Records · DPDP

Privacy notice

What this website collects, why, for how long, and your rights under the Digital Personal Data Protection Act, 2023. No advertising trackers, no data sold.

Last updated: 6 October 2026 · Version: 2026-10 · Applies to autowhat.ai and the site assistant. Data inside customer deployments is governed by that customer’s contract and DPA.

1. Who we are

Autowhat AI and Automations Pvt. Ltd. (CIN U26205MH2025PTC440557), 6th Floor, Plot No. 53/1, Visheshwar Nagar Road, Goregaon East, Mumbai 400063, India, is the Data Fiduciary for personal data collected on this website under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules made under it. For visitors outside India we apply the same standards, and GDPR/UK GDPR rights where they apply.

2. What we collect, why, and on what basis

DataPurposeBasisKept for
Enquiry form: name, work email, company, area of interest, your messageReplying to you, scoping a working session, opening an engagementConsent (you submit the form) and, after a contract, performance of that contract24 months after our last contact, or the life of the contract
Site assistant: the questions you type, the pages the assistant linked, and — only if you give it — your email in the lead cardAnswering your question; improving the answers; following up if you asked us toConsent (you start the conversation)Transcripts without an email: 90 days. With an email: as an enquiry (above)
Analytics: pages viewed, referrer, device type, browser, country-level language, clicks on buttons, scroll depth and time on page, with a random visitor idUnderstanding which pages help visitors and fixing what does notConsent via the cookie banner. Nothing is collected until you allow analyticsRaw events 400 days; daily totals without any identifier are kept
Consent record: your choices, the policy version shown, the page, time and a pseudonymous idProving what you consented to, as the DPDP Act requiresLegal obligation3 years after withdrawal or last activity
Technical logs: IP address, user agent, requested URLSecurity, rate limiting, uptimeLegitimate use (security) — IPs in our analytics are hashed with a salt that rotates daily and are never stored in the clearServer logs 30 days
Data-rights requests: your name, email, the request and our correspondenceHandling your request and keeping a record of itLegal obligation3 years after closure

We do not run advertising trackers, we do not sell or rent personal data, we do not profile visitors across other websites, and we do not knowingly collect data from children under 18. If we ever process children’s data for an education customer, that is done under that customer’s instructions with verifiable parental consent as the Act requires.

3. Consent and how to withdraw it

Where we rely on consent it is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. Analytics is off by default; the banner asks before anything non-essential runs. You can change or withdraw your choices at any time from Cookie settings in the footer; withdrawal is as easy as giving consent and takes effect immediately on this device. Withdrawing consent does not affect processing already done, and we may still keep what the law requires us to keep (for example the record that you withdrew). We honour the Global Privacy Control signal: when your browser sends it, analytics stays off unless you turn it on.

4. Who sees the data

Our own engineers and sales team, on a need-to-know basis. Processors acting on our instructions: our hosting provider, our email delivery provider for the enquiry form, and the model provider that powers the site assistant (which receives the text of the conversation and the page context, not your identity). Each is bound by contract to use the data only for the service we have asked for. Some processors are outside India; transfers are made only to countries not restricted by the Central Government under section 16 of the DPDP Act, under contractual safeguards. We disclose personal data to authorities only when the law requires it.

5. Your rights as a Data Principal

Use the data-rights request form or write to privacy@autowhat.ai. We verify your identity against the email we hold, acknowledge within 72 hours and respond within 30 days. There is no charge.

6. Grievance Officer

Grievance Officer, Autowhat AI and Automations Pvt. Ltd.
6th Floor, Plot No. 53/1, Visheshwar Nagar Road, Goregaon East, Mumbai 400063, India
privacy@autowhat.ai · +91 83696 44748 (Mon–Fri, 10:00–18:00 IST)

7. Security and breaches

Data is encrypted in transit (TLS) and at rest, access is role-based and logged, secrets are kept outside the code base, and raw analytics events expire automatically. If a personal data breach affects you, we will notify you and the Data Protection Board of India in the form and time the rules prescribe.

8. Customer systems

Products deployed for a customer (on managed cloud, in their VPC or on-premises) process data under that customer’s instructions; the customer is the Data Fiduciary and Autowhat is the processor. Those systems have their own notices, DPAs, retention schedules and deletion procedures. This notice covers the public website and the site assistant only.

9. Changes

When this notice changes materially the version number above changes and the banner asks for consent again. Earlier versions are available on request.