Privacy Policy
This Privacy Policy explains how TECHNODICT collects, uses, discloses and protects personal information — who we share it with, how long we keep it, and what rights you have over it.
Two companion documents cover the rest, and this policy does not repeat them:
- Cookie Policy — the exact cookies and browser storage this website uses, and how to change your choice.
Terms of Service — the rules that govern your use of this website.
Last updated: July 2026
- Effective from: July 2026
Who we are
TECHNODICT ("TECHNODICT", "we", "us", "our") is an applied-AI company headquartered in Ahmedabad, India. We provide AI consulting, AI agents, automation, chatbots, document intelligence, data and AI analytics, generative AI and custom AI development services.
| Entity | TECHNODICT AI Private Limited |
| Registered address | 1108, Shaligram Arcade, Bopal, Ahmedabad, Gujarat 380058, India |
| Contact for privacy | privacy@technodict.com |
| Phone | +91 95126 54319 |
Under the EU/UK GDPR we are the controller of the personal data described below. Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary. When we process personal data inside a client's systems during an engagement, the client is the controller and we act as a processor — see Client data we handle on instruction.
What this policy covers
Covers: technodict.com and its subdomains; our contact and enquiry forms; email, phone and messaging correspondence with us; our pre-sales, recruitment and service-delivery activities.
Does not cover: third-party websites we link to; our clients' own products and systems; and personal data we process solely on a client's instruction under a services agreement.
At a glance
| Question | Short answer |
|---|---|
| Do we sell your personal data? | No — and we do not "share" it for cross-context behavioural advertising. |
| Do you need an account to browse? | No. The public website has no visitor accounts and no visitor login. |
| What if you only read pages? | Server log data only, plus analytics if you accepted it. |
| What if you contact us? | Name, email, phone, service of interest, your message, and anti-abuse metadata. |
| Do we train AI models on your data? | see AI and automated decisions |
| Who do you complain to? | Our Grievance Officer, then your supervisory authority — see Contact and complaints. |
What personal data we collect
Data you give us
Contact form. The enquiry form on this website collects exactly these fields:
| Field | Required | Why |
|---|---|---|
| Full name | Yes | To address you correctly and identify the enquiry |
| Email address | Yes | To reply |
| Phone number and country code | Yes | To reply by phone where you prefer, and to rate-limit abusive submissions |
| Service of interest | Yes | To route the enquiry to the right team |
| Message | Yes | The substance of your request |
Please do not put sensitive information — health data, government identifiers, financial account numbers, passwords or API keys — into a free-text message. We do not need it to answer an enquiry, and we will delete it if you send it.
Correspondence. If you email, call or message us, we keep the content and the contact details you used, so we have a record of what was asked and answered.
Business relationship data. If you become a client, supplier or partner, we process business contact details for your personnel, contract and scope documents, project correspondence, and billing records.
Recruitment. If you apply to work with us, we process your CV, contact details, work history, education, portfolio links, and notes from interviews.
Data collected automatically
Server and security logs. Our servers record standard request data for every page served: IP address, browser user agent, the page requested, the referring page, and the timestamp. This is produced by the act of serving a web page, and we use it for security, abuse prevention and fault diagnosis.
Anti-abuse metadata on enquiries. Stored alongside each contact-form submission: your IP address, your user agent (truncated), the page you submitted from, and a flag recording whether the anti-bot check passed. The form also contains a hidden "honeypot" field that is never displayed to you and never stored — if it is filled in, we discard the submission as automated. We rate-limit repeated submissions from the same phone number.
Broken-link diagnostics. When a page cannot be found we log the requested path, the referring URL and a hit counter, so we can repair broken links. This log contains no IP address and is not linked to you.
Analytics. Only if you accept it. See Cookies and analytics.
Data we do not collect
- No visitor accounts, profiles or logins on the public website.
- No payment details on this website.
- No special-category / sensitive personal data as defined by the GDPR, and no "sensitive personal information" as defined by the CPRA.
- No advertising or retargeting pixels, no session-replay, no heatmaps, no social tracking pixels.
- No personal data from children — see Children.
Client data we handle on instruction
When we deliver an engagement, we may access personal data held in a client's systems, documents or datasets. In that situation:
- The client decides the purpose and means; we act only on their documented instructions.
- Our handling is governed by the services agreement and, where required, a Data Processing Agreement with transfer safeguards — not by this policy.
- If you are an individual whose data sits in a client's dataset, direct your request to that client. If you contact us, we will refer you to them and assist them in responding.
Why we use it, and our legal basis
| Purpose | Data used | GDPR / UK GDPR basis | DPDP Act basis |
|---|---|---|---|
| Answering your enquiry, scoping and quoting | Contact form fields, correspondence | Pre-contractual steps at your request — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) | Consent given on submission; legitimate uses |
| Delivering services under contract | Business contact, project, billing data | Performance of a contract — Art. 6(1)(b) | Performance of contract |
| Following up on an enquiry that did not convert | Contact form fields | Legitimate interests in developing our business — Art. 6(1)(f) | Consent |
| Security, spam and abuse prevention | IP address, user agent, anti-bot score, rate-limit counters | Legitimate interests in protecting our systems — Art. 6(1)(f) | Legitimate uses — security and fraud prevention |
| Diagnosing faults, fixing broken links | Server logs, 404 diagnostics | Legitimate interests in a working website — Art. 6(1)(f) | Legitimate uses |
| Measuring audience and page performance | Analytics events and identifiers | Consent — Art. 6(1)(a) | Consent |
| Recruitment | Application materials | Pre-contractual steps — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) | Legitimate uses — employment |
| Tax, accounting and statutory records | Contract and billing records | Legal obligation — Art. 6(1)(c) | Compliance with law |
| Establishing or defending legal claims | Any relevant record | Legitimate interests — Art. 6(1)(f) | Legitimate uses |
We do not repurpose your enquiry for anything unconnected with it, and a sales or support enquiry alone does not put you on a marketing list. Where we do send marketing email, every message carries a working unsubscribe link, and unsubscribing stops all marketing from us.
Where we rely on legitimate interests, we have weighed those interests against your rights, and you may object at any time. Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out.
Cookies and analytics
The full inventory — every cookie and storage key, its provider, purpose and lifetime — is in the Cookie Policy. What matters for your privacy:
- Nothing non-essential runs before you choose. Analytics and advertising storage are set to
deniedby default on every first visit, and are only enabled if you press Accept on the consent banner. - We use Google Analytics 4 for audience measurement, subject to that consent.
- The contact form uses Google reCAPTCHA v3 to distinguish humans from automated abuse. This runs as a security measure on the form.
- The contact page loads map tiles from OpenStreetMap, which discloses your IP address and user agent to the OpenStreetMap Foundation's servers.
- Declining costs you nothing. Every page works identically without analytics.
Who we disclose personal data to
We do not sell personal data, and we never disclose it for a third party's independent marketing. We disclose it only as set out here.
| Recipient | What they receive | Why | Role |
|---|---|---|---|
| Google (Google LLC / Google Ireland Ltd) | Analytics events and identifiers, with consent; reCAPTCHA device and behaviour signals | Audience measurement; bot prevention | Processor; independent controller for its own security purposes |
| OpenStreetMap Foundation | IP address and user agent when map tiles load | Rendering the contact-page map | Independent controller |
| Hosting provider | Everything stored on or passing through our servers | Infrastructure | Processor |
| Email and productivity provider — [Google Workspace | Correspondence and its metadata | Business communication | Processor |
| Professional advisers — accountants, auditors, lawyers, insurers | Only what a specific matter requires | Legal, tax and audit obligations | Controller / processor as applicable |
| Government bodies, regulators, courts, law enforcement | Only what a lawful and valid demand requires | Compliance with law; defence of claims | Controller |
| An acquirer or successor | Records relevant to the transaction | Merger, acquisition or transfer of the business | Controller |
Every processor is bound by contract to act only on our instructions, keep the data confidential, and apply appropriate security measures.
International transfers
We are in India; our servers are in India; our providers, including Google, process data in the United States and elsewhere. Your personal data may therefore be transferred outside your country of residence, including outside the EEA, the UK and India.
For data protected by the GDPR or UK GDPR and transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses — with the UK Addendum or IDTA where applicable — plus supplementary technical and organisational measures where a transfer risk assessment calls for them. Under the DPDP Act, transfers are made only to countries not restricted by the Central Government.
You can request a copy of the safeguards we rely on at the address in Contact and complaints.
How long we keep it
We keep personal data only while the purpose that justified collecting it still applies, plus any period required by law or needed to defend a legal claim.
| Record | Retention |
|---|---|
| Enquiries that did not become an engagement | 24 months from last contact, then deleted or anonymised |
| Client and project records | Term of the engagement plus 7 years |
| Invoices, tax and accounting records | Statutory minimum under Indian tax and companies legislation |
| Web server and security logs | 90 days, rolling deletion |
| Broken-link diagnostics | 12 months — contains no personal identifiers |
| Analytics data | As configured in the GA4 property — 14 months |
| Unsuccessful job applications | 12 months, with consent to stay on file |
| Records of privacy requests | [3 years], to evidence compliance |
How we protect it
- Encryption in transit — the site is served over HTTPS with HTTP Strict Transport Security, a
Content Security Policy, and
X-Content-Type-Options,Referrer-PolicyandPermissions-Policyheaders on every response. - No browser-to-database path — the public website never queries our content or enquiry systems from your browser. All data access is server-to-server over a private network path, so enquiry records are never exposed to the public internet.
- Access control — enquiry records are readable only by authenticated staff holding an explicit role, enforced at the database-query level as well as in the application.
- Abuse prevention — anti-bot scoring, a honeypot field, and per-identifier rate limiting on the contact form.
- Data minimisation — we store only the fields listed above, truncate stored user-agent strings, and never store the honeypot value.
No system is perfectly secure. If a personal data breach affects you, we will notify you and the relevant authority where the law requires — including the Data Protection Board of India under the DPDP Act, and the competent supervisory authority within 72 hours where the GDPR applies.
Your rights
Your rights depend on where you live. We apply the strongest applicable standard rather than the minimum.
Under the GDPR / UK GDPR
- Access — confirmation of whether we process your data, and a copy of it.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion where a ground in Article 17 applies.
- Restriction — processing paused while a dispute is resolved.
- Portability — data you gave us, in a structured, machine-readable format.
- Objection — to processing based on legitimate interests, and absolutely to direct marketing.
- Withdraw consent — at any time, without affecting prior processing.
- Complain — to your supervisory authority: in the EEA via the EDPB member list, in the UK to the ICO.
Under the DPDP Act, 2023
- Access — a summary of the personal data we process and what we do with it.
- Correction, completion, updating and erasure of your personal data.
- Grievance redressal — raise a grievance with our Grievance Officer, who will respond within the period prescribed by the rules.
- Nomination — nominate someone to exercise your rights if you die or become incapacitated.
- Escalation — complain to the Data Protection Board of India if your grievance is unresolved.
You also have duties under the DPDP Act: do not impersonate another person when exercising rights, and do not file false or frivolous grievances.
If you are a California resident
- Know what we collect, use and disclose, and to which categories of recipient.
- Delete what we hold, subject to statutory exceptions.
- Correct inaccurate personal information.
- Opt out of sale or sharing — we do not sell or share personal information, so no opt-out mechanism is required; we honour a Global Privacy Control signal regardless.
- Limit use of sensitive personal information — we do not collect any.
- Non-discrimination — we will never deny service, change the price, or degrade quality because you exercised a privacy right.
How to make a request
Write to privacy@technodict.com with enough detail to find your records: the email address or phone number you used, and roughly when you contacted us.
- We acknowledge every request. Where we cannot identify you from what you have given us, we will ask for the minimum extra detail needed to verify you — and use it for nothing else.
- We respond within 30 days. If a request is genuinely complex we may extend, and we will tell you why before the original deadline passes.
- Requests are free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive — and we will explain why and how to challenge that.
- An authorised agent may act for you with written proof of authority.
AI and automated decisions
We build AI systems for a living, which makes the following commitments about your data worth stating plainly:
- No solely automated decisions producing legal or similarly significant effects about you. Enquiries are read and answered by people.
- We do not use your enquiry, correspondence or browsing data to train or fine-tune machine-learning models.
- Client data in engagements is governed by the services agreement, which states whether client data may be used for training, evaluation or retention — never by default, never without written instruction.
Children
This website and our services are directed at businesses and are not intended for children. We do not knowingly collect personal data from anyone under 18. Consistent with the DPDP Act, we do not track or behaviourally monitor children, do not direct advertising at them, and do not process a child's personal data in a way likely to cause detriment. If you believe a child has given us personal data, contact us and we will delete it.
Third-party links
Our website, blog and AI Insights articles link to third-party sites and resources. We do not control them and this policy does not apply to them. Read the privacy policy of any site before giving it personal information.
Changes to this policy
We review this policy at least annually and whenever we materially change how we handle personal data. On a material change we update the "Last updated" date above and — where the change affects consent-based processing or significantly reduces your rights — take reasonable steps to notify you before it takes effect.
Contact and complaints
| Entity | TECHNODICT AI Private Limited |
| Address | 1108, Shaligram Arcade, Bopal, Ahmedabad, Gujarat 380058, India |
| privacy@technodict.com | |
| Phone | +91 95126 54319 |
| Website | technodict.com |
Grievance Officer (DPDP Act, 2023). [CONFIRM — name, designation, email and postal address. Publishing the business contact of a Grievance Officer, or of the person who can answer questions about our processing, is a statutory requirement — not optional.]
EU / UK representative (GDPR Art. 27). [CONFIRM — required if we offer services to, or monitor individuals in, the EEA or the UK. Name the appointed representative and their contact details here, or delete this line if it does not apply.]
If our response does not satisfy you, you may complain to the Data Protection Board of India or to the supervisory authority where you live.
