Legal

Data Processing Addendum

Last updated September 2026.

1. Scope and roles

This addendum forms part of the Terms of Service between you (the customer) and Mobility Inclusive Private Limited. For personal data you put into haylow.ai or that appears in the AI answers we store for you, you are the controller (a "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023) and we are your processor (a "Data Processor"). For our own account, billing and security data, we are the controller.

It applies alongside applicable laws including the DPDP Act, 2023 and the Information Technology Act, 2000.

2. What we process

  • Account data: name, email address and role of your team members.
  • Workspace data: brand names, domains, competitors, prompts you track and settings.
  • Check data: the AI answers, citations and derived metrics (mentions, sentiment, position). These are generally about organisations, not people, but may incidentally contain names of individuals.
  • Files you upload, only if you choose to: a Search Console queries export (top queries with clicks and impressions) and aggregated AI crawler counts from a server log (per day, crawler, page path and response class, with no IP addresses or query strings), each kept for a rolling 90 days and deletable by you at any time.
  • Usage and security data: logs, timestamps, IP addresses of sign-ins and admin actions.

3. Our commitments

  • We process personal data only on your documented instructions, which are these terms and your use of the product, unless the law requires otherwise.
  • Everyone with access is bound by confidentiality.
  • We apply security measures described on our Security page, including tenant isolation by database row-level security, encryption in transit, secrets kept server-side and audit logging of staff actions.
  • We help you respond to requests from individuals. You can export a workspace's data and delete brands or your account yourself, and we assist for anything else.
  • We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information we have to help you meet your own obligations, including to the Data Protection Board of India where applicable.
  • On termination we delete or return your data as described below, unless the law requires us to keep it.

4. Sub-processors

You authorise the sub-processors below. We give notice of new ones by updating this page and, for material additions, by email to your account owner, so you can object.

ProviderPurposeRegion
SupabaseDatabase, authentication and file storageSingapore (Asia-Pacific)
Dodo PaymentsPayment processing and merchant of record (cards and local payment methods, tax and invoices). We do not see or store your payment detailsGlobal
OpenAIRuns your prompts on ChatGPT modelsAs per OpenAI's API terms
Google (Gemini)Runs your prompts on Gemini models; answer analysis fallbackAs per Google's API terms
AnthropicRuns your prompts on Claude models; answer analysisAs per Anthropic's API terms
PerplexityRuns your prompts on PerplexityAs per Perplexity's API terms
xAIRuns your prompts on GrokAs per xAI's API terms
ResendTransactional email (billing reminders, notifications)As per Resend's terms
Google AnalyticsWebsite analytics (only after you accept cookies)As per Google's terms
Microsoft ClarityAnonymous session replays on public pages (only after you accept cookies)As per Microsoft's terms

5. International transfers

Our primary database is in Singapore. Some sub-processors process data in other countries. Transfers out of India are made in line with the DPDP Act, 2023 and any restrictions notified by the Government of India.

6. Retention and deletion

We keep workspace data while your account is active. Deleting a brand permanently removes its competitors, prompts and check history. Deleting your account removes your login and every workspace you alone belong to. Backups roll off on the provider's standard schedule. On request we will confirm deletion in writing.

7. Audits

On reasonable written notice, not more than once a year, we will answer security questionnaires and provide information needed to show compliance with this addendum. Independent audits are not currently offered. See our SOC 2 readiness page for our current position.

8. Order of precedence

If this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails.

Contact and grievances

Send questions, privacy requests or complaints through our contact form or email legal@visibilityos.ai. We acknowledge grievances within 48 hours and aim to resolve them within 30 days.

Grievance Officer: Ruby Rawat, ruby@garagecollective.agency.

Mobility Inclusive Private Limited, 3/3, MCD Flat, Andrews Ganj, South Delhi, New Delhi, Delhi 110094, India. GSTIN: 09AAECI2046R3Z1.

This addendum is a good-faith draft. If you need a signed copy, or your own template, contact us. Have it reviewed by counsel before relying on it.