Privacy Policy

Last updated: August 2026  ·  Effective date: May 2026  ·  Applies to: www.treeng.ai and treeng.ai

This Privacy Policy explains how "SSUNDAR.", a sole proprietorship ("SSUNDAR", "we", "us", or "our"), collects, uses, stores, shares, and protects your personal data when you use our platform at www.treeng.ai and treeng.ai (the "Platform"). It is written to comply with the General Data Protection Regulation (GDPR) (EU) 2016/679, the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, India's Digital Personal Data Protection Act 2023 (DPDPA), and other applicable data protection laws. Because the Platform generates analysis using AI, it also addresses the transparency approach we take under the EU AI Act (Regulation (EU) 2024/1689) — see Section 11. Please read this policy carefully before using the Platform.

1. WHO WE ARE AND HOW TO CONTACT US

Data Controller: SSUNDAR. (sole proprietorship), Telangana, India.

Privacy Contact: privacy@treeng.ai

General Contact: support@treeng.ai

Legal Contact: legal@treeng.ai

We do not currently have a mandatory obligation to appoint a Data Protection Officer (DPO) under Article 37 GDPR as we do not carry out large-scale systematic monitoring or process special category data as a core activity. If this changes, we will appoint a DPO and update this policy accordingly. For all data protection enquiries, contact privacy@treeng.ai.

If you are located in the European Union or European Economic Area, our processing of your personal data is subject to GDPR. If you are located in the United Kingdom, it is subject to UK GDPR. If you are in California, additional rights under CCPA/CPRA apply as described in Section 12.

2. WHAT PERSONAL DATA WE COLLECT

2.1 Account Data: When you register, we collect your email address, name (if provided), and a hashed password. We do not store plaintext passwords.

2.2 Profile Data: Your subscription tier, selected modules, account creation date, and last login timestamp.

2.3 Usage Data: Records of analyses run, modules accessed, analysis inputs you submit, outputs generated, tokens consumed, and session duration. This data is linked to your account.

2.4 Payment Data: Your billing country, currency, subscription plan, transaction ID, and invoice records. We do not store full card numbers, CVV codes, or bank account details — these are processed exclusively by Razorpay under PCI-DSS Level 1 certification. We receive only a payment confirmation and masked card metadata (last 4 digits, card type, issuing country) from Razorpay.

2.5 Technical Data: IP address (used for rate limiting and geo-based currency detection), browser type and version, operating system, device type, referring URL, and pages visited. This is collected automatically via server logs and our analytics provider.

2.6 Communications Data: If you contact us by email, we retain the content of that correspondence for up to 3 years.

2.7 Cookie Data: Session tokens, consent preferences, and analytics identifiers. See Section 8 for full cookie details.

2.8 Special Category Data: We do not intentionally collect special category data (health, biometric, racial/ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, or criminal records). You must not submit such data as inputs to any Analysis Module. If you inadvertently submit such data, you may request its deletion at privacy@treeng.ai.

3. LEGAL BASIS FOR PROCESSING (GDPR ARTICLE 6)

We process your personal data on the following legal bases:

Contract (Article 6(1)(b)): Processing necessary to provide the Platform services you have subscribed to — account creation, running analyses, delivering outputs, processing payments, sending transaction emails.

Legitimate Interests (Article 6(1)(f)): Security monitoring, fraud prevention, rate limiting, abuse detection, platform performance analytics, and product improvement. Our legitimate interests do not override your fundamental rights — you may object to this processing (see Section 10).

Legal Obligation (Article 6(1)(c)): Retaining billing and invoice records for the period required by Indian tax law (7 years under the Companies Act 2013 and GST regulations) and responding to lawful requests from competent authorities.

Consent (Article 6(1)(a)): Non-essential cookies and analytics tracking (PostHog). You may withdraw consent at any time through the cookie settings or by emailing privacy@treeng.ai. Withdrawal does not affect processing carried out before withdrawal.

4. HOW WE USE YOUR DATA

(a) To create and manage your account and authenticate your identity.

(b) To deliver the Analysis Module outputs you request, including transmitting your inputs to third-party AI model providers as described in Section 6.

(c) To process subscription payments, generate invoices, and apply applicable tax calculations.

(d) To send transactional emails: analysis completion notifications, subscription confirmation, invoices, password reset, and service announcements. We do not send marketing emails without your explicit consent.

(e) To monitor platform security, detect abuse, enforce rate limits, and prevent fraudulent transactions.

(f) To analyse aggregated, anonymised usage patterns to improve module quality and platform performance.

(g) To comply with applicable laws and respond to legal process.

(h) We do not sell, rent, or trade your personal data to third parties for their marketing purposes. We do not use your data to train AI models without explicit consent.

5. DATA RETENTION PERIODS

Account data: Retained for the duration of your account, plus 90 days following account deletion to allow for recovery requests, after which it is permanently purged.

Raw uploaded file content: The raw text of files you upload is automatically stripped from the analysis record 180 days after upload. The analysis results and the other inputs are retained for the life of your account so your stored analyses remain interpretable, and are deleted when your account is deleted (see "Account data" above).

Security audit logs: Records of security-relevant events (exports, payments, account and data-access actions) are retained for 24 months, then automatically deleted.

Billing and invoice records: Retained for 7 years from the date of transaction in compliance with Indian GST and Companies Act requirements.

Session and authentication logs: Retained for 90 days, then deleted.

Email correspondence: Retained for 3 years from the date of last contact.

Cookie and analytics data: PostHog analytics data retained for 1 year. Session cookies expire at end of browser session. Consent preference cookies expire after 12 months.

Deleted account data: After the 90-day recovery period, all personal data is irreversibly deleted from our live database. Billing records are retained separately in compliance with legal obligations and are not accessible through the Platform.

6. THIRD-PARTY DATA PROCESSORS

We share your data with the following third-party processors, each bound by appropriate data processing agreements and their own privacy policies:

Google (Gemini AI): Analysis inputs are transmitted to Google's Gemini API for AI inference. Per Google's Cloud Data Processing Addendum, customer data is not used to train Google's AI models. Data is processed in accordance with Google's Cloud Privacy Policy. Transfer basis: Standard Contractual Clauses (SCCs).

Supabase: Our database and authentication provider. Data is stored on AWS infrastructure in Singapore (region ap-southeast-1). Privacy policy: supabase.com/privacy. Transfer basis: SCCs.

Vercel: Our hosting and edge infrastructure provider. Processes request data (IP addresses, headers) at edge nodes globally. Privacy policy: vercel.com/legal/privacy-policy. Transfer basis: SCCs.

Razorpay: Payment processing. Processes payment card data under PCI-DSS Level 1. Privacy policy: razorpay.com/privacy. Data residency: India.

Resend: Transactional email delivery. Processes your email address and email content for delivery. Privacy policy: resend.com/legal/privacy-policy.

Inngest: Background job processing for long-running Analysis Modules. Processes task payloads including analysis inputs. Privacy policy: inngest.com/privacy.

Tavily: Research API used by the Research Pro module. May process search queries derived from your inputs. Privacy policy: tavily.com/privacy.

PostHog: Product analytics. Processes pageview data, click events, and session recordings (with inputs masked). Data hosted in the US. Privacy policy: posthog.com/privacy. Transfer basis: SCCs.

We do not permit any processor to use your data for their own commercial purposes beyond the service they provide to us.

7. INTERNATIONAL DATA TRANSFERS

Your personal data may be transferred to and processed in countries outside your country of residence, including India, the United States, and Singapore (our primary database region). Where data is transferred outside the EEA or UK, we ensure appropriate safeguards are in place:

(a) Standard Contractual Clauses (SCCs): For transfers to processors in countries without an EU adequacy decision, we rely on the EU Commission-approved SCCs (2021/914) and their UK equivalents.

(b) Adequacy Decisions: Where the European Commission has issued an adequacy decision for the destination country, we rely on that decision.

(c) Processor Certifications: Some processors (e.g., Google, Vercel) participate in recognised certification frameworks that provide additional transfer safeguards.

You may request a copy of the applicable transfer safeguards by emailing privacy@treeng.ai.

8. COOKIES AND TRACKING TECHNOLOGIES

We use the following categories of cookies and similar technologies:

Strictly Necessary Cookies (no consent required): Session authentication tokens (sb_access_token) required to keep you logged in. These expire at end of session or when you log out. Without these cookies, the Platform cannot function.

Preference Cookies (consent required): cookie_consent (records your cookie preference, 12-month expiry), preferred_currency (remembers your selected currency, 30-day expiry).

Analytics Cookies (consent required): PostHog analytics cookies (ph_*) that track pageviews, feature usage, and session recordings. Session recordings have all input fields masked. These cookies expire after 1 year.

We do not use advertising cookies, retargeting cookies, or social media tracking pixels.

You may withdraw consent for non-essential cookies at any time by clearing your browser cookies and declining on the next visit, or by emailing privacy@treeng.ai.

9. DATA SECURITY

We implement industry-standard technical and organisational measures to protect your personal data, including:

(a) Encryption of data in transit using TLS 1.2+ across all connections.

(b) Encryption of data at rest in our Supabase database.

(c) Row-Level Security (RLS) policies on all database tables, ensuring users can only access their own data.

(d) JWT-based authentication with server-side validation on all protected API routes.

(e) Rate limiting on all API endpoints to prevent brute-force attacks.

(f) Cloudflare Turnstile bot protection on registration and login forms.

(g) Strict separation of server-side secrets from client-accessible configuration.

(h) CORS restrictions limiting API access to authorised origins only.

Data Breach Notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Article 33). If the breach is likely to result in a high risk to you personally, we will also notify you directly without undue delay (GDPR Article 34).

10. YOUR DATA SUBJECT RIGHTS

Depending on your location, you have the following rights regarding your personal data. To exercise any of these rights, email privacy@treeng.ai with your request. We will respond within 30 days (extendable by a further 2 months for complex requests with notice).

Right of Access (Article 15 GDPR): You may request a copy of all personal data we hold about you, along with information about how it is processed.

Right to Rectification (Article 16 GDPR): You may request correction of inaccurate or incomplete personal data.

Right to Erasure / Right to be Forgotten (Article 17 GDPR): You may request deletion of your personal data. You can exercise this directly via Dashboard → Settings → Delete Account, or by emailing privacy@treeng.ai. We will comply unless retention is required by law (e.g., billing records).

Right to Restriction of Processing (Article 18 GDPR): You may request that we restrict processing of your data in certain circumstances (e.g., while accuracy is contested).

Right to Data Portability (Article 20 GDPR): You may request your personal data in a structured, commonly used, machine-readable format (JSON or CSV) for transfer to another controller.

Right to Object (Article 21 GDPR): You may object to processing based on legitimate interests (Section 3). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making (Article 22 GDPR): We do not make solely automated decisions that produce legal or similarly significant effects on you. AI-generated Outputs are decision-support tools and require human review before implementation.

Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority. In the EU, this is your national Data Protection Authority (DPA). In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk. In India, complaints regarding DPDPA compliance may be submitted to the Data Protection Board of India once operational.

11. AUTOMATED PROCESSING, AI TRANSPARENCY & PROVENANCE

We do not engage in profiling that produces legal or similarly significant effects on individuals as defined by Article 22 GDPR. Our Analytics Module (PostHog) creates anonymised usage profiles for product improvement purposes only — these profiles are not used for individual decision-making.

AI-generated analysis outputs are produced by automated systems but are intended solely as decision-support tools. No automated decision with legal or similarly significant effects is made about any user by SSUNDAR's systems without human review.

Our role under the EU AI Act. The Platform is an AI system built on a third-party general-purpose model (Google's Gemini). Under the EU AI Act (Regulation (EU) 2024/1689) we act as a downstream provider of that AI system; the general-purpose model obligations sit with Google as the model provider, and organisations that use our outputs act as deployers. This section describes the transparency measures we apply — it is not a claim of certification, which does not exist for this class of product.

AI-provenance marking of deliverables. Every report we generate (PDF, Excel, PowerPoint and Word) carries machine-readable AI-provenance marking in its document properties, together with a visible "AI-generated analysis — review before use" notice. This reflects the machine-readable marking approach of EU AI Act Article 50(2) — an obligation that is qualified by technical feasibility and carries exemptions for business-to-business and assistive-editing contexts — and, on a voluntary basis, the direction of content-provenance rules emerging elsewhere, such as India's IT (Intermediary Guidelines) Amendment Rules 2026 on "Synthetically Generated Information" (whose labelling duties fall on intermediaries and social-media platforms rather than on a downstream analytics provider such as us). We apply the marking regardless because it is honest, useful to you, and future-proofs the reports.

Human oversight and prohibited practices. Our reports are decision-support intended for qualified human review before any action is taken. We do not — and as a matter of engineering policy will not — build biometric emotion inference, social scoring, or covert monitoring of identified individuals (practices prohibited by Article 5 of the EU AI Act). Our modules produce organisational and cohort-level analysis: findings are expressed by role, skill, theme, or programme, never by named individual. They are not designed to evaluate, score, or rank identified individuals for employment, promotion, or termination decisions, and the Platform must not be used to make such individual-level assessments of identified persons.

12. CALIFORNIA RESIDENTS — CCPA/CPRA RIGHTS

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights:

Right to Know: You may request disclosure of the categories and specific pieces of personal information collected about you in the past 12 months, the categories of sources, the business purpose for collection, and the categories of third parties with whom it is shared.

Right to Delete: You may request deletion of personal information collected from you, subject to certain exceptions.

Right to Correct: You may request correction of inaccurate personal information.

Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioural advertising. No opt-out is required, but you may confirm this by emailing privacy@treeng.ai.

Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide the services.

Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise any CCPA right, submit a verifiable consumer request to privacy@treeng.ai. We will respond within 45 days, extendable by a further 45 days with notice.

Categories of personal information collected in the past 12 months: Identifiers (email, IP address), commercial information (subscription records, payment history), internet activity (usage data, session data), and inferences drawn from usage data (module preferences). No biometric, geolocation, or sensitive personal information as defined by CPRA is collected.

13. CHILDREN'S PRIVACY

The Platform is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact privacy@treeng.ai immediately and we will delete such data promptly. If you are under 18, you are not permitted to use this Platform.

14. LINKS TO THIRD-PARTY SITES

The Platform may contain links to third-party websites or services. This Privacy Policy applies only to data collected by SSUNDAR. We are not responsible for the privacy practices of third-party sites and recommend you review their privacy policies before providing any personal data.

15. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. Material changes will be communicated via email to your registered address and/or a prominent notice on the Platform at least 14 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Platform after changes take effect constitutes acceptance of the updated policy. If you do not accept the changes, you must discontinue use of the Platform and may request deletion of your data.

16. CONTACT AND COMPLAINTS

For any privacy-related queries, data subject requests, or complaints:

Email: privacy@treeng.ai

General: support@treeng.ai

Legal: legal@treeng.ai

Postal: SSUNDAR., Telangana, India

If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction (see Section 10).

© 2026 SSUNDAR. All rights reserved.  · Terms of Service · Privacy Policy

Pick Your Tone