Effective 11 September 2026
Who this policy covers
This policy applies when you visit RohitAI, contact us, use an account, book a meeting, engage us for AI consulting, subscribe to communications or an expressly offered paid plan, access digital content, or sign a project document. The business and grievance contacts are listed below. Where we process a client’s data only on their instructions, the relevant project agreement also applies.
You must be at least 18 years old to create an account or purchase a service. We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data.
Data we collect and where it comes from
We collect information you provide: your name, email, phone when supplied, organization, billing address, account settings, communication preferences, meeting or project requirements, contracts, messages, and support requests. Please share only the information needed for your request.
We also process session and security information, IP addresses and basic device information, consent records, bookings, invoices, transaction references and status, refunds, disputes, subscription status, digital-access records, and video progress where that feature is used. Information may come from your organization or the payment, email, calendar, conferencing, or signing service used for your request.
Card, bank, and UPI payment credentials are handled by the payment provider. RohitAI does not store full card numbers, card security codes, or UPI PINs. We retain the references and records needed for billing, reconciliation, refunds, disputes, and legal obligations.
Why we use personal data
We use personal data to respond to enquiries; provide consulting, meetings, accounts, and requested digital services; prepare contracts and invoices; process and reconcile payments; grant purchased access; provide support; prevent fraud; and meet tax, accounting, legal, and dispute obligations.
Where applicable, we rely on a contract or steps you request before a contract, legal obligations, your consent for optional activities, or legitimate interests in running and protecting the service without overriding your rights. Marketing email requires a separate opt-in. You can withdraw optional consent without losing access to unrelated services.
We do not sell personal data for money. Some disclosures to advertising providers may be treated as sale, sharing, or targeted advertising under applicable privacy laws. You can reject optional advertising or use Global Privacy Control as described below.
YouTube videos and external links
Video players on the homepage and in articles are loaded only when you press play. Before playback, the website displays a local preview panel. Pressing play allows the external player to connect; YouTube then receives information such as your IP address, browser information, and playback activity and may use cookies or other storage under its own policy.
We use YouTube’s privacy-enhanced embed domain. This reduces certain uses of embed viewing information; it does not make playback anonymous or prevent all data collection. You may instead follow the Watch on YouTube link. External sites have their own terms and privacy practices.
Recipients and service providers
We share information only as needed with hosting and security providers, payment processors, transactional email and opted-in newsletter delivery services, calendar and video-meeting providers, electronic-signing services, and professional advisers. The payment provider is identified in the payment process when a paid service is offered. Providers may also have independent legal obligations and privacy terms.
An organization involved in your project or account receives information only under its authorized access. We may disclose information when legally required, to protect rights or security, or during a business reorganization with appropriate safeguards. Embedded YouTube videos are described separately above.
International transfers
RohitAI is operated from India and service providers may process information in India, the United States, the European Economic Area, or other countries. Privacy protections can differ from those where you live. Where law requires a transfer mechanism, we use an applicable adequacy decision, contractual safeguards, provider data-protection terms, or another lawful mechanism, and apply technical and organizational safeguards proportionate to the data and service.
Retention and deletion
We retain personal data for the time needed to provide the requested service, operate an active account, handle support and disputes, protect security, and comply with legal, tax, and accounting duties. Retention varies by record type; transaction and consent records may need to be kept after an account closes.
You can request deletion, subject to records we must retain for legal or legitimate purposes. Privacy exports expire after seven days. Required invoices, payment records, contracts, consent evidence, and audit records are restricted or minimized where possible. Backup copies expire under the applicable retention schedule rather than being individually rewritten.
Your rights and choices
Depending on where you live and whether an exemption applies, you may request access, a copy, correction, completion, deletion, restriction, portability, withdrawal of consent, or information about processing and recipients. You may object to certain processing and appeal or complain to an applicable data-protection authority. You will not receive discriminatory service for exercising an applicable privacy right, although data needed to provide a requested product cannot always be deleted while that product is active.
Use the account privacy center when available or the privacy contact details below. We verify requests in a proportionate way and may ask for information needed to prevent disclosure to the wrong person. An authorized agent must provide valid authority and we may still verify the person. If we deny or limit a request, we explain the reason and available appeal route where required.
You can unsubscribe from marketing email using the message link or account preferences without affecting transactional messages needed for an account, purchase, security alert, contract, or service. You may also complain to the Data Protection Board of India or another competent regulator once and where the applicable process is available.
Security and incidents
We use access controls, encryption in transit, protected storage, session and MFA controls, least-privilege service identities, upload scanning, logging restrictions, backups, and audit evidence designed to protect the platform. No internet service is risk-free. If a personal-data incident requires notice, we will notify affected people and authorities in the form and time required by applicable law.
Changes and complaints
We publish an effective date when this policy changes and provide additional notice of material changes where appropriate. A new policy does not silently rewrite the terms recorded for an earlier transaction.
Contact the grievance officer below about privacy or consumer complaints. We acknowledge complaints within 48 hours and aim to resolve them within 30 days, or within any shorter period required by law. We explain requests for further information and available escalation routes. Your rights to approach a competent regulator, consumer forum, or court remain available.
Contact
General questions: support@rohitai.com. Grievance officer: support@rohitai.com (Rohit Ramachandran).
For business details and phone support, visit the Contact page.
Account holders can also use the privacy center.