Privacy Policy
This explains what we collect, why, who else sees it, and what you can ask us to do about it.
Last updated September 2026 · OptiAI Tech Private Limited
01. Who we are
OptiAI Tech Private Limited is a company incorporated in India under the Companies Act 2013, with its registered office in Pune, Maharashtra. We operate this website and are building Opswake, a product for clinics.
For the personal data described here we are the Data Fiduciary under the Digital Personal Data Protection Act 2023, and the data controller where the UK or EU GDPR applies.
Questions, requests and complaints about personal data go to privacy@optiaitech.com. That mailbox is monitored by a director, who acts as our grievance contact.
02. Who this covers
This policy covers people who contact us through this website, people at organisations we are talking to or working with, and visitors to the site.
Our services are sold to businesses. We do not offer them to consumers for personal, family or household use.
03. What we collect
What you send us. When you use the enquiry form we receive your name, email address, organisation, the area you selected, what you tell us about your situation, and optionally your phone number, timing and indicative budget. If you email or call us instead, we receive whatever you choose to put in that message.
Technical records. Our hosting provider keeps standard server logs, which include IP addresses, timestamps and the pages requested. These exist to run and secure the site.
What we do not collect. This site sets no advertising or analytics cookies, runs no third-party trackers, has no login, and takes no payment. There is nothing here to opt out of, which is why you were not shown a cookie banner.
04. Why we process it, and on what basis
We use what you send us to answer your enquiry, to work out whether we are the right people for the problem, and to carry out and administer any engagement that follows. We use technical records to keep the site working and to investigate abuse.
Under the DPDP Act we rely on your consent, given when you choose to send us an enquiry, and on the legitimate uses the Act permits. You can withdraw consent at any time.
Where the UK or EU GDPR applies we rely on: performance of a contract or steps taken at your request before entering one; our legitimate interests in responding to business enquiries and securing our systems; and compliance with legal obligations.
We do not sell personal data, we do not share it for anyone else’s advertising, and we do not use it to make automated decisions that produce legal or similarly significant effects.
05. Who else processes it
We use a small number of providers, each acting on our instructions under contract:
- Cloudflare — hosting for this website and the function that receives the enquiry form.
- Resend — delivery of the enquiry email to our own inbox.
- Google Workspace — our email, and a spreadsheet in which enquiries are recorded.
We will disclose personal data where the law requires it, or to establish or defend legal claims. If we add or change a provider we will update this list.
06. Where it goes
These providers operate internationally, so personal data you send us may be processed outside India, including in the United States and the European Economic Area.
Where the GDPR applies to a transfer, we rely on the safeguards available to us, such as the European Commission’s Standard Contractual Clauses or an adequacy decision. Under the DPDP Act, transfers are subject to any restrictions the Central Government notifies from time to time.
07. How long we keep it
Enquiries that do not lead to work are kept for up to 24 months so we recognise you if you come back, then deleted.
Records connected to an engagement are kept for the life of that engagement and then for as long as tax, accounting and limitation periods require, which in India is generally eight years.
Server logs are kept for the period our hosting provider retains them, which is short.
If you ask us to erase your data we will do so unless we are required to keep it, and we will tell you if that is the case.
08. Security
The site is served over HTTPS with a strict content security policy. The enquiry endpoint validates what it receives, and the credentials it needs are held as environment variables, not in our code. Access to enquiry records is limited to the directors.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and affected individuals as the DPDP Act requires, and the relevant supervisory authority where the GDPR applies.
09. Personal data inside client projects
When we build or run software for a client, that client’s systems may contain personal data about their own staff, customers or patients. For that data the client is the Data Fiduciary or controller and we act as a Data Processor on their instructions, under the terms of the agreement between us.
This policy does not govern that data. If you are a patient, customer or employee of one of our clients, please contact that organisation.
We ask clients not to send us production personal data for demonstrations or scoping, and we ask that anything shared before an agreement is in place is anonymised or made up.
10. Children
This site and our services are for business use and are not directed at children. We do not knowingly collect personal data of anyone under 18. Under the DPDP Act we do not process a child’s personal data without verifiable parental consent, and we do not track children or target advertising at them — we do not run advertising at all.
11. Your rights
Under the DPDP Act 2023 you may ask us for a summary of the personal data we hold about you and how we process it, ask us to correct, complete, update or erase it, nominate someone to exercise your rights if you die or become incapacitated, and withdraw consent at any time.
Where the UK or EU GDPR applies you additionally have rights of access, rectification, erasure, restriction, portability and objection.
Email privacy@optiaitech.com. We will respond within the period the applicable law allows, and sooner where we can. We may need to confirm who you are before we act.
12. Complaints
If you are not satisfied with how we have handled a request, tell us first at privacy@optiaitech.com so we have a chance to put it right.
In India you may complain to the Data Protection Board of India. In the UK you may complain to the Information Commissioner’s Office, and in the EEA to your local supervisory authority.
13. A note on timing
The DPDP Rules 2025 were notified on 13 November 2025 and phase in over the following eighteen months, with the main obligations on data fiduciaries taking effect on 13 May 2027. We have written this policy to that standard now rather than waiting, and we will update it as the remaining rules and any guidance take effect.
14. Changes
We will update this policy when what we do changes. The date at the top always reflects the current version. Where a change materially affects how we handle personal data we already hold, we will tell affected people directly.
15. Contact
OptiAI Tech Private Limited, Pune, Maharashtra, India.
Privacy: privacy@optiaitech.com
General: hello@optiaitech.com · +91 92725 15054
Something here unclear?
If any of this affects a decision you are about to make, ask us before you rely on it. We would rather answer in writing than have you guess.