Legal
Privacy Policy
What Asematic Technologies Private Limited collects when you use this site, which services receive it, how long we keep it, and how to make us delete it. Written to be read, not to be survived.
- Effective
- Applies to
- asematic.com and our enquiry channels
- Governing law
- DPDP Act, 2023 (India)
Summary
We do not sell your data
We have never sold, rented or traded personal information, and this policy commits us not to.
Enquiries go to our inbox
Contact forms are delivered by Web3Forms straight to hello@asematic.com. There is no customer database behind them.
Advertising tags are conditional
The Google and Meta tags only load on pages we are actively advertising against. When no campaign is configured, they are not on the page at all.
You can ask us to delete it
One email removes your enquiry and anything attached to it, unless we are required by law to keep the record.
Who we are
Asematic Technologies Private Limited ("Asematic", "we", "us") is a software development company registered in India and operating from Bhubaneswar, Odisha. We build websites, mobile apps, SaaS products, CRM and ERP systems and AI automation for clients in India and abroad.
Under India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the personal data described here — the party that decides why and how it is processed, and the party accountable for it.
This policy covers asematic.com and the enquiry channels reachable from it. It does not cover software we build for clients: when we develop a system for a client, that client is the Data Fiduciary for the data inside it and we act on their instructions as a Data Processor under our contract with them. Their privacy policy governs that data, not this one.
What we collect
Three categories, and nothing beyond them.
What you type into a form
Our contact form and the enquiry dialogue ask for your name and phone number, which are required, and your email address, company name, the services you are interested in and a free-text message, which are not. The message field is yours to fill; please do not put payment details, government identifiers or anyone else's personal data into it.
What your browser sends
Like any website, ours is served by a host that records standard request data — IP address, user agent, the page requested, the referring page and a timestamp. These logs exist to keep the site running and to investigate abuse. We do not build visitor profiles from them.
What advertising tags collect, when they run
If we are running a Google Ads or Meta campaign, the corresponding tag is loaded and sets cookies that let those platforms attribute a conversion to an ad. Section 05 covers this in full, including how to switch it off.
We do not collect special category data. We do not ask for your date of birth, government ID, financial account details or biometric data anywhere on this site, and no form on it has a field for them.
Where your information goes
We use a small number of third-party services to run this site. Each one is named below with what it receives and why, so you can read their policy as well as ours. We have no other recipients, and we do not sell, rent or trade personal data to anyone.
| Service | What it receives | Why |
|---|---|---|
| Web3Forms | Everything you submit through a form on this site | Delivers the enquiry to our inbox. We hold no separate database of submissions. |
| Email and calendar (Google Workspace) | Your enquiry, and any correspondence that follows | This is where we read and reply to what you send. |
| WhatsApp (Meta) | Your phone number and messages, only if you choose to open the chat | An optional handoff after a form submission. Nothing is sent to WhatsApp unless you tap through. |
| Google Ads | Cookie identifiers and page events, only while a campaign is running | Measures which ads produce enquiries. |
| Meta Pixel | Cookie identifiers and page events, only while a campaign is running | Measures which ads produce enquiries. |
| Google Search Console | Aggregated search statistics. No personal data. | Shows which queries surface our pages and whether they are indexed. |
| Our hosting provider | Standard server request logs | Serves the site and keeps it available. |
We may also disclose information where the law requires it — a valid order from a court or a competent authority, or where disclosure is necessary to establish or defend a legal claim. If that ever happens and we are permitted to tell you, we will.
Why we use it
The DPDP Act requires a lawful ground for every purpose. Ours are set out plainly rather than gathered into one paragraph, because a purpose you cannot identify is one you cannot object to.
| What we do | Why | Ground |
|---|---|---|
| Reply to your enquiry and quote for the work | It is what you contacted us for | Consent, given when you submit the form |
| Deliver a project and support it afterwards | Performing the contract we signed with you | Legitimate use — necessary for the contract |
| Issue invoices and keep accounting records | Indian tax and company law require it | Legal obligation |
| Keep the site available and investigate abuse | Security and continuity of service | Legitimate use |
| Measure advertising performance | Knowing which campaigns work | Consent, withdrawable at any time |
We do not use your data for automated decision-making that produces a legal or similarly significant effect on you, and we do not profile you to score or rank you.
If we want to use your information for a purpose that is not on this list, we will ask you first.
Cookies and tracking
This site sets no cookies of its own. It stores no analytics identifier, no session cookie and no preference cookie — the pages are static and do not need one.
The only cookies that can appear come from the two advertising tags, and both are conditional: they are configured per deployment, and on a deployment with no campaign configured the scripts are not added to the page at all. When they do run:
- Google Ads sets cookies under google.com and doubleclick.net to attribute a conversion to the ad you clicked.
- Meta Pixel sets cookies under facebook.com for the same purpose.
- Neither is used to build a profile of you for us. We see counts and conversions, never a list of individuals.
Turning them off
Every browser can block or clear cookies — usually under Settings, then Privacy. Blocking third-party cookies stops both tags from attributing anything, and nothing on this site breaks when you do. You can also opt out at the source, through Google Ads Settings and the Meta ad preferences in your account.
We honour Global Privacy Control. If your browser sends a GPC signal, we treat it as a withdrawal of consent for advertising measurement.
How long we keep it
The DPDP Act requires us to erase personal data once the purpose it was collected for is served. These are the periods we work to.
| What | How long | Then what |
|---|---|---|
| An enquiry that did not become a project | 24 months from your last message | Deleted from the inbox and from any notes taken from it |
| Client project correspondence | For the engagement, then 3 years | Deleted, except what accounting records require |
| Invoices and accounting records | 8 years | Retained — Indian tax and company law set this period, not us |
| Server request logs | Typically 30 to 90 days, per our host's policy | Rotated out automatically |
| Advertising cookies | Set and expired by Google and Meta, generally up to 13 months | Governed by their policies, not ours |
You do not have to wait for these periods. Ask us to erase your data and we will, within 30 days, unless a legal obligation in the table above requires us to keep a specific record.
Your rights
As a Data Principal under the DPDP Act, 2023, you hold the following rights over your personal data. Exercising any of them is free, and we will not treat you differently for it.
| Right | What it means |
|---|---|
| Access | A summary of the personal data we hold about you, what we do with it, and who we have shared it with. |
| Correction and completion | Have inaccurate data corrected and incomplete data completed. |
| Erasure | Have your data deleted once its purpose is served, subject to legal retention. |
| Withdraw consent | Withdraw consent as easily as you gave it. Processing up to that point stays lawful. |
| Grievance redressal | Raise a complaint with us first and get a substantive reply. |
| Nominate | Name someone to exercise these rights on your behalf if you die or become incapacitated. |
To exercise any of them, email hello@asematic.com with enough detail for us to find your record — the address or phone number you used, and roughly when. We reply within 30 days. We may ask one question to confirm you are who you say you are; we ask for the minimum that establishes it, and never for a government ID.
If our answer does not satisfy you, you may escalate to the Data Protection Board of India. If you are in the EU or UK, the GDPR rights of access, rectification, erasure, restriction, portability and objection apply to you as well, and you may complain to your national supervisory authority.
How we protect it
The measures below are the ones we actually operate. We have deliberately not claimed a certification we do not hold.
- The whole site is served over HTTPS, so what you submit is encrypted in transit.
- Access to the inbox that receives enquiries is limited to the people who answer them, and every account on it has two-factor authentication.
- Credentials and API keys are held in environment configuration, never in our source code repository.
- Client project access is granted per engagement and revoked when it ends.
- Forms carry a honeypot field and server-side validation to keep automated submissions out.
No system is perfectly secure, and we will not pretend otherwise. What we will do is tell you: if a breach affects your personal data, we will notify you and the Data Protection Board of India as the DPDP Act requires, without waiting to be asked.
Transfers outside India
Some of the services in Section 03 — Google, Meta, Web3Forms and our host — operate infrastructure outside India, so your data may be processed abroad. The DPDP Act permits this except to countries the Central Government restricts by notification, and we will stop using any recipient that becomes restricted.
For visitors in the EU and UK, transfers out of that region rely on the Standard Contractual Clauses in those providers' data processing terms.
Children's data
This is a business-to-business site and is not directed at anyone under 18. We do not knowingly collect data from children, and the DPDP Act prohibits us from tracking them or serving them targeted advertising in any case.
If you believe a child has sent us personal data, write to hello@asematic.com and we will delete it.
Links to other sites
Our pages link out to client work, social profiles, a Google Maps listing and WhatsApp. Once you follow one of those links you are on someone else's site under someone else's policy. We have no control over what they collect and this policy stops at our boundary.
Changes to this policy
We update this page when what we do changes — a new processor, a new purpose, a change in the law. The effective date at the top always reflects the version you are reading.
For a change that materially affects your rights, we will not rely on the date alone. We will contact clients and anyone with an open enquiry directly before it takes effect.
Contact and grievance redressal
Every question about this policy, every request to see, correct or delete your data, and every complaint goes to the same address. It is monitored by the people who can actually action it.
- Data Fiduciary
- Asematic Technologies Private Limited
- Contact
- Grievance Officer, Bhubaneswar, Odisha, India
- We reply within
- 30 days
- If we fall short
- Escalate to the Data Protection Board of India
Common questions
- Does Asematic sell or share my personal data?
- No. We have never sold, rented or traded personal data. The only third parties that receive anything are the processors listed in this policy — Web3Forms for form delivery, Google Workspace for email, and the Google and Meta advertising tags when a campaign is running — and each receives only what it needs to do its job.
- What happens to the contact form I submitted?
- It is delivered by Web3Forms to hello@asematic.com and read by the person who answers enquiries. There is no separate database behind the form. If the enquiry does not become a project, we delete it 24 months after your last message.
- Does this website use cookies?
- The site sets no cookies of its own — no analytics, session or preference cookies. The only cookies that can appear come from the Google Ads and Meta Pixel tags, and those tags are only loaded on deployments where an advertising campaign is configured. Blocking third-party cookies in your browser stops them, and nothing on the site breaks.
- How do I get my data deleted?
- Email hello@asematic.com and say what you want removed, including the address or phone number you contacted us with. We action erasure requests within 30 days. The one exception is accounting records, which Indian tax law requires us to keep for eight years.
- Who is responsible for data inside software Asematic built for a client?
- The client is. When we build a system for a client, they are the Data Fiduciary for the data their users put into it and we act as a Data Processor under our contract with them. Their own privacy policy governs that data. This policy covers asematic.com only.
The companion document is our Terms of Service.