1. Overview
AISOLO Technologies Private Limited ("AISOLO", "we", "us") operates explainx.aiand is incorporated under the laws of India. India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 use phased commencement dates. Some institutional provisions are already in force, while the principal notice, consent, Data Fiduciary duty, and Data Principal right provisions are scheduled to commence later.
This page explains our current practices, how we are preparing for the DPDP framework, the rights that will apply when the relevant provisions commence, and how to contact us now. This page should be read together with our full Privacy Policy.
We apply provisions as they come into force and update our processes as implementation dates arrive. Until then, we use the Act's transparency, purpose-limitation, minimisation, security, and accountability principles where practicable without representing that a future statutory process is already operational.
2. Who is the Data Fiduciary?
For the purposes of the DPDP Act, the Data Fiduciary is:
AISOLO Technologies Private Limited
1003, Kamdhenu Commerz, Sector 14, Kharghar
Navi Mumbai 410210, Maharashtra, India
Email: [email protected]
3. Personal data we process
We process personal data as described in our Privacy Policy (Section 2). Key categories include:
- Account data: Email address, name, authentication information.
- Transaction data: Payment amounts, order records (card details are processed by Stripe and not stored by us).
- Usage data: Pages visited, features used, analytics events (PostHog).
- Communications: Newsletter subscriptions (only with consent), support correspondence.
- User-submitted content: Skills, descriptions, and metadata submitted for the public registry.
- Learning and AI data: Course and Workshop activity, attendance, recording contributions, Melo prompts and saved conversations, selected learning sources, and files submitted for a current AI request.
The DPDP Act defines digital personal data broadly and does not create a separate statutory category called "sensitive personal data." Some information can nevertheless be particularly sensitive or regulated under other laws. Our Services are not designed for health records, biometrics, government identifiers, financial credentials, caste or religious information, or similar high-risk material; please do not place such information in Melo prompts, uploads, public listings, or class chat unless a feature expressly requests it and you have a lawful reason to provide it.
4. Grounds for processing (consent and legitimate uses)
When the relevant DPDP Act provisions commence, personal data may be processed on the basis of validconsent or for one of the specific certain legitimate useslisted in Section 7 of the Act. General contract performance and a business's "legitimate interest" are not standalone Section 7 categories merely because they are convenient for a service.
- Consent: Where we request your consent (e.g. for marketing newsletters, analytics cookies where required), we will do so with a clear, plain-language notice and obtain your explicit agreement. You may withdraw consent at any time.
- Requested Services: We use account, transaction, learning, and support information to provide features you deliberately request, such as account access, Melo, payments, Workshops, recordings, Courses, and Memberships. We provide notice and seek consent where the DPDP Act requires it once the relevant provisions apply.
- Legal obligation: We may process data where required by Indian law, including tax records, regulatory requirements, and responses to lawful government requests.
- Certain legitimate uses: We rely on a Section 7 use only where the facts fit that specific statutory category, such as a voluntary provision of data for a stated purpose or compliance with a legal obligation. Security, fraud prevention, and analytics are also limited to what applicable law permits and what is reasonably necessary.
We will not use your personal data for purposes incompatible with those for which it was originally collected without obtaining fresh consent or identifying a new legitimate ground.
5. Notice at collection
We provide notice of data collection at the point of collection — at account registration, newsletter signup, checkout, and other data-collection touchpoints. This notice includes:
- What personal data is being collected.
- The purpose for which it is being processed.
- How to exercise your rights as a Data Principal.
Our Privacy Policy serves as a consolidated notice document.
6. Your rights as a Data Principal
Sections 11–14 of the DPDP Act describe the following rights. Under the Government's phased commencement notification, these provisions are scheduled to take effect later. We nevertheless accept similar requests now as a matter of our current privacy practice, subject to identity verification, technical feasibility, and other applicable law.
6.1 Right to access information (Section 11)
You may request a summary of the personal data we process about you and information about the Data Processors with whom we have shared your data.
6.2 Right to correction and erasure (Section 12)
You may request correction of inaccurate or incomplete personal data. You may also request erasure of personal data where it is no longer necessary for the purpose for which it was collected, or where you have withdrawn consent and there is no other ground for processing. We may retain data required by law (e.g. billing records) even after an erasure request.
6.3 Right to grievance redressal (Section 13)
If you believe we have not complied with the Act in processing your personal data, you may raise a grievance with us. Applicable procedures and timelines will follow the Act and Rules when the relevant provisions commence. The Data Protection Board of India has been established; escalation rights become available in accordance with the operative statutory framework.
6.4 Right to nominate (Section 14)
You may nominate another individual to exercise your data rights on your behalf in the event of your death or incapacity. Contact us at [email protected] to submit a nomination.
How to exercise your rights
Email [email protected] with the subject "DPDP Rights Request — [right type]". Include your name, registered email address, and the nature of your request. We will respond within a reasonable period and within any statutory timeframe that is in force and applicable. We may ask you to verify your identity before processing your request.
7. Our duties as a Data Fiduciary
We use the following practices now and will apply the corresponding statutory duties when the relevant DPDP Act and Rules provisions commence:
- Purpose limitation: Processing personal data only for the purposes notified at collection or for which consent was given.
- Data minimisation: Collecting only the personal data necessary for the stated purpose.
- Accuracy: Ensuring that personal data is accurate and up to date, particularly where it is used to make decisions that affect you.
- Storage limitation: Not retaining personal data beyond the period necessary for the purpose for which it was collected, subject to legal retention requirements.
- Security safeguards: Implementing reasonable technical and organisational measures to prevent personal data breaches.
- Breach notification: Notifying the Data Protection Board and affected Data Principals of any personal data breach in the manner prescribed by the Act and applicable rules.
8. Data Processors we use
We engage third-party service providers ("Data Processors") to process personal data on our behalf. Key processors include Stripe (payments), Vercel (hosting), PostHog (analytics), OpenAI (AI inference, including Melo), and Google/GitHub (OAuth). Depending on the feature, processors may also include email, video, storage, security, and workshop-delivery providers. We require processors to process data only on our instructions and in accordance with applicable law. A full list is in our Privacy Policy and GDPR page.
9. Cross-border transfers
Some of our Data Processors are located outside India. When the DPDP Act's transfer provision commences, it allows the Central Government to restrict transfers to specified countries or territories, and stricter requirements under another applicable Indian law may still govern particular data. We use contractual, security, and minimisation measures for current cross-border processing and will comply with restrictions that are in force and applicable.
10. Grievance Officer
For DPDP Act grievances and requests, contact our designated point of contact:
Name: Yash Thakker
Organisation: AISOLO Technologies Private Limited
Email: [email protected]
Address: 1003, Kamdhenu Commerz, Sector 14, Kharghar, Navi Mumbai 410210, Maharashtra, India
We aim to respond within a reasonable period and will follow any mandatory acknowledgement, response, and escalation timelines that are in force and applicable.