Legal

Privacy Policy

Last updated August 9, 2026

This privacy notice for Sahodaya International Company ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you visit our website at https://impactex.app, or any website of ours that links to this privacy notice. This notice is written to meet India's Digital Personal Data Protection Act, 2023 ("DPDPA"), and also describes rights available to users in the EEA, UK, and other regions.

Summary of Key Points

This summary provides key points from our privacy notice. You can find out more details about any of these topics by reading the full section below.

  • What personal information do we process? Account details (name, email, password), business/billing data, the trade documents and contacts you create, and technical/usage data. See Section 1.
  • Do we process any sensitive personal information? We do not intentionally collect DPDPA-defined sensitive categories such as health data, biometric data, or financial account credentials. Your trade documents may contain confidential business information — see Section 1.
  • What is our lawful basis for processing? Consent, contractual necessity (to provide the Services you signed up for), and legal obligation. See Section 2.
  • Do we share information with AI or other third parties? Yes — when you use AI-assisted features, relevant text is sent to our AI provider (Google's Gemini API) to generate a response. We also use infrastructure and processing partners listed in the table in Section 4.
  • How do we keep your information safe? We have technical and organizational safeguards in place — see Section 8 and our Security page.
  • What are your rights? Access, correction, erasure, consent withdrawal, nomination, and grievance redressal under DPDPA, plus additional rights for EEA/UK users. See Section 10.

1. What Information Do We Collect?

Personal information you disclose to us: We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us. This includes: names, email addresses, phone numbers, usernames, passwords, and billing data (billing name, billing address, and — where applicable — GST details; card and payment instrument numbers are collected directly by our payment processor, not by us — see Section 7).

Business & trade content: When you use the Services, you create and upload content such as trade documents, orders, buyer/seller contacts, product descriptions, logos, and signatures. This content may include confidential commercial information (e.g., pricing, counterparty details, product specifications). We do not treat this as DPDPA-"sensitive" personal data, but we protect it with the same safeguards described in Section 8, and — as stated on our Security page — we do not use it to train AI models.

Google sign-in data: If you sign in or connect a Google account, Google shares your name, email address, and profile picture with us (Google OAuth 2.0). If you separately connect Gmail (to send documents) or Google Drive (to save documents), we additionally receive the access tokens needed to send email or save files on your behalf via those specific Google APIs. We never see or store your Google password. See Section 4 for the legal basis for this processing.

Sensitive Information: We do not intentionally process DPDPA-defined sensitive categories such as health information, biometric data, or financial account credentials.

Information automatically collected: We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information.

Children's data: The Services are intended for business use by individuals 18 years or older (see Terms of Service, Section 1) and are not directed at children. We do not knowingly collect personal information from anyone under 18. If we learn we have inadvertently collected such information, we will delete it. If you believe a minor has provided us personal information, contact us using the details in Section 15.

2. Lawful Basis & How We Process Your Information

Under the DPDPA, we only process your personal data where we have a valid lawful basis. We rely on the following:

  • Consent: For optional features you actively opt into — e.g., connecting Google Drive or Gmail, using the AI chatbot or AI terms enhancer, or receiving marketing communications. You give consent by taking the affirmative action to enable the feature (e.g., clicking "Connect Google Drive," starting a chat).
  • Contractual necessity: To create your account, authenticate you, generate and store your documents, enforce plan limits, and otherwise deliver the core Services you signed up for under our Terms of Service.
  • Legal obligation: To comply with tax, accounting, grievance-redressal, and other legal requirements applicable to us in India.

We use your personal information for purposes including: account creation and authentication; delivering and operating the Services (including AI-assisted features and HS code validation); responding to support requests; sending administrative and transactional communications; fulfilling and tracking orders you record; security and fraud prevention; and complying with law.

How to give or withdraw consent: Where we rely on your consent, you can withdraw it at any time by: (a) disconnecting the specific integration in your account settings (e.g., disconnecting Google Drive/Gmail); (b) simply not using an optional AI feature; or (c) emailing us at [email protected] with the subject line "Consent Withdrawal," describing what you'd like withdrawn. We will action account-settings changes immediately and email requests within 7 business days. Withdrawing consent does not affect the lawfulness of processing before withdrawal, and may mean the associated optional feature becomes unavailable to you.

3. Do We Use Cookies and Other Tracking Technologies?

We use a limited set of cookies, primarily to keep you signed in and to secure the Services. Specific information about which cookies we use, why, and how you can control them is set out in our Cookie Policy — as explained there, we do not currently use advertising or analytics cookies.

4. When and With Whom Do We Share Your Personal Information?

We do not sell your personal information. We share it only in the following situations, and only to the extent needed for that purpose:

Third PartyPurpose & Data Shared
Cloudflare R2Cloud file storage for your PDFs, logos, and signature files.
CloudinaryImage processing/optimization for logos and uploaded images.
Google OAuth 2.0Sign-in — receives your Google name, email, and profile picture.
Google Gmail & Drive APIsOptional, only if you connect them — send documents by email on your behalf, or save documents to your Drive.
Google Gemini APIPowers the chatbot, AI terms enhancer/translator, and HS code validation tool — receives the text (and, for the chatbot, any images) you submit to those features. See Section 5.
RazorpayPayment processing for paid subscriptions — see Section 7.
Email delivery providerSends transactional email (verification, receipts, notifications) on our behalf.
Business TransfersIf we're involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to this notice.

We require each processor above to protect your information consistent with this notice and to use it only for the purpose we've engaged them for.

5. AI Features & Automated Processing

The chatbot, AI terms enhancer/translator, and HS code validation tool are powered by Google's Gemini API. When you use these features, we send the relevant text (your chat messages, the terms you ask us to enhance or translate, or the product descriptions you submit for HS classification) — and, for the chatbot, any image you attach — to Google's Gemini API to generate a response. The "advanced" HS code validation tier (Pro and Max plans) may also use Google Search grounding to improve accuracy, which can send the product description to Google Search.

We do not use your content to train our own models. We do not control, and are not responsible for, how Google processes data submitted through its API beyond what is described in Google's own terms — see Google's Gemini API Additional Terms of Service for details of their data handling.

No solely automated decisions with legal effect: AI outputs (including HS code suggestions) are suggestions only. Nothing generated by these features is automatically applied to your documents or orders — a human user must actively review and accept the suggestion before it is saved (for example, HS code suggestions are recorded only once you accept them). We do not use these features to make decisions that produce legal or similarly significant effects concerning you.

6. Cross-Border Data Transfers

Some of the processors listed in Section 4 — including Cloudflare, Cloudinary, and Google — operate global infrastructure and may process or store your information outside India (including in the United States or other countries where they or their sub-processors operate). By using the Services, you understand your information may be transferred to, stored, and processed in a country other than your own, including countries that may have different data protection laws than your home jurisdiction. We select processors that maintain appropriate contractual and security safeguards for such transfers, consistent with the DPDPA and (where applicable) the standard contractual clauses framework used for cross-border transfers from the EEA/UK.

7. Payment Information

Paid subscriptions are billed through Razorpay Software Private Limited, a payment aggregator regulated by the Reserve Bank of India (RBI). When you subscribe to a paid plan:

  • Your card, UPI, netbanking, or other payment instrument details are entered directly into Razorpay's interface and are transmitted to and stored by Razorpay, not by us. We never receive, see, or store your full card number, CVV, or UPI PIN.
  • Where you save a payment method for recurring billing, it is tokenized by Razorpay in accordance with RBI's card-on-file tokenization rules — we hold only the token reference, not the underlying card data.
  • Payment data collected for Indian transactions is stored in India in accordance with RBI data localization requirements applicable to payment system data.
  • We receive limited information back from Razorpay to reconcile your subscription — such as payment status, the last four digits of your card (if applicable), and transaction identifiers.
  • Razorpay's own handling of your payment data is governed by Razorpay's Privacy Policy.

8. How Long Do We Keep Your Information?

We keep your account and content data for as long as your account remains active, so we can continue providing the Services to you. If you delete your account or request erasure:

  • We delete or anonymize your personal information and content within 30 days of a verified request, except where retention is required by law.
  • Financial and billing records (invoices, payment records) are retained for the period required under Indian tax and accounting law (currently up to 8 years), as required by the Income Tax Act and Companies Act.
  • Residual copies in encrypted backups are purged on our normal backup rotation, within 90 days of deletion.

Where we have no ongoing legitimate business or legal need to process your personal information, we delete or anonymize it, or — if that isn't immediately possible (e.g., because it sits in a backup archive) — we securely isolate it from further processing until deletion is possible.

9. How Do We Keep Your Information Safe?

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process — see our Security page for detail. These are commercially reasonable measures, not a guarantee: despite our safeguards, no electronic transmission over the Internet or storage technology can be guaranteed 100% secure, so we cannot promise that hackers, cybercriminals, or other unauthorized third parties will never be able to defeat our security and improperly access, collect, or modify your information.

Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.

10. What Are Your Privacy Rights?

Under India's DPDPA, as a data principal you have the right to:

  • Access a summary of the personal data we hold about you and the processing activities we carry out.
  • Correction of inaccurate or incomplete personal data — most account fields can be edited directly in your account settings; for anything else, email us.
  • Erasure of your personal data once it is no longer needed for the purpose it was collected, unless we're required to retain it by law (see Section 8).
  • Grievance redressal — raise a complaint with our Grievance Officer (Section 15). If unresolved, you may escalate to the Data Protection Board of India.
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity, by writing to us with the nominee's details.
  • Withdraw consent at any time where we rely on consent (Section 2).

To exercise access, correction, erasure, or nomination rights, email [email protected] with your request. We verify your identity (typically by confirming the request from your registered account email), and respond within 30 days.

If you are located in the EEA, UK, Switzerland, or Canada, you additionally have rights under applicable local law, which may include the right to: restrict processing; data portability; object to processing; and not be subject to solely automated decision-making. You can exercise these the same way, at the contact above.

Account Information: If you would at any time like to review or change the information in your account or terminate your account, you can log in to your account settings and update your user account, or contact us using the contact information provided.

11. Data Breach Notification

If we become aware of a personal data breach that affects you, we will notify the Data Protection Board of India and affected data principals without undue delay, as required by Section 8(6) of the DPDPA, describing the nature of the breach and the steps we are taking in response.

12. Controls for Do-Not-Track & Global Privacy Control

Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting you can activate to signal a preference not to be tracked online. No uniform technical standard for DNT has been finalized, and we do not currently respond to DNT browser signals.

Some browsers and extensions also send the Global Privacy Control ("GPC") signal, which has started to replace DNT and is treated as a valid opt-out request under some regulations (e.g., California's CPRA). Because we do not currently use advertising or cross-context behavioral-tracking cookies to sell or "share" personal information as those terms are defined under such laws, GPC does not presently change what data we collect. If that changes, we will honor GPC signals where legally required and update this notice.

13. Do We Make Updates to This Notice?

Yes, we will update this notice as necessary to stay compliant with relevant laws. The updated version will be indicated by an updated "Last updated" date at the top of this notice. If we make material changes, we will notify you by prominently posting a notice of the changes or by directly emailing you. We encourage you to review this notice periodically.

14. Enterprise Customers & Data Processing Agreements

If your business requires a Data Processing Agreement (DPA) to govern our processing of personal data on your behalf as a processor, one is available on request — see our Terms of Service, Section 18.

15. Grievance Officer & How to Contact Us

In accordance with the Consumer Protection (E-Commerce) Rules 2020 and the DPDPA 2023, we have appointed a Grievance Officer. If you have questions, complaints, or wish to exercise any right described above, contact:

Grievance Officer

Sahodaya International Company

Eluru, Andhra Pradesh 534001, India

Phone: (+91) 9701696996

Email: [email protected]

We acknowledge complaints within 48 hours and aim to resolve them within 30 days.