Privacy notice

What we do with your data

Written to the standard we ask of our own clients — itemised, in plain language, and specific about which law allows what.

Start here

We stand in three different positions

Which one you are in decides who answers to you, and the Act treats them differently. Almost every privacy notice blurs these together; this one does not.

You visited this website

You read a page, sent an enquiry, or took the free Scorecard. We are the Data Fiduciary — we decide why and how that information is used, and everything below applies to you directly.

You use RuleExpert at work

Your employer bought the platform and you have a login. We are the Data Fiduciary for your account details — name, work email, what you did in the product — because we decide what an account needs in order to work.

Your data is inside a customer’s account

A hospital or company you deal with uses RuleExpert. They are the Data Fiduciary and we are their Processor under Section 8(2). We act on their instructions only. Your rights run against them, and we help them answer you.

If you are in the third group and you came here looking for someone to ask, ask the organisation that holds your records. If they use RuleExpert, they can answer you faster because of it — but the duty is theirs, and we cannot lawfully act on your data without their instruction.

Itemised

What we collect, and what allows it

The DPDP Act has no “legitimate interests” and no contract basis. Everything below rests on either your consent under Section 6 or a legitimate use under Section 7, and each row says which.

WhenWhatWhyWhat allows it
You send an enquiry Name, organisation, work email, phone and message if given, and which parts of RuleExpert you asked about To reply and arrange the demo or consultation you asked for Section 7(a) — you handed it to us for exactly that purpose. We do not ask consent we do not need.
You tick the marketing box The same contact details Occasional DPDP updates and news about what we offer Section 6 consent — separate, optional, never pre-ticked, withdrawable at any time.
You take the free Scorecard Work email, your answers, and the score derived from them To verify the email, produce your result, and let you return to it Section 7(a). The answers are yours; we use them to score, not to profile you.
You have a platform login Name, work email, role, and a record of significant actions in the product To run the account, and because the audit trail is itself a compliance obligation Section 7(a), plus the record-keeping the Act requires of your employer.
You visit any page Standard server logs — IP address, page, time Keeping the site up and secure Section 7(a), kept short and never used to build a profile.
Cookies

Cookies, analytics and advertising measurement

This site uses cookies that keep it working and secure, and third-party tools — Google Analytics and Google’s advertising measurement among them — that tell us how pages are found and used and whether a campaign led to an enquiry. Those tools set their own identifiers and receive your IP address, and they are operated by Google, which processes outside India. That is a cross-border transfer under Section 16, made under Google’s data processing terms, which we have accepted.

Two things worth being straight about, because published notices in India get this wrong in both directions. There is no Indian cookie statute and no equivalent of the EU ePrivacy rules, so nobody here is legally required to show you a cookie banner — any page claiming otherwise is repeating European law. But an analytics identifier is still personal data, so the DPDP Act applies to it on its own terms, which is why it is disclosed here rather than treated as outside the rules.

You can clear or block cookies in your browser, and Google publishes its own opt-out for Analytics. The map on our contact page is the one thing we hold back by default: it stays a placeholder until you press “Load the map”, because loading it silently would hand Google your IP before you had asked for anything.

Writing your own notice, and finding this harder than expected?

That is the usual experience. The Act names a notice, not a policy, and the two do different jobs — which is most of why so many published ones do not work.

Who else sees it

Sharing, and where it sits

Who we share with

  • The service providers who run our hosting, email and business systems, under contract and on our instructions only
  • Professional advisers where we are obliged to take advice
  • Anyone a law or a lawful order requires us to tell

What we never do

  • Sell your data, to anyone, for anything
  • Share it for somebody else’s marketing
  • Use a customer’s data to train models — ours or anyone’s

The platform and its backups are hosted in India, deliberately. Two business tools are not: our email is sent through Mailgun on its United States region, and our analytics and advertising measurement run on Google, which processes globally. Both are cross-border transfers, both are covered by data processing agreements we hold, and both are permitted — Section 16 restricts transfer only to countries the Central Government notifies, and none are currently notified. Section 16(2) also preserves any other law setting a higher standard, so where a sector rule requires stricter localisation than the Act, that rule still governs.

How long

We delete things on a schedule

Section 8(7) says personal data goes once the purpose is served, unless a law requires it kept. These are the periods we hold ourselves to.

Enquiries

24 months from your last contact with us, then deleted.

Marketing consent

Until you withdraw it. Withdrawal is one line to us, or the unsubscribe link in any message.

Scorecard results

24 months, so you can come back to your result and compare a later one.

Customer account data is kept for the life of the contract and a defined period after it, set in the agreement. Data our customers put into the platform is deleted on their instruction — it is theirs, not ours.

Sections 11 to 14

Your rights, and how to use them

One address for all of them: tushar@ruleexpert.com. We answer within 90 days, which is the window Rule 14(3) sets, and usually far sooner.

Ask what we hold — Section 11

A summary of your personal data, what we are doing with it, and who else we have shared it with.

Correct or erase it — Section 12

Correction, completion, updating and erasure. Section 12(1) expressly covers information given under Section 7(a), so it applies to everything in the table above.

Withdraw consent — Section 6(4)

As easy to withdraw as it was to give. It stops future processing; it does not undo what was lawful before.

Nominate someone — Section 14

Name a person to exercise these rights for you if you die or become incapable of acting.

Section 13

If we get it wrong

Tell us first. The Act gives you a right to a readily available means of complaint, and under Section 13(3) the Data Protection Board expects you to have used ours before coming to it.

We acknowledge quickly and answer within 90 days. If we cannot fix it, we say so plainly rather than running out the clock — and we tell you what your next step is.

Grievance contact

Tushar
tushar@ruleexpert.com
+91 95408 17775

Expertinasia Pvt. Ltd., 302 Shagun Arcade, Vijay Nagar, Indore, Madhya Pradesh 452010.

Still unhappy, you may complain to the Data Protection Board of India. We would rather you did not need to, and we would rather you had a real answer from us first.

Children — Section 9

Nothing we run is aimed at children, and we do not knowingly collect their data through this website. If you believe a child’s data has reached us, write to the address above and we will delete it. Where our customers process children’s data in the platform, verifiable parental consent is their obligation and the product is built to record it.

Security — Section 8(5)

Reasonable security safeguards, as Section 8(5) requires and Rule 6 describes. Concretely: HTTPS on everything, credentials and other sensitive fields encrypted at rest, access limited by role to the people who need it, and an audit log the database itself refuses to update or delete — so a record of what happened cannot be quietly rewritten, including by us. Section 8(6) sets no materiality threshold: a breach is reportable whether or not we think it serious.

Questions

The ones people actually ask

I am a patient at a hospital that uses RuleExpert. Who do I ask?

The hospital. They decided to collect your data and why, which makes them the Data Fiduciary; we run software for them and act only on their instructions, which makes us a Processor under Section 8(2). Your rights under Sections 11 to 14 run against them. Ask them, and if they use the product properly they can answer you faster and more completely than they could without it. If they ignore you, your route is their grievance process and then the Board — not us.

Do you use my data to train AI?

No. Not yours, not our customers’, not the data inside anyone’s account. The AI modules we are building read the metadata a customer’s own registry holds — system names, categories, purposes — and they are not trained on customer content. If that ever changes it will be stated on its own page, in advance, and it will be a choice you make rather than one you discover.

You say Section 7(a) rather than consent. Why?

Because it is accurate, and asking for consent we do not need would be theatre. Section 7(a) covers personal data you voluntarily provide for a specified purpose without objecting to its use for that purpose — which is exactly what sending an enquiry is. Consent under Section 6 is reserved here for the thing that genuinely needs it: marketing. A notice that claims consent for everything trains people to click past it, which is how consent stops meaning anything.

Is my data kept in India?

The platform and its backups are, deliberately — a commitment rather than a coincidence. Two things are not: email goes through Mailgun’s United States region, and analytics runs on Google, which processes globally. Both sit under data processing agreements, and both are lawful: Section 16 restricts transfers only to countries the Central Government has notified, and it has notified none. We would rather name the two exceptions than claim a blanket residency that no company sending email can honestly promise — and if a sector rule binds you to something stricter, Section 16(2) keeps that rule in force.

Can I get a copy of what you hold on me?

Yes — write to tushar@ruleexpert.com. We will confirm who you are first, because handing your data to somebody claiming to be you would be its own breach, and we keep that verification proportionate rather than obstructive. Answer within 90 days under Rule 14(3), and in practice much sooner.

Will this notice change?

Yes, when what we do changes — and the date at the top moves when it does. If a change affects something you consented to, we will not treat silence as agreement: we will ask again. That is what Section 6 requires, and it is also the only version of this that is worth anything to you.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Questions about any of this

Ask us. A question about our own privacy practice gets the same answer a client’s DPO would get, from the same person.