1. Introduction
DStarix Techno (“DStarix,” “we,” “us” or “our”) is a Generative AI and AI engineering company based in India. This Privacy Policy describes how we handle personal information across our website, our marketing activities, and any systems we build and operate under a written engagement.
Because we are an Indian company, this policy is written primarily around India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”). Where the GDPR or other regimes apply to you as a visitor, we explain the equivalent position in the relevant sections below.
2. How We Handle Your Data
Under the DPDP Act, where we decide the purpose and means of processing your personal data, we act as a Data Fiduciary and you are a Data Principal. This applies primarily to website visitors, prospective clients and people who write to us.
Where we process personal data on someone else’s behalf as part of a system we have been engaged to build or operate, we act as a Data Processor. That processing is governed by the data processing agreement in the relevant contract rather than by this policy, and the organisation that engaged us remains the Data Fiduciary for it.
For visitors to whom the GDPR applies, “Data Fiduciary” corresponds broadly to data controller and “Data Principal” to data subject.
3. Information We Collect
We collect information in three ways: directly from you, automatically, and from trusted third parties.
Information you provide
- Contact and identity details such as name, email address, company, role and phone number when you fill out a form, book a call or email us.
- Content of your communications, including project requirements and any files you choose to share during a discovery conversation.
- Recruitment information such as your CV, work history and portfolio when you apply for a role.
Information collected automatically
- Device and connection data such as IP address, browser type, operating system and referring URLs.
- Usage data such as pages viewed, links clicked and time spent, collected through cookies and similar technologies.
Information from third parties
- Enrichment and verification data from business-information providers, and referrals from partners, where permitted by law.
We do not intentionally collect special categories of personal data (such as health, biometric or political data) through our website, and we ask that you do not submit such information to us unsolicited.
4. How We Use It
We use personal information only where we have a lawful basis to do so, including to:
- Respond to enquiries, schedule calls and provide the services you request.
- Deliver, maintain, secure and improve our website, products and services.
- Send relevant updates and marketing where you have consented or where we have a legitimate interest, subject to your right to opt out at any time.
- Evaluate job applications and manage our recruitment process.
- Detect, prevent and respond to fraud, abuse and security incidents.
- Comply with legal obligations and enforce our agreements.
Under the DPDP Act we process personal data on the basis of your consent, or for a legitimate use permitted by the Act — for example, responding to an enquiry you have voluntarily sent us. Where the GDPR applies, the corresponding bases are consent, performance of a contract, our legitimate interests in operating the business, and compliance with legal obligations.
5. Data Sharing
We do not sell your personal information. We share it only in the limited circumstances below:
- Service providers who process data on our behalf under contract — for example hosting, analytics, CRM and email delivery vendors.
- Professional advisers such as auditors, lawyers and accountants where necessary.
- Corporate transactions such as a merger, acquisition or asset sale, in which case data may be transferred subject to this policy.
- Legal and safety reasons, where disclosure is required by law, regulation or valid legal process, or to protect rights, property and safety.
All service providers are bound by contractual obligations to keep personal information confidential and to use it only for the services they provide to us.
6. Data Security
Security is foundational to how we build. We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, least-privilege permissions, network isolation and regular security reviews.
We are not currently certified to SOC 2, ISO 27001 or any equivalent standard, and we would rather state that plainly than imply otherwise. We design and build to those control expectations, and we will complete your security questionnaire and sign a data processing agreement before an engagement begins.
No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security, and any transmission is at your own risk.
7. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes described in this policy, including to satisfy legal, accounting or reporting requirements. Retention periods vary by data type: enquiry and CRM records are typically kept for the duration of our relationship plus a reasonable follow-up period; recruitment data is kept for the duration of the process and a limited period afterwards unless you consent to longer. When information is no longer needed, we securely delete or anonymize it.
8. Your Rights
As a Data Principal under the DPDP Act you may exercise the rights below. Where the GDPR applies to you, it grants a broadly equivalent set, and we handle both through the same process.
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data in certain circumstances.
- Restriction and objection — limit or object to certain processing, including direct marketing.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — where processing is based on consent, at any time.
- Nominate — nominate another individual to exercise your rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.
- Grievance redressal — raise a complaint with us about how we have handled your personal data. We do not sell personal information.
To exercise any of these rights, contact us using the details below. We will respond within the timeframes required by applicable law. If a grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India, or to your local data protection authority where another regime applies to you.
9. International Transfers
We are based in India and our infrastructure and service providers may be located in other countries. Your information may therefore be transferred to, and processed in, a country other than the one in which you reside. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with additional technical measures where needed.
11. Children’s Privacy
Our website and services are intended for businesses and individuals aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal requirements. When we make material changes, we will update the “last updated” date above and, where appropriate, provide additional notice. We encourage you to review this page periodically.
13. Contact Us
If you have questions about this policy or how we handle your information, or if you would like to exercise your rights, please reach out:
- Email: privacy@dstarix.in
- General enquiries: contact@dstarix.in
Grievance Officer: to be named. Until that appointment is published, please direct any grievance to privacy@dstarix.in and we will acknowledge it and respond within the timeframes required by applicable law.
DStarix Techno is based in India. A registered office address will be published here once the company’s incorporation is complete.