Skip to content
Dravin AI
  • Services
  • How we work
  • Work
  • Company
  • Blog
Book a callBook a call
MenuClose
  • Services
  • How we work
  • Work
  • Company
  • Blog

Privacy

What Dravin AI collects, why, for how long, and your rights under India’s Digital Personal Data Protection Act, 2023, and how the site uses Google Analytics.

LAST UPDATED 24 SEPTEMBER 2026 · DIGITAL PERSONAL DATA PROTECTION ACT, 2023

IN PLAIN LANGUAGE

What this policy says, in seven lines. Section 6 has every retention period in one place.

THE WEBSITE
Google Analytics 4 counts visits: cookieless in the EEA, the UK and Switzerland, with its own cookies elsewhere. Our host’s server logs record IP addresses for security. Section 2
WHEN YOU CONTACT US
We keep what you send for 24 months after the last contact, then delete it. Sending the message is your consent, and you can withdraw it by asking us to delete the correspondence. Section 3
YOUR SYSTEMS
Personal data inside a client’s systems is processed only on the client’s written instructions, kept off our machines unless a statement of work says otherwise, and never used to train a model. Section 4
DELETION
Our access and local copies go within seven days of an engagement ending. Technical review materials go 30 days after the review. Section 6
WHO ELSE SEES IT
A small number of subprocessors, listed by category on this page, named for anyone who asks and shared with clients before work starts. Section 5
YOUR RIGHTS
Ask what we hold about you, correct it, erase it or withdraw consent: email [email protected] with “DPDP request” in the subject line. We answer within 30 days. Section 7
IF SOMETHING GOES WRONG
A breach affecting personal data we hold is reported to the affected client within 72 hours of us knowing. Grievances go to the Grievance Officer (section 8). Section 9

CONTENTS

  1. 01Who is responsible
  2. 02The website
  3. 03When you contact us
  4. 04Client systems and the data inside them
  5. 05Subprocessors, by category
  6. 06Retention, in one place
  7. 07Your rights under the DPDP Act
  8. 08Grievances
  9. 09Security incidents
  10. 10Children
  11. 11Changes

TERMS USED ON THIS PAGE

DPDP Act
India’s Digital Personal Data Protection Act, 2023, and its rules. The law this policy is written for.
Data Principal
The person the personal data is about. You, when you visit the site or contact us.
Data Fiduciary
The party that decides why and how personal data is processed. Us, for website visitors and people who contact us; the client, for data inside the client’s own systems.
Data Processor
The party that processes personal data on a Data Fiduciary’s instructions. Us, for data inside a client’s systems.
Subprocessor
A third-party service we use to run the firm and that may handle data as a result. Listed by category in section 5; we send the named list to anyone who asks.
Grievance Officer
The role at Dravin AI that handles complaints about how we handle personal data, reachable at [email protected]. Section 8.

This policy covers two things: what the website and our enquiry forms collect about you, and how we handle personal data that lives inside client systems we are given access to. It is written for India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) and its rules. If you are outside India, the same practices apply, and we will honour the rights your own law gives you where we reasonably can.

1. Who is responsible

Dravin AI, Gachibowli, Hyderabad, Telangana 500032, India. For website visitors and people who contact us, we are the Data Fiduciary. For personal data inside a client’s systems, the client is the Data Fiduciary and we are a Data Processor acting on their instructions. Questions and requests: [email protected].

2. The website

dravin.ai uses Google Analytics 4 to count visits and a few actions, such as pressing “Book a call”, sending a form or subscribing to the newsletter. It records the pages you view, your approximate location (country and city, derived from your IP address, which Google Analytics does not store), your device and browser, and the site that sent you. We never send it your name, your email address or what you write in a form.

Google Analytics runs in consent mode. In the European Economic Area, the United Kingdom and Switzerland, storage is denied: it sets no cookies there and sends only cookieless pings, which Google uses for modelled, aggregate counts. Everywhere else it sets its own first-party cookies (_ga and _ga_<ID>, kept for up to two years) so that a return visit counts as the same visitor. Google processes this data for us under its data processing terms. Event-level data is kept for the retention period set in our Google Analytics account, at most 14 months. You can block it with any content blocker or with Google’s opt-out add-on at tools.google.com/dlpage/gaoptout. We run no advertising or social-media tracking tags.

Our host’s server logs record IP addresses for security and are kept by the host on its own schedule. That is the entire list.

3. When you contact us

If you email us, book a call, or send the review or contact form, we collect what you send: your name, email address, a repository URL if you give one, your description of the problem (and your company, if you mention it), and anything you say on the call. We use it to reply, to prepare for the call, and to write the review you asked for. We keep it for 24 months after the last contact, then delete it, unless an engagement follows, in which case it is kept for the life of the engagement and seven years after for accounting and legal reasons. Your consent to this is the act of sending the message; you can withdraw it by asking us to delete the correspondence, and we will, unless a legal obligation requires us to keep an invoice or a contract.

4. Client systems and the data inside them

When a client gives us access to a repository, a database or a cloud account, it may contain personal data of the client’s users. We process that data only on the client’s written instructions and only to do the work described in the statement of work. We do not copy production personal data to our machines unless the statement of work says so; we prefer anonymised or synthetic data for development and testing. We do not use client data to train any model. We access the least that will do the job, and we remove our access, delete local copies and confirm both in writing within seven days of the work ending. Review materials from a technical review are deleted 30 days after the review unless an engagement follows. If we believe a client’s instruction would breach the DPDP Act, we say so before acting on it.

5. Subprocessors, by category

We use a small number of third-party services to run the firm. They are listed by category here; we send the current named list to anyone who asks at [email protected], and share it with clients before work starts.

  • Cloud hosting and content delivery, for this website, for development environments and for preview deployments of client branches.
  • Email and calendar, for correspondence and booking.
  • Form tools, for the enquiry and review forms, and a newsletter service, for people who subscribe.
  • Web analytics (Google Analytics), to count visits and actions on this website.
  • Source-control hosting, for repositories we hold copies of during an engagement.
  • AI model providers, for coding assistance, used only on terms that prohibit training on the input and only where the client has not vetoed them.
  • Accounting and invoicing.

Some of these providers process data outside India. Where they do, they are bound by contract to protect it to at least the standard on this page.

6. Retention, in one place

  • Enquiry and correspondence data: 24 months after last contact.
  • Technical review materials: 30 days after the review, unless an engagement follows.
  • Client code, credentials and local copies: deleted within seven days of an engagement ending.
  • Contracts, statements of work and invoices: seven years, for accounting and legal purposes.
  • Website analytics (Google Analytics 4): event-level data for at most 14 months.
  • Website server logs: kept by our host on its own schedule, for security.

7. Your rights under the DPDP Act

As a Data Principal you can ask us: what personal data we hold about you and how we use it; to correct or complete it; to erase it, subject to legal retention; to withdraw consent; and to nominate someone to exercise these rights for you. Write to [email protected] with “DPDP request” in the subject line. We answer within 30 days. If you are a user of a client’s product, we will pass your request to the client, who is the Data Fiduciary, and help them answer it.

8. Grievances

Grievance Officer, Dravin AI: [email protected], Gachibowli, Hyderabad, Telangana 500032. If you are not satisfied with our answer, you may approach the Data Protection Board of India.

9. Security incidents

If we become aware of a breach affecting personal data we hold, we tell the affected client within 72 hours of knowing and support the notifications the DPDP Act requires of the Data Fiduciary. Our security practices are on the security page.

10. Children

Our services and website are for businesses. We do not knowingly collect personal data from anyone under 18.

11. Changes

The date at the top changes when this policy does. Material changes for existing clients are notified by email.

Questions about this page

Write to [email protected]. Put “DPDP request” in the subject line for anything about your own data, and we answer within 30 days. A complaint about how we handle personal data goes to the Grievance Officer at the same address (section 8).

Read alongside: Terms·Security

Dravin AI

An AI software company. We build AI systems and the apps they ship in.

Gachibowli, Hyderabad, Telangana 500032, India[email protected]+91 97040 32587
  • Dravin AI on GitHub, opens in a new tab

Pages

  • Services
  • How we work
  • Work
  • Company
  • Blog
  • Request a code review
  • Contact

Legal

  • Terms
  • Privacy
  • Security

© 2026 Dravin AI

  • RSS
  • llms.txt