Privacy Policy

Your privacy and data security are fundamental to how we build and operate eKTextAI.

Last updated: September 12, 2026

GDPR/UK-GDPR Compliant · Google API Services User Data Policy (Limited Use)

🔒 Our Commitment to Privacy

At eKTextAI (operated by MarvelSoft Ventures, Bangalore, India), we believe privacy is a fundamental right. This policy explains how we collect, use, and protect your information when you use our enterprise knowledge AI platform. eKTextAI is a multi-tenant product: each customer (tenant) has an isolated workspace. Google user data obtained through Google OAuth and Google APIs is stored only in that tenant’s space and is used solely to provide or improve the features you requested.

📋 Data Controller

Service Provider: eKTextAI

Operated by: MarvelSoft Ventures

Location: Bangalore, India

Phone: +91 95350 41234

Contact Email: info@ektextai.com

Legal Contact: info@marvelsoft.co.in

1. Information We Collect

Personal Information

  • Name, email address, and contact information
  • Organization details and business information
  • Account credentials and authentication data
  • Communication preferences and settings

Usage Data

  • Pages visited and features used within our platform
  • Time spent, click patterns, and user interactions
  • Browser type, device information, and technical specifications
  • IP address and general location data (country/region)

Content Data

  • Knowledge base content you upload or create
  • API queries and responses for service improvement
  • Training data and model customizations

2. How We Use Your Information

🚀 Service Delivery

  • • Provide and maintain AI knowledge services
  • • Process and respond to your queries
  • • Customize and improve AI responses using the tenant’s own workspace content (not Google user data for generalized model training)
  • • Enable optional Google Drive, Calendar, and profile connections so the tenant’s intended features work efficiently

📊 Analytics & Improvement

  • • Analyze platform usage patterns and performance (application telemetry, not Google user content)
  • • Develop new features and capabilities of eKTextAI
  • • Optimize how the tenant’s own knowledge base answers questions
  • • We do not use Google user data from Google APIs to train generalized AI/ML models

💬 Communication

  • • Send service updates and notifications
  • • Provide technical support and assistance
  • • Share relevant product information
  • • Respond to inquiries and feedback

🔒 Security & Compliance

  • • Detect and prevent fraudulent activity
  • • Ensure platform security and integrity
  • • Comply with legal and regulatory requirements
  • • Protect user rights and safety

3. Google User Data (OAuth / Limited Use)

eKTextAI may request access to certain Google user data when a tenant user connects a Google account via OAuth 2.0. This section states what Google user data we access, how we use it, with whom we share it, how we protect it, and how long we keep it. It is written to comply with the Google API Services User Data Policy, including the Limited Use requirements.

Limited Use affirmation

Google user data obtained through Google APIs (including Google Drive, Google Calendar, Google user profile / userinfo, and related OAuth tokens) is used only to provide or improve user-facing features of eKTextAI that are apparent in the product: connecting Drive files to a tenant knowledge base, scheduling and managing calendar events, identifying the connected Google account, and operating those features efficiently for that tenant.

  • We do not use Google user data for advertising, including personalized, retargeted, or interest-based ads.
  • We do not sell Google user data to data brokers, information resellers, or any third party.
  • We do not use Google user data to determine credit-worthiness or for lending.
  • We do not use Google Workspace APIs to develop, improve, or train generalized or non-personalized AI and/or ML models.
  • We do not transfer Google user data to third-party applications except as necessary to provide the requested eKTextAI feature, as required by law, or with the tenant’s direction.

What Google user data we access

Access is granted only after the user completes Google’s OAuth consent screen. We request only the scopes needed for the feature the tenant enables. Depending on which integration the tenant connects, eKTextAI may access:

Google user profile (OAuth userinfo)

We access your Google account identifier, name, email address, and profile picture (if provided). We use this only to identify which Google account is connected, display connection status in the tenant workspace, and bind tokens to the correct tenant user.

Google Drive (read-only)

We access file and folder metadata (such as name, ID, MIME type, modified time, and parent folder) and the content of files the tenant selects to import or sync into that tenant’s knowledge base. Access is read-only. We do not use Drive to browse or copy files unrelated to the tenant’s configured import.

Google Calendar

We access calendar lists and event data needed to create, read, update, or delete events the tenant (or the tenant’s authorized automation) requests—such as title, description, start/end time, timezone, attendees, and Google Meet conference details. This lets users schedule meetings, check availability, and send invitations from eKTextAI without leaving the application.

OAuth tokens

We store access tokens and refresh tokens issued by Google so the tenant’s connection remains active. Tokens are stored encrypted, scoped to that tenant, and used only to call Google APIs for the features above.

Other Google APIs the tenant may enable

If the tenant also connects optional Google services (for example Gmail read-only for email features, or Google Business Profile for listing management), we access only the data required for that feature. The same Limited Use, non-sharing, encryption, tenant-isolation, retention, and deletion rules in this section apply to that Google user data.

How we use Google user data

We use Google user data solely to operate the Google-connected features the tenant enabled, including:

  • Authenticating the tenant user with Google and showing which Google account is connected
  • Importing selected Drive documents into that tenant’s isolated knowledge base so their AI assistant can answer from the tenant’s own files
  • Creating and managing calendar events and Meet links that the tenant (or their flows) requested
  • Refreshing OAuth tokens so those features keep working until the tenant disconnects Google

Google user data is not used to train, develop, or improve generalized or non-personalized AI/ML models. Content imported from Drive remains in the connecting tenant’s workspace and is used only to provide that tenant’s knowledge and automation features.

With whom we share, transfer, or disclose Google user data

We do not sell Google user data. We do not share, transfer, or disclose Google user data to unaffiliated third-party applications for their own use. We do not transfer Google user data to third parties for advertising, data brokerage, credit decisions, lending, or training generalized AI/ML models.

Google user data may be processed only as follows:

  • Within the tenant’s own space: Data stays isolated to the customer account that connected Google. Other tenants cannot access it.
  • Google: API calls go back to Google to perform the action the user requested (for example, listing Drive files or writing a calendar event).
  • Infrastructure subprocessors: Encrypted hosting/database providers that store the tenant workspace, solely to run eKTextAI. They are not permitted to use Google user data for their own purposes.
  • Legal requirement: If we are required by law, court order, or a valid government request, we will disclose only what is legally required.

How we protect Google user data

  • Encryption: Data is encrypted in transit (TLS) and at rest. OAuth tokens and other sensitive credentials are stored encrypted.
  • Tenant isolation: Each tenant has a separate workspace. Google connections, tokens, Drive imports, and calendar data are keyed to that tenant and are not mixed with other customers.
  • Access controls: Only authorized users of that tenant (and systems acting on their behalf inside eKTextAI) can use the Google connection. MarvelSoft personnel access tenant data only when needed to provide support or maintain the service, under confidentiality and least-privilege controls.
  • Scope minimization: We request the minimum Google scopes needed for the enabled feature (for example, Drive read-only rather than full Drive write access).

Retention and deletion of Google user data

We retain Google user data only for as long as needed to provide the connected features, or until the tenant disconnects Google or deletes their eKTextAI account, unless a longer period is required by law.

  • While connected: Tokens and profile identifiers remain so the integration can function. Drive files imported into the tenant knowledge base remain until the tenant removes them or closes the account.
  • Disconnect Google: The tenant can revoke access in eKTextAI (and in their Google Account security settings). We then delete or invalidate stored Google OAuth tokens for that tenant and stop calling Google APIs with that account.
  • Account or data deletion: Request deletion via the dashboard GDPR tools, by emailing info@ektextai.com, or by closing the tenant account. We process deletion within 30 days, subject to legal retention duties.
  • When the retention period ends, we delete or irreversibly destroy the Google user data we hold for that purpose (including tokens). Backups expire on their normal rotation.

You can also revoke eKTextAI’s access at any time at Google Account permissions.

4. Information Sharing

🛡️ We do not sell your personal information. We only share data in specific, limited circumstances outlined below.

✅ With Your Consent

When you explicitly authorize us to share information with third parties.

⚖️ Legal Compliance

To comply with legal obligations, court orders, or governmental requests.

🤝 Service Providers

With infrastructure providers that host eKTextAI, solely to operate the product for the tenant. They may not use tenant or Google user data for their own products. We do not share Google user data with third-party applications for reasons other than providing or improving eKTextAI’s user-facing features.

🔒 Security & Safety

To protect our rights, prevent fraud, or ensure user safety.

5. Data Security

🔐

Encryption

Encryption in transit (TLS) and at rest. OAuth tokens and other sensitive credentials are stored encrypted.

🛡️

Access Controls

Role-based access, authentication, and least-privilege controls on each tenant account.

🏢

Per-tenant isolation

Each customer works in their own space. Tenant data, including Google user data, is not shared across tenants.

Security procedures are in place to protect the confidentiality of your data, including monitoring, encrypted backups, and restricted production access.

6. Cookies & Tracking

🍪 Essential Cookies

Required for basic site functionality, authentication, and security.

Always Active

📊 Analytics Cookies

Help us understand how you use our platform to improve user experience.

Optional

🎯 Preference Cookies

Remember your settings and preferences for a personalized experience.

Optional

7. Your Rights (GDPR/UK-GDPR)

🇪🇺 GDPR / UK-GDPR Compliance

If you are located in the European Union (EU) or United Kingdom (UK), you have specific rights under the General Data Protection Regulation (GDPR) and UK-GDPR. We are committed to ensuring your rights are respected and easily exercisable.

Legal Basis for Processing: We process your personal data based on your explicit consent, contract performance, legal obligations, legitimate interests, or vital interests as permitted under GDPR Article 6.

👁️

Right to Access (Article 15)

Request a copy of all personal information we hold about you. We will respond within 30 days.

Exercise this right →
✏️

Right to Rectification (Article 16)

Correct or update any inaccurate personal information. We will update your data promptly.

Request correction →
🗑️

Right to Erasure (Article 17)

Request deletion of your personal information (subject to legal requirements). We will process your request within 30 days.

Request deletion →
📦

Right to Data Portability (Article 20)

Export your data in a machine-readable format (JSON or CSV). We will provide your data within 30 days.

Export your data →

Right to Object (Article 21)

Object to processing of your personal information for specific purposes. We will respect your objection.

Object to processing →
📧

Right to Withdraw Consent (Article 7)

Withdraw your consent at any time. Withdrawal does not affect processing that occurred before withdrawal.

Withdraw consent →

How to Exercise Your Rights

You can exercise your GDPR rights through:

  • Dashboard: Log in to your account and visit the GDPR Rights section
  • Email: Send a request to info@ektextai.com
  • API: Use our GDPR API endpoints at /api/gdpr

Response Time: We will respond to your request within 30 days as required by GDPR. If your request is complex, we may extend this period by up to 60 days, and we will inform you of the extension.

⚠️ Right to Lodge a Complaint

If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local supervisory authority:

  • EU: Contact your local Data Protection Authority (DPA)
  • UK: Information Commissioner's Office (ICO) - ico.org.uk

8. Data Retention & Deletion

📅 Retention Periods

We retain your personal information only as long as necessary to provide our services and comply with legal obligations. Account data is typically retained for the duration of your subscription plus 30 days, unless longer retention is required by law. Google user data (OAuth tokens, profile identifiers, and imported Drive/Calendar data) is retained only while the Google integration is connected or until you request deletion, as described in Section 3.

GDPR Compliance: Under GDPR Article 17 (Right to Erasure), you can request deletion of your data. We will process deletion requests within 30 days, subject to legal requirements that may require longer retention.

🗑️ Data Deletion Requests

When you request data deletion:

  • We will delete your personal data within 30 days of your request
  • We may retain certain data for up to 30 days after deletion request for security and fraud prevention
  • Some data may be retained longer if required by law (e.g., financial records, legal obligations)
  • We will notify you when your data has been fully deleted

9. International Transfers & Data Residency

🌍 Data Storage Locations

Your data may be transferred to and processed in countries other than your own. We ensure adequate protection through appropriate safeguards such as standard contractual clauses and adequacy decisions.

Current Data Storage: We store your data in secure cloud infrastructure. For EU/UK users, we offer data residency options to keep your data within the EU/UK region.

🇪🇺 EU/UK Data Residency

If you are located in the EU or UK, you can request that your data be stored within the EU/UK region to comply with GDPR/UK-GDPR data residency requirements.

  • Request EU/UK data residency through your account settings
  • We will ensure your data is stored in EU/UK-approved data centers
  • Cross-border transfers are only made with your explicit consent or under approved mechanisms

10. Breach Notification (GDPR Article 33-34)

🚨 Our Commitment

In the event of a data breach that may affect your personal data, we are committed to:

  • Notify Supervisory Authority: Within 72 hours of becoming aware of the breach (GDPR Article 33)
  • Notify Affected Users: Without undue delay if the breach poses a high risk to your rights and freedoms (GDPR Article 34)
  • Provide Details: Information about the nature of the breach, affected data, and mitigation steps
  • Take Immediate Action: Contain the breach and prevent further unauthorized access

📧 How We Notify You

If a breach affects your personal data, we will notify you via:

  • Email to your registered email address
  • In-app notification if you are logged in
  • Public announcement if the breach affects multiple users

What to Do: If you receive a breach notification, please review your account for any suspicious activity, change your password if necessary, and contact us if you have concerns.

11. Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal information from children. If we become aware of such collection, we will take steps to delete the information promptly.

12. Policy Changes

We may update this Privacy Policy from time to time. We will notify you of any material changes via email or through our platform. The "Last updated" date at the top of this policy indicates when it was last revised.

13. Contact Us

Privacy Questions?

If you have any questions about this Privacy Policy or our data practices, please don't hesitate to contact us.

📧

General Inquiries

info@ektextai.com
🔒

Privacy & GDPR Requests

info@ektextai.com
🏢

Company

MarvelSoft Ventures

Bangalore, India

Phone: +91 95350 41234