Legal Last updated 21 August 2026

Privacy Policy

Simple, plain-language explanation of what data we collect, why, and what rights you have - written for both our India and US customers.

ISO 27001:2022 · Certified securityEnd-to-end encrypted · In transit and at restWe never sell data · Not to anyone, everDPDPA + CCPA ready · India and US coverage

Introduction

Dedups.ai ("Dedups", "we", "us") builds a cloud security and cost optimization platform. This policy explains, in plain language, what personal data we collect, why we collect it, how we protect it, and what choices you have.

This policy applies wherever you are, and specifically covers two laws we take seriously: the Digital Personal Data Protection Act, 2023 (DPDPA) in India, and US state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA). If a term in this policy conflicts with a right you have under your local law, your local law wins.

Dedups.ai is currently operated by an India-registered entity. If we open a separate US entity in the future, we will update this policy and tell you where your data is then held.

Dedups is a B2B service built for companies, not the general public. We work with corporates and organizations, and the people who use our platform on their behalf are expected to be adults who are legally eligible to work and are acting for their employer. See "Children's Privacy" below for more on this.

Information We Collect

We collect the following categories of personal data:

CategoryWhat it covers
Identity dataName, username, or similar identifier
Contact dataEmail address, phone number, and business address
Account dataLogin credentials, company name, and billing details
Technical dataIP address, browser type, device information, and time zone
Usage dataHow you click through and use our website and dashboard
Cloud infrastructure dataAWS/Azure account info, resource metadata, security findings, and cost data that you connect to our platform

We collect this data directly from you (when you sign up, fill a form, or contact us), automatically (as you use our website and dashboard), and from the cloud accounts you choose to connect to our platform.

How We Use Your Information

Your data helps us deliver and improve our services. We use it to:

  • Provide and run our cloud security and cost optimization services
  • Tell you about changes to our service
  • Give you customer support and answer your questions
  • Understand how people use our platform, so we can improve it
  • Keep the service running and catch problems early
  • Detect and stop misuse, fraud, or security issues
  • Meet our legal and regulatory obligations

AI Processing

Some parts of Dedups use AI to help you work faster - for example, our AI Scrum Master feature, which drafts replies to follow-up tickets, and our remediation engine, which suggests fixes for security findings.

To do this, relevant text (such as a support ticket message or a security finding description) is sent to OpenAI, our AI provider, to generate a response or suggestion. We only send what is needed for that specific task. OpenAI processes this data under its own API terms and does not use API data to train its models.

If you would rather not use AI-assisted features, most of them can be turned off - contact us and we will help.

Where We Store Your Data

By default, your data is stored on AWS servers located in India (Mumbai region). For enterprise customers who need their data to stay in a specific country or region, we offer custom deployments in a location of your choice - contact your account manager to arrange this.

As we grow, we plan to offer region-specific hosting (for example, a dedicated US deployment) so customers can keep data closer to home by default. We will update this policy when that becomes available.

Data Sharing and Disclosure

We only share data when it is necessary. The parties we may share it with are below - see our full Sub-processors & DPA page for details and to request a signed Data Processing Agreement.

PartyWhy
Service providersAWS, Microsoft Azure, payment processors, and other vendors we need to run the service
AI providersOpenAI, used to generate remediation suggestions and automate parts of our AI Scrum Master feature - see "AI Processing" below
Legal requirementsWhen the law requires it, or in response to a valid request from a court or government authority
Business transfersIf we are ever part of a merger, acquisition, or sale of assets, your data may transfer as part of that deal

We never sell your personal data, and we do not use advertising trackers (like ad pixels) that share your data for marketing purposes. Full stop.

Data Retention

We keep your personal data only for as long as we need it to provide the service you signed up for, or to meet legal, accounting, or reporting obligations. Once we no longer need it, we securely delete it.

As a concrete cap: if your account is closed, or a support/follow-up ticket is closed, we retain the related personal data for up to 3 years from the closure date, and then delete it - unless the law requires us to keep it longer, or you ask us to delete it sooner (see "Requesting Deletion" below).

Requesting Deletion

You can ask us to delete your personal data at any time by emailing privacy@dedups.ai from your account's registered email address. We ask that you email from that address (or be ready to confirm your identity via it) so that we only act on a deletion request from the account holder, not from someone impersonating them.

We do not offer an instant self-service "delete my account" button. This is a deliberate choice: an automated, one-click deletion path is also a one-click target for account takeover or abuse, and the safer trade-off is a short human-reviewed step before anything is permanently removed.

Once we receive your request, we will acknowledge it within 3 business days and complete the deletion within 30 days, except for data we're legally required to keep longer (for example, billing records we must retain for tax purposes). We will confirm once the deletion is complete.

Data Security

ISO 27001:2022 We are ISO 27001:2022 certified, which means our information security practices have been independently checked against a recognized international standard.

All data is encrypted in transit and at rest. We use industry-standard access controls and run regular security reviews. No system is 100% risk-free, but we work hard to keep your data safe and we tell you what to do if something goes wrong (see "Data Breach Notification" below).

Your Rights (India / DPDPA)

If you are in India, the Digital Personal Data Protection Act, 2023 gives you these rights. To use any of them, contact our Grievance Officer, Gaurav Sharma, at dpo@dedups.ai. For erasure requests specifically, see Requesting Deletion below for how we handle it and our response timeline.

Access

Ask for a copy of the personal data we hold about you

Correction

Ask us to fix data that is wrong or incomplete

Erasure

Ask us to delete your personal data

Grievance redress

Raise a complaint with us, and escalate to the Data Protection Board of India if unresolved

Nominate

Name someone to exercise your rights on your behalf if you are unable to (e.g. in case of death or incapacity)

Withdraw consent

Take back any consent you gave us, at any time, as easily as you gave it

Your Rights (US / CCPA)

If you are a resident of California or another US state with a privacy law, you have these rights over your personal data. To use any of them, email privacy@dedups.ai.

Know

Ask what personal data we have collected about you and why

Delete

Ask us to delete personal data we hold about you

Correct

Ask us to fix inaccurate personal data

Opt out

We do not sell or share data for advertising, so there is nothing to opt out of - but you can still ask

Non-discrimination

We will not treat you differently or deny service for exercising any of these rights

We do not sell or share personal data for cross-context behavioral advertising, so there are no "Do Not Sell or Share My Personal Information" or Global Privacy Control opt-outs needed - we simply don't do it.

Cookies

We use cookies and similar technology to keep you logged in and keep the platform secure. We do not use cookies for advertising. You can turn off cookies in your browser at any time, though some parts of the site may not work properly if you do. For the full list of cookies we use and your choices, see our Cookie Policy.

Children's Privacy

Dedups is a business-to-business (B2B) service, not a consumer product. We only do business with companies and organizations, and the individuals who use our platform on their behalf must be adults who are legally eligible to work and are using Dedups in a professional capacity for their employer.

Dedups is not directed at, marketed to, or intended for use by children. We do not knowingly collect personal data from anyone under 18. If we learn that a child has provided us personal data, we will delete it. If you believe this has happened, contact us at privacy@dedups.ai.

Data Breach Notification

If a data breach happens that affects your personal data, we will notify affected users and, where required by law, the relevant regulator (including the Data Protection Board of India under the DPDPA) without undue delay. We will tell you what happened, what data was involved, and what steps we and you should take.

Changes to This Policy

We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify you by email or through a notice on our platform before the change takes effect.

Contact Us

Have a question about this policy, or want to exercise your data rights? Reach out and we will get back to you promptly.