Draft for legal review. This document has not been reviewed by a lawyer. Do not publish it until an Indian data-protection counsel has reviewed it and every bracketed placeholder has been replaced.
Contents
- Who we are
- Who this policy covers
- Personal data we collect
- Recordings and demonstration data
- How we use personal data
- Consent and withdrawal
- Who we share data with
- International transfers
- How long we keep data
- How we protect data
- Your rights
- Grievance Officer
- Cookies and analytics
- Children
- Changes to this policy
- Contact us
1. Who we are
This Privacy Policy explains how [LEGAL ENTITY NAME] (“Akail.ai”, “we”, “us”), a company incorporated in India with CIN [CIN] and registered office at [REGISTERED ADDRESS], handles personal data.
We collect real-world human demonstration data — video, audio and sensor recordings of people performing everyday physical tasks — and supply it to robotics and artificial intelligence companies for the purpose of training models. Because that work involves recording real people in real places, privacy is central to how we operate rather than an afterthought.
For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we act as a Data Fiduciary in respect of the personal data described in this policy, except where we process personal data on a customer's documented instructions under a separate written agreement, in which case we act as a Data Processor for that customer.
2. Who this policy covers
This policy applies to three groups of people, and different parts apply to each:
- Website visitors — anyone who visits akail.ai or contacts us through it.
- Collection participants — people who take part in a data collection session and whose activity is recorded.
- Customer and partner contacts — individuals at companies we work with, or who apply for a role with us.
This policy does not govern the datasets we deliver to customers once they have been delivered. Those are governed by the written agreement between us and that customer, and by that customer's own privacy practices.
3. Personal data we collect
From website visitors
- Details you submit through the contact form: name, work email, company and the content of your message.
- Email address if you subscribe to our blog updates.
- Technical information your browser sends automatically, such as IP address, browser type, referring page and pages viewed. See Cookies and analytics.
From collection participants
- Identity and contact details — name, phone number, address, and government identification where required to verify identity or make payment.
- Eligibility information — occupation, relevant skills or experience, and language, to match participants to a protocol.
- Consent records — the signed consent form, the language it was provided in, the date, and any subsequent withdrawal.
- Payment information — bank or UPI details and tax identifiers necessary to compensate you and meet our statutory obligations.
- Recordings — see the next section.
From customer and partner contacts
- Name, role, business contact details, and records of our correspondence.
- For job applicants: CV, work history, and interview notes.
4. Recordings and demonstration data
This is the most significant category of personal data we handle, and it is the reason this policy exists in the form it does.
During a collection session we record a participant performing a physical task. Depending on the protocol agreed with a customer, that recording may include video from head-mounted and fixed cameras, depth or stereo imagery, audio, motion and inertial data, gaze data, and location. A recording will typically show the participant's hands and body, may show their face, and may capture their voice.
What we do to limit exposure:
- Protocols are designed so that only consenting participants are in frame. Where a non-participant unavoidably enters frame, we redact them or discard the episode.
- We apply a redaction profile agreed at project scoping. This can include blurring faces, removing audio or speech, masking documents, screens, badges, number plates and signage, and coarsening or removing location data.
- Operator and site identifiers are pseudonymised in delivered datasets. The mapping between a pseudonym and a real person is held separately and under stricter access control than the recordings themselves.
- We do not use recordings for any purpose other than the one described to the participant at the time of consent.
Where recordings go. Recordings are delivered to the customer who commissioned the collection, for the purpose of training and evaluating models. That customer is contractually restricted in what it may do with the data. We do not sell recordings, publish them, or make them publicly available without separate, specific consent from the participants concerned.
5. How we use personal data
We use personal data only for the purposes below:
- To respond to enquiries and to provide and manage our services.
- To recruit, screen, brief, schedule and compensate collection participants.
- To produce, quality-check and deliver datasets to the customer who commissioned them, in accordance with the participant's consent.
- To operate and improve our collection protocols and quality processes.
- To maintain records of consent, payment and chain of custody.
- To send blog updates where you have asked to receive them.
- To meet legal, tax, accounting and regulatory obligations.
- To protect our rights, and to prevent and investigate misuse or fraud.
We do not use personal data for automated decision-making that produces legal or similarly significant effects on an individual.
6. Consent and withdrawal
For collection participants, our processing is based on consent obtained before any recording begins. Consent is:
- Informed — you are told what will be recorded, why, who will receive it, and how long it will be kept, before you agree.
- Given in a language you understand — consent forms are provided in the participant's own language, and explained verbally where that is more appropriate.
- Free — participation is voluntary and paid. Declining does not affect any other relationship you have with us or with the site owner.
- Specific — separate consent is obtained for materially different purposes. We do not rely on a past consent to justify a new use.
- Withdrawable — see below.
Withdrawing consent. You may withdraw consent at any time by writing to privacy@akail.ai or contacting the operations lead for your session. On withdrawal we will stop processing your personal data, locate the episodes in which you appear, and delete them from our systems. Where a dataset containing those episodes has already been delivered to a customer, we will notify that customer of the withdrawal and require deletion in accordance with our agreement with them. We will tell you what we were and were not able to recall.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and does not require us to delete records we must retain by law, such as payment and tax records.
8. International transfers
Most of our customers are outside India. Delivering a dataset therefore usually involves transferring personal data outside India, including to [LIST COUNTRIES / REGIONS].
We make such transfers only in accordance with applicable Indian law, including any restrictions notified by the Central Government under the DPDP Act, and under written agreements requiring the recipient to protect the data to a standard consistent with this policy. Where a customer requires data to remain in India, we can accommodate that as a project requirement.
9. How long we keep data
- Recordings — retained for the period agreed with the commissioning customer and disclosed to participants at consent, then deleted. Deletion is confirmed in writing to the customer.
- Consent records — retained for as long as we hold or have delivered the associated recordings, plus the period necessary to evidence lawful processing.
- Payment and tax records — retained for the period required by Indian tax and companies legislation.
- Enquiries and correspondence — retained for [PERIOD] after our last interaction with you.
- Job applications — retained for [PERIOD], unless you ask us to delete them sooner or agree to us keeping them for future openings.
10. How we protect data
We apply the safeguards described on our security page, including encryption of data at rest and in transit, role-based access control on a least-privilege basis with named accounts and audit logging, integrity hashing and a logged chain of custody from capture to delivery, and documented standard operating procedures with operator training records.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Act and the Rules made under it.
11. Your rights
Subject to applicable law, you have the right to:
- Access — obtain a summary of the personal data we hold about you and the processing we carry out.
- Correction and completion — have inaccurate or incomplete data corrected or completed.
- Erasure — have your personal data deleted where we no longer need it for the purpose it was collected, and we are not required to retain it.
- Withdraw consent — as described in section 6.
- Grievance redressal — raise a complaint with our Grievance Officer, who will respond within the period prescribed by law.
- Nominate — nominate another individual to exercise your rights in the event of your death or incapacity.
- Complain to the Board — escalate to the Data Protection Board of India if you are not satisfied with our response.
To exercise any of these rights, write to privacy@akail.ai. We may need to verify your identity before acting on a request.
12. Grievance Officer
In accordance with the DPDP Act, the following person is responsible for addressing questions and grievances about how we handle personal data:
- Name: [GRIEVANCE OFFICER NAME]
- Designation: [DESIGNATION]
- Email: privacy@akail.ai
- Address: [REGISTERED ADDRESS]
We aim to acknowledge grievances within [NUMBER] working days.
14. Children
Our services are not directed at children. We do not knowingly recruit participants under the age of 18, and we do not knowingly collect personal data from children through this website. If you believe a child's personal data has been recorded or submitted, contact privacy@akail.ai and we will delete it.
15. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top reflects the most recent change. Where a change materially affects how we handle your personal data, we will take reasonable steps to notify you directly.
16. Contact us
Questions about this policy, or about how we handle personal data: privacy@akail.ai.
General enquiries: hello@akail.ai or through our contact form.
Postal address: [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
See also our Terms of Use and our security practices.