Privacy Policy.
How we handle personal data on this website. Short version: no cookies, no forms, no login, no tracking, no ad tech — cookieless analytics and server logs, and whatever you choose to put in an email to us.
This Site sets no cookies, has no forms and no login, and uses cookieless analytics that do not track you across sites. We do not sell or share personal data and we do not use anything from this Site to train AI models. Where we process personal data on a customer’s behalf inside our products, that is covered by our Data Protection Addendum instead.
01Who we are
SandLogic Technologies Private Limited (“SandLogic”, “we”, “us”) operates the website sandlogic.com (the “Site”). Our registered office is at 2nd Floor, Garuda BHIVE, BMTC Complex, Old Madiwala, Kuvempu Nagar, Stage 2, BTM Layout, Bengaluru, Karnataka 560068, India.
For the purposes of the Digital Personal Data Protection Act, 2023 (India) we are the Data Fiduciary for personal data processed through the Site. For the purposes of the EU GDPR and UK GDPR, where those laws apply, we are the Controller.
This policy covers the Site only. Where SandLogic processes personal data on a customer’s behalf as part of delivering a product or service, we act as a Processor and that processing is governed by the customer’s agreement with us and our Data Protection Addendum — not by this policy.
02What this Site collects — the short version
Very little, by design. The Site has no user accounts, no login, and no contact forms. We do not set cookies of our own, and we do not use advertising, retargeting, cross-site tracking, or session-recording tools. We do not sell or share personal data, and we do not use any data from the Site to train AI models.
| What | Why | Basis |
|---|---|---|
| Aggregated, cookieless page analytics | Understand which pages are useful | Legitimate interests / legitimate use |
| Page performance measurements | Keep the Site fast and available | Legitimate interests / legitimate use |
| Server and security logs, incl. IP address | Serve pages, prevent abuse | Legitimate interests / legal obligation |
| Anything you put in an email to us | To answer you | Consent / steps prior to a contract |
03Analytics and performance measurement
We use Vercel Web Analytics and Vercel Speed Insights, provided by Vercel Inc. These are cookieless: they set no cookies, use no persistent device identifier, and do not track you across other websites.
They record aggregated events such as the page visited, referrer, approximate country-level location, and coarse device and browser type, together with performance timings. Where an identifier is needed to distinguish one visit from another, it is derived as a hash and is not retained in a form that lets us identify you or recognise you on a later visit.
We use the result to see which pages are read and where the Site is slow. We do not build profiles, and there is no automated decision-making producing legal or similarly significant effects.
04Hosting, logs, and security data
The Site is hosted by Vercel Inc. on its global edge network. As with any web host, Vercel processes technical data necessary to deliver pages, including your IP address, request headers, user agent, and timestamps, and retains short-term operational and security logs.
We use this only to operate the Site, investigate faults, and detect and prevent abuse such as scraping at a volume that degrades service, or attempted intrusion.
Fonts are served from Google Fonts. We load them through Next.js font optimisation, which serves the font files from our own domain rather than calling Google at page load, so visiting the Site does not disclose your IP address to Google for this purpose.
05If you email us
Every contact route on the Site is a plain mailto: link — your own mail client sends the message. We receive whatever you choose to put in it: typically your name, email address, employer, and the substance of your enquiry.
We use that to respond, and to maintain a record of the correspondence. Business email is hosted on Microsoft 365. Where an enquiry becomes a commercial discussion, the correspondence may be retained as a business record.
Please do not send us sensitive personal data — health information, biometric data, financial account details, government identifiers, or special-category data — by email. We do not need it to answer a product enquiry.
06Who we share data with
We do not sell personal data, and we do not share it for advertising. We disclose it only to:
- Vercel Inc. — website hosting, analytics, and performance measurement;
- Microsoft Corporation (Microsoft 365) — business email;
- professional advisers (legal, accounting) where necessary and subject to confidentiality;
- a competent authority, where we are required to disclose by law, court order, or binding regulatory request.
Each provider acts on our instructions under a written data processing agreement. A current list of the sub-processors used in delivering our products and services (as distinct from this website) is maintained in Annex 2 of our Data Protection Addendum.
07International transfers
We are based in India and our providers operate globally, so personal data may be processed outside your country. Where personal data protected by the EU or UK GDPR is transferred outside the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the safeguards our providers maintain. Under the DPDP Act 2023, transfers out of India are permitted except to territories restricted by the Central Government, and we comply with any such restriction in force.
08How long we keep it
- Analytics and performance data — retained in aggregated form by our analytics provider on a rolling basis, typically no longer than 12 months.
- Server and security logs — short-term, typically no longer than 30 days, unless retained longer to investigate a specific security incident.
- Email correspondence — for as long as needed to deal with the matter and then as a business record, subject to any longer period required by Indian tax, company, or limitation law.
09Your rights
Under the DPDP Act 2023 (India), as a Data Principal you have the right to access a summary of your personal data and our processing of it; to correction, completion, updating, and erasure; to grievance redressal; and to nominate another individual to exercise your rights in the event of death or incapacity.
Under the EU / UK GDPR, where it applies, you additionally have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
To exercise any of these, email the contact in section 11. We will respond within 30 days. We may need to ask for enough information to confirm who you are. There is no charge unless a request is manifestly unfounded or excessive.
Because the Site sets no cookies and has no login, we typically hold no data that identifies an individual visitor — so for most requests about Site usage the accurate answer will be that there is nothing to retrieve or erase.
10Children's data
The Site is directed at business and professional audiences and is not intended for children. We do not knowingly collect personal data of children. Under the DPDP Act 2023, processing the personal data of a child (under 18 in India) requires verifiable parental consent, and we do not carry out any processing that would rely on it. If you believe a child has provided us personal data, contact us and we will delete it.
11Contact, Data Protection Officer, and complaints
For any privacy question, to exercise your rights, or to raise a grievance:
Data Protection Officer
SandLogic Technologies Private Limited
2nd Floor, Garuda BHIVE, BMTC Complex, Old Madiwala, Kuvempu Nagar, Stage 2, BTM Layout, Bengaluru, Karnataka 560068, India
Email: info@sandlogic.com
If you are not satisfied with our response, you may complain to the Data Protection Board of India established under the DPDP Act 2023. If you are in the EEA or UK, you may instead complain to your local supervisory authority or the UK Information Commissioner’s Office.
12Changes to this policy
We may update this policy as the Site or the law changes. The “last updated” date above reflects the current version. Where a change materially affects how we handle personal data, we will make that clear on this page.
See also our Terms of Use, Data Protection Addendum, and Trust & Compliance.