Draft for review by INK's legal team. Not legal advice. Approve or amend before launch. Highlighted items need INK's facts.
This policy explains what personal data INK Business Solutions collects through this website, why, how long we keep it, who we share it with, and the rights you have. It covers this website only. Our Cookie Policy explains cookies in detail.
Version: 2026-10 (draft) · Last updated: date of approval
In short
- We collect only what you type into our forms, and analytics data only if you agree to it.
- We use your data to answer your request. We do not sell it, and we do not use it for advertising.
- Your form data is kept in INK’s own business email and Microsoft 365 environment, protected by our ISO 27001 information security management system.
- You can ask to see, correct or delete your data, or withdraw consent, at any time.
Who is responsible for your data
INK Business Solutions is the controller (in India, the “data fiduciary”) for personal data collected through this website. Legal entity name, registered address and, if appointed, Data Protection Officer contact.
INK has teams in India, the United Arab Emirates, Saudi Arabia, Egypt and the United States. The INK company that handles your request may also be responsible for your data together with the entity above.
What we collect
Information you give us through our enquiry forms (Book a Consultation, Process Discovery Workshop, AI Readiness Assessment, Partner With Us, Submit a Requirement):
- name, company, country, work email address and mobile number;
- the topic you choose and the message you write, including any requirement details;
- the page you sent the form from.
Please do not include sensitive personal data (for example health or financial details) in your message.
Email verification. To confirm that a work email address is yours, we email you a 6-digit code. The code is valid for 10 minutes and is stored only as a keyed hash (a coded value that cannot be turned back into the code), and it is deleted once used. To stop abuse, we limit how many codes can be requested per email address and per network address each hour, using hashed values, not readable addresses.
Analytics, only with your consent. If you accept analytics, Google Analytics and Microsoft Clarity record how the site is used: pages viewed, clicks and scrolling, approximate location, device and browser type. Clarity can record anonymised session replays and is set to mask what you type into forms. See the Cookie Policy.
Technical data. When any website is visited, the hosting service processes your IP address and browser details to deliver pages securely and protect against attacks.
What we do not collect through this website: payment details, CVs or job applications (our careers portal is a separate service with its own privacy notice), or data from children. The “Ask IBS” assistant runs in your browser and does not store or send your questions; if you choose to send a question to a consultant, it goes through the enquiry form.
Why we use it, and our legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Reply to your enquiry, prepare a proposal or arrange a call | Form data | Steps you ask us to take before a contract; our legitimate interest in answering business enquiries; in India and where required elsewhere, your consent given by submitting the form |
| Confirm your work email and prevent spam and abuse | Email, hashed code, hashed network address | Legitimate interest in keeping the site secure |
| Send you a confirmation that we received your message | Name, email | Steps you ask us to take |
| Understand and improve the website | Analytics data | Your consent (you can withdraw it at any time) |
| Meet legal obligations and defend legal claims | Records as needed | Legal obligation; legitimate interest |
We do not use your data for automated decisions that have legal or similarly significant effects on you, and we do not send marketing emails from this website.
Who we share it with
- INK teams who handle your request, in the countries listed above.
- Service providers acting on our instructions: Microsoft (Microsoft 365 email and SharePoint, Azure hosting and storage, Clarity), and Google (Gmail, where INK receives a copy of each form notification, and Analytics, only with your consent).
- Authorities, only where the law requires it.
We do not sell or rent personal data.
Where it is stored, and international transfers
Form data is stored in INK’s own Microsoft 365 environment (SharePoint lists and business email), a copy of each form notification is delivered to INK’s Gmail inbox, and email verification data is kept in INK’s Azure storage. Microsoft 365 and Azure data region.
Because INK works across several countries, and because Google and Microsoft may process analytics data in other countries (including the United States), your data may be transferred outside the country where you live. When this happens we use the safeguards the law requires, such as the providers’ data-processing terms and standard contractual clauses, and, for data from Saudi Arabia, the transfer conditions of the PDPL and its regulations.
How long we keep it
| Data | How long |
|---|---|
| Enquiries and messages | for example 24 months after our last contact with you, unless we start working together (then as long as our contract and the law require) |
| Email verification codes | 10 minutes; deleted when used |
| Abuse-prevention counters | One hour (hashed values only) |
| Analytics data | Google Analytics retention setting (2 or 14 months); Clarity as set by Microsoft |
| Your cookie choice | 12 months in your browser |
How we protect it
INK operates an information security management system certified to ISO 27001. Data is encrypted in transit (HTTPS), access is limited to the people who need it, and our forms check your email address and mobile number to reduce fraud and errors. No system is completely secure, but if a breach affects your data we will notify you and the authorities as the law requires.
Your rights
Depending on where you live, you can:
- access the personal data we hold about you and get a copy;
- correct data that is wrong or incomplete;
- delete your data, or restrict or object to how we use it;
- withdraw consent at any time (for analytics, use “Cookie settings” in the footer);
- receive your data in a portable format, where the law gives this right;
- in India, nominate someone to exercise your rights if you cannot, and use our grievance process;
- complain to your data protection authority (see below).
To use any of these rights, contact us (details below). We may need to confirm your identity. We will reply within the time your local law requires, and we will not treat you differently for using your rights.
| Where you are | Main law | Where you can complain |
|---|---|---|
| European Economic Area, UK, Switzerland | GDPR / UK GDPR / Swiss FADP | Your national data protection authority (in the UK, the ICO) |
| Saudi Arabia | Personal Data Protection Law (PDPL) | Saudi Data and AI Authority (SDAIA) |
| United Arab Emirates | Federal Decree-Law No. 45 of 2021; DIFC and ADGM data protection laws where they apply | UAE Data Office, or the DIFC or ADGM commissioner |
| India | Digital Personal Data Protection Act 2023 and Rules 2025 | Our grievance officer first, then the Data Protection Board of India |
| Egypt | Personal Data Protection Law No. 151 of 2020 | Personal Data Protection Center |
| United States | Applicable state privacy laws | Your state attorney general where applicable |
Children
This website is for businesses and professionals. It is not intended for anyone under 18, and we do not knowingly collect their data.
Changes to this policy
We will update this page when our practices change, and change the version and date above. If a change affects how we use data you have already given us, we will tell you before it applies.
Contact us
Privacy questions and requests: privacy email address. Grievance officer (India): name and contact. You can also write to us through our contact page.