Privacy

Data Privacy Statement

Last updated: 9 July 2026 · Applies to vahinitech.com and its subdomains, the Vahini analyser, and the Vahini research programme.

Preamble

Vahini Technologies is built on a simple promise: the writer owns their writing. Everything we make, from the 20-factor analyser to the sensor pen and the handwriting-motion dataset, is designed consent-first. We process personal data in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and its rules, and, for visitors from the European Economic Area, the GDPR where it applies. This page tells you, in plain language, what we collect, why, how long we keep it, and how to get it corrected or deleted. We revise this statement as the law and our products evolve, so please check back from time to time; the date above always tells you the current version.

1 · Who we are (the Data Fiduciary)

The entity responsible for processing described here is Vahini Technologies, a registered partnership firm, Hyderabad, Telangana, India, incubated at RTIH Tirupati and recognised under Startup India (DPIIT). Under the DPDP Act we act as the Data Fiduciary for the personal data described in this statement. It applies to our web presence at vahinitech.com and its subdomains, the Vahini handwriting analyser, and our field research programme.

2 · Grievance Officer & contact

For any question, request or complaint about your personal data, contact our Grievance Officer:

  • Email: info@vahinitech.com (subject line "Privacy")
  • WhatsApp: +91 98857 61007
  • Post: Grievance Officer, Vahini Technologies, Hyderabad, Telangana, India

We acknowledge privacy requests within 72 hours and resolve them within the timelines the DPDP Act prescribes.

3 · Our principles

  • Consent first. We collect personal data only with your consent, or where the law permits processing for a legitimate use. Nothing about a writer is captured silently.
  • Minimisation. We collect only what a feature actually needs. You can browse the entire website without telling us who you are.
  • Purpose limitation. Data given for one purpose (say, scoring one handwriting page) is not reused for another (say, model training) without separate, explicit consent.
  • No selling. We do not sell personal data. Ever.

4 · What we collect, and why

4.1 Visiting the website

Our servers automatically log technical data needed to run and defend the site: IP address, browser type and version, operating system, referring page, pages viewed, and date and time of access. These logs are kept separate from anything you type into the site, are used for security monitoring and operations, and are routinely rotated. Legal basis: legitimate use for providing the service you request (DPDP §7; GDPR Art. 6(1)(f) for EEA visitors).

4.2 Using the handwriting analyser

When you upload or photograph a handwriting page, the image is processed on our servers to produce your 20-factor report. Uploads and generated reports are stored so you can retrieve your results, and so we can investigate faults you report. A handwriting sample can reveal things about a person, and we treat it accordingly:

  • Your page is used to produce your report. That is the default, and the whole of the default.
  • Your page is used to improve our models or grow the research dataset only if you separately opt in, and you can withdraw that consent later.
  • You can ask us to delete your uploads and reports at any time (section 9).

4.3 Writing to us, feedback and pre-orders

If you use the feedback widget, contact us, or place a pre-order, we process what you give us: typically your name, email address or phone number, and your message. We use it to answer you, fulfil the order, or fix the thing you reported, and for nothing else. Legal basis: performance of what you asked for (DPDP §7(a); GDPR Art. 6(1)(b)).

4.4 The pen and the research dataset

Our field research programme collects handwriting-motion data (pen movement, pressure, tilt, pen-lifts) to build India's first consented handwriting-motion dataset. This is the heart of our company, and it runs on the strictest rules we have:

Every page is opt-in. A contributor (or their parent or guardian) consents per collection session, knows exactly what is recorded, can see it, and can withdraw. Withdrawal removes their identifiable data from future processing. Contributors may be compensated; compensation never depends on surrendering rights.

  • Motion data is stored under a pseudonymous contributor ID, separately from names and contact details.
  • Dataset records used for research or licensing are de-identified: they describe how a hand moved, not who the writer is.
  • Research with children or clinical populations (for example our autism-support research) additionally follows the consent of parents or guardians and the guidance of the clinicians and special educators we work with, and measures each child only against their own baseline. We make no diagnostic claims.

5 · Cookies

We use two kinds of cookies, and the banner you saw on first visit controls the second kind:

KindWhat it doesConsentLifetime
EssentialMakes the site function: your saved preferences (for example your cookie choice itself) and session integrity.Not required (strictly necessary)Up to 12 months
AnalyticsGoogle Analytics (Consent Mode v2) telling us which pages help and which confuse. Loads only after you opt in; stays off if you do nothing or reject.Opt-in via the bannerUp to 24 months

Cookies here cannot read your files or carry viruses; each server can only read the cookies it set. You can change your mind any time via Cookie settings (also linked in the footer of every page), and your browser can block or delete cookies entirely, though some features may stop working.

6 · Data security

All traffic to vahinitech.com and its subdomains is encrypted with TLS (HTTPS) using automatically renewed certificates. Our servers sit behind a firewall; services run in isolated containers; and access to stored uploads, reports and research data is restricted to the people who need it for their work. We review these measures regularly and adapt them as technology moves.

Your part: the internet between us is not ours. Unencrypted email can be read in transit, so please do not email us sensitive documents; use the site's HTTPS upload instead.

7 · Service providers

We use a small number of service providers who process data on our behalf and only on our instructions (as Data Processors under the DPDP Act): server hosting, DNS and content delivery (Cloudflare), and, only after your opt-in, Google Analytics. Each is bound by contract to protect your data and is given access only to what its job requires, for only as long as it requires. Where a provider processes data outside India, we rely on contractual safeguards and transfer only to jurisdictions permitted under the DPDP Act; for EEA visitors we use the safeguards the GDPR requires.

8 · How long we keep data

  • Server logs: rotated on a short schedule, kept only as long as security requires.
  • Analyser uploads and reports: kept so you can retrieve your results; deleted on your request.
  • Messages, feedback, pre-orders: kept while we handle them and as bookkeeping law requires, then deleted.
  • Research dataset: identifiable contributor records are kept only while the contributor's consent stands; withdrawal stops future processing of their identifiable data. De-identified motion records may be retained for research.

When you withdraw consent, or a purpose is fulfilled, or the law no longer permits processing, the data is erased, subject only to retention periods statute imposes on us; during such periods it is not used for anything else.

9 · Your rights

As a Data Principal under the DPDP Act you have the right to:

  • Access: a summary of the personal data we hold about you and how it has been processed (DPDP §11).
  • Correction and erasure: have inaccurate data corrected, incomplete data completed, and data that is no longer needed erased (DPDP §12).
  • Grievance redressal: a working complaints process, which is section 2 of this page (DPDP §13).
  • Nomination: nominate a person to exercise these rights for you if you are unable to (DPDP §14).
  • Withdraw consent: at any time, as easily as you gave it (DPDP §6). Processing already lawfully done is unaffected; future processing stops.

Visitors from the EEA additionally have the GDPR rights of access, rectification, erasure, restriction, data portability and objection (GDPR Arts. 15–21), and the right to withdraw consent (Art. 7(3)).

To exercise any of these, contact the Grievance Officer (section 2). We will verify it is really you before acting, act within the statutory timelines, and never charge you for a reasonable request.

10 · Children's data

Much of our mission concerns children learning to write, so we hold ourselves to DPDP §9 explicitly: we process a child's personal data only with the verifiable consent of a parent or lawful guardian, we do not use children's data for tracking or behavioural advertising, and we do not undertake processing likely to cause a child harm. In school and clinical settings, collection happens through the institution with the guardians' consent, and a child's data can be withdrawn by their guardian at any time.

11 · Complaints

If you believe we have processed your data unlawfully and we have not resolved your grievance, you have the right to complain to the Data Protection Board of India under the DPDP Act. EEA visitors may complain to the supervisory authority of their residence or workplace. We would appreciate the chance to fix it first: most problems are solved fastest by an email to info@vahinitech.com.

12 · Changes to this statement

We will update this statement as our products, providers or the law change, and the date at the top will change with it. Substantive changes to how we use already-collected data will be announced on the site and, where the law requires, consented to afresh, not slipped in quietly.