Skip to main content
Bibha home

Data protection

Data protection at Bibha, as controller and as processor.

Bibha AI Labs Private Limited and its US affiliate, Bibha AI Inc., follow the same data protection practices, led by our Data Protection Officer at dpo@bibha.ai. Our GDPR and UK GDPR programmes are listed as in progress at the Bibha AI Trust Center.

  • GDPR badge

Controller, processor and your own environment

Bibha means Bibha AI Labs Private Limited and its US affiliate, Bibha AI Inc. Both companies follow the practices on this page. Our role, and the duties the law gives us, depend on whose data it is and who decides how it is used.

  • Bibha as controller

    Bibha AI Labs Private Limited is the controller for personal data collected through bibha.ai, such as enquiries and website logs, and for the personal data it handles to run its own business. Under India's DPDP Act, it is the Data Fiduciary for that data. Our privacy policy explains the website processing in detail.

  • Bibha as processor

    When you run personal data through the Bibha platform or a solution built on Bibha, such as TalentFlow, ReachFar or PeachDesk, you are the controller and Bibha is your processor. We process that data only on your documented instructions, under a data processing agreement.

  • Your own environment

    When parts of your system run in your own cloud account or on infrastructure you control, processing for those parts takes place in your environment, under your control. Bibha receives personal data from those parts only as agreed with you, for example when we operate the system or when you share data to investigate an issue.

Bibha AI Labs Private Limited (CIN U62099KA2024PTC193869) has its headquarters at Villa 92, JRC Palladio, Attibele Road, Billapura, Sarjapura, Anekal, Bangalore 562125, Karnataka, India. Bibha AI Inc. is at 3790 El Camino Real, Ste 853, Palo Alto, CA 94306, United States, and is the contact point for US residents.

The laws we work under

More than one data protection law can apply to the same system. Which ones apply depends on where the people whose data is processed are located, and on which Bibha company processes it. This is what each law means for you.

  • EU GDPR

    When an EU customer uses Bibha, its processing falls under Regulation (EU) 2016/679, and our data processing agreement binds Bibha to the processor duties in Article 28. The GDPR also applies to Bibha directly when we offer services to people in the EU or monitor their behaviour there (Article 3(2)).

    • Bibha has designated a representative in the European Union under Article 27, reachable at dpo@bibha.ai.
    • Bibha AI Labs Private Limited is the controller for our website and corporate data. For your system, the Bibha company named in your agreement is your processor.
  • UK GDPR and Data Protection Act 2018

    The UK GDPR and the Data Protection Act 2018 set equivalent controller and processor duties for personal data of people in the United Kingdom. The Information Commissioner's Office is the regulator.

    • Our UK representative under Article 27 of the UK GDPR is reachable at dpo@bibha.ai.
    • As the Data (Use and Access) Act 2025 now requires, we acknowledge data protection complaints within 30 days.
  • Swiss FADP

    The revised Federal Act on Data Protection has applied since 1 September 2023 to personal data of people in Switzerland. The Federal Data Protection and Information Commissioner (FDPIC) is the regulator.

    • Disclosures abroad need recognised safeguards (Article 16).
    • Access requests are generally answered within 30 days (Article 25).
    • Your Bibha counterparty is the same as under the GDPR.
  • India DPDP Act 2023 and DPDP Rules 2025

    Bibha AI Labs Private Limited is a Data Fiduciary under the Digital Personal Data Protection Act, 2023 for the personal data it decides to process, and a Data Processor when it processes data for a customer. The DPDP Rules, 2025 were published in November 2025, and most of their obligations, including notice, breach intimation and Data Principal rights, apply 18 months after publication.

    • When Bibha processes personal data of people outside India under a contract with a customer outside India, most of the Act's duties and rights do not apply to that processing (section 17(1)(d)). Sections 8(1) and 8(5), on responsibility for compliance and reasonable security safeguards, still apply.
  • US state privacy laws

    The California Consumer Privacy Act, as amended by the California Privacy Rights Act, and comprehensive privacy laws in states such as Virginia, Colorado, Connecticut, Utah, Texas and Oregon give residents rights over their personal information.

    • When we process personal information for a business customer, we act as its service provider or processor.
    • Bibha AI Inc. is the contact point for US residents.

International transfers

Bibha's companies are in India and the United States, so personal data may be processed in those countries, for example when our people support or operate your system. Hosted components run in the hosting provider regions agreed for your configuration. Data residency explains where each kind of data is stored and processed for each deployment arrangement.

Where personal data leaves the European Economic Area, the United Kingdom or Switzerland for a country without an adequacy decision, we use these safeguards:

  • European Economic Area: the standard contractual clauses in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, adopted under Article 46(2)(c) GDPR.
  • United Kingdom: the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, issued by the Information Commissioner, with a transfer risk assessment.
  • Switzerland: the EU standard contractual clauses as recognised by the FDPIC, with the adaptations Swiss law requires (Article 16(2)(d) FADP).
  • India: section 16 of the DPDP Act allows transfers outside India, except to countries the Central Government restricts by notification.

Clause 14 of the standard contractual clauses requires both parties to assess the laws and practices of the destination country and to document that assessment. We share our transfer impact assessment with customers on request at dpo@bibha.ai.

Data processing agreement and sub-processors

When Bibha processes personal data for you, a data processing agreement governs it. As Article 28(3) GDPR requires, it sets out the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects. It commits Bibha to:

  • process personal data only on your documented instructions, including for international transfers
  • ensure that the people authorised to process it are bound by confidentiality
  • apply appropriate technical and organisational security measures
  • help you respond to data subject requests and meet your security, breach and impact assessment duties
  • delete or return the personal data at the end of the service, at your choice
  • give you the information you need to demonstrate compliance, and allow for and contribute to audits

Request our data processing agreement through our contact page.

Service providers that process personal data on our behalf do so under contracts with the same data protection obligations as our agreement with you. A current list of sub-processors is available on request at dpo@bibha.ai. We tell you about intended additions or replacements before they take effect, so you can object, as Article 28(2) GDPR provides.

Rights requests from individuals

Data subjects under the GDPR and Data Principals under the DPDP Act can ask Bibha about their personal data. This is how to make a request and when we respond.

Email privacy@bibha.ai, or write to our Data Protection Officer at dpo@bibha.ai. Tell us what you are asking for and the email address or other identifier we hold for you. We may ask for more information to confirm your identity before we act. In most cases, making a request is free.

If Bibha processes your data for one of our customers, that customer is the controller and decides on your request. We refer it to the customer and help them respond.

Rights and response times by law
LawYour rightsWhen we respond
GDPR and UK GDPRAccess, rectification, erasure, restriction, data portability, objection, and rights related to automated decision-making (Articles 15 to 22)Within one month of receiving your request. For complex or numerous requests, we may extend this by two further months and tell you why within the first month (Article 12(3)).
Swiss FADPInformation about your data, data portability, and correction or deletion of your data (Articles 25, 28 and 32)Generally within 30 days (Article 25(7)).
India DPDP Act 2023Access to a summary of your data, correction, completion, updating and erasure, grievance redressal and nomination (sections 11 to 14)Within 90 days, the longest period the DPDP Rules, 2025 allow (Rule 14(3)).
California CCPA, as amended by the CPRAKnow, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and non-discriminationWithin 45 days, extendable once by 45 days with notice to you (Civil Code section 1798.130).
Other US state privacy lawsDepending on the state: confirm and access, correct, delete, data portability, opt out of sale, targeted advertising and profiling, and appeal our decisionWithin the period each state law sets, for example 45 days, extendable once by 45 days, under Virginia Code section 59.1-577.

Rights and response times by law

Law
GDPR and UK GDPR
Your rights
Access, rectification, erasure, restriction, data portability, objection, and rights related to automated decision-making (Articles 15 to 22)
When we respond
Within one month of receiving your request. For complex or numerous requests, we may extend this by two further months and tell you why within the first month (Article 12(3)).
Law
Swiss FADP
Your rights
Information about your data, data portability, and correction or deletion of your data (Articles 25, 28 and 32)
When we respond
Generally within 30 days (Article 25(7)).
Law
India DPDP Act 2023
Your rights
Access to a summary of your data, correction, completion, updating and erasure, grievance redressal and nomination (sections 11 to 14)
When we respond
Within 90 days, the longest period the DPDP Rules, 2025 allow (Rule 14(3)).
Law
California CCPA, as amended by the CPRA
Your rights
Know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and non-discrimination
When we respond
Within 45 days, extendable once by 45 days with notice to you (Civil Code section 1798.130).
Law
Other US state privacy laws
Your rights
Depending on the state: confirm and access, correct, delete, data portability, opt out of sale, targeted advertising and profiling, and appeal our decision
When we respond
Within the period each state law sets, for example 45 days, extendable once by 45 days, under Virginia Code section 59.1-577.

Under the DPDP Act, raise a grievance with our Grievance Officer, Prashant Kumar, at privacy@bibha.ai first. Section 13(3) requires you to use this route before approaching the Data Protection Board of India, which hears complaints under section 27.

You can also complain to a data protection supervisory authority, in particular in the EU or EEA country where you live or work, or where you believe the problem happened (Article 77 GDPR). In the United Kingdom, this is the Information Commissioner's Office. In Switzerland, it is the Federal Data Protection and Information Commissioner.

Personal data breaches

These are legal duties, not service levels, and Bibha meets them.

  • As a controller under the GDPR and UK GDPR, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to people (Article 33(1)).
  • When a breach is likely to result in a high risk to people, we tell them without undue delay, in clear and plain language (Article 34).
  • As a processor, we notify the customer without undue delay after becoming aware of a breach (Article 33(2)) and help it meet its own notification duties (Article 28(3)(f)).
  • Under the Swiss FADP, we notify the FDPIC as quickly as possible of a breach likely to lead to a high risk (Article 24).
  • Under the DPDP Act, we intimate each affected Data Principal and the Data Protection Board of India as the DPDP Rules, 2025 prescribe: affected Data Principals without delay, and the Board without delay, with a detailed report within 72 hours (section 8(6) and Rule 7).

We document every personal data breach, including its effects and the remedial action taken (Article 33(5)). To report a suspected incident, email dpo@bibha.ai.

Security and compliance status

Data protection rests on information security. This is the status published at the Bibha AI Trust Center on 2 October 2026.

  • ISO 27001 information security management badge

    ISO 27001

    Compliant

    The Bibha AI Trust Center lists ISO 27001 as compliant. ISO 27001 is the international standard for an information security management system. Request the assurance documents and confirm their scope for your engagement.

  • AICPA SOC badge for SOC 2

    SOC 2

    Compliant

    The Bibha AI Trust Center lists SOC 2 as compliant. Contact us for assurance documents, including the report type, scope and review period relevant to your assessment.

  • GDPR badge

    GDPR and UK GDPR

    In progress

    The Bibha AI Trust Center lists GDPR and UK GDPR programmes as in progress. Our privacy policy describes how we process personal data and the rights that apply.

The Bibha AI Trust Center is the live record of these programmes and the controls behind them. Read more on our security page.

EU AI Act and AI governance

  • ISO 42001 badge

    ISO/IEC 42001:2023

    In progress

    Our ISO/IEC 42001 programme covers AI governance, risk management and the responsible operation of AI systems. The Trust Center lists it as in progress.

  • EU AI Act badge

    EU AI Act

    In progress

    Our programme for Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, is in progress. The Act applies in stages.

On the platform, your team keeps human control. Change and release authority defines who approves material changes and production releases, authorised people can stop work and revoke access, and audit history records important access, configuration and operational changes.

A capability or a programme does not by itself establish compliance with a regulation. That assessment depends on the actual system, its data, configuration and operating practices, reviewed for each engagement.

Frequently asked questions

Do you sign a data processing agreement?

Yes. When Bibha processes personal data for you, a data processing agreement under Article 28 GDPR governs it. Request our agreement through our contact page.

Where is our data processed?

It depends on how you deploy. Bibha's companies are in India and the United States, so our people may process personal data there when they support or operate your system. Hosted components run in the hosting provider regions agreed for your configuration, and parts that run in your own environment stay there. Data residency explains each arrangement.

Is Bibha GDPR compliant?

The Bibha AI Trust Center lists GDPR and UK GDPR programmes as in progress. Our data protection page and privacy policy explain our processing practices and how you can exercise your rights.

Who is your Data Protection Officer?

Prashant Kumar is our Data Protection Officer and our Grievance Officer under India's DPDP Act. Contact our Data Protection Officer at dpo@bibha.ai or privacy@bibha.ai.

Do you have representatives in the EU and the UK?

Yes. Bibha has designated representatives in the European Union and the United Kingdom under Article 27 of the GDPR and the UK GDPR. You can contact them at dpo@bibha.ai.

How do I exercise my data protection rights?

Email privacy@bibha.ai or dpo@bibha.ai and tell us what you are asking for. We may ask you to confirm your identity. We respond within one month under the GDPR and UK GDPR, generally within 30 days under the Swiss FADP, within 45 days under the CCPA and within 90 days under India's DPDP Act. If Bibha processes your data for a customer, we refer your request to that customer.

Do you sell personal data?

No. Bibha does not sell personal information or share it for advertising, so there is nothing to opt out of. When we process personal data for a customer, we use it only on that customer's documented instructions.