Review preview · not the live site · forms do not send

Legal

Privacy Policy

Draft for review by INK's legal team. Not legal advice. Approve or amend before launch. Highlighted items need INK's facts.

This policy explains what personal data INK Business Solutions collects through this website, why, how long we keep it, who we share it with, and the rights you have. It covers this website only. Our Cookie Policy explains cookies in detail.

Version: 2026-10 (draft) · Last updated: date of approval

In short

  • We collect only what you type into our forms, and analytics data only if you agree to it.
  • We use your data to answer your request. We do not sell it, and we do not use it for advertising.
  • Your form data is kept in INK’s own business email and Microsoft 365 environment, protected by our ISO 27001 information security management system.
  • You can ask to see, correct or delete your data, or withdraw consent, at any time.

Who is responsible for your data

INK Business Solutions is the controller (in India, the “data fiduciary”) for personal data collected through this website. Legal entity name, registered address and, if appointed, Data Protection Officer contact.

INK has teams in India, the United Arab Emirates, Saudi Arabia, Egypt and the United States. The INK company that handles your request may also be responsible for your data together with the entity above.

What we collect

Information you give us through our enquiry forms (Book a Consultation, Process Discovery Workshop, AI Readiness Assessment, Partner With Us, Submit a Requirement):

  • name, company, country, work email address and mobile number;
  • the topic you choose and the message you write, including any requirement details;
  • the page you sent the form from.

Please do not include sensitive personal data (for example health or financial details) in your message.

Email verification. To confirm that a work email address is yours, we email you a 6-digit code. The code is valid for 10 minutes and is stored only as a keyed hash (a coded value that cannot be turned back into the code), and it is deleted once used. To stop abuse, we limit how many codes can be requested per email address and per network address each hour, using hashed values, not readable addresses.

Analytics, only with your consent. If you accept analytics, Google Analytics and Microsoft Clarity record how the site is used: pages viewed, clicks and scrolling, approximate location, device and browser type. Clarity can record anonymised session replays and is set to mask what you type into forms. See the Cookie Policy.

Technical data. When any website is visited, the hosting service processes your IP address and browser details to deliver pages securely and protect against attacks.

What we do not collect through this website: payment details, CVs or job applications (our careers portal is a separate service with its own privacy notice), or data from children. The “Ask IBS” assistant runs in your browser and does not store or send your questions; if you choose to send a question to a consultant, it goes through the enquiry form.

Purpose Data Legal basis
Reply to your enquiry, prepare a proposal or arrange a call Form data Steps you ask us to take before a contract; our legitimate interest in answering business enquiries; in India and where required elsewhere, your consent given by submitting the form
Confirm your work email and prevent spam and abuse Email, hashed code, hashed network address Legitimate interest in keeping the site secure
Send you a confirmation that we received your message Name, email Steps you ask us to take
Understand and improve the website Analytics data Your consent (you can withdraw it at any time)
Meet legal obligations and defend legal claims Records as needed Legal obligation; legitimate interest

We do not use your data for automated decisions that have legal or similarly significant effects on you, and we do not send marketing emails from this website.

Who we share it with

  • INK teams who handle your request, in the countries listed above.
  • Service providers acting on our instructions: Microsoft (Microsoft 365 email and SharePoint, Azure hosting and storage, Clarity), and Google (Gmail, where INK receives a copy of each form notification, and Analytics, only with your consent).
  • Authorities, only where the law requires it.

We do not sell or rent personal data.

Where it is stored, and international transfers

Form data is stored in INK’s own Microsoft 365 environment (SharePoint lists and business email), a copy of each form notification is delivered to INK’s Gmail inbox, and email verification data is kept in INK’s Azure storage. Microsoft 365 and Azure data region.

Because INK works across several countries, and because Google and Microsoft may process analytics data in other countries (including the United States), your data may be transferred outside the country where you live. When this happens we use the safeguards the law requires, such as the providers’ data-processing terms and standard contractual clauses, and, for data from Saudi Arabia, the transfer conditions of the PDPL and its regulations.

How long we keep it

Data How long
Enquiries and messages for example 24 months after our last contact with you, unless we start working together (then as long as our contract and the law require)
Email verification codes 10 minutes; deleted when used
Abuse-prevention counters One hour (hashed values only)
Analytics data Google Analytics retention setting (2 or 14 months); Clarity as set by Microsoft
Your cookie choice 12 months in your browser

How we protect it

INK operates an information security management system certified to ISO 27001. Data is encrypted in transit (HTTPS), access is limited to the people who need it, and our forms check your email address and mobile number to reduce fraud and errors. No system is completely secure, but if a breach affects your data we will notify you and the authorities as the law requires.

Your rights

Depending on where you live, you can:

  • access the personal data we hold about you and get a copy;
  • correct data that is wrong or incomplete;
  • delete your data, or restrict or object to how we use it;
  • withdraw consent at any time (for analytics, use “Cookie settings” in the footer);
  • receive your data in a portable format, where the law gives this right;
  • in India, nominate someone to exercise your rights if you cannot, and use our grievance process;
  • complain to your data protection authority (see below).

To use any of these rights, contact us (details below). We may need to confirm your identity. We will reply within the time your local law requires, and we will not treat you differently for using your rights.

Where you are Main law Where you can complain
European Economic Area, UK, Switzerland GDPR / UK GDPR / Swiss FADP Your national data protection authority (in the UK, the ICO)
Saudi Arabia Personal Data Protection Law (PDPL) Saudi Data and AI Authority (SDAIA)
United Arab Emirates Federal Decree-Law No. 45 of 2021; DIFC and ADGM data protection laws where they apply UAE Data Office, or the DIFC or ADGM commissioner
India Digital Personal Data Protection Act 2023 and Rules 2025 Our grievance officer first, then the Data Protection Board of India
Egypt Personal Data Protection Law No. 151 of 2020 Personal Data Protection Center
United States Applicable state privacy laws Your state attorney general where applicable

Children

This website is for businesses and professionals. It is not intended for anyone under 18, and we do not knowingly collect their data.

Changes to this policy

We will update this page when our practices change, and change the version and date above. If a change affects how we use data you have already given us, we will tell you before it applies.

Contact us

Privacy questions and requests: privacy email address. Grievance officer (India): name and contact. You can also write to us through our contact page.

Not sure where to start?

Spend one day with us mapping a single process. You keep the map, whatever you decide next.