Overview
AlignAI is a product and brand of AscendX Innovations Pvt. Ltd.
This Privacy Policy explains how AscendX Innovations Pvt. Ltd., operating under the brand name AlignAI, collects, uses, processes, stores, shares, retains, and protects personal data when users access or use the AlignAI website, applications, platform, artificial intelligence features, and related services.
In this Privacy Policy, “AlignAI,” “we,” “us,” and “our” refer to AscendX Innovations Pvt. Ltd. “Service” refers collectively to the AlignAI website, platform, applications, integrations, tools, artificial intelligence features, and related services.
By accessing or using the Service, you acknowledge the practices described in this Privacy Policy.
1. Scope of This Privacy Policy
This Privacy Policy applies to users of AlignAI, including:
Where an educational institution, teacher, or organisation provides personal data to AlignAI, that institution, teacher, or organisation may determine the purposes for which the data is processed.
In such cases, AlignAI may process the information on behalf of the relevant institution or account holder.
2. Information We Collect
2.1 Account and Profile Information
When an account is created or maintained, we may collect:
We use this information to create, authenticate, administer, and secure user accounts.
2.2 Organisation and Membership Information
Where the Service is used by an institution or organisation, we may process:
2.3 Student and Academic Information
Teachers, institutions, administrators, students, or other authorised users may enter, upload, generate, or manage academic information, including:
2.4 Lecture, Digital Board, Audio, Video, and Document Content
When users upload, record, or submit lectures, digital board sessions, audio recordings, videos, presentations, images, documents, worksheets, or other materials, we may process and store such content to provide features including:
2.5 Communication Information
When users send messages or notifications through AlignAI, we may process:
This may include communications sent through email, Telegram, WhatsApp, SMS, or other supported services.
2.6 Fee and Payment Information
Where fee-management functionality is used, we may process:
Payments for AlignAI subscriptions or institutional fees may be processed by authorised third-party payment providers.
AlignAI does not ordinarily store complete credit-card numbers, bank-account credentials, UPI PINs, card-verification values, or other sensitive payment authentication information where these are processed directly by the payment provider.
2.7 Technical and Usage Information
When users access the Service, we may automatically collect:
2.8 Customer Support Information
When users contact us, we may collect:
3. How We Collect Information
We may collect information:
Institutions and account holders are responsible for ensuring that they have appropriate authority, consent, or another lawful basis before providing personal data relating to students, parents, employees, teachers, or other individuals.
4. How We Use Information
We may process information to:
We do not sell personal data to third-party advertisers.
5. Legal Grounds and Permitted Processing
Depending on the applicable law and circumstances, we may process personal data:
Where consent is the basis for processing, the individual may withdraw consent through available account controls or by contacting us.
Withdrawal of consent does not affect processing already lawfully completed before the withdrawal.
Certain features may no longer be available where the information is necessary to provide those features.
6. Artificial Intelligence and Automated Processing
AlignAI uses artificial intelligence and automated systems to process educational and operational content.
AI-assisted outputs may include:
Artificial intelligence outputs may contain errors, omissions, incomplete information, or inaccurate conclusions.
Teachers, institutions, administrators, and other authorised users must review AI-generated outputs before using them for:
Users remain responsible for decisions made using AI-generated outputs.
Customer content is not used to train third-party general-purpose artificial intelligence models without authorisation or consent where such authorisation or consent is required.
Certain AI features may be provided through trusted third-party model or infrastructure providers acting as service providers to AlignAI.
7. Disclosure and Sharing of Information
We may share information in the circumstances described below.
7.1 Service Providers
We may use trusted service providers for:
These providers may process information only as necessary to perform authorised services or meet legitimate operational requirements.
7.2 Organisation Administrators
Where an account is managed by an organisation, the organisation’s administrators may be able to:
Users should contact their organisation administrator regarding access controlled by the organisation.
7.3 Integrations
When a user enables or uses a third-party integration, information may be transmitted to or received from that service.
The third party’s own privacy policy and terms may apply to its independent processing.
7.4 Legal Requirements
We may disclose information where we reasonably believe disclosure is necessary to:
7.5 Business Transfers
Information may be transferred as part of:
Where required, appropriate notice will be provided before personal data becomes subject to a materially different privacy policy.
8. Vendor and Third-Party Risk Management
AlignAI selects third-party service providers based on factors including:
Depending on the nature of the service and associated risk, our vendor-management process may include:
Providers involved in security assessments, vulnerability assessments, infrastructure monitoring, or similar services receive access only where reasonably necessary and subject to appropriate restrictions.
A provider’s certification or independent assessment does not guarantee complete security. Vendor controls are applied using a risk-based approach.
9. Data Storage and International Processing
Information may be processed or stored in India or other countries where AlignAI or its service providers maintain infrastructure.
Those countries may have privacy and data-protection laws that differ from those in the user’s country.
Where required, we use appropriate contractual, technical, and organisational safeguards for international transfers and processing.
We may restrict or modify international transfers where required by applicable law or governmental direction.
10. Data Retention
We retain personal data only for as long as reasonably necessary to:
Retention periods may vary according to:
Account data is generally retained while the account remains active.
Information controlled by an organisation may remain available until it is deleted by an authorised organisation administrator, the organisation’s relationship with AlignAI ends, or retention is no longer necessary.
When personal data is no longer required, we may delete, anonymise, aggregate, or securely isolate it.
Anonymised or aggregated data that no longer reasonably identifies an individual may be retained for analytics, platform improvement, security, and research.
11. Backup and Recovery
AlignAI uses Neon’s managed database infrastructure for its production database backup and recovery processes.
Automated database backups are performed daily and retained for up to 60 days, unless a different retention period is required for legal, contractual, operational, or security reasons.
Backups are maintained to support recovery from events including:
Backup and recovery safeguards include, where applicable:
Backup copies are maintained for business continuity and disaster recovery. They are not intended to provide users with permanent historical archives or access to every previous version of their information.
When information is deleted from active systems, copies may remain temporarily in secured backups until the relevant backup reaches the end of its 60-day retention period and is deleted or overwritten.
AlignAI does not ordinarily restore individual user records from backups unless required for broader recovery, security, legal, or operational purposes.
12. Information Security
AlignAI maintains technical and organisational safeguards designed to protect information against:
Safeguards may include:
No internet transmission, storage system, or technical environment can be guaranteed to be completely secure.
Users are responsible for protecting their passwords, authentication credentials, devices, and account access.
Users should immediately report suspected unauthorised access or other security concerns to contact@alignai.in.
13. Access Control
Access to production systems, administrative tools, source-code systems, infrastructure, databases, and personal data is restricted according to legitimate operational requirements.
Our access-control practices may include:
Organisation administrators are responsible for managing access within their organisation.
Administrators should promptly remove or restrict access where a student, teacher, parent, institution employee, contractor, or other organisation user no longer requires access.
14. Secure Software Development
AlignAI applies security considerations throughout the development and maintenance lifecycle of the Service.
Depending on the nature and risk of the relevant system or change, practices may include:
14.1 Secret and Credential Management
Passwords, API keys, database credentials, tokens, certificates, and other secrets are managed using practices designed to prevent unauthorised disclosure.
These practices may include:
14.2 Vulnerability Management
AlignAI may conduct internal or third-party security checks appropriate to the nature and risk of the Service.
These may include:
Identified vulnerabilities are evaluated and prioritised according to factors such as severity, exploitability, affected information, and operational impact.
No security test can guarantee that a system is free from every vulnerability.
15. Change Management
Changes to applications, infrastructure, databases, integrations, configurations, and production systems are managed using procedures designed to reduce security, privacy, and operational risks.
Depending on the type and impact of the change, procedures may include:
Material changes to the way personal data is processed may result in an update to this Privacy Policy or another appropriate notice.
16. Security Incident Response
AlignAI maintains procedures for responding to suspected or confirmed security or privacy incidents.
Depending on the nature and severity of an incident, the response may include:
Our incident-response priorities are to:
Where required by applicable law, AlignAI will notify affected individuals, institutions, regulators, authorities, or other appropriate parties.
Security concerns should be reported promptly to contact@alignai.in.
17. Customer, Organisation, and Platform User Offboarding
When a teacher, student, parent, organisation administrator, institution employee, contractor, or other platform user account is deleted, suspended, disabled, or removed from an organisation, AlignAI or the relevant organisation administrator may:
Retain information required for security, legal, contractual, audit, or academic-record purposes
Organisation administrators are responsible for promptly offboarding platform users who should no longer have access.
This includes:
Deletion from active systems does not necessarily cause immediate deletion from secured backups. Backup copies may remain until the relevant 60-day retention period expires.
18. AlignAI Workforce Access, Onboarding, Role Changes, and Offboarding
AlignAI manages access for its employees, contractors, consultants, interns, and other authorised workforce members throughout their relationship with the company.
Workforce onboarding and access-management procedures may include:
Recording or approving access to sensitive systems, production environments, source-code repositories, cloud infrastructure, databases, and administrative tools
When responsibilities change, access may be reviewed and adjusted so that permissions remain appropriate to the individual’s current role.
When a workforce member leaves AlignAI or no longer requires particular access, offboarding procedures may include:
Access is granted, reviewed, adjusted, and removed according to the individual’s responsibilities, the systems involved, and the associated security and privacy risk.
19. Children and Student Privacy
AlignAI is intended to be used by teachers, educational institutions, students, parents, guardians, and other authorised users.
Educational institutions, teachers, and organisation administrators are responsible for ensuring that they possess the authority, permissions, notices, and consents required to provide and process student data.
Where an institution uses AlignAI on behalf of students, the institution may control the relevant student information and may be responsible for:
AlignAI does not knowingly collect personal data directly from a child without the authorisation or consent required by applicable law.
Where legally required, verifiable consent from a parent or lawful guardian may be required before processing a child’s personal data.
AlignAI does not knowingly undertake tracking or behavioural monitoring of children for targeted advertising.
We do not knowingly direct targeted advertising to children through the Service.
A parent, guardian, teacher, or institution that believes a child’s information has been provided without appropriate authority may contact us at contact@alignai.in.
We will review the request and take appropriate action, which may include restricting processing or deleting eligible information.
20. User Rights and Requests
Depending on applicable law and the circumstances, individuals may have rights to:
Requests involving information controlled by a school, teacher, institution, or organisation may need to be directed to that organisation.
AlignAI may refer such requests to the relevant account holder or organisation administrator.
Before fulfilling a request, we may verify:
Certain requests may be restricted or refused where:
Privacy requests may be submitted to contact@alignai.in.
21. Account and Data Deletion
Users may request deletion of eligible personal data by:
Deletion may be subject to:
Following deletion from active systems, information may remain in secured backups for up to 60 days before being deleted or overwritten.
Information may be anonymised rather than deleted where it can no longer reasonably identify an individual.
23. Communications
We may send:
Users may be able to manage certain communication preferences.
Essential account, transaction, security, legal, and service notices may still be sent where necessary.
24. External Links and Third-Party Services
The Service may contain links to or integrations with websites, applications, and services operated by third parties.
AlignAI is not responsible for the independent privacy, security, availability, or content practices of those third parties.
Users should review the privacy policies and terms of third-party services before using them or providing information.
25. Security Responsibilities of Users
Users must take reasonable steps to protect their accounts, including:
Organisation administrators are responsible for managing permissions and access within their organisation.
26. Grievance and Contact Mechanism
Users may contact us regarding:
Contact:
AscendX Innovations Pvt. Ltd.
Email: contact@alignai.in
Website: https://www.alignai.in
Please include sufficient information to identify the relevant account and understand the request.
Do not send passwords, complete payment credentials, or other unnecessary sensitive information by email.
27. Changes to This Privacy Policy
We may update this Privacy Policy to reflect:
When the Privacy Policy is updated, the “Last updated” date will be revised.
Where appropriate, material changes may also be communicated through:
The updated Privacy Policy will take effect on the effective date stated at the beginning of the policy.
Continued use of the Service following the effective date will be subject to the updated Privacy Policy, subject to any additional consent requirements under applicable law.