Privacy Policy

At Rajat AI, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, and safeguard your data when you visit our website or engage our services.

1. Information Collection

We may collect personal information that you voluntarily provide to us when you:

  • Fill out a contact form or book a strategy call.
  • Subscribe to our newsletter or download free resources.
  • Engage our services for consulting, development, or automation projects.

The types of information collected may include your name, email address, phone number, company name, and any other details you choose to share regarding your project requirements.

2. AI Data Processing

In delivering our services, we may use third-party Artificial Intelligence (AI) tools and Large Language Models (LLMs) (e.g., OpenAI, Anthropic) to process data.

  • No Training on Your Data: We prioritize privacy-first configurations. Unless explicitly agreed upon for a custom model fine-tuning project, we do not use your proprietary business data to train public foundation models.
  • Data Security: We ensure that any data shared with AI providers for processing purposes is done so via secure, enterprise-grade APIs where data retention for training is disabled where possible.

3. Data Protection & Global Processing

We implement appropriate technical and organizational measures to protect your personal information.

Contact form and resource downloads

When you submit the contact form or download a gated resource, the name, email address and message you provide are sent to an endpoint we operate on Cloudflare and stored in a Cloudflare D1 database whose primary location is in the Asia-Pacific region. A copy is also emailed to us so we can reply to you. We do not store your IP address.

A previous version of this policy said that form data was processed by Google Apps Script and stored in Google Sheets. That stopped being accurate on 26 August 2026 and no submission goes to Google now.

How long we keep your data

We keep what you send through the contact form for as long as we need it to answer you and to keep a record of that correspondence. We do not delete it on a fixed clock, and that is deliberate: an enquiry from two years ago may still be a live conversation with a client, and India's fixed three-year erasure rule applies to large e-commerce, social media and online gaming platforms rather than to a business of this size. Instead we review what we hold and delete what is no longer needed. You can ask us to delete your data at any time using the contact details in section 7, and we will, within ninety days at the outside.

Consent records are kept for as long as we rely on your consent, plus a reasonable period afterwards, because we are required to be able to demonstrate that consent was given.

International data transfers

Your data may be processed in a country other than the one you live in. Contact form data is held by Cloudflare with its primary location in the Asia-Pacific region. Analytics data, and only if you have allowed analytics, is processed by Google and by Microsoft and may be transferred to the United States under Google's Data Processing Terms and Standard Contractual Clauses.

4. Third-Party Sharing

We do not sell, trade, or rent your personal information to third parties. We may share your data with trusted third-party service providers (including the AI providers mentioned above) who assist us in operating our website or servicing you.

5. Analytics & Cookies

Strict Opt-In Policy: This website uses Google Analytics 4 and Microsoft Clarity to analyze traffic and user behavior. However, specifically for compliance with GDPR and ePrivacy Directive, no tracking cookies are set and no analytics data is collected unless you explicitly click "Accept" on our cookie banner.

If you click "Decline" or ignore the banner, strictly necessary cookies (essential for the site to function) may still be used, but no personal data will be shared with Google Analytics or Microsoft Clarity.

  • Google Analytics 4: Collects anonymized data (IP anonymization enabled) about page visits, session duration, and device type.
  • Microsoft Clarity: Records anonymised session replays, click and scroll behaviour, and heatmaps, so we can see where a page is unclear. Text masking is enabled, so the content you type is not captured. Provided by Microsoft Corporation as a processor. Loads only after you click Accept, and stops immediately when you withdraw consent.
  • Cookie Management: You can withdraw your consent at any time using the Cookie Preferences link in the footer of every page. That records the withdrawal properly and stops analytics immediately.

6. Your Rights (GDPR, CCPA and DPDP)

Depending on your location, you have specific rights regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can ask us to correct inaccurate data.
  • Right to Erasure ("Right to be Forgotten"): You can ask us to delete your personal data.
  • Right to Withdraw Consent: You can withdraw consent for analytics at any time using the Cookie Preferences link in the footer of every page. Withdrawing is as easy as giving consent, and takes effect immediately.
  • CCPA "Do Not Sell": We do not sell your personal information to third parties.

To exercise any of these rights, email us at [email protected]. We will not charge you for it, and we will not ask you to create an account to make the request.

How to make a request, and how long we take

  • Where to send it: [email protected]. Please put the word "request" or "grievance" in the subject line so it is not mistaken for an enquiry.
  • What to include: the email address you used when you contacted us, so we can find your data. We hold no account numbers or usernames, so that address is the only identifier we need. If you are asking on behalf of someone else, say so and tell us on what basis.
  • How long we take: we aim to answer within days, and we will answer within ninety days at the outside, which is the maximum the DPDP Rules 2025 allow for a grievance.
  • What it costs: nothing.

7. India: Digital Personal Data Protection Act

We are based in India, so the Digital Personal Data Protection Act 2023 and the rules made under it apply to how we handle your personal data. Under that framework we act as a data fiduciary, which means we decide why and how your data is processed and we are answerable for it.

  • What we process, and why: contact form submissions, so we can reply to you, and analytics data, but only if you allow it.
  • Your consent is specific and withdrawable: analytics never runs until you allow it, and you can withdraw at any time using the Cookie Preferences link in the footer.
  • Your rights: you can ask for access to your data, ask us to correct or erase it, nominate another person to exercise these rights on your behalf, and raise a grievance with us.
  • How long we keep it: see "How long we keep your data" in section 3. You can ask us to erase your data at any time.
  • We keep a record of consent: when you accept or decline cookies we store the decision, the time, and which version of this policy was in force. We do not store your IP address.

Grievance redressal, and who to contact

Rajat Gautam is the person who answers questions about how we process your personal data and who handles grievances under the DPDP Act. This is the business contact the Act requires us to publish, and we include it in every reply we send about your data.

  • Email: [email protected], with "DPDP grievance" in the subject line so it is not mistaken for an enquiry.
  • What happens next: we acknowledge it, look into it, and tell you what we are doing. We will respond within ninety days at the outside, and normally far sooner.
  • If you are not satisfied: you can take the complaint to the Data Protection Board of India, in the form and manner it prescribes. You are expected to raise it with us first, which is why the route above exists.

If there is a data breach

If personal data we hold is affected by a breach, we will tell you without delay, in plain language, and we will tell you all of the following:

  • what happened, how much data was involved, and when it happened;
  • what is likely to follow from it for you;
  • what we have already done and are still doing to limit the damage;
  • what you can do to protect yourself; and
  • how to reach us with questions, which is the email in the section above.

We will also notify the Data Protection Board of India without delay, and give it a full account within seventy-two hours of becoming aware, as the DPDP Rules 2025 require.

How we keep your data safe

The DPDP Rules 2025 set out the safeguards a data fiduciary is expected to have. In plain terms, here is what we actually do:

  • Encryption in transit: the whole site is served over HTTPS, and the form submits to an endpoint on the same secure connection.
  • Data minimisation: the strongest safeguard is not holding data in the first place. We do not store your IP address anywhere, we ask for no phone number, and we collect nothing from you that we do not need in order to reply.
  • Access control: the database holding contact submissions is reachable only through an authenticated account that Rajat Gautam controls. It is not exposed to the public internet.
  • Abuse limits: the form is rate limited, so no one can use it to harvest or flood the record.
  • Logging: every submission is recorded with a timestamp set by our server rather than by your device, and that record is kept. Requests to the endpoint are logged so unusual activity can be investigated, and administrative access to the systems holding your data goes through an authenticated Cloudflare account which keeps its own audit trail.
  • Backups: the database supports point-in-time recovery for the previous seven days, so an accidental deletion or a failure can be undone rather than being final.
  • Processors: where a third party processes data for us, we rely on their published data processing terms.

8. Children's Data

This website and our services are meant for businesses and the people who run them. They are not directed at children. Under India's DPDP Act a child is anyone under 18.

  • We do not knowingly collect personal data from anyone under 18. If you believe a child has given us their data, email [email protected] and we will delete it.
  • We do not carry out behavioural advertising or build advertising profiles of any visitor, child or adult. Google Signals, which is the setting that would enable ad personalisation in our analytics, is switched off.

9. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated policy will be posted on this page with a revised effective date.

Last Updated: September 11, 2026 (policy version 2026-09-11)