Ailaysa

Ailaysa - Privacy Policy

Effective date: October 3, 2026

Previous version: September 17, 2026
This Privacy Policy describes Our policies and procedures on the collection, use, storage, disclosure, cross-border transfer, and erasure of Your information when You use the Service, and describes Your privacy rights and how applicable law protects You. We use Your Personal Data to provide and improve the Service, including features powered by artificial intelligence and machine learning ("AI Features"). By using the Service, You agree to the collection and use of information in accordance with this Privacy Policy.

1. Interpretation and Definitions

#

1.1 Interpretation

#
Words with an initial capital letter have the meanings defined below, regardless of whether they appear in the singular or plural.

1.2 Definitions

#
For the purposes of this Privacy Policy:
  • Website refers to Ailaysa, accessible from www.ailaysa.com and platform.ailaysa.com.

  • Company ("the Company", "We", "Us", "Our") refers to Ailaysa Technologies Private Limited, located at Ailaysa Technologies Pvt Ltd, No.120 (First floor), 23/1, Major Mukund Varadharajan Rd, Ram Nagar South, Chennai, Tamil Nadu 600100. For the purposes of the GDPR, the Company acts as the Data Controller; for the purposes of the DPDP Act, the Company acts as the Data Fiduciary.

  • Affiliate means an entity that controls, is controlled by, or is under common control with a party, "control" meaning ownership of, or the right to direct the voting of, 50% or more of the relevant voting securities or equivalent managing authority.

  • Account means a unique account created for You to access the Service.

  • Service refers to the Website and the Ailaysa platform, including all AI-powered translation, localization, transcription, content-generation, and language-technology features made available through it.

  • Country refers to Tamil Nadu, India, being the Company's principal place of business. Given the Service's availability to Users in the European Union/European Economic Area ("EU/EEA") and India, this Policy separately addresses the GDPR and the DPDP Act as applicable.

  • Service Provider means a natural or legal person, public authority, agency, or other body that processes Personal Data on the Company's behalf, including AI Model Providers, Infrastructure Providers, and Localization Tooling Providers (each defined below). For purposes of the GDPR, a Service Provider is a Data Processor; for purposes of the DPDP Act, a Data Processor; for purposes of the CCPA, a Service Provider.

  • AI Model Provider means a third-party provider of artificial intelligence, large language model ("LLM"), or generative AI ("Gen AI") technology accessed by the Company via Application Programming Interface ("API") to power AI Features, including Google LLC. An AI Model Provider is a category of Service Provider and, in relation to General-Purpose AI models within the meaning of the EU AI Act, may itself be a "provider" of a general-purpose AI model under that Regulation, with the Company acting as a "deployer" of such models within the Service.

  • Localization Tooling Provider means a third-party provider of content-extraction, filtering, terminology-management, and translation-quality-assurance tooling used to prepare, validate, or check Content Data in connection with AI Features, including the Okapi Framework (an open-source localization/content-processing toolset).

  • Infrastructure Provider means a third-party provider of cloud computing, hosting, storage, or content-delivery infrastructure on which the Service and its data stores run, including Amazon Web Services, Inc. ("AWS") and DigitalOcean, LLC. An Infrastructure Provider is a category of Service Provider.

  • AI Features means features of the Service that use artificial intelligence, machine learning, or Gen AI — including translation, content generation, transcription, terminology management, and related content-intelligence functionality — whether powered by the Company's own models or by an AI Model Provider.

  • Content Data means the text, documents, audio, video, images, or other content that You submit to, upload to, or generate through the Service for processing by AI Features (for example, a document submitted for translation).

  • Third-party Social Media Service refers to any website or social network through which a User may log in or create an Account to use the Service.

  • Personal Data is any information relating to an identified or identifiable natural person. For GDPR purposes, Personal Data has the meaning given in Article 4(1) GDPR. For CCPA purposes, Personal Data means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular consumer or household. For DPDP Act purposes, the equivalent term is "Personal Data" as defined in Section 2(t) of the DPDP Act, being data about an individual who is identifiable by or in relation to such data.

  • Cookies are small files placed on Your device by a website, storing details of Your browsing activity, among other uses.

  • Usage Data refers to data collected automatically through use of the Service or the Service's infrastructure (for example, page-visit duration).

  • Data Controller (GDPR) refers to the Company as the entity which, alone or jointly with others, determines the purposes and means of processing Personal Data.

  • Data Fiduciary (DPDP Act) refers to the Company as the entity which, alone or in conjunction with other Data Fiduciaries, determines the purpose and means of processing Personal Data.

  • Data Principal (DPDP Act) means the individual to whom the Personal Data relates, and, where such individual is a child or a person with disability who has a lawful guardian, includes the parent or lawful guardian acting on their behalf.

  • Consent Manager (DPDP Act) means a person registered with the Data Protection Board of India who acts as a single point of contact enabling a Data Principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.

  • Do Not Track (DNT) is a browser-transmitted signal, promoted by the U.S. Federal Trade Commission, indicating a preference to opt out of cross-site tracking.

  • Business (CCPA) refers to the Company as the entity that determines the purposes and means of processing Consumers' Personal Data and does business in California.

  • Consumer (CCPA) means a natural person who is a California resident.

  • Sale (CCPA) means selling, renting, releasing, disclosing, disseminating, or otherwise communicating a Consumer's Personal Data to a third party for monetary or other valuable consideration.

  • EU Representative means the representative in the European Union designated by the Company pursuant to Article 27 GDPR, where the Company is not established in the EU/EEA but offers the Service to, or monitors the behavior of, Data Subjects located there.

2. Collecting and Using Your Personal Data

#

2.1 Types of Data Collected

#

Personal Data

While using the Service, We may ask You to provide personally identifiable information, including but not limited to:
  • Email address

  • First name and last name

  • Phone number

  • Address, State, Province, ZIP/Postal code, City

  • Payment/billing details necessary to process transactions (processed via PCI-DSS-compliant third-party payment processors; the Company does not itself store full payment card numbers)

  • Usage Data

Content Data submitted to AI Features

When You use an AI Feature — to translate, write, transcribe, localize, or otherwise process content — You submit Content Data to the Service. Content Data may include text, documents, audio, video, or images, and may itself contain Personal Data (for example, where a submitted document names identifiable individuals). We process Content Data to generate the output You request and, where applicable, transmit it to an AI Model Provider and/or process it via Localization Tooling for that purpose, as described in Section 3 below.

Usage Data

Collected automatically, and may include Your device's IP address, browser type and version, pages visited, time and date of visit, time spent on pages, unique device identifiers, mobile device type/OS, and other diagnostic data.

2.2 Tracking Technologies and Cookies

#
We use Cookies and similar technologies (beacons, tags, scripts) to operate, secure, and analyze the Service:
CategoryTypeAdministered byPurpose
Necessary/EssentialSessionUsAuthentication; fraud prevention; core functionality
Cookies Policy/Notice AcceptancePersistentUsRecords cookie-consent status
FunctionalityPersistentUsRemembers preferences (e.g., language, login)
Tracking/PerformancePersistentThird partiesTraffic analytics; feature testing
Where required by GDPR/ePrivacy rules or the DPDP Act's consent framework, non-essential Cookies are set only after You provide affirmative, informed consent via Our cookie-consent mechanism. You may withdraw consent or manage preferences at any time via Your browser settings or Our cookie-preference center; declining Cookies may limit certain Service functionality.

2.3 Use of Your Personal Data

#
The Company may use Personal Data to:
  • Provide, operate, and monitor the Service;

  • Manage Your Account and registration;

  • Provide AI Features — generating translations, transcriptions, content drafts, terminology suggestions, and related outputs from Content Data, including by transmitting Content Data to AI Model Providers and processing it via Localization Tooling as described below;

  • Perform contracts, including purchase contracts for products/services;

  • Contact You regarding Service updates, security notices, or informational communications;

  • Send news, offers, and related communications, where You have not opted out;

  • Manage and respond to Your requests, including data-subject/Data Principal rights requests;

  • Detect, prevent, and address technical issues, fraud, or misuse, and monitor AI Feature performance and reliability — this does not include using Your Content Data to train any AI model, as set out in Section 3.2.

2.4 Disclosure for the Above Purposes

#
We may share Personal Data:
  • With Service Providers, including AI Model Providers, Localization Tooling Providers, and Infrastructure Providers, to operate the Service and AI Features, process payments, and provide support;

  • In Business Transfers — mergers, asset sales, financings, or acquisitions;

  • With Affiliates, bound to honor this Privacy Policy;

  • With business partners, to offer products, services, or promotions You have opted into;

  • With other Users, where You voluntarily share information in public or shared areas of the Service.

3. Use of Artificial Intelligence and Third-Party AI Model Providers

#

3.1 How AI Features Work

#
The Service uses artificial intelligence, including LLMs and other Gen AI systems, to power AI Features such as multilingual translation, content generation, transcription, and terminology/style management. To provide these features, the Company accesses AI models made available by third-party AI Model Providers — currently Google LLC (Gemini models)[, and, where applicable, OpenAI, L.L.C. and Anthropic, PBC] — via their respective APIs. When You use an AI Feature, the Content Data You submit is transmitted to the relevant AI Model Provider solely to generate the output You requested; the output is returned to the Service and made available to You.
Content Data may also be processed through Okapi Framework–based localization tooling (content extraction, filtering, and translation-quality checks) prior to or alongside AI-model processing. The Company does not operate its own frontier foundation models; it orchestrates and applies third-party Gen AI models within the platform, together with the Company's own terminology, style, and workflow technology, to produce the final result.

3.2 No Use of Your Data to Train AI Models

#
The Company does not use Your Content Data or Personal Data to train, retrain, or fine-tune any AI model — whether the Company's own models or those of any AI Model Provider. The Company accesses AI Model Providers through their commercial API offerings, which, unlike certain free consumer-facing products of the same providers, do not use API-submitted data to train the provider's models by default. The Company does not opt in to any AI Model Provider program that would use Your data for model training.

3.3 AI Model Providers and Localization Tooling Providers as Sub-Processors

#
Each AI Model Provider and Localization Tooling Provider acts as a Service Provider/sub-processor of the Company for the limited purpose of generating AI outputs or performing content-processing/quality-assurance functions on the Company's instructions. Such providers are contractually and/or technically restricted from using Your Content Data for any purpose other than fulfilling the Company's instructions, and are required to apply data-protection and security safeguards consistent with industry standards and, where applicable, Article 28 GDPR data-processing agreement requirements. You may review each provider's own data-handling terms at:
  • Google (Gemini/Cloud AI): https://policies.google.com/privacy

  • Okapi Framework

3.4 Retention by AI Model Providers

#
AI Model Providers generally retain API-submitted data only for a limited period, primarily for abuse monitoring, safety, and legal-compliance purposes, in accordance with their own published API data-retention terms — not for model training. Where an AI Model Provider offers zero- or reduced-retention arrangements for API customers, the Company seeks to use such arrangements where commercially available.

3.5 Human Oversight and AI-Generated Content

#
AI Features are designed to assist human translators, editors, writers, and reviewers — not to replace human judgment. The Company does not use AI to make solely automated decisions producing legal or similarly significant effects concerning You within the meaning of Article 22 GDPR. Outputs generated by AI Features may contain errors and should be reviewed before use, particularly for accuracy-critical, legal, medical, or safety-related content.

3.6 EU AI Act — Transparency Obligations

#
To the extent the Service uses general-purpose AI models (such as Gemini) or generates or manipulates content within the meaning of Regulation (EU) 2024/1689 (the "EU AI Act"), the Company, acting as a deployer, adheres to the following transparency principles as they come into force under the Act's phased implementation timeline:
  • Where the Service generates synthetic text, audio, image, or video content that could reasonably be mistaken for authentic human-generated content, the Company will implement appropriate machine-readable marking or disclosure of AI-generated/manipulated output, consistent with Article 50 EU AI Act, to the extent such obligations apply to the Company's use case;

  • Where You interact directly with an AI system (for example, a conversational or generative AI Feature) and it is not obvious from the circumstances, the Company will disclose that You are interacting with an AI system, as required by Article 50(1) EU AI Act;

  • The Company does not deploy AI systems within the Service for purposes classified as "unacceptable risk" under Article 5 EU AI Act (e.g., social scoring, real-time biometric categorization for law enforcement, or manipulative/subliminal techniques causing harm);

  • The Company continues to assess whether any AI Feature falls within a "high-risk" use case under Annex III EU AI Act and will update this Policy and implement corresponding conformity obligations if so.

3.7 Changes to AI Model Providers

#
The Company may add, remove, or change its AI Model Providers, Localization Tooling Providers, or Infrastructure Providers as the Service evolves. Material changes affecting how Your Personal Data or Content Data is processed will be reflected in updates to this Privacy Policy, and We will notify You as described in Section 12 ("Changes to this Privacy Policy").

4. Cloud Infrastructure and Hosting

#
The Service, including Personal Data and Content Data stores, is hosted on cloud infrastructure provided by Amazon Web Services, Inc. (AWS) and DigitalOcean, LLC, acting as Infrastructure Providers/sub-processors. These providers do not access Personal Data or Content Data other than as necessary to provide hosting, storage, networking, and related infrastructure services, and are contractually bound by data-processing terms consistent with Article 28 GDPR (where applicable) and industry-standard security certifications (e.g., ISO 27001, SOC 2). Data center locations used by these Infrastructure Providers may be located outside Your country of residence; see Section 6 ("Transfer of Your Personal Data").

5. Retention of Your Personal Data

#
The Company retains Your Personal Data and Content Data only for as long as necessary for the purposes set out in this Privacy Policy, to comply with legal obligations, resolve disputes, and enforce Our agreements and policies.
Account deletion. Where You delete Your Account, or request deletion, the Company will delete or anonymize Your Personal Data and Content Data held in its active systems within ninety (90) days of the deletion event, except to the extent retention of specific data is required to comply with a legal obligation, resolve a dispute, prevent fraud/abuse, or enforce Our agreements, in which case such data will be retained only for so long as that specific purpose requires and will be deleted or anonymized thereafter. Residual copies in encrypted backups are purged in the ordinary course of Our backup-rotation cycle, which does not exceed the same 90-day window beyond the point of deletion from live systems.
Deletion on request. Independently of Account deletion, You may request erasure of Your Personal Data and/or Content Data at any time by emailing ilangoven@ailaysa.com from Your Account's registered email address (or by another verification method We may specify). Upon successful verification of Your identity, the Company will process such requests and complete deletion within the timelines set out above, save for data the Company is legally required or permitted to retain (e.g., billing records for tax/audit purposes, or data subject to a legal hold).
Content Data retained by AI Model Providers/Localization Tooling Providers. Content Data transmitted to AI Model Providers is retained by such providers only for the shorter, provider-specific periods described in Section 3.4, independent of the Company's own retention timeline.
Usage Data is retained for a shorter internal-analysis period by default, except where extended retention is necessary for security, functionality, or legal compliance.

6. Transfer of Your Personal Data

#
Your Personal Data and Content Data are processed at the Company's operating offices and at the facilities of the parties involved in processing — including the data centers of Google (Gemini), AWS, and DigitalOcean, which may be located in the United States, the European Union, or other jurisdictions outside India. This means Your information may be transferred to, and maintained on, computers located outside Your state, province, country, or governmental jurisdiction, where data-protection laws may differ.
GDPR cross-border transfers. Where Personal Data of Users in the EU/EEA is transferred to a country outside the EU/EEA that has not received an adequacy decision from the European Commission under Article 45 GDPR, the Company relies on appropriate safeguards under Article 46 GDPR — in particular, the European Commission's Standard Contractual Clauses ("SCCs") — together with supplementary technical and organizational measures (such as encryption in transit and at rest) as appropriate, before effecting such transfer.
DPDP Act cross-border transfers. Under Section 16 of the DPDP Act, the Company may transfer Personal Data outside India except to countries or territories specifically restricted by the Central Government by notification. The Company will maintain awareness of, and comply with, any such notified restrictions.
By using the Service and providing Your information, You acknowledge this Policy and the described transfer mechanisms. The Company will take reasonable steps to ensure Your data is treated securely and in accordance with this Privacy Policy, and no transfer will occur without appropriate contractual or other lawful safeguards.

7. Disclosure of Your Personal Data

#

Business Transactions

#
In a merger, acquisition, or asset sale, Your Personal Data may be transferred; We will provide notice before it becomes subject to a different privacy policy.

Law Enforcement

#
We may disclose Your Personal Data where required by law or in response to valid requests by public authorities (e.g., a court or government agency), applying proportionality and, where legally permissible, notifying You.
The Company may disclose Personal Data in the good-faith belief that doing so is necessary to comply with a legal obligation; protect the Company's rights or property; investigate wrongdoing in connection with the Service; protect personal safety of Users or the public; or protect against legal liability.

8. Security of Your Personal Data

#
The security of Your Personal Data is important to Us, but no method of transmission over the internet or electronic storage is 100% secure. We apply commercially reasonable technical and organizational measures — including encryption of Content Data and Personal Data in transit (TLS/SSL) to and from AI Model Providers and Infrastructure Providers, access controls, and encryption at rest where supported by Our Infrastructure Providers — but cannot guarantee absolute security.

9. Detailed Information on the Processing of Your Personal Data

#
Service Providers have access to Your Personal Data only to perform their designated tasks on Our behalf and are contractually obligated not to disclose or use it for any other purpose.

AI Model Providers

#
  • Google LLC — Gemini model APIs, used for translation, content generation, and related AI Features.

Localization Tooling Providers

#
  • Okapi Framework — content extraction, filtering, and translation-quality-assurance tooling used in connection with AI Features.

Infrastructure Providers

#
  • Amazon Web Services, Inc. — cloud hosting, storage, and compute infrastructure.

  • DigitalOcean, LLC — cloud hosting, storage, and compute infrastructure.

Analytics

#
  • Third-party analytics tools (e.g., Google Analytics, Firebase, Matomo, or similar), used to monitor and analyze Service usage via Cookies. See each provider's own privacy policy.

Email Marketing

#
  • Third-party email service providers (e.g., Mailchimp), used to manage marketing communications; You may opt out at any time via the unsubscribe link or by contacting Us.

Payments

#
  • Third-party, PCI-DSS-compliant payment processors handle payment card details directly; the Company does not store full card details.

10. GDPR Privacy

#
The Company processes Personal Data on the following legal bases under Article 6 GDPR:
  • Consent — for one or more specific purposes;

  • Performance of a contract — necessary for an agreement with You or pre-contractual steps;

  • Legal obligations — necessary for compliance with law;

  • Vital interests — necessary to protect Your vital interests or those of another person;

  • Legitimate interests — necessary for the Company's legitimate interests, including operating and securing AI Features, provided such interests are not overridden by Your fundamental rights and freedoms.

10.2 Your Rights under the GDPR

#
Subject to applicable conditions and exceptions, You have the right to:
  • Access Your Personal Data and receive a copy of it;

  • Rectify incomplete or inaccurate Personal Data;

  • Object to processing, including for direct marketing;

  • Request erasure ("right to be forgotten") where there is no overriding lawful ground for continued processing;

  • Request restriction of processing in certain circumstances;

  • Receive Your Personal Data in a structured, commonly used, machine-readable format ("data portability");

  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;

  • Lodge a complaint with a supervisory authority, in particular in the EU/EEA Member State of Your habitual residence, place of work, or place of the alleged infringement.

You may exercise these rights by contacting Us as set out in Section 14 ("Contact Us"). We may request identity verification before responding, and will respond within the timeframes required by Article 12 GDPR (generally one month, extendable by two further months for complex requests, with notice to You).

10.3 EU Representative and Data Protection Officer

#
Where the Company is not established in the EU/EEA but offers the Service to, or monitors the behavior of, Data Subjects in the EU/EEA, the Company designates an EU Representative pursuant to Article 27 GDPR:
EU Representative: A C ILANGOVEN, Ailaysa Technologies Pvt Ltd
No.120 (First floor), 23/1, Major Mukund Varadharajan Rd, Ram Nagar South, Chennai, Tamil Nadu 600100, ilangoven@ailaysa.com
Data Protection Officer:A C ILANGOVEN, ilangoven@ailaysa.com

11. CCPA Privacy (California Residents)

#
If You are a California resident, You have the right to:
  • Notice of the categories of Personal Data collected and the purposes of use;

  • Know the categories and specific pieces of Personal Data collected, their sources, and the business purpose for collection or sale;

  • Delete Personal Data collected about You, subject to statutory exceptions;

  • Opt out of the sale of Personal Data — the Company does not sell Personal Data;

  • Non-discrimination for exercising any CCPA right.

To exercise these rights, contact Us using the details in Section 14. We will respond within 45 days of a verifiable request, extendable once by a further 45 days where reasonably necessary.

Do Not Track

#
The Service does not respond to DNT browser signals. You may enable/disable DNT via Your browser preferences; some third-party sites may still track Your activity independently.

12. Your Rights under India's Digital Personal Data Protection Act, 2023

#
As the Company is headquartered in Tamil Nadu, India, processing of Personal Data of Data Principals is governed by the DPDP Act and its rules, to the extent and from the dates such provisions are brought into force. Subject to the DPDP Act and applicable rules, You may have the right to:
  • Obtain a summary of Personal Data being processed and the processing activities undertaken, including the identities of Data Processors with whom Personal Data has been shared;

  • Request correction, completion, updating, and erasure of Your Personal Data, unless retention is necessary for a specified purpose or for compliance with law;

  • Nominate another individual to exercise Your rights in the event of Your death or incapacity;

  • Withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal, though withdrawal may result in the Company being unable to continue providing the relevant AI Feature or Service;

  • Access a readily available means of grievance redressal, register a grievance with the Company, and, if unresolved within the applicable timeline, escalate the complaint to the Data Protection Board of India;

  • Where applicable, exercise rights through a Consent Manager, once such infrastructure is operational and integrated by the Company.

Where the Company relies on Your consent as the basis for processing under the DPDP Act, We will provide an itemized notice, in clear and plain language, describing the Personal Data to be collected and the purpose of processing, and will seek Your free, specific, informed, unconditional, and unambiguous affirmative consent, capable of being as easily withdrawn as given.

Data Breach Notification

#
In the event of a personal data breach, the Company will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDP Act and its rules.

Grievance Officer

#
A C ILANGOVEN, reachable at ilangoven@ailaysa.com.

13. Children's Privacy

#
The Service does not knowingly address, or collect Personal Data from, anyone under the age of 13 (or the relevant minimum age in Your jurisdiction, including any higher age threshold applicable under the DPDP Act for "child" status, currently under 18) without verifiable parental/guardian consent as required by applicable law. If You are a parent or guardian and believe Your child has provided Us with Personal Data without appropriate consent, please contact Us; We will take steps to remove such information from Our servers.
The Company does not knowingly permit minors to submit Content Data to AI Features without appropriate parental/guardian consent, and may limit the collection, use, and storage of information relating to Users between 13 and 18 years of age.
The Service may contain links to third-party websites not operated by Us, including any AI Model Provider's own consumer-facing products. We strongly advise You to review the privacy policy of every site You visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services.

15. Changes to this Privacy Policy

#
We may update this Privacy Policy from time to time, including to reflect changes in the AI technologies, AI Model Providers, Localization Tooling Providers, or Infrastructure Providers We use. We will notify You of changes by posting the updated Privacy Policy on this page and updating the "Effective date" above, and, for material changes, by emailing You and/or posting a prominent notice on the Service prior to the change taking effect. You are advised to review this Privacy Policy periodically.

16. Contact Us

#
If You have questions about this Privacy Policy, or wish to exercise any right described above (including a request for erasure of Your Personal Data or Content Data), You may contact Us:
  • By email: ilangoven@ailaysa.com

  • Grievance Officer (DPDP Act): A C ILANGOVEN, ilangoven@ailaysa.com

  • EU Representative (Article 27 GDPR): A C ILANGOVEN, ilangoven@ailaysa.com

  • Data Protection Officer (if appointed): A C ILANGOVEN, ilangoven@ailaysa.com

Legal & Compliance Inquiries

For questions regarding this Ailaysa - Privacy Policy, data protection rights under GDPR/CCPA, or contract terms, please contact our designated legal representatives:

support@ailaysa.com•Ailaysa Technologies Private Limited•Visit Help Center