Privacy Policy
Last updated: August 18, 2026
This Privacy Policy explains how RG Novatech (“RG Novatech,” “we,” “us,” or “our”), the company that develops and operates ExitIntelli (the “Service”), collects, uses, discloses, and protects personal data. It is written to comply with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA, India’s Digital Personal Data Protection Act, and other applicable data protection laws, and applies to everyone whose personal data we process in connection with the Service: the corporate customers who purchase ExitIntelli (“Customer,” “you”), the Customer’s internal staff who use the product (HR, admin, and leadership users), and the Customer’s departing employees who complete an exit interview.
1. Two roles we play, and why it matters
Data protection law distinguishes between a controller (the entity that decides why and how personal data is processed) and a processor (the entity that processes it on the controller’s behalf and instructions). ExitIntelli plays both roles, for different data:
- We are the controller for account data belonging to the Customer’s internal staff (name, work email, role, login activity) and for the Customer’s own billing and subscription data. We decide how this data is used to operate and secure the Service.
- We are a processor (service provider) for the personal data of the Customer’s departing employees collected through an exit interview — their responses, sentiment/severity scoring, and any safety-exception content. The Customer is the controller for that data: they decide to run exit interviews and receive the aggregated output; we process it strictly to deliver the Service and under the confidentiality safeguards described below. If you are a departing employee with a question about your own interview data, your former employer (the Customer) is the primary point of contact as the controller, but we will always accept, verify, and act on a request you send us directly at privacy@exitintelli.com, consulting the Customer where their instructions are required.
2. What we collect
Internal user accounts (Customer staff)
- Name, work email address, assigned role, and department/business-unit scope.
- Authentication events: one-time sign-in codes (never stored beyond verification), login timestamps.
- Access logs for sensitive views (dashboard aggregates, flight-risk scores, verbatim quotes, safety-summary views, and safety/legal consent-routing decisions) — who viewed what, and when.
Departing-employee interview data
- Pseudonymous exit record: termination date, tenure band, level band, department — never a name.
- Interview responses: your own words (free text) and structured answers across 15 topic areas, plus derived sentiment, severity, and driver-attribution scores.
- An end-of-interview advocacy check (would you refer a friend / would you consider returning).
- If your responses describe something like harassment, discrimination, or a safety concern, and you explicitly consent, a short summary and category is shared with your former employer’s designated legal/POSH/ethics contact — see Section 5.
Billing data
Credit purchase and consumption records, and the tier/rate a Customer is on. We do not process or store payment card numbers or bank details — there is currently no live payment gateway integrated; payments are arranged directly between the Customer and RG Novatech outside the Service, and a Customer admin records the resulting credit purchase.
Technical data
We use only the cookies strictly necessary to keep you signed in (session/authentication cookies set by our authentication provider). We do not use advertising or third-party analytics/tracking cookies.
3. Why we process this data (legal bases)
- Performance of a contract — operating the Service for the Customer that has signed up, and for their internal users who need accounts to use it.
- Explicit consent — a departing employee’s participation in an interview is always voluntary, and sharing anything with a legal/ethics contact requires a separate, explicit, two-step consent captured in the product before it is sent (see Section 5).
- Legitimate interests — securing the Service, preventing abuse, and improving the product, balanced against your rights (for example, our audit logging of sensitive data views).
- Legal obligation — tax and accounting record-keeping for billing, and responding to valid legal process.
Content shared under a safety-exception consent may include special-category data under GDPR Article 9 (for example, data revealing an alleged act connected to a protected characteristic, or health-related content). Our lawful basis for processing that specific content is your explicit consent, captured at the point you choose to share it — never inferred, and never required to complete the rest of your interview.
4. How confidentiality is enforced
This isn’t just a policy promise — it’s enforced at the database level. Individual interview responses live in a restricted data tier that the reporting layer has no access to. Only combined, anonymized themes are ever exposed to a Customer’s leadership, and only once enough departures are behind a given number that no one could be singled out — currently a minimum of 30 employees and 5 departures in scope before any metric is shown at all, with further suppression of any sub-group (e.g. a specific tenure band) that’s still small enough to be identifying. Below that threshold, the dashboard shows “insufficient data” instead of a number. A small number of illustrative verbatim quotes are shown organization-wide only, never for a department, and are excluded entirely if they relate to a safety exception.
5. Safety and legal-exception handling
If something you say suggests harassment, discrimination, or a safety concern, you are shown the exact message that would be sent to your former employer’s designated contact (legal, POSH/ethics committee, or CHRO, depending on category), can edit the summary, and must confirm a second time before anything actually sends. If you decline, nothing is shared beyond an internal flag that a case exists needing separate review — the content of what you said is never shared without your consent.
6. Automated processing
The interview conversation is conducted with the assistance of an AI model (see Section 9), and responses are scored for sentiment, severity, and topic relevance to route the conversation and build aggregate reporting. None of this results in a solely-automated decision that produces a legal or similarly significant effect about you: no automated system decides employment, benefit, or legal outcomes, and any safety-escalation routing always requires your own explicit, human decision to proceed. A predictive flight-risk feature exists in the data model for future use but is not yet backed by a working model or used to make any decision today.
7. Who we share data with
We do not sell personal data, and we do not share individual interview responses with anyone at the Customer organization. We use the following categories of subprocessors to operate the Service, each bound by a data processing agreement:
- Database, authentication, and hosting infrastructure (Supabase) — stores all Service data and manages sign-in.
- AI processing (Anthropic) — processes interview text to conduct the adaptive conversation and perform the safety-content check described in Section 5. Interview content sent for this purpose is used to generate the immediate response and is not used by our AI provider to train their models.
- Transactional email (Resend) — delivers interview invite links, one-time sign-in codes, and safety-escalation notices. No marketing email is sent through this channel.
- Application hosting (Vercel) — hosts and serves the Service itself.
Some of these subprocessors operate infrastructure outside your country, including in the United States. Where personal data is transferred internationally, we rely on the subprocessor’s Standard Contractual Clauses or an equivalent recognized transfer mechanism. A current subprocessor list is available on request at privacy@exitintelli.com. We otherwise disclose data only where required by law, to protect rights and safety, or with your explicit consent (Section 5).
8. How long we keep data
We retain Service data for as long as the Customer’s subscription is active, plus 90 days afterward to allow for export or reactivation, after which it is permanently deleted unless we are required to retain it longer — for example, an active, unresolved safety-exception case under legal review, or billing records kept for tax and accounting purposes as required by law. If you exercise a deletion right individually (Section 10), we will act within 30 days, subject to the same legal-retention exceptions.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request erasure (“right to be forgotten”), subject to Section 8’s exceptions.
- Restrict or object to certain processing, including processing based on legitimate interests.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting processing that already happened.
- Lodge a complaint with your local data protection authority (in the EU/UK, the supervisory authority in your country of residence).
- If you are a California resident: know what personal information we collect, request deletion, and not be discriminated against for exercising these rights. We do not sell or “share” personal information as those terms are defined under the CCPA/CPRA.
To exercise any of these rights, contact privacy@exitintelli.com. We may need to verify your identity before acting on a request. RG Novatech has not appointed a formal Data Protection Officer; until we do, this same address handles that function and is monitored by our team responsible for privacy matters.
10. Security
Data is encrypted in transit (TLS) and at rest. Access to individual interview content is restricted by database-level row-level security tied to organization and role, not just application logic. There are no passwords anywhere in the product — every sign-in uses a one-time emailed code — removing an entire class of credential-theft risk. Access to sensitive views (aggregates, flight-risk scores, verbatim quotes, and safety-consent routing) is logged in an append-only audit trail that no role, including admins, can edit or delete.
11. Children’s data
The Service is intended for use by working adults in an employment context and is not directed at, or knowingly used to collect data from, children under 16 (or the higher age of majority in your jurisdiction).
12. Changes to this policy
We’ll update the “Last updated” date above whenever this policy changes. If a change materially affects how we handle your data, active users will be asked to review and re-accept it before continuing to use the Service.
13. Contact us
RG Novatech
No: 8, II Cross Street, Ganesh Nagar, Adambakkam, Chennai – 600088, India
Privacy inquiries: privacy@exitintelli.com