Legal
Privacy policy
Last updated .
- Fiduciary
- Digiaeon Services Pvt Ltd
- Framework
- DPDP Act, 2023 · GDPR · UK GDPR
- Scope
- digiaeon.com — contact form, email, server logs
- Requests
- hello@digiaeon.com
On this page
Contents — 17 sections
This policy explains what digiaeon.com collects, why, how long it is kept and what you can ask us to do about it. The site is a marketing site — the only personal data we ask for is what you type into the contact form, or what you send us when you apply for a role. There is no account, no advertising network and no cross-site tracking anywhere on it.
Who is responsible
Digiaeon Services Pvt Ltd, a private limited company incorporated in India with its office in Chandigarh, operates digiaeon.com and decides how data collected through it is used.
Under India’s Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for that data. For visitors in the EU or the UK we are the controller under the GDPR and the UK GDPR.
Every request, question or complaint about this policy goes to hello@digiaeon.com.
What we collect
Contact-form submissions. Your name, work email address, company name and indicative budget where you choose to give them, the message you write, and the IP address the submission was sent from — recorded with the enquiry so abuse can be traced. Everything in that message is personal data once it is attached to your email address, so send only what you are comfortable sending — we do not need commercial secrets to reply to a first enquiry.
Email correspondence and job applications. If you write to us, reply to us, or apply for a role, the thread and any attachments — a CV, work samples, links you choose to send — sit in our business email system. Application material is read only to assess you for the role you applied for.
Server and CDN logs. Our hosting and content-delivery layer records the usual technical lines: IP address, user agent, referring page, requested path, response code and timestamp. These are generated automatically by the infrastructure, not by anything we place in your browser.
A theme preference. If you switch the site between light and dark, that choice is stored locally in your own browser so the page does not flash on your next visit. It never reaches our servers and is not tied to you.
What we do not collect
No advertising or cross-site tracking cookies, no pixels, no remarketing tags, no data brokers, no fingerprinting.
No payment details. Nothing on this site takes money, so no card or bank data is ever entered here.
No special or sensitive categories of data — health, biometric, financial, religious or political data. Please do not put any of it in the contact form.
We do not buy, sell, rent or trade personal data, and we do not build advertising profiles.
Why we process it, and on what lawful basis
Contact-form data is processed on your consent, given when you submit the form, for one purpose: to read your enquiry and reply to it. Under the DPDP Act that consent is free, specific, informed and revocable, and you may withdraw it at any time.
For visitors in the EU or the UK the bases are Article 6(1)(a) consent for the enquiry itself, Article 6(1)(b) where the exchange is a step towards a contract you asked for, and Article 6(1)(f) legitimate interests for keeping server logs to defend the site against abuse.
Withdrawing consent is as easy as giving it — one line to hello@digiaeon.com. It does not affect processing that already took place lawfully before the withdrawal.
Purpose limitation
An enquiry is used to answer that enquiry. It is not added to a newsletter, a mailing list or a campaign audience unless you separately ask to be added.
If we ever want to use what you sent for a genuinely different purpose, we ask again first. Silence is not consent.
Enquiries and AI tools
We build AI systems, so we will be precise about this: the content of your enquiry is not used to train any model, ours or anyone else’s.
Where an AI assistant is used internally to help draft or summarise a reply, it runs under commercial terms that prohibit training on the input, with retention limited to the provider’s short abuse-monitoring window.
No enquiry is answered, ranked, scored or rejected automatically. A person reads it.
How long we keep it
Contact-form submissions and the email thread that follows: up to 24 months from our last exchange with you, then deleted. If the conversation becomes a signed engagement, the records move under that contract and its own retention terms.
Server and CDN logs: a short operational window, ordinarily 30 to 90 days, after which they age out.
If you ask us to erase your data sooner we do so within 30 days, unless a specific law requires us to keep a record — in which case we say which one, and keep only that.
When consent is withdrawn and no legal ground remains, the data is erased and our processors are instructed to do the same.
Who else handles it
We keep the supply chain deliberately short. Personal data from this site may be handled by these categories of processor, each under a written agreement that limits them to acting on our instructions:
A cloud hosting and content-delivery provider, which serves the site and generates the technical logs described above. A transactional email provider, which delivers the form submission to our inbox. A business email and productivity provider, where the resulting correspondence is stored. If privacy-preserving, aggregate site analytics are enabled, that provider too — it would measure page traffic, not people.
We name the specific vendors on request rather than in this page, because vendors change and a stale list is worse than none. Write to hello@digiaeon.com for the current list.
Beyond that we disclose personal data only where a law, a court or a lawful government order requires it, and only as far as the order reaches. If a company transfer or restructuring ever occurs, the data follows under this policy and you are told before anything changes.
Where data is processed
Our infrastructure is hosted primarily in India. Some processors — particularly email and content delivery — operate globally, so data may be stored or processed outside India.
The DPDP Act permits transfer outside India except to territories the Central Government restricts by notification, and we will not transfer to a restricted territory.
For data covered by the GDPR or UK GDPR, transfers outside the EEA or the UK rely on the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, together with the technical measures below.
How it is protected
Traffic to the site is served over HTTPS with modern TLS. Data at rest with our providers is encrypted using their platform encryption.
Access to the inbox and the hosting account is limited to the people who need it, with multi-factor authentication and no shared logins. Production personal data is never copied into development or test environments.
The strongest control is the simplest one: we collect very little and keep it for a short time.
No system is perfectly secure, and we will not pretend otherwise. If a personal data breach occurs, we notify the Data Protection Board of India and affected individuals as the DPDP Act and the rules under it require. Where the GDPR applies, we notify the supervisory authority within 72 hours of becoming aware, and tell affected individuals without undue delay where the breach is likely to put their rights at high risk.
Your rights under the DPDP Act
Access. Ask for a summary of the personal data we hold about you, what we are doing with it, and the identities of anyone it has been shared with.
Correction and completion. Ask us to correct data that is wrong, complete data that is partial, or update data that has gone stale.
Erasure. Ask us to delete your data where the purpose it was given for is finished and no law requires us to retain it.
Grievance redressal. Raise a complaint with us about how your data has been handled, and get an answer in a defined time.
Nomination. Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
Withdrawal of consent. Withdraw at any time, with the same ease you gave it.
Exercising any of these is free. Please make requests honestly — the Act expects the same of data principals, and frivolous or false complaints help nobody.
If you are in the EU or the UK
The GDPR and UK GDPR add rights to restrict processing, to object to processing carried out on legitimate interests, and to receive the data you gave us in a portable, machine-readable form.
You may also lodge a complaint with your national supervisory authority, or with the Information Commissioner’s Office in the UK. We would rather you came to us first, but that route is yours regardless.
How to exercise a right
Email hello@digiaeon.com with the subject line “Data request”, tell us what you want done, and write from the address you used when you contacted us.
If we cannot reasonably tie the request to data we hold, we may ask one clarifying question to confirm identity. We will not ask for identity documents to service a website enquiry.
We acknowledge requests within 72 hours and aim to complete them within 30 days. If a request is genuinely complex we tell you why and give a date, and in every case we answer within the period required by the applicable law.
Grievance redressal
To raise a grievance, email hello@digiaeon.com with the subject line “Grievance — DPDP” and describe what happened. The grievance route is monitored by the company’s directors, and the named Grievance Officer will be published on this page once that appointment is formalised.
We acknowledge grievances within 72 hours and work to resolve them within 30 days, and in any event within the period the rules prescribe.
If our answer does not satisfy you, you may escalate to the Data Protection Board of India through the channels it publishes.
Children
This is a business-to-business site, not directed at children, and we do not knowingly collect data from anyone under 18 — the threshold the DPDP Act sets.
We do not track children, profile them, or direct advertising at them. We run no advertising at all.
If you believe a child has submitted data through this site, write to hello@digiaeon.com and we will delete it.
Changes to this policy
When this policy changes, the date at the top changes with it. Material changes — a new category of data, a new purpose, a new class of recipient — are flagged prominently on the page for a reasonable period.
Earlier versions are available on request, so you can see what you agreed to at the time.
Counsel review pending
Review status
This policy is a carefully drafted template reflecting how the site is actually built, not a lawyer-approved final document. It should be reviewed and adapted by qualified Indian counsel — with GDPR input where EU or UK visitors are material — before the site goes live, and the named Grievance Officer and vendor list should be confirmed at that point.
Digiaeon Services Pvt Ltd · Chandigarh, India · last updated
Questions
Anything here that reads as unclear, we would rather fix than defend.
One email reaches the people who wrote this and the people who run the site. Data requests, corrections and grievances go to the same address.
