Privacy Policy
Version 1.0
Last updated: July 24, 2026
1. Introduction
This Privacy Policy describes how Digitomics Technologies Private Limited ("Digitomics," "we," "our," or "us") collects, uses, stores, shares, and protects your personal data when you use the Digitomics platform, website (digitomics.ai), and related services (collectively, the "Services").
This Policy is drafted in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the DPDP Rules 2025, the Information Technology Act, 2000 ("IT Act"), and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this Policy, please do not use our Services.
2. Definitions
For the purposes of this Privacy Policy:
"Data Principal" means the individual to whom the personal data relates — i.e., you, the user.
"Data Fiduciary" means Digitomics Technologies Private Limited, which determines the purpose and means of processing your personal data.
"Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act 2023.
"Processing" includes collection, storage, use, sharing, and deletion of personal data.
"Infrastructure Data" means technical data about your cloud, on-premises, SaaS, telecom, and facilities infrastructure that you connect to Digitomics. This may include cost figures, resource utilization metrics, configuration data, and operational logs.
"Consent Manager" means a person registered with the Data Protection Board of India who acts as a single point of contact for the Data Principal to manage consent.
3. Data We Collect
3.1 Data You Provide Directly
When you register, book a demo, or contact us, we collect:
- Full name
- Email address
- Phone number (optional)
- Company name and your role/designation
- Monthly infrastructure spend bracket (selected from a range)
- Any message or query you include in contact forms
3.2 Infrastructure Data (Connected via MCP Integrations)
When you connect your infrastructure accounts to Digitomics, the platform accesses:
- Cloud cost and billing data (AWS Cost Explorer, GCP Billing, Azure Cost Management)
- Resource utilization metrics (Kubernetes clusters, compute instances, storage volumes)
- Infrastructure configuration data (Terraform state, IaC configurations)
- SaaS subscription and license utilization data
- Telecom and network cost data (if connected)
- Observability data (Datadog, Prometheus, Grafana metrics — if connected)
Important: For edge-deployed instances (on NVIDIA DGX Spark, Mac Mini, or your own servers), Infrastructure Data is processed entirely on your premises. Zero data is transmitted to Digitomics cloud servers. For our SaaS deployment, Infrastructure Data is processed on our secure cloud infrastructure within India.
3.3 Usage Data (Automatically Collected)
We automatically collect certain data when you interact with our Services:
- IP address (anonymized after 30 days)
- Browser type, operating system, and device information
- Pages visited, features used, and session duration
- Referral source (how you found us)
- Copilot queries and interaction patterns (for service improvement, anonymized)
We use privacy-respecting analytics (no third-party ad tracking). We do not use cookies for advertising purposes.
3.4 Data We Do NOT Collect
Digitomics does not collect:
- Passwords or authentication credentials to your cloud accounts (we use OAuth2/IAM roles with read-only access)
- Source code, application data, or database contents
- Personal data of your end users or customers
- Biometric data, caste, religious beliefs, or political opinions
- Financial account numbers, credit card details, or banking credentials
4. Legal Basis and Purpose of Processing
Under the DPDP Act 2023, we process your personal data on the following lawful bases:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the Services | Account data, Infrastructure Data | Consent + Contract performance |
| Responding to demo requests | Name, email, company, role, spend | Consent (form submission) |
| Product improvement | Anonymized usage data, query patterns | Legitimate interest (anonymized) |
| Security and fraud prevention | IP address, access logs | Legitimate interest + Legal obligation |
| Product communications | Email address | Consent (opt-in) |
| Legal compliance | As required by law | Legal obligation |
5. Consent
5.1 How We Obtain Consent
In accordance with the DPDP Act 2023, we obtain your consent through:
- Clear, affirmative action when you submit the demo request form or create an account
- Explicit opt-in checkboxes for marketing communications (no pre-checked boxes)
- Separate consent for each distinct purpose of data processing
- Consent requests presented in clear, plain language (English and Hindi available)
5.2 Withdrawal of Consent
You may withdraw your consent at any time by:
- Emailing privacy@digitomics.ai with subject line "Withdraw Consent"
- Using the consent management settings in your Digitomics account dashboard
- Contacting our Consent Manager (details in Section 14)
Withdrawal of consent is as easy as giving consent. Upon withdrawal, we will cease processing your personal data for the relevant purpose within 72 hours. Please note that withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
6. Data Storage and Retention
6.1 Storage Location
SaaS Deployment: All data is stored on servers located in India (Mumbai/Hyderabad AWS regions) using encrypted storage.
Edge Deployment: All Infrastructure Data is stored entirely on your premises on the deployed hardware (DGX Spark, Mac Mini, or your servers). Only your account registration data is stored on our servers.
6.2 Retention Periods
| Data Type | Retention Period | After Retention |
|---|---|---|
| Account data | Duration of account + 90 days | Permanently deleted |
| Demo request data | 12 months from submission | Anonymized or deleted |
| Infrastructure Data (SaaS) | Duration of subscription + 30 days | Permanently deleted |
| Infrastructure Data (Edge) | Stored on your hardware | Your responsibility |
| Usage analytics | 24 months (anonymized after 30 days) | Permanently deleted |
| Security logs | 12 months | Permanently deleted |
7. Data Security Measures
We implement reasonable security safeguards as required under the IT Act 2000, SPDI Rules 2011, and the DPDP Act 2023:
Technical Measures
- Encryption at rest: AES-256 for all stored data
- Encryption in transit: TLS 1.3 for all API and web communications
- Access controls: Role-based access control (RBAC) with least-privilege principle
- Authentication: Multi-factor authentication (MFA) for all admin and API access
- Network security: VPC isolation, firewall rules, intrusion detection systems
- Key management: HashiCorp Vault for credential and secret management
Organizational Measures
- Annual security awareness training for all employees
- Background verification for employees handling personal data
- Incident response plan with defined escalation procedures
- Regular vulnerability assessments and penetration testing
- SOC 2 Type II certification in progress (target: Q3 2026)
Edge Deployment Security
For edge-deployed instances, additional security measures include:
- Full-disk encryption (LUKS with TPM-backed keys)
- Air-gap capability: zero internet connectivity required for core inference
- Hardware security module (HSM) integration for credential management
- Signed, verifiable update packages (USB or internal repository)
8. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We may share data only in these limited circumstances:
8.1 Service Providers
We engage trusted third-party service providers who process data on our behalf under strict contractual obligations:
- Cloud infrastructure: Amazon Web Services (India regions) — for SaaS hosting
- Email services: Google Workspace — for business communications
- Analytics: Privacy-respecting analytics tools (no advertising SDKs)
- Payment processing: Razorpay — for subscription billing (we do not store card details)
All service providers are bound by data processing agreements that comply with the DPDP Act.
8.2 Legal Requirements
We may disclose your data if required by law, regulation, legal process, or government request, including to meet national security or law enforcement requirements under Indian law.
8.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you via email and/or prominent notice on our website before your data is transferred and becomes subject to a different privacy policy.
8.4 With Your Consent
We may share your data with third parties when you have given explicit consent for such sharing.
9. Cross-Border Data Transfer
As of the effective date, the DPDP Act 2023 permits transfer of personal data to countries not restricted by the Central Government of India. We primarily store and process data within India. If any data is transferred outside India, we will ensure:
- The transfer complies with Section 16 of the DPDP Act 2023
- Appropriate contractual safeguards are in place (Standard Contractual Clauses)
- The receiving jurisdiction is not on any restricted list notified by the Central Government
- You are informed of such transfers in advance
10. Your Rights as a Data Principal
Under the DPDP Act 2023, you have the following rights:
- Right to Access (Section 11): You may request a summary of your personal data being processed and the processing activities undertaken.
- Right to Correction (Section 11): You may request correction or completion of your personal data that is inaccurate or incomplete.
- Right to Erasure (Section 12): You may request deletion of your personal data, subject to any legal retention obligations.
- Right to Grievance Redressal (Section 13): You may raise a grievance with our Grievance Officer. If unsatisfied, you may file a complaint with the Data Protection Board of India.
- Right to Nominate (Section 14): You may nominate an individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, please contact our Grievance Officer at privacy@digitomics.ai. We will respond within 30 days of receiving your request, as required by law.
11. Children's Data
Our Services are designed for enterprise business use and are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided personal data to us, please contact us at privacy@digitomics.ai, and we will promptly delete such data.
In compliance with Section 9 of the DPDP Act 2023, we obtain verifiable consent from a parent or guardian before processing any data of a child, should such a situation arise.
12. Cookies and Tracking Technologies
We use the following categories of cookies:
| Category | Purpose | Duration | Consent Required |
|---|---|---|---|
| Essential | Authentication, security, basic functionality | Session / 30 days | No (strictly necessary) |
| Analytics | Usage patterns, page views, feature adoption | 12 months | Yes (opt-in) |
| Preferences | Language, theme, dashboard layout | 12 months | No (functional) |
We do not use advertising or tracking cookies. We do not participate in cross-site tracking or targeted advertising. You can manage cookie preferences through the cookie banner on our website or your browser settings.
13. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the Data Protection Board of India as required under Section 8(6) of the DPDP Act 2023
- Report the incident to CERT-In within 6 hours as required under the IT Act directions
- Notify affected Data Principals without unreasonable delay if the breach is likely to result in high risk to their rights
- Provide details of the breach including: nature of the breach, data affected, remedial actions taken, and contact information for further queries
- Document the breach in our internal incident register with root cause analysis and preventive measures
14. Grievance Officer
In accordance with the IT Act 2000 and the DPDP Act 2023, we have appointed the following Grievance Officer:
- Name: To Be Appointed
- Designation: Grievance Officer & Data Protection Officer
- Email: privacy@digitomics.ai
- Address: Digitomics Technologies Pvt. Ltd., Bangalore, Karnataka, India
- Response Time: Within 30 days of receipt of grievance
If you are not satisfied with the resolution provided by our Grievance Officer, you have the right to file a complaint with the Data Protection Board of India.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
- We will post the updated Policy on our website with a new effective date
- We will notify registered users via email at least 15 days before the changes take effect
- We will obtain fresh consent where the changes affect the basis of processing
- Previous versions will be archived and available upon request
We encourage you to review this Policy periodically.
16. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: privacy@digitomics.ai
- General: hello@digitomics.ai
- Address: Digitomics Technologies Private Limited, Bangalore, Karnataka, India — 560001
- Website: https://digitomics.ai