Legal · Draft

Privacy Policy

This policy describes what personal data www.accurith.com collects, why we collect it, where it is stored, and how to ask us to delete it. It covers this website only — engagement data held under a signed statement of work is governed by that contract and our Data Processing Agreement.

Last updated · Accurith Technologies Private Limited, Bangalore 560092, Karnataka, India

01

Status

Draft — pending legal review. This page describes how the site works today and has not been reviewed by counsel. It is published for transparency, not as a binding legal document, and will be replaced by a reviewed version before launch.

02

Terms

01

Who we are

Accurith Technologies Private Limited, Bangalore 560092, Karnataka, India, is the data fiduciary (under India's Digital Personal Data Protection Act, 2023) and the data controller (under the GDPR, where it applies) for personal data collected through this website.

For any privacy question or request, write to [email protected]. For a suspected vulnerability or security issue, use [email protected] and the process at /trust/report-vulnerability.

02

What we collect, and when

We collect personal data only when you choose to send it to us through one of three forms. There is no account system, no login, and no newsletter sign-up. Every field below is stored in our database and also sent to our team inbox as an alert.

WhereWhat we collectWhy
Consultation form (/contact)Name, email, company, role, service of interest, your messageTo answer your enquiry and, if it goes further, to scope an engagement
Job application (/about/careers)Name, email, phone, LinkedIn URL, portfolio URL (optional), cover note, and which opening you applied toTo assess your application and contact you about it
Early-access form (/products)Name, email, which product you registered interest inTo write to you when that product opens — and, as the form states, about nothing else

We do not accept file or CV uploads. Applicants share links instead. This is deliberate: an endpoint that accepts arbitrary files from strangers is an obvious attack surface, and we would rather not hold your documents at all.

We do not buy contact lists, we do not enrich what you give us from third-party data brokers, and we do not sell or rent personal data to anyone.

03

Data we handle but do not store

Your IP address is read from the incoming request so we can rate-limit form submissions and block abuse. It is held in memory for the length of the rate-limit window and is never written to the database alongside your name or email. Where an IP appears in a diagnostic log it is first hashed and truncated, which is enough to count repeat requests and useless for identifying you.

Our hosting provider and the CDN in front of this site keep their own short-lived infrastructure logs for security and abuse prevention. Those are outside our application and are retained under their policies, not ours.

04

Analytics

No analytics or measurement script is currently loaded on this site. None. The cookie banner offers an analytics choice because we intend to add measurement later, and we would rather ask before that happens than retro-fit consent afterwards.

The measurement we plan to add is Google Analytics 4. It will not run at all unless you have turned analytics on, and it will not run before you have answered the banner. If you decline, or simply never answer, no analytics script loads for you.

What that means for your data: GA4 collects technical and usage information — IP address, device and browser details, pages viewed, referring URLs — and Google processes it as our processor, on infrastructure that includes the United States. Google states that GA4 does not store IP addresses. The cookies involved are listed in our Cookie Policy.

An earlier version of this page said we would never use Google Analytics on this site. That was our position, and it has changed. We are recording the change here rather than editing the sentence away, because a privacy policy that quietly reverses a promise is worth less than one that admits it did.

05

The website assistant

If a chat assistant is available on this site, it answers only from published Accurith web pages. What you type into it is sent to our server, and from there to a third-party AI provider that writes the reply from excerpts of our own public content. That provider is currently hosted outside India, so anything you type crosses a border.

Do not type personal or confidential information into the assistant. It is built to answer questions about our services, not to take your details — use the contact form for that.

We log the question asked, which safeguard handled it, the retrieval score, and which pages were used. We do not log your IP address, a session identifier, or the answer text.

06

Where your data is stored

This site and its database run on cloud infrastructure hosted in the United States (our provider's US West region). Personal data submitted through the forms above is therefore stored in the United States, not in India. Email alerts travel to our team inbox through our mail provider, which operates its own global infrastructure.

The DPDP Act permits transfer of personal data outside India except to countries the Government restricts by notification. We monitor that position, and if data residency becomes a binding requirement for us we will move this data to an Indian region and update this page.

We would rather host this data closer to the people it describes, and moving it to a region in or nearer to India is on our list. Until that happens, this page describes where it actually is rather than where we intend it to be.

07

How long we keep it

We keep enquiry and application records for as long as needed to act on them and to keep a reasonable business record afterwards, then delete them. The exact retention periods are being set and will be stated here — see Open items below.

If you would like your record deleted sooner, ask us and we will do it. You do not need a reason.

08

Your rights

Under the DPDP Act, and under the GDPR where it applies to you, you can ask us to:

  • Tell you what personal data of yours we hold, and confirm how it is being processed
  • Correct anything inaccurate, or complete anything incomplete
  • Erase your data, where we have no continuing obligation to keep it
  • Withdraw consent you previously gave, at any time
  • Nominate someone to exercise these rights for you if you die or become incapacitated (DPDP Act, section 14)
  • Raise a grievance with us, and escalate to the Data Protection Board of India if our answer does not resolve it

Write to [email protected] and we will respond. Deletion at our current size is performed manually by an administrator against the database — there is no self-service delete button, and we would rather say so than imply an automation we do not have.

09

Who else sees your data

We share personal data with the service providers that make this site work — our cloud host and database provider, our CDN and security layer, our email provider, and (for the assistant only) an AI provider. Each processes data on our instructions and for no purpose of their own.

Once analytics is enabled, Google will be added to that list as our analytics processor, receiving the website-usage data described above from visitors who turned analytics on. It receives nothing from visitors who did not.

We otherwise disclose personal data only where the law requires it. We do not sell it, and we do not share it for advertising.

10

How we protect it

The site is served over HTTPS with a strict Content-Security-Policy carrying a per-request nonce, alongside the standard security headers. Form submissions are rate-limited and size-capped, and database queries are parameterised. Error responses to visitors are deliberately generic, because a detailed error message is reconnaissance.

No control set is perfect. If you find a weakness, please tell us at [email protected].

11

Children

This site is intended for business use by adults. We do not knowingly collect personal data from children. If you believe a child has submitted data through one of our forms, contact [email protected] and we will delete it.

12

Changes to this policy

When this policy changes we will update the date at the top of this page. The current version is a pre-launch draft and will be replaced by a version reviewed by counsel.

03

Open items

Still to be settled.

Listed here rather than answered with a guess — a policy that states a commitment nobody has agreed to is worse than one that admits the gap.

  • Google Analytics is described above as planned, not running. Every sentence about it is written in the future tense on purpose, and each one has to be moved to the present tense — and checked against the real configuration — on the day it is switched on.
  • The lawful basis for analytics. Consent is what the banner collects and what this page relies on; whether legitimate interests is also argued for any part of it is a question for counsel, not one to settle here.
  • Whether Google Signals is enabled, which decides whether GA4 is aggregate measurement or advertising infrastructure. It also decides whether the sentence “we do not share it for advertising” above stays true, so it must be settled before this page is published.
  • The transfer mechanism for GA4 data reaching Google in the United States. Google relies on its Standard Contractual Clauses; counsel to confirm that is sufficient for our EU/UK exposure and what, if anything, DPDP requires alongside it.
  • Retention of analytics data. GA4's own default is 14 months and is configurable; the figure we choose belongs in the retention section rather than being left to the vendor default.
  • Hosting region: the running deployment reports US West (San Francisco), and neither service sets a region override. Confirm the database service's region directly in the hosting dashboard and, if it differs from the web service, state both here.
  • Whether to move this data to a region in or nearer to India, which would change this section and remove the cross-border transfer question for DPDP purposes.
  • The GDPR analysis, if the GDPR applies to us, is different for a US host than for one inside an adequacy decision. Counsel to advise on the transfer mechanism needed.
  • Retention periods for consultation, job application and early-access records are not yet fixed. The working proposal is 24 months for enquiries and 36 months for applications, both aligned to a routine audit cycle — to be confirmed.
  • [email protected] must exist and be monitored before this page is published; it is referenced throughout.
  • The Data Protection Board grievance escalation route should name our grievance officer once that role is assigned (DPDP Act, section 13).
  • Sub-processors are described by role rather than named. Counsel to confirm whether a named list is required here or belongs only in the DPA.
  • Whether the GDPR applies to us at all depends on our EU-facing activity; the references above are written to be true either way and should be narrowed once that is settled.