Skip to content

Legal

Privacy Policy.

What personal data Recvis collects, why, who it is shared with, how long we keep it, and the rights you have over it.

Updated 5 October 2026

Who we are

Recvis ("we", "us") runs this website and the Recvis client dashboard, and provides AI search optimization services from India. We decide why and how the personal data described here is used, which makes us its "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023.

For any question about this policy or your data, email our Grievance Officer, Sahil Ahmed A, at sahilahmeda2005@gmail.com.

What we collect, and why

This is everything we collect about people, item by item.

WhatWhen we collect itWhy
Your website address and business emailYou send the Talk to us formTo reply to you about our services
Your name and email addressWe invite you to the client dashboardTo create your account, send you the invitation and password-reset emails, and show you your brand's reports
Your password, stored only as a secure hashYou set a passwordTo sign you in
Your name, email address and profile picture from GoogleYou choose to sign in with GoogleTo sign you in
Your IP address and browser typeWhile you are signed inTo keep your account secure
Request logs: IP address, time, page requestedAny visit to the site, recorded by our hosting providerTo run the service and protect it from abuse
Anonymous usage and speed data: page visited, referring site, country, browser and device type, page load timesOnly if you choose Allow in the privacy bannerTo see which pages are useful and keep the site fast

Under the IT Act's 2011 rules, a password is sensitive personal data. We never see or store your actual password, only a one-way hash of it, and only to sign you in.

Audit data is about businesses, not people. To audit a brand we collect its name, website, public content, the questions we ask AI assistants and their answers. An answer can occasionally mention a person, such as a founder, by name.

You don't have to give us any of this. Without an email address we can't reply to you, and without an account you can't use the dashboard. We don't collect any other sensitive data, and the site is not meant for anyone under 18.

Why we're allowed to use it

  • When you contact us, you provide your details voluntarily so we can reply. The DPDP Act allows that use (section 7(a)) until you tell us to stop.
  • For anonymous analytics, we rely on your consent in the privacy banner. Nothing is measured until you choose Allow, and you can change your choice at any time with Cookie settings at the bottom of every page.
  • For the client dashboard, we rely on your consent, which you give when you accept our invitation and set a password or sign in. You can withdraw it at any time, as easily as you gave it: tell us, and we will remove your access and stop using your data within a reasonable time. Withdrawing doesn't affect what we did before.

We use your data only for the purposes above. We don't use it for advertising, we don't sell it, and we don't add you to mailing lists.

Who we share it with

We use a few service providers to run the site and the service. They process data on our behalf, only for these purposes, under their contracts with us, which require them to protect it.

ProviderWhat forData involved
VercelHosting the website and dashboard; anonymous analytics and speed measurement, if you allow themRequest logs; anonymous usage and speed data
NeonDatabase for the client dashboardAccount details, sessions, audit reports
GoogleDelivering our emails; Google sign-in if you use it; Gemini, for auditsEmail messages; your Google profile basics; audit questions about the brand
OpenAI, Perplexity, SerpApiAsking AI assistants and search engines the audit questionsQuestions about the audited brand, not your personal data

We don't share your data with anyone else, except when the law requires it, for example a lawful request from a government agency, or when you ask us to.

Data stored outside India

Our database and hosting are in the United States, and our providers may process data in other countries. Indian law allows this: the DPDP Act permits transfers abroad unless the government restricts a particular country, and the IT Act's rules allow transfers to providers that protect data to the same standard, where the transfer is needed to provide the service. We choose providers on that basis.

How long we keep it

  • Enquiries: until we no longer need them to talk to you, and no longer than 24 months after our last contact.
  • Dashboard accounts: while you have access. When your access to every brand ends, we delete your account and sessions.
  • Audit reports: while the brand is our client, and up to 24 months afterwards, so its history is there if it returns.
  • Records the law requires, such as invoices, for as long as that law requires.

From 13 May 2027, the DPDP Rules (rule 8(3)) also require us to keep a record of the personal data we processed, and the logs of that processing, for at least one year, after which we erase them. We will keep these records only for that purpose.

How we protect it

Connections to the site and dashboard are encrypted. Passwords are stored only as secure hashes. Each dashboard account sees only the brands it was invited to, and only our founders can reach the admin area. Our providers encrypt data and keep backups.

No system is perfectly secure. If a breach affects your personal data, we will tell you without delay: what happened, what it means for you, what we are doing about it and what you can do. We will also report it to the Data Protection Board of India, and to CERT-In where Indian law requires.

Your rights

Under the DPDP Act you can ask us to:

  • give you a summary of the personal data we hold about you, what we do with it, and who we have shared it with (section 11);
  • correct, complete or update it, or erase it where we don't need to keep it by law (section 12);
  • withdraw consent you gave (section 6);
  • resolve a complaint about how we handled your data (section 13);
  • let someone you nominate exercise these rights for you if you die or become unable to (section 14).

To make a request, email our Grievance Officer, Sahil Ahmed A, at sahilahmeda2005@gmail.com, from the email address you use with us, so we can identify you. We will reply within 30 days. You can also ask for this policy in any language listed in the Eighth Schedule to the Constitution.

If our answer doesn't resolve your complaint, you can then complain to the Data Protection Board of India. The Act asks you to raise it with us first.

Grievance Officer

Our Grievance Officer is Sahil Ahmed A, reachable at sahilahmeda2005@gmail.com. They answer questions about how we process personal data and resolve complaints within 30 days.

Cookies

We use only the cookies needed to keep you signed in to the dashboard, and no advertising or tracking cookies. Our optional analytics sets no cookies and runs only if you allow it. The Cookie Policy has the details.

The laws this policy follows

  • Information Technology Act, 2000, section 43A and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which apply until 13 May 2027.
  • Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. The Data Protection Board provisions apply now; the main obligations on businesses apply from 13 May 2027. We already follow them.

Changes to this policy

If we change how we handle personal data, we will update this page and the date at the top. If the change is significant, we will email dashboard users before it takes effect.