Privacy Policy
Effective May 2026 · Governed by India's Digital Personal Data Protection Act 2023
1. Who we are
Sensewise is an organisational consulting and culture diagnostics firm. We operate a web-based diagnostic platform (the "Platform") built on Lovable (frontend) and Supabase (backend, Mumbai region). References to "we", "our", or "us" mean Sensewise. References to "client" mean the organisation that has engaged Sensewise. References to "participant" mean any employee or individual completing a diagnostic on behalf of a client.
2. What data we collect
- Client intake data: names, professional email addresses, company names, and role information submitted via our booking and onboarding flows.
- Diagnostic response data: Likert-scale survey responses, scenario selections, open-ended text responses, and self-profiling ratings submitted by participants. This data is aggregated and does not include medical, biometric, or clinical information.
- Practitioner-entered data: interview scores, observation scores, and associated notes entered by Sensewise practitioners during an engagement.
- HR and operational metrics: workforce data (attrition rates, tenure, performance distributions) voluntarily provided by client organisations for diagnostic purposes.
- Survey resume tokens: when a participant begins a survey, we generate a temporary anonymous identifier (a "resume token") and store it in the participant's browser local storage. This token allows the participant to return to an incomplete survey and continue from where they left off. The token contains no personal information, cannot identify the participant, and is not used for any tracking or advertising purpose. It expires automatically after 7 days or upon survey completion, whichever comes first. When it expires or the survey is completed, the token is invalidated and the local storage entry serves no further function.
3. How and where data is stored
All data — including partial survey responses and resume tokens — is stored in Supabase infrastructure hosted in the Mumbai, India region. No personal or organisational data is transferred or stored outside Indian territory. Row-Level Security (RLS) is enforced on all tables. Partial survey responses associated with a resume token are accessible only via that token and only until it expires. Practitioner access is governed by our Internal Data Access Policy.
4. Legal basis for processing
Under the Digital Personal Data Protection Act 2023 (DPDP Act), we process personal data on the following bases:
- Consent of the data principal (participant), obtained via the Participant Consent Notice presented before survey commencement.
- Legitimate use for the purposes of fulfilling a contract with the client organisation.
- Legitimate interests of the client organisation in understanding organisational health, where participant anonymity is preserved.
The resume token is processed on the basis of the participant's consent, obtained at the same point as consent for the survey itself.
5. How we use data
- To generate aggregated diagnostic reports and culture profiles for the client organisation.
- To identify patterns and flags across the 12-parameter Sensewise framework.
- To support consultation calls and intervention design with the client.
- To enable participants to resume incomplete surveys via the resume token mechanism.
- We do not use diagnostic data for advertising, profiling unrelated to the engagement, or sale to third parties. Resume tokens are not used for any purpose beyond survey continuation.
7. Local storage
We store one item in your browser's local storage: your survey resume token. This is a randomly generated identifier with no personal information attached. It is not a cookie and is not transmitted to any third party. It is not used to track your behaviour across websites or sessions beyond the single purpose of allowing you to resume your survey. You can delete it at any time by clearing your browser's local storage or site data — doing so will mean you cannot resume an incomplete survey from that device, but will have no other effect.
8. Data principal rights (DPDP Act 2023)
As a data principal under the DPDP Act, participants have the right to:
- Obtain a summary of personal data being processed and the purposes of processing.
- Correct inaccurate or incomplete personal data.
- Request erasure of personal data where retention is no longer necessary.
- Withdraw consent at any time — this will invalidate your resume token and delete your partial or complete survey response from our systems.
- Nominate a representative to exercise these rights in the event of death or incapacity.
To exercise any of these rights, contact us at privacy@sensewise.in. We will respond within 72 hours.
9. Retention
- Resume tokens and partial responses: retained for 7 days from the point the survey was started, then automatically deleted whether or not the survey was completed.
- Completed survey responses: retained for the duration of the client engagement plus 12 months, unless the client requests earlier deletion.
- Practitioner-entered data: same retention as completed survey responses.
- HR and operational metrics: deleted within 30 days of engagement close unless the client has requested earlier deletion.
After the applicable retention period, data is permanently deleted from Supabase.
10. Security
We implement Row-Level Security on all database tables, practitioner authentication via Supabase Auth, and restrict data access to named Sensewise personnel on a need-to-know basis. Partial survey responses are accessible only via the resume token and only for 7 days. No participant data is accessible to other participants. The Supabase service role key (which bypasses RLS) is held only by named Sensewise co-founders and is never embedded in frontend code.
11. Changes to this policy
We will notify active clients of material changes to this policy with at least 14 days' notice before the change takes effect. The updated policy will always be accessible at sensewise.in/privacy.