What we do with your data
Calculation endpoints keep nothing. They compute your response and return it. The birth details in the request are not written to our logs.
Reports and chatbot sessions are kept for 90 days, then deleted. PDF report content is kept so a purchased report can be re-served. Chatbot question text is kept to operate the endpoint. Both are deleted automatically after 90 days.
We log the call, not the contents. Account, endpoint, timestamp, IP, domain, device and API key. That is what we keep to run, secure and bill the service. Deleted within 90 days.
We never train on your data. Not for models, not for advertising, not for profiling.
Where your data is processed
| What | Where |
|---|---|
| Primary database | India, AWS ap-south-1 (Mumbai) |
| Application hosting | Bangalore, India (blr1), DigitalOcean |
| Chatbot endpoint only | United States (OpenAI, Anthropic, Google Gemini) |
Unless you call the chatbot endpoint, your data stays within our India infrastructure.
Documents
| Document | What it is |
|---|---|
| Data Processing Agreement (PDF) | Our processor commitments under UK and EU GDPR. Includes the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Sign and return, we countersign. |
| Subprocessor list | Every third party that may touch your data, and where. |
| Privacy policy | How we collect and use personal data across the DivineAPI website and service. |
| Terms of service | The terms that govern use of the DivineAPI service. |
Security
- TLS on all API traffic
- Database encrypted at rest (AES-256, AWS KMS), backups encrypted with it
- Production databases not publicly reachable, ports firewalled
- Production access limited to named personnel, by SSH key from approved IP addresses only, no password login
- Multi-factor authentication on the AWS console, source code repository, domain registrar and payment provider
- Automated backups retained for 90 days, encrypted
- Security updates applied monthly, critical patches within 7 days
- Read-only credentials for reporting and analysis
- Breach notification within 72 hours of becoming aware
Frequently asked
Do you sign DPAs?
Yes. Download it above, fill in your details, sign it, and send it to
admin@divineapi.com. We countersign and return the
executed copy.
Can you sign the UK IDTA or the EU SCCs?
Yes, both are included with the DPA.
Is our data processed outside the UK or EU?
Yes, in India, and in the United States if you use the chatbot endpoint. The transfer clauses
above cover this.
Do you use our API data to train AI?
No. Our LLM providers do not train on data sent through their APIs either.
Who is the contracting entity?
Dinesh Kumar Gahlot, trading as DivineAPI, New Delhi, India.
How do I report a security issue?
admin@divineapi.com.
Can I have my data deleted?
Yes. API logs, report content, chatbot sessions and error logs are deleted automatically
within 90 days. Your account record is deleted within 7 days of a written request. Invoices
and payment records are kept for the period Indian tax law requires, which we cannot waive.