Data Privacy Framework

EaseMyPrompt.ai — Data Privacy Framework

Effective Date: August 2026 | Version: 1.0 | EaseMyPrompt.ai, a product of Derek AI Labs

1. Introduction

This Data Privacy Framework ("Framework") describes the comprehensive approach EaseMyPrompt.ai, a product of Derek AI Labs takes to personal data protection. It supplements our Privacy Policy and is designed for users, partners, and enterprise customers who require a detailed understanding of our data governance practices.

This Framework is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology (Reasonable Security Practices) Rules, 2011, and international best practices including GDPR principles, to the extent applicable.

2. Data Governance Structure

2.1 Roles and Responsibilities

Data Fiduciary: EaseMyPrompt.ai, a product of Derek AI Labs is the Data Fiduciary under the DPDPA, responsible for the purpose and means of processing personal data.

Data Processors: Third-party service providers who process data on our behalf are Data Processors. All Data Processors are bound by Data Processing Agreements.

Grievance Officer: Responsible for receiving and resolving user data complaints within statutory timeframes.

3. Data Inventory and Classification

3.1 Data Categories

We classify data into the following categories:

• Identity Data: name, email, mobile number, username

• Financial Data: masked payment details, transaction history, payout information

• Usage Data: platform interactions, prompt history, session data

• Technical Data: IP address, device identifiers, browser information

• Content Data: prompts created, purchased, and interacted with

• Communication Data: support tickets, feedback, correspondence

3.2 Sensitive Personal Data

Financial information is classified as Sensitive Personal Data under the SPDI Rules and is subject to heightened protection measures including explicit consent collection and restricted access controls.

4. Data Lifecycle Management

4.1 Collection

We collect data through: account registration forms, platform usage and interactions, payment processing, cookies and similar technologies, and third-party OAuth providers with your consent.

4.2 Processing

All data processing activities are documented in our Records of Processing Activities (RoPA). Processing occurs only for specified, explicit, and legitimate purposes.

4.3 Storage

Data is stored in encrypted databases on cloud infrastructure within or outside India, subject to appropriate transfer safeguards. Primary storage is within India where feasible.

4.4 Retention Schedule

• Account data: retained for the duration of account plus 3 years

• Transaction records: 7 years (requirement under Indian accounting law)

• Content data: retained while account is active; deleted within 90 days of account closure

• Log data: 90 days for security logs; 1 year for audit logs

• Support communications: 2 years from resolution

4.5 Deletion

Upon account deletion, personal data is soft-deleted immediately and hard-deleted within 90 days, except where retention is required by law. Anonymised data may be retained for analytics purposes indefinitely.

5. Consent Management

We obtain explicit, informed, and granular consent for:

• Collection and processing of sensitive personal data

• Marketing communications

• Non-essential cookies

• Use of data to improve AI models (opt-in only)

Consent is recorded with timestamp, mechanism, and specific purpose. Users may withdraw consent at any time through account settings or by contacting us.

6. Data Principal Rights (DPDPA 2023)

As a Data Principal, you have the following rights under the DPDPA:

• Right to access: obtain a summary of personal data processed and information about how it is processed

• Right to correction and erasure: correct inaccurate or incomplete data; erase data no longer necessary for the stated purpose

• Right to grievance redressal: raise concerns with our Grievance Officer

• Right to nominate: nominate another individual to exercise rights on your behalf in the event of death or incapacity

To exercise any right, submit a request to legal@easemyprompt.ai. We will respond within 30 days of receipt.

7. Cross-Border Data Transfers

Where personal data is transferred outside India, we ensure: (a) the recipient country provides adequate data protection; or (b) appropriate contractual safeguards (Standard Contractual Clauses or equivalent) are in place; or (c) the transfer is otherwise permitted under the DPDPA.

8. Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for: new products or features that involve large-scale processing of personal data; use of new technologies that may present high risks to data principals; and significant changes to existing data processing activities.

9. Breach Notification

In the event of a personal data breach:

• We will assess the breach and determine affected data within 24 hours

• Affected Data Principals will be notified without undue delay

• Notification will include: nature of breach, data affected, likely consequences, and remediation steps

• Regulatory notification will be made as required under the DPDPA

10. Contact and Complaints

Grievance Officer: EaseMyPrompt.ai, a product of Derek AI Labs, Mumbai, Maharashtra, India. Email: legal@easemyprompt.ai.

If you are unsatisfied with our response, you may approach the Data Protection Board of India (once constituted under the DPDPA) or other applicable regulatory authority.