1. Introduction
Aptibit Technologies ("Aptibit", "we", "us", or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you:
- Visit our website at aptibit.com and any associated subdomains
- Use our products, including the Visylix AI video intelligence platform
- Engage with our services, including custom AI/ML development, consulting, and software engineering
- Communicate with us via email, contact forms, or other channels
- Subscribe to our newsletter or marketing communications
This policy applies to all individuals who interact with Aptibit Technologies, including website visitors, prospective clients, existing clients, and partners. By using our website or services, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
We collect information in the following categories:
2.1 Personal Information You Provide
When you voluntarily interact with us, we may collect:
- Contact details: Full name, email address, phone number, company name, and job title
- Inquiry information: The content of messages you send through our contact forms, including project requirements and budget range
- Newsletter preferences: Email address and communication preferences when you subscribe to our newsletter via Kit (formerly ConvertKit)
- Feedback and correspondence: Any information you provide when communicating with us directly
2.2 Information Collected Automatically
When you visit our website, we automatically collect:
- Device information: Browser type and version, operating system, device type (desktop/mobile/tablet), and screen resolution
- Usage data: Pages visited, time spent on pages, navigation paths, referring URLs, and exit pages
- Network information: IP address (anonymized where required by law), approximate geographic location (city/country level), and internet service provider
- Performance data: Page load times, errors encountered, and interaction events
2.3 Information from Third Parties
We may receive information about you from third-party services we integrate with, such as Google Analytics and Google Ads (website analytics and advertising measurement), Microsoft Clarity (product analytics), Meta (Facebook/Instagram) advertising tools, HubSpot (customer relationship management), Kit (email marketing), and Chatwoot (live chat). We do not purchase personal data from data brokers or third-party data vendors.
3. How We Use Your Information
We process your personal information for the following purposes and legal bases:
- To respond to inquiries and provide support (Legal basis: Legitimate interest / Contract performance). When you contact us through our website, we use your information to respond to your questions and provide relevant information about our services.
- To deliver our services (Legal basis: Contract performance). When you engage us for AI development, consulting, or other services, we process information necessary to fulfill our obligations.
- To send marketing communications (Legal basis: Consent). With your explicit opt-in consent, we send newsletters, product updates, and promotional content. You can unsubscribe at any time.
- To analyze and improve our website (Legal basis: Legitimate interest). We use analytics data to understand how visitors interact with our website, identify areas for improvement, and optimize the user experience.
- To advertise and measure ad performance (Legal basis: Consent). With your marketing-cookie consent, we run advertising and remarketing and measure conversions, including sending Google a hashed version of your email to attribute an enquiry to an ad. See Section 4.3.
- To ensure security and prevent fraud (Legal basis: Legitimate interest). We monitor for suspicious activity, unauthorized access attempts, and other security threats.
- To comply with legal obligations (Legal basis: Legal obligation). We may process your information to comply with applicable laws, regulations, and legal proceedings.
4. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your experience. In compliance with GDPR and ePrivacy regulations, we use Google Consent Mode v2, which defaults all non-essential cookies to "denied" until you provide explicit consent through our cookie banner.
4.1 Types of Cookies We Use
- Essential cookies: Required for basic website functionality, including session management, security, and cookie preference storage. These cannot be disabled.
- Analytics cookies: Used via Google Analytics (GA4) to understand website usage patterns, measure performance, and generate aggregated statistical reports. These are only activated with your consent.
- Functional cookies: Enable enhanced functionality such as theme preferences (dark/light mode) and previously submitted form data. These are only activated with your consent.
- Marketing cookies: Used to track visitors across websites to display relevant advertisements and measure ad campaign effectiveness. These are only activated with your consent.
4.2 Managing Your Cookie Preferences
You can manage your cookie preferences at any time by:
- Clicking the cookie settings button (shield icon) at the bottom-left of any page
- Adjusting your browser settings to block or delete cookies
- Using browser extensions that manage cookie consent
Please note that disabling certain cookies may affect the functionality of our website.
4.3 Advertising and Conversion Measurement
When you consent to marketing cookies, we use the following advertising features. If you do not consent, none of them run, and no advertising or user-provided data is shared:
- Enhanced Conversions for Leads (Google): When you submit a form, a one-way, irreversibly hashed (SHA-256) version of your email address may be sent to Google to measure whether an ad led to your enquiry. Hashing happens in your browser before transmission; we and Google use the hash only to match a conversion, and it cannot be reversed to recover your email. This runs only with your marketing-cookie consent (Google Consent Mode "ad_user_data").
- Remarketing and personalized advertising: We use Google Ads and Meta (Facebook/Instagram) to show you relevant ads on other sites and platforms based on your visit, and we may share audience signals from Google Analytics with Google Ads for this purpose. You can opt out at any time by rejecting marketing cookies, and via Google's My Ad Center and Meta's ad preferences.
- Conversion measurement: We measure aggregate ad and form-submission performance. Where consent is absent, Google Consent Mode collects only aggregated, non-identifying signals and redacts advertising identifiers.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information in the following limited circumstances:
- Service providers: We share data with trusted third-party providers who assist us in operating our website and delivering our services. These include Google (Analytics, Ads and conversion measurement), Microsoft Clarity (product analytics), Meta (advertising), HubSpot (CRM), Kit (email marketing), Chatwoot (live chat support), and Cloudflare (website hosting, CDN, and form bot protection). All service providers are contractually obligated to protect your data and use it only for the purposes we specify.
- Legal requirements: We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect our rights, property, or safety.
- Business transfers: In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change and the choices you have regarding your information.
- With your consent: We may share your information with third parties when you have given us explicit consent to do so.
6. International Data Transfers
Aptibit Technologies is headquartered in Kolkata, India, and serves clients globally across India, the United States, United Kingdom, United Arab Emirates, Singapore, Australia, Canada, and Germany. Your information may be transferred to and processed in countries other than your country of residence.
When we transfer personal data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA
- Adequacy decisions where applicable
- Binding corporate rules or similar approved transfer mechanisms
- Compliance with India's Digital Personal Data Protection (DPDP) Act, 2023 for data originating in India
7. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
- Contact form submissions: Retained for up to 2 years from the date of submission, or until the related business inquiry is resolved, whichever is longer.
- Newsletter subscriptions: Retained until you unsubscribe. Upon unsubscription, your email is removed from our mailing lists within 30 days.
- Analytics data: Google Analytics data is retained for 14 months, after which it is automatically deleted or anonymized.
- Client project data: Retained for the duration of the business relationship and for up to 5 years after project completion for legal and contractual purposes.
- Cookie data: Cookie consent preferences are stored for 12 months. Analytics cookies expire according to Google's cookie policies.
When your data is no longer required, we securely delete or anonymize it using industry-standard methods.
8. Data Security
We take the security of your personal information seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction. Our security measures include:
Technical Measures
- HTTPS encryption (TLS 1.3) for all data in transit
- Strict Content Security Policy (CSP) headers to prevent cross-site scripting
- HTTP Strict Transport Security (HSTS) with preloading
- Cross-Origin-Opener-Policy (COOP) for browsing context isolation
- Regular security audits and vulnerability assessments
- Access controls and authentication for all internal systems
Organizational Measures
- Employee training on data protection and privacy best practices
- Data access limited to authorized personnel on a need-to-know basis
- Incident response procedures for data breaches
- Regular review and update of security policies
While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to improve our security posture.
Breach notification: In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected individuals without undue delay and within the timelines required by applicable law (for example, within 72 hours under the GDPR, and as prescribed under India's DPDP Act, 2023).
9. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal data:
9.1 Rights Under GDPR (EU/EEA/UK)
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Request correction of inaccurate or incomplete data
- Right to erasure: Request deletion of your personal data ("right to be forgotten")
- Right to restrict processing: Request limitation of how we process your data
- Right to data portability: Request a copy of your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: Withdraw previously given consent at any time
9.2 Rights Under India's DPDP Act
- Right to access information about your personal data being processed
- Right to correction and erasure of personal data
- Right to grievance redressal
- Right to nominate a representative to exercise your rights
9.3 Rights Under US State Privacy Laws
If you are a resident of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), or another US state with a comprehensive privacy law, you have the right to:
- Know and access the personal information we collect, use, and disclose
- Delete and correct your personal information
- Opt out of the "sale" or "sharing" of personal information and of targeted (cross-context behavioral) advertising and profiling
- Appeal a decision we make on your privacy request (Virginia, Colorado, Connecticut and others)
- Non-discrimination for exercising your privacy rights
We do not sell your personal information for money. However, when you consent to marketing cookies, our use of advertising and remarketing tools may constitute "sharing" or "targeted advertising" under some US state laws.
9.4 Your Privacy Choices — Do Not Sell or Share My Personal Information
You can opt out of any "sale" or "sharing" and of targeted advertising at any time:
- Reject marketing cookies using the cookie settings control (shield icon) at the bottom-left of any page.
- Enable a Global Privacy Control (GPC) signal in your browser or extension — we automatically detect and honor GPC as a valid opt-out of sale and sharing.
- Email info@aptibit.com for any other request. We will not discriminate against you for exercising these rights.
9.5 Rights in Other Jurisdictions
We extend equivalent rights to individuals wherever they live. Depending on your location you may also have rights under, among others:
- UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021)
- Singapore Personal Data Protection Act (PDPA)
- Australia Privacy Act 1988 and the Australian Privacy Principles
- Canada PIPEDA (and Quebec Law 25) and, for electronic marketing, CASL
- Brazil Lei Geral de Proteção de Dados (LGPD)
- UK GDPR and the Data Protection Act 2018
To exercise any of these rights, please contact us at info@aptibit.com. We will respond to your request within 30 days (or sooner if required by applicable law). We may ask you to verify your identity before processing your request.
10. Children's Privacy
Our website and services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have inadvertently collected personal data from a child under 18, we will take steps to delete such information as promptly as possible. If you believe that a child has provided us with personal information, please contact us immediately at info@aptibit.com.
Consistent with India's DPDP Act 2023, we do not knowingly track, profile, or build advertising audiences from individuals we know to be children, and we do not direct targeted advertising at children. Our advertising and remarketing partners (Google and Meta) apply their own restrictions on advertising to users under 18. As a business-to-business service, our site is intended for professional and organizational users.
11. Third-Party Links and Services
Our website may contain links to third-party websites, products, or services that are not owned or controlled by Aptibit Technologies. We are not responsible for the privacy practices, content, or security of these third-party sites.
We currently use the following third-party services:
- Google Analytics (GA4): Website analytics and usage tracking (analytics consent)
- Google Ads: Advertising, remarketing, and conversion measurement incl. Enhanced Conversions (marketing consent)
- Meta Pixel: Facebook/Instagram advertising and conversion measurement (marketing consent)
- Microsoft Clarity: Product analytics, heatmaps, and session replay of page interactions (analytics consent)
- HubSpot: Customer relationship management; stores contact-form submissions to manage your enquiry (form submission), plus optional analytics (marketing consent)
- Ahrefs Analytics: Privacy-friendly, cookieless website analytics (no cookies, no personal data stored)
- Cloudflare: Website hosting, CDN, DNS, and bot/spam protection on our forms (Turnstile) (essential/security)
- Kit (ConvertKit): Email newsletter management
- Chatwoot: Live chat and customer support
We encourage you to review the privacy policies of any third-party services before providing them with your personal information.
12. AI and Machine Learning Data Practices
As an AI company, we want to be transparent about how we handle data in relation to our AI and machine learning technologies:
- Website visitor data: We do not use personal data collected from website visitors to train any AI models or machine learning systems.
- Visylix platform: The Visylix video intelligence platform processes video data on behalf of our clients. Data processed by Visylix belongs to the respective client and is governed by separate data processing agreements. Aptibit does not access, retain, or use client video data for any purpose other than providing the contracted service.
- Custom AI development: When we build custom AI/ML solutions for clients, all training data and models belong to the client unless otherwise specified in the service agreement. We maintain strict data isolation between client projects.
- AI model development: Our proprietary AI models are trained using publicly available datasets, licensed datasets, and synthetic data. We do not use customer data or website visitor data to train our commercial AI models.
12.1 Automated Decision-Making and AI Transparency
Where we deploy an AI system that interacts directly with you (for example, an AI chat assistant), we will make clear that you are interacting with AI, consistent with the EU AI Act. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing without human involvement. Where automated processing is used to support a decision, you may request human review, express your point of view, and contest the outcome. Our AI video analytics capabilities (including biometric features such as facial recognition) are configured and operated by our customers on their own infrastructure; those customers act as the controller and are responsible for lawful use, transparency to affected individuals, and any required consents.
13. Do Not Track Signals
Some web browsers transmit "Do Not Track" (DNT) signals to websites. Our website respects your privacy preferences. When analytics cookies are not consented to via our cookie banner, no tracking occurs regardless of DNT signals. We recommend using our cookie consent mechanism as the primary way to manage your tracking preferences on our website.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes that materially affect your rights, we will make reasonable efforts to provide notice, such as displaying a prominent notification on our website or sending an email to registered users. We encourage you to review this policy periodically to stay informed about how we protect your information.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Aptibit Technologies Private Limited
CIN: U46510WB2024PTC275420
Grievance Officer: Mr. Falguni Chatterjee (Chief Executive Officer)
Email: info@aptibit.com
Registered office: Eco Space Business Park Premises, Block 4A, 3rd Floor, New Town Action Area II, Rajarhat, Kolkata, West Bengal 700156, India
Website: aptibit.com
We aim to respond to all privacy-related inquiries within 30 days. For urgent matters involving potential data breaches, please include "URGENT: Privacy" in your email subject line.
If you are located in India and are not satisfied with our response, you have the right to register a complaint with the Data Protection Board of India under the Digital Personal Data Protection Act, 2023. This notice is available in English; a version in any language listed in the Eighth Schedule to the Constitution of India can be provided on request to the email above.
This Privacy Policy has been drafted to comply with the General Data Protection Regulation (GDPR), India's Digital Personal Data Protection (DPDP) Act 2023, the California Consumer Privacy Act (CCPA), and other applicable data protection laws. If any provision of this policy conflicts with applicable local law, the local law shall prevail to the extent of the conflict.