This policy explains, in plain terms, what personal data Raydian Technologies Private Limited handles and what we do with it. It is written to be checked rather than skimmed — if a claim here cannot be verified against how we actually operate, treat that as a bug and tell us at legal@raydian.ai.
1.Who we are
Raydian Technologies Private Limited (“Raydian”, “we”, “us”) is a company incorporated in India with its registered office in Ernakulam, Kerala. We build AI software for project planning and execution, and we operate the website at raydian.ai and the Raydian platform.
For the personal data described in this policy, Raydian is the data controller (under the GDPR and UK GDPR) and the data fiduciary (under India's Digital Personal Data Protection Act, 2023). That means we decide why and how the data is processed, and we are accountable for it.
| Detail | Value |
|---|---|
| Legal entity | Raydian Technologies Private Limited |
| CIN | U62010KL2025PTC098182 |
| Registered office | GFX33, 69/1854 A1, SRM Road, Nirmala Shishu Bhavan, Ernakulam North, Ernakulam 682018, Kerala, India |
| Privacy contact | legal@raydian.ai |
| General contact | hello@raydian.ai |
2.Scope
This policy covers:
- the public website at raydian.ai, including its contact and waiting-list forms;
- the Raydian platform available to signed-in users;
- our internal, self-hosted social scheduling tool, which authorised Raydian team members use to publish and schedule content to Raydian's own LinkedIn presence through the LinkedIn API; and
- our use of third-party APIs and services in connection with the above.
This policy does not cover:
- third-party websites and platforms we link to or integrate with, including LinkedIn itself. Your use of LinkedIn is governed by LinkedIn's own Privacy Policy;
- content that a customer chooses to put into the platform about their own end users — for that content the customer is the controller and we act as a processor on their instructions; and
- recruitment, employment, and supplier relationships, which are handled under separate notices.
3.Information we collect
3.1 Information you give us directly
When you fill in a form, sign up, or write to us, we receive what you type. In practice that is your name, work email address, company name, and the content of your message. If you create an account, we also hold your account credentials, workspace name, role, and any profile details you add.
We do not ask for financial account numbers, government identifiers, health data, or any other special category of data through these forms. Please do not send them to us.
3.2 Information collected automatically
When you visit the website, our servers and analytics tools record your IP address, user agent (browser and operating system), the pages you view, the referring URL, and timestamps.
We do use analytics. Specifically, we run Google Analytics 4 and Microsoft Clarity. Google Analytics loads on all visits; Microsoft Clarity, which records session interactions such as clicks and scrolling, loads only after you opt in through our cookie banner. See Cookies for how to change that choice.
3.3 Information received from LinkedIn
This is the most specific part of this policy, because it describes data we receive from a third-party platform rather than from you directly.
We never receive LinkedIn data by default. A Raydian team member must first click “Connect LinkedIn” in our internal scheduling tool and complete LinkedIn's own OAuth 2.0 consent screen, where LinkedIn shows exactly which permissions are being requested. Only after that member grants consent does LinkedIn return anything to us. No LinkedIn data is collected from visitors to this website.
What we receive and store as a result:
- OAuth tokens. An access token and, where LinkedIn issues one, a refresh token. These are credentials, not profile data — they let us call the LinkedIn API as the connecting member until the token expires or is revoked.
- Member identity data returned by the scopes we request: the member identifier (“sub”), name, profile picture URL, and — where the
emailoropenid profilescopes are granted — the email address on the member's LinkedIn account. - Organization data for company-page posting: the organization ID and basic page metadata (page name, logo, and the administrator role the member holds on that page).
- Content we send on the member's behalf: the post text, any media the member attaches, and the scheduling metadata (intended publish time, target account or page, status).
- Engagement data LinkedIn returns for those posts: the post URN, publication status, and aggregate metrics such as impressions, clicks, reactions, comment counts, and shares.
We request the narrowest set of scopes that lets the tool work. The table below lists each one, what it exposes, and why we need it.
| Scope | Data it exposes | Why we need it |
|---|---|---|
openid | A stable, LinkedIn-issued member identifier (sub). | To recognise which LinkedIn member is connected, so tokens and posts are attributed to the right person. |
profile | Member name, profile picture URL, and public profile URL. | To display which account is connected in the tool, so a team member can confirm they are posting from the intended account. |
email | The primary email address on the member's LinkedIn account. | To distinguish between multiple connected accounts and to notify the member if their connection breaks. |
w_member_social | Permission to create, edit, and delete posts as the member. | To publish or schedule the specific posts that member has authored and authorised in the tool. |
r_organization_admin | Organization ID and page metadata for pages the member administers. | To list the company pages the member may post to, and to confirm they actually hold that admin role. |
w_organization_social | Permission to publish posts to an administered company page. | To publish scheduled content to the Raydian company page. |
r_organization_social | Read access to posts and their engagement metrics for the administered page. | To report back how the posts we published performed. |
4.How we use information
Each purpose below is tied to the data described above. We do not use data for purposes not listed here.
| Data | What we use it for |
|---|---|
| Name, work email, company, message content | To answer your enquiry, send you the information you asked for, and keep a record of the correspondence. |
| Account and workspace details | To create and secure your account, apply your workspace role and permissions, and provide the platform. |
| IP, user agent, pages viewed, referrer | To keep the service secure and available, diagnose faults, prevent abuse, and understand which pages are useful. |
| LinkedIn OAuth tokens | Solely to authenticate our API calls as the connecting member. Tokens are never used for anything else. |
| LinkedIn member identity data | Solely to authenticate the connecting member and display which LinkedIn account is currently connected. |
| LinkedIn organization data | Solely to list the company pages a member may post to and to confirm their admin role. |
| Post content and scheduling metadata | Solely to publish or schedule the content that member has authorised, at the time they chose. |
| LinkedIn engagement metrics | Solely to report back the performance of posts we published, to the member who published them. |
To state it plainly: LinkedIn data is used only to authenticate the connecting member, show which account is connected, publish or schedule the content that member has authorised, and report performance of those posts back to them. Nothing else.
5.What we explicitly do not do with LinkedIn data
Standing commitments
- We do not use LinkedIn member data to train, fine-tune, benchmark, or evaluate any artificial intelligence or machine-learning model — ours or anyone else's.
- We do not sell, rent, licence, trade, or otherwise monetise LinkedIn data.
- We do not build, enrich, or maintain standalone profiles, lead lists, or shadow databases of LinkedIn members.
- We do not scrape, crawl, spider, or bulk-export LinkedIn content, and we do not use automated means to obtain LinkedIn data outside the official API.
- We do not share LinkedIn data with advertisers, ad networks, data brokers, or any similar third party.
- We do not use LinkedIn data for any purpose beyond the one the member consented to at the OAuth screen, and we do not retain it after that consent ends.
These are standing commitments, not statements of current intent that we might quietly revise. They are consistent with the LinkedIn API Terms of Use and the LinkedIn Platform Guidelines, and they apply for as long as we hold any LinkedIn data. If we ever needed to process LinkedIn data for a new purpose, we would seek fresh consent first.
6.Legal bases
If you are in the EEA or the UK, the GDPR requires us to have a lawful basis for each thing we do with your data. Here is ours, activity by activity. The same reasoning maps onto the consent and legitimate-use provisions of India's DPDP Act, 2023.
| Activity | Legal basis | Why |
|---|---|---|
| Connecting a LinkedIn account and storing tokens | Consent | The member actively grants it at LinkedIn's OAuth screen and can withdraw it at any time. |
| Publishing or scheduling a post | Consent | The member authorises each specific post. Withdrawing the connection stops all future posting. |
| Non-essential analytics (Microsoft Clarity) | Consent | Opt-in through the cookie banner; you can withdraw it at any time. |
| Providing the platform to an account holder | Performance of a contract | We cannot deliver the service you signed up for without processing your account data. |
| Billing and record-keeping | Contract and legal obligation | Required to invoice you and to meet Indian tax and accounting law. |
| Security, fraud prevention, abuse detection, and server logging | Legitimate interests | Keeping the service safe and available. We use the minimum data needed and retain it briefly. |
| Responding to an enquiry you sent us | Legitimate interests | You contacted us and expect a reply. |
8.International transfers
We run the platform on infrastructure we manage ourselves rather than on a managed SaaS backend: a virtual private server provided by Hostinger International Ltd., located in India. Our company is established in India, and our personnel administer these systems from India.
Where personal data of individuals in the EEA or the UK is transferred outside those areas — for example when our team in India administers the systems — we rely on the European Commission's Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum) as the transfer mechanism, supported by a transfer risk assessment and the technical measures described in Storage, security, and retention.
Under India's DPDP Act, 2023, transfers outside India are permitted except to countries the Central Government restricts. We monitor that list and will update this policy if it affects us.
You can ask us for details of the safeguards in place by writing to legal@raydian.ai.
9.Storage, security, and retention
9.1 How we protect data
- OAuth tokens are encrypted at rest and are never exposed to the browser, never written to client-side storage, and never included in any API response to a front-end client. They are transmitted only over TLS, server to server.
- Encryption in transit. All traffic to raydian.ai and our APIs is served over TLS. Plain HTTP requests are permanently redirected to HTTPS, and HTTP Strict Transport Security is enabled.
- Least privilege. Database credentials are scoped to the minimum permissions each service needs. Administrative access to production is restricted to named, authorised personnel on a need-to-know basis.
- Access logging. Administrative and API access to production systems is logged, and those logs are reviewed when investigating an incident.
- Separation of secrets. Credentials and tokens are held in server-side configuration, outside the application code and outside any client bundle.
No system is perfectly secure, and we will not claim otherwise. If a personal data breach occurs that is likely to result in risk to you, we will notify the relevant supervisory authority and affected individuals as required by law — including notification to the Data Protection Board of India under the DPDP Act and, where the GDPR applies, within 72 hours of becoming aware.
9.2 How long we keep it
We keep personal data only as long as we need it for the purpose we collected it for.
| Data | Retention period |
|---|---|
| Contact-form and waiting-list submissions | 24 months from your last contact with us, then deleted. |
| Server and access logs | 90 days, then rotated out automatically. |
| LinkedIn OAuth access and refresh tokens | Only while the connection is active. Deleted within 30 days of disconnection, revocation, or token expiry without renewal. |
| LinkedIn profile and organization data held for display | Only while the connection is active. Deleted within 30 days of disconnection or revocation. |
| Published-post records (text, media references, schedule, returned metrics) | 24 months from publication, so performance can be reported over time. Deleted sooner on request. |
| Account and workspace records | For the life of the account, then deleted within 90 days of closure. |
| Invoices and financial records | Eight years, as required by section 128 of the Companies Act, 2013 and Indian tax law. |
Deletion of LinkedIn data
10.Your rights and controls
Depending on where you live, you have some or all of the following rights over your personal data:
- Access — a copy of the data we hold about you, and a summary of how we use it.
- Correction — to have inaccurate or incomplete data fixed.
- Deletion — to have your data erased where we no longer have a reason to keep it.
- Portability — to receive your data in a structured, machine-readable format.
- Objection and restriction — to object to processing based on legitimate interests, or to ask us to pause processing while a dispute is resolved.
- Withdrawal of consent — to withdraw consent at any time, without affecting processing that already happened. Withdrawing is as easy as giving it.
- Nomination — under India's DPDP Act, to nominate someone to exercise these rights on your behalf if you die or become incapacitated.
- Complaint — to complain to your data protection authority. In India that is the Data Protection Board; in the EEA, your national supervisory authority; in the UK, the ICO.
To exercise any of these, email legal@raydian.ai. We will acknowledge within 72 hours and respond substantively within 30 days. If a request is complex and we need longer, we will tell you why before that deadline passes. We may need to verify your identity first, and we will not charge you unless a request is manifestly excessive or repetitive.
10.1 How to revoke LinkedIn access
There are two independent places to do this. Doing either one stops us posting; doing both is the most thorough.
Option A — disconnect inside our tool
- Sign in to the Raydian social scheduling tool.
- Open Settings → Connected accounts.
- Find the LinkedIn connection and choose Disconnect.
- Confirm. Any scheduled posts that have not yet gone out are cancelled, and we begin deleting the stored tokens and profile data — completed within 30 days.
Option B — revoke at LinkedIn
- Sign in to LinkedIn.
- Go to Settings & Privacy → Data privacy → Other applications → Permitted services, or open linkedin.com/psettings/permitted-services.
- Find the Raydian application in the list and select Remove.
- LinkedIn immediately invalidates our tokens. We delete our stored copies and the associated profile data within 30 days.
If you would rather we deleted everything immediately instead of waiting out the 30-day window, email legal@raydian.ai and we will do it on request.
12.Children
Raydian is a business tool. It is not directed to anyone under 18, and we do not knowingly collect personal data from children. Consistent with India's DPDP Act, 2023, we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
If you believe a child has given us personal data, write to legal@raydian.ai and we will delete it promptly.
13.Compliance references
This policy is written to meet the following:
- Digital Personal Data Protection Act, 2023 (India) — we act as a data fiduciary, process personal data for lawful purposes with notice and consent, honour data principal rights, and have appointed a Grievance Officer.
- Information Technology Act, 2000 and the SPDI Rules, 2011 (India) — we maintain reasonable security practices and procedures for sensitive personal data or information, publish this policy, and provide a grievance mechanism.
- GDPR (EU) 2016/679 and the UK GDPR — for individuals in the EEA and the UK, we identify a lawful basis for each activity, honour data subject rights, apply transfer safeguards, and meet breach notification duties.
- CCPA/CPRA (California) — California residents have the right to know what personal information we collect and why, to request deletion or correction, to request a portable copy, and to be free from discrimination for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information beyond the purposes permitted by that law, so we offer no “Do Not Sell or Share My Personal Information” link. Requests can be sent to legal@raydian.ai and may be made by an authorised agent.
Our use of the LinkedIn API is additionally governed by the LinkedIn API Terms of Use and the LinkedIn Platform Guidelines, which we comply with as a condition of access.
14.Grievance Officer
As required by the Information Technology Act, 2000 and the DPDP Act, 2023, we have appointed a Grievance Officer to receive and address complaints about how we handle personal data.
| Detail | Value |
|---|---|
| Name | Abdul Adil Basheer |
| Designation | Grievance Officer |
| legal@raydian.ai | |
| Postal address | GFX33, 69/1854 A1, SRM Road, Nirmala Shishu Bhavan, Ernakulam North, Ernakulam 682018, Kerala, India |
The Grievance Officer acknowledges every complaint within 24 hours and resolves it within 15 days of receipt. If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India, or to your own supervisory authority if you are in the EEA or the UK.
15.Changes to this policy
We update this policy when our practices change, when we add or remove a processor, or when the law requires it. The Last updated date at the top of this page always reflects the version you are reading.
For material changes — a new purpose, a new category of data, or a new recipient — we will give notice before the change takes effect: by email to account holders, by a notice in the product, and by a prominent note on this page. Where the change requires your consent, we will ask for it rather than assume it. Minor clarifications and typographical corrections are made without notice.
Superseded versions are available on request from legal@raydian.ai.
16.Contact us
Questions about this policy, or about anything we do with your data, are welcome. We would rather answer them than have you guess.
Raydian Technologies Private Limited
GFX33, 69/1854 A1, SRM Road, Nirmala Shishu Bhavan, Ernakulam North, Ernakulam 682018, Kerala, India
Privacy matters: legal@raydian.ai
General enquiries: hello@raydian.ai
Grievances: legal@raydian.ai