Privacy Policy
Effective Date: August 2026 · Last Updated: August 2026
Akshee Digital Solutions Private Limited ("meraPA", "we", "us", or "our") operates the meraPA application, website and related services (collectively, the "Service").
We respect your privacy and are committed to protecting the personal information entrusted to us. This Privacy Policy explains how personal information may be processed when you use meraPA, what information may be involved, why it may be processed, when it may be shared, how it is protected, and the choices and rights available to you.
meraPA is designed as a globally accessible personal information management platform. Accordingly, this Policy establishes our general global privacy practices while recognising that additional rights, obligations and requirements may apply depending on where you live and which laws apply to your use of the Service.
These may include, where applicable, the Digital Personal Data Protection Act, 2023 and its Rules in India, the EU General Data Protection Regulation (GDPR), UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA) and other U.S. state privacy laws, the UAE Personal Data Protection Law, Saudi Arabia's PDPL, and other applicable privacy and data-protection laws in the jurisdictions in which meraPA operates.
Where mandatory local law provides rights or protections greater than those described here, those requirements apply to the extent required by law.
1. About meraPA
meraPA is developed and operated by Akshee Digital Solutions Private Limited, Hyderabad, Telangana, India.
- General Support: support@merapa.in
- Privacy & Data Protection / Grievance Officer: privacy@merapa.in
- EU / UK Representative: Where required under applicable GDPR or UK GDPR requirements, meraPA will appoint and publish the details of an EU and/or UK representative.
For applicable data-protection laws, Akshee Digital Solutions Private Limited may act as the data fiduciary, data controller, or equivalent responsible entity, depending on the jurisdiction and the nature of the processing.
2. Our Privacy Approach
Your information is yours. You decide what you want meraPA to organise, connect, remember and make useful. We follow these principles: user choice, data minimisation, purpose limitation, transparency, security, user control, and no sale of personal information — we do not sell personal information.
3. What meraPA Does Not Collect
meraPA does not require you to provide most categories of information described here. What is processed depends on the account you create, the features you choose to use, the information and documents you choose to add, the people you designate, the integrations you connect, the permissions you grant, and information generated automatically through your use of the Service. For example, meraPA does not require you to upload insurance, medical or property documents to create an account — you add them only when you want to use a relevant feature.
What we do NOT collect:
- No continuous or background location during normal use — location is used only during an active emergency (see §5.6).
- No SMS or call logs from your device.
- No device address book — we never read or upload your contact list; when you add an emergency contact from your phone, only the single contact you pick is saved.
- No bank account numbers, card details, or UPI credentials — payments are handled by our payment providers and are not stored by us.
- No advertising identifiers or cross-app tracking — meraPA contains no advertising SDKs.
- No independent accounts or data from children under 18 (see §24).
4. Sources of Information
Information may come directly from you (account, profile, uploads, health profiles, reminders, nominees, emergency features, support, purchases); from your device (technical and security data generated automatically); from services you choose to connect (such as Google Drive, OneDrive or Dropbox, per the permissions you grant); from service providers (payment, authentication, communication, security); and from other individuals (for example, a nominee or trusted person, in connection with a feature you enabled).
5. Categories of Information
Depending on how you use meraPA, the following may be processed.
5.1 Account & Identity — name, email, mobile number, date of birth, gender, profile photo, authentication and account identifiers, security information.
5.2 Documents You Choose to Store — identity documents (Aadhaar, PAN, passport, driving licence, national ID, voter ID and equivalents), insurance policies, medical records, prescriptions, property documents, wills, certificates, warranties, invoices, educational and financial documents, and other personal documents. meraPA does not require you to store these — you decide what to add to your vault. We do not verify the authenticity of identity documents and do not share them with any authority unless required by law.
5.3 Health Information You Choose to Add — blood group, allergies, chronic conditions, medications, prescriptions, diagnoses, lab reports, vaccination records, medical history, health-insurance details. Health information may constitute sensitive or specially protected information under applicable law; we process it only in connection with the features for which it is provided or otherwise on a lawful basis. It is encrypted at rest using AES-256 with a unique key per user, and personnel access is restricted by role-based controls and audit logging.
5.4 Nominee & Trusted-Person Information — name, mobile, email, relationship, and the specific access permissions you authorise. To confirm a nominee's identity, a nominee may be asked to provide a government ID and a live selfie for identity / face-match verification. Where a biometric comparison is performed, the verification provider may process biometric information for that limited purpose. meraPA does not retain a raw biometric template after the verification process, unless expressly stated otherwise; we retain only the verification result and information necessary for audit, security and the relevant feature. You control the permissions, for each nominee and each data category.
5.5 Emergency Information — emergency contacts (added manually or picked from your device, in which case only the single contact you select is saved), and the health subset you choose to make available through Emergency QR. What is available depends on the configuration and permissions you establish.
5.6 Location (Emergency Only) — meraPA does not track your location during normal use. If you activate an emergency location feature, your device may provide location for that specific emergency and period. If you enable emergency live-location sharing, an approximate last-known location may be recorded to help verify an alert is genuine. Live-location sharing stops automatically when the emergency ends (and after two hours at most), and you can disable it at any time via the app toggle or device permission.
5.7 Reminders — title, date, time, category and notification-channel preferences (push, SMS, WhatsApp, voice).
5.8 Warranty & Product — product info, purchase date, warranty period, expiry date, retailer, invoice.
5.9 Voice (Optional) — if you use voice input, your device captures short audio which is converted to text to carry out your request. We do not retain the voice audio, and microphone access is requested only if you use this feature.
5.10 Payment & Subscription — plan and add-ons, amount, applicable tax and invoice details, and payment references. Card, UPI and banking credentials are handled by our payment providers and are not stored by meraPA.
5.11 Technical & Security Information — IP address, device type/model, OS and app version, device identifiers/fingerprint, push-notification tokens, session identifiers, crash and performance data, and security and audit logs of key account actions (with the IP and device used). This helps us operate, secure, troubleshoot and improve the Service.
5.12 Usage Information — features used, screens visited and actions taken. Where used for analytics and service improvement, we use aggregated and/or de-identified information designed not to identify you directly.
5.13 Communications & Assistant — support messages, feedback, complaint records, and the text you type into the in-app assistant. The text you type into the assistant is sent to an AI provider to understand your request; your stored records and documents are not sent to it (see §9).
5.14 Emergency QR Scans (about the scanner) — if you scan another person's Emergency QR, we collect information about you, the scanner — a mobile number verified by OTP, an approximate location, and, for hospital-level access, your name and a photo — to confirm a genuine emergency, log who accessed the information, notify the cardholder, and detect and prevent misuse.
6. How We Use Information
To provide the Service (Vault, Health Profiles, Emergency QR, Trusted Nominees, Smart Reminders, warranty tracking, Personal Assistant); security (authenticate, prevent unauthorised access, detect fraud and suspicious activity, maintain audit trails); AI-assisted features (OCR, classification, extraction, health summaries, assistant); notifications; customer support; service improvement (using aggregated and/or de-identified information); legal compliance; and business operations. We do not use your data for advertising, commercial profiling, or sale.
7. Legal Bases
Depending on jurisdiction and purpose, we rely on one or more of: consent; performance of a contract / provision of a requested Service; legal obligation; vital interests; legitimate interests (where permitted); and other lawful grounds. Your general use of meraPA is not blanket consent to every type of processing; where a feature requires separate consent, we request it separately. For sensitive information we apply additional requirements where required by law.
8. Consent Management
How we obtain consent — through clear, affirmative actions in the app, obtained separately for each sensitive category; we do not bundle consent for unrelated purposes. Records — we keep records of what you consented to, when, and the policy version in effect. Withdrawal — any time from Settings; withdrawal disables features that depend on that data and does not affect processing carried out before withdrawal.
9. AI & Automated Processing
meraPA uses AI/ML to provide OCR, document classification, data extraction, summarisation, natural-language understanding and assistant functionality. Where third-party AI providers are used, only the information necessary for the relevant function is processed, under contractual and security controls. Document scanning and health-summary features process the document images and health data you submit; the assistant processes only the text you type — not your stored vault or records. We do not sell personal information to AI providers, and your documents and cloud imports are not used to train generalised AI/ML models. AI outputs may contain errors and are not medical, legal, financial, insurance or other professional advice. We do not make decisions producing legal or similarly significant effects about you solely through automated processing.
10. How We Share Information
We do not sell, rent or trade personal information. We share only: with nominees and trusted persons you designate (the categories you authorise, revocable in-app); through emergency features you configure; with service providers (cloud/storage, AI, payments, authentication, identity verification, email/SMS/WhatsApp/voice, push, mapping, security, support, analytics) bound by data-processing agreements that prohibit using your data for their own purposes and require appropriate security; where required by law (we notify you where permitted); in a business transaction (merger, acquisition, restructuring, or sale — we notify you and, where applicable, give you the option to delete your account before transfer); and with your direction. A current list of our service providers is available on request from privacy@merapa.in.
11. Third-Party Integrations
If you connect an external service (for example, Google Drive, OneDrive or Dropbox), what is made available depends on the permissions you grant; you can disconnect it via the available controls. Third-party services are governed by their own policies.
12. Cloud Storage Imports (Google Drive, OneDrive, Dropbox)
meraPA lets you import documents from third-party cloud storage you already use — currently Google Drive, Microsoft OneDrive, and Dropbox. In every case:
- meraPA imports only the documents you choose. The files you select are copied into your meraPA vault and encrypted at rest with AES-256, exactly like any other vault document. Anything you don't select is not imported.
- meraPA does not modify, delete, add, or reorganise anything in your cloud storage — it only reads the documents you choose, to copy them into your vault.
- We read your account's email address solely to label the connected account.
- The authorisation (refresh token) is stored encrypted and used only to complete the imports you initiate. You can disconnect any provider at any time from "My Cloud Drives," which revokes the authorisation and deletes the stored token.
- Imported documents are treated exactly like any other vault document — never sold, never shared except with the service providers in §10 needed to store or process them, and never used for advertising or to train generalised AI/ML models.
Permissions requested, by provider:
- Google Drive —
access to only the specific files you select (
drive.file). meraPA can see and import just the individual files you pick; it has no access to any of your other Drive files, and whole folders cannot be imported — you choose the files you want. - Microsoft OneDrive — read-only access to the files you can access (
Files.Read.All), plus your account email, so you can browse folders and select files — including whole folders — to import. - Dropbox — read-only access to your file content and metadata (
files.content.read), plus your account email, so you can browse folders and select files — including whole folders — to import.
Google Limited Use. meraPA's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Because meraPA requests
only the non-sensitive drive.file scope ,
access limited to the specific files you choose to import
— and does not request broad or restricted access to your Google Drive. We do not use Google Drive data for advertising, we do not sell it, and we do not use it to train generalised AI/ML models.
13. Google Maps Platform
meraPA's emergency location features use Google Maps Platform — including the Maps JavaScript API and the Places API — to display maps, look up and label place names, provide directions to a shared location, and help confirm emergency context (for example, verifying proximity to a hospital when your Emergency QR is scanned for hospital-level access). When these features are used, Google processes the relevant location and request data as an independent service; Google's processing is governed by the Google Privacy Policy. meraPA uses Google Maps Platform only for these functions and never for advertising.
14. Data Security
We implement technical and organisational measures including: AES-256 encryption at rest; envelope encryption with a unique Data Encryption Key per user, so every user's data is cryptographically isolated; TLS 1.3 in transit; OTP-verified login combined with device biometric (Face ID / fingerprint) and PIN app-lock; role-based access controls and audit logging; key management; user-level data isolation; access and security monitoring; restricted personnel access; backup and recovery controls; and regular security reviews. No system can be guaranteed completely secure; you are responsible for protecting your device, credentials, PIN and account access.
15. Data Retention
We retain information only as long as reasonably necessary for the Service, the purposes in this Policy, security and fraud prevention, legal/regulatory requirements, and dispute resolution:
- Account information — Until deletion + a 30-day recovery window
- Documents / health records — Until you delete them or close your account
- Nominee / reminders / warranty — Until removed or account closure
- Assistant chat history — Until you clear it or close your account
- Emergency access & scan logs — As reasonably necessary to detect and prevent misuse
- Usage & technical logs — For a limited period appropriate to security and operational needs
- Support communications — As reasonably necessary for support and dispute resolution
- Payment / tax records — For the period required by applicable law (e.g., India financial regulations)
On account deletion, personal data is removed from active systems within 30 days; residual copies in encrypted backups are removed in the ordinary course of our backup lifecycle. Information required to be retained by law is kept for the required period; de-identified, non-identifiable data may be retained.
16. International Data Transfers
meraPA is operated from India and primarily stores personal data on servers located in India (Mumbai region), and may use infrastructure and service providers in other countries — so your information may be transferred to or accessed from countries other than where you reside. Where local law restricts transfers, we use legally recognised mechanisms and safeguards. For individuals in the EEA or UK, transfers to countries not deemed adequate rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum / IDTA), together with additional technical measures such as encryption; you may request a copy of the relevant safeguards from privacy@merapa.in. We apply the transfer mechanisms required by the UAE PDPL, Saudi PDPL and other applicable local laws.
17. Your Privacy Rights
Depending on your location and applicable law, you may have rights to: know / be informed, access, correction, deletion / erasure, restrict processing, object, withdraw consent, data portability, rights relating to sensitive information and to automated decision-making, and to lodge a complaint with a regulator. The precise rights depend on the law applicable to you; the region-specific sections below (§19–§23) describe them further.
18. How to Exercise Your Rights
Contact privacy@merapa.in, or use the in-app privacy controls where provided — in Settings you can access a summary of your data, correct information, export your data in JSON or PDF (free), withdraw consent per category, and request account deletion. To protect your account we may verify your identity before completing certain requests, and we respond within the timeframe required by applicable law (extendable where the law allows — e.g., a further two months under the GDPR for complex requests).
19. India — Digital Personal Data Protection Act, 2023
Where the Digital Personal Data Protection Act, 2023 and applicable Rules apply to our processing, meraPA will process personal data in accordance with the requirements applicable to us. The DPDP Act and the Digital Personal Data Protection Rules, 2025 (notified in November 2025) have a phased commencement, so specific obligations apply according to their respective commencement dates. Until those provisions fully commence, India's Information Technology Act, 2000 and the SPDI Rules, 2011 continue to apply to sensitive personal data.
The DPDP framework provides Data Principals with rights including access to information about their personal data and its processing, correction and updating, erasure, grievance redressal and nomination, subject to the applicable provisions, rules, commencement dates and legal exceptions.
meraPA also provides in-app privacy controls and a data-export feature (JSON or PDF) to support your control over your personal information. These product features may provide functionality beyond the minimum rights required by applicable law.
Grievance Officer: Akshee Digital Solutions Private Limited, Hyderabad, Telangana, India — privacy@merapa.in. Complaints may be submitted through this address; we will respond within the period required by applicable law or, where no statutory period applies, within the period published in our grievance mechanism. Where applicable, an unresolved complaint may be escalated to the Data Protection Board of India (dpboard.gov.in).
20. European Union / EEA — GDPR
Where the EU GDPR applies, you may have rights to be informed, access, rectification, erasure, restriction, portability, objection (including to direct marketing at any time), withdrawal of consent, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We apply the GDPR principles (lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security, accountability). Our legal bases are set out per category above; where we rely on legitimate interests, we have balanced them against your rights. You may lodge a complaint with your national supervisory authority.
21. United Kingdom — UK GDPR
Where UK GDPR and applicable UK data-protection law apply, you have rights to access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and rights relating to automated decision-making. You may complain to the UK Information Commissioner's Office (ico.org.uk).
22. United States — California & Other State Laws
Where applicable U.S. state laws apply, we provide the required rights. For California residents (CCPA/CPRA): the right to know / access, delete, correct, opt out of the sale or sharing of personal information, limit the use of sensitive personal information, and non-discrimination. meraPA does not sell personal information and does not share it for cross-context behavioural advertising; accordingly we do not provide a "Do Not Sell or Share My Personal Information" mechanism for an activity we do not conduct. Authorised agents may submit requests with proof of authorisation. If our practices change, we will update our notices and provide the legally required controls.
23. Middle East
Where meraPA is subject to local privacy laws in Middle Eastern jurisdictions, we comply with the requirements applicable to the relevant processing, including, where applicable: United Arab Emirates (Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, plus DIFC/ADGM requirements where relevant), Saudi Arabia (the Personal Data Protection Law and its implementing regulations, including rules on transfers outside the Kingdom), and the applicable personal-data protection requirements of Qatar, Bahrain, Oman, Kuwait, and Israel. Nothing in this section limits any additional rights available under the law of your jurisdiction.
24. Children's Privacy
meraPA accounts are intended for individuals aged 18 and above. We do not knowingly offer independent accounts to under-18s. An adult account holder may create and manage family information relating to children or others where the account holder has the necessary authority or lawful basis (including as a parent or legal guardian), and by doing so confirms they have that authority and may consent on the individual's behalf. Where applicable law imposes additional requirements concerning children's information (for example, verifiable parental consent), we apply them. If you believe a child's information has been added without authority, contact privacy@merapa.in.
25. Cookies & Tracking
The meraPA mobile application does not use cookies. Our website or web application may use strictly necessary technologies for authentication, session management, security and essential functionality. Where analytics or optional tracking technologies are used, appropriate notices and consent mechanisms are provided where required by applicable law. We do not use cookies for targeted advertising.
26. Communications
We may contact you via email, SMS, push, in-app and other necessary channels — for security alerts, account and subscription information, service updates, reminders you configured, important legal or privacy notices, and support responses. Marketing communications, where used, are subject to applicable consent and opt-out requirements.
27. Data Breaches & Security Incidents
We maintain procedures to detect, investigate, contain and respond to security incidents, assessing the nature of the incident, the categories of information affected, the risk to individuals, and applicable notification requirements. Where required by applicable law, we will notify affected individuals, regulators (including the Data Protection Board of India and/or the competent EU/UK supervisory authority) and other relevant authorities within the applicable timeframe. For example, under the GDPR, certain personal-data breaches presenting a risk to individuals' rights and freedoms must generally be notified to the relevant supervisory authority without undue delay and, where applicable, within 72 hours of becoming aware of the breach.
28. Your Responsibilities
You are responsible for protecting your device, account credentials, PIN, password, authentication methods and Emergency QR access; for carefully considering what you make accessible through nominees, Emergency QR, emergency contacts, integrations and other sharing features; and for ensuring you have the necessary authority before adding another person's personal information to meraPA.
29. Changes to This Policy
We may update this Policy to reflect new features, changes to the Service or our practices, technology, security, or applicable law. Where required by applicable law, we will provide notice of material changes before they take effect; where appropriate, we may also provide advance notice through email, in-app notification or other reasonable means. The latest version will be available on the meraPA website and application.
30. Contact
Akshee Digital Solutions Private Limited, Hyderabad, Telangana, India
- Privacy & Data Protection / Grievance Officer: privacy@merapa.in — we acknowledge and respond within the period required by applicable law
- General Support: support@merapa.in
- EU / UK Representative: appointed and published where required under applicable GDPR / UK GDPR requirements
If your complaint is not resolved to your satisfaction, you may escalate to your supervisory authority: the Data Protection Board of India (dpboard.gov.in), the UK ICO (ico.org.uk), your EEA Data Protection Authority, or the California Attorney General, as applicable.
For privacy requests, please provide sufficient information for us to understand and verify your request.
31. No Waiver of Local Privacy Rights
Nothing in this Privacy Policy is intended to remove, restrict or waive any mandatory privacy or data-protection right available to you under applicable law. Where this Privacy Policy conflicts with a mandatory requirement of the law applicable to you, that law will prevail to the extent of the conflict.
This Privacy Policy describes how meraPA processes personal information and the rights and choices available to users. Where consent is required for a particular processing activity, meraPA will obtain that consent through the appropriate mechanism.
This Privacy Policy is effective from August 2026 and supersedes all previous versions.