This Privacy Policy explains how dhvati ("dhvati", "we", "us") — a product of Adiyogi Technologies, Coimbatore, Tamil Nadu, India — collects, uses, stores, shares, and retains information when you use the dhvati agent-authorization platform, including the dhvati Console, the dhvati Gateway, and the dhvati connector for Claude and other AI clients (together, the "Service").
dhvati is infrastructure that governs the tool calls AI agents make on behalf of employees. In most deployments your employer is the data controller and dhvati acts as a data processor on their behalf, under their instructions and their agreement with us.
1. Data we collect
We collect only what is needed to authenticate the acting person, decide each request against policy, and produce an audit trail.
- Identity data — from your organization's identity provider (IdP) via OIDC / SAML / SCIM: your name, email, group/role membership, and a subject identifier. dhvati does not store your IdP password.
- Authorization metadata — the policies, roles, and individual grants an administrator defines, and the decision (allow/deny) for each tool call.
- Audit records — for each governed call: timestamp, the acting person, the tool and action, the allow/deny decision, and the reason. These describe that a call happened; dhvati does not retain the tool's response payloads for its own purposes.
- Vendor credentials — tokens you connect (for example, your own Slack OAuth token) are held encrypted in the dhvati vault so the Gateway can act as you. They are never exposed to the agent, the browser, or other users.
- Operational data — service logs, error traces, and health metrics needed to run and secure the Service.
We do not sell personal data, and we do not use your data to train machine-learning models.
2. How we use data
- To verify the acting person and evaluate each tool call against your organization's policy.
- To inject the correct credential from the vault when a call is allowed, and to block it when it is not.
- To produce the audit trail your administrators and compliance teams rely on.
- To operate, secure, debug, and improve the reliability of the Service.
- To communicate with account administrators about the Service.
3. Storage, security, and data residency
Credentials are encrypted at rest in the vault; data in transit is protected with TLS. Access to production data is restricted to authorized personnel on a need-to-know basis.
Data residency is configurable. Organizations may choose where policy, audit, and vault metadata are stored — including India, the EU, the US, or an on-premises / self-hosted deployment in your own infrastructure. In a self-hosted deployment, your data stays within your environment and dhvati does not receive it.
4. How we share data
We share data only as needed to provide the Service:
- Your organization. Administrators can see policies, grants, and the audit trail for their workspace.
- Vendors you connect. When a call is allowed, dhvati forwards it — with your connected credential — to the destination service you chose (for example, Slack). That service's own privacy terms then apply to the forwarded request.
- Subprocessors. Vetted infrastructure providers (for example, hosting and managed databases) that process data on our behalf under contract. A current list is available on request.
- Legal. Where required by law, or to protect the rights, safety, and security of users and the Service.
We do not share personal data with third parties for their own marketing.
5. Data retention
- Audit records are retained for the retention window configured by your organization, then deleted or archived per that setting.
- Vendor credentials are retained until you disconnect the integration or your account is closed, after which they are deleted from the vault.
- Identity data is kept in sync with your IdP and removed when you are de-provisioned there or the workspace is deleted.
- Operational logs are retained for a limited period for security and debugging, then rotated out.
6. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Because your employer is usually the data controller, please direct such requests to your organization's administrator; we will assist them in fulfilling verified requests. You may also contact us directly using the details below.
7. Children
The Service is intended for use by businesses and their workforce. It is not directed to children and we do not knowingly collect data from anyone under 16.
8. Changes to this policy
We may update this policy as the Service evolves. Material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to account administrators.
9. Contact us
Questions, requests, or security reports: vishwa@dhvati.com