What this website collects, what it does not, and the rights you hold over your information.
Aquison Technologies is a software studio based in Surat, Gujarat, India. This policy explains what happens to your information when you visit aquisontechnologies.com — this website and nothing else.
Two things it deliberately does not cover:
Under the Digital Personal Data Protection Act, 2023 we are the Data Fiduciary for this website. Under the GDPR we are the controller. In plain terms: for anything described below, we are the ones answerable to you.
This document describes the site as it is actually built, not as a template imagines it. Every factual claim below — no analytics, no cookies, no server-side form handling — is a property of the published code, and we have tried to say why each one is true so you can check rather than trust.
Very little, because there is very little to collect. This website is a static site: pre-built HTML and CSS served from a file host. It has no database, no application server, no user accounts and no login.
| What | Where it comes from | Why we have it | How long it lasts |
|---|---|---|---|
| Your name, email address and message | Only if you choose to email us | To answer you | Up to 24 months, then deleted — unless it becomes part of a client relationship |
| Your job application and CV | Only if you apply for a role by email | To assess your application | 12 months, so we can contact you about later openings. Ask us and we delete it sooner |
| Your theme preference | Set by your own browser when you use the light/dark toggle | So the site opens in the mode you chose | Until you clear your browser data. Never sent to us |
| Standard web request data | Sent automatically by every browser to every website | So the host can deliver the page and absorb attacks | Held briefly by our host. See Third parties we rely on |
That last row deserves a plain explanation. Any request for any web page necessarily reveals your IP address, your browser's user-agent string, and which page you asked for — that is how the internet delivers a response to the right place. Our hosting provider processes that to serve the file and to protect its network. We do not analyse it, build profiles from it, or connect it to you.
To be unambiguous, this site contains none of the following, and a look at its source will confirm it:
We have never sold personal data, never shared it for cross-context behavioural advertising, and will not do either.
This is the part most website privacy policies get wrong, so here is the mechanism precisely.
The form on our contact page is a draft composer, not a submission form. When you press send, your browser opens your own email application with the fields already filled in. Nothing is transmitted to us at that moment, and nothing is written to any server of ours — there is no server to write to.
You then decide whether to send the email. If you do, we receive an ordinary email from you, and it lives in our mailbox like any other correspondence. If you close the draft instead, we never learn you were there.
The same applies to the other ways to reach us:
wa.me in a new tab. It only does anything when you click it, and the conversation is then covered by WhatsApp's own privacy policy as well as ours.This website sets no cookies. There is no consent banner because there is no non-essential storage to ask you about.
One value is kept on your own device: whether you prefer the light or the dark theme. It is stored in localStorage under the key theme, and localStorage is not a cookie — unlike a cookie, the browser never attaches it to a network request, so it cannot travel to us or to anyone else. Clearing your site data removes it and the site reverts to its default appearance.
The full detail, including how to inspect and clear it, is in our Cookie Policy.
We keep this list short on purpose. Every entry is a service that can, by the nature of what it does, observe something about your visit.
| Who | What they do for us | What they can see | Their policy |
|---|---|---|---|
| Render | Hosts and serves this website | The technical request data described above, for pages you load | render.com/privacy |
| Google Maps | The embedded map on our contact page | That your browser loaded the map. Google may set its own cookies here | policies.google.com/privacy |
| WhatsApp (Meta) | The chat button | Nothing, unless you click it and start a conversation | whatsapp.com/legal/privacy-policy |
| Our email provider | Carries mail you send us | The contents of your correspondence, as any mail host does | — |
Two absences are worth stating. Our fonts are served from this site, not fetched from Google Fonts, so loading a page makes no request to Google. And the embedded map appears on the contact page only — every other page on this site loads nothing from a third-party domain.
| What we do | Lawful basis (GDPR) | Ground (DPDP Act, 2023) |
|---|---|---|
| Reply to an enquiry you sent us | Art. 6(1)(b) — steps at your request before a contract | Consent, given by your choosing to write to us |
| Consider a job application | Art. 6(1)(b) — pre-contractual steps | Consent, and the legitimate use of employment-related processing |
| Keep this site available and secure | Art. 6(1)(f) — legitimate interests | Legitimate use for maintaining the service |
| Remember your theme choice | No basis needed — the data never leaves your device | Not applicable |
Where we rely on consent you may withdraw it at any time, and where we rely on legitimate interests you may object. Neither is difficult: one email is enough, and neither costs you anything.
You have real, enforceable rights over your information. Which statute you rely on depends on where you are, but we apply the fuller standard to everyone rather than sorting people by geography.
Everyone, under the DPDP Act, 2023:
In addition, if the GDPR or UK GDPR applies to you:
We do not charge for any of this, and we will not treat you differently for asking.
Email hello@aquisontechnologies.com with what you want. Plain language is fine — you do not need to cite a statute or use a particular form.
We answer within 30 days. If a request is unusually complex we will tell you before that deadline rather than after it, and explain why. We may ask you to confirm your identity, but only where we genuinely cannot otherwise tell that the request is yours — never as a way of stalling.
If our answer does not satisfy you, say so and we will look again. You can also complain to the Data Protection Board of India under the DPDP Act, or to your local supervisory authority under the GDPR. We would rather you gave us the chance to put it right first, but that choice is yours, not ours.
This website is aimed at businesses and at people looking for work with us. It is not directed at children, and we do not knowingly collect data from anyone under 18 — the age the DPDP Act treats as the threshold for a child.
We run no tracking, no advertising and no profiling, so the practices those rules exist to prevent are absent here by construction. If you believe a child has sent us personal data, write to us and we will delete it.
We are in India, so any correspondence you send us is read and stored in India.
The services listed above operate internationally, and mail or requests may be processed on servers outside your country. Where the GDPR applies, those transfers rely on the transfer mechanisms each provider maintains — typically the European Commission's Standard Contractual Clauses. We do not move personal data anywhere ourselves beyond receiving your email.
Because there is no database and no server-side application, the entire class of attacks that steals visitor records does not apply here — there is no store to breach. What remains is protecting the delivery of the site itself:
X-Frame-Options: DENY — no other site can embed and impersonate this one.X-Content-Type-Options: nosniff — browsers must respect declared content types.Referrer-Policy: strict-origin-when-cross-origin — outbound links do not leak the full page you came from.Permissions-Policy denying camera, microphone and geolocation — this site cannot request them, even if a page were tampered with.No system is perfectly secure, and we will not pretend otherwise. What we can say is that we have chosen an architecture that holds as little of your data as possible, because data we never collect cannot be lost.
When we change this document we update the effective date and the version number shown at the top of the page. Those values come from the same source as the date in our sitemap, so they cannot quietly disagree.
If a change materially affects how we handle information about you, we will say so plainly here rather than relying on you to diff two versions. Substantive revisions are not applied retroactively to correspondence we have already deleted.
Questions about this policy, or want to exercise any of the rights above? Write to us and a person will read it.