Privacy Notice
What this site collects, what it does with it, and how to get it back or get it deleted.
This notice describes how atyantik.com actually works, checked against the code that runs it on the date shown above. It is short because the site does little with personal data. If you read this site and submit nothing, the only record of your visit is in the server logs our infrastructure provider keeps for a month.
Who we are
Atyantik Technologies is a software engineering firm serving clients worldwide. Our registered office is at Office 501, Privilege Avenue, Behind Atlantis, Sarabhai Campus, Sarabhai Road, Vadiwadi, Vadodara, Gujarat 390007, India. Our GST registration number is 24AANCA6054A1Z1.
For anything you send us through a form on this site, we are the controller. We decide what happens to it, and this notice is our account of that.
For data we handle inside a client engagement, we are a processor. Our client controls that data, the engagement contract governs it, and this notice does not cover it.
We apply one standard everywhere rather than varying it by where you live. That standard is the strictest of the ones that reach us, so the protections below apply to you whether or not your local law requires them.
What we collect
Personal data reaches us in one way: you fill in a form and submit it. There is no other collection surface.
What you type. Your name, your work email address, and whatever you write in the message. Some forms ask which role best describes you. If you attach a file, we receive the file. A job application usually attaches a CV, and a CV holds a lot about you, so send only what you want us to have.
The newsletter form takes an email address and nothing else.
Context recorded alongside a submission, so that a reply makes sense and so that abuse can be traced:
- the page you submitted from, and any campaign parameters that were in that address
- your browser language, viewport size, how far down the page you had scrolled, how long you had been on it, and how many pages you had seen in that visit
- a one-way salted hash of your IP address, of your browser identification string, and of the page that referred you
- the result of each anti-abuse check: whether the bot check passed, whether the hidden field that only an automated submitter fills in was left empty, whether the request carried a valid token from the page it claimed to come from, and whether your email domain is a known disposable-address provider
- for an attachment, its size, its declared type, and whether its contents match that declared type
Your IP address and browser identification string are turned into a one-way hash before they are stored with your submission. The hash is computed with a secret value only we hold, and it cannot be turned back into your address. It is enough to recognise repeated abuse from one source. It is not something we can resolve back to you. The same address does produce the same hash for as long as that secret is unchanged.
What we do not collect
- No cookie while you are reading. Browsing this site sets none. Submitting a form sets one, and answering the cookie banner sets one more. The next paragraph describes both.
- One page counter, and it sets nothing on your device. This site loads Cloudflare Web Analytics, a small script from Cloudflare that counts page views and measures how fast pages load. It sets no cookie, writes nothing to your browser's storage, and does not fingerprint your address or your browser to recognise you later. Beyond that counter and the bot check described below, the only script this site loads is its own: no tag manager, no measurement pixel, no session recorder, no heat map, no advertising tag.
- No third-party tracking of any kind. Every outside address in a page here is either our own content network or a link you can choose to follow.
- No profile of you. The page counter cannot tell a return visit from a first one, and there is no advertising cookie, so nothing here follows you from one visit to the next.
- No sale of personal data, and no sharing of it for advertising. We give personal data to no data broker and no advertising network.
The two cookies. When you submit a form, we set a cookie named __Host-anima-csrf. It holds a random value, lasts 24 hours, cannot be read by any script, and is never sent to another site. Its only job is to prove your submission came from a page we served rather than from somewhere else pretending to be us. It says nothing about you and it is not used to recognise you on a later visit. When you answer the cookie banner, we set a second cookie named atyantik_consent. It records the version you answered, when you answered, and whether you allowed analytics and marketing. Both cookies are strictly necessary and both are set without asking: the first delivers something you asked for, and the second is the record of your answer, including an answer of no.
Cookies are covered on their own in our cookie policy. Site usage terms sit in our terms of use.
Why we are allowed to hold it
The basis differs by purpose, and treating every purpose the same would be wrong in one direction or the other.
- Answering what you sent us, whether that is a project enquiry, a job application, a legal notice, a security report or a bug report. The basis is legitimate interest. You approached us about a specific thing, and we cannot answer without reading it.
- Marketing email. The basis is consent, and consent means the confirmation step. Submitting the newsletter form does not put you on the list. We email you a link, and only if you follow it does the subscription become active, with the confirmation date recorded against your subscription. Nobody is added without that.
- Keeping the forms usable. Blocking automated abuse and enforcing rate limits rest on legitimate interest. Without it the forms would be unusable within a day.
Where the basis is legitimate interest you can object, and where it is consent you can withdraw. Both are covered under your rights below.
Nothing here obliges you to give us anything. No law and no contract requires you to fill in a form on this site. The fields marked as required are required only so that we can reply: without a name and an email address we have no way to reply to you. If you would rather not give us your details, do not send the form, and nothing follows from that.
What happens to a submission
One endpoint receives every form on this site. A submission passes through it in this order.
- A Cloudflare Turnstile bot check runs in your browser as you submit, and we verify the result. The check script loads at that moment rather than on page load, which is why it is absent until you submit something.
- The hidden honeypot field, the page token and the rate limit are all checked.
- Any attachment is written to our file storage and its contents are checked against its declared type.
- The submission is given an identifier, and the complete record is written to our object storage before anything else touches it. That ordering is deliberate: if a later step fails, your message still exists and is not silently lost.
- A routing record is then written to our database, and an audit entry records that a submission was received. Where the classifier below could not place your message, that routing record carries the whole submission so it can be read again.
Your message body sits in the stored record, and reading it is limited to the people who handle submissions.
If one of those checks refuses a submission, we record that a refusal happened, which check refused it, and the IP address it arrived from. On that path the address is recorded as given rather than hashed. We do not record what you wrote. That refusal record is an audit entry and is kept for the period given below.
Automated processing
Something automated reads what you write, and you are entitled to know what it is.
Every submission goes through a classifier that decides where it belongs: a project enquiry, a job application, a legal notice, a privacy request, a security report, a bug report, a partnership enquiry or a newsletter subscription. It works on keywords in your text and on whether a file is attached.
That classifier is a set of rules. No language model is applied to what you send. Where the rules cannot decide, the submission is set aside rather than routed on a guess.
Nothing here makes a decision about you. A job application is passed to the people who do our hiring, and it is passed on unchanged. We do not screen, score or rank applicants automatically, and no automated step here produces a legal effect or anything close to one.
How long we keep it
These are the periods we have committed to in writing.
- Your submission, including everything you wrote: 18 months, after which it moves to encrypted archive storage.
- The routing record for your submission: 12 months.
- Audit entries, which record that something happened rather than what was in it: 24 months.
- Records of alert emails our own systems send: 12 months.
- Server logs held by Cloudflare on our behalf: their default of 30 days.
- A newsletter subscription: until you unsubscribe.
Changing any of these periods requires a written decision on our side. They do not drift.
Who else handles it
Cloudflare provides everything this site runs on: the network in front of it, the servers behind it, the object storage, the database and the bot check. Anything the site stores sits inside our own Cloudflare account.
Nobody else. Page counting is done by Cloudflare Web Analytics inside that same Cloudflare account, and it is the only measurement in use. We use no other analytics service, no external log collection service and no external monitoring service. Personal data does not leave our own Cloudflare account for any of those purposes.
Where it is processed
The site runs on Cloudflare's global network, so processing may happen in more than one country depending on how a request is routed.
Cloudflare maintains standard contractual clauses for cross-border transfers along with its compliance certifications, and those are the transfer mechanism we rely on. We do not maintain separate contractual clauses of our own.
Cloudflare publishes those clauses and certifications itself, so you can read them without asking us. If you would rather have them from us, ask through the contact form and we will send you a copy of the safeguards we rely on.
Your rights
Whatever your jurisdiction, you can ask us to do all of the following.
- Tell you what we hold about you, and give you a copy.
- Correct anything that is wrong.
- Delete it.
- Hand it over in a form you can take elsewhere.
- Stop using it while a dispute about it is open.
- Object to a use that rests on legitimate interest.
- Withdraw consent where consent is what we relied on, which in practice means the newsletter.
We answer within 30 days.
Deletion runs as a cascade. We delete the stored submission, anything derived from it, and the audit entries keyed to the hash of your email address. One record survives: an entry saying that a deletion happened, on what date and at whose request. That entry holds no part of what was deleted, and it exists so we can show the deletion took place.
How to exercise them
Send a request through our contact form and choose the privacy option. It arrives as a request rather than as an enquiry and is handled on that track.
We publish no email address for this, and that is on purpose rather than an oversight. One form is the only way anything reaches us, so every request gets an identifier, a timestamp and a route the moment it lands. Nothing sits unread in a mailbox somebody forgot about.
To leave the newsletter, use the unsubscribe link in any email we have sent you. It works without a reply from us. The contact form works too.
If you are unhappy with how we handle a request, you can complain to your data protection authority. In India that is the Data Protection Board; in the European Union and the United Kingdom it is the supervisory authority for where you live.
California residents
We do not sell personal information and we do not share it for cross-context behavioural advertising. No personal information is exchanged with anyone for money or for anything else of value, apart from the provider that runs this site, which handles it only on our instructions and may not use it for its own purposes. There is no opt-out to configure because there is nothing to opt out of.
If you want an objection recorded anyway, send it through the contact form and we will record it.
Your rights to know what we hold, to have it deleted and to have it corrected are the same ones listed above and are exercised the same way.
We do not discriminate against anyone for using these rights. Asking us what we hold, or asking us to delete it, changes nothing about the service you get from us, nothing about what it would cost you, and nothing about how we deal with you afterwards.
Children
This site is for people working in a business context. We do not knowingly collect personal data from anyone under 16.
If you believe a child has sent us something, tell us through the contact form and we will delete it.
Changes to this notice
The date at the top is when this document was last checked against the system it describes.
It describes how the site behaves on that date and nothing further. When the site starts doing something new with personal data, this notice is rewritten before that happens rather than after.