Data Processing Agreement
This page summarises how Shrinam Memory processes personal data on your behalf. It is a plain-language companion to our executable DPA, which is available on request for customers with a signed order form. Last updated 27 July 2026.
Overview
Shrinam Memory is a memory-as-a-service API operated by Hindustani AI Logics OPC Pvt Ltd (“Shrinam”, “we”). When you store, recall or delete memories through the API, we process the personal data contained in those memories strictly to provide the service. We do not sell your data, and we do not use your memories to train shared models.
Roles & scope of processing
For personal data you send to the API, you are the data controller (or processor for your own customers) and Shrinam is the processor. We process data only on your documented instructions — i.e. the API calls your application makes.
- Subject matter: storage and retrieval of memories on your behalf.
- Duration: for the life of your account, until you delete the data or close the account.
- Data types: whatever your application sends — you control what is ingested.
- Purpose: providing recall, knowledge-graph and lifecycle functions of the API.
Sub-processors
We engage a small set of sub-processors to run the service. We remain responsible for their compliance and will give notice before adding a new one.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Application hosting, managed PostgreSQL storage and secret management | Mumbai, India (asia-south1) |
| Google — Gemini API | Optional honesty-layer adjudication of ingested memories. Disabled by default; engaged only when a customer explicitly enables the LLM judge. | Google, global |
Data residency
Your memories are stored in Google Cloud’s Mumbai region (asia-south1). Primary storage and processing stay in India, which supports data-localisation requirements under India’s Digital Personal Data Protection Act, 2023 (DPDP). The only exception is the optional Gemini honesty-judge, which — when you turn it on — sends memory text to Google for adjudication.
Security measures
- Encryption in transit: TLS 1.2+ on every API connection.
- Encryption at rest: AES-256 on all stored data (Google Cloud managed).
- Tenant isolation:each customer’s data lives in a dedicated PostgreSQL schema — no shared tables.
- Access control: bearer API keys with per-key rate limiting and instant revocation.
- Injection gate: ingested memories are screened so poisoned content cannot hijack downstream recall.
- Post-quantum-ready erasure: deletions are backed by cryptographically signed certificates.
Your live security posture — encryption, regulations and the tamper-evident audit trail — is visible in the Compliance Center once you sign in.
Your rights (DPDP + GDPR)
Because you control the data, you (and your data principals / data subjects) can exercise the following rights directly through the API or by contacting us:
- Access & portability: export your data at any time via the account export endpoint.
- Correction: update or overwrite stored memories.
- Erasure with proof: delete a memory or a whole topic and receive a signed deletion certificate you can verify independently.
- Purpose limitation: we process memories only to run the service, never to train shared models.
- Grievance redressal: escalate to our grievance officer (below).
Retention & deletion
You decide how long memories live. On individual deletion, the record is removed and a signed certificate is issued. On account closure, your entire PostgreSQL schema is dropped in full (“cremation”) and a final erasure certificate is produced. We keep minimal billing and audit metadata only as long as the law requires.
Grievance officer
For any privacy question, data-subject request or complaint, contact our grievance officer / Data Protection Officer:
This summary is provided for transparency and does not itself constitute the signed Data Processing Agreement. Where a signed DPA or order form exists, that document governs. Nothing here is legal advice.