Skip to content

Legal

Privacy notice

What we collect through this website, why, how long we keep it, and what you can ask us to do about it.

Effective TBC - pending counsel review

Unreviewed draft - not yet in force

This document is a working draft prepared to give our legal advisers a starting point. It has not been settled by counsel and should not be relied upon. Placeholders marked “TODO” are outstanding.

Scope

This notice covers personal data collected through https://authtechai.com only.

Personal data we process while delivering a client engagement is governed by the contract with that client, under which we act as a Data Processor on their instructions rather than as a Data Fiduciary. It is not covered here. If you are a client seeking our data processing terms, write to connect@authtechai.com.

Who we are

TODO - registered legal name, e.g. AuthTechAI Private Limited (“AuthTechAI”, “we”) is the Data Fiduciary for personal data collected through this website.

  • Registered office: TODO - full registered office address
  • CIN: TODO - Corporate Identity Number
  • Email: connect@authtechai.com

What we collect

Only what you send us through the contact form. That is:

  • Full name - required, so we know who we are replying to
  • Work email address - required, so we can reply
  • Mobile number - optional, if you would like us to call you
  • Company - optional, to understand your context
  • Your message - whatever you choose to tell us. Please do not include sensitive personal data, credentials, or confidential information about your institution in this field.
  • Your consent - that you agree to be contacted

We also process the IP address your request arrives from. It is held briefly in memory to limit automated submissions, and included in the notification email so we can identify abuse. It is not written to a database by us.

What we do not do

Stated plainly, because it is unusual enough to be worth saying:

  • We set no cookies. None at all - not analytics, not advertising, not “essential”.
  • We run no analytics or tracking of any kind, and no advertising or profiling pixels.
  • We load nothing from third-party servers. Fonts and every other asset are served from our own domain, so browsing this site does not disclose your visit to anyone else.
  • We do not sell or share your data for anyone else’s marketing.
  • We make no automated decisions about you on this website.

Your browser’s local storage is read once to check whether you have chosen a dark or light appearance. That preference stays on your device and is never transmitted to us.

Why we process it, and on what basis

We process the above solely to respond to your enquiry and, if it leads somewhere, to discuss the services you asked about.

Our basis is your consent, which you give by ticking the box on the contact form. You may withdraw it at any time - see clause 8. Withdrawing consent does not affect processing already carried out.

Who else sees it

We use the following processors. They act on our instructions and may not use your data for their own purposes.

ProcessorPurposeLocation
Amazon Web ServicesWebsite hosting (Amplify) and outbound email (SES)Asia Pacific (Mumbai), ap-south-1
TitanMailbox hosting for connect@authtechai.comTODO - confirm with the provider

We may also disclose personal data where we are legally required to - for example to a regulator, or under a court order.

How long we keep it

Enquiries are held in our mailbox for 24 months from your last contact with us, then deleted. Where an enquiry becomes a client engagement, the records move under that engagement’s retention terms instead.

You can ask us to erase your enquiry sooner - see clause 8.

Your rights

Under the Digital Personal Data Protection Act 2023 you may:

  • Access a summary of the personal data we hold about you and how we process it
  • Correct or complete data that is inaccurate or out of date
  • Erase your data where it is no longer needed for the purpose you gave it for
  • Withdraw consent at any time, as easily as you gave it - email us and we will stop and delete
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity
  • Complain to us, and then to the Data Protection Board of India if we do not resolve it

To exercise any of these, email connect@authtechai.com. We may need to verify your identity before acting.

Grievance Officer

If you are unhappy with how we have handled your personal data, contact our Grievance Officer:

  • Name: TODO - full name
  • Designation: TODO - designation
  • Email: TODO - dedicated address, e.g. grievance@authtechai.com

We will acknowledge within 3 working days and resolve within 90 days. If you remain dissatisfied you may complain to the Data Protection Board of India.

Security

The site is served over HTTPS with HSTS, a content security policy and related protections. Submissions travel over TLS and are delivered to a mailbox with access limited to the people who need it.

No system is impenetrable, and we do not claim otherwise. If you believe you have found a vulnerability, our responsible disclosure policy explains how to tell us.

Children

This site is aimed at businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us data, tell us and we will delete it.

Changes

If we change how we handle personal data we will update this notice and the effective date above. Material changes affecting data we already hold will be notified to you directly where we can.