Back to Agentic AI Tech Solutions
Data governance

Privacy Policy

This policy explains how personal data is handled across our public website and authorized internal application.

Last updated 14 August 2026

Who we are and the scope of this policy

Agentic AI Tech Solutions LLP, based in Visakhapatnam, Andhra Pradesh, India, controls the purposes described in this policy. It applies to personal data handled through our public website, enquiries, customer and applicant interactions, and the authorized internal application used by staff.

We interpret this policy in line with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and applicable rules as provisions become applicable. This statement describes our practices; it is not a claim of blanket certification under every privacy regime.

Personal data we collect

Depending on how you interact with us, we may collect identifiers and contact details, account and role information, enquiry content, operational records, submitted documents, technical security records, and consent-gated product usage events. The people covered can include public visitors, leads, customers, applicants, and authorized staff.

We aim to collect data that is relevant to the stated purpose. The exact fields vary by workflow and the information a person chooses or is authorized to provide.

How and why we use personal data

We use personal data to respond to requests, provide and secure services, administer authorized accounts, operate agreed business workflows, maintain records, support customers and staff, improve product reliability, meet contractual or legal obligations, and establish or defend claims.

The basis for processing depends on the context and may include a requested service or contract, a legal obligation, consent, or a legitimate operational or security need considered against the person's interests and applicable law.

Public enquiries and lead forms

Public forms may collect a name, work email, organization, other contact details, and the enquiry content submitted to us. We use that information to evaluate and reply to the request, keep an appropriate business record, and arrange follow-up where requested.

Accounts and authentication

Authorized accounts may contain identity, role, reporting line, and authentication/session records. Supabase Auth supports authentication and session management. Essential cookies or browser storage may maintain authentication, security, and continuity state needed for the service to function.

Authorized staff operations and management information

Internal operations may contain worklogs, attendance, tasks, reviews, leave, training, expenses, approvals, and related management information (MI). Access is limited by authorized work responsibilities and used to run operations, support people processes, review delivery, and produce appropriate organizational reports.

Employee MI and performance reporting are separate from product analytics. They are not combined into an opaque surveillance score, and non-essential product analytics consent is not used as a basis for staff evaluation.

Expenses, receipts and document processing

Expense workflows may contain receipts and related expense details. When receipt OCR is enabled, a private document may be sent to Google Document AI to extract proposed fields. A person must verify extracted fields before relying on them, and details can be entered manually when OCR is unavailable or unsuitable.

Templates, files and private storage

Supabase provides our database and private Storage for authorized application data and files. Access controls are intended to prevent public access to private objects. Google Sheets synchronization occurs only through authorized workflows configured for an approved operational purpose.

Product analytics, cookies and similar storage

Non-essential product analytics is captured only after consent has been granted. Product events use allowlisted, pseudonymous identifiers and exclude free text, receipt contents, and employee MI or performance reporting. These product events target deletion after 90 days.

Essential cookies or similar browser storage can still be used without optional analytics to maintain authentication, prevent abuse, and preserve security state. Consent can be withdrawn for future non-essential collection.

Service providers and international processing

We use service providers where needed to deliver and protect the service. Supabase supports authentication, database, and private object storage; Google Document AI supports optional receipt extraction; and Google Sheets supports explicitly authorized synchronization. Operational monitoring may process technical events and diagnostics needed to detect failures and security issues.

A provider may process data in locations determined by its service configuration and infrastructure. Where cross-border processing occurs, we assess the workflow and use contractual, access, and configuration measures appropriate to the data and applicable requirements. We do not promise universal data residency.

Retention, backups and deletion

We retain personal data only as needed for the stated purpose and for applicable contractual or legal obligations, disputes, security, and recovery. Retention varies by record type and context. Product analytics events have a 90-day deletion target; that target does not automatically apply to records required for a different stated purpose.

Live records approved for deletion are removed or made inaccessible through the relevant workflow. Copies in encrypted backups may remain until they leave the protected backup rotation, so backup deletion can take longer than deletion from live systems. Backups are intended for recovery rather than routine access.

Security

We use reasonable technical and organizational controls intended to reduce risk, including access restrictions, private storage, encryption available in the service stack, operational monitoring, and recovery processes. No system or transmission is risk-free, and these measures cannot guarantee absolute security.

Your rights, consent withdrawal and grievances

Subject to applicable law and the context of the processing, you may request access, correction, completion, or deletion of personal data, withdraw consent for future consent-based processing, or raise a grievance. Email us at privacy@agenticaisolutions.tech. We may verify identity before acting and may retain data where a lawful obligation or permitted need applies.

We respond within timelines required by applicable law. Identity verification, request complexity, or legal constraints may affect how a request is handled; where appropriate, we will explain its status.

Children's privacy

Our services are not directed to children, and we do not knowingly seek children's personal data through the public site. If you believe a child has provided personal data to us, contact us so we can assess and address it appropriately.

Changes to this policy

We may update this policy when our services, providers, or legal requirements change. The current version will show its last-updated date. Material changes may also be communicated through an appropriate service or business channel.