Shoutly AI logo
ShoutlyAI

Security & Data Processing

Last Updated: April 2026

✅ Qubixel Technologies Private Limited is committed to protecting your data with industry-leading security measures. This document outlines our technical and organizational security practices.

1. Data Encryption

  • In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (Transport Layer Security).
  • At Rest: All personal data stored in our databases is encrypted using AES-256 encryption.
  • Backups: Encrypted backups are stored in geographically redundant locations.

2. Access Controls

  • Role-Based Access Control (RBAC): Only authorized employees have access to production systems based on their job function.
  • Multi-Factor Authentication (MFA): Required for all employees accessing sensitive systems.
  • Least Privilege Principle: Employees are granted only the minimum access necessary.
  • Access Logging: All access to production systems is logged and audited.

3. Subprocessors (Data Processors)

We use the following subprocessors to provide our Service. Each subprocessor is GDPR and CCPA compliant:

  • AWS (Amazon Web Services): Cloud hosting (us-east-1, eu-west-1, ap-south-1)
  • Google Cloud Platform: AI model hosting and analytics
  • Stripe & Razorpay: Payment processing (PCI DSS Level 1)
  • Intercom: Customer support chat
  • Zendesk: Support ticket system
  • Google Analytics & Mixpanel: Usage analytics

4. Data Breach Notification Procedure

In the event of a personal data breach, we will:

  • Notify affected users within 72 hours of discovery (GDPR Article 33)
  • Notify relevant supervisory authorities (e.g., ICO, Data Protection Board of India)
  • Provide a clear description of the breach, data affected, and mitigation steps
  • Conduct a post-mortem and implement corrective measures

5. Security Certifications & Audits

  • GDPR Compliance: Annual external audit
  • PCI DSS: Our payment processors are PCI DSS Level 1 compliant
  • Vulnerability Scanning: Weekly automated scans; quarterly penetration testing

6. Data Processing Agreement (DPA)

For enterprise customers, we offer a Data Processing Agreement (DPA) that complies with GDPR Article 28. To request a DPA, email dpa@shoutlyai.com.

7. Data Retention & Deletion

  • Active accounts: Data retained for the duration of your subscription
  • Deleted accounts: Data permanently deleted within 90 days (except anonymized analytics)
  • Legal retention: Invoices and transaction records retained for 7 years (tax compliance)

8. Reporting Security Vulnerabilities

If you discover a security vulnerability in our Service, please report it to security@shoutlyai.com. We have a responsible disclosure policy and will not take legal action against good-faith reporters.

9. Contact Us

ShoutlyAI – Qubixel Technologies Private Limited

📧 Security Team: security@shoutlyai.com

📧 Data Protection Officer: dpo@shoutlyai.com

📍 Address: JP Nagar 8th Phase, Karnataka 560083, India