AI Newtika ← Back to site

Privacy

Privacy Policy

Last updated · 26 July 2026 Applies to · www.ainewtika.com

This policy describes what happens to personal data on this website. It is deliberately specific: it names every field the enquiry form collects, every third party that touches it, and where the data physically sits.

The short version

  • No cookies, no analytics, no tracking pixels. This site sets no cookies, runs no analytics of any kind, and loads nothing from third-party servers — fonts included.
  • The only data you give us is what you type into the enquiry form — plus the IP address your browser sends with every request, which we need for security.
  • Your data is stored in India (Bangalore), on a server we control.
  • We use it to reply to you. We do not sell it, share it for advertising, or add you to a marketing list.
  • Ask us to delete it and we will — email build@ainewtika.com.

01Who we are

This website is operated by AI Newtika ("we", "us"), an engineering studio that designs and builds custom AI agents. We are based in India.

For anything in this policy — including requests to access or erase your data — contact build@ainewtika.com. We aim to reply within one working day.

For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we act as a Data Fiduciary for the data described below. Where the UK or EU GDPR applies to a visitor, we act as a controller.

02What we collect

Data you give us

The enquiry form is the only place on this site where you can submit information. It collects exactly these fields, and nothing more:

FieldRequiredWhy it is asked
NameYesTo address you in our reply
Work emailYesTo reply to your enquiry
Systems involvedYesTo assess technical feasibility
Organisation, country, industryNoContext for scoping and data-residency questions
Workflow shape, whether an API exists, data residencyNoTo judge whether the work is feasible and how it would be deployed
Budget, timeline, decision roleNoTo prioritise and give you a realistic answer
Free-text descriptionNoWhatever you choose to tell us

Two further values are attached automatically when you submit: the time of submission and your browser's timezone (for example Asia/Kolkata), so we can reply during your working hours.

Please do not put confidential, regulated or personal data about third parties — patient records, customer files, credentials — into the free-text box. Describe the shape of the problem instead. If we work together, we will agree a proper channel and the appropriate agreements first.

Data collected automatically

  • IP address and standard request metadata (page requested, timestamp, browser user-agent). Our web server records these in access logs. Your IP address is also included in the notification email generated by an enquiry, so we can identify abuse of the form.
  • Nothing else. We do not fingerprint devices, build profiles, or track you across sites.

Cookies and browser storage

This site sets no cookies. There is no cookie banner because there is nothing to consent to.

The site stores exactly one value in your browser's session storage: a flag named af_booted, set to 1, so the intro animation does not replay if you navigate within the same tab. It contains no personal data, is not sent to us or anyone else, and is discarded when you close the tab.

03Why we use it, and on what basis

PurposeBasis (GDPR)Basis (DPDP Act)
Replying to your enquirySteps taken at your request prior to entering a contract; legitimate interestsThe consent you give by voluntarily submitting the form for that purpose
Keeping the site and form secure (abuse prevention, rate limiting)Legitimate interestsLegitimate use / reasonable security safeguards
Meeting legal or regulatory obligationsLegal obligationLegal obligation

We do not use your data for advertising, profiling, automated decision-making, or training machine-learning models, and we do not sell or rent it to anyone.

04Who else touches it

We keep the list of third parties as short as we can. These are all of them:

ProviderWhat it doesWhat it sees
DigitalOceanHosts the server this site runs onEverything stored on the server, in Bangalore, India
ResendDelivers the notification email generated by an enquiryThe contents of your enquiry, in transit. Processed outside India.
Our email providerHosts the mailbox that receives enquiriesThe contents of your enquiry, once delivered

Note what is not on this list. The typefaces this site uses are served from our own server rather than from Google Fonts, so loading a page here contacts no third-party origin at all and no outside party sees your IP address.

We may also disclose data where we are legally required to, or to establish or defend legal claims.

05Where it is stored

The server is located in Bangalore, India. Enquiry data and access logs stay there.

The one routine international transfer is email delivery: the notification generated by your enquiry is transmitted through Resend, which processes it outside India. Where the GDPR applies to that transfer, it is made on the basis of the provider's standard contractual clauses.

06How long we keep it

  • Enquiries: up to 24 months from your last contact with us, so we still have context if a slow-moving procurement conversation resumes. After that they are deleted.
  • Server access logs: a short period only — they rotate automatically and are overwritten.
  • If we go on to work together, the engagement is governed by a separate written agreement, and data handled under it is retained according to that agreement rather than this policy.

You can ask us to delete your enquiry sooner at any time. We will do it, unless we are legally required to keep something.

07Your rights

Wherever you are, you can ask us to:

  • Tell you what we hold about you, and why
  • Correct anything inaccurate or incomplete
  • Erase it
  • Withdraw consent, where consent is what we relied on
  • Receive a copy in a portable form, or object to or restrict our use of it, where the GDPR gives you those rights

Email build@ainewtika.com. We will not charge you, and we will not ask why. We may need to confirm your identity before acting, and we will respond within the period the applicable law allows.

Under the DPDP Act you may also nominate another person to exercise these rights on your behalf. If you are unhappy with how we have handled a request, you may complain to the Data Protection Board of India, or — if the GDPR applies to you — to your local supervisory authority.

08How we protect it

  • The whole site is served over HTTPS, with HSTS and a strict Content-Security-Policy
  • The enquiry service runs in an isolated, read-only container with no unnecessary privileges, and is not reachable directly from the internet
  • Submissions are rate limited per IP address, and the form carries a honeypot to absorb bots
  • Access to the server uses key-based authentication
  • We minimise by default — no analytics, no cookies, no third-party scripts, and self-hosted fonts, so no outside origin ever sees your IP address

No system is perfectly secure. If you believe you have found a vulnerability in this site, please tell us at build@ainewtika.com and give us a reasonable chance to fix it before disclosing it publicly.

09Children

This is a business-to-business site and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has submitted data through this site, tell us and we will delete it.

10Changes to this policy

If we change how this site handles data, we will update this page and the "last updated" date above. Material changes will be described here rather than quietly folded in.

11Contact and grievances

Questions, requests and complaints about personal data all go to the same place:

  • Emailbuild@ainewtika.com
  • Response time — normally within one working day; formal requests within the statutory period

This is also the contact point for grievance redressal under the DPDP Act.