This Privacy Policy explains how RHA Technologies Private Limited ("RHA Technologies", "RHA Axis", "we", "us", or "our") collects, uses, stores, discloses, and protects personal information in connection with:
- The RHA Axis website;
- Product demonstration and contact requests;
- Marketing and communications;
- RHA Axis customer portals and applications;
- Enterprise accounts and user access;
- Proof of Value ("PoV") deployments;
- RHA Axis analytics, digital twin, API, and cloud services; and
- Other services provided by RHA Technologies.
This Privacy Policy should be read together with our Terms of Service and, where applicable, an executed Data Processing Addendum ("DPA") or other customer agreement.
1. Introduction and Scope
RHA Technologies provides RHA Axis, an AI-powered analytics and digital twin platform designed for commercial properties including shopping malls, retail environments, airports, hospitality properties, and other physical spaces.
This Privacy Policy applies to personal information collected or processed by RHA Technologies when you:
- Visit or interact with our Website;
- Submit a contact, enquiry, or demo request;
- Communicate with our sales, support, or technical teams;
- Register for or access an RHA Axis account;
- Use our customer portal or platform;
- Participate in a PoV, pilot, or evaluation;
- Subscribe to communications from us; or
- Otherwise interact with RHA Technologies in connection with our products or services.
Enterprise Customer Data
Where an enterprise customer uses RHA Axis to process information relating to individuals, the customer may determine the purposes and means of such processing.
In those circumstances, RHA Technologies may process such information on behalf of the customer as a service provider, processor, or other contracted data-processing party, depending on the applicable law and contractual arrangement.
The customer's applicable privacy notice, MSA, SOW, DPA, or other contractual documentation may therefore also apply.
2. Privacy by Design in Physical-Space Analytics
Privacy is an important consideration in the architecture of RHA Axis. Our platform is designed primarily to provide aggregated and operational analytics rather than individual identification.
Depending on the specific deployment, technology configuration, customer requirements, and applicable agreements, RHA Axis may process information derived from cameras, sensors, Wi-Fi systems, access systems, point-of-sale systems, or other data sources.
RHA Axis is designed, where technically and commercially applicable, to generate analytics such as:
- • Footfall counts
- • Zone occupancy
- • Dwell-time distributions
- • Heatmaps
- • Traffic patterns
- • Spatial utilization
- • Aggregated visitor flows
- • Statistical operational metrics
These analytics are generally intended to describe patterns and aggregated activity rather than identify individual visitors.
RHA Axis does not provide facial recognition or individual biometric identification as a standard feature of the platform.
Unless expressly agreed in writing and supported by the applicable service, RHA Technologies does not intend to create or maintain facial-recognition databases or biometric identification profiles through the RHA Axis platform.
Customers remain responsible for ensuring that any data source connected to RHA Axis is used lawfully and in accordance with applicable privacy and data-protection requirements.
2.3 Camera and Sensor Data
Where camera or sensor data is used to generate analytics, the technical architecture and retention period may vary depending on the customer's deployment.
Where the architecture permits processing at an edge or ingestion layer, raw imagery may be processed without being retained by RHA Technologies for analytics purposes.
However, RHA Technologies does not represent that every customer deployment or third-party data source operates identically. The applicable architecture, data flows, retention periods, and processing responsibilities may be documented in the customer's technical documentation, SOW, DPA, or other applicable agreement.
2.4 Important Privacy Distinction
Data that has been aggregated, anonymised, or de-identified may still constitute personal information under certain laws if an individual can reasonably be re-identified.
Accordingly, RHA Technologies does not describe data as "anonymous" solely because direct identifiers have been removed. Where we rely on anonymisation, our objective is to ensure that individuals are no longer reasonably identifiable from the resulting information.
3. Information We Collect
The information we collect depends on how you interact with RHA Technologies.
3.1 Business Contact Information
When you request a demonstration, contact us, or communicate with our team, we may collect:
- Name;
- Business email address;
- Business telephone number;
- Job title or role;
- Company or organization name;
- Property, mall, airport, or business information;
- Country or region;
- Information contained in your enquiry; and
- Other information you voluntarily provide.
3.2 Enterprise Account Information
For authorized RHA Axis users, we may process:
- Name;
- Corporate email address;
- Organization;
- Role and permissions;
- User account information;
- Authentication and SSO identifiers;
- Login information;
- Account preferences;
- Access and administrative activity;
- Audit logs; and
- Security-related events.
Where enterprise authentication is provided through a customer's identity provider, certain authentication information may be received from that provider.
3.3 Customer and Platform Data
Depending on the applicable service, customers may provide or connect data such as:
- Property information;
- Floor plans and spatial information;
- Digital twin assets;
- Tenant information;
- Sales or operational data;
- Footfall information;
- Sensor telemetry;
- Camera-derived analytics;
- Occupancy information;
- Point-of-sale information;
- Device or network telemetry;
- Integration data; and
- Other information required to provide the contracted Services.
The customer's ownership and rights in Customer Data are governed by the applicable customer agreement.
3.4 Website and Device Information
When you access our Website, we may automatically collect certain technical information, including:
- IP address;
- Browser type and version;
- Operating system;
- Device type;
- Approximate geographic region derived from IP address;
- Referring website;
- Pages visited;
- Interaction information;
- Date and time of access;
- Session information;
- Cookie identifiers; and
- Other technical information generated through your interaction with the Website.
3.5 Communications
If you contact us by email, telephone, contact form, or other communication channel, we may retain information necessary to respond to and manage the communication.
4. How We Use Personal Information
We may use personal information for the following purposes:
Service Delivery
- • Providing and operating RHA Axis
- • Creating and administering enterprise accounts
- • Providing PoV and pilot deployments
- • Providing customer support
- • Managing integrations & service requests
- • Maintaining customer relationships
Business Communications
- • Responding to enquiries
- • Scheduling demonstrations
- • Providing proposals and quotations
- • Communicating about subscriptions or services
- • Sending important service notifications
- • Responding to support requests
Security & Fraud Prevention
- • Authenticating users
- • Detecting unauthorized access
- • Monitoring security events
- • Protecting the platform & audit trails
- • Investigating suspected abuse
- • Preventing fraud or misuse
Product & Service Improvement
- • Understanding user interactions
- • Diagnosing technical issues
- • Improving usability and performance
- • Developing new functionality
- • Evaluating system reliability
- • Aggregated and de-identified analytics
Legal and Regulatory Compliance
We may process information where necessary to comply with applicable law, respond to lawful governmental requests, maintain required records, establish, exercise, or defend legal claims, or protect our legal rights, property, personnel, customers, or users.
5. Legal Bases and Processing Purposes
Depending on the applicable jurisdiction and circumstances, we may process personal information based on:
- Your consent;
- Performance of a contract or steps taken at your request before entering into a contract;
- Compliance with a legal obligation;
- Our legitimate business interests, where permitted by law and where those interests do not override applicable privacy rights; or
- Other lawful grounds available under applicable law.
For individuals subject to the GDPR: Processing must have an applicable legal basis and comply with principles including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and security.
For individuals subject to India's Digital Personal Data Protection framework: Personal data processing will be handled in accordance with applicable provisions of the Digital Personal Data Protection Act, 2023 and applicable rules and notifications as they come into force.
6. Customer Data and Enterprise Services
RHA Technologies generally processes enterprise Customer Data to provide the Services requested by the customer.
Where an enterprise customer determines the purposes for which personal data is processed, the customer may be responsible for:
- Establishing the appropriate lawful basis for processing;
- Providing privacy notices to individuals;
- Obtaining required consents or permissions;
- Determining appropriate retention periods;
- Responding to data-subject requests where required; and
- Ensuring that information supplied to RHA Technologies may lawfully be processed.
RHA Technologies will process such information in accordance with the applicable customer agreement and DPA.
Data Processing Addendum (DPA)
Enterprise customers that require specific data-protection terms may enter into a DPA with RHA Technologies. Where a DPA applies, its terms govern the processing of personal data covered by that DPA to the extent of any conflict with this Privacy Policy.
7. Data Sharing and Disclosures
RHA Technologies does not sell or rent personal information to third parties for their own direct marketing purposes.
We may disclose information in the following circumstances:
7.1 Service Providers
We may use carefully selected third-party service providers to operate our business and Services. These may include providers of:
- Cloud infrastructure (e.g., Microsoft Azure);
- Data hosting;
- Identity and authentication;
- Email and communications;
- Customer relationship management;
- Website analytics;
- Security services, monitoring, and logging; and
- Customer support and technology infrastructure.
Third-party providers may process information only as necessary to provide services to us and are subject to appropriate contractual or confidentiality obligations.
7.2 Customer-Directed Integrations
Information may be shared with third-party systems or service providers when the customer requests or authorizes an integration, the integration is necessary to provide contracted functionality, or the customer independently connects its own third-party systems to RHA Axis. Such third parties may have their own privacy policies and contractual terms.
7.3 Legal Requirements
We may disclose information where reasonably necessary to comply with applicable law, respond to lawful requests from government authorities, comply with court orders, protect our rights or property, investigate fraud or security incidents, or protect users, customers, employees, or the public.
7.4 Corporate Transactions
If RHA Technologies is involved in a merger, acquisition, restructuring, financing, sale of assets, or similar corporate transaction, personal information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality protections.
8. International Data Transfers
RHA Technologies is based in India and may use service providers or infrastructure located in countries other than the country in which you are located.
Where personal information is transferred internationally, we will take measures required by applicable law to protect that information.
For individuals subject to the GDPR, transfers of personal data outside the European Economic Area may require appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses, or other legally recognized transfer mechanisms.
Enterprise customers may receive additional information about applicable data locations and transfer mechanisms through the relevant DPA, security documentation, or contractual arrangements.
9. Data Security
RHA Technologies uses commercially reasonable technical and organizational safeguards designed to protect personal information. Depending on the applicable service and architecture, safeguards may include:
Encryption of data in transit and, where applicable, at rest.
Role-based access controls, least-privilege principles, and MFA where supported.
Security monitoring, audit logging, access monitoring, and incident detection.
Controls protecting cloud infrastructure, applications, networks, and databases.
Employee and Contractor Controls: Access to personal information is restricted to personnel and authorized service providers who require access for legitimate business purposes.
No method of transmission or storage can be guaranteed to be completely secure. Accordingly, while we take reasonable measures to protect information, we cannot guarantee absolute security.
10. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, the applicable customer agreement, or as required by law. Retention periods may depend on:
- The nature of the information;
- The purpose for which it was collected;
- Whether you maintain an active customer relationship;
- Contractual requirements;
- Legal and regulatory requirements;
- Security and fraud-prevention requirements; and
- Legitimate business needs.
When information is no longer required, we may securely delete, anonymise, de-identify, or otherwise dispose of it in accordance with applicable requirements.
For enterprise Customer Data, retention and deletion are generally governed by the applicable MSA, DPA, SOW, Order Form, or other contractual arrangement.
12. Marketing Communications
If you provide your contact information, we may send you business communications relating to RHA Axis, including product information, demonstration follow-ups, industry insights, events, product announcements, and other business communications.
You may opt out of promotional communications at any time by using the unsubscribe mechanism included in the communication or by contacting us at:
We may continue to send non-promotional communications that are necessary to provide a service or fulfill contractual obligations.
13. Your Privacy Rights
Depending on your location and applicable law, you may have rights regarding your personal information. These may include:
- Access: Request information about the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Request deletion of personal information where legally applicable.
- Restriction: Request restriction of certain processing activities where applicable.
- Objection: Object to certain processing, including direct marketing.
- Portability: Request a copy in a structured, machine-readable format.
- Withdraw Consent: Withdraw consent where processing is based on consent.
- Complaint: Lodge a complaint with your relevant privacy authority.
For example, GDPR provides rights including access, rectification, erasure, restriction, portability, and objection, subject to the conditions and exceptions provided by the regulation. India's DPDP framework also establishes rights and obligations relating to digital personal data, subject to the applicable provisions and their commencement.
How to Exercise Your Rights
You may contact us at privacy@rhatechnologies.com. We may request reasonable information necessary to verify your identity before processing a request, and will respond within the time period required by applicable law.
14. Children's Privacy
RHA Axis is an enterprise business-to-business platform and is not directed toward children.
We do not knowingly collect personal information from children through our Website for the purpose of providing our enterprise Services. If you believe that a child has provided personal information to us through the Website, please contact us at privacy@rhatechnologies.com and we will take reasonable steps to investigate and address the situation.
15. Third-Party Websites and Services
Our Website or Services may contain links to third-party websites, applications, platforms, or services. We are not responsible for the privacy practices, security, content, or policies of third parties.
We recommend reviewing the privacy policy of any third-party service before providing personal information to it.
16. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in:
- Our products or Services;
- Technology;
- Data-processing practices;
- Applicable laws and regulations; or
- Business operations.
When we make material changes, we may update the "Last Updated" date and, where appropriate, provide additional notice. The latest version of this Privacy Policy will be published on the RHA Axis Website.
17. Contact Us
If you have questions, concerns, requests, or complaints regarding this Privacy Policy or our privacy practices, please contact:
Sector 21, Dwarka
New Delhi - 110077
India