Privacy Policy

Last updated: 2 August 2026

This policy explains how Grappi ("we") handles personal data when you use grappi.ai and the Grappi APIs. It is designed to meet the Digital Personal Data Protection Act, 2023 ("DPDP Act") and associated rules.

1. Who we are

For data you give us about yourself (account and billing data), Grappi is the data fiduciary. For your end customers' data that you submit to our APIs, you are the data fiduciary and Grappi processes it solely on your documented instruction.

2. What we collect

  • Account data — name, work email, phone, password (stored only as a salted scrypt hash), organisation name.
  • Billing data — wallet balance, ledger of top-ups and debits, GST details you provide for invoicing. Card/UPI details are handled by our payment gateway (Razorpay) and never touch our servers.
  • Usage data — API endpoints called, timestamps, latency, success, and IP addresses, for metering, security, and abuse prevention.
  • API payload data — data you send to the APIs (e.g. a PAN for verification, a statement PDF for parsing). Sensitive fields are encrypted at rest with AES-256; payloads are retained only as long as needed to serve the request and meet legal obligations.

3. Why we process it

  • To provide, meter, and bill the Services (contractual necessity).
  • To secure the platform — fraud, abuse, and incident detection (legitimate use).
  • To meet legal obligations — tax, accounting, KYC/AML where applicable.
  • To send service communications (OTP, billing, incident notices).

We do not sell personal data, and we do not use it for advertising.

4. Consent

Where the APIs act on an individual's personal data (KYC, account aggregation, statements), the request must be backed by that individual's informed consent collected by you. Consent records are stored and auditable; Account Aggregator flows additionally follow the ReBIT consent artefact framework.

5. Storage and transfers

Production data is stored on servers located in India. We transfer personal data outside India only where permitted under the DPDP Act and required for a named sub-processor.

6. Retention

  • Account and ledger data — for the life of the account plus statutory retention periods.
  • API payloads — transient; encrypted vault items follow the product's stated data-life.
  • Audit records — retained as an append-only log for compliance.

7. Your rights

You may access, correct, or request erasure of your personal data, nominate a representative, and withdraw consent by writing to support@grappi.ai. We respond within the timelines prescribed under the DPDP Act. If unsatisfied, you may escalate to the Data Protection Board of India.

8. Grievance officer

Grievance Officer, Grappi — support@grappi.ai. We acknowledge grievances within 72 hours and aim to resolve them within 15 days.

9. Security

Row-level tenant isolation in the database, AES-256 encryption for sensitive fields, scrypt password hashing, TLS in transit, least-privilege database roles, an append-only audit chain, and rate limiting. Report vulnerabilities to support@grappi.ai.

10. Third parties

Named sub-processors include our payment gateway (Razorpay), transactional email (Zoho ZeptoMail), accounting (Zoho Books), and the upstream data utilities each API documents (e.g. RTAs, depositories, exchanges). Each processes only what its function requires.

11. Changes

We will notify material changes by email or portal notice. See also our Terms of Service.