Legal
Privacy Policy
Last updated — 3 September 2026
01Who we are
This policy is issued by The Automation Company, registered at [[FILL: registered address]] ("we", "us"). Reach us at theautomationcomp@gmail.com or +91 95990 94602. It explains how we handle personal data as a data fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), and how we act as a data processor for our clients' systems.
02What the contact form collects
When you submit our contact form we collect: your name, work email, phone number (optional), company, plant location (optional), the solutions you selected, and your message. We also record the page the form was submitted from, standard campaign parameters if present in the URL, the submission time, and your IP address (used only for rate limiting and abuse prevention).
We do not collect data from this website beyond what you type into the form. There is no advertising tracking on this site — see the Cookie Policy.
03Lawful basis and consent
We process contact-form data on the basis of your consent, given by submitting the form for the stated purpose: responding to your enquiry and following up about the services you asked about. We do not use this data for unrelated marketing, and we do not add you to newsletters you did not ask for.
You may withdraw consent at any time by writing to the Grievance Officer below, after which we will delete your enquiry data unless a legal obligation requires retention.
04Retention
Enquiry data is retained for 24 months from the last contact, so that returning enquiries have context, and is then deleted. Where an enquiry becomes a commercial engagement, related correspondence is retained as part of the engagement records for as long as legally required.
05Third-party processors
We share personal data only with the processors needed to run this website and respond to you:
- Resend (Resend, Inc.) — sends the enquiry notification and your confirmation email. Your form contents pass through Resend's systems.
- Vercel (Vercel, Inc.) — hosts this website; standard server logs, including IP addresses, are processed by Vercel.
- Upstash (Upstash, Inc.) — provides rate limiting; a hashed/plain form of your IP address is processed briefly to count requests.
We do not sell personal data to anyone, and we do not share it with advertisers or data brokers.
06Your rights under the DPDP Act
As a data principal under the DPDP Act, you have the right to:
- access a summary of the personal data we hold about you and how it has been processed;
- correction and completion of inaccurate or incomplete data;
- erasure of your data where retention is no longer necessary or consent is withdrawn;
- grievance redressal through the Grievance Officer below;
- nominate another individual to exercise these rights on your behalf in case of death or incapacity.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
07Grievance Officer
Grievance Officer: [[FILL: grievance officer name]], The Automation Company, [[FILL: registered address]]. Email: theautomationcomp@gmail.com. Phone: +91 95990 94602. We acknowledge grievances within 72 hours and aim to resolve them within 15 days.
08CCTV and facial recognition data in client deployments
Our Spatial AI services process camera footage and, where a client enables it, facial-recognition data inside client factories. This section states plainly how that works:
- Data stays on client premises by default. Video is processed on edge hardware inside the client's network; raw footage does not flow to us or to any cloud unless the client explicitly configures otherwise.
- The client is the data fiduciary for their footage and their employees' biometric data. We act as a data processor on the client's documented instructions.
- Facial recognition requires informed consent. Deployments include explicit employee enrollment with a non-biometric alternative, and consent records are the client's obligation, which we help implement.
- Signage and notice are mandatory. We install statutory notice boards at monitored areas and entrances as part of every vision deployment, and go-live is conditional on them being in place.
- Retention defaults are conservative: event clips default to 90 days and face embeddings are deleted when an employee exits, unless the client documents a different lawful retention period.
Employees of client plants who have questions about footage or biometric data should contact their employer as data fiduciary; we will support every such request the client passes to us.
09Security
Contact-form data is transmitted over TLS and stored in access-controlled systems. Client deployment data is protected by network isolation (on-premise processing), role-based access, and encrypted transport. No system is perfectly secure; we notify affected parties and the authorities of personal data breaches as the DPDP Act requires.
10Children
This website and our services are directed at businesses. We do not knowingly process children's personal data.
11Changes to this policy
We will post any changes on this page and update the date at the top. Material changes affecting how enquiry data is used will be notified to affected individuals by email where we hold one.