Beta pricing ends when monitoring launches. Current customers keep their price for 12 months. Lock it in →
Privacy Policy
Last updated: July 2026 (draft)
1. Who we are
This Privacy Policy is issued by [COMPANY LEGAL NAME], operating as Ritam Labs ("we," "our," or "us"), incorporated in [JURISDICTION]. We operate the website at ritamlabs.com and the Ritam Labs audit platform.
This policy explains what information we collect when you use our website or product, how we use it, who we share it with, and the choices and rights you have over it.
Questions about this policy or your data go to [email protected].
2. What we collect
Account information
Name and email address when you create an account, plus anything you add to your profile or organization.
Billing information
Billing is handled by a third-party payment processor. We never see or store your full card number; we retain only the billing metadata (plan, amount, invoice history) needed to run your account.
Audit data
The URLs you submit for audit, and the publicly accessible page content our crawler reads from those URLs on your instruction. This includes page text, markup, headers, and metadata; we do not crawl behind logins or paywalls unless you explicitly provide access.
Usage analytics
Website analytics (page views, referrers, device type) are collected only if you accept cookies in our consent banner. See the "Cookies" section below and our Cookie Policy.
3. How we use it
We use the information above to:
- Provide the audit platform: run audits, generate fixes, and render reports and dashboards
- Operate and secure your account, including billing and support
- Improve our analyzers and scoring, using aggregated and anonymized signals where possible
- Communicate with you about your account, your audits, and product updates
- Comply with legal obligations and enforce our Terms of Service
LLM processing disclosure
Portions of the publicly accessible page content you ask us to crawl are processed by third-party AI providers (Google, OpenAI, and Anthropic) to generate analysis, such as content quality scoring and the AI Citation Score. We sanitize crawled content before it reaches any model, and we do not permit training on your data where a provider's controls allow us to opt out. We only list a provider here once it is actually live in our analysis pipeline; providers we plan to add (e.g. Perplexity) are named on our methodology page as "coming soon" and are not processing your data yet.
4. Legal bases
Where the GDPR applies, we process personal data under these legal bases:
- Contract: account, billing, and audit data, to provide the service you signed up for
- Legitimate interests: product improvement, fraud prevention, and security monitoring
- Consent: analytics and advertising cookies, and marketing email
- Legal obligation: tax, billing, and regulatory recordkeeping
Where the Digital Personal Data Protection Act, 2023 (DPDPA) applies, we process personal data on the basis of your consent (for optional processing such as marketing) or as necessary to perform the contract you have with us, and we honor the rights and grievance-redressal obligations DPDPA sets out. See sections 7 and 12.
5. Sharing
We do not sell your personal information. We share it only with the service providers ("subprocessors") who help us run the service, each bound by contract to use your data only to provide that service to us:
- Hosting & storage: Amazon Web Services (compute hosting and S3 storage for audit reports)
- CDN / bot protection: Cloudflare
- Payment processor: for billing; card details never touch our servers
- Email delivery: Google (Gmail API), for transactional and account email
- AI / LLM providers: Google, OpenAI, and Anthropic, for the analysis described in section 3
- Error tracking: Sentry, for application error monitoring
- Site analytics: Google (Tag Manager, Analytics) and Meta, only after cookie consent — see section 9
A dedicated, continuously updated subprocessor page is planned; until it ships, this list is the current source of truth and we will update it here when a subprocessor changes.
We may also disclose information if required by law, or as part of a merger, acquisition, or asset sale, with notice to you beforehand where practicable.
6. Retention
We keep personal data only as long as we need it:
- Account data: for as long as your account is active, plus 90 days after closure to handle disputes or restoration requests
- Audit data and reports: for the retention period attached to your plan, then deleted; you can delete a report at any time from your dashboard
- Billing records: retained as required by applicable tax and accounting law
- Analytics data: retained in aggregate form per the retention window of the analytics provider (see our Cookie Policy)
7. Your rights
Depending on your location, you may have the right to:
- Access: request a copy of the personal data we hold about you
- Correction: ask us to fix inaccurate or incomplete data
- Deletion: ask us to delete your personal data, subject to what we must retain by law
- Portability: request your data in a machine-readable format
- Objection / withdrawal: object to processing based on legitimate interests, or withdraw consent at any time
To exercise any of these rights, email [email protected]. No form required. We respond within 30 days.
8. International transfers
Our subprocessors operate globally, so your data may be transferred to and processed in countries other than your own, including the United States. Where required, we rely on standard contractual clauses or an equivalent safeguard with each subprocessor to protect data that leaves your jurisdiction.
9. Cookies
Our website uses a strictly-necessary cookie to remember your cookie choice, and, only if you accept in our banner, Google Tag Manager, Google Analytics, and a Meta Pixel (loaded through Tag Manager) for site analytics and advertising measurement. If you reject or dismiss the banner, none of those cookies are set and none of those scripts load.
The full list of cookies, what each one does, and how to withdraw consent lives on our Cookie Policy.
10. Children
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, contact us and we will delete it.
11. Changes
We may update this Privacy Policy from time to time. When we make a material change, we will update the "Last updated" date above and keep a versioned archive of prior policies available on request. Continued use of the service after a change is published means you accept the update.
12. Grievance officer (DPDPA)
As required by India's Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to handle complaints about how we handle your personal data: