Privacy Policy

Last updated: 17 April 2026 · Vedintel™ AstroAPI · A CoMo® Workshops Company

Data handled with privacy and precision – fully GDPR + DPDP compliant.

1. Who We Are

VedIntelAstroAPI is a Vedic astrology computation API service operated by CoMo® Workshops ("we," "us," or "our"). Our service is accessible at www.vedintelastroapi.com.

We are committed to protecting the personal data of our users, developers, and their end-users in accordance with the General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act (DPDP) 2023.

For privacy-related queries, contact us at: support@predintel.zohodesk.in

2. Data We Collect

Account Data: When you register, we collect your name, email address, and password (hashed). For paid plans, we collect billing information processed securely through Razorpay — we do not store raw card or bank details.

API Usage Data: We log API requests including endpoint called, timestamp, API key used, response time, and HTTP status code. We do not log the full request payload beyond what is necessary for billing and debugging.

Birth Data: Birth data (date of birth, time of birth, coordinates) submitted through API requests is used solely to compute astrological output. We cache computed natal charts in our Supabase database using a one-way SHA-256 hash as the cache key. This data is never sold or shared with third parties.

Technical Data: IP addresses, browser type, device identifiers, and session data collected automatically for security and performance monitoring.

Communications: Any messages sent through our contact form or support system.

3. How We Use Your Data

  • Providing and improving the VedIntelAstroAPI service
  • Authentication and account management
  • Billing and subscription management via Razorpay
  • API rate limiting and quota enforcement
  • Sending transactional emails (account alerts, usage warnings, invoices)
  • Security monitoring and fraud prevention
  • Legal compliance and dispute resolution

We do not use your data for advertising, profiling, or selling to third parties.

4. Legal Basis for Processing (GDPR)

We process personal data under the following legal bases:

  • Contract performance — to provide the API service you subscribed to
  • Legitimate interests — security monitoring, fraud prevention, service improvement
  • Legal obligation — tax records, compliance with court orders
  • Consent — marketing communications (you can opt out at any time)

5. Data Retention

Account data is retained for as long as your account is active. If you delete your account, personal data is purged within 30 days, except where we are required to retain it for legal purposes (e.g., billing records for 7 years as required by Indian tax law).

Cached natal charts (stored by birth data hash) are retained indefinitely as they do not contain personally identifiable information.

API usage logs are retained for 12 months.

6. Data Sharing

We share data only with:

  • Supabase — database and authentication infrastructure
  • Razorpay — payment processing (PCI-DSS compliant)
  • Vercel — hosting and deployment infrastructure
  • Anthropic — AI narrative generation (Phase 3, when you use /ai/ endpoints)

All sub-processors are contractually bound to process data only as directed and in compliance with applicable data protection laws. We do not sell personal data.

7. International Data Transfers

Our infrastructure providers (Supabase, Vercel, Anthropic) may process data in the United States and European Union. Where data is transferred outside India or the EU, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) under GDPR.

8. Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Access — request a copy of your personal data
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your personal data ("right to be forgotten")
  • Portability — receive your data in a machine-readable format
  • Restriction — request restriction of processing in certain circumstances
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — at any time for consent-based processing

To exercise any of these rights, email support@predintel.zohodesk.in. We will respond within 30 days.

9. Cookies

We use strictly necessary cookies for authentication (session tokens). We do not use tracking, advertising, or analytics cookies. Our dashboard uses localStorage for theme preference only.

10. Security

We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, API key hashing, and regular security audits. Access to production databases is restricted to authorised personnel only.

11. DPDP Compliance (India)

In compliance with India's Digital Personal Data Protection Act 2023:

  • We process personal data only for lawful purposes with your consent or for legitimate use cases
  • We appoint a Data Fiduciary responsible for ensuring compliance
  • Children's data (under 18) is not knowingly collected without verifiable parental consent
  • Data breach notifications will be issued to affected users within 72 hours of discovery

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users by email for material changes. Continued use of the service after changes constitutes acceptance.

13. Contact

For privacy-related requests or complaints:

Email: support@predintel.zohodesk.in
Company: CoMo® Workshops
Website: www.vedintelastroapi.com

If you are in the EU, you have the right to lodge a complaint with your local Data Protection Authority.