Legal
Privacy Policy
What personal data this site and our services collect, why, who else processes it, how long it is kept, and the rights you have over it.
Last updated 2 September 2026
Draft — pending legal review. This document was prepared by the engineering team during the build of this website. It has not been reviewed by a qualified legal adviser and should not be relied on as a statement of your rights or our obligations until it has been.
Known gaps a reviewer must close
- The registered office address and CIN of the controller named below. The company and its registered city are stated; the full statutory identification is not.
- The retention period for enquiry correspondence, which is described honestly below as not yet fixed rather than given a number nobody has set.
- The lawful basis recorded against each processing purpose, and whether a UK/EU representative or a Data Protection Officer is required.
- The processing region configured for each provider named below, and the transfer mechanism relied on for personal data leaving its country of origin.
Who controls your data
The controller of the personal data described in this policy is Bralak AI Pvt. Ltd., a company registered in Noida, Uttar Pradesh, India, trading as Bralak AI. Questions about this document go to info@bralakai.com.
Our registered office address and corporate identity number are not yet published on this site. Both are listed above as gaps a reviewer must close, and neither is withheld deliberately.
What this policy covers, and what it does not
This policy covers personal data we collect through this website and through enquiries made to us — that is, data for which we decide the purpose.
Personal data we process on behalf of a client as part of a system we have built is not covered here. In that relationship the client is the controller, we act on their documented instructions, and the terms are set by the contract for that engagement rather than by this page.
What we collect
Three categories, and every one of them is either something you type and send deliberately or something a web server unavoidably receives. We collect nothing else, and we buy nothing from anyone.
- Enquiry data — the fields you complete on the contact form: name, work email, company, country, job title, industry, what you need, your current systems, budget, timeline and your project description.
- Technical data — the IP address, user agent and timestamp that reach the server when a page or the contact endpoint is requested.
- Rate-limiting data — your IP address, and the email address you submit with the form, held as counter keys that expire within ten minutes. This is how the contact endpoint is protected from automated abuse.
Why we use it
Enquiry data is used to answer your enquiry, to prepare for a call about it, and to keep a record of the conversation. We do not sell it, we do not use it to build a profile of you, we do not use it to train any model, and we do not add you to a marketing list because you contacted us.
Technical and rate-limiting data is used to keep the site available and to stop automated abuse of the contact endpoint. It is not used to identify you or to track you between visits.
Automated decision-making
This website makes no automated decisions about you and does no profiling. Your enquiry is read by a person, not by a routing rule.
Where an AI system we build for a client processes personal data, the decisions about what is automated, what requires human review and where approval gates sit are made with that client and recorded in the engagement. The position we take on those decisions is set out on the Security page.
Who else processes it
Three providers, named individually rather than described as a category, because a policy that says only "our hosting and email providers" tells you nothing you could check:
- Google Workspace (Google LLC) — receives and stores the contents of your enquiry, because enquiries are delivered to a Workspace mailbox by email.
- Vercel Inc. — hosts this website and runs the contact endpoint, and therefore processes the request data described above in the course of serving pages.
- Upstash, Inc. — holds short-lived rate-limiting counters keyed on the requesting IP address and, for the per-address limit, on the email address submitted with the form. Nothing else from the form reaches it, and the keys expire within ten minutes.
Where it is processed
We are established in India, and the providers named above are incorporated in the United States and operate globally. Personal data covered by this policy will therefore cross borders.
Open — pending review. The specific processing region configured for each provider, and the transfer mechanism relied on where a transfer requires one, have not yet been confirmed and recorded. We would rather state that plainly than name a region we have not verified.
How long we keep it
Open — pending review. Enquiry correspondence is kept while the conversation is live and afterwards as a business record. No fixed deletion date is configured today, and rather than publish a period nobody has set, we are stating the position as it actually is. Setting that period is listed above as a gap to close.
Rate-limiting counters expire automatically within ten minutes. Server logs are short-lived and are not used to identify individuals.
You can ask us to delete your enquiry correspondence at any time by emailing info@bralakai.com, and we will, unless we are required to keep it.
Your rights
Depending on where you live, you may have the right to ask for a copy of your personal data, to have it corrected or deleted, to object to or restrict how it is used, to withdraw consent where we relied on it, and to receive your data in a portable form. You also have the right to complain to the data protection authority in your country.
To exercise any of these, email info@bralakai.com. We will not charge you for it, we will not require you to justify the request, and we will respond within the period the applicable law sets.
Security
Data is encrypted in transit and at rest, administrative access requires two-factor authentication, and API credentials are held as environment variables that never reach browser code. The Security page describes our practices in more detail, and every item on it is something you can ask us to demonstrate.
We hold no security certification and claim none.
This site is not intended for children
This is a business-to-business website. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, email us and we will delete it.
Changes to this policy
If this policy changes materially we will update the date at the top of this page in the same change that alters the behaviour it describes, not afterwards. The version published here is the current one.
Also