Privacy Notice

What this site collects, what it does with it, and how to get it back or get it deleted.

This notice describes how atyantik.com actually works, checked against the code that runs it on the date shown above. It is short because the site does little with personal data. If you read this site and submit nothing, the only record of your visit is in the server logs our infrastructure provider keeps for a month.

Who we are

Atyantik Technologies is a software engineering firm serving clients worldwide. Our registered office is at Office 501, Privilege Avenue, Behind Atlantis, Sarabhai Campus, Sarabhai Road, Vadiwadi, Vadodara, Gujarat 390007, India. Our GST registration number is 24AANCA6054A1Z1.

For anything you send us through a form on this site, we are the controller. We decide what happens to it, and this notice is our account of that.

For data we handle inside a client engagement, we are a processor. Our client controls that data, the engagement contract governs it, and this notice does not cover it.

We apply one standard everywhere rather than varying it by where you live. That standard is the strictest of the ones that reach us, so the protections below apply to you whether or not your local law requires them.

What we collect

Personal data reaches us in one way: you fill in a form and submit it. There is no other collection surface.

What you type. Your name, your work email address, and whatever you write in the message. Some forms ask which role best describes you. If you attach a file, we receive the file. A job application usually attaches a CV, and a CV holds a lot about you, so send only what you want us to have.

The newsletter form takes an email address and nothing else.

Context recorded alongside a submission, so that a reply makes sense and so that abuse can be traced:

  • the page you submitted from, and any campaign parameters that were in that address
  • your browser language, viewport size, how far down the page you had scrolled, how long you had been on it, and how many pages you had seen in that visit
  • your IP address and your browser identification string, as they arrived, together with a one-way salted hash of each and of the page that referred you
  • what our edge network reads from that connection at that moment: the country, region and city it appears to come from, the time zone there, the network provider it arrived through, and the browser, operating system and kind of device you used
  • the result of each anti-abuse check: whether the bot check passed, whether the hidden field that only an automated submitter fills in was left empty, whether the request carried a valid token from the page it claimed to come from, and whether your email domain is a known disposable-address provider
  • for an attachment, its size, its declared type, and whether its contents match that declared type

LinkedIn. We also read the performance statistics of our own LinkedIn company page and, with each person's consent, of posts published by Atyantik staff from their own profiles, through LinkedIn's reporting exports and its Marketing API. What we receive is counts: impressions, reactions, comments, clicks, follower growth, and follower and visitor totals grouped by country, industry, job function and seniority. LinkedIn never tells us who an individual viewer or follower is, and we have no way to find out. Those counts are stored in our own systems and shown only to Atyantik staff.

Facebook and Instagram. In the same way we read the performance statistics of our own Facebook Page and Instagram account through Meta's Graph API: views, reach, reactions, comments, saves, shares, follows, and follower totals grouped by country, city, age band and gender. Meta never tells us who an individual viewer or follower is, and we do not receive names, profiles or messages. Those counts are stored in our own systems and shown only to Atyantik staff.

Your IP address and browser identification string are stored with your submission, as they arrived. We keep them so that the people who read your message know where in the world it came from and what you were using, and so that repeated abuse from one source can be recognised. They are kept for the same period as the rest of your submission, they are deleted with it, and they are seen only by the people at Atyantik who handle enquiries. Alongside them we keep a one-way salted hash of each, computed with a secret value only we hold, which is what our automated abuse checks compare against.

What we do not collect

  • No cookie while you are reading. Browsing this site sets none. Submitting a form sets one, and answering the cookie banner sets one more. The next paragraph describes both.
  • One page counter, and it sets nothing on your device. This site loads Cloudflare Web Analytics, a small script from Cloudflare that counts page views and measures how fast pages load. It sets no cookie, writes nothing to your browser's storage, and does not fingerprint your address or your browser to recognise you later. Beyond that counter and the bot check described below, the only script this site loads on its own is its own: no tag manager, no measurement pixel, no session recorder, no heat map, no advertising tag.
  • Google Analytics, measuring only if you switch it on. Every page loads the Google Analytics 4 script with every permission denied, in what Google calls consent mode. In that state it sets no cookie and sends Google only a cookieless signal that a page was viewed, with no identifier that could recognise you again. Turn the Analytics switch on in the cookie banner and it sets two cookies and lets us see which pages get read and where visitors arrive from. It then also records, with no name attached: which call-to-action buttons and navigation links you click, which outside links you follow (the site they lead to, never the page), how far down a page you scrolled in quarters, whether a page stayed open for 30, 60 or 180 seconds, when you started filling in a form, and when a form you sent was accepted, with the form's subject and an opaque submission number. That number identifies the message, not you; we use it to match the count in Google Analytics against the message in our own records, and it is the only thing about a form that goes to Google. The cookie policy lists those cookies, what they hold and how long they last.
  • One signal from our own server, only if Analytics is on. When a form you sent is accepted, our server also tells Google Analytics that an enquiry, a partnership request or a job application arrived, with the same opaque submission number and the same consent check: if you did not switch Analytics on, or Google Analytics never set its cookies in your browser, nothing is sent. Your name, address and message never go with it.
  • Audiences, defined now, used for advertising by nobody yet. Google Analytics groups visitors who did similar things, such as reading for a minute, clicking through on a hire page, starting a form, or sending one, into named audiences. We could use those audiences to target advertising later. No advertising campaign runs today, an audience can only be used for advertising if you have also switched Marketing on, and this page will say so before that changes.
  • No third-party tracking of any kind. Every outside address in a page here is either our own content network or a link you can choose to follow.
  • No profile of you. The page counter cannot tell a return visit from a first one, and there is no advertising cookie. Google Analytics, if you allowed it, can recognise a return visit to this site and can place you in one of the audiences described above; it is not used to follow you to any other site today, and the only link between it and anything you send us through a form is the opaque submission number.
  • No sale of personal data, and no sharing of it for advertising. We give personal data to no data broker and no advertising network.

The two cookies. When you submit a form, we set a cookie named __Host-anima-csrf. It holds a random value, lasts 24 hours, cannot be read by any script, and is never sent to another site. Its only job is to prove your submission came from a page we served rather than from somewhere else pretending to be us. It says nothing about you and it is not used to recognise you on a later visit. When you answer the cookie banner, we set a second cookie named atyantik_consent. It records the version you answered, when you answered, and whether you allowed analytics and marketing. Both cookies are strictly necessary and both are set without asking: the first delivers something you asked for, and the second is the record of your answer, including an answer of no.

Cookies are covered on their own in our cookie policy. Site usage terms sit in our terms of use.

Why we are allowed to hold it

The basis differs by purpose, and treating every purpose the same would be wrong in one direction or the other.

  • Answering what you sent us, whether that is a project enquiry, a job application, a legal notice, a security report or a bug report. The basis is legitimate interest. You approached us about a specific thing, and we cannot answer without reading it.
  • Marketing email. The basis is consent, and consent means the confirmation step. Submitting the newsletter form does not put you on the list. We email you a link, and only if you follow it does the subscription become active, with the confirmation date recorded against your subscription. Nobody is added without that.
  • Keeping the forms usable. Blocking automated abuse and enforcing rate limits rest on legitimate interest. Without it the forms would be unusable within a day.

Where the basis is legitimate interest you can object, and where it is consent you can withdraw. Both are covered under your rights below.

Nothing here obliges you to give us anything. No law and no contract requires you to fill in a form on this site. The fields marked as required are required only so that we can reply: without a name and an email address we have no way to reply to you. If you would rather not give us your details, do not send the form, and nothing follows from that.

What happens to a submission

One endpoint receives every form on this site. A submission passes through it in this order.

  • A Cloudflare Turnstile bot check runs in your browser as you submit, and we verify the result. The check script loads at that moment rather than on page load, which is why it is absent until you submit something.
  • The hidden honeypot field, the page token and the rate limit are all checked.
  • Any attachment is written to our file storage and its contents are checked against its declared type.
  • The submission is given an identifier, and the complete record is written to our object storage before anything else touches it. That ordering is deliberate: if a later step fails, your message still exists and is not silently lost.
  • A routing record is then written to our database, and an audit entry records that a submission was received. Where the classifier below could not place your message, that routing record carries the whole submission so it can be read again.

Your message body sits in the stored record, and reading it is limited to the people who handle submissions.

If one of those checks refuses a submission, we record that a refusal happened, which check refused it, and the IP address it arrived from. On that path the address is recorded as given rather than hashed. We do not record what you wrote. That refusal record is an audit entry and is kept for the period given below.

Automated processing

Something automated reads what you write, and you are entitled to know what it is.

Every submission goes through a classifier that decides where it belongs: a project enquiry, a job application, a legal notice, a privacy request, a security report, a bug report, a partnership enquiry or a newsletter subscription. It works on keywords in your text and on whether a file is attached.

That classifier is a set of rules. No language model is applied to what you send, with the one exception described next. Where the rules cannot decide, the submission is set aside rather than routed on a guess.

Internship applications are screened with AI assistance. The CV is turned into text and into a structured summary of what it states, the public links the applicant gives us are checked, and the application is assessed against evidence of real work. The strongest applicants may receive questions by email about their own work, and their replies are assessed the same way. A person makes every decision about who is invited to the next round. Applicants can ask for a human-only review, or opt out, by replying to any email from us. Our Internship screening process sets out what is read, what is never read and how automated tools are used.

Every other job application is passed to the people who do our hiring, unchanged. We do not screen, score or rank those applicants automatically, and no automated step here produces a legal effect or anything close to one.

How long we keep it

These are the periods we have committed to in writing.

  • Your submission, including everything you wrote: 18 months, after which it moves to encrypted archive storage.
  • The routing record for your submission: 12 months.
  • Audit entries, which record that something happened rather than what was in it: 24 months.
  • Records of alert emails our own systems send: 12 months.
  • Server logs held by Cloudflare on our behalf: their default of 30 days.
  • A newsletter subscription: until you unsubscribe.
  • An internship application: an applicant who asks to be kept on file is kept, and may be contacted about future internships and roles, until they ask us to stop. Otherwise the application is anonymised 18 months after it was received: the screening summary and notes go with it, and what remains, such as the track, scores and dates, no longer identifies anyone. An applicant who opts out of automated screening has the screening record deleted at once.

Changing any of these periods requires a written decision on our side. They do not drift.

Who else handles it

Cloudflare provides everything this site runs on: the network in front of it, the servers behind it, the object storage, the database and the bot check. Anything the site stores sits inside our own Cloudflare account.

Google, as our processor. Google LLC receives the cookieless page-view signal described above from every visitor, and full Google Analytics 4 measurement from visitors who switched Analytics on, including the one signal our own server sends when a form is accepted, under Google's data processing terms and with your address truncated. Page counting that needs no permission is done by Cloudflare Web Analytics inside our Cloudflare account. We use no other analytics service, no external log collection service and no external monitoring service.

For internship applications only: AI service providers and an email delivery provider, acting as our processors under contract, receive only what each task needs. Automated reading of a CV happens within our own hosting account, where this site runs. Any AI service provider outside it receives an application only with the applicant's name and contact details removed.

Where it is processed

The site runs on Cloudflare's global network, so processing may happen in more than one country depending on how a request is routed.

Cloudflare maintains standard contractual clauses for cross-border transfers along with its compliance certifications, and those are the transfer mechanism we rely on. We do not maintain separate contractual clauses of our own.

Cloudflare publishes those clauses and certifications itself, so you can read them without asking us. If you would rather have them from us, ask through the contact form and we will send you a copy of the safeguards we rely on.

For internship applications, our AI service providers and our email delivery provider may process data outside India, under contractual safeguards. Any AI service provider outside our own hosting account receives an application only with the applicant's name and contact details removed.

Your rights

Whatever your jurisdiction, you can ask us to do all of the following.

  • Tell you what we hold about you, and give you a copy.
  • Correct anything that is wrong.
  • Delete it.
  • Hand it over in a form you can take elsewhere.
  • Stop using it while a dispute about it is open.
  • Object to a use that rests on legitimate interest.
  • Withdraw consent where consent is what we relied on, which in practice means the newsletter.

We answer within 30 days.

Deletion runs as a cascade. We delete the stored submission, anything derived from it, and the audit entries keyed to the hash of your email address. One record survives: an entry saying that a deletion happened, on what date and at whose request. That entry holds no part of what was deleted, and it exists so we can show the deletion took place.

How to exercise them

Send a request through our contact form and choose the privacy option. It arrives as a request rather than as an enquiry and is handled on that track.

We publish no email address for this, and that is on purpose rather than an oversight. One form is the only way anything reaches us, so every request gets an identifier, a timestamp and a route the moment it lands. Nothing sits unread in a mailbox somebody forgot about.

To leave the newsletter, use the unsubscribe link in any email we have sent you. It works without a reply from us. The contact form works too.

If you are unhappy with how we handle a request, you can complain to your data protection authority. In India that is the Data Protection Board; in the European Union and the United Kingdom it is the supervisory authority for where you live.

California residents

We do not sell personal information and we do not share it for cross-context behavioural advertising. No personal information is exchanged with anyone for money or for anything else of value, apart from the provider that runs this site, which handles it only on our instructions and may not use it for its own purposes. There is no opt-out to configure because there is nothing to opt out of.

If you want an objection recorded anyway, send it through the contact form and we will record it.

Your rights to know what we hold, to have it deleted and to have it corrected are the same ones listed above and are exercised the same way.

We do not discriminate against anyone for using these rights. Asking us what we hold, or asking us to delete it, changes nothing about the service you get from us, nothing about what it would cost you, and nothing about how we deal with you afterwards.

Children

This site is for people working in a business context. We do not knowingly collect personal data from anyone under 16.

If you believe a child has sent us something, tell us through the contact form and we will delete it.

Changes to this notice

The date at the top is when this document was last checked against the system it describes.

It describes how the site behaves on that date and nothing further. When the site starts doing something new with personal data, this notice is rewritten before that happens rather than after.

Back to top