Legal
Privacy policy
We collect very little. This page says exactly what, why, and for how long — including how we handle your data inside an AI engagement, which is the part that actually matters.
Draft — not yet published
Entity details are still placeholders and this text has not been reviewed by a lawyer. Fill in src/data/legal.ts and set verified: true before launch.
| Registered name | TODO — registered entity name, e.g. Geeks & Nomads Technologies Pvt. Ltd. |
| CIN | TODO — CIN |
| GSTIN | TODO — GSTIN |
| Registered address | TODO — registered address as it appears on the incorporation certificate |
| Grievance officer | TODO — name |
| Contact | ravi@geeksnomads.com |
01The short version
This website has no advertising trackers, no third-party analytics scripts, no cookie wall and no marketing pixels. The only personal data we collect through the site is what you type into the contact form.
Client data handled during an engagement is a separate matter and is governed by your contract. Section 06 covers it.
02What we collect through this site
Contact form. Your name, email address, and optionally company, phone, segment, area of interest, budget indication, and whatever you write in the message field. We ask for this so we can reply usefully.
Server and hosting logs. Our host records standard request data — IP address, user agent, timestamp, path — to serve the site and defend against abuse. We do not use these logs to build a profile of you.
No cookies are set by us. There is no analytics, no remarketing, no session tracking on this site.
03Why we are allowed to hold it
For enquiries: because you asked us to contact you, and because we have a legitimate interest in responding to business enquiries about our services. For logs: legitimate interest in operating and securing the site.
We do not use enquiry data for marketing. You will not be added to a mailing list or a nurture sequence because you filled in a form.
04Who else sees it
We use a small number of processors, and only these:
- Vercel — website hosting and server logs
- Resend — delivery of contact-form emails to our inbox
- Our email and CRM provider — so we can reply and keep track of the conversation
We do not sell personal data, and we do not share it with advertising networks or data brokers. Ever.
Contact-form content is never sent to an AI model by this website.
05How long we keep it
Enquiries that do not become an engagement: deleted within 24 months. Enquiries that become an engagement: retained for the life of the relationship and then as required by tax and contract law, typically eight years in India. Server logs: retained by our host on their standard schedule, generally under 30 days.
06Client data inside an AI engagement
This is the section that matters most, so it is the most specific.
In an engagement we are a processor acting on your documented instructions. You remain the controller of your data and of any personal data within it. The governing terms are those in your contract or data processing agreement, not this page.
Our standing practices:
- Data residency by design. Where you require data to stay in a jurisdiction or inside your own environment, we architect for it — regional endpoints, in-VPC deployment, or open-weight models hosted by you.
- PII redaction before external calls wherever the use case permits it.
- No training on your data. We use enterprise API tiers configured so that your content is not used to train provider models, and we do not use your data to train anything of our own or to benefit another client.
- Least privilege and audit logging. Access limited to the team on your engagement, with decisions, inputs, model versions and costs logged.
- Deletion on exit. On termination we return or delete your data as you instruct, and confirm it in writing.
We will name every subprocessor and model provider used on your engagement, in writing, before any of your data reaches them.
07Your rights
You can ask us what personal data we hold about you, ask us to correct it, ask us to delete it, ask for a copy, or object to our processing it. Write to ravi@geeksnomads.com and we will respond within 30 days.
Depending on where you are, these rights may arise under India’s Digital Personal Data Protection Act 2023, the UK/EU GDPR, or other applicable law. We apply the same standard regardless of which one you are relying on.
If you are unhappy with how we have handled a request, you may complain to your data protection authority. We would rather you told us first.
08Grievance officer
In accordance with Indian law, the grievance officer for data matters is TODO — name, reachable at ravi@geeksnomads.com, at TODO — registered address as it appears on the incorporation certificate.
09Security
Access on a least-privilege basis, encryption in transit, secrets held in managed secret storage, and separation between client environments. No security posture is absolute; if we become aware of a breach affecting your data we will tell you promptly and directly, with what we know and what we are doing about it.
10Changes
We will update this page when our practices change, with the date below. Changes that affect a live engagement will be raised with you directly.
Last updated 21 August 2026