Legal
Privacy Policy
Last updated: July 1, 2026
This Privacy Policy explains how Manav Research Lab Pvt. Ltd. collects, uses, shares, retains, and protects personal data when you visit our website, sign up for an account, or use the Manav platform. It also explains the rights you have over your data and how to exercise them.
A note on scope
This Privacy Policy covers personal data that Manav collects directly — for example, when you visit our website, sign up for an account, contact our support team, or use the Manav platform as an individual user.
If you are using Manav as part of an organisation that has its own contract with us, personal data that your organisation uploads to or generates within the platform is processed under our Data Processing Agreement (DPA), where your organisation is the data controller and Manav is the processor. For that data, please refer to your organisation's privacy notice and our DPA.
This policy is written to satisfy the EU GDPR, the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India.
1. Who we are
The entity responsible for personal data described in this policy (the "data controller" under the GDPR, the "business" under the CCPA, and the "Data Fiduciary" under the DPDP Act) is:
Manav Research Lab Pvt. Ltd.
2165 Sushant Lok, Gurugram – 122002
Haryana, India
Email: privacy@manavagi.com
We refer to ourselves as "Manav", "we", "us", or "our" throughout this policy.
2. What this policy covers
This Privacy Policy applies to:
- the Manav marketing website (
manavagi.comand its subdomains); - our platform (the Manav app, agent store, dashboards, APIs, and related services);
- email and other communications between you and Manav;
- recruitment processes for candidates who apply to roles at Manav.
It does not apply to:
- third-party websites we link to (each has its own privacy policy);
- personal data that your organisation processes through Manav on behalf of its end users — that is governed by the DPA;
- personal data we receive in our capacity as a model-inference customer of providers like Anthropic or OpenAI (those providers govern their own customer data).
3. The personal data we collect
We collect personal data in the following categories. The level of detail depends on how you interact with us.
3.1 Identity and contact information
| Field | Example |
|---|---|
| Name | First name + last name |
| Email address | name@example.com |
| Phone number (optional) | E.164 format |
| Job title and organisation | "Head of Engineering, Acme" |
| Postal address (only when needed) | e.g. for billing or recruitment |
Source. You provide this when you sign up, request a demo, contact sales/support, or apply to a job opening.
3.2 Authentication and account data
| Field | Example |
|---|---|
| Password (hashed only) | bcrypt hash; never the plain text |
| Multi-factor authentication (MFA) secret | only if you enable MFA |
| Account preferences | language, time-zone, notifications |
API keys (your own mnv_* keys) | metadata only; we display the secret to you exactly once at issuance |
| BYOLLM provider keys | encrypted at rest with per-user Fernet keys |
3.3 Usage data
| Field | Example |
|---|---|
| Pages visited, features used, time on page | aggregate analytics |
| Agent invocations, API call counts | for product analytics and billing |
| Audit-log entries | who did what, when, on which resource |
| Device and browser data | user-agent, screen size, approximate language |
| IP address | logged for security and abuse prevention |
3.4 Content you give us
| Field | Example |
|---|---|
| Documents, files, knowledge bases | anything you upload to Manav |
| Prompts and agent inputs | what you ask agents to do |
| Agent outputs | what agents produce in response |
| Chat messages, task descriptions, comments | in-product communication |
3.5 Billing and payment data
Card numbers and CVV codes are handled by Stripe and never reach our servers. We store invoices, subscription status, and the billing contact's name and address.
3.6 Candidate data (recruitment)
If you apply to a role on /careers, we collect: your name, email, phone (if provided), CV/resume (if uploaded), years of experience, current and expected CTC (if provided), and any cover note. This is processed for the purpose of evaluating your application.
3.7 Sensitive personal data
We do not intentionally collect sensitive categories of personal data (such as health, biometric, political, religious, or sexual-orientation data). Please do not upload such information to Manav unless you have a legitimate need and have obtained appropriate consent. If you do, that data will be treated under the same security measures as other content, but the responsibility for the lawful basis rests with your organisation.
4. How we use your data — purposes and lawful bases
Under the GDPR (and equivalent frameworks), we must have a lawful basis for every use of personal data. The table below maps each purpose to its lawful basis.
| Purpose | Lawful basis (GDPR Article 6) |
|---|---|
| Create and operate your account, log you in, run agents and workflows | Performance of a contract (Art. 6(1)(b)) |
| Provide customer support and respond to your questions | Performance of a contract (Art. 6(1)(b)) |
| Charge subscription fees and process payments | Performance of a contract; legal obligation (Art. 6(1)(b)(c)) |
| Send service emails (password reset, billing, breach notifications, critical product changes) | Performance of a contract / legitimate interests (Art. 6(1)(b)(f)) |
| Send marketing emails about new features and content | Consent (Art. 6(1)(a)); withdrawable at any time |
| Detect, investigate, and prevent fraud, abuse, and security incidents | Legitimate interests (Art. 6(1)(f)) — security of our service and our customers |
| Comply with legal obligations (tax, accounting, regulatory, court orders) | Legal obligation (Art. 6(1)(c)) |
| Defend our legal rights, including claims and disputes | Legitimate interests (Art. 6(1)(f)) |
| Improve the platform in aggregate (analytics, debugging, performance) | Legitimate interests (Art. 6(1)(f)) — we use pseudonymised, aggregated data where possible |
| Evaluate job applications | Steps prior to entering a contract (Art. 6(1)(b)) |
| Train foundation models on your data | We do not do this. See Section 5 below. |
For data falling under "Special Categories" under Article 9 GDPR or "Sensitive Personal Data" under the DPDP Act, processing only occurs on explicit consent, where required by law, or to protect vital interests.
5. What we do not do with your data
To be clear and on the record:
- We do not train foundation models on your data. Your prompts, content, files, and outputs are not used to fine-tune our models or those of our model-provider sub-processors. Where you use an included model (instead of BYOLLM), we engage those providers under contracts that prohibit training on your data.
- We do not sell your personal data to third parties — within the meaning of the CCPA, the DPDP Act, or any other applicable law.
- We do not share your personal data for cross-context behavioural advertising.
- We do not use your content to "personalise" what we sell to you in ways that would surprise you.
- We do not surveil individual users outside the purposes set out above (we generate aggregate metrics; we do not track individual click streams for marketing purposes).
6. Sharing and disclosure
We share personal data only with:
6.1 Sub-processors
We rely on a small number of vetted third-party service providers to operate the platform. Each is bound by a written contract with data-protection obligations substantially equivalent to ours. The current sub-processor list is published in Annex III of our DPA. Key categories:
- Cloud infrastructure — AWS (Mumbai region primary)
- Payment processing — Stripe
- Model providers — Anthropic, OpenAI (only when you use included models, not BYOLLM)
- Edge / CDN / DDoS protection — Cloudflare
- Transactional email — for verification, password reset, billing notices, breach notifications
6.2 Professional advisors
We may share data with our lawyers, auditors, accountants, and insurers under confidentiality obligations, where strictly necessary for them to advise us.
6.3 Legal and regulatory disclosures
We may disclose personal data when required by valid legal process (court order, subpoena, regulatory request) or when necessary to protect rights, safety, or property. Where lawfully permitted, we will notify the affected user in advance.
6.4 Business transfers
If Manav merges with, is acquired by, or transfers a significant part of its business to another company, personal data may be transferred to that company subject to this Privacy Policy (or a successor policy that gives at least equivalent protection).
6.5 With your direction
We share data with third parties where you direct us to — for example, when you connect a third-party integration (Slack, Stripe Connect, your BYOLLM provider) and authorise the transfer of data to that integration. In those cases, the third party's terms apply.
7. International data transfers
Personal data may be processed in countries other than the country where it was collected.
- Primary hosting region. Most production data is stored in Asia–Pacific (Mumbai), AWS
ap-south-1. - EU/UK transfers. Where personal data subject to the GDPR or UK GDPR is transferred to a country that the European Commission or the UK has not recognised as providing an adequate level of protection, we rely on Standard Contractual Clauses (SCCs) (Commission Implementing Decision (EU) 2021/914) and, for UK transfers, the UK International Data Transfer Addendum.
- India transfers. For personal data subject to the DPDP Act transferred outside India, we comply with the cross-border transfer requirements of that Act and rules issued under it.
- Transfer impact assessment. We have performed an internal transfer-impact assessment of the destinations involved; a summary is available to enterprise customers and supervisory authorities on request.
8. How long we keep your data
Retention depends on the category of data and our legal obligations.
| Category | Retention period |
|---|---|
| Account data (name, email, organisation, role) | For the lifetime of your account, plus up to 30 days after deletion for backups; longer where required by law (tax, accounting). |
| Authentication data (password hashes, MFA secrets) | For the lifetime of your account; deleted within 30 days of account deletion. |
| Audit log entries | Minimum 12 months in immutable form; may be longer where required by law (anti-money-laundering, audit). |
| Content (documents, prompts, outputs) | For as long as you keep it in the platform. Deleted (not soft-deleted) when you delete the resource. |
| Billing data (invoices, subscription state) | 7 years from the financial year of issue (Indian tax / audit requirements). |
| Candidate data (job applications) | 12 months from application date, or as long as you remain a candidate in our pipeline. We delete sooner on request. |
| Marketing email preferences | Until you unsubscribe; the unsubscribe record itself is retained as proof of opt-out. |
| Backups | Rolling 30-day window for short-term backups; data in a deleted resource is removed from backups within that window. |
When retention ends, data is either deleted or anonymised so that re-identification is not reasonably possible.
9. Your rights
You have the following rights over your personal data. Some are available everywhere; others depend on your jurisdiction.
9.1 Rights available to everyone
- Access. Get a copy of the personal data we hold about you.
- Rectification. Ask us to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"). Ask us to delete data where there is no overriding legitimate reason to keep it.
- Restriction. Ask us to stop processing your data temporarily, while a dispute is resolved.
- Portability. Receive your data in a structured, machine-readable format and transmit it to another controller.
- Objection. Object to processing based on legitimate interests, including direct marketing.
- Withdraw consent. Where we rely on your consent, withdraw it at any time (without affecting prior processing).
- Lodge a complaint. Complain to a supervisory authority — for India, the Data Protection Board (once operational); for the EU, your local Data Protection Authority; for the UK, the ICO; for California, the Attorney General or CPPA.
9.2 California (CCPA / CPRA) — additional rights
If you are a California resident, you also have the right to:
- know what categories of personal information we collect about you (see Section 3);
- know whether and to whom we sell or share your personal information (we do not "sell" or "share for cross-context behavioural advertising");
- request deletion of your personal information (subject to legal exemptions);
- limit the use and disclosure of sensitive personal information;
- be free from retaliation for exercising your rights.
The categories of personal information we have collected over the past 12 months are described in Section 3 of this policy.
9.3 India (DPDP Act) — additional notes
Under the DPDP Act, you have the rights to access, correct, complete, update, and erase your personal data, the right of grievance redressal, and the right to nominate. To exercise these, contact privacy@manavagi.com. If you are dissatisfied with our response, you may complain to the Data Protection Board.
9.4 How to exercise your rights
Email privacy@manavagi.com with the right you wish to exercise. Include enough information for us to verify your identity (typically the email address on your account). For sensitive requests we may ask for additional verification.
Timelines. We respond within statutory timelines — generally within 30 days for GDPR/DPDP requests and 45 days for CCPA requests, with a possible extension where the request is complex (you will be informed).
No fee. Exercising your rights is free, unless your request is manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse).
Self-service. Where the Services include in-product tools to view, export, or delete your data, we encourage using those first — they are faster than email.
10. Marketing communications
We send marketing emails (product updates, newsletter) only with your consent at sign-up or via a separate opt-in. Every marketing email contains an unsubscribe link. We honour unsubscribe requests promptly and retain a record of the opt-out only for the purpose of not contacting you again.
Service emails (password reset, billing, breach notifications, critical product changes) are sent regardless of marketing preference, because they are necessary to operate your account.
11. Cookies and similar technologies
The marketing site uses minimal cookies — primarily for session management and security. See our Cookies Policy for the full list of cookies, what each does, and how to opt out.
If we add analytics or marketing cookies that require consent under applicable law, we will deploy a consent banner before they load. As of the effective date of this policy, no analytics or marketing cookies are set on the marketing site without consent.
12. Automated decision-making and profiling
We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing of your personal data.
The platform's own agentic workflows are configured and supervised by your organisation. Where an agent's output materially affects an individual (for example, a hiring decision, a credit decision, a customer-service refusal), your organisation is responsible for ensuring meaningful human oversight — including via the Human-in-the-Loop approval gates the platform provides.
13. Children's privacy
Manav is a business-to-business platform. We do not knowingly collect personal data from anyone under the age of 18. If we learn that we have collected personal data from someone under 18, we will delete it promptly. If you believe we have such data, contact privacy@manavagi.com.
14. Security
We protect personal data using the technical and organisational measures described in Annex II of our DPA. Headlines:
- Encryption at rest for credentials (Fernet); bcrypt for passwords; TLS in transit.
- Role-based access control with 57 distinct resource types; tenant isolation via
org_idon every row. - Append-only audit log; multi-factor authentication available for every user.
- Vetted sub-processors; written contracts; access reviews at least annually.
- Personnel under written confidentiality obligations; security training.
No system is perfectly secure. If you suspect a security issue, contact security@manavagi.com and we will investigate.
15. Personal data breaches
If we become aware of a personal data breach that affects your personal data and is likely to result in a risk to your rights and freedoms, we will:
- notify our customers (where Manav is the processor) within 72 hours of becoming aware, per Section 9 of the DPA;
- notify you directly (where Manav is the controller of your data — e.g. our website visitors, candidates) without undue delay if the breach is likely to result in a high risk to you;
- notify supervisory authorities in line with applicable law.
16. Changes to this policy
We will update this policy from time to time to reflect changes in our practices, the platform, or the law. When we make material changes, we will:
- update the version date and effective date at the top of this page;
- notify you by email (if we have your address and a material change affects you);
- where required by law, ask for renewed consent.
A change log of previous versions is maintained in our git repository. If you want a historical version, contact us.
17. Contact
For any questions about this policy or to exercise your rights, contact:
- Email:
privacy@manavagi.com - Security disclosures:
security@manavagi.com - General support:
support@manavagi.com - Postal: Manav Research Lab Pvt. Ltd., 2165 Sushant Lok, Gurugram – 122002, Haryana, India
We do not currently have a designated Data Protection Officer (DPO) under Article 37 GDPR or a Data Protection Impact Assessment under the DPDP Act, as our processing does not currently meet the relevant statutory triggers. We will appoint a DPO and publish their contact details if and when those thresholds apply to us.
If you are dissatisfied with how we handle your request, you may complain to your local supervisory authority. We would, however, appreciate the chance to address your concerns directly first.