Legal

    Privacy Policy

    Last updated: 20 July 2026 | Effective: 20 July 2026 | Version 1.0 (Private Beta)

    1. Introduction

    This Privacy Policy explains how Aeza Innovations Private Limited (CIN U63122AP2025PTC120051, registered office at H No. 26/9/419/26-3, Revenue Ward No. 26-III, Bhaktavatsalanagar, Nellore 524003, Andhra Pradesh) ("Aeza", "we", "us" or "our") collects, uses, shares and protects your personal data when you use the Aeza platform, including our website, mobile application and related services (the "Service").

    For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it, Aeza is the Data Fiduciary and you are the Data Principal. We also comply with the Information Technology Act, 2000 and the rules made under it, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent applicable.

    This Policy should be read together with our Terms of Use, Consent Notice and Cookie Notice. By using the Service you acknowledge that you have read this Policy. Where the law requires consent for processing, we will rely on the consent you give through the Consent Notice, not on this acknowledgement.

    2. Personal data we collect

    Account and identity data. Name, email address, phone number, date of birth or confirmation that you are 18 or older, login credentials, and beta invite details.

    Style and preference data. Style preferences, brand and category preferences, likes, dislikes, saved items, quiz or onboarding responses, and interactions with recommendations.

    Body measurement data. Measurements you choose to provide for size and fit recommendations, such as height, weight, and garment sizes.

    Photographs. Photographs of yourself that you choose to upload to use the virtual try-on feature, and the try-on renders generated from them.

    Usage and device data. Log data, pages and screens viewed, features used, search queries within the Service, device type, operating system, app version, browser type, IP address, approximate location derived from IP, identifiers, crash reports and diagnostics.

    Communications data. Messages you send us, support requests, survey responses and feedback.

    Cookies and similar technologies. As described in our Cookie Notice.

    We do not knowingly collect personal data from persons under 18. We do not ask for, and you should not submit, financial account details, passwords for other services, official identifiers such as Aadhaar or PAN, or health information.

    3. How we collect personal data

    We collect personal data: (a) directly from you, when you register, complete onboarding, provide measurements, upload photographs, or communicate with us; (b) automatically, through your use of the Service, using cookies and similar technologies; and (c) from service providers that help us operate the Service, such as analytics providers.

    4. Purposes of processing

    We process your personal data for the following purposes:

    • Providing the Service: creating and managing your account, generating personalised recommendations, size and fit suggestions and virtual try-on renders, and operating discovery features;
    • Improving the Service: analytics, debugging, testing, understanding feature usage during the beta, and improving the quality, safety and performance of the Service and our recommendation systems;
    • Communications: service announcements, beta updates, responses to your requests, and, only if you separately opt in, marketing communications;
    • Safety and security: authenticating users, preventing fraud and abuse, enforcing our Terms of Use, and protecting the Service and its users;
    • Legal compliance: complying with applicable law, responding to lawful requests, and establishing, exercising or defending legal claims.

    We will not process your personal data for purposes incompatible with those notified to you without giving you notice and, where required, obtaining your consent.

    6. Photographs and body measurements: special handling

    Photographs and body measurements are treated with heightened care. Unless you give us separate, explicit consent for a different use:

    • photographs you upload are used solely to generate virtual try-on renders for you and to operate, secure and debug that feature; this processing is carried out on our systems and through third-party AI model providers acting on our documented instructions;
    • our third-party providers are contractually required to use your data only to provide services to us, and not for their own independent purposes;
    • we do not use your photographs to perform facial recognition for identification purposes, to identify you across other services, or to build biometric profiles;
    • we do not use your photographs or renders to train or improve our models, unless you separately opt in to the optional consent described in the Consent Notice;
    • we do not sell your photographs or measurements, and we do not share them with brand partners or advertisers;
    • uploaded photographs and renders are retained until you delete them or your account is deleted, whichever is earlier; beta data may also be reset as described in the Terms of Use; and
    • you can delete your uploaded photographs and renders at any time through the Service or by writing to ayush.shetty@aeza.in.

    7. Cookies and analytics

    We use cookies and similar technologies as described in our Cookie Notice, available at aeza.in and in the app. During the beta we use product analytics tools to understand feature usage; a current list of tools is available on request. We do not use third-party advertising cookies during the beta.

    8. How we share personal data

    We do not sell personal data. We share personal data only as follows:

    • Service providers (data processors): providers that process personal data on our behalf and under our instructions, including cloud hosting and storage (Amazon Web Services, on infrastructure located in India), third-party AI model providers used to generate recommendations, size suggestions and try-on renders, product analytics tools, email and communications delivery providers, and security and monitoring tools. A current list of providers is available on request at ayush.shetty@aeza.in. These providers are bound by contracts requiring them to protect your data and use it only to provide services to us;
    • Brand and retail partners: aggregated or de-identified insights only (for example, category-level demand trends). We do not share your photographs, measurements, identity or contact details with brand partners without your separate, explicit consent;
    • Legal and safety: where required by law, regulation, legal process or enforceable governmental request, or where necessary to enforce our Terms, protect our rights, or protect the safety of any person;
    • Corporate transactions: in connection with a merger, acquisition, financing or sale of assets, in which case we will ensure continued protection of your personal data and notify you as required by law; and
    • Professional advisers: auditors, lawyers and similar advisers under duties of confidentiality.

    9. Cross-border transfers

    Your personal data is hosted and stored on Amazon Web Services infrastructure located in India. Certain service providers, including third-party AI model providers, may process personal data on systems located outside India in the course of providing services to us. Any such transfer or processing is carried out in accordance with the DPDP Act and the rules made under it, including any restrictions notified by the Central Government on transfers to specific countries, and we require our providers to apply protections consistent with this Policy.

    10. Retention

    We retain personal data only as long as necessary for the purposes described in this Policy or as required by law. In particular: uploaded try-on photographs are deleted as described in Section 6; if you delete your account, we delete or anonymise your personal data within 90 days, except data we must retain to comply with law, resolve disputes or enforce agreements; security and access logs are retained for at least one year where required by applicable rules; and beta data may be deleted earlier as described in the Terms of Use. When personal data is no longer required, we delete it or irreversibly anonymise it.

    11. Security

    We implement reasonable security safeguards designed to protect personal data against unauthorised access, disclosure, alteration and destruction, including encryption of data in transit, access controls and logging, environment segregation, and vendor security review. No system is completely secure; you are responsible for keeping your login credentials confidential. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act and applicable rules.

    12. Your rights

    Subject to applicable law, you have the right to:

    • Access: obtain a summary of the personal data we process about you and the processing activities undertaken;
    • Correction and erasure: correct, complete or update your personal data, and request erasure of personal data no longer necessary for the purpose for which it was processed;
    • Withdraw consent: withdraw any consent you have given, at any time, with effect for the future, through your account settings or by writing to ayush.shetty@aeza.in;
    • Grievance redressal: raise a complaint with our Grievance Officer as described in Section 15; and
    • Nomination: nominate another individual to exercise your rights in the event of your death or incapacity.

    To exercise your rights, use the in-product controls or write to ayush.shetty@aeza.in from your registered email address. We may need to verify your identity before acting on a request. We will respond within the timelines prescribed by applicable law. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

    13. Children

    The Service is intended for persons aged 18 and above. We do not knowingly process the personal data of children. If you believe a person under 18 has provided personal data to us, contact us at ayush.shetty@aeza.in and we will delete it.

    14. Third-party websites

    The Service links to third-party brand and retailer websites. This Policy does not apply to those websites. Review the privacy policies of any third-party site you visit; purchases made on third-party sites are governed by those parties' terms and privacy practices.

    15. Grievance Officer and complaints

    Our Grievance Officer for the purposes of the Information Technology Act, 2000, the rules under it, and the DPDP Act is:

    • Name: Ayush Shetty
    • Designation: Grievance Officer, Aeza Innovations Private Limited
    • Email: ayush.shetty@aeza.in
    • Address: H No. 26/9/419/26-3, Revenue Ward No. 26-III, Bhaktavatsalanagar, Nellore 524003, Andhra Pradesh

    We will acknowledge grievances within 24 hours and endeavour to resolve them within 15 days, or within such period as applicable law prescribes. Details of the process appear in our Grievance Redressal Notice. If you are not satisfied, you may escalate to the Data Protection Board of India.

    16. Changes to this Policy

    We may update this Policy from time to time. Material changes will be notified through the Service or by email, and the "Last updated" date above will be revised. Where changes require fresh consent under applicable law, we will seek it.

    17. Contact

    Aeza Innovations Private Limited, H No. 26/9/419/26-3, Revenue Ward No. 26-III, Bhaktavatsalanagar, Nellore 524003, Andhra Pradesh. Privacy queries: ayush.shetty@aeza.in.

    Related: Terms of Use

    Aeza Innovations Private Limited, Bengaluru. aeza.in