‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
‌
Alayn — AI Operating System for Hospitality
‌

Legal Hub

Privacy PolicyTerms of ServiceRefund PolicyCookie PolicySecurity & DataResponsible AICorporate InfoSupport & Grievance

Contact Legal

brahmglobalholdings@gmail.com

Security & Data Protection

Effective Date: 14 August 2026

Last Updated: 14 August 2026

At Alayn AI, security is fundamental to the way we design, build and operate our platform.

Alayn is designed to help businesses manage critical operational information across areas such as sales, orders, inventory, workforce, customers and business intelligence. We therefore take the protection, confidentiality, integrity and availability of information seriously.

This Security & Data Protection Policy explains the security principles and measures that Alayn applies to its Services.

This Policy should be read together with our Privacy Policy and Terms of Service.

1. ABOUT ALAYN

Alayn AI is operated in India by:

Trade Name: BRAHM GLOBAL HOLDINGS

Legal Name: IYAAN KHAN TAUQUIR KHAN

Constitution: Sole Proprietorship

Principal Place of Business:
Shop No. 6, Veena Beena Shopping Centre,
Guru Nanak Marg, Bandra West,
Mumbai, Maharashtra 400050, India

General Support: info@alaynai.com

Privacy & Data Protection: brahmglobalholdings@gmail.com

2. OUR SECURITY PRINCIPLES

Alayn's security approach is built around four core principles:

Confidentiality

Information should only be accessible to authorised individuals, systems and service providers.

Integrity

Information should be protected against unauthorised alteration, corruption or misuse.

Availability

The Alayn platform is designed to remain accessible and operational for authorised customers, subject to maintenance, technical limitations and events outside our reasonable control.

Accountability

Security responsibilities should be clearly defined, monitored and continuously improved.

3. PROTECTING CUSTOMER DATA

Customers retain ownership and control of their underlying business data.

Alayn processes Customer Data only to the extent reasonably necessary to:

  • provide the Services;
  • operate and maintain customer accounts;
  • provide support;
  • maintain security;
  • detect and prevent misuse;
  • troubleshoot technical issues;
  • improve service performance;
  • comply with legal obligations; and
  • perform other functions authorised under the applicable agreement.

Alayn does not sell Customer Data as a commercial product.

4. ACCESS CONTROL

Alayn uses access-control principles designed to limit access to information and systems to authorised personnel and services.

Depending on the relevant system and functionality, measures may include:

  • user authentication;
  • role-based access controls;
  • permission management;
  • restricted administrative access;
  • credential management;
  • access logging;
  • authentication controls; and
  • periodic review of access where appropriate.

Access to Customer Data is intended to be limited to personnel and systems that require such access for legitimate business or service purposes.

5. DATA TRANSMISSION AND ENCRYPTION

Where appropriate, Alayn uses encryption and secure communication protocols to help protect information while it is transmitted between users, applications and our Services.

Security controls may include encryption in transit and other appropriate technical safeguards depending on the nature of the information and system involved.

Where encryption at rest is implemented for particular systems or data stores, it may be used to provide an additional layer of protection against unauthorised access.

Specific encryption technologies may change as our infrastructure develops.

6. INFRASTRUCTURE SECURITY

Alayn uses third-party infrastructure and technology services where appropriate to operate its platform.

We seek to select service providers that maintain appropriate technical and organisational security measures relevant to the services they provide.

Infrastructure may include controls relating to:

  • network security;
  • system access;
  • authentication;
  • monitoring;
  • backups;
  • vulnerability management;
  • infrastructure resilience;
  • physical security; and
  • incident response.

Because our infrastructure and technology stack may evolve, specific infrastructure providers and technologies are not permanently defined by this Policy.

7. APPLICATION SECURITY

Security considerations are incorporated into the development and maintenance of the Alayn platform.

Depending on the relevant system, our security practices may include:

  • secure authentication;
  • access controls;
  • input validation;
  • protection against common application vulnerabilities;
  • logging and monitoring;
  • dependency management;
  • vulnerability identification;
  • security testing;
  • controlled software deployments; and
  • ongoing maintenance.

Security practices may evolve as the platform develops and new risks are identified.

8. MONITORING AND LOGGING

Alayn may maintain technical logs and monitoring information to help:

  • detect suspicious activity;
  • investigate security incidents;
  • maintain system reliability;
  • troubleshoot problems;
  • protect accounts;
  • identify misuse; and
  • improve the security of our Services.

Security and technical logs may include information such as:

  • login events;
  • authentication attempts;
  • IP addresses;
  • device information;
  • system events;
  • application errors; and
  • other technical information relevant to security and operations.

Such information is handled in accordance with our Privacy Policy and applicable law.

9. BACKUPS AND RECOVERY

Where appropriate, Alayn may maintain backups of information and systems to support service continuity and recovery.

Backup and recovery procedures may be used to help protect against:

  • accidental deletion;
  • infrastructure failures;
  • system failures;
  • data corruption;
  • security incidents; and
  • other operational disruptions.

Backup practices may vary depending on the type of information and service involved.

Backups are not intended to replace the Customer's own responsibility to maintain appropriate copies of critical business information where necessary.

10. DATA RETENTION AND DELETION

Alayn retains information only for as long as reasonably necessary for legitimate business, contractual, security or legal purposes.

When Customer Data is no longer required, it may be:

  • deleted;
  • anonymised;
  • de-identified; or
  • securely disposed of,

subject to applicable legal, contractual and operational requirements.

Following account cancellation or termination, Customer Data may remain temporarily available to facilitate account closure, data export, dispute resolution or legal compliance.

Further information is provided in our Privacy Policy and Refund & Cancellation Policy.

11. DATA PROTECTION

Alayn is committed to handling personal data responsibly.

Our processing of personal data is governed by our Privacy Policy and applicable data protection laws.

Where Alayn processes personal data on behalf of a Customer, the Customer may determine the purposes for which that information is processed, while Alayn may act as a Data Processor or equivalent service provider depending on the circumstances.

Customers remain responsible for ensuring that they have appropriate rights, notices, permissions and lawful grounds to process personal data through Alayn.

12. AI AND DATA PROTECTION

Alayn incorporates artificial intelligence into certain features of its Services.

AI may process relevant Customer Data where necessary to provide functionality requested by the Customer, including:

  • business intelligence;
  • forecasting;
  • operational recommendations;
  • inventory insights;
  • workforce insights;
  • waste analysis;
  • reporting; and
  • automation.

Customer Data is not used to train general-purpose AI models without appropriate authorisation or consent where required.

Alayn may use aggregated, anonymised or de-identified information for purposes such as service improvement, analytics, research and product development, subject to applicable law.

13. EMPLOYEE AND CUSTOMER INFORMATION

Alayn may process information relating to employees, customers, suppliers and other individuals when such information is entered into the platform by a Customer.

Customers are responsible for:

  • determining appropriate access permissions;
  • limiting access to authorised personnel;
  • maintaining appropriate privacy notices;
  • obtaining required permissions or consent;
  • complying with applicable employment and privacy laws; and
  • ensuring that the information entered into Alayn is lawfully processed.

Alayn provides the technology; the Customer remains responsible for how it chooses to use that technology.

14. THIRD-PARTY SERVICE PROVIDERS

Alayn may use third-party providers for services such as:

  • cloud infrastructure;
  • databases;
  • authentication;
  • payment processing;
  • communications;
  • analytics;
  • security;
  • monitoring;
  • customer support; and
  • other technical functions.

Third-party providers may process information on Alayn's behalf where necessary to provide the Services.

Alayn seeks to use appropriate contractual and technical safeguards when engaging relevant service providers.

Third-party services remain subject to their own applicable terms and privacy policies.

15. INTERNATIONAL PROCESSING

Depending on the infrastructure and service providers used, information may be processed or stored outside India.

Where international processing occurs, Alayn will take appropriate measures required by applicable law.

Our infrastructure and service-provider arrangements may evolve as Alayn expands into additional markets.

Where legally required, we will provide additional information concerning relevant international transfers.

16. SECURITY INCIDENTS

Alayn maintains procedures designed to identify, assess and respond to suspected security incidents.

Where a security incident occurs, our response may include:

  1. identifying and containing the incident;
  2. assessing the nature and potential impact;
  3. taking steps to protect affected systems and information;
  4. investigating the cause;
  5. implementing appropriate remediation;
  6. documenting relevant actions; and
  7. providing notifications where required by applicable law or contractual obligations.

Where Alayn processes Customer Data on behalf of a Customer, we may notify the relevant Customer where appropriate so that the Customer can fulfil its own legal and contractual responsibilities.

17. VULNERABILITY MANAGEMENT

Alayn seeks to identify and address security vulnerabilities affecting its Services.

Depending on the circumstances, this may include:

  • security updates;
  • software patching;
  • dependency updates;
  • configuration changes;
  • vulnerability assessment;
  • security testing; and
  • other remediation measures.

The timing and priority of remediation may depend on the severity and nature of the identified vulnerability.

18. EMPLOYEE AND INTERNAL SECURITY

Alayn seeks to ensure that personnel with access to systems or Customer Data understand their security responsibilities.

Depending on their role, personnel may be subject to:

  • confidentiality obligations;
  • access restrictions;
  • security procedures;
  • account-management controls; and
  • other internal security requirements.

Access to information is limited according to legitimate business requirements.

19. CUSTOMER SECURITY RESPONSIBILITIES

Security is a shared responsibility.

Customers are responsible for:

  • maintaining secure passwords;
  • protecting account credentials;
  • enabling available security controls;
  • managing user permissions appropriately;
  • removing former users promptly;
  • restricting administrative access;
  • ensuring authorised use of integrations;
  • keeping devices and browsers reasonably secure;
  • monitoring appropriate account activity; and
  • notifying Alayn promptly of suspected unauthorised access.

Alayn cannot protect an account where credentials are intentionally shared, compromised through Customer-controlled systems or otherwise misused outside Alayn's reasonable control.

20. SECURITY REPORTING

If you believe you have identified a security vulnerability or security incident affecting Alayn, please contact us promptly.

Security & Privacy Contact: brahmglobalholdings@gmail.com

Please provide as much relevant information as reasonably possible, including:

  • a description of the issue;
  • affected service or functionality;
  • steps required to reproduce the issue, where applicable;
  • relevant screenshots or technical information; and
  • your contact details.

Please do not publicly disclose a suspected vulnerability before allowing Alayn a reasonable opportunity to investigate and respond.

21. SECURITY DISCLOSURES AND CERTIFICATIONS

Alayn is committed to continuously developing its security programme.

We will not claim that Alayn holds a particular security certification, accreditation or compliance status unless that certification or status has actually been obtained and remains current.

Information concerning specific certifications, audits or security assessments may be made available to eligible enterprise customers where appropriate.

22. SERVICE AVAILABILITY

Alayn aims to provide reliable and resilient Services.

However, no internet-based platform can guarantee uninterrupted availability.

Availability may be affected by:

  • planned maintenance;
  • emergency maintenance;
  • infrastructure failures;
  • telecommunications;
  • internet connectivity;
  • third-party services;
  • security incidents;
  • events beyond our reasonable control; or
  • other technical circumstances.

Specific uptime commitments, response times or service levels may be provided under a separate Service Level Agreement (SLA) for eligible enterprise customers.

23. RESPONSIBLE SECURITY PRACTICE

Alayn's security programme is designed to evolve with the platform.

As Alayn grows, we may introduce additional measures including:

  • enhanced authentication;
  • expanded monitoring;
  • security assessments;
  • penetration testing;
  • additional encryption controls;
  • formal security frameworks;
  • independent audits; and
  • additional enterprise security controls.

Where such measures are implemented and materially relevant to customers, we may update this Policy or provide additional documentation.

24. NO ABSOLUTE SECURITY GUARANTEE

While Alayn takes reasonable technical and organisational measures to protect information, no digital system can be guaranteed to be completely secure.

Accordingly, Alayn cannot guarantee that:

  • unauthorised access will never occur;
  • every security vulnerability will always be identified immediately;
  • every third-party service will remain secure;
  • data will never be lost or compromised; or
  • the Services will never experience a security incident.

Alayn will nevertheless take appropriate steps to prevent, identify, contain and respond to security incidents.

25. CHANGES TO THIS POLICY

We may update this Security & Data Protection Policy from time to time to reflect:

  • changes to our technology;
  • improvements to security practices;
  • new Services;
  • changes to our infrastructure;
  • legal or regulatory developments; or
  • changes in industry security practices.

The latest version will always display the applicable Last Updated date.

Material changes may be communicated through the Alayn website, platform, email or other appropriate channels.

26. CONTACT US

For security, privacy or data protection enquiries:

BRAHM GLOBAL HOLDINGSA sole proprietorship owned and operated by Iyaan Khan Tauquir Khan
Principal Place of Business

Shop No. 6, Veena Beena Shopping Centre
Guru Nanak Marg, Bandra West
Mumbai, Maharashtra 400050
India

General Support: info@alaynai.com

Security & Privacy: brahmglobalholdings@gmail.com

GSTIN: 27KOBPK2043Q1ZH

© 2026 Alayn. All rights reserved.

ALAYN AI — The AI Operating System for Modern Business.

Alayn

The Intelligent Operating System for Hospitality. Built for scale, designed for clarity.

Platform

About UsBook a DemoDeveloper APIsLog inSign up

Connect

Contact Salesinfo@alaynai.comllms.txtInstagram

Legal & Trust

Privacy PolicyTerms of ServiceCookie PolicySecurity & Data ProtectionResponsible AICorporate Information

© 2026 Alayn AI (BRAHM Global Holdings). All Rights Reserved.

AboutContactPrivacyAPIs