Loading
Loading
LoadingLegal
This policy describes what personal data www.accurith.com collects, why we collect it, where it is stored, and how to ask us to delete it. It covers this website only — engagement data held under a signed statement of work is governed by that contract and our Data Processing Agreement.
Last updated · Accurith Technologies Private Limited, Bangalore 560092, Karnataka, India
Accurith Technologies Private Limited, Bangalore 560092, Karnataka, India, is the data fiduciary (under India's Digital Personal Data Protection Act, 2023) and the data controller (under the GDPR, where it applies) for personal data collected through this website.
For any privacy question or request, write to info@accurith.com. For a suspected vulnerability or security issue, use security@accurith.com and the process at /trust/report-vulnerability.
We collect personal data only when you choose to send it to us through one of three forms. There is no account system, no login, and no newsletter sign-up. Every field below is stored in our database and also sent to our team inbox as an alert.
| Where | What we collect | Why |
|---|---|---|
| Consultation form (/contact) | Name, email, company, role, service of interest, your message | To answer your enquiry and, if it goes further, to scope an engagement |
| Job application (/about/careers) | Name, email, phone, LinkedIn URL, portfolio URL (optional), cover note, and which opening you applied to | To assess your application and contact you about it |
| Early-access form (/products) | Name, email, which product you registered interest in | To write to you when that product opens — and, as the form states, about nothing else |
We do not accept file or CV uploads. Applicants share links instead. This is deliberate: an endpoint that accepts arbitrary files from strangers is an obvious attack surface, and we would rather not hold your documents at all.
We do not buy contact lists, we do not enrich what you give us from third-party data brokers, and we do not sell or rent personal data to anyone.
Your IP address is read from the incoming request so we can rate-limit form submissions and block abuse. It is held in memory for the length of the rate-limit window and is never written to the database alongside your name or email. Where an IP appears in a diagnostic log it is first hashed and truncated, which is enough to count repeat requests and useless for identifying you.
Our hosting provider and the CDN in front of this site keep their own short-lived infrastructure logs for security and abuse prevention. Those are outside our application and are retained under their policies, not ours.
This site uses Google Analytics 4, and it runs only for visitors who have turned analytics on. It does not run before you have answered the cookie banner, and it does not run at all if you decline or simply never answer — in those cases no analytics script is loaded for you and no analytics cookie is set on your device.
That is enforced in the page itself rather than by asking Google to behave: the measurement script is not placed in the page until your stored answer says analytics is allowed, and withdrawing consent from our cookie preferences removes it again. The site's content security policy also refuses to contact Google's analytics domains at all unless measurement is configured and permitted.
What that means for your data: GA4 collects technical and usage information — IP address, device and browser details, pages viewed, referring URLs — and Google processes it as our processor, on infrastructure that includes the United States. Google states that GA4 does not store IP addresses. The cookies involved are listed in our Cookie Policy.
We use GA4 for aggregate measurement only. The Google setting called Google Signals, which would feed this data into Google's advertising products and link it to visitors across other sites, is not enabled on our property. We do not use analytics data for advertising, we do not sell it, and we do not combine it with any other source to build a profile of you.
An earlier version of this page said we would never use Google Analytics on this site. That was our position, and it has changed. We are recording the change here rather than editing the sentence away, because a privacy policy that quietly reverses a promise is worth less than one that admits it did.
If a chat assistant is available on this site, it answers only from published Accurith web pages. What you type into it is sent to our server, and from there to a third-party AI provider that writes the reply from excerpts of our own public content. That provider is currently hosted outside India, so anything you type crosses a border.
Do not type personal or confidential information into the assistant. It is built to answer questions about our services, not to take your details — use the contact form for that.
We log the question asked, which safeguard handled it, the retrieval score, and which pages were used. We do not log your IP address, a session identifier, or the answer text.
This site and its database run on cloud infrastructure hosted in the United States (our provider's US West region). Personal data submitted through the forms above is therefore stored in the United States, not in India. Email alerts travel to our team inbox through our mail provider, which operates its own global infrastructure.
The DPDP Act permits transfer of personal data outside India except to countries the Government restricts by notification. We monitor that position, and if data residency becomes a binding requirement for us we will move this data to an Indian region and update this page.
We would rather host this data closer to the people it describes, and moving it to a region in or nearer to India is on our list. Until that happens, this page describes where it actually is rather than where we intend it to be.
We keep enquiry and application records for as long as needed to act on them and to keep a reasonable business record afterwards, then delete them. The exact retention periods are being set and will be stated here — see Open items below.
If you would like your record deleted sooner, ask us and we will do it. You do not need a reason.
Under the DPDP Act, and under the GDPR where it applies to you, you can ask us to:
Write to info@accurith.com and we will respond. Deletion at our current size is performed manually by an administrator against the database — there is no self-service delete button, and we would rather say so than imply an automation we do not have.
We share personal data with the service providers that make this site work — our cloud host and database provider, our CDN and security layer, our email provider, and (for the assistant only) an AI provider. Each processes data on our instructions and for no purpose of their own.
Google is on that list as our analytics processor, receiving the website-usage data described above from visitors who turned analytics on. It receives nothing at all from visitors who declined or never answered the banner.
We otherwise disclose personal data only where the law requires it. We do not sell it, and we do not share it for advertising.
The site is served over HTTPS with a strict Content-Security-Policy carrying a per-request nonce, alongside the standard security headers. Form submissions are rate-limited and size-capped, and database queries are parameterised. Error responses to visitors are deliberately generic, because a detailed error message is reconnaissance.
No control set is perfect. If you find a weakness, please tell us at security@accurith.com.
This site is intended for business use by adults. We do not knowingly collect personal data from children. If you believe a child has submitted data through one of our forms, contact info@accurith.com and we will delete it.
When this policy changes we will update the date at the top of this page. This version has been reviewed by counsel and takes effect from that date.
Listed here rather than answered with a guess — a policy that states a commitment nobody has agreed to is worse than one that admits the gap.