Privacy Policy

Privacy Policy

Effective date: 01 Aug 2026
Last updated: 01 Aug 2026

This Privacy Policy explains how i47 Labs Private Limited ("i47", "we", "us" or "our") handles digital personal data through Aegir smart water management products, websites, web and mobile applications, support services and related services (collectively, the "Services").

Registered office: #1506, E Block, AECS Layout, Bangalore, Karnataka 560037
CIN: U62099KA2023PTC176706
Privacy and grievance contact: Vishnupriya V
Email: dpdp@i47.in
Telephone: +91 7411 722 766

This policy should be read with the agreement between i47 and the organisation that provides you access to Aegir (the "Customer"), and any privacy notice supplied by that Customer.

1. Our Different Roles

Most Aegir users are members, residents, employees or contractors whose access is arranged by a business, utility, residents' association or other Customer.

  • Customer-managed member data: The Customer ordinarily decides whose details are entered, which unit or department the person may access, and which operational alerts are sent. For this processing, the Customer is ordinarily the Data Fiduciary and i47 acts as its Data Processor. Please contact the Customer first to exercise rights concerning that account or unit association. i47 will assist the Customer as required by contract and applicable law.
  • Customer administrator and business relationship data: i47 decides how it manages Customer administrator accounts, enquiries, contracts, billing, security and direct support. For those activities, i47 acts as the Data Fiduciary.
  • Independent legal or security purposes: i47 may act as a Data Fiduciary where it independently processes personal data to comply with law, establish or defend legal claims, or secure the Services, to the extent permitted by applicable law.

The parties' actual decisions and activities determine their legal roles.

2. Personal Data We Handle

Depending on your relationship with Aegir, we may handle:

  • name, mobile number and optional email address;
  • Customer, unit, department or household association and assigned role;
  • authentication information, including OTP requests, successful/failed login events, session and device information;
  • communication and alert preferences;
  • operational messages, including leak, unusual-use or device-status alerts;
  • support requests and communications;
  • IP address, application/device type, operating-system version, event time and security or diagnostic logs; and
  • usage or meter information associated with a unit where that association can reasonably relate to an identifiable person or household.

Aegir devices report hardware identifiers, sequence information and water flow, rainfall or other operational readings. Those readings may become personal data when i47 or a Customer can associate them with an identifiable person or household.

We do not ask Customers to provide government identity numbers, financial account information or personal data about children.

3. How We Receive Data

We receive personal data:

  • from Customer administrators who create and manage member accounts and unit access;
  • directly from Customer administrators and authorised users when they log in, set preferences or contact support;
  • automatically from applications, security systems and connected Aegir devices; and
  • from service providers that deliver OTPs, alerts, hosting or support functions on our behalf.

Customers are responsible for the accuracy of the personal data they submit and for giving their members the notice and obtaining any consent required by applicable law.

4. Why We Process Personal Data

We process personal data, as applicable, to:

  • create and secure accounts and authenticate users by mobile OTP;
  • enforce role-based access to Customer and unit information;
  • display authorised unit consumption, device status, leaks and operational alerts;
  • send requested OTPs and opted-in operational SMS alerts;
  • administer Customer relationships, contracts, billing and support;
  • diagnose faults, maintain service availability, investigate misuse and protect the Services;
  • respond to correction, erasure, grievance and other lawful requests;
  • comply with applicable law and binding directions; and
  • create statistics that have been anonymised and aggregated so they no longer identify an individual or household.

Where i47 is the Data Fiduciary, we process personal data on the basis of consent or another use permitted by applicable Indian law. Where processing is based on consent, you may withdraw it with comparable ease. Withdrawal does not make earlier lawful processing invalid, but it may prevent us from providing the relevant account or feature.

We do not sell personal data. We do not use member PII for advertising or to profile individual consumption. Unit-level alerts and rankings are provided only for authorised Customer operational use. A unit may identify a household or occupant and is protected accordingly.

5. Aggregated and Anonymised Information

We may analyse and publish aggregate information, such as water savings across a city or sufficiently large group of communities. Before external use, we remove direct identifiers and apply aggregation and suppression controls intended to prevent a person, household or small community from being identified. We do not attempt to re-identify anonymised information.

Information remains personal data if it can reasonably be linked back to an individual or household using data available to i47 or the recipient.

For any other use in case studies or research, we will seek your explicit permission.

6. Sharing and Processors

We disclose personal data only as needed for the purposes described above:

  • to the Customer and its authorised administrators according to configured roles;
  • to Microsoft Azure, which hosts the Aegir platform and storage in India;
  • to SMS India Hub, which receives mobile numbers and message content to deliver OTPs and operational alerts;
  • to professional advisers, auditors or insurers under confidentiality obligations where reasonably necessary;
  • in connection with a corporate transaction, subject to appropriate confidentiality and applicable notice requirements; and
  • to a court, government body or law-enforcement authority where disclosure is legally required.

Processors must act on documented instructions, protect confidentiality and security, and comply with agreed deletion and incident-reporting obligations. We maintain a current processor register and will update this policy if processor categories materially change.

7. Storage and Transfers

The principal Aegir data and compute environment is hosted in Microsoft Azure regions in India. SMS India Hub has represented that its relevant servers and providers are in India; i47 is obtaining and periodically refreshing confirmation of the precise processing and retention locations.

We do not intentionally transfer personal data outside India. If a transfer becomes necessary, we will assess and implement the safeguards required by applicable Indian law and any Central Government restriction before the transfer. Internet, vendor support and cloud operations can create unexpected data flows, so locations are reviewed periodically.

8. Retention and Deletion

We retain information only for the period needed for its stated purpose, the Customer's documented instructions, an agreed service period, security, dispute resolution or applicable law.

  • Member PII and unit mappings: retained while the account/association is active and removed or updated on a verified Customer instruction, subject to limited security logs and legal holds.
  • Customer administrator and commercial records: retained during the relationship and afterward for 3 years where needed for accounts, disputes or law.
  • Metered data: retained for at least three years where promised in the Customer contract and longer while the contracted service requires it. On termination it is returned, deleted or irreversibly anonymised according to the Customer agreement.
  • Raw device data: retained with same timeframe as corresponding metered data.
  • OTP, SMS delivery, support and security logs: retained no longer than 6 months.
  • Residual and redundant copies: expire according to documented Azure deletion and recovery cycles unless preserved under a lawful hold.

Removing a person's association with a unit does not require deletion of non-personal unit measurements that the Customer needs for billing, infrastructure management or usage planning. We ensure the removed person is no longer linked to that data in active systems.

9. Security

We use measures designed to protect personal data, including mobile OTP authentication, role-based access, restricted production access, encryption provided by Azure, audit logging, vulnerability assessment and service redundancy. We are strengthening privileged authentication, read/export logging, security monitoring, independent penetration testing and device-ingestion security.

No system can be guaranteed completely secure. If you suspect unauthorised access, please contact the grievance contact promptly and do not send passwords or OTPs.

10. Your Rights and Choices

Subject to applicable law, a Data Principal may request:

  • a summary of personal data being processed and processing activities;
  • correction, completion or updating of inaccurate or incomplete personal data;
  • erasure of personal data that is no longer required or lawfully retained;
  • withdrawal of consent where consent is the basis of processing;
  • redressal of a grievance; and
  • nomination of another individual to exercise rights in the event of death or incapacity.

For a Customer-managed member account, submit the request to your Customer administrator because the Customer ordinarily determines the account and unit access. You may also contact i47; we will verify and route the request without requiring you to navigate internal legal roles.

For an i47-managed Customer administrator account, contact us directly. We may ask for reasonable information to verify identity and authority. We will not disclose another person's data or data outside the requester's entitlement. If a request is refused or limited, we will provide the reason and available escalation route where required.

Operational SMS alerts may be disabled through settings page in user app or by asking the Customer administrator. Transactional OTP delivery is initiated when a login is requested and is necessary to complete that login.

11. Grievances

Send privacy questions or grievances to contact details mentioned at the beginning of this document.

Please include enough information to identify the relevant account and describe the concern, but never include an OTP. We will acknowledge and resolve grievances within the period required by applicable law and will coordinate with the relevant Customer where it is the Data Fiduciary. You may escalate an unresolved matter to the Data Protection Board of India using the process then prescribed, after giving us a reasonable opportunity to resolve it.

12. Children

The Services are intended for adults and organisations. Customers must not create an account for, or upload personal data about, a person under 18. We do not knowingly process children's personal data.

If you believe a child's personal data has been submitted, contact us immediately. We will restrict the data, notify the relevant Customer, verify the circumstances and delete it unless retention is required by applicable law. This restriction does not prevent Aegir devices from recording non-personal water usage for premises where children may live or visit.

13. Cookies and Application Technologies

We use only cookies, local storage, SDKs and similar technologies necessary for authentication, security, preferences, service operation and analytics (Google Analytics and Microsoft Clarity). Non-essential technologies, if introduced, will be subject to the notice and choice required by applicable law.

14. Changes to This Policy

We may update this policy when our Services, processors or legal obligations change. We will publish the revised version with its effective date and provide a prominent notice, and obtain fresh consent where legally required, before a material new processing purpose takes effect. Archived versions are available from the grievance contact.

15. Contact

For general service enquiries, contact hello@aegir.in. For privacy rights and grievances, use the dedicated contact mentioned at the beginning of this document.