Legal

Privacy Policy

Effective 12 July 2026

Roles

Rashi Technologies operates RaksHex from Bengaluru, India. We act as controller or data fiduciary for our website, account, billing, security, and sales data. For Customer Data in a workspace, the Customer controls the purpose and RaksHex acts as a processor or service provider under the applicable DPA.

Data we handle

This can include account and authentication data, workspace settings, masked discovery findings, subscription and seat records, audit events, usage and latency metadata, billing references, support messages, and encrypted credential material. We do not store card details.

Prompt and credential boundaries

Discovery is designed to send masked metadata and fingerprints rather than secret values. Raw prompts are not retained by default in hosted audit records. Gateway controls may process prompts transiently for policy evaluation, redaction, and routing. Customer configuration and connected providers affect processing.

Retention and sharing

We retain data only for service, security, billing, legal, and support purposes. The default schedule covers 180-day security logs, 13-month audit metadata, rolling backups, and Customer-configurable enterprise retention. We use limited service providers and disclose the current categories in the Subprocessor Register.

Your rights

Depending on applicable law, you may request access, correction, deletion, export, restriction, objection, withdrawal of consent, or grievance redressal. Email privacy@rakshex.in from your account address. Workspace-controlled requests may need to be handled by the Customer administrator.

Security and contact

We use access controls, encryption measures, audit logging, rate limits, and incident response processes designed for the Service. To report a vulnerability, email security@rakshex.in. For privacy questions or requests, email privacy@rakshex.in.

Read the detailed policy, Data Processing Addendum, retention schedule, and subprocessor register in the RaksHex Legal Center.