Legal
Privacy Notice
What personal data we collect, why we collect it, how long we keep it, and the rights you have over it.
Pending legal review. This notice is drafted to reflect how Deep Heuristics intends to operate, but it has not been settled by qualified counsel in the relevant jurisdictions. It must be reviewed and approved before the site is published to a live audience.
1. Who we are
Deep Heuristics is an independent AI trust and assurance institution with its registered office at 6b Garden Road, Chennai, Tamil Nadu 603112, India. For questions about this notice or about how we handle personal data, write to [email protected].
2. What this notice covers
This notice covers personal data we collect through deepheuristics.com and in the course of correspondence with us. Personal data processed inside a client engagement is governed by the contract for that engagement, including any data processing terms agreed within it; where those terms conflict with this notice, the contract prevails.
3. What we collect
Information you give us
- Enquiry and assessment request forms. Your name, work email address, organisation, role, and the content of your message, together with the subject or service line you select.
- Correspondence. Anything you choose to send us by email, including attachments.
Information collected automatically
- Server logs. Our web server records the requested URL, timestamp, HTTP status, referrer, user agent, and IP address. These entries support security monitoring and fault diagnosis.
- No analytics or advertising. This site sets no cookies, embeds no advertising or analytics trackers, and loads no third-party scripts. Fonts, stylesheets, scripts, and images are served from this domain, so browsing the site does not disclose your visit to any third party.
4. Why we process it, and on what basis
| Purpose | Data | Basis |
|---|---|---|
| Responding to your enquiry | Form submissions, correspondence | Steps taken at your request prior to entering a contract, and our legitimate interest in answering enquiries |
| Providing and administering services | Contact and engagement records | Performance of a contract |
| Security monitoring and abuse prevention | Server logs, submission metadata | Legitimate interest in protecting our systems and users |
| Meeting legal and regulatory obligations | Engagement and financial records | Legal obligation |
5. Automated submission controls
Our forms include a hidden field and a timing check to detect automated submission, and we rate-limit submissions by IP address. These controls process only submission metadata. They do not profile you and produce no decision with legal or similarly significant effect.
6. Sharing
We do not sell personal data and we do not share it for advertising. We disclose personal data only to: service providers who process it on our behalf under written instructions (including our email and hosting providers); professional advisers under a duty of confidentiality; and public authorities where disclosure is legally required. Where a provider is located outside your jurisdiction, transfers are made under an appropriate safeguard recognised by the applicable law.
7. Retention
- Enquiries that do not lead to an engagement — retained for up to 24 months, then deleted.
- Engagement records — retained for the contractual retention period and any longer period required by law or professional obligation.
- Server logs — retained for up to 90 days, other than entries preserved for an active security investigation.
8. Your rights
Subject to the law applicable to you, you may have the right to request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability, and to object to processing carried out on the basis of legitimate interests. Where processing relies on consent, you may withdraw that consent at any time without affecting processing already carried out.
To exercise any of these rights, write to [email protected]. We may need to verify your identity before acting. You also have the right to complain to your national data protection authority.
9. Confidential material
Please do not submit credentials, production data, personal data about third parties, or confidential technical detail through the forms on this site. Where an engagement requires technical material, we will agree a secure channel and appropriate contractual terms first.
10. Security
We apply access controls, encryption in transit and at rest, logging, and least-privilege administration to the systems that hold personal data. Client evidence is segregated by client and is never used to train models. Suspected security issues should be reported under our responsible disclosure policy.
11. Changes
Material changes to this notice will be published on this page. The version in force is the version published here.