What we collect
Three kinds of information, and no more than we need for the purpose at hand. We do not buy personal data, and we do not build advertising profiles.
If you only read the site, the first group is all we ever hold.
- Technical signals — IP address (truncated), browser and device type, referring page, and the pages you viewed. Used for security and for understanding which work resonates.
- Things you tell us — name, work email, company, and the contents of an enquiry or job application you submit through our forms.
- Engagement data — whether you opened a reply from us, and which links in it you followed, where you have not opted out.
Why we use it
Each purpose below is tied to a lawful basis under the GDPR and India's DPDP Act. We do not repurpose data for something you would not reasonably expect.
- To respond — answering an enquiry, scheduling a conversation, or progressing an application. Basis: taking steps at your request before a contract.
- To operate — keeping the site available, fast and free of abuse. Basis: legitimate interest in a secure service.
- To improve — aggregate analysis of which pages and case studies are useful. Basis: your consent, given through the cookie banner.
- To comply — tax, accounting and statutory record-keeping. Basis: legal obligation.
Who else touches it
We keep the vendor list short and each one is bound by a data-processing agreement. At the time of writing we rely on:
- Hosting and delivery — infrastructure and CDN providers serving this site.
- Email — transactional and correspondence delivery.
- Analytics — Google Analytics 4, loaded only if you accept analytics.
- Spam protection — Google reCAPTCHA, on the Contact, Careers and Opinion forms.
- Recruitment — applicant tracking, for careers submissions only.
How long we keep it
Enquiries are retained for 24 months from the last exchange, then deleted. Applications are held for 12 months so we can come back to you about a later role, unless you ask us to remove them sooner. Server and security logs roll off after 90 days. Contractual and financial records are kept for the statutory period we are required to hold them.
When a retention period ends we delete rather than archive.
How we protect it
Encryption in transit and at rest, least-privilege access reviewed quarterly, multi-factor authentication on every internal system, and separated environments for client production data. No system is perfectly secure — if a breach affects you, we will notify you and the relevant authority within 72 hours of becoming aware of it.
Your rights
Depending on where you live, you can ask us to do any of the following. We will not charge you, and we will not treat you differently for asking.
- Access — a copy of what we hold about you.
- Correct — fix anything inaccurate or incomplete.
- Delete — erase your data where no legal obligation requires us to keep it.
- Port — receive your data in a structured, machine-readable format.
- Object or restrict — stop or pause processing based on legitimate interest, including any marketing.
Where it goes
We operate from Bangalore and work with clients across Europe, the Gulf and North America, so data may be processed outside your country. Transfers out of the EEA or UK are covered by Standard Contractual Clauses plus a transfer risk assessment; transfers out of India follow the DPDP Act's permitted-country framework.
Children
Our services are built for businesses. We do not knowingly collect information from anyone under 18. If you believe a child has submitted data to us, write to us and we will delete it.
Changes to this policy
When we change something material we update the version stamp at the top of this page and, where we hold your contact details, tell you directly before the change takes effect. Earlier versions are available on request.
Contacting us
Ubinox Ventures, Bangalore, India. Write to hello@ubinox.in for anything in this policy, including data requests and questions about our processors.
If you are in the EEA or UK and are unhappy with our response, you have the right to complain to your local supervisory authority. In India, you may escalate to the Data Protection Board.
Access, correction, deletion, portability or objection — one message starts it. We acknowledge within 72 hours and resolve within 30 days.