Privacy policy

Last updated: 6 October 2026

Paradise AI ("we", "us") runs this website and a private portal where clients follow their projects, share files, message us and pay invoices. This policy explains what personal data we collect, why, who else sees it, how long we keep it and the choices you have. We handle personal data in line with the Digital Personal Data Protection Act, 2023 and other Indian law that applies to us.

Who is responsible

Paradise AI, [address not set]. For any question or request about your data, write to [[email not set]](mailto:[email not set]). This address is also our grievance contact; we acknowledge requests within 3 working days and aim to resolve them within 30 days.

What we collect and why

  • Enquiries and quote requests. Your name, email, phone, company, project details, budget and timeline, and (if you came from a campaign) which campaign. We use this to reply, prepare proposals and judge fit.
  • Client accounts. Name, work email, company, a password (stored only as a salted hash, never readable), when you accepted our terms, and sign-in activity (time, device type, IP address) to keep the account secure. If you turn on two-step verification we store an encrypted key for your authenticator app.
  • Work we do together. Messages, files you upload, project details, proposals, and the notifications we send you inside the portal.
  • Invoices and payments. Billing name and address, GSTIN, invoice and payment records. Card, UPI and bank details are entered with our payment provider, not with us; we only receive the result.
  • Reviews. Anything you choose to submit, published only with your permission.
  • Website analytics (only if you accept). Which pages are viewed, which buttons are clicked and how fast pages load, tied to a random per-tab identifier that disappears when you close the tab. No advertising profile is built, no IP address is stored with these events, and nothing is shared with advertisers.
  • Security logs. Sign-ins, permission changes and file downloads are recorded in an audit log so we can investigate misuse.

Why we may process it

To provide services you asked for and perform our contract; because you gave consent (for example analytics, publishing a review); to meet legal duties (tax and accounting records, responding to lawful requests); and for legitimate uses permitted by law such as keeping the service secure and preventing fraud.

Who else handles your data

We use service providers who process data only on our instructions: hosting and database providers, file storage, an email delivery provider, a payment provider (Razorpay or Stripe) and an error-monitoring service. We do not sell personal data. We may disclose data if required by law. If a provider stores data outside India, we choose providers that protect it to a comparable standard.

How long we keep it

  • Enquiries that never became a project: deleted about two years after the last activity.
  • Sign-ups that never confirm their email: deleted after 7 days.
  • Client accounts and project records: while you are a client, then as long as needed for the work and our legal duties.
  • Invoices and payment records: for the period tax and company law require us to keep them, even if you close your account.
  • Analytics events: up to 13 months. In-portal notifications: 6 months. Audit logs: kept for security and legal purposes, with your name removed if you ask us to erase your account.

Your rights

You can ask us to show you the data we hold about you, correct it, erase it, or stop using it where you gave consent, and you can nominate someone to exercise these rights for you if you cannot. Signed-in clients can download their data and delete their account from the Profile page. We may need to keep some records (for example invoices) because the law requires it, and we will tell you which. You can withdraw analytics consent at any time with "Cookie settings" in the footer. If you are not satisfied with our reply, you may complain to the Data Protection Board of India.

Security

Passwords are hashed, traffic is encrypted, access is limited by role and by client, uploads are checked, and team accounts can require two-step verification. No system is perfectly secure; if a breach affecting you occurs we will tell you and the authorities as the law requires.

Children

This website and portal are for businesses and are not directed at children. We do not knowingly collect children's data.

Changes

If we change this policy in a way that matters, we will update the date above and, for clients, tell you in the portal or by email.