Data Processing Agreement
Last updated 27 June 2026.
This Data Processing Agreement (“DPA”) applies when you use Ruhu AI to process personal data belonging to your own clients — for example, a chartered accountant analysing a client's ledgers, invoices or returns. It forms part of, and is governed by, the Terms of Service and Privacy Policy. It is written to support compliance with the UAE Personal Data Protection Law (PDPL) and India's Digital Personal Data Protection Act (DPDP Act).
1. Roles
For personal data about your clients that you put into Ruhu AI, you are the data controller and Ruhu AI is the data processor. We process that data only to provide the service to you, and only on your instructions (which your use of the product expresses). For your own account data, Ruhu AI is the controller — see the Privacy Policy.
2. Our obligations as processor
- Process personal data only to deliver the service and on your documented instructions.
- Keep it confidential and limit access to personnel who need it.
- Apply the security measures described below.
- Engage sub-processors only under equivalent obligations, and tell you before adding new ones.
- Assist you, so far as practical, with data-subject requests and your own compliance duties.
- Delete or return the data on deletion or termination, as set out below.
3. Sub-processors
To deliver the service we use the following sub-processors. AI providers process your content only to generate a response and, under their API terms, do not use it to train their models. The exact AI provider for a given message depends on the model you choose or that Ruhu routes to.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google (Gemini) | AI responses & Google sign-in | USA |
| OpenAI | AI analysis & file/code processing | USA |
| Anthropic (Claude) | AI responses (premium models) | USA |
| DeepSeek | AI responses (default model) | China |
| Z.ai (GLM) | AI responses (optional model) | China |
| Tavily | Live web search (when used) | USA |
| Neon | Database (encrypted Postgres) | Singapore |
| Vercel | Application hosting | Singapore |
4. Security measures
- Data is encrypted in transit (TLS) and stored in a managed Postgres database.
- For regions with stricter rules (UAE PDPL, India DPDP Act), typed identifiers — TRN, Emirates ID, GSTIN, PAN, IBAN, email and similar — are masked before any text is sent to an AI provider, and restored only in the reply you see.
- Uploaded files used for analysis are processed in a secure sandbox and deleted after the run. (Files are not masked, because the analysis needs the real figures to reconcile them — a tracked trade-off recorded in the audit log.)
- Access to production data is restricted to authorised personnel.
- A privacy audit log records, per request, what protection ran (region, model, whether redaction applied, how many identifiers were masked) — counts only, never the values.
5. International transfers
Some AI sub-processors are located outside your region — in the USA (Google, OpenAI, Anthropic) and in China (DeepSeek, Z.ai). Transfers rely on the providers' contractual API terms (including no-training commitments and, where offered, Standard Contractual Clauses). Identifier masking for regulated regions further limits what personal data leaves the region. If you would rather your data never be processed in a given country, choose a model from a provider in an acceptable location (each model's provider is shown in the picker) or use the on-device local engine for spreadsheets. Fully region-resident processing is on our roadmap.
6. Data-subject rights
You can delete any conversation at any time, which removes its messages and attachments. On request we will help you access, correct or delete personal data so you can answer a data subject under the DPDP Act / PDPL. Email team@ruhu.in.
7. Personal-data breach
If we become aware of a breach affecting your data, we will notify you without undue delay and share the information you reasonably need to meet your own notification obligations.
8. Retention & deletion
Conversations and files are kept until you delete them or close your account. On termination, we will delete your personal data within a reasonable period, except where we must retain limited records (e.g. billing) by law.
9. Liability
Liability under this DPA is subject to the limitations in the Terms of Service. Ruhu AI is decision-support, not a registered tax or legal practitioner — you remain responsible for reviewing output before you rely on or file it.
10. Contact
Data protection questions or requests: team@ruhu.in.