Privacy Policy
Last updated: August 19, 2026
Octon Solutions ("we," "us," or "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at octonsolutions.in and use our services. This policy is in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
For any privacy-related inquiries, please contact us at reachus@octonsolutions.in. We will respond to your request within 30 days.
2. Personal Data We Collect
We collect personal data only when you provide it to us voluntarily through the following touchpoints:
2.1 Contact Form
When you submit a contact form on our website, we collect:
- Name — to address your inquiry
- Email address — to respond to your inquiry
- Subject (optional) — to categorize your inquiry
- Message content — to understand and address your request
Legal basis: Consent (Article 6(1)(a) GDPR) — you provide this data voluntarily by submitting the form, and you must consent to our Privacy Policy before submitting.
Purpose: To respond to your inquiry and provide requested information about our services.
2.2 AI Chat Feature
When you use our AI Chat Assistant, we collect:
- Message text — the content of your messages
- Timestamp — when each message was sent
- Session identifier — a randomly generated, non-identifying session ID
Legal basis: Consent (Article 6(1)(a) GDPR) — by using the chat feature, you consent to your messages being processed.
Purpose: To provide AI-powered responses to your queries. Messages may be processed by third-party AI services (see Section 6).
2.3 Server Logs
When you visit our website, our hosting provider automatically collects:
- IP address (anonymized where possible)
- Browser type and version
- Operating system
- Referring URL
- Date and time of access
- Pages viewed and time spent
Legal basis: Legitimate interest (Article 6(1)(f) GDPR) — to ensure website security, prevent abuse, and maintain service availability.
3. How We Use Your Data
We use your personal data for the following purposes:
- Responding to inquiries — processing contact form submissions (Legal basis: Consent)
- Providing AI chat services — processing chat messages (Legal basis: Consent)
- Website analytics — understanding how visitors use our site (Legal basis: Consent — analytics cookies)
- Security and fraud prevention — detecting and preventing malicious activity (Legal basis: Legitimate interest)
- Legal compliance — complying with applicable laws and regulations (Legal basis: Legal obligation)
4. Data Retention Periods
We retain your personal data only for as long as necessary for the purposes described in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Contact form submissions | 24 months | To maintain record of correspondence and follow-up |
| AI Chat messages | 12 months | To improve service quality and for troubleshooting |
| Analytics data (GA) | 26 months | Standard Google Analytics retention setting |
| Session recordings (Clarity) | 30 days | Microsoft Clarity default retention |
| Necessary cookies | Session | Deleted when browser is closed |
| Analytics cookies | 12 months | From time of consent |
| Marketing cookies | 12 months | From time of consent |
After the retention period expires, your data is securely deleted or anonymized so that it can no longer be linked to you.
5. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience on our website. Cookies are small text files stored on your device. You can manage your cookie preferences at any time by clicking the "Cookie Settings" link in our footer.
5.1 Necessary Cookies
These cookies are essential for the website to function and cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
| CookieConsent | Stores your cookie consent preferences | 12 months |
| csrf_token | Prevents cross-site request forgery attacks | Session |
5.2 Analytics Cookies
These cookies help us understand how visitors interact with our website. They are only loaded with your explicit consent.
| Service | Purpose | Data Collected |
|---|---|---|
| Google Analytics | Website usage analytics | Page views, session duration, bounce rate, anonymized IP, browser info |
| Microsoft Clarity | Session recording and heatmap analytics | Click patterns, scroll depth, mouse movements (anonymized) |
5.3 Marketing Cookies
These cookies are used to deliver relevant advertisements and track campaign performance. They are only loaded with your explicit consent.
| Service | Purpose |
|---|---|
| Google Tag Manager | Manages marketing and analytics tags; may set cookies for remarketing and ad personalization |
6. Third-Party Services
We use the following third-party services that process personal data:
| Service | Provider | Purpose | Data Residency |
|---|---|---|---|
| Google Analytics | Google LLC | Website analytics | United States |
| Google Tag Manager | Google LLC | Tag management | United States |
| Microsoft Clarity | Microsoft Corporation | Session recording and heatmaps | United States |
| Netlify | Netlify, Inc. | Website hosting and form processing | United States |
| n8n Webhooks | n8n / self-hosted | Contact form and chat message processing | Varies by deployment |
| Cookiebot | Usercentrics A/S | Consent management | European Union |
We have entered into Data Processing Agreements (DPAs) with all third-party processors that handle personal data on our behalf.
7. Cross-Border Data Transfers
Some of our third-party service providers operate outside the European Economic Area (EEA). When we transfer your personal data outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) — approved by the European Commission for transfers to countries without an adequacy decision
- EU-US Data Privacy Framework — for transfers to US-based organizations that have certified under the framework (e.g., Google, Microsoft)
You may request a copy of the applicable transfer safeguards by contacting us at reachus@octonsolutions.in.
8. Your Rights Under GDPR
If you are a resident of the European Economic Area (EEA) or the United Kingdom (UK), you have the following data protection rights:
Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you.
Right to Rectification (Article 16)
You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure / Right to be Forgotten (Article 17)
You have the right to request deletion of your personal data, subject to certain legal exceptions.
Right to Restriction of Processing (Article 18)
You have the right to request that we limit how we use your data in certain circumstances.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format.
Right to Object (Article 21)
You have the right to object to the processing of your personal data, including for direct marketing purposes.
Right to Withdraw Consent (Article 7(3))
Where processing is based on consent, you have the right to withdraw consent at any time. You can manage cookie consent via the "Cookie Settings" link in our footer. For other data, contact us directly.
Right to Lodge a Complaint
You have the right to file a complaint with your local data protection supervisory authority if you believe your rights have been violated.
To exercise any of these rights, please contact us at reachus@octonsolutions.in. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.
9. Data Subject Request Process
When you submit a data subject access, deletion, or modification request:
- Submission — Send your request to reachus@octonsolutions.in with the subject line "Data Subject Request"
- Identity verification — We may ask you to provide identifying information to confirm your identity and prevent unauthorized access
- Processing — We will process your request within 30 days. If the request is complex, we may extend this period by an additional 60 days, with notification
- Response — We will provide a written response to your request, including any actions taken or reasons for refusal
10. How We Protect Your Data
We implement appropriate technical and organizational security measures to protect your personal data, including:
- SSL/TLS encryption for all data in transit
- Access controls limiting who can view personal data
- Regular security assessments of our infrastructure
- Secure hosting through Netlify with DDoS protection
While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
11. Children's Privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at reachus@octonsolutions.in and we will delete it promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or through a prominent notice on our website. We encourage you to review this policy periodically.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Octon Solutions — Privacy Inquiries
Vile Parle East, Mumbai, India
Email: reachus@octonsolutions.in
Phone: +91 79000 85116
