New Rilono Copilot — AI-powered guidance for DS-160 & visa application workflows, right in your browser.
Add to Chrome Learn More
Rilono Logo Rilono
Home
Student visas
🇺🇸United StatesF-1 · J-1 · M-1 student visas, DS-160, I-20 & interview prep. 🇬🇧United KingdomStudent visa (Tier 4) — CAS, financial proof & interview. 🇨🇦CanadaStudy Permit — LOA, proof of funds & biometrics. 🇦🇺AustraliaSubclass 500 — CoE, OSHC & Genuine Student. 🇩🇪GermanyNational Visa (Type D) — Sperrkonto, APS & admission.
Blog Pricing About Us Enterprise Login Get started

Notifications

No notifications

Dashboard Profile Settings Manage Subscription Referral Program Feature Request Logout

Login

By continuing, you agree to our Terms & Conditions and Privacy Policy, and confirm you are 18+ (or a parent/guardian agrees on your behalf).

or
Forgot Password?

Don't have an account? Register here

Forgot Password

Enter your email address and we'll send you a link to reset your password.

Back to Login | Create Account

Reset Password

Enter your new password below.

Use 10+ characters with uppercase, lowercase, number, and special character. Choose a strong password to protect your account.

Back to Login

Verify Your Email

Please check your email and click the verification link to activate your account.

Back to Login

Email Notifications

Validating unsubscribe link...

Before You Unsubscribe

If you unsubscribe, you may miss important visa alerts, timeline warnings, and document-related updates.

Account: your account

Email notifications are already disabled for this account.
You have unsubscribed successfully. In-app bell notifications will continue.

Create Account

By continuing, you agree to our Terms & Conditions and Privacy Policy, and confirm you are 18+ (or a parent/guardian agrees on your behalf).

or sign up with email
Use 10+ characters with uppercase, lowercase, number, and special character.

We sent a 6-digit code to . Enter it below to verify your email.

Didn't get the code? Resend · Change email

Already have an account? Login here

AI-Powered F1 Visa Workflow

Complete F1 Visa Journey
Without Guesswork

Track documents, catch critical mismatches early, and prepare confidently with one guided workflow.

Get Started Free →
Login to Dashboard Go to Dashboard →
1K+
Students Helped
20+
Document Types
24/7
Rilono AI Assistance
I-20 Form
Verified
Mock Interview
Why this university?
Readiness Score
Excellent 94%
Visa Approved
🇺🇸 F-1 Student Visa✦DS-160✦Form I-20✦SEVIS I-901✦ Visa Interview✦Financial Proof✦Mock Interview✦ University Shortlist✦Document Vault✦Rilono AI Red-Flag Check✦
🇺🇸 F-1 Student Visa✦DS-160✦Form I-20✦SEVIS I-901✦ Visa Interview✦Financial Proof✦Mock Interview✦ University Shortlist✦Document Vault✦Rilono AI Red-Flag Check✦
Study where the postcards are real

United States moments waiting for you

From campus evenings to city icons and west-coast bridges, Rilono helps you prepare for the visa journey before the dream becomes your daily routine.

🇺🇸 Arrival icon Statue of Liberty in New York for students arriving in the United States
Statue of Liberty New York, NY
🎓 Campus life University of Maryland campus at dusk
Campus lights at dusk College Park, MD
🌉 West coast Golden Gate Bridge in San Francisco
Golden Gate Bridge San Francisco, CA
Success story

From application to approved F-1 visa

Prathyaksh Paramashiva in front of the Statue of Liberty after his US F-1 student visa was approved 🇺🇸 F-1 Approved
★★★★★
“Rilono checked every one of my documents before I submitted and drilled me with mock interviews that felt exactly like the real thing. I walked into my F-1 interview calm and confident — and got my visa for Clark University.”
Prathyaksh Paramashiva F-1 student · Clark University, USA
Product Reel

See F1 Visa Prep and DS-160 Help in Action

A fast walkthrough of how students use Rilono for F1 visa document checklist tracking, DS-160 support, mock interview training, and timeline risk alerts.

Document Intelligence Context-Aware Rilono AI Mock Interview Coaching Risk & Deadline Alerts
Start Free → Open Dashboard →
Scene 1 · Document Engine

Upload DS-160, I-20, and financial documents once.

Get Rilono AI validation notes, missing-document warnings, and a stage-wise F1 visa document checklist from first upload to interview readiness.

20+Document Types
Stage-WiseChecklist Tracking
InstantValidation Feedback
✅ Validated
Scene 2 · Personalized Rilono AI

Ask anything. Rilono AI answers with your context in mind.

Chat guidance adapts to your profile, uploaded documents, and current journey stage for better decisions.

24/7Rilono AI Assistance
Profile-AwareRecommendations
FocusedF1 Visa Scope
How much funding do I need to show?
Based on your I-20 from NYU, you need to show $72,500 for the first year.
Scene 3 · Interview Prep

Practice real F1 visa interview questions before interview day.

Train with structured prep sessions and realistic USA student visa mock interview flows to improve confidence, clarity, and answer quality.

VO-StyleMock Simulation
ActionableFeedback Loops
RepeatablePractice Runs
🧑‍💼
"Why are you choosing this specific university?"
Good detail on faculty research!
Scene 4 · Risk Radar

Stay ahead with deadline alerts, news signals, and private access.

Rilono highlights timeline risks, document gaps, and key F1 updates inside a student-only ecosystem.

Real-TimeAlerting
LatestF1 News Tracking
.eduStudent-Only Access
⚠️ I-20 expires in 15 days
ℹ️ New F1 policy update
Document Intelligence

How to Prepare for a US F1 Student Visa

From DS-160 and document collection to F1 visa interview confidence

1

Build Your F1 Visa Document Checklist

Upload required files like DS-160 confirmation, I-20, SEVIS receipt, and financial documents, then monitor stage-wise progress in one place.

Docs Loaded
2

Practice F1 Visa Interview Questions

Use context-aware chat, personalized F1 interview prep, and mock visa-officer practice in chat or voice mode.

Interview Ready
3

Track Updates and Stay Interview-Ready

Follow latest F1 news, real interview experiences, and smart deadline alerts so you stay aligned with current US student visa requirements.

Approved
Now Live on Chrome Web Store

Meet Rilono Copilot for Chrome

Your Rilono AI side panel that reads DS-160 and other visa application pages, then gives step-by-step guidance right inside your browser.

ceac.state.gov/genniv
Consular Electronic Application Center
U.S. DEPARTMENT OF STATE
Apply For a Nonimmigrant Visa
Select a location
INDIA, NEW DELHI
Enter the code as shown
T96CR3
Start Application
R
Rilono AI
Connected as Arjun on rilono.com
Copilot
Usage Guide
RILONO AI COPILOT
New Session
Inspect Page
Read-only. Rilono Copilot does not type, submit, or modify your form data.
Hi! I see you are on the DS-160 application start page. Here's what to do:
Select a location: Choose INDIA, NEW DELHI from the dropdown — the consulate closest to you.
Enter the Captcha exactly as shown, then click Start Application.
Students Studying in The United States
REQUESTING YOUR I-20 (F-1)
All admitted students who will be studying with an F-1 visa need an I-20 form in order to move forward with the visa process.
Funding Source
Personal / Family Funds
Proof of Funds Amount ($)
R
Rilono AI
Connected as Arjun on rilono.com
To receive your I-20, you must show proof of $72,500 for the first year.
Does this include living expenses?
Yes, the $72,500 estimate includes $45,000 tuition and $27,500 for living expenses.
Does this include li|
Privacy Policy • Terms & Conditions
Student Profile Setup
Security Enabled
Passport Number
R
Rilono AI
Connected as Arjun on rilono.com
100% Read-Only Safety
Rilono Copilot never types, submits, or modifies your form data. Your application stays completely in your control.
Input protected...
Privacy Policy • Terms & Conditions
Inspect Page
Reads on-screen context from any visa application page and provides field-by-field guidance.
Rilono AI Copilot Chat
Ask questions about DS-160 fields, I-20 details, or any visa form — get instant, context-aware answers.
100% Read-Only
Rilono Copilot never types, submits, or modifies your form data. Your application stays in your hands.
Works Everywhere
CEAC, university portals, I-20 request pages — Copilot adapts to any page you're on.
Add to Chrome — It's Free →

Available on Chrome, Edge, Brave, and all Chromium browsers

Stop Overpaying for F1 Visa and DS-160 Help

We've been there: DS-160 confusion, I-20 anxiety, endless checklists, and expensive consultant packages for basic advice. Rilono gives you practical Rilono AI guidance for F1 visa documents and interview prep at a fraction of traditional costs.

No more overpaying for outdated advice. Get faster, clearer F1 visa guidance and interview practice — completely free to start.

₹999 one-time · vs ₹50K+ agents
24/7 Always available
Real Experience Built by visa holders
Private Community
Exclusively for Students

No Outsiders. By Students, For Students.

Rilono is a fully private student community. Only verified students planning for F1 visa or currently on F1 status can access Rilono. No agents, no consultants, no outsiders — just fellow students helping each other succeed.

Verified Students Only
.edu email required
Student Community
Share experiences & tips
100% Private
Your data stays yours
Rilono Platform Features

One Platform for DS-160, Interview Prep, and Your Complete F1 Visa Journey

Practical tools for US student visa requirements, document checks, and interview training.

From DS-160 and I-20 readiness to F1 visa interview practice and latest policy updates, Rilono helps you plan, prepare, and reduce rejection-prone mistakes at every stage.

F1 Visa Document Checklist & Tracking
Validate uploaded files, track status by stage, and know exactly what is pending.
DS-160, I-20, and SEVIS Rilono AI Guidance
Get personalized answers based on your profile, documents, and current visa stage.
Risk & Deadline Notifications
Receive alerts for document errors, critical dates, and potential rejection-prone gaps.
F1 Mock Interview (VO Simulation)
Practice realistic visa-officer style interviews and get final approval/rejection probability insights.
F1 Interview Prep Training
Train question-by-question with feedback tailored to your current condition, documents, and goals.
Latest Candidate Experiences
Controlled access to recent F1 interview experiences shared by real candidates online.
Latest F1 News & Changes
Stay aware of policy updates and plan your education and career decisions accordingly.
End-to-End Journey Support
Profile-Aware Personalized Rilono AI
24/7 Rilono AI Assistance

Why Students Use Rilono for F1 Visa Interview Prep

DS-160 help, interview question practice, and complete document support

Rilono AI Answers for DS-160, I-20, and SEVIS

Get instant answers to F1 visa questions across DS-160, I-20, SEVIS, and financial documents.

F1 Document Checklist

Never miss required paperwork. Build a complete F1 visa document checklist from I-20 and passport to bank statements and academic records.

End-to-End Encryption

Your documents are encrypted on your device with a passphrase only you hold, so at rest we only ever store ciphertext we can't read. Each document is read once in memory for AI validation as you upload it, then discarded — never stored unencrypted.

Document Intelligence

Rilono AI extracts and organizes information from your documents automatically. No manual data entry.

F1 Interview Question Practice

Practice common F1 visa interview questions around funding, university choice, and post-study plans with Rilono AI feedback.

Access Anywhere

Your F1 documents and Rilono AI assistant available on any device — even while waiting at the embassy.

F1 Visa Documents We Help With (DS-160, I-20, SEVIS + More)

Core documents required for US student visa interviews

DS-160

DS-160 form and confirmation page

I-20 Forms

Current, previous, and signed copies

Financial Docs

Bank statements, loans, and sponsor proof

Academic Records

Transcripts, degree certificates, and admits

Test Scores

GRE, TOEFL, IELTS

Work Experience

Internship letters and resume

F1 Visa FAQ: DS-160, I-20, SEVIS, and Interview Questions

Quick answers students search before a US visa interview

What documents are required for an F1 visa interview?

Students usually carry passport, DS-160 confirmation, I-20, SEVIS fee receipt, appointment confirmation, financial proof, and academic records.

How do I practice F1 visa interview questions?

Prepare answers for common topics like university choice, funding, course goals, and post-study plans, then improve with mock F1 interview feedback.

What is the DS-160 form for F1 visa applicants?

The DS-160 is your online U.S. nonimmigrant visa application. You need it to schedule and attend your F1 student visa interview.

✈ Now boarding

Ready for Your F1 Visa Interview?

Practice F1 visa interview questions, organize DS-160 and I-20 documents, and walk into your interview with confidence.

Start F1 Visa Prep Free → Go to Dashboard →
✓ Free to start
✓ End-to-end encryption
✓ 24/7 Rilono AI assistance
Rilono
Rilono

Notifications

No notifications

Overview Documents F1-Visa (Interviews) ▾
F-1 Visa Interview Prep (Rilono AI) F1 Mock Interview (Rilono AI) Recent Interview Experiences
News Rilono Copilot Universities
Shortlist & Recommendations SOP Studio
Rilono AI
Subscription
Free
AI: 0/25 used
AI Chat Uploads (24h): 0/7 used
Uploads: 0/5 used
Prep: 0/3 used
Mock: 0/2 used
Profile Settings Subscription Referral Program Feature Request
Logout

Overview

Your dashboard at a glance

🛂 Your F1 Visa Journey

📝
Getting Started
🎓
Admission
📘
I-20
📋
DS-160
💳
Fees Paid
🛂
Visa
✈️
Ready to Fly
📝
Stage 1: Getting Started
Welcome! Start your visa journey.
Next step: Upload your university offer/admission letter

📄 Document Health

Validation Overview
Status of uploaded documents and Rilono AI checks
No Data
Uploaded
0
Unique Types
0
Validated
0
Needs Review
0
Pending Validation
0
Processed
0
Validation Rate 0%
Recent Validation Notes
No documents uploaded yet.

Rilono AI Assistant

Online

Welcome! I'm Rilono AI. I'm here to guide your F1 visa journey with practical, step-by-step help.

I can help you with:

• What to upload next (document checklist)

• Profile and visa-stage gaps you should fix first

• Interview prep, mock questions, and answer quality

• Important deadlines, risks, and updates

Tell me your current stage (I-20, DS-160, fees, or interview), and I'll suggest your best next step.

🎓 Universities

Get Rilono AI university recommendations for your destination and track your shortlist.

Loading…

✍️ SOP Studio

Rilono AI drafts your statement from your real profile and documents — then refines it with you, line by line.

Loading…

Profile Settings

Manage your account information

👤 Profile

Profile Picture
⏳ Pending Change
Waiting for verification:
Email Notifications
Email notifications are currently disabled for this account.
Marketing emails
Product tips, visa updates and occasional offers.

📄 Documentation Preferences

This reflects the study destination saved to your account.

Settings

Manage security and account actions

⚙️ Account Settings

Security
Change your password securely.
Use 10+ characters with uppercase, lowercase, number, and special character.

Destination & visa type

Your dashboard, checklist, and AI guidance are tailored to this destination and visa.

Delete account

Your privacy is yours. Deleting your account permanently erases everything tied to you — your profile, every uploaded document, your AI chats and your journey progress — from our systems and from our encrypted cloud storage. Nothing is retained and it cannot be undone. For your security we'll email a one-time code to confirm it's really you. (We keep only de-identified payment records the law requires, with your personal details removed — see our Privacy Policy.)

This is permanent and cannot be undone. We'll email a one-time code to confirm it's really you before anything is deleted.

Referral Program

Invite a friend — they get ₹200 off their first Visa Success Pass, and you earn a free 30-day Visa Success Pass the moment they purchase it.

🎁 Referral Program

Plan & Billing

Track plan, usage, access period, referral bonus, and billing status.

Current Membership

Free Plan

Get the one-time Visa Success Pass when you need premium access.

Status Active
Billing N/A
Billing Details
Access Until -
Plan Type -
Activated On -
Latest Payment -
Referral bonus: Not active
Included Usage
AI: 0/25 used
AI Chat Uploads (24h): 0/7 used
Uploads: 0/5 used
Prep: 0/3 used
Mock: 0/2 used
Plan Actions

Rilono AI Documentation Agent

Manage your documents and preferences

📄 Document Health

Validation Overview
Status of uploaded documents and Rilono AI checks
No Data
Uploaded
0
Unique Types
0
Validated
0
Needs Review
0
Pending Validation
0
Processed
0
Validation Rate 0%
Recent Validation Notes
No documents uploaded yet.

📁 My Documents

Loading documents...

📤 Upload Documents

🔒 End-to-end encrypted

Your documents are encrypted on your device with your encryption passphrase before they're uploaded — our servers only ever store ciphertext. Keep your passphrase and recovery code safe; without them, encrypted documents can't be recovered.

Loading document types...
Supported formats: PDF, DOC, DOCX, TXT, Images (Max 5MB)
💡 Rilono AI reads this description to better understand and process your document.
🔎 Rilono AI validates every document. Your file is read once in memory to check its type and extract key details, then discarded — it's never stored unencrypted. The document itself is kept end-to-end encrypted.

F1-Visa (Interviews)

Choose a module to work in a dedicated standalone view.

🎯 F-1 Visa Interview Prep (Rilono AI)

Get personalized prep questions and answers based on your profile, docs, and stage.

  • Why this university and program
  • Funding and ties-to-home-country responses
  • Red-flag answer correction
Prep Console
Idle Mode: not selected
Choose Voice or Chat mode to start your prep session. You will get feedback after each answer.
Choose prep mode for this session
Start Prep Session to begin a guided F-1 interview coaching flow.
Mic status checking...

🧠 F1 Mock Interview (Rilono AI)

Run a realistic visa-officer style interview. Feedback is withheld until the final report.

  • Real VO-style question flow
  • No coaching during interview
  • Final approval/rejection probability report
Interview Console
Idle Mode: not selected Time: 00:00 Report: 00:00
Click Start Interview, choose Voice or Chat, then proceed question by question. The Rilono AI officer ends the interview when complete.
Choose interview mode for this session
Interview Transcript
Click Start Interview and choose Voice or Chat to begin your visa-officer simulation. The Rilono AI officer will close it automatically.
Mic status checking...

📚 Recent Interview Experiences

Select a country and one or more consulates to fetch recent interview experiences discussed by users online.

Choose filters and fetch latest experiences.
Fetching interview experiences...

News

Latest visa and student updates

📰 News

Loading latest updates...
Loading F1 visa news...

Rilono Copilot

Application workflow guidance in your Chrome side panel

🧭 What is Rilono Copilot?

Rilono Copilot is a Chrome side-panel assistant for students navigating F-1 visa applications. It helps you move through active forms step by step with context-aware guidance.

It focuses on application workflows like DS-160, university I-20 requests, and related health/onboarding forms, while helping you maintain answer consistency and submission accuracy.

Safety: Inspect Page is read-only
Add Chrome Extension for All Workflows

Unlock Rilono Copilot Workflows

Get the Visa Success Pass to see the power of Rilono Copilot in action across your application workflows.

🧩 Where you can use it

  • DS-160 and visa appointment workflows
  • University I-20 request portals
  • Health and onboarding forms in your F-1 journey
  • Any application pages where you need guided field-by-field help

⚙️ How to use it

  1. Open your active application page in Chrome.
  2. Open Rilono Copilot from the Chrome side panel.
  3. Click Inspect Page to share visible form context.
  4. Ask what to fill next and answer clarifying questions.
  5. Use New Session when you move to a different form.

Rilono AI

Your Rilono AI assistant for visa documentation and guidance

Rilono AI Assistant

Online

Welcome! I'm Rilono AI. I'm here to guide your student visa journey with practical, step-by-step help.

I can help you with:

• What to upload next (document checklist)

• Profile and visa-stage gaps you should fix first

• Interview prep, mock questions, and answer quality

• Important deadlines, risks, and updates

Tell me your current stage (I-20, DS-160, fees, or interview), and I'll suggest your best next step.

Pricing

Simple plans for every stage of your visa journey.

Currency: USD

Free

For getting started

$0/month
  • Up to 25 messages with Rilono AI
  • Up to 7 Rilono AI chat file uploads every 24 hours
  • Up to 5 document uploads
  • Up to 3 interview prep sessions
  • Up to 2 mock interviews
  • Rilono Copilot workflows: No access
  • Dashboard and visa journey tracking
Start Free
Most Popular

Visa Success Pass

One-time payment, 30 days access

One-time pass. No subscription, no auto-renew.
Less than a weekend dinner — pass your interview the first time.
₹999/ one-time
  • Unlimited document audits & red-flag scans
  • 3 full Rilono AI voice mock interviews
  • Unlimited Rilono Copilot (Chrome extension)
  • Unlimited messages with Rilono AI
  • Unlimited document uploads
  • Unlimited Rilono Copilot workflows
  • Valid for 30 days · priority support
For teams

Enterprise

For visa consultancies, universities & study-abroad teams

Free to start · no card required
Scales with your team — pay only for what you use.
Custom · volume plans
  • Team workspace with roles & seats
  • Client CRM — intake, pipeline & document tracking
  • Bulk AI document audits & red-flag scans
  • Rilono AI mock interviews for your clients
  • All destinations: US, UK, Canada, Australia, Germany & Ireland
  • Prepaid Rilono Credits — top up only for premium AI
  • Priority support & guided onboarding
Book a demo Explore Rilono Enterprise →

Prices are shown in local currency and updated daily using exchange rates.

We'd love to hear from you

Get in touch

Have a question, feedback, or need a hand with your visa journey? Drop us a note — our team usually replies within a day.

🔒 Your details are kept private and never shared.

💬

Chat with Rilono AI

Instant answers to visa & document questions — 24/7.

Try Rilono AI →
📧

Email us

For general inquiries:

contact@rilono.com
⏱️

Response time

We typically reply within 24–48 hours on business days.

in

Follow us

Stay connected for updates & tips.

LinkedIn →

About Rilono

Last Updated:

Who We Are

Rilono is an AI-first platform dedicated to simplifying the US F1 visa journey for international students. We combine advanced artificial intelligence with real-time data to bridge the gap between expensive consultants and self-guided research.

Founded by a team of AI engineers and data scientists in Bengaluru, India, we understand the anxiety of the visa process firsthand. We built Rilono to be the intelligent, 24/7 companion we wish we had during our own studies.

What We Do

  • AI Documentation Validation: Instant, intelligent reviews of your visa documents to ensure accuracy and compliance before you submit, with tracking throughout your journey.
  • Mock Interview: Realistic voice-enabled or chat-mode AI mock interviews that prepare you for real consulate pressure, including approval and rejection probability scoring based on your interview conversation.
  • Deadline Guardrails: Smart notifications and timeline tracking so you never miss critical dates, intake deadlines, or submission windows.
  • Real-Time Visa Intelligence: Latest F1 visa news, policy updates, and interview trends curated for your region.
  • F1 Interview Experiences from Real Candidates: Access to recent interview experiences shared by students across countries and consulates.
  • Personalized AI Assistant: A dedicated Rilono AI companion that understands your profile, answers questions quickly, and guides you on exactly what to do next at every stage.

Our Mission

To democratize access to high-quality visa guidance. We believe every student deserves a personalized expert in their pocket: affordable, accurate, and always available.

Contact Us

We are here to help you succeed.

Email: contact@rilono.com
Location: Bengaluru, Karnataka, India

Contact Us Form

Back to Home

Privacy Policy

Last Updated:

1. Introduction

Welcome to Rilono ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, Chrome extension, and AI-powered visa documentation services.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, username, full name, university, current country of residence, and authentication credentials. Passwords are stored only in hashed form; we do not store readable passwords.
  • Profile Information: Profile picture and any additional information you choose to provide
  • Document Uploads: File names, types, metadata you provide, and extracted text for processing
  • Journey Preferences: Destination country, visa type, intake, year, and related application details
  • AI and Support Content: Messages, files, feedback, and support requests you choose to submit

2.2 Automatically Collected Information

  • Usage Data: Information about how you interact with our platform, including pages visited, features used, and time spent
  • Device Information: IP address, browser type, device type, operating system, and unique device identifiers
  • Cookies and Tracking: We use cookies and similar tracking technologies to enhance your experience

2.3 Payment Information

We use third-party payment processors, including Razorpay and applicable app-store payment providers, to handle payments. We do not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their privacy policies. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council.

2.4 Chrome Extension and Page Inspection Data

When you use the Rilono Copilot Chrome extension, the following data is handled only as needed to provide its student-visa application guidance:

  • Authentication Session: The extension reuses your existing signed-in rilono.com session. It does not read, request, or store your password.
  • Local Extension Storage: A limited recent conversation history, attachment metadata, and interface preferences are stored in chrome.storage.local. Attached file contents, inspected-page snapshots, and decrypted vault text are not persisted there.
  • Extension Chat Requests: When you send a message, the message, limited recent conversation history, and files you have selected for that request are sent to our backend to generate a response.
  • Inspect Page Data (User-Initiated): If you click "Inspect Page," the extension requests access to the active site's origin, then captures the page URL, title, language, visible text, visible form-field labels and values, and visible action controls. Password-field values are masked. This snapshot is attached only to the chat session you initiated and is sent when you submit a message.
  • Optional Encrypted-Document Context: If your Rilono vault is unlocked, the extension displays a separate control that is off by default. Only after you enable it for the current Copilot session may decrypted document text be included with chat requests. Your encryption passphrase and vault key never leave the signed-in Rilono page.
  • Sensitive Content in Submitted Context: Depending on what you choose to inspect or attach, submitted context may include personally identifiable information, personal communications, web-history context (for example page URL/title), health-related information, and financial/payment-related information.
  • No Continuous Background Monitoring: We do not continuously collect page content in the background. Page context is captured only when you explicitly trigger inspection.
  • Operational Metadata: We may retain limited records such as timestamps, usage counts, attachment tracking identifiers, request status, and AI cost metadata for quotas, security, troubleshooting, and service reliability.

2.5 Business Verification (KYC) and Payment Collection Data

When an enterprise organization enables Rilono Finance to collect payments from its clients, we process additional data:

  • Business KYC Details: Legal business name, business type, contact details, PAN, GSTIN (optional), IFSC code, and beneficiary name, which are shared with our payment processor (Razorpay) to verify the business and enable settlement. Tax identifiers are stored with encryption at rest.
  • Bank Account Number: The full account number is passed to Razorpay for settlement setup and is not stored by Rilono — we retain only the last 4 digits for display.
  • Payer (Client) Data: For each payment request we process the client's name, email address, amount, description, invoice reference, payment status, and the processor's payment and settlement references, in order to complete the payment on the organization's behalf and maintain financial records. Card, UPI, and banking credentials are collected by Razorpay directly — Rilono never sees them. Processor notifications may include limited contact details and masked payment-instrument metadata, retained for reconciliation, security, and audit purposes.
  • Attestation Records: We record the organization's eligibility attestations (with timestamp and IP address) as proof of the declarations made when connecting a bank account.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Process document uploads, validation, and AI responses
  • Provide Copilot guidance for application workflows in our website and Chrome extension, including user-initiated page-inspection context
  • Send you important updates, notifications, and administrative messages
  • Respond to your inquiries and provide customer support
  • Detect, prevent, and address technical issues and fraudulent activity
  • Comply with legal obligations and enforce our Terms of Service
  • Analyze usage patterns to improve user experience, where permitted and subject to your cookie choices

3.1 Personalization, Encryption, and AI Processing

To provide personalized guidance, we process relevant account, profile, journey, chat, inspected page, and user-selected document context. Uploaded original visa documents are protected by the encryption mode selected in the product. Relevant request content may be processed by Google Gemini / Vertex AI solely to generate the requested validation, recommendation, or response.

Rilono does not use your personal data or document content to train Rilono-owned AI models, and we do not use that data for unrelated commercial purposes. AI processing is limited to delivering and improving your requested platform functionality.

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • Service Providers: We may share information with third-party service providers who assist us in operating our platform (e.g., hosting, analytics, storage, AI processing)
  • AI Processing Partners: We may send relevant request data (such as chat prompts, recent conversation context, attachments, inspected context, and consented decrypted-document text) to Google Gemini / Vertex AI to generate responses.
  • Legal Requirements: We may disclose information if required by law or to protect our rights and safety
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred

4.1 Chrome Web Store Limited Use

Rilono Copilot's use and transfer of information received from Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We do not sell extension user data, use it for personalized advertising, or use it to determine creditworthiness. We transfer it only as needed to provide or improve Copilot's single purpose, protect security, comply with law, or complete a permitted business transfer. Human access is restricted to cases where you give specific consent for support, access is necessary for security or legal compliance, or the data is aggregated and de-identified for internal operations.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

5.1 Data Retention

Account, profile, uploaded-document, billing, and enterprise records are retained only as long as needed to provide the service, meet security and legal obligations, resolve disputes, and enforce our agreements. You may request deletion through your account dashboard, subject to records we must retain by law.

The Rilono application does not persist extension message bodies, inspected-page snapshots, attachment contents, or decrypted vault text as chat records in its application database. They are processed for the requested response. Limited operational metadata described above may be retained. Processing by our AI provider is governed by the applicable provider terms and data controls.

Recent extension chat entries and attachment metadata remain in chrome.storage.local until you clear the conversation, clear the extension's local data, or uninstall it. Deleting your Rilono account initiates deletion of eligible server-side account data, subject to the legal, security, billing, and dispute records described above, but does not automatically erase data stored locally by Chrome.

6. Your Rights and Choices

You have the right to:

  • Access: Request access to your personal information
  • Correction: Update or correct your personal information through your account settings
  • Deletion: Delete your account and associated server-side data by using the account deletion feature in your dashboard, subject to legally required records
  • Opt-Out: Unsubscribe from non-essential communications
  • Data Portability: Request a copy of your data in a portable format
  • Extension Control: You can stop extension-based data collection at any time by disabling optional encrypted-document sharing, clearing local chat history, removing site permissions, clearing extension data, or uninstalling the extension.

7. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Remember your preferences and settings
  • Analyze how you use our platform
  • Provide personalized product content and communications you have requested or consented to

7.1 Analytics

If you enable optional analytics cookies, we use Google Analytics to understand how our Service is used. Google Analytics collects information such as how often users visit this site, what pages they visit when they do so, and what other sites they used prior to coming to this site. We use the information we get from Google Analytics only to improve this site. Google's ability to use and share information collected by Google Analytics about your visits to this site is restricted by the Google Analytics Terms of Use and the Google Privacy Policy.

You can control cookies through your browser settings, but this may affect the functionality of our platform.

The Chrome extension itself does not rely on third-party advertising cookies to inspect page content. Extension authentication depends on your active rilono.com browser session.

8. Children's Privacy

Our platform is not intended for children under 13, and we do not knowingly collect their personal information. Users aged 13 through 17 may use Rilono only with the consent and supervision of a parent or legal guardian. If you believe a child under 13 has provided personal information, contact us immediately.

9. Third-Party Links

Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

10. Cross-Border Data Transfers

Rilono operates globally and relies on trusted sub-processors that may store or process your information outside your country of residence. Depending on the feature you use, your data may be transferred to and processed in the United States, the European Union, India, and other regions where our providers operate, including:

  • Cloudflare R2 (document and file storage) — globally distributed object storage. Documents you upload with end-to-end encryption are stored only as ciphertext.
  • Google (Gemini / Vertex AI) (AI document validation and assistance) — processes the content needed for AI features under the applicable Google service terms and data controls. When you upload a document it is read once, in memory, for AI validation and is not stored unencrypted; separately, your stored end-to-end-encrypted document content is shared with AI only when you enable encrypted-document context in Copilot.
  • Razorpay (payments) — payment processing, primarily in India.
  • Resend (transactional email) — email delivery.

Where required by law — including the EU GDPR and India's Digital Personal Data Protection Act, 2023 (DPDP Act) — these transfers are carried out under appropriate safeguards such as standard contractual clauses and data-processing agreements with each provider. We process and transfer data only as needed for the purposes described in this policy and as permitted by applicable law.

11. Grievance Officer & Data Protection Contact

In accordance with India's Digital Personal Data Protection Act, 2023 and other applicable data protection laws, you may contact our Grievance Officer with any question, request, or complaint about your personal data or the exercise of your rights (access, correction, erasure, or withdrawal of consent):

  • Grievance Officer: Rilono Data Protection Team
  • Email: grievance@rilono.com

We will acknowledge and respond to grievances within the timelines required by applicable law.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Your continued use of our platform after such changes constitutes acceptance of the updated policy.

13. AI Output Disclaimer and Responsibility

Rilono and Rilono AI may generate information, recommendations, summaries, or validations that are incomplete, inaccurate, or outdated. Such output is provided for general informational purposes only and does not constitute legal, immigration, financial, or professional advice. You remain solely responsible for independently verifying all information and for any actions or decisions you take based on platform output. To the maximum extent permitted by applicable law, Rilono disclaims liability for losses, damages, delays, denials, penalties, or other adverse outcomes resulting from reliance on AI-generated output.

14. Rilono Enterprise (Business Customers)

Rilono Enterprise lets visa consultancies, agencies, and similar organizations manage their own applicants through our CRM, AI document review, and mock-interview tools. When an organization uses Rilono Enterprise, that organization decides what end-client information to collect and upload and is the controller of that personal data. Rilono acts as a processor and handles such data on the organization's behalf and instructions, solely to provide the service.

  • End-Client Data: Information an organization uploads about its clients (such as names, contact details, application status, and uploaded documents) is processed to deliver CRM, document-review, and interview-preparation features to that organization.
  • Organization Responsibility: The organization is responsible for having a lawful basis and any necessary consents to collect and share its clients' data with Rilono, and for responding to its clients' privacy requests. Organizations must not upload data they are not authorized to share.
  • Access Controls: Each organization's data is logically separated by tenant, and access is limited to that organization's authorized users and to Rilono personnel and sub-processors who need it to operate or support the service.
  • AI Processing: End-client content may be processed by our AI sub-processors (including Gemini AI) only to generate the requested output. We do not use end-client data to train Rilono-owned AI models or for unrelated purposes.
  • Retention & Deletion: We retain organization and end-client data for as long as the organization's account is active or as needed to provide the service and meet legal obligations. Organizations may request export or deletion of their data, subject to legal retention requirements.

End clients of an organization should direct privacy requests to that organization in the first instance. Where Rilono receives such a request directly, we will refer it to the relevant organization or assist as required by applicable law.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:

Email: contact@rilono.com
Office Region: Bengaluru, Karnataka, India

Contact Us Form

Back to Home

Terms and Conditions

Last Updated:

1. Acceptance of Terms

By accessing and using Rilono ("the Platform," "we," "us," or "our"), you accept and agree to be bound by these Terms and Conditions ("Terms"). If you do not agree to these Terms, please do not use our platform.

2. Description of Service

Rilono is an AI-powered visa documentation platform that helps students organize their visa documents, receive AI guidance, and prepare for visa interviews. We provide document management and informational guidance, but do not provide legal or immigration advice.

2.1 Browser Extension Features

Rilono may provide browser-extension features (including a Chrome side-panel experience) to help users complete application workflows.

  • Extension features rely on your signed-in Rilono session; the extension does not request or store your password.
  • Inspect Page runs only when you explicitly trigger it, requests access to the active site's origin, and is designed for read-only context capture.
  • Encrypted-document context is optional and off by default. It is used only after you enable the session control while your Rilono vault is unlocked.
  • You remain solely responsible for all data entered, reviewed, or submitted in third-party application forms and websites.

3. User Accounts

3.1 Registration

  • You must be at least 13 years old to use our platform. If you are under 18, a parent or legal guardian must consent to and supervise your use.
  • You must provide accurate, current, and complete information during registration
  • You are responsible for maintaining the confidentiality of your account credentials
  • You are responsible for all activities that occur under your account

3.2 Account Termination

We reserve the right to suspend or terminate your account at any time for violations of these Terms, fraudulent activity, or any other reason we deem necessary.

4. User Conduct

You agree not to:

  • Post false, misleading, or fraudulent information
  • Upload documents or content you do not own or have permission to use
  • Use extension or inspection features to collect, upload, or process data without lawful authorization
  • Harass, threaten, or abuse other users
  • Spam or attempt to misuse the platform
  • Violate any applicable laws or regulations
  • Infringe on intellectual property rights
  • Interfere with or disrupt the platform's functionality
  • Use automated systems to access the platform without permission
  • Impersonate any person or entity

5. Document Uploads

5.1 Upload Requirements

  • All uploaded documents must be accurate and lawful to store
  • You must have the rights or permission to upload the files
  • Files must comply with size and type limits described in the platform

5.2 Prohibited Content

You may not upload content that is:

  • Illegal, harmful, or malicious
  • Stolen or confidential without authorization
  • Explicitly abusive or harassing
  • In violation of intellectual property rights

5.3 Moderation

We reserve the right to remove or restrict access to content that violates these Terms or applicable laws.

6. Payments, Paid Access, and Refunds

6.1 Consumer Access

Rilono offers free consumer access and a paid, fixed-duration Visa Success Pass. New consumer purchases are one-time purchases, not recurring subscriptions. By purchasing a Pass, you authorize our payment processor to charge the amount displayed at checkout.

6.2 Visa Success Pass (One-Time Access)

The Visa Success Pass is a one-time purchase that unlocks premium features for a fixed period (currently ₹999 for 30 days, as displayed at checkout). It is not a subscription and does not auto-renew; access ends automatically when the validity period expires, after which you may purchase a new Pass. Feature allowances are shown at checkout and in your dashboard. Prices, validity, and allowances may change for future purchases, but a change will not affect a Pass already purchased. Pass fees are non-refundable except where required by applicable law.

6.3 Rilono Credits (Enterprise)

Rilono Enterprise organizations may prepay for "Rilono Credits," a stored-value balance used to pay for premium AI actions (such as Deep Scan document audits and AI mock interviews) at the per-action credit prices shown in the dashboard. Credits — including any promotional or bonus credits — have no cash value, are not legal tender, cannot be exchanged for money, and are non-transferable between accounts. Purchased credits do not expire while your organization account remains active and in good standing; credits may be forfeited if an account is closed or terminated for a violation of these Terms. Top-up amounts are non-refundable except where required by applicable law. We may change credit pricing or per-action credit costs prospectively; such changes do not affect credits already purchased.

6.4 Expiry, Legacy Subscriptions, and Enterprise Renewals

The consumer Visa Success Pass expires automatically and does not need to be canceled. You may purchase another Pass after expiry. Rilono no longer offers new recurring consumer plans. If your account still has a legacy recurring consumer subscription purchased under an earlier checkout model, it may renew under the terms shown when purchased until you cancel it. You can cancel its auto-renewal from Plan & Billing or by contacting support; paid access normally continues through the current billing period. Rilono Credits are prepaid and do not auto-renew. If an enterprise organization purchases a separately identified recurring plan, its checkout and dashboard will state the billing cycle and cancellation process before purchase.

6.5 Refund Policy

Fees are generally non-refundable after digital access or credits are delivered. Exceptions apply where required by law or where Rilono confirms a duplicate, unauthorized, or incorrect charge. We do not otherwise offer refunds for unused or partially used Visa Success Pass time, unused Rilono Credits, or partial enterprise billing periods. If you believe there has been a billing error, contact support within 7 days after discovering it; this notice period does not limit rights that cannot be waived under applicable law.

6.6 Delivery of Service

Rilono is a digital service. Visa Success Pass access, enterprise paid features, and Rilono Credits are delivered electronically to your account after successful payment verification and activation. No physical goods are shipped.

6.7 Payment Collection for Consultancies (Rilono Finance)

Rilono Finance lets enterprise organizations (consultancies and agencies) collect payments from their own clients through secure payment links. These payments are transactions between the paying client and the organization for the organization's services — Rilono is not a party to that underlying contract. Payments are processed by Razorpay, an RBI-authorised payment aggregator; funds are collected and settled by Razorpay directly to the organization's verified bank account. Rilono never holds or takes custody of these funds.

  • Platform Fee: Rilono deducts a platform fee from each collected payment — a percentage with a minimum amount, as displayed in the Finance dashboard at the time the payment request is created. The paying client is charged only the face amount of the request. The fee is exclusive of the payment processor's own charges and applicable taxes.
  • Onboarding & KYC: To activate collection, the organization must provide accurate business and settlement details, which are shared with Razorpay for verification (KYC). By connecting a bank account, the organization confirms that its details are accurate, that it directly provides the services being paid for, and authorises Rilono to accept Razorpay's linked-account terms on its behalf.
  • Organization Responsibilities: The organization is solely responsible for delivering the underlying services, for the accuracy and lawfulness of its payment requests, for its own taxes, GST, and invoicing to the payer, for honouring its refund commitments, and for any chargebacks or disputes raised on payments collected on its behalf. Amounts refunded, reversed, or charged back may be recovered from the organization's settlements or linked account through the payment processor.
  • Refunds of Collected Payments: Refunds are decided and initiated by the organization and are returned to the payer's original payment method. Where a full refund is processed, the payer receives back the entire amount paid.
  • Suspension: Rilono may suspend or disable payment collection for an organization at any time in cases of suspected fraud, misuse, ineligibility, payment processor requirements, or breach of these Terms.

7. AI Guidance

7.1 Informational Use

  • AI responses are provided for informational purposes only
  • We do not provide legal or immigration advice
  • You are responsible for verifying information and making your own decisions

7.2 Limitations

AI outputs may be incomplete or incorrect. You should consult qualified professionals for legal or immigration guidance.

7.3 Regulated Immigration Advice

Rilono is a self-service software platform for organizing documents and preparing applications. It is not a law firm or a registered or licensed immigration adviser, and it does not provide immigration, migration, or legal advice or representation. In particular, Rilono is not regulated by, and does not act as, an immigration adviser under the regimes governing paid immigration assistance in the countries we support — including the College of Immigration and Citizenship Consultants (CICC) in Canada, the Office of the Migration Agents Registration Authority (OMARA/MARA) in Australia, and the Immigration Advice Authority (IAA, formerly OISC) in the United Kingdom. For advice on your specific circumstances, you should consult a lawyer or a duly registered/licensed immigration or migration professional in the relevant country. Where you use Rilono through a consultancy or agency, that organization — not Rilono — is responsible for any advice it gives you and for holding any licence its jurisdiction requires.

7.4 Data Handling for AI Responses

To provide personalized results, Rilono may process relevant profile, journey, chat, user-selected document, and user-triggered inspected-page context with third-party AI services, including Google Gemini / Vertex AI. Documents are read once, in memory, for AI validation when you upload them; stored end-to-end-encrypted document text is additionally included only after the user enables the applicable Copilot session control. Rilono does not use personal data or document content to train Rilono-owned AI models or for unrelated purposes.

8. Communications

Any communications provided through the platform (including AI chat and support interactions) must be used responsibly. You agree not to:

  • Send spam, unsolicited messages, or advertisements
  • Harass, threaten, or abuse others
  • Use communications for any illegal purpose

9. Intellectual Property

9.1 Platform Content

All content on the platform, including text, graphics, logos, and software, is the property of Rilono or its licensors and is protected by copyright and other intellectual property laws.

9.2 User Content

By posting content on our platform, you grant us a non-exclusive, worldwide, royalty-free license to use, display, and distribute your content in connection with operating the platform.

10. Disclaimers and Limitation of Liability

10.1 Platform "As Is"

Our platform is provided "as is" and "as available" without warranties of any kind, either express or implied. We do not guarantee that the platform will be uninterrupted, error-free, or secure.

10.2 Limitation of Liability

To the maximum extent permitted by law, Rilono shall not be liable for any indirect, incidental, special, consequential, or punitive damages, or any loss of profits or revenues, whether incurred directly or indirectly, or any loss of data, use, goodwill, or other intangible losses.

10.3 No Warranty

We do not warrant the accuracy, completeness, or usefulness of any information on the platform. We are not responsible for the conduct of any user or the outcome of any transaction.

10.4 AI Output and User Responsibility

Rilono and Rilono AI may make mistakes and may provide content that is incomplete, inaccurate, or outdated. Any AI-generated content is provided for informational purposes only and is not legal or immigration advice. You are solely responsible for reviewing and verifying all information before acting on it. To the maximum extent permitted by law, Rilono is not liable for any direct or indirect loss, damage, denial, delay, penalty, or other consequence arising from your use of or reliance on AI-generated output.

11. Indemnification

You agree to indemnify and hold harmless Rilono, its officers, directors, employees, and agents from any claims, damages, losses, liabilities, and expenses (including legal fees) arising out of your use of the platform, violation of these Terms, or infringement of any rights of another.

12. Privacy

Your use of our platform is also governed by our Privacy Policy. Please review our Privacy Policy to understand how we collect, use, and protect your information.

13. Modifications to Terms

We reserve the right to modify these Terms at any time. We will notify users of material changes by posting the updated Terms on this page and updating the "Last Updated" date. Your continued use of the platform after such changes constitutes acceptance of the updated Terms.

14. Termination

We may terminate or suspend your account and access to the platform immediately, without prior notice, for any reason, including breach of these Terms. Upon termination, your right to use the platform will cease immediately.

15. Governing Law

These Terms shall be governed by and construed in accordance with the laws of India, without regard to its conflict of law provisions. You agree that the courts located in Bengaluru, Karnataka, India shall have exclusive jurisdiction over any dispute arising out of or relating to these Terms or your use of the platform.

16. Mobile App Store Terms

If you download the Rilono app from the Apple App Store or Google Play Store, you acknowledge that:

  • These Terms are between you and Rilono, not with Apple or Google.
  • Apple and Google are not responsible for the App or its content.
  • Apple and Google have no obligation to furnish any maintenance or support services for the App.
  • You must comply with applicable third-party terms of agreement when using the App (e.g., your wireless data service agreement).

17. Contact Information

If you have any questions about these Terms, please contact us at:

Email: contact@rilono.com
Office Region: Bengaluru, Karnataka, India

Contact Us Form

Back to Home

Refund Policy

Last Updated:

1. General

Digital access and prepaid credits are generally non-refundable after delivery, except where a refund is required by applicable law or Rilono confirms a duplicate, unauthorized, or incorrect charge. Approved monetary refunds are returned to the original payment method where possible.

2. Visa Success Pass

The Visa Success Pass is a one-time purchase that grants fixed-duration access (currently ₹999 for 30 days, as displayed at checkout). Because access is delivered immediately and does not auto-renew, Pass fees are non-refundable for unused or partially used time except where required by law.

3. Legacy Consumer Subscriptions

Rilono no longer sells new recurring consumer subscriptions. A legacy recurring subscription may continue until canceled under its original checkout terms. Canceling stops future renewals and normally leaves access active through the paid billing period. Charges already processed are generally non-refundable except where required by law or where Rilono confirms a duplicate, unauthorized, or incorrect charge.

4. Enterprise Plans and Credits

Enterprise plan charges and prepaid Rilono Credits are non-refundable after activation or credit delivery except where required by law or expressly stated in an enterprise order form. Credits, including promotional credits, have no cash value and cannot be exchanged for cash.

5. Payments Made to Consultancies (Rilono Finance)

Payments made through a Rilono payment link are payments to the consultancy or agency named on the payment page for its services — not to Rilono. Refunds for such payments are decided and initiated by that organization under its own refund policy; when a full refund is processed, the entire amount is returned to your original payment method. Please contact the organization first with any refund request. If you cannot reach them, contact us at contact@rilono.com and we will help route your request to the right place.

6. Billing Errors

Contact support within 7 days after discovering a billing error and include the payment reference. We will investigate and correct verified errors. This notice period does not limit rights that cannot be waived under applicable law.

7. Contact

For billing questions, contact us at:

Email: contact@rilono.com
Office Region: Bengaluru, Karnataka, India

Contact Us Form

Back to Terms Back to Home

Delivery Policy

Last Updated:

1. Nature of Service

Rilono provides digital software services only. We do not sell or ship physical products.

2. Delivery Timeline

The Visa Success Pass, enterprise plans, and Rilono Credits are delivered electronically after successful payment authorization and verification. Pass or plan access is normally activated immediately; purchased credits are normally added to the organization's wallet immediately.

3. Delays and Failed Activations

If payment is successful but your access is not activated, please contact us from the Contact Us page with your payment reference. We will validate and resolve activation issues as quickly as possible.

4. Contact

Email: contact@rilono.com
Office Region: Bengaluru, Karnataka, India

Contact Us Form

Back to Pricing Back to Home

Data Processing Agreement

Last Updated:

1. Scope and Roles

This Data Processing Agreement ("DPA") governs the processing of personal data by Rilono on behalf of organizations that use Rilono Enterprise — visa consultancies, agencies, and similar businesses that manage their own applicants through the platform ("Organization," "you").

Processor role (the main subject of this DPA). For personal data relating to the Organization's own applicants and to people named in their files ("Client Data"), the Organization is the controller and Rilono is the processor. Rilono processes Client Data only on the Organization's documented instructions, as set out in Section 3 and Annex I.

Controller role (a separate relationship, described here for transparency). Some data Rilono holds in connection with an Enterprise account is not Client Data and is not processed on the Organization's instructions. Rilono is an independent controller for that data and the Privacy Policy — not this DPA — governs it. It comprises:

  • The Organization's own business verification and settlement details collected for Rilono Finance — legal business name, business type, business contact name, email and phone, PAN, GSTIN, the last four digits of the settlement bank account, IFSC code, beneficiary name, and the timestamp, version and IP address of the Organization's service-delivery attestation (see Section 9).
  • Accounts and sign-in data of the Organization's staff users, including authentication records, consent records for the Terms & Conditions and Privacy Policy, and sign-up attribution data.
  • Platform operations data — AI usage metering (token counts, model, cost) attributed to the Organization and the staff user who triggered the action, and staff-facing abuse-control records such as rate-limit counters keyed to a staff member's account or IP address. Abuse-control records generated by the Organization's clients through client-facing links are Client Data and are dealt with in Annex I, not here.
  • Retained financial records. Where the Organization deletes a client record, Rilono retains the associated payment records — including the client's name and the email address the payment link was sent to — as its own accounting records, on the terms set out in Section 13. Rilono determines that retention itself; it is not carried out on the Organization's instruction, and for that residual processing Rilono is a controller relying on its legal obligations under Indian accounting and tax law.
  • Enquiries submitted through Rilono's public demo-request form.

This DPA does not apply to the Rilono consumer platform. Where an individual uses Rilono directly as a student or applicant (the B2C product), Rilono is the controller of that person's data and the Privacy Policy governs it. Nothing in this DPA creates rights or obligations in respect of that relationship, and the technical measures described in this DPA describe the Enterprise product only.

2. Definitions

  • "Client Data" means personal data relating to the Organization's applicants and to other individuals named in or derived from the Organization's files, which Rilono processes on the Organization's behalf through Rilono Enterprise. Annex I sets out the categories in detail.
  • "Client" or "end client" means an applicant or other individual whose record the Organization maintains in Rilono. Clients do not hold Rilono user accounts; their records are created and controlled by the Organization's staff.
  • "Data Protection Laws" means all laws applicable to the processing of Client Data under this DPA, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR, in each case to the extent they apply.
  • "controller," "processor," "personal data," "processing," "data subject" and "personal data breach" have the meanings given in the GDPR; where the DPDP Act applies, "Data Fiduciary" and "Data Processor" are read as controller and processor respectively.
  • "Sub-processor" means a third party engaged by Rilono to process Client Data. Annex II is the current register.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 and, for transfers subject to the UK GDPR, the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018.
  • "Services" means Rilono Enterprise, including the web dashboard, the client-facing portal and links described in Section 8, Rilono Finance, and the Rilono Copilot browser extension.

3. Processing Instructions and Purpose

Rilono processes Client Data only on the Organization's documented instructions. The Organization's instructions are: this DPA, the Terms & Conditions, the configuration choices the Organization's staff make in the product, and any further written instruction the parties agree. Rilono will inform the Organization if, in its opinion, an instruction infringes Data Protection Laws.

Processing required by law. Rilono may process Client Data otherwise than on the Organization's documented instructions where it is required to do so by a law to which Rilono is subject. In that case Rilono will inform the Organization of that legal requirement before processing, unless that law prohibits it from doing so on important grounds of public interest.

Government and law-enforcement demands. Rilono is established in India and is subject to Indian law, including the Information Technology Act, 2000 and the DPDP Act. If Rilono receives a binding demand from a public authority — law enforcement, a regulator, a court or a national-security body — for disclosure of Client Data, Rilono will:

  • notify the Organization promptly, and where possible before disclosing anything, unless legally prohibited from giving notice; where notice is prohibited, use reasonable efforts to obtain a waiver of the prohibition and to inform the Organization as soon as it is permitted to;
  • challenge the demand where, on a reasonable assessment, it is unlawful, overbroad or does not follow the applicable procedure, and, where a challenge is available, suspend disclosure pending its outcome so far as the law allows;
  • disclose only the minimum amount of Client Data that the demand actually requires; and
  • keep a record of the demands it receives and provide the Organization, on written request, with aggregate figures on those demands and how it responded.

These commitments mirror Clause 15 of the Standard Contractual Clauses. Rilono has not to date published a transparency report; the aggregate figures above are provided on request.

The purposes for which Rilono processes Client Data are the delivery of the following features. This list describes the processing surface as at the "Last Updated" date at the top of this document; Section 15 governs how it changes:

  • Client CRM and pipeline management — storing and organising applicant records, assignment, priority and pipeline stage.
  • Destination-aware case records — structured, per-stage case fields specific to the destination country (for example SEVIS and DS-160 references for the United States, CAS and GWF references for the United Kingdom, UCI and IRCC application numbers for Canada, TRN and HAP identifiers for Australia, APS and blocked-account details for Germany, and AVATS references for Ireland).
  • Document storage — storing documents uploaded by the Organization's staff and by clients themselves.
  • AI document processing — extracting the text of each uploaded document, validating it, extracting structured fields (name, date of birth, document number, issue and expiry dates, country), cross-checking a document against the client's profile and their other documents, and recording validation outcomes and red-flag explanations.
  • Automated profile population — where an identity document validates successfully, populating empty fields on the client's profile (name, date of birth, nationality, passport number, passport expiry) from the extracted values, recording differences as conflicts rather than overwriting existing values, and adding a note to the client timeline attributed to "Rilono AI".
  • Deep Scan — a whole-dossier AI audit that reviews the client's profile, case records, document contents, staff notes, stored emails, university shortlist, mock-interview results and payment records together, and produces a stored risk level, summary, findings and checks-passed record retained as history.
  • AI Copilot in the dashboard — an assistant scoped to the Organization's own records, which reads those records and generates an answer but creates and alters no client records.
  • AI Copilot in the Rilono browser extension — see Section 10.
  • AI mock visa interviews — conducted by staff on a client's behalf or by the client directly through an emailed link, grounded in the client's own documents and staff notes, producing a stored transcript, AI feedback and verdict. Staff notes are excluded from the prompt on the client-facing path.
  • Email — composing, sending and storing the Organization's outbound email to its clients, including attachments (see Section 8). Rilono does not currently receive or store clients' replies; the dormant inbound capability, and the notice Rilono will give before activating it, are described in Section 8.
  • Client portal — making a read-only case portal available to the Organization's clients and reporting their engagement with it back to staff (see Section 8).
  • Document requests — inviting clients to upload their own documents through a secure link.
  • Calendar, deadlines and reminders — recording case events and deadlines, in-product staff notifications, and automated reminder emails to clients where staff enable them.
  • University shortlisting and Course Finder — generating and storing university and course recommendations with AI rationale, competitiveness assessments and estimated costs. Both features transmit client profile data to the AI sub-processor; Annex II states exactly what is sent.
  • Rilono Finance — raising payment requests to the Organization's clients and recording collection, settlement, refund and dispute status (see Section 9).
  • Service operation and support — hosting, backup, security monitoring, fault diagnosis, and support requested by the Organization.

Restrictions Rilono accepts. Rilono will not sell Client Data, will not process Client Data for its own unrelated commercial purposes, and does not use Client Data to train Rilono-owned AI models. Client Data is not used for Rilono's marketing, is not added to any Rilono marketing audience, and no analytics or advertising technology operates on the Enterprise dashboard, the client portal or the payment page.

A limit on what Rilono can promise about AI providers. Client Data is transmitted to the AI sub-processors named in Annex II, which process it under their own terms. Rilono's no-training commitment above is a commitment about Rilono's own models. Rilono's AI integration can operate through either Google Cloud Vertex AI or the Gemini API depending on how the deployment is configured, and the applicable Google terms — including whether prompts and responses may be used by Google to improve its services — differ between them. Rilono therefore does not represent that Client Data is excluded from the AI provider's own model training, and the Organization should treat that as an open point in its own assessment. Annex II states the position in full.

4. Organization Responsibilities

The Organization is the controller of Client Data and is responsible for it. In particular:

  • Lawful basis and notice. The Organization warrants that it has a valid lawful basis, and has given all notices required of a controller, for collecting its clients' personal data and for having Rilono process it as described in this DPA — including processing by the AI sub-processors in Annex II and the international transfers in Section 7.
  • Per-client consent attestation. Rilono requires a staff member to confirm, when a client record is created, that the client has consented to their personal data being processed through Rilono. Rilono records the confirmation and the staff member who gave it as an audit trail. Rilono does not verify that confirmation; it is the Organization's warranty, and responsibility for its accuracy rests with the Organization.
  • Third parties named in files. Client files routinely contain personal data about people who are not the applicant — sponsors, guarantors, parents, guardians, spouses, dependants, referees and employers — including their financial evidence. Rilono's AI extraction records the names of every person appearing in a document. These individuals have no relationship with Rilono. The Organization is solely responsible for informing them and for the lawful basis for processing their data.
  • Minors. The platform supports destinations whose checklists contemplate applicants under 18 and their guardians, and Rilono applies no age verification to client records and holds no age flag on them. Where the Organization enrols a minor, the Organization is solely responsible for obtaining verifiable parental or guardian consent and for any additional protections required by Data Protection Laws. The Organization should note in particular that section 9(3) of the DPDP Act prohibits tracking and behavioural monitoring of children outright — a prohibition that parental consent does not cure — and that the portal engagement telemetry described in Section 8 is behavioural data. Because there is no age flag on a client record, Rilono cannot suppress that telemetry automatically; the Organization must not issue portal links to clients it knows or believes to be under 18 unless it has satisfied itself that doing so is lawful.
  • Direct contact with clients. Several features have Rilono email the Organization's clients directly and collect data from them (Section 8). The Organization instructs Rilono to do so and warrants that it has informed its clients that a third-party platform will contact them on the Organization's behalf, that messages will be sent from a rilono.com address branded "{Organization} via Rilono", and that clients may be asked to upload identity and financial documents directly to Rilono. The Organization is responsible for providing its clients with its own privacy notice.
  • Content the Organization transmits. Staff-authored free text — case notes, calendar reminder notes and email bodies — is transmitted to clients as written. Rilono acts only as a conduit and does not review that content.
  • Accuracy and rectification. The Organization is responsible for the accuracy of Client Data, including AI-derived values (extracted fields, validation messages, Deep Scan risk levels and recommendation rationales) which are generated automatically, may be wrong, and must be reviewed by the Organization before being relied on. The Organization must correct inaccurate records through the dashboard.
  • Data minimisation. The Organization must not upload data it is not authorised to share, and should not enter personal data into free-text fields beyond what the engagement requires.
  • Access management. Any active member of the Organization can see every client record in that Organization. Rilono provides organization-level roles (administrator, editor, viewer) but no per-record access restriction. Deciding who to invite and at what role is the Organization's responsibility.
  • Data subject requests. The Organization is responsible for responding to its clients' privacy requests, with Rilono's assistance as described in Section 11.

5. Confidentiality and Security

Rilono keeps Client Data confidential, and personnel with access are bound by confidentiality obligations and act only on the Organization's instructions or as required by law. Rilono maintains the technical and organisational measures set out in Annex III.

Client Data is readable by Rilono, by design. The Organization should understand this before signing. To deliver the AI features in Section 3 — document validation, Deep Scan, the Copilot, mock interviews and recommendations — Rilono's systems must be able to read the contents of Client Data. Specifically:

  • Uploaded document files are encrypted by the application before they are written to object storage, using a key Rilono holds, and are decrypted by Rilono's servers whenever they are read. The storage provider holds ciphertext; Rilono holds the key.
  • The text extracted from documents, the structured facts derived from them, extracted field values, validation messages, Deep Scan findings, case records, staff notes, email bodies and interview transcripts are stored in Rilono's database in readable form, because the AI features must query them.
  • Passport numbers on client records are the only category of Client Data for which Rilono operates field-level encryption at rest. That control is qualified: it depends on an encryption key being supplied through the deployment environment, and it is backward-compatible, meaning a value written to the database before the control was introduced remains in plaintext until that record is next saved. Rilono has not run a migration to encrypt pre-existing rows. Annex III(A) and Annex III(H) describe this in full, and the Organization should not treat passport-number encryption as universal.

No end-to-end encryption for Client Data. Rilono offers end-to-end encryption on its separate consumer product, where documents are encrypted in the user's browser and the server holds no key. That feature does not exist in Rilono Enterprise and none of its protections apply to Client Data. Rilono makes no claim that it is technically unable to read Client Data, and the Organization should not represent otherwise to its own clients.

Rilono's internal administrative console provides no interface for browsing an Organization's client records, documents or extracted document text; its Enterprise views are limited to account, billing and credit metadata. This is an application-layer control, not a cryptographic one, and it does not restrict access at the database or infrastructure layer by the personnel who operate the platform.

The Organization is responsible for the security of its own staff accounts and credentials and for removing access promptly when a staff member leaves.

6. Sub-processors

The Organization gives Rilono general written authorisation to engage sub-processors to process Client Data. The current register is at Annex II, which names each sub-processor, what it processes and its processing region. Annex II also identifies, separately and for transparency only, third parties that process data for which Rilono is a controller under Section 1 and which is therefore not Client Data.

Rilono imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to the Organization for a sub-processor's performance of those obligations.

Change notification and objection. Rilono will give the Organization at least thirty (30) days' notice before adding or replacing a sub-processor that processes Client Data, by updating Annex II and notifying the Organization's administrators at their registered email address. The Organization may object on reasonable data-protection grounds within fifteen (15) days of that notice. If the parties cannot agree a resolution, the Organization may terminate the affected Services on written notice without penalty, with a pro-rata refund of prepaid fees for the unused period. Where a change is required urgently to protect the security or availability of the Services, Rilono may make it immediately and notify the Organization without undue delay; the objection right above still applies.

Sub-processor assurance. On the Organization's reasonable written request, Rilono will pass through any audit report, certification or security documentation it holds in respect of a sub-processor, to the extent that sub-processor permits disclosure, and will exercise its own contractual audit and information rights against that sub-processor on the Organization's behalf where doing so is necessary to address a specific, identified concern.

7. International Transfers

Rilono operates globally and relies on the sub-processors in Annex II, which may store or process Client Data outside the Organization's own country. Depending on the features the Organization uses, Client Data may be transferred to and processed in the United States, the European Union, India, and other regions where those providers operate. AI processing in particular is performed on Google infrastructure and may take place in the United States.

Rilono maintains data-processing agreements with each sub-processor and transfers Client Data only as needed for the purposes described in Section 3 and as permitted by Data Protection Laws.

Transfer mechanism — read this before relying on it. Where the Organization is subject to the EU GDPR or the UK GDPR and requires a transfer mechanism under Chapter V, the Standard Contractual Clauses are not incorporated into this DPA by reference. Rilono has deliberately not done so, because clauses incorporated without their options resolved and their annexes completed are not a reliable safeguard. Instead, Rilono will, on the Organization's written request and before or at the time the Organization begins transferring Client Data, enter into the Standard Contractual Clauses with the Organization as a separate executed schedule to this DPA, completed as follows: Module Two (controller-to-processor); Clause 7 (docking) included; Clause 9 option (a), general written authorisation, with the thirty (30) day notice period in Section 6; the Clause 11(a) optional independent-redress mechanism not included unless the Organization requires it; Clause 17 governed by the law of the EU Member State in which the Organization is established, or Ireland where the Organization is not established in the EU; and Clause 18(b) forum being the courts of that Member State. Annex I of this DPA is drafted to complete Annex I of those Clauses, and Annex III of this DPA to complete their Annex II. For a UK exporter, Rilono will execute the UK International Data Transfer Addendum with Tables 1 to 4 completed and the Mandatory Clauses acknowledged.

Until such a schedule is executed between the parties, the Organization should not treat this DPA on its own as establishing a Chapter V transfer mechanism. Rilono will provide its transfer impact assessment, and the government-access information described in Section 3, on written request. Where the Standard Contractual Clauses are executed, their governing-law and forum provisions prevail over Section 15 for the transfers they govern.

Rilono has not independently verified, and does not represent, the specific storage region of any individual sub-processor's infrastructure beyond what that provider publishes.

8. Direct Interactions with Data Subjects

Rilono contacts the Organization's clients directly, on the Organization's instruction. This is a material feature of the Services and the Organization should read this section before using it. In every case the message is sent from a rilono.com address and is branded "{Organization} via Rilono". These are transactional messages tied to the client's case; they carry no marketing content and no unsubscribe link, because clients have no Rilono account.

  • Client portal. Staff can issue a read-only portal link. Rilono emails the link to the client, verifies the client with a one-time code sent to their own email address, and issues them a short-lived, read-only session. The portal shows the client their own profile (with the passport number masked to its last three characters), case records, document list and status, university shortlist and payment history. It has no write, upload or download capability, and internal free-text counselor notes and the Organization's commission and payout figures are deliberately withheld. Portal links expire after 180 days and staff can revoke them at any time, which takes effect immediately.
  • Engagement telemetry. Each time a client opens their portal, Rilono records the timestamp and increments an open counter, and reports both back to the Organization's staff as an engagement signal. This is behavioural data about the client. The Organization instructs Rilono to collect and report it and is responsible for disclosing it in its own privacy notice. Portal links should not be issued to a client the Organization knows or believes to be under 18 without the Organization satisfying itself that doing so is lawful, given the outright prohibition on tracking and behavioural monitoring of children in section 9(3) of the DPDP Act. Rilono does not currently offer a per-client or per-share control to suppress telemetry, and holds no age flag on client records; until it does, the only way to avoid the telemetry is not to issue the link. Rilono will delete telemetry records for a named client on the Organization's written request.
  • Mock-interview invitations. Rilono emails the client a link allowing them to take AI mock interviews themselves, verified by one-time code. The full transcript, AI feedback and verdict are stored on the Organization's account, staff are notified, and Rilono emails the feedback report to the client. Invitations expire after 30 days.
  • Document requests. Rilono emails the client a link, verified by one-time code, allowing them to upload their own documents directly into the Organization's account. Client-uploaded documents go through the same AI extraction, validation and profile-population pipeline as staff uploads. Requests expire after 30 days.
  • Calendar reminders. Where staff enable client notification on a case event, an automated job emails the client the event title, its due status and the staff-written note verbatim, with no human review at the time of sending.
  • Payment requests. See Section 9.
  • Outbound email. Staff-composed messages to clients are sent through Rilono and stored on the client's record, including the message body and any attachments. Where a document already on file is attached, a separate copy of that document is created and retained with the sent message, so that the record of what was actually sent survives later deletion of the original document. Section 13 explains what that means for deletion and retention.
  • Inbound email — dormant, and controlled by Rilono, not by the Organization. Rilono does not receive clients' replies. Outbound messages carry the sending staff member's own email address as the Reply-To, so replies go to that staff member's mailbox, outside Rilono's systems. Rilono has built, but has not activated, the capability to route replies back into the client record. Activating it would be a platform-wide change made by Rilono; it is not a setting the Organization holds, and no per-organization control for it exists. Rilono will not activate it for the Organization's account without first giving the Organization's administrators written notice under Section 15, and the Organization may object on the same terms as for a sub-processor change under Section 6. If it were activated, the reply body, subject and sender address would be stored on the client record, inbound attachments would not be stored, and the email sub-processor in Annex II would receive and hold the full inbound message.

Voice mode. Where a mock interview is taken in voice mode, speech synthesis and speech recognition are performed by the participant's own web browser. Rilono neither receives nor stores audio — only the resulting text. The Organization should be aware that some browsers transmit captured audio to their own vendor's speech service; that is a characteristic of the participant's browser and is outside Rilono's systems and its sub-processor chain.

A capability link alone, before the one-time code is verified, discloses a limited preview: the Organization's name, the client's first name, destination and visa type, a masked form of their email address and, for document requests, the list of requested documents and the staff message. Case data is released only after the one-time code is verified.

9. Payments and Rilono Finance

Rilono Finance lets the Organization collect payments from its own clients through payment links, using Razorpay Route. Consistent with the Terms & Conditions, the payment is a transaction between the paying client and the Organization for the Organization's services; Rilono is not a party to that underlying contract, funds are collected and settled by Razorpay directly to the Organization's verified bank account, and Rilono never holds or takes custody of those funds. The two data relationships are different and are set out separately below.

(a) The client's payment data — Client Data, Rilono as processor. On the Organization's instruction, Rilono raises a payment request against a client, emails the client a payment link, hosts the checkout page, and records the outcome. Rilono processes and stores: the client's name and the email address the link was sent to, invoice number and description, amounts (including the Organization's commission and payout), due date, payment method (including off-platform methods such as cash, UPI or cheque recorded by staff), Razorpay order, payment and transfer identifiers, settlement status and bank UTR, refunds, and dispute status including chargeback, retrieval, fraud and pre-arbitration phases and reason codes. The client enters their payment instrument directly with Razorpay; Rilono does not receive or store card or bank credentials.

Rilono also stores the raw webhook payloads it receives from the payment processor as an append-only reconciliation ledger. These can contain the payer's contact details and masked payment-instrument metadata; their retention is governed by Section 13.

(b) The Organization's own onboarding data — not Client Data, Rilono as controller. To activate collection, the Organization provides business verification and settlement details. These concern the Organization and its own officers, not its clients, and Rilono does not process them on the Organization's instruction as a processor. Rilono transmits legal business name, business type, contact name, email and phone, PAN, GSTIN, stakeholder name and email, and the full settlement bank account number, IFSC code and beneficiary name to Razorpay for verification. Rilono does not store the full bank account number — only the last four digits, the IFSC code and the beneficiary name are retained for display. PAN and GSTIN are stored using the same field-level encryption control as passport numbers, subject to the same qualifications set out in Section 5 and Annex III(A). Rilono records the Organization's service-delivery attestation with its timestamp, version and the IP address from which it was given. Stakeholder verification material beyond name and email is held by Razorpay, not by Rilono. The Privacy Policy governs this data.

The Organization remains solely responsible for the accuracy and lawfulness of its payment requests, for its own tax and invoicing obligations to the payer, for honouring its refund commitments, and for chargebacks and disputes.

10. Rilono Copilot Browser Extension

Rilono publishes a Chrome extension that gives the Organization's staff access to the Copilot while they work. The Organization should understand both what it does and what constrains it.

What it can send, and where. Every request the extension makes is routed through an authenticated rilono.com tab using the staff member's own session, and is checked against a fixed, hard-coded allowlist of six Rilono endpoints: four read-only endpoints (the current user, onboarding status, and the Copilot context and client-list endpoints) and two chat endpoints (general AI chat and Copilot chat). The two chat endpoints are not read-only — they carry the staff member's prompt and any attached context outward to Rilono and on to the AI sub-processor, and they debit the Organization's AI credit meter and write a usage record. They create and alter no client records. A request to any other endpoint is rejected. The allowlist is enforced independently in the extension's background worker and again in the page. The extension declares no external connectivity, so no third-party website can invoke it, and its content script runs only on rilono.com. The extension cannot send data anywhere other than Rilono.

What it can read. The allowlist constrains destinations, not content. The extension includes an "Inspect Page" action which, when a staff member clicks it, reads the page in the active browser tab and captures the page URL, title and language, up to 28,000 characters of visible text, and up to 220 visible form controls including the values currently entered in them, together with visible button labels. Password fields are replaced with a masked placeholder; no other field type is masked. On a government or institution application form this can include the applicant's identity, contact and history data as typed. The captured block is attached to the Copilot conversation and transmitted to Rilono and on to the AI sub-processor. Rilono does not write it to its database — Copilot conversations and their attachments are held only for the duration of the request. That says nothing about what the AI sub-processor retains, which is governed by that provider's own terms.

The controls on that capability. The extension holds no standing access to any site other than rilono.com. Access to any other site is requested from the browser at the moment of use, origin by origin, and the browser prompts the staff member to grant it. Capture never happens in the background or automatically; it requires an explicit click each time.

What the extension is not given. The client list the extension retrieves deliberately excludes sensitive identifiers such as passport numbers. For completeness, the Organization should note that the passport number is nevertheless included in the client profile that Rilono's server assembles and sends to the AI sub-processor for Copilot and Deep Scan requests, together with the extracted text of the client's documents. Both statements are true: the extension does not receive the passport number; Rilono's server transmits it to the AI provider.

The Organization is responsible for instructing its staff on appropriate use of the Inspect Page action, for the credit consumption those requests cause, and for any third-party terms that govern the sites on which they use it.

11. Data Subject Requests and Assistance

Clients should direct privacy requests to the Organization in the first instance, because the Organization — not Rilono — is the controller and Data Fiduciary for Client Data. Where Rilono receives a request directly from one of the Organization's clients, Rilono will not respond to it on the merits and will promptly refer it to the Organization, unless legally required to act otherwise. The Grievance Officer named in Section 16 acts only as a referral point in respect of Client Data.

Taking into account the nature of the processing, Rilono will provide reasonable assistance to help the Organization meet its obligations, by appropriate technical and organisational measures and insofar as possible, including:

  • Responding to requests for access, rectification, erasure, restriction, objection and portability. Most of these the Organization can satisfy itself: client records, case data, documents, notes, emails, interview results and recommendations are all directly viewable and editable in the dashboard, and portal, interview and document-request links can be revoked there. Section 13 sets out the limits of what deletion in the dashboard actually removes, and what must be requested from Rilono in writing.
  • Export. The product does not offer a self-service bulk export. Where the Organization needs a structured copy of its Client Data, Rilono will produce one through a manual process within thirty (30) days of a written request from an administrator, in a commonly used machine-readable format.
  • Assisting with the Organization's obligations on security, breach notification, data protection impact assessments and prior consultation with a supervisory authority, taking into account the information available to Rilono.
  • Providing, on written request, the information in this DPA and its Annexes needed to answer a client's question about how their data is processed.

Rilono may charge a reasonable fee for assistance that is manifestly unfounded, excessive or repetitive, having first notified the Organization.

Automated decision-making. Rilono's AI features generate assessments about individuals — document validation outcomes, Deep Scan risk levels and findings, and admission-difficulty and rationale text on recommendations. These are decision-support outputs presented to the Organization's staff; Rilono takes no decision about any client. Where a client exercises a right in relation to such an output, the Organization is the party that must respond, and Rilono will assist as set out above.

12. Personal Data Breach

Rilono will notify the Organization without undue delay and in any event within twenty-four (24) hours after becoming aware of, or forming a reasonable suspicion of, a personal data breach affecting Client Data. Rilono will not delay an initial notification because its investigation is incomplete. Notice will be sent to the email addresses of the Organization's administrators and to any dedicated security contact the Organization has given Rilono in writing.

The notification will describe, to the extent then known and as further information becomes available: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Rilono will provide updates at reasonable intervals until the incident is closed, will provide the information reasonably available to it to help the Organization meet its own notification duties to supervisory authorities and to affected individuals, and will document the breach and the remedial action taken.

Notification is not an acknowledgement of fault or liability. Rilono will not notify the Organization's clients or any supervisory authority about a breach affecting Client Data on the Organization's behalf unless the Organization instructs it to do so in writing or Rilono is legally required to.

13. Retention, Return and Deletion

Rilono retains Client Data for as long as the Organization's account is active, except where a shorter period is stated below. The Organization can delete client records, individual documents, notes and case data from the dashboard at any time, and doing so is an instruction to Rilono to delete that data. What that deletion actually reaches today is set out below, and the Organization should read it before relying on the dashboard as its erasure mechanism.

What dashboard deletion does and does not remove.

  • Deleting an individual document from a client's record deletes both the database record and the encrypted file in object storage.
  • Deleting a client record removes that client's database records — the profile, case data, document metadata, extracted text and structured facts, notes, emails, interview results and recommendations. It does not currently remove the corresponding encrypted document files, or the encrypted copies of files attached to messages already sent, from object storage. Those objects are left in place, unreferenced, as ciphertext under a key Rilono holds. Rilono will delete them on the Organization's written request, and is working to make client deletion remove them automatically; until that ships, an Organization that requires the file objects themselves to be destroyed must ask.
  • Sent messages cannot currently be deleted through the dashboard, and neither can the copy of an attachment stored with a sent message. Rilono will delete a specified sent message and its stored attachment copy on the Organization's written request.

Retention targets, and how they are enforced. Rilono has adopted the retention limits below. The Organization should understand that Rilono does not currently operate an automated retention sweep over Enterprise Client Data; these limits are enforced operationally, on request and on review, and Rilono is building the automated enforcement. Until Rilono confirms in an updated version of this DPA that automated enforcement is live, these are commitments Rilono performs manually, not periods the platform imposes by itself:

  • Uploaded client documents — a target of 1,095 days (three years) from upload. Rilono's objective is to delete the document record, its stored file and the text and structured facts derived from it no later than 1,095 days after it was uploaded, whether it was uploaded by staff or by the client. An Organization that needs a shorter or a certain period should delete documents from the dashboard, which takes effect immediately.
  • Raw payment webhook payloads — a target of 180 days. Rilono's objective is to redact the raw payload received from the payment processor no later than 180 days after receipt. The ledger record itself is retained — the event identifier, event type, entity references, amount and timestamps remain, so that payments stay reconcilable and duplicate events are not reprocessed.
  • Copies of documents attached to sent messages are not subject to the 1,095-day target. They are retained with the message for the life of the client record, or until Rilono deletes them on written request.
  • Capability links. Mock-interview invitations and document requests expire 30 days after issue; portal links expire after 180 days. One-time codes expire after 15 minutes and lock after six failed attempts. Sessions issued to clients last 3 hours (interviews), 6 hours (document uploads) or 24 hours (portal). These periods are enforced in code.
  • Abandoned draft email attachments. Rilono sweeps a staff member's stale draft attachments, and the files behind them, when that staff member next uploads an attachment; the sweep targets drafts older than 48 hours. There is no background timer, so a draft abandoned by a staff member who never composes again can persist until Rilono removes it, which it will do on written request.

Deletion on termination. On termination or expiry of the Services, and at the Organization's choice, Rilono will return Client Data (through the manual export process in Section 11) or delete it. Unless the Organization instructs otherwise in writing within thirty (30) days of termination, Rilono will delete Client Data within ninety (90) days of termination, including the object-storage files described above. Rilono will confirm deletion in writing on request. There is no self-service organization-closure or tenant-deletion function; termination and deletion are carried out by Rilono operationally on written instruction.

What deletion does not reach. The Organization should be aware of the following exceptions, which apply both to deletion of an individual client and to deletion on termination:

  • Object-storage files after client deletion. As described above, deleting a client record does not itself remove the encrypted document and email-attachment files from object storage; they remain until deleted on written request or through the deletion-on-termination process.
  • Financial records survive. Payment records are deliberately retained when a client record is deleted, because they are Rilono's own accounting records. They carry forward the client's name and the email address the payment link was sent to, de-linked from the deleted client record. Rilono retains them for the period required by applicable tax and accounting law, which under Indian law is not less than eight (8) years from the end of the relevant financial year. This retention is carried out by Rilono as a controller under Section 1, in reliance on its own legal obligations, is not used for any other purpose, and is governed by the Privacy Policy.
  • Sent message attachments. A document attached to a message sent to a client is stored as a separate copy with that message. Deleting the original document does not delete that copy. Deleting the client record removes the database record of the message and its attachment but, as noted above, not the underlying stored file.
  • Incidental references. A client's name may persist in the Organization's own credit-usage history (as the label on a charged AI action) and in staff notification records. Rilono will remove such references on the Organization's written request.
  • Legal holds and backups. Rilono may retain Client Data where required by law, and residual copies may persist in routine backups for a limited period before being overwritten. Data retained on either basis remains subject to every obligation in this DPA that survives termination under Section 15, and is not processed for any other purpose.

Where Rilono acts as a controller under Section 1, retention of that data is governed by the Privacy Policy.

14. Audit

Rilono will make available to the Organization the information necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by the Organization or an auditor it mandates, on the following terms.

  • Information on request, at any time. Rilono will provide this DPA and its Annexes, written responses to a reasonable security questionnaire, and any third-party audit report, certification or penetration-test summary it then holds, on reasonable written request and without any annual limit. Rilono holds no third-party security certification at present (see Annex III(H)).
  • On-site and hands-on audits. Where the Organization reasonably considers that the information above is insufficient to address a specific, identified concern, or where a supervisory authority requires it, the Organization may conduct an on-site or hands-on audit. Such an audit may be conducted not more than once in any twelve (12) month period, except where it is required by a supervisory authority or follows a personal data breach affecting the Organization's Client Data, in which case the frequency limit does not apply.
  • Notice. At least thirty (30) days' prior written notice for an on-site or hands-on audit, with the scope agreed in advance, save where a supervisory authority requires shorter notice.
  • Sub-processors. Rilono will pass through sub-processor audit reports and certifications as described in Section 6, and will exercise its own audit and information rights against a sub-processor on the Organization's reasonable request.
  • Conduct. Audits take place during business hours, must not unreasonably disrupt Rilono's operations, and must not compromise the confidentiality, security or availability of other customers' data. The Organization's auditor must not be a competitor of Rilono and must sign a confidentiality undertaking before access is given.
  • Confidentiality. All information obtained in an audit is Rilono's confidential information, may be used only to verify compliance with this DPA, and must not be disclosed except to the Organization's professional advisers or a supervisory authority requiring it.
  • Cost. Each party bears its own costs. Where an audit requires significant Rilono personnel time beyond the documentation response, Rilono may charge its reasonable costs at its then-current professional-services rates, notified and agreed in advance. Where an audit identifies a material breach of this DPA by Rilono, Rilono bears its own costs and will remediate at its expense.

15. Term, Liability, Amendments and Order of Precedence

Term. This DPA takes effect when the Organization accepts it and continues for as long as Rilono processes Client Data. Sections 3, 5, 6, 7, 11, 12, 13, 14, 15 and 16, together with Annexes I, II and III, survive termination and continue to apply for as long as Rilono retains any Client Data.

Liability. Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Terms & Conditions, except as follows:

  • The exclusion in the Terms & Conditions of liability for loss of data does not apply to claims under this DPA or arising out of a personal data breach affecting Client Data. That exclusion would otherwise remove liability for the very harm this DPA concerns, and the parties agree it is disapplied here.
  • The indemnity given by the Organization in the Terms & Conditions does not extend to claims arising out of Rilono's own breach of this DPA or of Data Protection Laws.
  • Mutual indemnity. Each party indemnifies the other against claims by data subjects under Article 82 GDPR (or its equivalent under other Data Protection Laws) and against administrative fines imposed by a supervisory authority, in each case to the extent the claim or fine is attributable to that party's own breach of this DPA or of Data Protection Laws.
  • Cap. Subject to the paragraph below, each party's aggregate liability for all claims under this DPA is limited to the total fees paid or payable by the Organization for the Services in the twelve (12) months preceding the first event giving rise to the claim. This cap applies to claims under this DPA in addition to, and separately from, any general cap in the Terms & Conditions, and is not reduced by claims under those Terms.

Nothing in this DPA or in the Terms & Conditions limits or excludes either party's liability where it cannot lawfully be limited or excluded, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, and including the rights of data subjects under Data Protection Laws. Where the Standard Contractual Clauses are executed under Section 7, nothing in this Section limits the liability provisions of Clause 12 of those Clauses in respect of the transfers they govern.

Amendments. Rilono may update this DPA to reflect changes to the Services, its sub-processors or Data Protection Laws. Rilono will publish the updated version, update the "Last Updated" date and, where a change materially affects the processing of Client Data, notify the Organization's administrators at their registered email address at least thirty (30) days before it takes effect. If the Organization objects within that thirty-day period and the parties cannot agree a resolution, the Organization may terminate the affected Services without penalty, with a pro-rata refund of prepaid fees for the unused period. Continued use of the Services after that thirty-day notice period constitutes acceptance of the updated version. Sub-processor changes follow the notice and objection process in Section 6.

Adding a new purpose or category of processing to Section 3 is a material change requiring notice under this Section; where it introduces a new category of personal data or a new sub-processor, it requires the Organization's agreement rather than deemed acceptance. Any change that materially reduces the protections in this DPA likewise requires the Organization's agreement, and where the parties disagree on whether a change does so, the Organization may exercise the objection and termination right above.

Record of the version in force. Rilono records the version of this DPA that an Organization has accepted, the date of acceptance, and the administrator who accepted it. When this DPA is updated, the Rilono Enterprise portal notifies the Organization and prompts an administrator with user-management rights to review and accept the updated version; other staff are shown the notice but cannot accept on the Organization's behalf. The Organization should note that Rilono stores only the most recent acceptance — accepting a new version replaces the previous record rather than adding to a history, so Rilono cannot evidence the full sequence of versions an Organization has accepted over time. Rilono will supply written confirmation of the version currently recorded against an Organization on request.

Order of precedence. This DPA supplements the Terms & Conditions. In the event of any conflict regarding the processing of Client Data, the order of precedence is: (1) the Standard Contractual Clauses or other transfer mechanism, where executed and where they apply to the transfer in question; (2) this DPA; (3) the Terms & Conditions; (4) the Privacy Policy. For all other matters the Terms & Conditions prevail. For the avoidance of doubt, the Privacy Policy does not override this DPA in respect of Client Data.

Governing law. This DPA is governed by the laws of India and is subject to the exclusive jurisdiction of the courts of Bengaluru, Karnataka, India, as provided in the Terms & Conditions — except that, where the Standard Contractual Clauses are executed under Section 7, their own governing-law and forum provisions prevail for the transfers they govern.

16. Contact

Rilono is operated by [REGISTERED ENTITY NAME], a company incorporated in India (CIN [CIN]) with its registered office at [REGISTERED OFFICE ADDRESS], Bengaluru, Karnataka, India. These details identify the processor that contracts under this DPA.

In accordance with India's Digital Personal Data Protection Act, 2023, questions, requests and complaints about personal data may be addressed to our Grievance Officer. Scope: the Grievance Officer answers on the merits only in respect of data for which Rilono is a controller under Section 1. For Client Data, the Organization is the Data Fiduciary and the Grievance Officer acts as a referral point only, forwarding the request to the Organization as described in Section 11.

  • Grievance Officer: Rilono Data Protection Team
  • Email: grievance@rilono.com

We will acknowledge and respond to grievances within the timelines required by applicable law.

EU and UK representatives. Rilono has not at the date of this DPA appointed a representative under Article 27 of the EU GDPR or of the UK GDPR. An Organization established in, or with data subjects in, the EU or the UK should take this into account in its own assessment. Rilono will appoint and publish representatives where it is required to do so, and will update this Section when it does.

For contractual and commercial matters relating to this DPA, including sub-processor objections, audit requests, export requests, deletion instructions, requests for the executed Standard Contractual Clauses, and supervisory-authority correspondence:

Entity: [REGISTERED ENTITY NAME]
Email: contact@rilono.com
Data protection: grievance@rilono.com
Office Region: Bengaluru, Karnataka, India

17. Annex I — Details of Processing

This Annex is drafted so that it can complete Annex I of the Standard Contractual Clauses where those Clauses are executed under Section 7.

A. Parties

  • Data exporter / controller: the Organization, as identified in its Rilono Enterprise account. Role: controller of Client Data. Contact: the administrator email addresses registered on the account. Activities relevant to the transfer: providing visa, education and immigration advisory services to its own clients.
  • Data importer / processor: [REGISTERED ENTITY NAME], Bengaluru, Karnataka, India. Role: processor. Contact: grievance@rilono.com. Activities relevant to the transfer: operating the Rilono Enterprise platform and carrying out the processing described in Section 3.

B. Subject matter, duration and frequency

Subject matter. Rilono's provision of the Rilono Enterprise platform to the Organization, and the processing of Client Data necessary to deliver the features listed in Section 3.

Duration. For the term of the Organization's subscription, plus the retention and deletion periods in Section 13.

Frequency of transfer. Continuous, for the duration of the Services. A transfer occurs each time a staff member or a client uses a feature that involves a sub-processor named in Annex II.

C. Nature and purpose of the processing

Collection, recording, organisation, structuring, storage, retrieval, adaptation, automated analysis by AI models, disclosure by transmission to the data subject and to sub-processors, erasure and destruction — for the purposes enumerated in Section 3, namely: client CRM and pipeline management; destination-specific case records; document storage; AI text extraction, document validation, structured field extraction, cross-validation and automated profile population; whole-dossier Deep Scan audit; AI Copilot in the dashboard and in the browser extension; AI mock visa interviews, staff-run and client self-serve; outbound email (and inbound reply capture only if Rilono activates that dormant capability on notice under Section 8); the read-only client portal and engagement reporting; client document requests; calendar events, deadlines and automated client reminders; staff notifications; university shortlisting and Course Finder recommendations; payment collection through Rilono Finance; and platform operation, security and support.

D. Categories of data subjects

  • The Organization's visa applicants (end clients) — the primary category. They hold no Rilono account; their records are created and controlled by the Organization's staff.
  • Third parties named in a client's documents or derived facts — sponsors, guarantors, parents, guardians, spouses, dependants, referees, employers and any other person named in an uploaded document. Rilono's AI extraction records every person name appearing in a document.
  • Minors and their guardians or custodians, where the Organization enrols applicants under 18. Rilono applies no age verification to client records.
  • Third-party payers — a person other than the client who pays a payment request, and (only if inbound reply capture is ever activated under Section 8) any third party who replies into a client email thread.
  • The Organization's staff users, to the extent their identity appears in Client Data (for example as the author of a note, the sender of an email or the person who triggered an AI action). Staff account data itself is processed by Rilono as a controller under Section 1.

E. Categories of personal data

  • Identity and contact data — full name, email address, phone number, nationality, date of birth. Nationality is not special-category data, but combined with name and travel documents it may indirectly indicate ethnic origin.
  • Government and travel identifiers — passport number (subject to the qualified field-level encryption described in Section 5 and Annex III(A)) and passport expiry date.
  • Immigration case data — visa category, destination country, visa type, intake, application reference, pipeline stage, priority, target dates, and structured per-stage case fields. Depending on destination these include enquiry source and prior refusal history; funds-evidence status and amounts; tuition deposit; application submission and visa fee receipts; appointment date, location, reference and biometrics attendance; case status and information-request dates; visa decision dates, visa document numbers and validity; passport-return tracking; and refusal date, refusal ground, appeal deadline and appeal status.
  • Destination-specific government identifiers — including SEVIS ID, I-901 receipt, DS-160 confirmation number, consular post and G-221 slip reference (United States); CAS number, ATAS reference, GWF/UAN number, IHS reference and eVisa share code (United Kingdom); UCI, IRCC application number, DLI, LOA, PAL/TAL, CAQ and GIC certificate numbers, biometrics deadline, medical exam status and misrepresentation findings (Canada); TRN, CoE number, CRICOS code, OSHC policy number, HAP ID, medical clinic date and medical status (Australia); APS certificate number, blocked-account provider and number, health-insurance type and VIDEX barcode (Germany); AVATS application number, ILEP programme code and medical insurance policy number (Ireland).
  • Document files and their contents — passports and biometric pages, photographs, academic transcripts and certificates, admission and offer letters, English-test results, bank statements and balance certificates, loan sanction letters, sponsor affidavits with the sponsor's own income and bank evidence, chartered-accountant net-worth statements, scholarship awards, insurance documents, government forms, prior-refusal documents, and any other file the Organization or its client uploads.
  • AI-derived data — extracted document text; extracted structured fields (name, date of birth, document number, issue and expiry dates, country and other information); validation status and free-text validation messages, which are AI judgements about the person or their evidence; cross-validation conflict flags; cached structured facts per document, including person names, dates of birth, passport numbers, nationalities, institutions, financial amounts and key dates; and stored Deep Scan audits comprising a risk level, summary, findings and checks-passed record, retained as history.
  • Communications — outbound email to clients including recipient, subject, plain-text and rich-text body, attachments and delivery status; and, only if inbound reply capture is activated under Section 8, the client's reply body, subject and sender address.
  • Interview data — the full transcript of AI mock interviews as authored by the participant, AI feedback, verdict and mode. Transcripts routinely contain the applicant's own account of their finances, sponsorship, family circumstances and study intent.
  • Recommendation data — university and course shortlists with AI rationale, competitiveness assessment (reach, match or safety), estimated tuition, requirements and staff notes; and Course Finder request parameters, AI summary and recommendation lists.
  • Payment data — client name and payer email as recorded at the time, invoice number, description, amounts, commission and payout, due date, payment method including off-platform methods, payment processor order, payment and transfer identifiers, settlement status and bank UTR, refunds, and dispute status, phase and reason code (including fraud-phase disputes, which record an allegation against a named individual). Card and bank credentials are entered directly with the payment processor and are not received or stored by Rilono.
  • Engagement and technical data — the timestamp and count of each time a client opens their portal, reported to the Organization's staff; the email address a capability link was sent to; one-time-code verification attempts; and the IP address of clients who use the portal, document-upload, interview or payment links, together with the rate-limit and abuse-prevention counters keyed to it. These client-facing abuse-control records are Client Data, processed by Rilono as processor on the Organization's instruction for the security purposes contemplated by Article 32 GDPR; the equivalent records generated by the Organization's own staff sit in Rilono's controller role under Section 1.
  • Staff-authored free text — case notes, hold and refusal notes, rebuttal plans, calendar event notes and any other free-text field, which may contain any category of personal data the Organization chooses to enter.

F. Special-category and sensitive data

The Services are not designed to collect special-category data as a distinct field, but it is routinely and sometimes necessarily present in a student-visa dossier. The Organization must satisfy itself of a valid condition for processing it under Article 9 GDPR and the equivalent provisions of the DPDP Act.

  • Health data is not incidental. A tuberculosis test certificate is a required checklist item for the United Kingdom; health or travel insurance proof is required for Germany and Ireland; and medical examination status is a required case field for Canada and Australia, including outcomes such as "further tests requested" or "referred to a medical officer". Health-insurance and eMedical identifiers are recorded as structured fields.
  • Immigration-compliance and adverse-history data — prior refusal history (including overstay, status violation and removal), refusal grounds (including documents false or unverifiable, character or suitability, and health or security inadmissibility), and misrepresentation findings including a recorded five-year ban. Under the GDPR this sits close to Article 10; under the DPDP Act it is sensitive in effect.
  • Financial data about both the applicant and third parties — bank balances, income evidence, loan sanctions, blocked accounts and sponsor affidavits.
  • Family and relationship data — dependants included in an application, marriage and relationship certificates, guardianship and custodianship declarations.

Biometric data — a precise statement. The image of a passport biometric page and applicant photographs are uploaded and stored. Rilono's processing of them is text and field extraction only. Rilono performs no facial recognition and creates no biometric template, and therefore does not process biometric data for the purpose of uniquely identifying a natural person within the meaning of Article 9 GDPR.

No sensitivity classification. Special-category data is not separately identified, tagged or segregated in the platform. It resides inside document files, extracted text, derived facts, case fields, notes, email bodies and interview transcripts, and is handled with the same controls as all other Client Data.

G. Retention and onward transfers

Retention. Client Data is retained for the periods and on the terms set out in Section 13, which the Organization should read together with the disclosure there that automated retention enforcement for Enterprise data is not yet in operation.

Onward transfers. The sub-processors in Annex II(A) process Client Data for the purposes and for the duration described in Annex II and in Section 3, under data-processing terms no less protective than this DPA. Rilono does not otherwise transfer Client Data onward, save as required by law and subject to the government-access commitments in Section 3.

H. Competent supervisory authority

Where the Standard Contractual Clauses are executed under Section 7, the competent supervisory authority is the authority of the EU Member State in which the Organization is established or, where the Organization is not established in the EU, the authority of the Member State in which its Article 27 representative is established or in which the data subjects whose data is transferred are located. For a UK exporter it is the Information Commissioner's Office. The parties will record the specific authority in the executed schedule.

I. Roles

For all data described in this Annex I, the Organization is the controller and Rilono is the processor. The data described in Section 1 as belonging to Rilono's controller role is not Client Data, is not covered by this Annex, and is governed by the Privacy Policy.

18. Annex II — Sub-processor Register

A. Sub-processors of Client Data

  • Cloudflare, Inc. (Cloudflare R2) — object storage. Stores uploaded client document files and email-attachment files. Rilono encrypts these files before they are written, so the provider holds ciphertext. Region: globally distributed object storage.
  • Google LLC (Gemini API / Vertex AI) — AI processing. Receives: document text and files for extraction and validation; for Deep Scan, the client profile — including name, email, phone, nationality, date of birth and passport number — together with case records, staff notes, stored emails, university shortlist, interview results, payment records and document contents; for each Copilot request, the client profile and document text, including any page content captured by the browser extension; document-grounded context for mock interviews; for university shortlisting, the client's nationality and academic profile (the client's name is not included in that prompt); and for Course Finder, on every run and regardless of whether search grounding is used, the client's full name, nationality, destination, visa type, target intake, target date and up to eighteen scalar case-field values from the client's case record, alongside the consultant's request parameters and notes. Where PDFs are processed through the file-upload interface, the file is transmitted to Google's file service and deletion is then requested. Region: United States and other Google regions. Terms: Rilono's integration can run through Google Cloud Vertex AI or through the Gemini API depending on deployment configuration, and the applicable Google terms differ between them — including on whether Google may use prompts and responses to improve its services. Rilono does not represent that Client Data is excluded from Google's model training. An Organization for which this is material should raise it with Rilono in writing before transferring Client Data.
  • Google LLC (Google Search grounding) — a distinct mode of the above, in which a live Google Search tool call forms part of the model request. This mode is always attempted for university shortlisting, and is used for Course Finder where Rilono's verified internal catalogue is thin for the destination. The data sent is as described in the entry above. Region: as above.
  • Resend, Inc. — transactional email. Delivers Rilono's email to the Organization's staff and, more significantly, directly to the Organization's clients: portal invitations and one-time codes, interview invitations, codes and feedback reports, document requests and codes, payment requests, calendar reminders, and staff-composed messages. Attachment content is transmitted in readable form, so identity and financial documents pass through this provider. If Rilono ever activates inbound reply capture (Section 8), this provider would also receive and hold clients' complete inbound messages, including attachments. Region: United States.
  • Razorpay Software Private Limited — payment processing, including Razorpay Route. Processes the paying client's name, email address and payment instrument, and returns transaction, settlement, refund and dispute records. Region: India.

B. Third parties processing data for which Rilono is a controller (not Client Data)

Listed for transparency. This data is governed by the Privacy Policy, not by this DPA.

  • Cloudflare, Inc. (Turnstile) — bot mitigation on Enterprise staff sign-in, sign-up and password reset. Receives the staff member's IP address and a challenge token. The Turnstile script is loaded by the Enterprise application shell, so Cloudflare sees the staff member's IP address on Enterprise page loads generally, not only at the authentication gate. It is not present on the client portal, interview, document-upload or payment pages and does not process Client Data.
  • Razorpay Software Private Limited — verification (KYC) of the Organization's own business and settlement details under Section 9(b). Region: India.
  • Google LLC — federated sign-in for staff accounts that choose it. Rilono receives email address, verification status, name and a provider subject identifier.

C. Third parties that are not sub-processors

  • Reference-data lookups — currency-rate services and published government maintenance-fund pages. These are requests for reference data only and transmit no personal data.
  • The participant's own web browser — voice mode in mock interviews uses the browser's built-in speech synthesis and recognition. Rilono receives only text. Any transmission of audio to a browser vendor's service is a characteristic of that browser, not a Rilono sub-processing operation.
  • Google Cloud Text-to-Speech is used only in Rilono's consumer product and processes no Client Data.
  • Rilono uses no analytics or advertising provider on the Enterprise dashboard, the client portal or the payment page.

19. Annex III — Technical and Organisational Measures

The measures below are those Rilono actually operates. Rilono has deliberately not listed measures it does not yet have; Section H below sets those out expressly, and Section 14 describes how the Organization can verify this Annex.

A. Encryption

  • In transit — TLS for all connections, with HTTP Strict Transport Security applied for one year including subdomains.
  • At rest, object storage — uploaded client documents and email attachments are encrypted by the application, using authenticated symmetric encryption (AES-128 in CBC mode with HMAC-SHA256 integrity), before being written to storage, and are stored as opaque binary objects. Keys are held by Rilono and the data is decrypted on read. This is not end-to-end encryption.
  • At rest, field level — with important qualifications. Client passport numbers, and the Organization's PAN and GSTIN, are configured to be stored under field-level encryption using the same authenticated cipher. No other Client Data field is individually encrypted. Three limits apply and the Organization should factor them into its own assessment: (i) the control depends on an encryption key being present in the deployment environment — if no key is configured the application logs a warning and stores the value as plaintext rather than failing; (ii) it is backward-compatible by design, so a value written before the control was applied to a column is read back as plaintext and stays plaintext until that record is next saved; and (iii) Rilono has not run a backfill to encrypt pre-existing rows, so a plaintext tail may remain. Rilono states this rather than asserting universal coverage.
  • Keys are supplied to the application through its deployment environment, and the field-encryption key may be derived from the application's general secret rather than from a dedicated, segregated key. Rilono does not currently operate a managed key-management service, hardware security module or automated key-rotation process, and does not claim to.

B. Tenant isolation and access control

  • Every authenticated request is bound to the caller's organization membership and to that organization's dedicated portal subdomain; a request whose subdomain does not match the caller's organization is rejected.
  • Record lookups are scoped to the caller's organization. One user account belongs to one organization.
  • Role-based access at the organization level: administrator, editor and viewer. There is no per-client or per-record restriction within an organization — any active member can see every client in that organization.
  • Rilono's internal administrative console has no interface for reading an organization's client records, documents or extracted document text; its Enterprise views cover account, billing and credit metadata only. This is an application-layer control and does not restrict access at the database or infrastructure layer.
  • Rilono personnel are bound by confidentiality obligations and access Client Data only where needed to operate or support the Services. Rilono does not currently operate multi-factor authentication or an audit log of personnel access, and does not claim to.

C. Authentication and session security

  • Passwords are stored using the bcrypt adaptive hash.
  • Session cookies are HttpOnly, Secure and SameSite-restricted, with server-side session invalidation that revokes previously issued tokens.
  • Client-facing capability links (portal, interview, document request, payment) never store the raw token — only a hash, compared in constant time. Opening a link requires a six-digit one-time code sent to the client's own email address, valid 15 minutes with a six-attempt cap. The resulting session is short-lived and scoped to that single purpose.
  • Portal payloads mask the passport number to its last three characters and omit internal counselor free-text notes and the Organization's commission and payout figures.

D. Application and transport hardening

  • A Content-Security-Policy restricting script, connect, frame, object, base-uri and form-action sources to Rilono and a named allowlist of payment, bot-mitigation and analytics providers. Inline scripts are currently permitted (the policy includes 'unsafe-inline' in script-src), which materially weakens the containment a Content-Security-Policy would otherwise give against cross-site scripting. Rilono states this rather than describing the policy as strict. The header is emitted by default and its value is configurable through the deployment environment.
  • frame-ancestors and X-Frame-Options set to deny, X-Content-Type-Options nosniff, a strict referrer policy, and cross-origin opener and resource policies.
  • An explicit cross-origin allowlist with no wildcard origin.
  • All API responses are marked private and no-store and vary on credentials.
  • Uploaded files are checked against an extension allowlist and a size cap, stored under non-guessable keys, and served only through authenticated, organization-scoped endpoints — never from a public or pre-signed URL. The served content type is derived from the validated extension rather than from the uploader's declared type, and anything not known-safe is forced to download, which substantially reduces the risk of stored cross-site scripting from uploaded files. Rich-text email bodies are sanitised before sending.
  • Rilono relies on SameSite cookie enforcement rather than synchroniser-token CSRF protection, and states this expressly rather than claiming a control it does not have.

E. Abuse prevention and integrity

  • Rate limiting on authentication, administrative, AI, upload, email and all public client-facing endpoints, keyed to the requesting IP address and, where relevant, the organization or user.
  • Bot mitigation on staff sign-in, sign-up and password reset.
  • Inbound webhooks from the payment processor and the email provider are verified by HMAC-SHA256 signature over the raw request body, compared in constant time. A request-size cap is applied to the inbound-email webhook; the payment webhook is rate-limited but is not currently size-capped.
  • Webhook events are de-duplicated against a unique event identifier so that a repeated event is not reprocessed. This engages where the provider supplies its event-identifier header; a signed event delivered without one is not currently caught by that constraint.

F. AI processing controls

  • Copilot conversations and any context attached to them, including page content captured by the browser extension, are processed for the duration of the request and are not written to Rilono's database. What the AI sub-processor retains is governed by that provider's terms, not by this control.
  • The browser extension can transmit only to a fixed allowlist of six Rilono endpoints — four read-only, and two chat endpoints that carry the prompt and any attached context outward and debit the Organization's credit meter — always through an authenticated rilono.com tab, and it can be invoked by no third-party site. Page capture requires an explicit per-origin browser permission granted at the moment of use, and password fields are masked.
  • The client list exposed to the browser extension deliberately excludes passport numbers.
  • On the client-facing mock-interview path, staff notes are excluded from the model prompt.
  • AI usage is metered per organization and per user for billing and cost control; those metering records store token counts, model and cost, not prompt or response content.

G. Operational resilience and assurance

  • Availability and backups. The platform's database and object storage run on managed cloud infrastructure with the provider's own redundancy and routine backups. Rilono does not currently publish a recovery time or recovery point objective and does not commit to one in this DPA.
  • Vulnerability and dependency management. Rilono applies security updates to its application dependencies and hosting platform on an ongoing basis. Rilono does not currently commit to a defined patching cadence.
  • Incident handling. Rilono investigates suspected security incidents on becoming aware of them and notifies the Organization on the terms in Section 12.
  • Personnel. Rilono personnel are bound by written confidentiality obligations.

H. Measures Rilono does not currently claim

For the avoidance of doubt, and so that the Organization's own assessment is accurate, Rilono does not presently claim any of the following. Rilono will update this Annex as these change, in line with Section 15.

  • End-to-end or zero-knowledge encryption of Client Data.
  • A managed key-management service, hardware security module, key rotation, or a field encryption key segregated from the application's general secret.
  • A completed backfill of field-level encryption over rows written before that control was applied.
  • Multi-factor authentication for staff accounts, or audit logging of Rilono personnel access to Client Data.
  • Synchroniser-token CSRF protection, or a Content-Security-Policy that excludes inline scripts.
  • Per-record access control within an organization.
  • Automated retention enforcement for Enterprise Client Data, or an automated tenant-offboarding or organization-deletion routine — the retention and deletion commitments in Section 13 are performed operationally.
  • Automatic removal of object-storage files when a client record is deleted (see Section 13).
  • A request-size cap on the payment-processor webhook, or de-duplication of signed webhook events delivered without the provider's event-identifier header.
  • A per-organization control over inbound email reply capture (see Section 8), or a per-client control over portal engagement telemetry (see Section 8).
  • A periodic penetration test, a formal programme for regularly testing and evaluating the effectiveness of these measures under Article 32(1)(d) GDPR, a documented disaster-recovery plan with tested restores, formal personnel background screening or a recurring security training programme, or any third-party security certification or attestation (such as ISO/IEC 27001 or SOC 2).
Back to Home
Rilono

The AI-powered platform for student visas to the US, UK, Canada, Australia & Germany — helping students and consultancies prepare confident, complete applications.

Product
  • US F-1 Visa
  • UK Student Visa
  • Canada Study Permit
  • Australia Subclass 500
  • Germany Student Visa
  • Rilono Enterprise
  • Pricing
Company
  • About us
  • Careers
  • Blog
  • Contact
  • Login
  • Enterprise Login
  • Get started
Legal
  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Delivery Policy
  • Data Processing Agreement
  • Cookie Settings

Rilono provides document-organization and Rilono AI guidance tools — not legal or immigration advice. Visa rules change often; always confirm requirements with the official government source for your destination.

© 2026 Rilono. All rights reserved. Made for international students 🌍

Cookie Preferences

We use necessary cookies to keep Rilono secure and working. With your consent, we also use analytics cookies to understand usage and improve the platform. Learn more.

Cookie Settings

Choose what you want to allow. Necessary cookies stay on to keep login, security, and core features working.

Strictly Necessary

Required for authentication, security, and essential website functionality.

Analytics

Helps us understand traffic and product usage through Google Analytics.

💡 Request a Feature

Share what would help your F1 journey. We review all requests and prioritize by student impact.

Name: -
Email: -
🎓

Change University

Enter your new university email to verify and update your university.

Must be a valid .edu email from your new university

📧 A verification email will be sent to your new university email.
Click the link to confirm the change.

🎁

Invite Friends, Earn a Free Visa Success Pass

Your friend gets ₹200 off their first Visa Success Pass — and the moment they buy it, you earn a free 30-day Visa Success Pass.

Your Referral Code
--------
Your Invite Link
Visa Success Pass

Unlock everything

One payment, 30 days of full access — no subscription, no auto-renew. Everything stays right here in your dashboard.

What You Get
  • Unlimited document audits & red-flag scans
  • 3 full Rilono AI voice mock interviews
  • Unlimited Rilono AI messages & uploads
  • Unlimited interview prep & Copilot workflows
  • Priority support
Visa Success Pass
₹999 / one-time

One-time payment · valid 30 days · no subscription, no auto-renew.

Danger zone

Permanently delete your account?

This erases everything tied to your account — your profile, every uploaded document, your AI chats and your journey progress — from our systems, including from our encrypted cloud storage. None of your personal data is kept, and it cannot be undone.

Check your email

Enter the 6-digit code

For your security we emailed a one-time code to your account email. This window stays open — switch tabs, grab the code, and come back.

Free Plan Limit Reached

This feature is exhausted

You have used all free usage for this feature. Get the Visa Success Pass to continue instantly.


                        
document.pdf
PDF · 1.2 MB
🔒 Encrypting
☁️ Uploading
Rilono AI Scanning
✅ Complete

Encrypting document...

🔒 Encrypted on your device · read once by AI, never stored
Item image
1 / 1
1
Rilono AI
Your Visa Expert Assistant

👋 Please login to chat with Rilono AI