Privacy Policy
Effective date: July 15, 2026
This Privacy Policy explains how PeachBot collects, uses, protects, shares, and retains personal data when you use peachbot.in, our forms, accounts, dashboards, research content, AI-enabled services, and related platforms. It is written for users in India, Singapore, the UAE, the EU/EEA, and other regions where our services may be accessed.
1. Who We Are
PeachBot provides AI, edge computing, digital health workflow, agriculture, environmental, and bioinformatics software and content. For privacy questions, contact [email protected].
2. Information We Collect
- Account and contact data: name, email address, organization, role, profile details, login metadata, and messages you send to us.
- Content and uploads: blog drafts, research inputs, documents, images, datasets, notes, comments, and other material you choose to provide.
- Usage and device data: IP address, browser, device type, pages viewed, referring URLs, approximate location from network data, cookies, session information, and security logs.
- Operational data: support requests, approvals, audit logs, system events, error reports, and communications about services.
- Special or sensitive data: health, biological, student, child, biometric, genetic, or other sensitive data should only be uploaded where you have authority, consent or other lawful basis, and appropriate safeguards.
3. How We Use Information
- Provide, secure, maintain, personalize, and improve the website and software services.
- Manage accounts, authors, approvals, dashboards, profiles, content publishing, and administrative workflows.
- Respond to enquiries, partnership requests, support requests, legal notices, and security matters.
- Perform analytics, debugging, abuse prevention, fraud detection, reliability monitoring, and product improvement.
- Support responsible AI controls such as logging, human oversight, model evaluation, data minimization, access control, and incident response.
- Comply with legal obligations, regulatory requests, professional duties, contracts, and dispute resolution.
4. Lawful Bases and Regional Privacy Laws
Depending on your location and context, we process data under consent, contract, legitimate interests, legal obligation, vital interests, public interest, or other lawful bases available under applicable law. Regional requirements may include:
- India: Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025, including notice, consent or permitted use, data principal rights, security safeguards, breach reporting, and children-related obligations where applicable.
- Singapore: Personal Data Protection Act and PDPC guidance, including consent or deemed consent, notification, purpose limitation, access/correction, protection, retention, transfer limitation, and AI recommendation/decision-system guidance.
- UAE: Federal Decree-Law No. 45 of 2021 on Personal Data Protection, related rules, UAE Data Office guidance, and applicable free-zone or sector rules.
- EU/EEA: GDPR, ePrivacy rules where applicable, and EU AI Act data governance expectations where AI systems are in scope.
5. Health, Research and AI Data
Health, biological, clinical, agricultural, environmental, and research data can carry heightened privacy and safety risk. Users must not upload such data unless they are authorized to do so, have obtained required consents or approvals, and have removed or minimized personal data whenever possible. Health workflows may also require medical, telemedicine, ABDM, CDSCO, MDR/IVDR, professional, institutional, or ethics review.
AI outputs may be logged, reviewed, evaluated, or filtered to improve safety, prevent misuse, investigate incidents, and maintain quality. We do not use private customer content for public disclosure unless authorized, anonymized, aggregated, or legally required.
6. Cookies and Analytics
We may use cookies, local storage, analytics, and similar technologies to operate the site, remember preferences, measure performance, secure sessions, and understand usage. You can control cookies through your browser settings, but some features may not work without essential cookies.
7. Sharing and Processors
We do not sell personal data. We may share information with hosting providers, email services, analytics tools, security vendors, professional advisers, payment or operations providers, regulators, courts, law enforcement, and partners where necessary for the services, legal compliance, security, or a transaction such as merger or restructuring. Providers are expected to handle data under appropriate confidentiality and security terms.
8. Cross-Border Transfers
Data may be processed in India, Singapore, the UAE, the EU/EEA, the United States, or other locations where our providers or collaborators operate. Where required, we use contractual, technical, organizational, and legal safeguards for cross-border transfers.
9. Security and Governance
We apply reasonable technical and organizational measures such as access controls, encryption where appropriate, backups, logging, least-privilege access, vulnerability review, incident response, and vendor review. Our governance references may include ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 42001, ISO/IEC 23894, NIST AI RMF, OWASP guidance, and secure software lifecycle practices. No system is perfectly secure.
10. Retention
We retain data only as long as reasonably needed for the purposes described in this policy, including account operation, legal compliance, security, audit, dispute resolution, research governance, and backup. Retention periods vary by data type and legal context.
11. Your Rights
Depending on applicable law, you may request access, correction, deletion, portability, restriction, objection, withdrawal of consent, grievance redressal, nomination, or review of certain automated processing. We may need to verify identity and may decline requests where exceptions apply. Send requests to [email protected].
12. Children and Students
PeachBot may be used in educational contexts only with appropriate supervision and lawful authority. Children-related processing must comply with applicable guardian consent, school authorization, age, safety, and advertising restrictions, including India DPDP child-related obligations and relevant local law.
13. Changes
We may update this policy as laws, standards, products, and operations change. The latest version will be posted on this page.