Questions, rights requests and grievances.
Privacy information that is understandable and usable
Aerlinked aims to process digital personal data for defined business purposes, limit access, keep information accurate where it affects decisions and provide practical ways for individuals to exercise applicable rights.
India’s DPDP framework is subject to phased commencement. Aerlinked will review this notice and its operational controls as additional provisions become effective, official guidance develops or our processing activities change.
Purpose limitation
We connect data collection and use to identified platform, security, billing, support or business-service purposes.
Data minimisation
We seek to process information that is reasonably needed for the relevant service or lawful operational requirement.
Accountability
Privileged actions, important changes, consent choices and rights requests are designed to be recorded and reviewable.
Digital personal data Aerlinked may handle
The exact data depends on how you use Aerlinked, your organisation settings and whether you use lead search, CRM, billing, referrals or support.
| Data category | Examples | Typical use |
|---|---|---|
| Account and identity | Name, business email, mobile number, login identifiers and verification status. | Registration, authentication, account administration and communication. |
| Organisation information | Business name, verified domain, role, team membership and organisation policies. | Organisation grouping, shared access and duplicate-protection controls. |
| Lead-directory activity | Search filters, viewed records, unlock activity, credit source and organisation-sharing history. | Delivering lead search, preventing repeated unlocks and maintaining an access history. |
| CRM content | Contacts, notes, deal stages, task details, follow-up history and ownership. | Providing contact, deal, task and sales-workflow features. |
| Billing and tax | Plan, payment status, billing address, GST information, invoices and refund references. | Payment processing, invoices, accounting, tax and dispute resolution. |
| Support and communication | Ticket messages, attachments, complaints, replies and notification preferences. | Support, grievance redressal, service communication and quality improvement. |
| Device and security | IP address, device, browser, session, timestamps, request identifiers and risk signals. | Authentication, fraud prevention, audit, security monitoring and incident response. |
| Consent and preferences | Consent records, withdrawals, marketing choices and cookie preferences. | Honouring choices and demonstrating when and how a preference changed. |
Why we process personal data
We process personal data where consent has been provided, where information is voluntarily provided for a specified purpose, or where another use is permitted by applicable law.
Provide the service
Create accounts, verify users, deliver lead search, unlock records, manage CRM and support collaboration.
Manage billing
Process subscriptions, allocate credits, generate GST invoices, reconcile payments and handle refunds.
Protect Aerlinked
Detect unauthorised access, investigate suspicious activity, preserve audit trails and maintain service continuity.
Provide support
Respond to enquiries, resolve lead-quality complaints, investigate issues and manage grievances.
Improve the platform
Understand feature use, diagnose errors and improve usability using aggregated or appropriately controlled information.
Communicate
Send service, security, billing and support messages, and marketing updates where permitted and selected.
Where information may come from
Directly from you
Information entered during registration, billing, CRM use, support, consent or a privacy request.
Your organisation
Team invitations, domain verification, ownership assignments and organisation-level access settings.
Lawful business sources
Business information from lawful public or authorised third-party sources, subject to applicable law and source terms.
Automatically
Technical, usage, session and security data created when the service is used.
Service providers
Payment status, delivery confirmations and technical events from authorised processors or integrations.
Rights and grievances
Identity verification and supporting information submitted to resolve a request or complaint.
Choice should be as clear as the request
Where processing depends on consent, Aerlinked aims to present the purpose clearly, preserve a record of the choice and make withdrawal reasonably accessible.
Identify the data and specific service or communication purpose.
Obtain an unambiguous action where consent is required.
Store the choice, version, timestamp and relevant context.
Stop future consent-based processing after withdrawal, subject to lawful retention.
Withdrawing consent affects future consent-based processing. Some information may still be retained or processed where necessary for a legal requirement, security, fraud prevention, dispute resolution or another use permitted by applicable law.
Ways to understand and control your personal data
Available rights may depend on commencement, the processing context, identity verification and lawful retention requirements.
Access information
Request a summary of personal data being processed and relevant information about processing or sharing.
Correct or update
Ask us to correct inaccurate or misleading information and complete or update relevant records.
Request erasure
Request deletion where the purpose is complete and retention is not required for law or another permitted purpose.
Withdraw consent
Change or withdraw applicable consent choices through available account or privacy controls.
Raise a grievance
Tell us about a privacy concern and receive a tracked response through the grievance process.
Nominate an individual
Where applicable, nominate another individual to exercise rights in the event of death or incapacity.
We do not intend to keep personal data indefinitely
Retention is linked to the service purpose, account relationship, security needs, legal requirements, disputes and configured deletion processes.
| Information | General retention approach | Deletion trigger |
|---|---|---|
| Account and organisation | During the account relationship and for a limited period needed for security, recovery, disputes or legal compliance. | Verified account deletion, completion of lawful retention and closure of unresolved matters. |
| CRM content | While the user or organisation maintains the CRM record, subject to account and backup controls. | User or authorised organisation deletion, account closure or configured retention policy. |
| Billing and invoice data | For the period needed for accounting, taxation, payment disputes and applicable legal obligations. | Expiry of the applicable financial and legal retention period. |
| Support and grievances | Until the issue is resolved and for a limited period needed for audit, recurrence prevention or legal defence. | Closure of the matter and expiry of the relevant retention period. |
| Security and processing logs | At least one year where the applicable DPDP Rules require it, or longer where another law or active investigation requires. | Expiry of the applicable period and absence of a security, legal or investigation hold. |
| Consent records | For as long as needed to demonstrate the consent choice, withdrawal and related processing history. | When no longer needed for accountability or a legal requirement. |
Deleted data may remain temporarily in restricted backups until the backup lifecycle completes. Deletion may also be delayed where information is subject to a lawful hold, fraud review, dispute or other statutory requirement.
Who may receive or process personal data
Technology providers
Hosting, storage, monitoring, email delivery, support and other infrastructure providers operating under contractual controls.
Payment providers
Payment gateways, banks, tax and accounting services needed to process payments and financial records.
Authorised integrations
Services connected by Aerlinked or by an authorised user, based on the integration scope and configured permissions.
Legal and regulatory recipients
Authorities, courts or professional advisers where disclosure is required or permitted by applicable law.
Your organisation
Authorised organisation members where shared access, ownership or collaboration is enabled.
Business transition
Appropriately protected disclosures during a merger, acquisition, financing or transfer of business assets.
Layered controls to protect confidentiality, integrity and availability
Appropriate encryption, masking, obfuscation or token-based controls depending on the system and risk.
Authentication, role permissions, least-privilege access and privileged action controls.
Audit logs, security signals, review processes and investigation support for unauthorised access.
Encrypted backups, continuity measures and controlled restore testing.
Security and confidentiality requirements for processors and relevant service providers.
Detection, containment, investigation, remediation and communication workflows.
Operational procedures, administrator accountability and periodic control reviews.
Purpose-linked collection, restricted access, retention controls and secure deletion processes.
Aerlinked is designed for business users
Aerlinked is not intended for individuals under 18. We do not knowingly seek to provide accounts to children or use children’s data for tracking, behavioural monitoring or targeted advertising.
Where you believe a child has submitted personal data to Aerlinked, contact Hello@aerlinked.com. We may request appropriate verification before taking corrective action.
Contain, investigate, communicate and improve
Validate the incident, restrict exposure and preserve evidence.
Identify affected data, people, systems, timing and likely consequences.
Provide clear information to affected individuals and the Board in the applicable manner and timeframe.
Reduce risk, prevent recurrence and document corrective measures.
Where notification is required, Aerlinked aims to explain the nature and extent of the breach, likely consequences, mitigation measures, steps individuals can take and a business contact for questions.
Cross-border processing with appropriate controls
Aerlinked may use vetted service providers in India or other jurisdictions. Where personal data is processed outside India, we aim to apply contractual, technical and organisational safeguards and comply with restrictions notified by the Central Government or other applicable laws.
Provider review
Assess the service, data scope, security controls and intended processing location.
Contractual protection
Define confidentiality, security, sub-processing, incident and deletion obligations.
Government restrictions
Review applicable notifications or restrictions concerning transfers to a country or territory.
A tracked path for privacy concerns
Please contact Aerlinked first so that we can investigate and provide a response. Applicable law may require this internal grievance opportunity to be exhausted before approaching the Data Protection Board.
Use the privacy request centre or email Hello@aerlinked.com.
We may verify identity, authority and the request scope.
The Privacy & Grievance Team reviews systems, records and applicable exceptions.
Receive a decision, action taken, limitations and available next steps.
Aerlinked Privacy & Grievance Team
For questions about this notice, processing of personal data, a rights request or a privacy grievance.
Official DPDP framework documents
These government publications are provided for reference. The official text, commencement notifications and subsequent amendments prevail over this summary.
This page is a public-facing explanation of Aerlinked’s intended privacy approach. It does not replace the official law or constitute legal advice. The final production notice should remain aligned with Aerlinked’s actual legal entity, systems, vendors and data flows.