Legal
Privacy policy
We collect very little. This page says exactly what, why, and for how long — including how we handle your data inside an AI engagement, which is the part that actually matters.
01The short version
This website has no advertising trackers, no third-party analytics scripts, no cookie wall and no marketing pixels. The only personal data we collect through the site is what you type into the contact form.
One exception, stated plainly: if you arrived from one of our adverts, we keep the click identifier from that link so we can tell which advert brought you. It is not a cookie, nothing is loaded from Google in your browser, and it is described in full in section 02.
Client data handled during an engagement is a separate matter and is governed by your contract. Section 06 covers it.
02What we collect through this site
Contact form. Your name, email address, and optionally company, phone, segment, area of interest, budget indication, and whatever you write in the message field. We ask for this so we can reply usefully.
Server and hosting logs. Our host records standard request data — IP address, user agent, timestamp, path — to serve the site and defend against abuse. We do not use these logs to build a profile of you.
Advertising click identifier. If you reach us by clicking one of our adverts, the link carries an identifier from the advertising platform. Your browser stores it locally and sends it with the contact form if you choose to fill one in, so that we can tell which advert led to which enquiry. It expires by itself after 90 days, it is stored with your enquiry and deleted with it, and if you never contact us it never reaches our servers at all. No script from the advertising platform runs on this site, and the identifier is not used to build a profile of you or to follow you anywhere else.
No cookies are set by us. There is no analytics, no remarketing, no session tracking on this site.
03Why we are allowed to hold it
For enquiries: because you asked us to contact you, and because we have a legitimate interest in responding to business enquiries about our services. For logs: legitimate interest in operating and securing the site.
If you contact us, we follow up. After our first reply you will get a small number of further emails over the following weeks — four at most, and the last one says it is the last one. They contain things worth reading rather than reminders to buy something. Every one carries a one-click unsubscribe that takes effect immediately and permanently, and the sequence stops on its own the moment you reply, book a call, or we speak.
We do not sell or rent your details, we do not add you to a general mailing list, and we do not use enquiry data to advertise to you anywhere else.
04Who else sees it
We use a small number of processors, and only these:
- Vercel — website hosting and server logs
- Resend — delivery of contact-form emails to our inbox
- Our email and CRM provider — so we can reply and keep track of the conversation
We do not sell personal data, and we do not share it with advertising networks or data brokers. Ever.
Contact-form content is never sent to an AI model by this website.
05How long we keep it
Enquiries that do not become an engagement: deleted within 24 months. Enquiries that become an engagement: retained for the life of the relationship and then as required by tax and contract law, typically eight years in India. Server logs: retained by our host on their standard schedule, generally under 30 days.
06Client data inside an AI engagement
This is the section that matters most, so it is the most specific.
In an engagement we are a processor acting on your documented instructions. You remain the controller of your data and of any personal data within it. The governing terms are those in your contract or data processing agreement, not this page.
Our standing practices:
- Data residency by design. Where you require data to stay in a jurisdiction or inside your own environment, we architect for it — regional endpoints, in-VPC deployment, or open-weight models hosted by you.
- PII redaction before external calls wherever the use case permits it.
- No training on your data. We use enterprise API tiers configured so that your content is not used to train provider models, and we do not use your data to train anything of our own or to benefit another client.
- Least privilege and audit logging. Access limited to the team on your engagement, with decisions, inputs, model versions and costs logged.
- Deletion on exit. On termination we return or delete your data as you instruct, and confirm it in writing.
We will name every subprocessor and model provider used on your engagement, in writing, before any of your data reaches them.
07Your rights
You can ask us what personal data we hold about you, ask us to correct it, ask us to delete it, ask for a copy, or object to our processing it. Write to ravi@geeksnomads.com and we will respond within 30 days.
Depending on where you are, these rights may arise under India’s Digital Personal Data Protection Act 2023, the UK/EU GDPR, or other applicable law. We apply the same standard regardless of which one you are relying on.
If you are unhappy with how we have handled a request, you may complain to your data protection authority. We would rather you told us first.
08Grievance officer
In accordance with Indian law, the grievance officer for data matters is Ravi Verma, reachable at ravi@geeksnomads.com, in Gurugram, Haryana.
09Security
Access on a least-privilege basis, encryption in transit, secrets held in managed secret storage, and separation between client environments. No security posture is absolute; if we become aware of a breach affecting your data we will tell you promptly and directly, with what we know and what we are doing about it.
10Changes
We will update this page when our practices change, with the date below. Changes that affect a live engagement will be raised with you directly.
Last updated 24 August 2026