Legal
Privacy Policy
How Intellara Technologies handles personal data in troveGEN — and, because the same product is sold three different ways, exactly which of those handlings applies to you.
Last updated 13 August 2026 · Applies to trovegen.com, the troveGEN API, and the troveGEN software when supplied for self-hosting.
Read this first
Which deployment model you are on changes everything below.
troveGEN is one engine sold in three shapes. The privacy consequences are not marketing distinctions — they determine whether Intellara holds your content at all.
SOVEREIGN · SELF-HOSTED
We hold nothing
You run troveGEN on your own infrastructure. Your documents, vectors, embeddings and logs never reach us. Intellara is not a processor of that data — you are both controller and processor. We hold only the account and billing data of whoever bought the licence.
BYO VECTOR DATABASE
We hold your text, not your vectors
troveGEN runs as a hosted service and writes embeddings into your vector database. But the extracted document text is stored in our Postgres, because the keyword half of hybrid search runs against it. We are a processor for that text.
MANAGED · troveGEN-Z
We hold your corpus
We host the documents, the extracted text and the vectors, in a Postgres schema and vector namespace dedicated to your workspace. We are a processor for all of it.
1. Who we are
Intellara Technologies Private Limited (“Intellara”, “we”), a company incorporated in India with its registered office in Bengaluru, Karnataka, operates troveGEN. For questions about this policy, to exercise a right, or to raise a grievance, contact [email protected]. We aim to acknowledge within 72 hours and resolve within 30 days.
Under India’s Digital Personal Data Protection Act, 2023, that address also reaches our grievance officer. Under the GDPR, it reaches the person responsible for data protection. We have not appointed a statutory Data Protection Officer, and we say so rather than implying an office that does not exist.
2. Roles: controller and processor
The distinction decides who owes you what, so we set it out explicitly:
- Account data — we are the controller. Names, email addresses, workspace names, billing details, authentication records, support correspondence and usage metering. We decide why and how these are processed.
- Customer content — we are a processor (on the managed and BYO models only). Documents you ingest, the text extracted from them, embeddings, queries you run, and answers generated. You remain the controller; we act on your instructions, which are the API calls and settings you configure.
- On the Sovereign model we are neither. We never receive that data. If you self-host, this policy governs only your relationship with us as a customer, not your handling of your own users’ data.
Where we act as a processor for customers subject to the GDPR, a Data Processing Addendum incorporating the Standard Contractual Clauses is available on request. That DPA, not this page, is the contractual instrument.
3. Personal data we collect as a controller
- Account. Name, email address, hashed password, workspace name and slug, role, email-verification state, and the timestamp of the last password change. Passwords are stored as bcrypt hashes; we cannot read them.
- Billing. Legal name, billing address, country and state, tax identifier, plan, billing cycle, and a record of each payment. We never receive or store your card number. Payments are processed by Razorpay; we retain only what the processor reports back for display and reconciliation — the method (card, UPI, netbanking), the card network with its last four digits, or the bank or VPA.
- Service operation. Request logs with a correlation identifier, tenant identifier, endpoint, status and duration; API key metadata and last-used timestamp; error reports; and usage counters (pages processed, searches, storage) used for entitlement enforcement and billing.
- Communications. What you send us by email, and one-time codes issued for email verification and password reset (stored hashed, valid for minutes).
We do not use advertising cookies, third-party analytics or tracking pixels on this website or in the console. The console keeps your session in browser local storage, not in a tracking cookie. There is no consent banner because there is nothing to consent to.
4. Customer content: exactly what we hold, per model
This is the section most likely to be glossed over elsewhere, so it is written literally. On the Sovereign model, none of the following reaches us at all.
| Data | BYO vector database | Managed (troveGEN-Z) |
|---|---|---|
| Original uploaded file | Not retained after processing | Not retained after processing |
| Extracted text and chunks | Stored by us — the keyword half of hybrid search runs on it | Stored by us |
| Embeddings (vectors) | Written to your database; we hold no copy | Stored by us in a namespace dedicated to your workspace |
| Extracted figures and images | Stored by us when figure extraction is enabled | Stored by us when figure extraction is enabled |
| Queries and generated answers | Processed in memory; stored only if you enable conversations | Same |
| Credentials for your own stores and models | Encrypted at rest with AES-256-GCM, never returned by any API | |
If your documents contain personal data, we process it. troveGEN is content-agnostic — it will ingest a personnel file as readily as a product manual. Deciding what is lawful to put into it is the controller’s responsibility, which on the managed and BYO models is yours.
Two product features exist specifically to reduce that exposure, and both are opt-in: PII redaction detects identifiers before embedding, replaces them with tokens, and keeps the mapping in a separately encrypted vault, so raw identifiers never reach the vector store; and ACL enforcement filters retrieval by the end user’s permissions before results are ranked, rather than filtering afterwards.
5. Why we process it, and on what legal basis
| Purpose | Basis (GDPR Art. 6) |
|---|---|
| Providing the service you signed up for | Contract |
| Billing, invoicing and tax records | Contract; legal obligation |
| Security, abuse prevention and rate limiting | Legitimate interests |
| Diagnosing faults and improving reliability | Legitimate interests |
| Service and security notifications | Contract; legitimate interests |
| Marketing email, where sent | Consent, withdrawable at any time |
| Processing customer content | Your instructions, under the DPA |
We do not train models on your content. Not our own models, and we do not permit it for our sub-processors. Your corpus is used to answer your queries and for nothing else.
6. Sub-processors
The managed service uses a small number of third parties. Which apply depends on your configuration — several are used only if you choose a hosted model rather than bringing your own.
| Provider | Purpose | When |
|---|---|---|
| Cloud infrastructure provider | Hosting, databases, backups | Managed and BYO |
| Razorpay Software Private Limited | Payment processing | Paid plans only |
| Email relay (SMTP) | Verification codes, service email | When a relay is configured |
| Embedding / reranking / LLM providers | Generating embeddings and answers | Only where troveGEN supplies the model. Bring your own and no third party receives your text through us |
Every sub-processor is bound by written terms no less protective than this policy. We will give notice of a new sub-processor before it starts processing customer content, and you may object.
7. International transfers
Intellara is established in India. Depending on the region you choose, data may be processed in India or in the region hosting your deployment. Where personal data protected by the GDPR or UK GDPR leaves the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum), with a transfer risk assessment available on request.
Data residency is a deployment choice, not a pricing tier. If your obligations require content to stay in a particular jurisdiction, self-hosting or a BYO vector database in that region achieves it absolutely, rather than contractually.
8. Retention
- Account data — for as long as the workspace exists, then up to 90 days.
- Customer content — until you delete it or close the workspace. Deleting a document removes its chunks, its vectors (including from your own store, where troveGEN wrote them) and any PII vault entries for it. A failed vector deletion aborts the whole operation rather than silently orphaning data, so a delete that reports success has actually propagated.
- Billing and tax records — retained for the period Indian tax law requires (currently up to eight financial years). These survive account closure because we are legally required to keep them.
- Operational logs — typically 30 days.
- Backups — deleted data persists in encrypted backups for up to 35 days before rotating out.
9. Security
Measures actually implemented, not aspirations:
- TLS in transit; encryption at rest for databases and backups.
- Credentials for your vector stores and model providers encrypted with AES-256-GCM and never returned by any API — a leaked database read does not yield a usable key.
- Workspace isolation: managed tenants get a dedicated Postgres schema and vector namespace, with routing enforced by a check that fails the build if a query could read the wrong tenant.
- Passwords stored as bcrypt hashes. Password reset and email verification use short-lived, hashed, attempt-limited one-time codes, and a completed reset revokes sessions created before it.
- Rate limiting per account and per IP; scoped API keys that can be revoked individually.
- Prompt-injection sanitisation on ingested content, and egress filtering on generated answers.
What we do not claim: we hold no SOC 2, ISO 27001 or HIPAA attestation today. We would rather state that plainly than let an unqualified “enterprise-grade security” imply one. If certification is a procurement requirement, tell us where you are in your process and we will be straight about ours.
If a breach affects your personal data, we will notify you without undue delay and, where the law requires, within 72 hours of becoming aware — with what we know at the time rather than waiting for a complete picture.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict or object to processing, and to withdraw consent. Indian residents additionally have rights under the DPDP Act, including nomination; residents of California and similar jurisdictions have rights of access and deletion and to opt out of “sale” or “sharing” — we do neither, and never have.
Exercise any of these at [email protected]. We do not charge for a first request and will not penalise you for making one. Most account data is also directly editable or exportable from the console.
If your request concerns data inside a customer’s troveGEN workspace — for example you are an employee of one of our customers — we are the processor, not the controller. We will forward your request to that customer and support them in answering it, but we cannot alter their corpus on your instruction. That is the correct outcome, not an evasion: acting unilaterally on someone else’s data is precisely what a processor must not do.
You also have the right to complain to a supervisory authority — the Data Protection Board of India, or your local authority in the EEA or UK.
11. Children
troveGEN is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.
12. Changes
We will update this policy as the product changes. The date at the top always reflects the current version. For a material change affecting how we handle personal data, we will notify account owners by email before it takes effect rather than relying on you to notice a new date.
Questions
Intellara Technologies Private Limited, Bengaluru, Karnataka, India · [email protected]
For how sovereignty is enforced technically rather than contractually, see Sovereignty.