Legal

Privacy Policy

This policy explains what information DStarix Techno collects, why we collect it, and the choices you have. We keep it plain, because trust is part of the product. DStarix Techno is based in India and this policy is written primarily around Indian law.

1. Introduction

DStarix Techno (“DStarix,” “we,” “us” or “our”) is a Generative AI and AI engineering company based in India. This Privacy Policy describes how we handle personal information across our website, our marketing activities, and any systems we build and operate under a written engagement.

Because we are an Indian company, this policy is written primarily around India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). Where the GDPR or other regimes apply to you as a visitor, we explain the equivalent position in the relevant sections below.

2. How We Handle Your Data

Under the DPDP Act, where we decide the purpose and means of processing your personal data, we act as a Data Fiduciary and you are a Data Principal. This applies primarily to website visitors, prospective clients and people who write to us.

Where we process personal data on someone else’s behalf as part of a system we have been engaged to build or operate, we act as a Data Processor. That processing is governed by the data processing agreement in the relevant contract rather than by this policy, and the organisation that engaged us remains the Data Fiduciary for it.

For visitors to whom the GDPR applies, “Data Fiduciary” corresponds broadly to data controller and “Data Principal” to data subject.

3. Information We Collect

We collect information in three ways: directly from you, automatically, and from trusted third parties.

Information you provide

  • Contact and identity details such as name, email address, company, role and phone number when you fill out a form, book a call or email us.
  • Content of your communications, including project requirements and any files you choose to share during a discovery conversation.
  • Recruitment information such as your CV, work history and portfolio when you apply for a role.

Information collected automatically

  • Device and connection data such as IP address, browser type, operating system and referring URLs.
  • Usage data such as pages viewed, links clicked and time spent, collected through cookies and similar technologies.

Information from third parties

  • Enrichment and verification data from business-information providers, and referrals from partners, where permitted by law.

We do not intentionally collect special categories of personal data (such as health, biometric or political data) through our website, and we ask that you do not submit such information to us unsolicited.

4. How We Use It

We use personal information only where we have a lawful basis to do so, including to:

  • Respond to enquiries, schedule calls and provide the services you request.
  • Deliver, maintain, secure and improve our website, products and services.
  • Send relevant updates and marketing where you have consented or where we have a legitimate interest, subject to your right to opt out at any time.
  • Evaluate job applications and manage our recruitment process.
  • Detect, prevent and respond to fraud, abuse and security incidents.
  • Comply with legal obligations and enforce our agreements.

Under the DPDP Act we process personal data on the basis of your consent, or for a legitimate use permitted by the Act — for example, responding to an enquiry you have voluntarily sent us. Where the GDPR applies, the corresponding bases are consent, performance of a contract, our legitimate interests in operating the business, and compliance with legal obligations.

5. Data Sharing

We do not sell your personal information. We share it only in the limited circumstances below:

  • Service providers who process data on our behalf under contract — for example hosting, analytics, CRM and email delivery vendors.
  • Professional advisers such as auditors, lawyers and accountants where necessary.
  • Corporate transactions such as a merger, acquisition or asset sale, in which case data may be transferred subject to this policy.
  • Legal and safety reasons, where disclosure is required by law, regulation or valid legal process, or to protect rights, property and safety.

All service providers are bound by contractual obligations to keep personal information confidential and to use it only for the services they provide to us.

6. Data Security

Security is foundational to how we build. We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege permissions, network isolation and regular security reviews.

We are not currently certified to SOC 2, ISO 27001 or any equivalent standard, and we would rather state that plainly than imply otherwise. We design and build to those control expectations, and we will complete your security questionnaire and sign a data processing agreement before an engagement begins.

No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security, and any transmission is at your own risk.

7. Data Retention

We retain personal information only for as long as necessary to fulfil the purposes described in this policy, including to satisfy legal, accounting or reporting requirements. Retention periods vary by data type: enquiry and CRM records are typically kept for the duration of our relationship plus a reasonable follow-up period; recruitment data is kept for the duration of the process and a limited period afterwards unless you consent to longer. When information is no longer needed, we securely delete or anonymize it.

8. Your Rights

As a Data Principal under the DPDP Act you may exercise the rights below. Where the GDPR applies to you, it grants a broadly equivalent set, and we handle both through the same process.

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — ask us to delete your data in certain circumstances.
  • Restriction and objection — limit or object to certain processing, including direct marketing.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent — where processing is based on consent, at any time.
  • Nominate — nominate another individual to exercise your rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.
  • Grievance redressal — raise a complaint with us about how we have handled your personal data. We do not sell personal information.

To exercise any of these rights, contact us using the details below. We will respond within the timeframes required by applicable law. If a grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India, or to your local data protection authority where another regime applies to you.

9. International Transfers

We are based in India and our infrastructure and service providers may be located in other countries. Your information may therefore be transferred to, and processed in, a country other than the one in which you reside. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with additional technical measures where needed.

10. Cookies & Analytics

We use cookies and similar technologies to run this website and to understand how it is used. So that you know exactly what runs, here is the current position:

  • Vercel Analytics and Vercel Speed Insights — aggregate page-view and performance measurement, loaded on every page.
  • Google Analytics — website usage measurement, loaded only when a measurement ID is configured for the site.
  • Web3Forms — processes submissions from our contact and newsletter forms and delivers them to our inbox.

We do not run advertising or ad-targeting scripts on this website. You can block or clear cookies through your browser settings; doing so may affect how parts of the site behave. If you would like your analytics data removed, contact us using the details below.

11. Children’s Privacy

Our website and services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. When we make material changes, we will update the “last updated” date above and, where appropriate, provide additional notice. We encourage you to review this page periodically.

13. Contact Us

If you have questions about this policy or how we handle your information, or if you would like to exercise your rights, please reach out:

Grievance Officer: to be named. Until that appointment is published, please direct any grievance to privacy@dstarix.in and we will acknowledge it and respond within the timeframes required by applicable law.

DStarix Techno is based in India. A registered office address will be published here once the company’s incorporation is complete.

Skip to content