Built for teams that have to answer to a compliance review

If you are shipping an app in the UK or EU, you need to know where your data goes, who touches it, and what we sign. Everything is on this page, and the documents are ready to download.

What we do with your data

Calculation endpoints keep nothing. They compute your response and return it. The birth details in the request are not written to our logs.

Reports and chatbot sessions are kept for 90 days, then deleted. PDF report content is kept so a purchased report can be re-served. Chatbot question text is kept to operate the endpoint. Both are deleted automatically after 90 days.

We log the call, not the contents. Account, endpoint, timestamp, IP, domain, device and API key. That is what we keep to run, secure and bill the service. Deleted within 90 days.

We never train on your data. Not for models, not for advertising, not for profiling.

Where your data is processed

What Where
Primary database India, AWS ap-south-1 (Mumbai)
Application hosting Bangalore, India (blr1), DigitalOcean
Chatbot endpoint only United States (OpenAI, Anthropic, Google Gemini)

Unless you call the chatbot endpoint, your data stays within our India infrastructure.

Full subprocessor list

Documents

Document What it is
Data Processing Agreement (PDF) Our processor commitments under UK and EU GDPR. Includes the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. Sign and return, we countersign.
Subprocessor list Every third party that may touch your data, and where.
Privacy policy How we collect and use personal data across the DivineAPI website and service.
Terms of service The terms that govern use of the DivineAPI service.

Security

  • TLS on all API traffic
  • Database encrypted at rest (AES-256, AWS KMS), backups encrypted with it
  • Production databases not publicly reachable, ports firewalled
  • Production access limited to named personnel, by SSH key from approved IP addresses only, no password login
  • Multi-factor authentication on the AWS console, source code repository, domain registrar and payment provider
  • Automated backups retained for 90 days, encrypted
  • Security updates applied monthly, critical patches within 7 days
  • Read-only credentials for reporting and analysis
  • Breach notification within 72 hours of becoming aware

Frequently asked

Do you sign DPAs?
Yes. Download it above, fill in your details, sign it, and send it to admin@divineapi.com. We countersign and return the executed copy.

Can you sign the UK IDTA or the EU SCCs?
Yes, both are included with the DPA.

Is our data processed outside the UK or EU?
Yes, in India, and in the United States if you use the chatbot endpoint. The transfer clauses above cover this.

Do you use our API data to train AI?
No. Our LLM providers do not train on data sent through their APIs either.

Who is the contracting entity?
Dinesh Kumar Gahlot, trading as DivineAPI, New Delhi, India.

How do I report a security issue?
admin@divineapi.com.

Can I have my data deleted?
Yes. API logs, report content, chatbot sessions and error logs are deleted automatically within 90 days. Your account record is deleted within 7 days of a written request. Invoices and payment records are kept for the period Indian tax law requires, which we cannot waive.