✅ Qubixel Technologies Private Limited is committed to protecting your data with industry-leading security measures. This document outlines our technical and organizational security practices.
1. Data Encryption
- In Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.3 (Transport Layer Security).
- At Rest: All personal data stored in our databases is encrypted using AES-256 encryption.
- Backups: Encrypted backups are stored in geographically redundant locations.
2. Access Controls
- Role-Based Access Control (RBAC): Only authorized employees have access to production systems based on their job function.
- Multi-Factor Authentication (MFA): Required for all employees accessing sensitive systems.
- Least Privilege Principle: Employees are granted only the minimum access necessary.
- Access Logging: All access to production systems is logged and audited.
3. Subprocessors (Data Processors)
We use the following subprocessors to provide our Service. Each subprocessor is GDPR and CCPA compliant:
- AWS (Amazon Web Services): Cloud hosting (us-east-1, eu-west-1, ap-south-1)
- Google Cloud Platform: AI model hosting and analytics
- Stripe & Razorpay: Payment processing (PCI DSS Level 1)
- Intercom: Customer support chat
- Zendesk: Support ticket system
- Google Analytics & Mixpanel: Usage analytics
4. Data Breach Notification Procedure
In the event of a personal data breach, we will:
- Notify affected users within 72 hours of discovery (GDPR Article 33)
- Notify relevant supervisory authorities (e.g., ICO, Data Protection Board of India)
- Provide a clear description of the breach, data affected, and mitigation steps
- Conduct a post-mortem and implement corrective measures
5. Security Certifications & Audits
- GDPR Compliance: Annual external audit
- PCI DSS: Our payment processors are PCI DSS Level 1 compliant
- Vulnerability Scanning: Weekly automated scans; quarterly penetration testing
6. Data Processing Agreement (DPA)
For enterprise customers, we offer a Data Processing Agreement (DPA) that complies with GDPR Article 28. To request a DPA, email dpa@shoutlyai.com.
7. Data Retention & Deletion
- Active accounts: Data retained for the duration of your subscription
- Deleted accounts: Data permanently deleted within 90 days (except anonymized analytics)
- Legal retention: Invoices and transaction records retained for 7 years (tax compliance)
8. Reporting Security Vulnerabilities
If you discover a security vulnerability in our Service, please report it to security@shoutlyai.com. We have a responsible disclosure policy and will not take legal action against good-faith reporters.
9. Contact Us
ShoutlyAI – Qubixel Technologies Private Limited
📧 Security Team: security@shoutlyai.com
📧 Data Protection Officer: dpo@shoutlyai.com
📍 Address: JP Nagar 8th Phase, Karnataka 560083, India
