Effective Date: 15 August 2022
Last Updated: September 2026
This privacy policy ("Policy") explains how Scribble Data Private Limited or any of its affiliates or subsidiaries ("Scribble Data", "We", "Us", "Our") processes Personal Data collected from You in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and DPDP Rules, 2025, and with other data protection laws that apply to You, including the General Data Protection Regulation of the European Union and of the United Kingdom where they apply. This Policy applies to Our Website(s), Scribble Products and the Public Services described in Section 1.
September 2026: This Policy now covers Carver ELI and the Public Services, including the descriptions and documents You submit, records of Your acceptance of Our terms, requests You ask Us to pass to lawyers or insurance providers, and use of Our MCP servers. We have also restored information for individuals outside India and clarified Our security, breach notification and change notification practices.
February 2026: This Policy was updated to reflect India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Changes included:
• Enhanced consent management procedures
• Data breach notification procedures
• Expanded Data Principal rights and grievance mechanisms
• Multilingual privacy notice availability
Terms not specifically defined herein shall have the meaning ascribed thereto in the License Agreement, Service Agreement, or the DPDP Act, 2023.
1.1. "Data Fiduciary" means any person who alone or in conjunction with others determines the purpose and means of processing of Personal Data. Scribble Data acts as a Data Fiduciary when collecting Personal Data as described in Section 2.
1.2. "Data Principal" means the individual to whom the Personal Data relates. In this Policy, "You" and "Your" refer to Data Principals.
1.3. "Data Processor" means any person who processes Personal Data on behalf of a Data Fiduciary.
1.4. "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
1.5. "Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organization, storage, adaptation, use, disclosure, or erasure.
1.6. "Data Protection Board" means the Data Protection Board of India established under Section 18 of the DPDP Act.
1.7. "Website(s)" means the websites that We own and operate, including carveragents.ai, eli.carveragents.ai, scribbledata.io and ismyagentlegal.com, agentobligations.com, agentlegalcheck.com, checkagentliability.com, agentlegalrisk.com, ismyagentinsurable.com, underwritemyagent.com, findagentinsurance.com, agentinsurancefinder.com, agentlegalcontext.com, agentlegalapi.com, agentcomplianceapi.com.
1.8. "Scribble Products" means the platforms and services made available by Scribble Data, including Scribble Enrich, Scribble Hasper, Carver Agents and Carver ELI, whether deployed on-premises, in hosted environments or as Software-as-a-Service (SaaS).
1.9. "Public Services" means Carver ELI and the Website(s), Model Context Protocol (MCP) servers and other programmatic interfaces, tools, reports and other outputs that We make available to the public, with or without an account, as described in the Carver Public Services Terms at https://www.carveragents.ai/public-services-terms.
1.10. "Submission" means any description, document, answer or other content You provide to the Public Services, for example a description of an AI agent or a product requirements document.
2.1. Data You Provide Directly:
a) Account Information: When You purchase a license or subscription to Scribble Products, We collect Your name, email address, billing address, phone number, and authentication information.
b) Website Interactions: When You submit forms, provide feedback, participate in surveys, or use interactive features on Our Website(s).
c) Event Participation: Contact information collected when You attend webinars, seminars, or visit Our office.
d) Employment Applications: Resume and related information when You apply for positions with Us.
e) Public Services Submissions: The descriptions, documents and answers You submit to the Public Services, and the results We generate from them. Attached documents are read once to extract their text and are not kept. Submissions should describe Your product or AI agent. Please do not include Personal Data about other people, or sensitive Personal Data, in a Submission unless it is necessary.
f) Verification and Requests: Your email address when You verify it to see results or obtain MCP access, and the contact details and information You provide when You ask Us for a full report, an introduction to a lawyer, or an insurance quote.
2.2. Data We Collect Automatically:
a) Technical Information: Device type, operating system, IP address when You use Scribble Products or visit Our Website(s).
b) Cookies and Similar Technologies: As described in Section 11 (Cookie Policy).
c) Public Services and MCP Usage: Assessment identifiers, access key identifiers, request and response metadata, IP address, user agent, timestamps, and the website or client from which a request was made. This includes requests made by software or AI agents acting for You.
d) Records of Acceptance: When You accept the Public Services Terms or acknowledge that the Public Services are not legal advice, We record the version accepted, the time, the website used, a hashed form of Your IP address and Your user agent.
2.3. Data from Third Parties: We may receive Personal Data from business partners, social media platforms, marketing databases, and single sign-on services, but only where We have verified that these third parties have appropriate legal basis to share Your data with Us.
3.1. DPDP Act Compliance (Indian Residents):
Under the DPDP Act, We process Your Personal Data on the following legal bases:
a) Consent: For most processing activities, We obtain Your free, specific, informed, unconditional, and unambiguous consent through clear affirmative action.
b) Legitimate Uses: As permitted under Section 7 of the DPDP Act, including:
• Performance of contracts and service delivery
• Compliance with legal obligations
• Prevention and detection of fraud
• Employment-related processing
3.2. How We Obtain Consent:
When We collect Your Personal Data, We provide a clear privacy notice that includes:
• Description of Personal Data being collected
• Purpose for which data will be processed
• How You can exercise Your rights (access, correction, erasure)
• How to withdraw consent
• How to file complaints with the Data Protection Board
3.3. Right to Withdraw Consent:
You may withdraw Your consent at any time by:
• Contacting Our Privacy Officer at legal@carveragents.ai
• Using the consent management tools provided in Your account settings
• Clicking 'unsubscribe' links in marketing communications
Upon withdrawal, We will cease processing Your Personal Data for that purpose, except where We have a legal obligation to retain it.
3.4. Children's Data:
We do not knowingly collect Personal Data from children under 18 years of age without verifiable parental or guardian consent. If We collect data from children, We obtain consent through mechanisms verified by:
• Existing information on record
• Details provided by parent/guardian
• Virtual tokens from authorized entities or Digital Locker verification
3.5. Individuals in the European Economic Area, United Kingdom and Switzerland:
Our legal basis for collecting and using Personal Data depends on the Personal Data concerned and the context in which We collect it. We normally collect Personal Data from You only where We need it to perform a contract with You, where the Processing is in Our legitimate interests and not overridden by Your data protection interests or fundamental rights and freedoms, or where We have Your consent. In some cases We may also have a legal obligation to collect Personal Data from You. Our legitimate interests include providing, securing and improving the Public Services and preventing their misuse.
3.6. Individuals in Other Jurisdictions:
For individuals in other jurisdictions, including California, We Process Personal Data in accordance with the data protection laws that apply to You.
We process Your Personal Data only for specific, explicit, and legitimate purposes:
a) Facilitate access to Website(s) and Scribble Products
b) Process and complete payment transactions
c) Provide product updates, new features, and service communications
d) Perform contractual obligations
e) Organize events and conduct marketing activities (with separate consent)
f) Investigate and prevent fraud, unauthorized access, and illegal activities
g) Personalize Website(s) and Scribble Products
h) Evaluate job applications
i) Technical support and customer service
j) Security and integrity of Scribble Products
k) Improve services and conduct research (anonymized where possible)
l) Provide the Public Services, including generating assessments, reports and exports from Your Submissions, and responding to Your requests
m) Pass Your request and the information You choose to include to a lawyer, insurance provider or insurance intermediary, where You ask Us to
n) Keep records of acceptance of Our terms, enforce Our terms, and establish, exercise or defend legal claims
o) Maintain and improve the Public Services using Submissions and results, in de-identified or aggregated form where practicable
p) Contact You about Your assessment and about Carver's services, where You have verified an email address, with Your consent where applicable law requires it
Use of AI Tools: We use Our own and third-party software that incorporates artificial intelligence, including large language models, to provide the Public Services and other Scribble Products. Submissions and related Personal Data are processed by these tools to generate results. The providers of these tools act as Our Data Processors (see Section 6.1).
De-identified and Aggregated Data: We may de-identify or aggregate Personal Data so that it can no longer be linked to You. We keep and use such data in de-identified form, do not attempt to re-identify it except where applicable law permits, and may use it for any purpose.
5.1. Definition of Personal Data Breach:
Under the DPDP Act, a Personal Data Breach means any unauthorized processing, accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to Personal Data that compromises confidentiality, integrity, or availability.
5.2. Our Notification Obligations:
In the event of a Personal Data Breach, We will notify the persons and authorities that applicable law requires, in the manner and within the time that applicable law requires. Under the DPDP Act and DPDP Rules, 2025, this includes:
a) Intimating the Data Protection Board of India, including a detailed report within the period prescribed by the DPDP Rules, 2025 (currently 72 hours of becoming aware of the breach, unless the Board allows a longer period)
b) Intimating affected Data Principals without delay
5.3. Breach Notification Contents:
Our breach notifications will include the information required by applicable law, which may include:
• Nature and extent of the breach
• Categories and approximate number of affected Data Principals
• Types and approximate volume of Personal Data involved
• Date, time, and location of the breach
• Likely consequences of the breach
• Measures taken or proposed to mitigate harm
• Contact information for further inquiries
6.1. Data Processors:
We share Personal Data with Data Processors who provide services on Our behalf, including:
• Cloud hosting providers (Google Cloud Platform)
• Providers of AI models and related services that process Submissions to generate results
• Payment processing services
• Analytics and monitoring services
• Marketing and communication platforms
We require Data Processors, by contract, to process Personal Data only on Our instructions and to maintain appropriate security measures.
6.2. Legal Disclosure:
We may disclose Personal Data when required by law, including:
• Response to lawful requests by public authorities
• Compliance with court orders or legal processes
• Protection of Our legal rights
• Prevention of fraud or illegal activities
6.3. Third Parties at Your Request:
If You ask Us for an introduction to a lawyer, or for an insurance quote, We share Your request and the information You choose to include with the lawyer, insurance provider or insurance intermediary concerned. They are independent of Us and handle Your Personal Data under their own privacy policies. We are not responsible for their practices.
6.4. Business Transfers:
We may share Personal Data with an entity to which We divest all or a portion of Our business, or otherwise in connection with a merger, consolidation, change in control, reorganization or liquidation of all or a portion of Our business.
6.5. No Sale of Personal Data:
We do not sell Personal Data for money. [Counsel: confirm whether advertising cookies (Section 11.2(d)) amount to "sharing" under California law, and add an opt-out link if so.]
7.1. Cross-Border Transfers:
We may transfer Personal Data outside India to:
• Our affiliates and subsidiaries
• Data Processors providing services
• Cloud infrastructure providers (including United States)
7.2. Safeguards:
We take the following steps for international transfers, including those required by Section 16 of the DPDP Act:
a) Transferring data only to countries not restricted by the Indian Government
b) Implementing Standard Contractual Clauses approved by authorities
c) Ensuring recipients provide adequate data protection standards
d) For SaaS deployments using Google Cloud Platform, relying on EU-US Data Privacy Framework and Google's Standard Contractual Clauses
e) For Personal Data of individuals in the European Economic Area, United Kingdom or Switzerland that is Processed outside those regions, relying on an adequacy decision, Standard Contractual Clauses approved by the relevant authorities, or another transfer mechanism permitted by law
8.1. Retention Principles:
We retain Personal Data only as long as necessary for the purposes stated in this Policy or as required by law.
8.2. Specific Retention Periods:
a) Account Data: Duration of active subscription plus 7 years for financial records
b) Marketing Data: Until consent is withdrawn or 3 years of inactivity
c) Technical Logs: 90 days unless required for security investigation
d) Job Applications: 1 year from application date
e) Unclaimed Assessments: An assessment, including its Submission and results, that is not claimed by verifying an email address is deleted after 30 days
f) Attached Documents: Read once to extract their text, and not kept
g) Claimed Assessments and Contact Details: Kept until You ask Us to remove them, subject to Section 8.1
h) Requests Passed to Third Parties: Up to 2 years from the request
i) Records of Acceptance: For as long as needed to establish, exercise or defend legal claims, and in any case no longer than 7 years
j) MCP Logs: 90 days unless required for security investigation
8.3. Deletion Procedures:
When retention periods expire or consent is withdrawn, We will securely delete or anonymize Personal Data unless legal obligations require continued retention. We also instruct Our Data Processors to delete Your data.
We implement reasonable security safeguards, as required under Section 8 of the DPDP Act, which include measures such as:
• Encryption: Encryption of data in transit and at rest
• Access Controls: Role-based access, multi-factor authentication, principle of least privilege
• Security Monitoring: Intrusion detection, vulnerability assessments and penetration testing
• Security Frameworks: Security practices informed by recognized frameworks such as SOC 2 and ISO 27001. [Counsel: name a certification here only if one is currently held.]
• Incident Response: Documented procedures for breach detection and response
• Employee Training: Regular security awareness and DPDP compliance training
No method of transmission over the internet or of electronic storage is completely secure. While We work to protect Your Personal Data, We cannot guarantee its security.
Under the DPDP Act, You have the following rights:
10.1. Right to Access:
You can request:
• Summary of Personal Data being processed
• Identities of Data Fiduciaries and Data Processors with access
• Other relevant information about data processing activities
10.2. Right to Correction and Completion:
You can request correction of inaccurate Personal Data or completion of incomplete Personal Data.
10.3. Right to Erasure:
You can request deletion of Your Personal Data, except where We have a legal obligation to retain it.
10.4. Right to Withdraw Consent:
You can withdraw consent at any time. This will not affect the lawfulness of processing conducted prior to withdrawal.
10.5. Right to Grievance Redressal:
You can file grievances regarding Personal Data processing with Our Privacy Officer or directly with the Data Protection Board of India.
10.6. Right to Nominate:
You may nominate another individual to exercise Your rights in the event of death or incapacity.
10.7. How to Exercise Your Rights:
Contact Our Privacy Officer at: legal@carveragents.ai
We aim to respond to Your requests within a reasonable timeframe, typically within 30 days of verification, and within any period that applicable law requires.
For marketing communications, click 'unsubscribe' in emails or contact Us directly.
10.8. Rights Under Other Laws:
If You are in the European Economic Area, United Kingdom or Switzerland, You may also object to or ask Us to restrict Processing of Your Personal Data, ask for portability of Your Personal Data, and complain to Your local supervisory authority. Residents of other jurisdictions, including California, may have additional rights under the laws that apply to them.
10.9. Public Services Without an Account:
To exercise Your rights over a Submission or result, contact Our Privacy Officer and include the assessment key or the email address You used. We may need to verify Your request before acting on it.
11.1. What Are Cookies:
Cookies are small text files placed on Your device that collect information about Your browsing behavior. Under the DPDP Act, cookies that collect Personal Data require Your consent.
11.2. Types of Cookies We Use:
a) Essential Cookies (No Consent Required): Enable core functionality like security, authentication, and network management. You cannot opt out of these cookies, but may disable them in browser settings.
b) Analytics Cookies (Consent Required): Help Us understand website usage through aggregated data.
c) Customization Cookies (Consent Required): Remember Your preferences and settings.
d) Advertising Cookies (Consent Required): Track website visits to deliver relevant advertisements.
11.3. Cookie Consent Management:
We use a consent management platform (currently CookieYes) to:
• Display cookie consent banners with clear choices
• Provide granular consent options by cookie category
• Record and store consent preferences
• Allow easy withdrawal or modification of consent
• Maintain auditable consent logs
11.4. Managing Cookie Preferences:
You can change Your cookie preferences at any time by clicking the cookie settings link in Our website footer or by visiting Your browser settings.
12.1. Privacy Officer / Grievance Officer:
Designation: Privacy Officer
Email: legal@carveragents.ai
Address: No. 40, 4th Floor, Lakshmi Complex, Fort A Road, Kalasipalya, Bangalore 560002, India
Product Questions: support@carveragents.ai (for questions about using the Public Services; privacy requests go to the address above)
Response Time: We aim to respond to all grievances within 30 days of receipt
12.2. Data Protection Board of India:
If You are not satisfied with Our response, or wish to file a complaint directly, You may contact the Data Protection Board of India through the channels it publishes.
To help You understand this Policy, it is available in the following languages:
• English (current document)
• Hindi / हिन्दी
• Tamil / தமிழ்
• Telugu / తెలుగు
• Kannada / ಕನ್ನಡ
To access this Policy in other languages, please use the language selector on Our website or contact Our Privacy Officer. Translations may be machine-generated. If a translation differs from the English version, the English version prevails.
We review this Policy regularly and may update it to reflect:
• Changes in applicable laws or regulations
• New features or services
• Best practice improvements
Where applicable law requires, We will notify You of material changes. Otherwise, We may communicate changes through:
• Prominent notice on Our Website(s)
• Email to registered users
• Updated 'Last Updated' date at the top of this Policy
***
This Privacy Policy is intended to meet the requirements of:
Digital Personal Data Protection Act, 2023
Digital Personal Data Protection Rules, 2025
Effective implementation date: May 13, 2027