Privacy Policy
Last updated: August 2026 · Compliant with the Digital Personal Data Protection (DPDP) Act 2023, Information Technology Act 2000, and Global Enterprise Security Standards.
1. Overview & Commitment
Sevikr Technologies ("Company", "we", "us", or "our"), the operator of Sevikr Scan (accessible at scan.sevikr.com and sevikr.com), is committed to safeguarding the privacy, confidentiality, and security of our users and enterprise customers.
This Privacy Policy outlines the specific types of data we collect, how it is processed strictly for document extraction, the cryptographic safeguards in place, and your rights regarding data access, retention, and deletion.
2. Information We Collect
We adhere to the principle of strict data minimization. We collect only the data necessary to provide and bill for our automated document extraction services:
- Account Identity Data: Full name, registered business email address, company name, and cryptographically hashed authentication credentials managed via Supabase Auth.
- Billing & Transaction Metadata: Razorpay transaction references, order IDs, invoice identifiers, and GST numbers (if provided). We never store credit card numbers, debit card PINs, CVVs, or raw banking credentials; all payment transactions are tokenized and processed directly by Razorpay under PCI-DSS Level 1 certification.
- Uploaded Documents & Payloads: PDF files, images (PNG, JPG), TIFF scans, and Excel/CSV spreadsheets uploaded solely for automated optical and AI data extraction.
- Technical Usage Logs: IP address, browser type, job processing timestamps, and credit consumption telemetry for rate limiting, security monitoring, and fraud prevention.
3. Purpose of Processing & Zero AI Training Guarantee
Your uploaded documents are processed exclusively to execute your requested extraction jobs, perform mathematical validation proofs (Qty × Rate = Total), and generate your structured export datasets (XLSX, CSV, PDF, JSON).
We strictly enforce zero-retention enterprise agreements with foundational AI providers (Google Gemini & DeepSeek). Your uploaded business invoices, contracts, and proprietary data are never used to train, retrain, or fine-tune public AI models.
Every database query enforces strict multi-tenant Row Level Security (RLS). Extraction results, templates, and credit balances belonging to your account are completely isolated and inaccessible to any other user or organization.
4. Cryptographic Security & Infrastructure Safeguards
We implement defense-in-depth security measures to protect your documents against unauthorized access, loss, or alteration:
- Encryption in Transit: All web traffic and API calls are strictly encrypted using TLS 1.3 / SSL with HSTS (HTTP Strict Transport Security) preloaded.
- Encryption at Rest: Database records and file storage are protected with AES-256 encryption.
- Payment HMAC Signatures: All checkout callbacks require cryptographic SHA-256 HMAC verification to prevent payment spoofing or replay attacks.
- No Third-Party Advertising Trackers: We do not sell, rent, or monetize your personal or business data to third-party ad networks or data brokers.
5. Data Retention & User Erasure Rights
You have full authority over your data lifecycle:
- Extraction Results Retention: Extracted datasets remain available in your secure workspace dashboard for as long as your account remains active, or until manually deleted by you.
- Right to Erasure (One-Click Deletion): You may delete individual extractions, projects, or request complete account and data erasure at any time by contacting our privacy desk. Upon verification, all associated files and records will be permanently expunged from active databases within 48 business hours.
6. Third-Party Service Providers
We partner with verified, enterprise-grade service providers who process data strictly under our direct instruction and confidentiality covenants:
- Database & Authentication: Supabase Inc. (SOC-2 Type II compliant).
- Payment Gateway: Razorpay Software Private Limited (PCI-DSS Level 1 certified).
- AI Inference APIs: Google Cloud Platform Vertex AI & DeepSeek (Enterprise Zero-Data-Retention endpoints).
7. Privacy Grievance Officer & Contact Information
In accordance with the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023, for any privacy inquiries, data subject access requests, or security concerns, you may contact our designated Grievance Desk:
Legal Entity: Sevikr Technologies
Brand / Platform: Sevikr Scan (scan.sevikr.com)
Primary Support Email: hello@sevikr.com
Escalation / Legal Desk: sevikr.contact@gmail.com
Phone / WhatsApp Support: +91 82472 83972
Registered Address: Gachibowli, Hyderabad, Telangana, India, 500032
