Effective date: 01 Aug 2026
Last updated: 01 Aug 2026
This Privacy Policy explains how i47 Labs Private Limited ("i47", "we", "us" or "our") handles digital personal data through Aegir smart water management products, websites, web and mobile applications, support services and related services (collectively, the "Services").
Registered office: #1506, E Block, AECS Layout, Bangalore, Karnataka 560037
CIN: U62099KA2023PTC176706
Privacy and grievance contact: Vishnupriya V
Email: dpdp@i47.in
Telephone: +91 7411 722 766
This policy should be read with the agreement between i47 and the organisation that provides you access to Aegir (the "Customer"), and any privacy notice supplied by that Customer.
Most Aegir users are members, residents, employees or contractors whose access is arranged by a business, utility, residents' association or other Customer.
The parties' actual decisions and activities determine their legal roles.
Depending on your relationship with Aegir, we may handle:
Aegir devices report hardware identifiers, sequence information and water flow, rainfall or other operational readings. Those readings may become personal data when i47 or a Customer can associate them with an identifiable person or household.
We do not ask Customers to provide government identity numbers, financial account information or personal data about children.
We receive personal data:
Customers are responsible for the accuracy of the personal data they submit and for giving their members the notice and obtaining any consent required by applicable law.
We process personal data, as applicable, to:
Where i47 is the Data Fiduciary, we process personal data on the basis of consent or another use permitted by applicable Indian law. Where processing is based on consent, you may withdraw it with comparable ease. Withdrawal does not make earlier lawful processing invalid, but it may prevent us from providing the relevant account or feature.
We do not sell personal data. We do not use member PII for advertising or to profile individual consumption. Unit-level alerts and rankings are provided only for authorised Customer operational use. A unit may identify a household or occupant and is protected accordingly.
We may analyse and publish aggregate information, such as water savings across a city or sufficiently large group of communities. Before external use, we remove direct identifiers and apply aggregation and suppression controls intended to prevent a person, household or small community from being identified. We do not attempt to re-identify anonymised information.
Information remains personal data if it can reasonably be linked back to an individual or household using data available to i47 or the recipient.
For any other use in case studies or research, we will seek your explicit permission.
We disclose personal data only as needed for the purposes described above:
Processors must act on documented instructions, protect confidentiality and security, and comply with agreed deletion and incident-reporting obligations. We maintain a current processor register and will update this policy if processor categories materially change.
The principal Aegir data and compute environment is hosted in Microsoft Azure regions in India. SMS India Hub has represented that its relevant servers and providers are in India; i47 is obtaining and periodically refreshing confirmation of the precise processing and retention locations.
We do not intentionally transfer personal data outside India. If a transfer becomes necessary, we will assess and implement the safeguards required by applicable Indian law and any Central Government restriction before the transfer. Internet, vendor support and cloud operations can create unexpected data flows, so locations are reviewed periodically.
We retain information only for the period needed for its stated purpose, the Customer's documented instructions, an agreed service period, security, dispute resolution or applicable law.
Removing a person's association with a unit does not require deletion of non-personal unit measurements that the Customer needs for billing, infrastructure management or usage planning. We ensure the removed person is no longer linked to that data in active systems.
We use measures designed to protect personal data, including mobile OTP authentication, role-based access, restricted production access, encryption provided by Azure, audit logging, vulnerability assessment and service redundancy. We are strengthening privileged authentication, read/export logging, security monitoring, independent penetration testing and device-ingestion security.
No system can be guaranteed completely secure. If you suspect unauthorised access, please contact the grievance contact promptly and do not send passwords or OTPs.
Subject to applicable law, a Data Principal may request:
For a Customer-managed member account, submit the request to your Customer administrator because the Customer ordinarily determines the account and unit access. You may also contact i47; we will verify and route the request without requiring you to navigate internal legal roles.
For an i47-managed Customer administrator account, contact us directly. We may ask for reasonable information to verify identity and authority. We will not disclose another person's data or data outside the requester's entitlement. If a request is refused or limited, we will provide the reason and available escalation route where required.
Operational SMS alerts may be disabled through settings page in user app or by asking the Customer administrator. Transactional OTP delivery is initiated when a login is requested and is necessary to complete that login.
Send privacy questions or grievances to contact details mentioned at the beginning of this document.
Please include enough information to identify the relevant account and describe the concern, but never include an OTP. We will acknowledge and resolve grievances within the period required by applicable law and will coordinate with the relevant Customer where it is the Data Fiduciary. You may escalate an unresolved matter to the Data Protection Board of India using the process then prescribed, after giving us a reasonable opportunity to resolve it.
The Services are intended for adults and organisations. Customers must not create an account for, or upload personal data about, a person under 18. We do not knowingly process children's personal data.
If you believe a child's personal data has been submitted, contact us immediately. We will restrict the data, notify the relevant Customer, verify the circumstances and delete it unless retention is required by applicable law. This restriction does not prevent Aegir devices from recording non-personal water usage for premises where children may live or visit.
We use only cookies, local storage, SDKs and similar technologies necessary for authentication, security, preferences, service operation and analytics (Google Analytics and Microsoft Clarity). Non-essential technologies, if introduced, will be subject to the notice and choice required by applicable law.
We may update this policy when our Services, processors or legal obligations change. We will publish the revised version with its effective date and provide a prominent notice, and obtain fresh consent where legally required, before a material new processing purpose takes effect. Archived versions are available from the grievance contact.
For general service enquiries, contact hello@aegir.in. For privacy rights and grievances, use the dedicated contact mentioned at the beginning of this document.