Privacy Policy
We collect only what's necessary, use it only for delivering our services, and never sell your data โ ever. This policy explains everything clearly, including how we handle data in an AI-powered world.
(Hosting, Payments)
(If required by law)
Advertisers
or Resellers
Information We Collect
We collect only the minimum information needed to deliver our services, process your payments, and communicate with you. Nothing more.
Name, email address, phone number, billing details, company name, and job title provided when you contact us, place an order, or create an account.
IP address, browser type, device details, operating system, referring URLs, and usage behaviour when you visit our website โ collected automatically via analytics tools.
Content, media files, brand assets, access credentials, and project documentation shared by clients during web development, app development, or digital marketing engagements.
Emails, support tickets, WhatsApp messages, and call records maintained for project management, support, and service continuity purposes.
Invoice details, transaction references, and payment status. Full card or bank details are processed by our secure payment partners โ we do not store raw payment credentials.
Where AI-powered features are used in service delivery, interaction logs may be retained temporarily for quality review. Client project data is never shared with public AI training datasets.
Minimum Necessary: We apply a data minimisation principle โ we collect only what is genuinely required to fulfil our service obligations and legal duties. We do not engage in unnecessary data collection.
How We Use Your Information
Your information is used only for the purposes for which it was collected. We never use client data for unrelated commercial activities.
Service Delivery: To build, launch, and manage websites, mobile applications, hosting environments, cloud infrastructure, and digital marketing campaigns on your behalf.
Payments & Invoicing: To process payments, generate invoices, track billing cycles, and manage subscription renewals for hosting, cloud, and retainer services.
Communication: To send project updates, milestone notifications, renewal reminders, technical support responses, and essential service alerts.
Service Improvement: To analyse website usage patterns, identify technical issues, improve user experience, and enhance the performance of our platforms and delivery processes.
AI-Assisted Operations: Where AI tools are used internally (e.g., code assistance, content drafting), they operate on commercially licensed platforms with strict data isolation โ your project data is not used to train any AI model.
Legal & Compliance: To comply with applicable Indian laws, tax regulations, contractual obligations, and to protect Royal IT Park's legal rights where necessary.
Marketing (Opt-In Only): With your explicit consent, to send newsletters, product updates, or promotional offers. You can opt out at any time from any marketing email.
AI Use Transparency: Artificial intelligence tools are used internally to improve development speed and quality. All AI-processed outputs are reviewed by humans. Client data is never exposed to public-facing AI systems or used as training input.
Data Security
We implement layered, industry-standard security practices to protect your personal and project data from unauthorised access, misuse, alteration, or disclosure.
Encryption in Transit: All data transmitted between you and our systems is encrypted using TLS/SSL protocols. Our website and client portals are HTTPS-secured.
Secure Storage: Personal and project data is stored on access-controlled servers hosted by enterprise-grade cloud providers (AWS, Azure). Access is restricted to authorised personnel only.
Access Controls: Internal access to client data is governed by role-based permissions. Employees access only the information required to fulfil their specific responsibilities.
Regular Backups: Client project data and hosting environments are backed up regularly using Acronis Cloud Backup or equivalent enterprise solutions to prevent data loss.
AI Security: AI tools used in our workflows are enterprise-licensed solutions with contractual data-privacy agreements that prohibit the use of our inputs for model training or sharing with other customers.
No Absolute Guarantee: While we take strong precautions, no data transmission over the internet or storage system is 100% impenetrable. Clients are advised to maintain independent secure backups of critical data.
Incident Response: In the unlikely event of a data breach that affects your information, Royal IT Park will notify affected clients as soon as practicable and take immediate steps to contain the incident.
Sharing & Disclosure
We operate on a strict no-sale, no-rent policy for personal data. The only circumstances under which data is shared are listed below โ all of which serve your service delivery or legal requirements.
We do not sell, rent, lease, or trade your personal information to any third party, advertiser, data broker, or marketing network โ ever.
Trusted Service Partners: Data may be shared with vetted third-party vendors who assist in delivering our services โ including hosting providers (AWS, Azure), payment gateways, email platforms, and IT infrastructure partners โ all bound by confidentiality agreements.
Legal Authorities: We may disclose information to government bodies, law enforcement, or courts where required by applicable Indian law, court order, or to protect the legal rights and safety of Royal IT Park and its clients.
AI Platform Providers: Commercially licensed AI tools used internally operate under data-processing agreements that explicitly prohibit sharing client inputs with other organisations or using them for training AI models.
Business Transfers: In the event of a merger, acquisition, or asset transfer, client data may be transferred to the successor entity. Clients will be notified of such changes in advance wherever possible.
Your Assurance: Every third-party partner who handles client data on our behalf is contractually obligated to maintain confidentiality, use data only for the specified purpose, and uphold security standards consistent with our own.
Data Retention
We retain personal information only for as long as necessary to deliver our services and meet legal obligations. We do not hold data indefinitely.
Active Client Data: Personal and project data is retained throughout the duration of your engagement with Royal IT Park and for a reasonable period after service completion to handle warranty claims, disputes, or renewal requests.
Financial Records: Billing information, invoices, and payment records are retained for a minimum of 7 years in compliance with Indian tax and accounting regulations (Income Tax Act, GST requirements).
Communication Logs: Support tickets, email correspondence, and project communications are retained for up to 3 years post-project for dispute resolution and quality reference purposes.
AI Interaction Logs: Any temporary logs generated through AI-assisted workflows are automatically purged within 30 days and are never archived for long-term storage or analytical mining.
Deletion on Request: Clients may request deletion of their personal data after service completion. Deletion will be completed within 30 business days, subject to our legal retention obligations which may prevent deletion of certain records.
Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience, measure site performance, and understand how visitors engage with our content.
Required for core website functionality โ session management, security, and navigation. These cannot be disabled without breaking the site.
Used to collect aggregated, anonymised data on how visitors use our site โ pages visited, time spent, and traffic sources โ via tools like Google Analytics.
Remember your settings and preferences (e.g., language, region) to personalise your experience across return visits.
Used to track engagement with our marketing content on platforms like Google and Meta. Only activated with your consent via our cookie banner.
You can manage or disable cookies at any time through your browser settings or via our Cookie Consent Manager. Disabling non-essential cookies will not affect your ability to access our core services.
For full details on the specific cookies we use, their purpose, and duration, please refer to our dedicated Cookie Policy.
AI Technologies & Your Data
Royal IT Park uses artificial intelligence tools to enhance service quality and delivery speed. This section explains exactly how AI interacts with your data and what protections are in place.
AI Tools We Use: We use commercially licensed AI tools including AI code assistants, language model APIs, generative design aids, and automated testing frameworks โ all through enterprise-tier subscriptions with strict data privacy contracts.
No Training on Your Data: Your client data, project files, communications, and personal information are never used to train, fine-tune, or improve any AI model โ public or private. This is contractually enforced with all AI platform providers we use.
Human Review: All AI-generated outputs โ including code, content, and designs โ are reviewed and validated by qualified members of our human team before delivery to clients. AI augments our team; it does not replace expert oversight.
Data Isolation: AI tools are used in isolated, session-specific contexts. Client data entered for one task is not carried over to other clients' sessions or retained beyond the immediate operational need.
AI-Free Option: Clients who require a guarantee that no AI tools will be used in any part of their project delivery may request this explicitly in writing. Standard pricing and timelines may differ for fully human-only delivery pipelines.
Transparency on Request: Clients may enquire at any time which AI tools were used in their project and how their data was handled. We will respond clearly and honestly to such requests within 5 business days.
Our AI Commitment: We believe in responsible AI use. Your data belongs to you โ not to any AI company. We use AI as a tool to serve you better, with full transparency, human accountability, and zero compromise on your privacy.
Client Responsibilities
When Royal IT Park builds digital products that process personal data on your behalf โ such as ecommerce stores, CRM systems, or mobile apps โ additional responsibilities apply to you as the data controller.
Clients are responsible for ensuring that all content, images, data, and third-party assets provided to Royal IT Park are lawful and do not infringe on the intellectual property or privacy rights of any individual or organisation.
If your project involves collecting personal data from your own customers (e.g., via an ecommerce platform, booking app, or CRM), you are the data controller for that data and are solely responsible for compliance with applicable data protection laws.
Clients operating products accessible to users in the European Union must independently ensure compliance with GDPR. Clients in India must comply with the IT Act 2000 and the Digital Personal Data Protection Act 2023 (DPDPA).
If Royal IT Park integrates AI-powered features (chatbots, recommendation engines, etc.) into your product, you are responsible for the ethical and lawful use of those features in your live product environment.
Clients must maintain their own privacy policy and data processing notices for end-users of digital products built by Royal IT Park. We can provide guidance on structure, but legal responsibility lies with the client.
Third-Party Links & Integrations
Our website and the digital products we build for clients may contain links to, or integrate with, third-party platforms. This section clarifies our responsibility boundaries.
Our website may contain links to external websites, social media platforms, and partner services. Royal IT Park is not responsible for the privacy practices, data handling, or content of any third-party website.
Client projects may integrate with third-party APIs and platforms such as payment gateways (Razorpay, PayU), social login providers (Google, Facebook), mapping services, or communication tools. Each such platform's own privacy policy governs data shared with them.
Cloud and SaaS services used in delivering your project โ including AWS, Microsoft Azure, Google Workspace, Microsoft 365 โ are governed by their own enterprise data protection agreements and are GDPR / SOC 2 compliant.
We recommend clients review the privacy policies of any third-party service integrated into their product before going live, particularly if those services receive personal data from end-users.
Your Privacy Rights
You have clear rights over the personal data we hold about you. Royal IT Park is committed to honouring these rights promptly and transparently.
Request a copy of all personal data we hold about you at any time.
Request correction of inaccurate or outdated personal information we hold.
Request deletion of your personal data, subject to legal retention obligations.
Request that we limit how we process your data in certain circumstances.
Request your data in a structured, machine-readable format for transfer.
Unsubscribe from marketing emails at any time via the link in any email.
How to Exercise Your Rights: Email us at support@royalitpark.com with the subject line "Privacy Rights Request". We will acknowledge your request within 3 business days and fulfil it within 30 business days.
Policy Updates
The digital landscape โ and the regulations governing it โ evolves continuously. We update this Privacy Policy to reflect changes in our business, technology, and legal obligations.
This Privacy Policy is reviewed and updated at least annually and whenever significant changes occur in our services, technology stack, or applicable regulations โ including new AI laws and data protection updates.
Material changes will be communicated to active clients via email notification or a prominent notice on our website prior to the changes taking effect, giving you time to review the updated policy.
The "Last Updated" date at the top of this policy reflects the most recent revision. Continued use of our services after an update constitutes acceptance of the revised policy.
Policy updates related to AI technologies and data handling will be clearly flagged so clients can quickly identify what has changed in this rapidly evolving area.
Stay Informed: We recommend bookmarking this page and checking it periodically. If you have questions about any update, contact us before continuing to use our services.
Questions About Your Privacy?
Whether you want to exercise your data rights, report a concern, or simply ask how we handle a specific type of data โ our team will respond clearly and promptly.