Legal · Privacy Policy
Privacy Policy
Data Fiduciary by design. DPDP 2023 / GDPR / APP-aligned.
Last updated: 2026-06-11
1. Scope and roles
This Privacy Policy governs how RAOSCAFF collects, uses, retains, and protects personal data across raoscaff.com and the RAOSCAFF platform. RAOSCAFF acts as a Data Fiduciary under the Digital Personal Data Protection Act 2023 for the personal data it processes, as a Controller under GDPR / UK GDPR for EU/UK residents whose data we process, and as an APP-entity under the Australian Privacy Principles for Australian residents. The operational data flow is described in the Data Use Policy; this Privacy Policy sits one layer above and frames the legal bases, rights, and contact paths.
2. What we collect
Two streams. (a) Enterprise client data — submissions made through the contact form, the structured engagement intake, or during an active engagement: name, email, phone, organisation, role, decision context, supporting documents, and any other material the client supplies to commission a Decision Brief. (b) Consumer behaviour data — voluntary questionnaire responses given by individuals using Personal Decision Intelligence surfaces on an opt-in basis. Each questionnaire discloses its specific data points up front. Streams are governed by separate consent mechanics and are not co-mingled.
3. Legal bases for processing
RAOSCAFF processes personal data on the following legal bases: explicit consent under DPDP 2023 § 6 / GDPR Art. 6(1)(a) / APP 3 (for consumer questionnaires and any optional data); contractual necessity under GDPR Art. 6(1)(b) / DPDP § 7(b) / APP 6 (for enterprise engagements where processing is required to deliver the commissioned Brief); and legitimate interest under GDPR Art. 6(1)(f) where applicable (for security, fraud prevention, and legitimate-business operation), balanced against the data subject's rights.
4. Purpose limitation
Enterprise client data is used solely to deliver the commissioned Decision Brief. Consumer questionnaire data is used solely to feed aggregate behaviour models for Personal Decision Intelligence. We do not use either stream for unrelated marketing, profiling, or third-party sharing. Detailed mechanics are in the Data Use Policy.
5. Sensitive personal data
RAOSCAFF does not solicit sensitive personal data (financial account numbers, government identification, biometric data, health information, sexual orientation, religious affiliation, caste, etc.) through ordinary engagements. Where an engagement genuinely requires processing of such data, it is captured under a specific consent and contract clause with heightened access controls. Clients should not include sensitive personal data in submissions unless specifically requested.
6. Cookies, analytics, and tracking
raoscaff.com uses functional cookies and basic privacy-respecting analytics necessary to operate the website, secure the platform, and understand aggregate usage patterns. We do not use third-party advertising cookies, do not run cross-site tracking, and do not sell or share visitor data with advertising networks. Where additional analytics are introduced, this section will be updated and the cookie disclosure refreshed.
7. Sharing with sub-processors
RAOSCAFF engages a small set of named sub-processors to operate the platform (cloud hosting, AI-orchestration providers, payment processors, email delivery). The sub-processor list is available on written request to the Privacy Office (contact in § 14) and is updated as the stack changes. Each sub-processor operates under a written data-processing agreement bound to the same purpose-limitation rules, and is not authorised to use the data for its own purposes.
8. Cross-border data transfers
Indian client data is primarily resident in India. Australian client data is primarily resident in Australia. Where cross-border processing occurs (typically because an AI-orchestration call routes to a model hosted outside the primary residency region), data is transferred under the legal basis applicable in the source jurisdiction: rules notified under the DPDP Act 2023 § 16 for India; reasonable steps under APP 8 for Australia; appropriate transfer mechanisms (e.g. Standard Contractual Clauses) under GDPR for EU/UK residents. The underlying material is anonymised before transfer wherever feasible.
9. Retention
Identifiable enterprise client material is retained for the engagement window plus 90 days for delivery support and disputes, after which it is deleted from active records. Engagement contracts may extend or shorten this window in writing. Consumer questionnaire data is retained for as long as the participant maintains an active account; on withdrawal of consent, identifiable data is removed from active records within 30 days and from rolling backups within 90 days.
10. Your rights
You have the right to access the personal data RAOSCAFF holds about you, to correct inaccurate data, to port your data in a commonly used machine-readable format where applicable, to delete your identifiable data from active records, to withdraw consent prospectively at any time, and to lodge a complaint with the Data Protection Board of India (under DPDP 2023) or your local data-protection regulator. Anonymised structural patterns extracted into the training corpus prior to a deletion request are not re-identifiable and are not retroactively reversible. Answers you submit to daily decision questions in the RAOSCAFF app are retained, linked to your account, for as long as your account remains active. You can erase your response history at any time from inside the app (Settings → Erase my response history, or Profile → Delete account — both run the account-deletion flow, which erases your answer history together with the account), with removal from active records and rolling backups on the timelines in §9. De-identified, k-anonymised answer aggregates — never your individual responses — remain subject to the anonymised-patterns carve-out above.
11. Children
RAOSCAFF surfaces are intended for adults. Personal Decision Intelligence questionnaires apply a self-declared age gate; participants below 18 (or the age of majority in their jurisdiction, where lower) are not eligible to submit questionnaires. Where RAOSCAFF becomes aware that data has been submitted by a child without verifiable parental consent, the data is deleted from active records.
12. Automated processing and AIO inference (GDPR Art. 22 / DPDP analog)
RAOSCAFF uses automated AI-assisted inference to produce analytical research outputs (Decision Briefs / AIOs). The automated processing produces an analytical inference for the client's consideration, not an automated decision that produces legal or similarly significant effects on the data subject. RAOSCAFF does not use solely automated processing to make decisions about creditworthiness, employment, immigration status, eligibility for services, or other Art. 22-equivalent decisions. Clients retain decision authority and execution authority for any action taken on the basis of an AIO.
13. Security
Client submissions and Decision Briefs are stored on RAOSCAFF-controlled infrastructure with encryption in transit and at rest. Access is restricted to engagement-relevant team members under a principle of least privilege, with access logging on identified records. RAOSCAFF maintains incident-response procedures and will notify affected data principals and regulators in the event of a notifiable breach in accordance with DPDP 2023, GDPR, and applicable laws.
14. Data Fiduciary, Grievance Officer, and contact
RAOSCAFF acts as a Data Fiduciary under the Digital Personal Data Protection Act 2023. The Grievance Officer function is staffed by the RAOSCAFF Privacy Office, contactable at inquiries@raoscaff.com (subject line: 'Privacy — [your request]'). The currently designated officer within the Privacy Office, with full postal contact, is disclosed to the data principal on written request through the same channel. RAOSCAFF is operationally headquartered in New Delhi, India. Every written privacy request is assigned a case reference and acknowledged within 7 calendar days, with a substantive response delivered within the timelines required by the DPDP Rules. Where a complaint cannot be resolved internally, the data principal retains the right to escalate to the Data Protection Board of India or the analogous regulator in their jurisdiction.
14a. Off-device account-deletion request path
If you have lost access to your device (and therefore cannot use the in-app Profile → Delete account flow) you may request account deletion by emailing inquiries@raoscaff.com from the email address associated with your RAOSCAFF account, with subject line 'Account deletion request — [your email]'. The Privacy Office acknowledges within 7 calendar days and completes the deletion within the timelines required by the DPDP Rules. The same anonymisation/retention carve-outs described in §15 apply. This off-device path is provided to satisfy Google Play's account-deletion-access requirement for apps that offer account creation.
15. RAOSCAFF Mobile App data handling
The RAOSCAFF mobile app (Play Store: com.raoscaff.app) processes a narrower data set than the website. Cognito-issued authentication tokens are stored exclusively in the device's hardware-backed secure store (Android Keystore via Tink AES-GCM-256; iOS Keychain Services with kSecAttrAccessibleAfterFirstUnlock); tokens are excluded from the device's cloud-backup stream and from device-to-device transfer. Briefs you save for offline reading are stored only on your device's app-private sandbox and are not synced to RAOSCAFF servers; uninstalling the app removes them. Contact-form submissions sent from the mobile app are subject to the same purpose-limitation and retention rules described above for the website's enterprise enquiry surface. The mobile app does not request access to camera, microphone, contacts, calendar, photos, or location. Account deletion from inside the app (Profile → Delete account) submits a fresh-JWT-gated request that erases your Cognito identity, anonymises your votes and enquiries, and confirms via email; an alternative deletion request channel for users who have lost device access is inquiries@raoscaff.com (subject line: 'Account deletion request — [your email]').
16. Crashes and diagnostics
When enabled, the RAOSCAFF mobile app reports uncaught exceptions and unhandled promise rejections to a third-party error-monitoring sub-processor (Sentry, sentry.io) so we can identify and fix bugs that affect users. The event payload includes a stack trace, the device's OS version, the app version, and a non-identifying breadcrumb trail; it does not include your name, email, phone, contact-form narrative, authentication tokens, or any presigned URL parameters (these are scrubbed in code before send). The corresponding declarations are reflected in the Google Play Data Safety form under 'Crashes and diagnostics'. You may request deletion of crash records associated with your install ID through the same Privacy Office channel.
17. Updates
This Privacy Policy may be updated as platform surfaces, regulatory contexts, and engagement patterns evolve. Material updates are dated and the latest version supersedes prior versions. Each engagement contract incorporates the version current at contracting; site updates apply prospectively to subsequent engagements and to consumer questionnaire submissions made after the update.
See also Data Use Policy, General Disclaimer, and Terms of Use.