Privacy Policy

Effective 28 August 2026v2026-08-28.2

1. Who we are

Valytica (“Valytica”, “we”, “us”) is an AI-assisted property valuation manager for Indian valuers and valuation firms, operated by Gnanalytica. This policy explains what personal data we process across our web app (valytica.gnanalytica.com) and our Android app, and how we protect it. We act as a data fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP).

This notice is published in English, Hindi, Telugu and Kannada. Use the language links at the top of this page. If you would rather read it in another language listed in the Eighth Schedule to the Constitution of India, write to us at privacy@gnanalytica.com and we will provide it.

2. Data we collect

Account and profile. Name, email address, mobile number, city, state, professional registration number (e.g. IBBI/RV), firm name, and your role. We use email and (when enabled) mobile to sign you in via one-time codes, and Google account details if you sign in with Google.

Case and valuation data you enter or upload. Applicant and owner names, property addresses, uploaded property documents (sale deeds, tax receipts, approved plans, bank forms, etc.), AI-extracted fields, digital-check results, valuation inputs, and generated reports.

Site-visit data (mobile). When a surveyor records a site visit, we collect GPS coordinates and accuracy (to verify presence at the property within a ~200 m geofence), inspection checklist responses and notes, site photographs (including any GPS/timestamp embedded by the camera), and on-device plot sketches.

Device permissions (mobile). The app requests Camera (to capture site photos and plot sketches) and Location (to verify site visits). These are used only for the stated purpose and only while you use the relevant feature.

Billing. Wallet balance, plan, and per-report transactions. Card/UPI payment details are handled by our payment processor and are not stored by us.

Operational logs. Audit logs of key actions (for security and compliance) and standard technical logs. We do not place names, emails, or phone numbers in URLs.

3. How we use your data

  • To provide the service: create cases, extract fields, verify records, record site visits, compute valuations, and generate reports.
  • To authenticate you and keep your account secure.
  • To process per-report billing and maintain your wallet.
  • To maintain audit trails required for valuation compliance.
  • To communicate with you about your cases and account.

We do not sell your personal data or use it for advertising.

4. AI processing

To extract fields from your uploaded documents and assist with insights, document contents and images are processed by Google’s Gemini models. This processing is solely to provide the extraction and assistance features you request. For customers who require it, AI processing runs on an India-region endpoint; otherwise inference may be served from Google’s global infrastructure, which DPDP currently permits.

The AI proposes; you decide. Every field it extracts is shown to you with the passage it came from, and nothing reaches a report until you accept it.

5. Where your data is stored (India)

Our database, authentication, and file storage run on infrastructure located in Mumbai, India (ap-south-1), and our application functions run in the Mumbai region. Files (documents and photos) are stored in encrypted, private storage. We are committed to keeping customer data in India.

Three narrow exceptions are processed outside India, and all are listed in the sub-processors section below: the AI inference described above; our error-monitoring, performance-monitoring and session-recording tooling (Sentry), which runs in the United States, and our product-analytics tooling (PostHog), which runs in the European Union; and the market-comparables lookup (Zyte, Ireland), which fetches public property advertisements. None of them receives your case documents, valuation data, or the personal details of property owners and applicants — analytics is limited to page paths, counts and timings, error reports are scrubbed of cookies, request contents, email addresses and IP addresses before they are sent, session recordings are masked in your browser so that every word, form entry and image on the screen is hidden before the recording is sent, and the comparables lookup receives only a locality name and property type. Under the DPDP Act, transfers are permitted to any country the Central Government has not restricted; no country is currently restricted.

6. Sub-processors

We share data only with service providers that help us run Valytica, under appropriate safeguards:

  • Supabase (Mumbai) — database, authentication, file storage.
  • Vercel — application hosting (Mumbai functions) and AI Gateway routing.
  • Amazon SES (Mumbai) — transactional email (sign-in codes).
  • Google — Gemini AI processing, Google sign-in, and Google Maps (map display and address geocoding; receives property addresses to locate them).
  • Mappls (MapmyIndia) — map display and address geocoding; receives the property address to locate it. India-resident infrastructure.
  • MSG91 — SMS one-time codes (when mobile sign-in is enabled).
  • Razorpay — payment processing for wallet recharges.
  • 2Captcha / AntiCaptcha — solve captcha images during state-portal checks; they receive only captcha image bytes, never your personal data.
  • Zyte (Ireland) — fetches publicly listed property advertisements from Indian property portals when a valuer asks for market comparables. It receives only a locality or area name (for example “Kukatpally, Hyderabad”) together with the property type and size band. It never receives the property address, plot or door number, map coordinates, owner name, or any other case detail.
  • Sentry (US region, United States) — application error monitoring, performance monitoring, and masked session recording. Reports are scrubbed before they are sent: no cookies, no request bodies, no query strings, no email address and no IP address — only the internal account identifier and the page path where the error occurred. Performance data is timings and page paths. Session recordings capture the layout of the screen and the actions taken on it, with every word, every form entry and every image hidden before the recording leaves your browser — so names, addresses and document contents are not recorded. We record a small sample of sessions and any session in which an error occurred.
  • PostHog (EU region) — product analytics. We record which pages are visited, and counts of key actions (a case created, a document uploaded, an AI suggestion accepted or rejected, a report finalised, a wallet recharge). Automatic capture of on-screen text, form contents and session recording are all switched off, query strings are stripped, and no case, document or customer identifier is sent — so case and customer details are not shared.

7. Retention

We keep your account and case data for as long as your account is active and as long as we need it to provide the service.

Some records we must keep even if you close your account. A registered valuer is required to keep the records of each valuation assignment for at least three years. So when a report is finalised, that case is placed under a three-year records hold. If you close your account while a hold is running, we erase your personal details — your name, email, mobile, registration numbers and signature — and permanently disable sign-in, but the valuation record and its supporting file are kept until the hold ends. They are then deleted in full.

Cases with no finalised report are deleted in full 30 days after you close your account. Activity history (audit logs) is kept for three years and three months, which is the same record-keeping minimum.

You can ask us to delete your data at any time, subject only to those records we are required by law to retain.

8. Your rights under DPDP

  • Access a summary of the personal data we process about you — download it yourself at any time from Account → Your data.
  • Correct or update inaccurate or incomplete data.
  • Request erasure of your personal data.
  • Withdraw your consent at any time — do it yourself from Account → Consent, where you can also see which version of this notice you accepted and when. Because everything we do with your data is the service itself, withdrawing means we stop processing and close your account: sign-in is disabled immediately and your data is erased after a 30-day grace period, except for records under the statutory hold described in section 7.
  • Nominate another person to exercise your rights in case of incapacity.
  • Grievance redressal (see below).

To exercise any right, contact us at privacy@gnanalytica.com.

9. Security

We use encryption in transit and at rest, row-level access controls so each organisation can only see its own data, private file storage with time-limited signed links, and audit logging. No method of transmission or storage is perfectly secure, but we work to protect your data and notify you of material breaches as required by law.

10. Children

Valytica is a professional tool not directed to anyone under 18, and we do not knowingly collect their data.

11. Changes to this policy

We may update this policy as the product evolves. We will revise the effective date above and, for material changes, notify you in the app or by email and ask you to accept the new version. All four language versions are updated together.

12. Grievance Officer and contact

For questions, requests, or complaints about your data, contact our Grievance Officer at privacy@gnanalytica.com. We will acknowledge and respond within the timelines required under DPDP.