Privacy Policy
How iAastha collects, uses, protects, and manages your personal and enterprise data.
iAastha is committed to safeguarding your privacy and ensuring enterprise-grade security across all AI consulting, engineering, and data platform engagements. We do not sell your personal data.
Information We Collect
We collect information to deliver tailored AI, machine learning, and data engineering services, improve our digital platforms, and communicate effectively with our clients and partners.
Information You Provide Directly: This includes contact details (such as your name, business email address, phone number, job title, and company name) provided when requesting consultations, submitting inquiries through our contact forms, applying for career opportunities, or entering into service agreements.
Client & Engagement Data: In the course of enterprise AI and data engagements, you may share project specifications, architectural workflows, and datasets. All client confidential data is handled under strict non-disclosure agreements (NDAs) and role-based access controls.
Technical & Usage Data: When you visit our website, our servers and analytics tools automatically collect standard device information, IP address, browser type, operating system, referral URLs, and interactions with website pages to ensure site reliability and performance.
How We Use Your Information
We use the data we collect solely for legitimate business, operational, and contractual purposes:
- Service Delivery & Deployment: Delivering end-to-end AI consulting, data science, and cloud platform engineering solutions tailored to your organization.
- Client Communication: Responding to inquiries, scheduling technical consultations, delivering project milestones, and providing ongoing support.
- Platform Optimization & Security: Monitoring website health, analyzing usage trends, preventing fraud, and defending against cyber threats.
- Legal & Regulatory Compliance: Fulfilling statutory obligations, auditing requirements, and enforcing legal agreements.
Legal Bases for Processing
Depending on your jurisdiction (such as under the EU/UK GDPR or applicable state privacy statutes), we process personal data under one or more recognized legal bases:
- Contractual Necessity: Processing necessary to negotiate, execute, or perform contracts with clients and vendors.
- Legitimate Interests: Operating and enhancing our business operations, securing our infrastructure, and communicating with enterprise prospects.
- Consent: Where you have granted explicit consent for specific processing activities (e.g., optional communications or non-essential cookies).
- Legal Compliance: Processing required to comply with applicable laws, court orders, or governmental regulations.
Data Sharing and Disclosure
We do not sell, rent, or trade personal data to third parties for marketing purposes. We share data only in the following restricted circumstances:
- Trusted Service Providers: Vetted third-party infrastructure and tooling partners (such as cloud hosting, analytics, and CRM platforms) operating under binding data processing agreements.
- Enterprise Engagements: Subcontractors or technical specialists working directly under iAastha's supervision, bound by strict confidentiality obligations.
- Corporate Transactions: In connection with any merger, acquisition, or sale of company assets, subject to continued privacy safeguards.
- Legal Requirements: When compelled by subpoena, court order, or applicable statutory authority to protect legal rights and public safety.
Data Security & Protection
We implement enterprise-grade technical, organizational, and physical safeguards designed to prevent unauthorized access, alteration, disclosure, or destruction of data.
These measures include TLS/SSL encryption in transit, AES-256 encryption at rest where applicable, multi-factor authentication (MFA), strict role-based access control (RBAC), regular security reviews, and secure code deployment pipelines.
International Data Transfers
iAastha operates globally, serving clients across North America, Europe, the Middle East, and Asia-Pacific. Personal data may be transferred to and processed in countries outside your country of residence.
When transferring data across international borders, we ensure adequate protection mechanisms are in place, including Standard Contractual Clauses (SCCs), data protection addenda, and adherence to relevant international data privacy frameworks.
Data Retention
We retain personal information only for as long as necessary to fulfill the purposes outlined in this policy, satisfy contract deliverables, maintain accurate financial records, and comply with statutory retention mandates.
When data is no longer required, it is securely destroyed, deleted, or anonymized in accordance with industry best practices.
Your Privacy Rights
Depending on your geographic location and applicable data privacy regulations (such as GDPR, CCPA/CPRA, or DPDP Act), you have rights regarding your personal data:
- Access & Portability: Request a copy of the personal data we hold about you in a structured format.
- Correction: Request rectification of inaccurate, incomplete, or outdated personal information.
- Erasure: Request the deletion of your personal data ("right to be forgotten"), subject to legal exceptions.
- Restriction & Objection: Object to or request restriction of certain processing operations.
- Withdraw Consent: Withdraw previously given consent at any time without affecting prior lawful processing.
To exercise any of these rights, please contact us at business@iaastha.com.
Contact Us & Grievances
If you have any questions, concerns, or requests regarding this Privacy Policy or our data management practices, please contact our data governance and privacy team.
Get in Touch