notice does not replace the customer’s own notices, and we handle that data only on its documented instructions.
- 2.3
We describe categories of personal data rather than every field. If you need more detail, contact us under section 22.
- 2.4
If you do not agree with this notice, please do not use the Service.
§ 3Personal data we collect
- 3.1
Account and identity data: your full name, your age (given as a number and used to confirm eligibility), your email address, your password (held only as a salted, one-way hash and never in readable form), account identifiers, your employer or organisation where you give it, and account preferences.
- 3.2
Single sign-on data: if you sign in with Google or Microsoft, we receive from the provider the profile details you authorise, typically your name, email address, a provider-specific identifier and, where shared, a profile picture. We do not receive your password for that provider.
- 3.3
Content you create: notes, highlights, dossiers, watchlists, alert rules, saved views, settings, prompts and messages you send to the agent, feedback, and any files or exports you create or upload.
- 3.4
Device and usage data: IP address and the approximate location derived from it, device type, browser type and version, operating system, language, time zone, referral URL, the pages and features you use, dates and times of access, interactions such as clicks, searches and scrolls, crash and performance data, and unique identifiers in cookies or similar technologies.
- 3.5
Communications: messages you send us, support requests, survey responses, our replies, and your marketing preferences.
- 3.6
Security and log data: authentication events, session records, rate-limit and abuse signals, and audit logs of actions taken in the Service.
- 3.7
Payment data, if paid plans are introduced: billing name, address, tax details and transaction records. Card details are handled by payment processors, and we receive only limited information such as the last four digits and the expiry date.
- 3.8
Business and recruitment contacts: if you apply for a role or deal with us commercially, we process the details you give us.
- 3.9
What we do not intentionally collect. We do not intentionally collect special-category or sensitive personal data (such as health, biometric, genetic, sexual-orientation, religious-belief, political-opinion, caste or tribe data), government identification numbers, financial account credentials, precise geolocation, your contacts, or microphone, camera or photo data from your device. We do not knowingly collect personal data of children under eighteen. Please do not submit any of these to the Service. If you do, we may delete them.
§ 4Where we get personal data
- 4.1
From you, when you register, use the Service or contact us.
- 4.2
From Google or Microsoft, when you choose to sign in with them.
- 4.3
Automatically from your device and browser when you use the Service.
- 4.4
From your organisation, where it adds you as an authorised user.
- 4.5
From Sources and other public material. The Service analyses news reports, articles, filings and other public material that may mention individuals, for example public officials, public figures and people quoted in reporting. We process that material to analyse how events are reported, not to profile individuals. We do not build personal profiles or make statements about named people (see section 18).
- 4.6
From service providers and partners, such as analytics and security providers, and from public registries and professional directories that we use for business contact and fraud prevention.
§ 5How we use personal data
- 5.1
We use personal data to:
- (a)create and administer your Account, authenticate you and provide the Service, including saving your notes, dossiers, alert rules and preferences;
- (b)personalise the Service, for example by remembering your settings, watchlists and display choices;
- (c)communicate with you: respond to requests, send service, security and administrative messages and, where permitted, send updates about the Service (you can opt out at any time);
- (d)operate, maintain, secure and improve the Service, including debugging, monitoring, testing, analytics, capacity planning, research and development, using aggregated or de-identified data where practicable;
- (e)detect, prevent and respond to fraud, abuse, security incidents, violations of our Terms and other harmful or illegal activity;
- (f)verify eligibility, including that you are at least eighteen, and enforce our Terms;
- (g)comply with legal obligations, respond to lawful requests from courts, regulators and law-enforcement authorities, and establish, exercise or defend legal claims;
- (h)carry out corporate transactions such as a merger, financing, acquisition or sale of assets (see section 7); and
- (i)for any other purpose for which we obtain your consent, or that is notified to you when we collect the data.
- 5.2
We will not use your personal data for a purpose that is incompatible with those above without telling you and, where required, obtaining your consent.
- 5.3
We do not sell personal data, and we do not use personal data for targeted or cross-context behavioural advertising.
§ 6Legal bases
- 6.1
India. We process personal data under the DPDP Act on the basis of your consent, which you give by ticking the consent box, by continuing to use the Service or as otherwise described when we collect the data, and which you may withdraw at any time (see section 11). We also process personal data for the “legitimate uses” that the DPDP Act permits, including where you voluntarily provide data for a specified purpose and have not indicated that you do not consent to its use, for compliance with law or with a judgment, order or direction of a court or authority, and for responding to medical emergencies or threats to life or public safety. Until the DPDP Act and its rules are fully in force we also follow the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable.
- 6.2
European Economic Area and United Kingdom. Where GDPR or UK GDPR applies, our lawful bases under Article 6(1) are: (a) consent, for example for optional cookies and marketing, which you may withdraw at any time; (b) performance of a contract with you, or steps taken at your request before entering into one, which covers providing the Service and your Account; (c) compliance with a legal obligation; and (f) our legitimate interests, which are not overridden by your interests or rights, in operating, securing, improving and promoting the Service, preventing fraud and abuse, protecting our legal rights and managing our business. You may object to processing based on legitimate interests (see section 11).
- 6.3
Where we process special categories of personal data, which we do not intend to do, we rely on your explicit consent or another condition in Article 9 of the GDPR.
- 6.4
Where we need personal data to comply with law or to perform a contract and you choose not to give it, we may be unable to provide the Service.
§ 7Sharing and processors
- 7.1
We share personal data only as described here. We do not sell it.
- 7.2
Service providers (processors). We use carefully selected providers that process personal data on our instructions under written contracts, for: cloud hosting, storage and content delivery; identity and authentication; email and notification delivery; product analytics and error monitoring; customer support and communication tools; security and fraud prevention; payment processing, if introduced; and professional services such as legal, audit, accounting and insurance. A list of the categories of provider, and on request of the sub-processors, is available from us [TODO(legal): publish the sub-processor list].
- 7.3
Identity providers. When you sign in through Google or Microsoft, that provider learns that you were authenticated for our Service, and handles that data under its own privacy policy.
- 7.4
Your organisation. If you use the Service through an organisation, it may receive information about your use.
- 7.5
Affiliates. We may share personal data with our Affiliates for the purposes in this notice, subject to this notice.
- 7.6
Legal and safety. We disclose personal data where we believe in good faith that disclosure is required by law, regulation, legal process or a governmental request; to enforce our Terms; to protect the rights, property or safety of us, our users or others; or to detect and respond to fraud, abuse or security issues. Where permitted and practical we will tell you about such requests.
- 7.7
Corporate transactions. If we are involved in a merger, acquisition, financing, reorganisation, sale of assets or insolvency, personal data may be transferred to the relevant party, who will be bound by this notice or will give you notice of any change.
- 7.8
With your consent or at your direction, for example when you share a dossier.
- 7.9
Aggregated or de-identified information that cannot reasonably identify you may be shared for research, product and business purposes.
- 7.10
We do not sell personal data or share it for cross-context behavioural advertising, and we have not done so in the preceding twelve (12) months.
§ 8International transfers
- 8.1
We are based in India, and the Service may be hosted and supported from India and from other countries in which our providers operate. Your personal data may therefore be transferred to, stored in and accessed from countries other than the one in which you live, including countries whose data-protection laws differ from yours.
- 8.2
Where the DPDP Act applies, we transfer personal data outside India except to any country or territory that the Central Government restricts by notification, and we comply with any further requirements in force.
- 8.3
Where GDPR or UK GDPR applies and we transfer personal data to a country without an adequacy decision, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum or Agreement, supplemented by transfer impact assessments and technical and organisational measures where needed. You can request a copy of the safeguards by contacting us under section 22.
- 8.4
Where appropriate, we rely on an adequacy decision, or on a recipient’s certification under a recognised framework.
§ 9Retention
- 9.1
We keep personal data only for as long as necessary for the purposes in this notice, to meet our legal, accounting, security and reporting obligations, to resolve disputes and to enforce our agreements. [TODO(legal): confirm the schedule below with engineering.] Typical periods are:
- (a)account and profile data: for as long as your Account is open, and deleted or anonymised within thirty (30) days after closure unless you ask us to delete it sooner or the law requires us to keep it;
- (b)User Content: until you delete it or close your Account, then as in (a);
- (c)security, authentication and audit logs: up to twelve (12) months, or longer where needed to investigate incidents or to comply with law, including at least one hundred and eighty (180) days where Indian directions require it;
- (d)support communications: up to three (3) years after the last interaction;
- (e)billing and tax records: for the period that Indian tax and company law requires, currently up to eight (8) years;
- (f)marketing preferences: until you withdraw consent, plus a suppression record so that we honour your choice; and
- (g)backups: overwritten on a rolling cycle of up to ninety (90) days.
- 9.2
We may keep de-identified or aggregated data for longer. When we no longer need personal data, we delete or anonymise it or, if that is not possible, securely isolate it until deletion is possible. A legal hold may extend retention.
§ 10Security
- 10.1
We implement reasonable security practices and procedures appropriate to the nature of the data, including: encryption of data in transit using TLS and encryption at rest; salted, one-way hashing of passwords; role-based access controls and least privilege; multi-factor authentication for administrative access; logging and monitoring; network segmentation and firewalls; vulnerability management and periodic security testing; secure development practices and code review; vendor due diligence and contractual security requirements; employee confidentiality obligations and training; and business-continuity and backup procedures. Our programme is designed with recognised standards such as ISO/IEC 27001 in mind [TODO(legal): confirm certification status before making any stronger statement].
- 10.2
No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for using a strong, unique password.
- 10.3
See section 19 for how we handle incidents.
§ 11Your rights
- 11.1
Depending on where you live, you may have the following rights, subject to the conditions and exceptions of Applicable Law:
- (a)access: to obtain confirmation of whether we process your personal data, a summary of it and of the processing activities, and the identities of those with whom we have shared it;
- (b)correction, completion and updating: to correct inaccurate data or complete incomplete data;
- (c)erasure: to ask us to erase your personal data where it is no longer necessary, where you withdraw consent, or as the law otherwise provides;
- (d)restriction: to ask us to restrict processing in the circumstances that the law provides (GDPR and UK GDPR);
- (e)portability: to receive personal data you provided in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible (GDPR and UK GDPR);
- (f)objection: to object to processing based on legitimate interests or for direct marketing (GDPR and UK GDPR);
- (g)withdrawal of consent: to withdraw consent at any time, which does not affect the lawfulness of processing before withdrawal and may mean that we can no longer provide some or all of the Service; withdrawing consent will be as easy as giving it;
- (h)grievance redressal: to have a grievance about our processing addressed (see section 12);
- (i)nomination: under the DPDP Act, to nominate another individual to exercise your rights if you die or become incapacitated;
- (j)automated decisions: not to be subject to a decision based solely on automated processing that has legal or similarly significant effects (see section 17);
- (k)complaint: to complain to a regulator (see section 13); and
- (l)non-discrimination: we will not discriminate against you for exercising a right, including by denying services, charging different prices or providing a different quality of service, except where the difference is reasonably related to the value of the data or is required by law.
- 11.2
How to exercise your rights. Email bhuvanchandra@7analytica.com from the address registered to your Account, or use the settings in the Service where available, telling us which right you wish to exercise. We may need to verify your identity and may ask for further information to locate your data. An authorised agent may make a request for you with written authority.
- 11.3
Timing. We will respond within one (1) month, or within the period that Applicable Law or the DPDP rules prescribe. We may extend that period by two further months for complex or numerous requests, and will tell you why.
- 11.4
Cost. We do not charge for requests, but may charge a reasonable fee for, or refuse, a request that is manifestly unfounded, excessive or repetitive, as the law allows.
- 11.5
Limits. Rights are not absolute. We may refuse or limit a request where the law allows or requires, for example where fulfilling it would reveal another person’s data, infringe privilege or trade secrets, prevent us from complying with law or prejudice legal claims. We will explain our reasons.
- 11.6
You can also change many account details and delete User Content directly in the Service.
§ 12Grievance Officer and data protection officer
- 12.1
Grievance Officer (India). In accordance with the Information Technology Act, 2000, the DPDP Act and the rules made under them: [TODO(legal): name], [TODO(legal): designation], 7Analytica Information Intelligence Pvt Ltd; email bhuvanchandra@7analytica.com.
- 12.2
Data protection officer. [TODO(legal): name and contact details of the Data Protection Officer or other person able to answer questions about processing. Appoint a Data Protection Officer if we become a Significant Data Fiduciary, and an EU or UK data protection officer if the law requires one.]
- 12.3
Timelines. We acknowledge grievances within twenty-four (24) hours and aim to resolve them within fifteen (15) days of receipt, or within such other period as the law prescribes.
§ 13Complaints to authorities
- 13.1
We encourage you to contact us first so that we can resolve your concern.
- 13.2
India. If you are not satisfied with our response, you may complain to the Data Protection Board of India in the manner provided under the DPDP Act and its rules.
- 13.3
European Economic Area. You have the right to lodge a complaint with a supervisory authority in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
- 13.4
United Kingdom. You may complain to the Information Commissioner’s Office (ico.org.uk).
- 13.5
California and other US states. You may contact the California Privacy Protection Agency or the Attorney General of your state, as applicable.
§ 14California and US state privacy disclosures
- 14.1
This section supplements the rest of this notice for California residents under the CCPA and, to the extent applicable, similar US state laws. It applies to the extent that we are a “business” under the CCPA.
- 14.2
In the preceding twelve (12) months we have collected the following categories of personal information, with the examples given in section 3: identifiers (name, email address, IP address, account identifiers); personal information described in California Civil Code section 1798.80(e) (name, email address); characteristics of protected classifications (age, given as a number and used only to confirm eligibility); internet or other electronic network activity (usage and log data); geolocation data (approximate location from IP address); professional or employment-related information (employer, if you give it); inferences (preferences drawn from your use of the Service, to personalise it); and other information you choose to give us. We do not collect sensitive personal information as the CCPA defines it, other than account log-in credentials, which we use only to provide the Service.
- 14.3
The sources and purposes are described in sections 4 and 5. We disclose the categories above to service providers and contractors for the business purposes described in section 7.
- 14.4
Sale and sharing. We do not sell personal information and do not “share” it for cross-context behavioural advertising, as those terms are defined in the CCPA. We have no actual knowledge that we sell or share the personal information of consumers under sixteen.
- 14.5
Your rights. You have the right to know and access, to delete, to correct, to opt out of sale or sharing (not applicable, because we do not sell or share), to limit the use of sensitive personal information (not applicable, because we use it only as the CCPA permits) and not to be retaliated against. To exercise them, contact us under section 11. We will verify your identity by matching information you give us to information we hold. You may use an authorised agent. We respond within forty-five (45) days, which we may extend by a further forty-five (45) days where reasonably necessary.
- 14.6
Global Privacy Control. We treat a valid opt-out preference signal, such as Global Privacy Control, as a request to opt out of sale and sharing for that browser, where applicable.
- 14.7
Shine the Light. California residents may request information about disclosures of personal information to third parties for their direct marketing. We make no such disclosures.
- 14.8
Residents of other US states, such as Colorado, Connecticut, Virginia and Texas, may have comparable rights, and may appeal a refusal by replying to our decision.
§ 15Children
- 15.1
The Service is for business users aged eighteen and over. We do not direct it to, and do not knowingly collect personal data from, anyone under eighteen. Under the DPDP Act a child is an individual under eighteen, and processing a child’s data would require verifiable parental consent, which we do not seek or provide for.
- 15.2
If we learn that we have collected personal data from someone under eighteen, we will delete it promptly and close the Account. If you believe that a child has given us personal data, contact us under section 22.
§ 16Cookies and similar technologies
- 16.1
We use cookies and similar technologies, such as local and session storage, pixels and software development kits, to make the Service work, to keep it secure and to understand how it is used.
- 16.2
The categories are: (a) strictly necessary, such as session and authentication, security, load balancing and your choices (for example theme, display density and tour progress held in session storage); (b) functionality, such as remembering preferences and settings; and (c) analytics and performance, which measure use, errors and performance in aggregate. We do not use advertising or cross-site tracking cookies.
- 16.3
Consent and control. Strictly necessary technologies do not require consent. Where consent is required for others, we ask for it, and you can change your choice at any time through [TODO(legal): cookie settings link]. You can also control cookies through your browser settings and delete stored data. Blocking some of them may affect the Service.
- 16.4
Do Not Track and Global Privacy Control. We honour Global Privacy Control signals as described in section 14. There is no industry standard for Do Not Track signals, and we do not track you across other websites.
- 16.5
Third-party analytics tools, if used, act as our processors and are restricted from using data for their own purposes [TODO(legal): list the analytics tools in use].
§ 17Automated decision-making
- 17.1
We use automated tools to analyse Sources and to generate Scores and summaries. Those outputs concern published material. They are not decisions about you.
- 17.2
We do not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects. Automated tools help us detect abuse and secure accounts, for example by rate limiting, and a person can review the outcome on request, including where it affects your access.
- 17.3
Our Terms of Use prohibit using the Service to make such decisions about individuals.
§ 18People mentioned in Sources
- 18.1
Sources may mention people. We process these mentions only to analyse how an event is reported, for example who is quoted and how statements are attributed. We do not aim to build profiles of individuals, we do not assign Scores to people, and we do not assert any fact about a named person (see the Terms of Use).
- 18.2
The legal basis for this limited processing is our legitimate interests and the public-interest nature of publicly available reporting, balanced against individual rights. Where GDPR applies we rely on Article 6(1)(f) and, where relevant, the journalism, research and freedom-of-expression provisions of Applicable Law.
- 18.3
If you are mentioned in a Source and want to ask about, correct or object to how we display it, contact us under section 22. We may refer you to the publisher, who is the controller for the original article.
§ 19Data breach handling
- 19.1
We maintain an incident response plan. If we discover a personal data breach, we will contain it, assess the risk and investigate.
- 19.2
Where the law requires it, we notify: (a) the Data Protection Board of India and affected individuals, in the form and within the time prescribed under the DPDP Act and its rules; (b) the Indian Computer Emergency Response Team (CERT-In), within six (6) hours of noticing a reportable cyber incident, as its directions require; and (c) under GDPR and UK GDPR, the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours, and affected individuals where the breach is likely to result in a high risk to them.
- 19.3
Where required, we will tell affected individuals what happened, what data was involved, the likely consequences, the measures we have taken and what they can do to protect themselves.
- 19.4
Please report a suspected breach to bhuvanchandra@7analytica.com.
§ 20Third-party links and services
- 20.1
The Service links to Sources, websites and services that we do not own or control, and integrates with Google and Microsoft sign-in. Their privacy practices are their own. We encourage you to read their notices before giving them personal data. We are not responsible for them.
§ 21Changes to this notice
- 21.1
We may update this notice to reflect changes in our practices, the Service or the law. We will publish the updated notice with a new version number and effective date and, where a change is material or requires fresh consent, tell you in the Service or by email in advance and, where required, ask for your consent again.
- 21.2
The “Effective” date at the top of this notice shows when the current version took effect. Please review it from time to time.
§ 22Contact us
- 22.1
Privacy questions, requests and complaints: bhuvanchandra@7analytica.com.
- 22.2
Grievance Officer: see section 12.
- 22.3
Security: bhuvanchandra@7analytica.com.
End of Privacy Notice · 7ANALYTICA-L-000002 · Version 1.0