Privacy Policy
Who we are and what this covers
Data Say is a proprietary analytics platform operated by DataVader Info Private Limited.
This notice covers personal data Data Say handles for its website, platform accounts, customer administration, support, billing, security and business communications. When Data Say processes personal data contained in Customer Data solely to provide the Platform on a customer's instructions, the signed Customer Agreement and any applicable data-processing terms also apply.
Information we may collect
The information we handle depends on how a visitor, user or customer interacts with Data Say.
- Business contact and account information, including name, work e-mail, organisation, role and account-administration details.
- Customer Data made available through connected systems, files or reports, such as catalogue, SKU, order, inventory, advertising, return, payout and operational information.
- Source-connection information, including connection status, permissions, credentials or tokens where needed to operate an enabled integration.
- Usage, device and security information, such as IP address, browser or device details, log-in events, activity logs, error records and diagnostic information.
- Support, sales and business communications, including messages, meeting notes, requests and feedback.
- Billing, invoicing and tax records for customer administration and legal compliance.
- Cookie, analytics or session information where those technologies are enabled.
- AI-feature information, where offered, such as prompts, generated queries or outputs and related operational metadata.
Where information comes from
We may receive information directly from users and customer administrators; from systems a customer chooses to connect; from files, reports or instructions supplied by a customer; through website and platform activity; through support or sales interactions; from referrals; and from lawful public or third-party sources used for the relevant service.
How we use information
- Provide, configure, secure, support and maintain the Platform and agreed services.
- Retrieve, reconcile and analyse authorised commerce information and produce dashboards, reports, alerts and decision support.
- Authenticate users, administer access and investigate operational or security issues.
- Respond to requests, provide support and communicate about the service and customer relationship.
- Invoice customers, maintain financial records and meet tax or legal obligations.
- Understand service performance and improve reliability, usability and product experience using appropriately controlled information.
- Protect Data Say, customers and users; enforce agreements; establish or defend legal claims; and comply with lawful requests.
Customer Data and our role
Customers retain ownership of Customer Data. Customers are responsible for having the rights, notices, consents and lawful basis needed to provide that data and instruct Data Say to process it.
Where applicable, the customer acts as Data Fiduciary and Data Say acts as Data Processor for personal data within Customer Data. Data Say may separately act as Data Fiduciary for its own account, security, billing, website, support and business-contact processing. The correct role depends on the specific data flow and applicable law.
Connected services and credentials
Data Say requests read-only and least-privilege access wherever the connected source supports it. If granular read-only access is unavailable, access is used only for authorised retrieval, analysis, support and security purposes.
Customers remain responsible for authorising each connection and complying with the connected provider's terms. Integration-specific notices may provide additional details about scopes, data accessed, retention, revocation and deletion before a sensitive connection or AI feature is enabled.
Sharing and service providers
We may share information only where reasonably necessary for the purposes described in this notice, subject to appropriate confidentiality or professional obligations.
- With personnel, contractors and implementation partners who need access to operate or support Data Say.
- With hosting, authentication, database, monitoring, analytics, communications, support, payment or AI providers used for the relevant service.
- With professional advisers, auditors, insurers, investors, financing sources or prospective acquirers where appropriate and protected.
- When required by law, regulation, court order or a lawful government request, or to protect rights, safety and security.
- In connection with a merger, restructuring, financing, acquisition or sale, subject to suitable confidentiality and notice where required.
Processing locations
Data Say and its service providers may process information in India and in other countries where the relevant systems, support teams or providers operate. We do not make an absolute India-only storage claim. Before publication, Data Say will reconcile this section with its current provider register and applicable transfer requirements.
Cookies, analytics and replay
The website and Platform may use strictly necessary technologies for security, authentication and core functionality, and may use analytics, error-monitoring or session-replay technologies where enabled. Any non-essential technology should follow the consent or preference design applicable to the relevant user and geography.
A production cookie and analytics notice will identify the current technologies, providers, purposes and durations after a live tracker audit. Users will be given a persistent way to change relevant preferences where required.
Retention, return and deletion
We retain information only for as long as reasonably needed for the service, customer relationship, security, legal, tax, audit, backup, compliance or dispute-resolution purposes. Different categories may require different periods.
On termination, Customer Data return or export is handled in accordance with the signed Customer Agreement and any applicable agreed data-processing terms. Some copies may remain temporarily in backups or be retained where law, security or an active dispute requires it; retained information remains protected.
Security and incidents
Data Say uses reasonable technical and organisational safeguards appropriate to the nature of the information, including access controls, credential hygiene, least-privilege handling and reasonable monitoring or backups where applicable.
No service can guarantee absolute security. Incident investigation, mitigation and customer notification for Customer Data are governed by the signed Customer Agreement, applicable processing terms and law.
Your choices and rights
Subject to applicable law and Data Say's role for the relevant information, an individual may request access, correction, updating or erasure; withdraw consent where processing relies on consent; opt out of marketing; raise a grievance; or exercise any other applicable statutory right. We may need to verify identity and authority before acting on a request.
Privacy and grievance requests can be sent to our Grievance Officer, Vaibhav Singhal, at vs@datasay.ai.
Children
Data Say is a business service intended for organisations and their authorised professional users. It is not directed to children and we do not knowingly offer platform accounts directly to children. If we learn that child data has been provided without appropriate authority, we will review and address it in accordance with applicable law and customer instructions.
Changes and contact
We will post the current version on this page. If a change materially affects how we handle personal data, we will provide additional notice by e-mail, in-product message or another appropriate method where required.
Contact DataVader Info Private Limited at vs@datasay.ai.
