Legal

Privacy Policy

Effective: July 20, 2026Last updated: July 20, 2026
On This Page

1. Introduction

Nunmathi Technologies Pvt Ltd ("Nunmathi," "Company," "we," "our," or "us") is an industrial artificial intelligence company registered in India, with its principal place of business at NO.1A, Street-5, R K Nagar, Irugur, Coimbatore – 641103, Tamil Nadu, India.

We develop and deploy AI-powered software, web applications, mobile applications, APIs, SaaS products, enterprise automation systems, computer vision platforms, predictive analytics engines, and custom AI solutions for industrial and healthcare clients.

This Privacy Policy ("Policy") describes how we collect, use, store, protect, and share information about you when you access or use our website at nunmathi.com, interact with our products and services, or submit enquiries through our contact form.

We comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the EU General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the CPRA, and internationally recognised data protection principles.

We do not sell your personal data. We never have and we never will.

2. Definitions

For the purposes of this Privacy Policy, the following terms have the meanings set out below:

TermMeaning
Personal DataAny information that identifies or could identify a natural person, directly or indirectly.
ProcessingAny operation performed on personal data including collection, storage, use, disclosure, transfer, or deletion.
Data ControllerThe entity that determines the purposes and means of processing. For this website, Nunmathi Technologies Pvt Ltd is the Data Controller.
Data ProcessorA third party that processes personal data on behalf of the Data Controller under a written agreement.
Data Subject / UserThe natural person whose personal data is being processed — including website visitors, enquiry submitters, API users, and enterprise clients.
ConsentA freely given, specific, informed, and unambiguous agreement to the processing of personal data for a stated purpose.
GDPRGeneral Data Protection Regulation (EU) 2016/679, effective May 25, 2018.
CCPA/CPRACalifornia Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020.
DPDP ActIndia's Digital Personal Data Protection Act, 2023.
AI Interaction DataPrompts, queries, uploaded documents, generated outputs, and feedback submitted through any Nunmathi AI product or API.
Enterprise CustomerA business or organisation that engages Nunmathi under a separate contractual agreement to deploy, integrate, or license AI systems.

3. Information We Collect

3.1 Personal Information

  • Full name
  • Work email address
  • Phone number
  • Job title and department
  • Billing name and address (for paid services)
  • Digital signatures or electronic acknowledgements

3.2 Business Information

  • Company or organisation name
  • Industry sector and company size
  • Business use case and operational requirements
  • Enterprise contract details
  • Details of the AI challenge described in enquiries

3.3 Technical Information

  • IP address (may be anonymised or truncated)
  • Browser type, version, and language settings
  • Operating system and device type
  • Referring URL and exit pages
  • Pages visited and navigation path
  • Timestamps and session duration

3.4 Device Information

  • Device model and manufacturer
  • Operating system version
  • Unique device identifiers (where applicable)
  • Network connection type and mobile carrier

3.5 Cookies and Tracking Technologies

We use cookies and similar technologies to operate our Site. See Section 12 for a detailed explanation of cookie categories and your choices.

3.6 Analytics Data

Aggregated or pseudonymised data about how visitors use our Site — page performance metrics, feature adoption rates, and user flow data — used to improve our website and services. This data is not used to identify individual users.

3.7 AI Interaction Data

When you use any Nunmathi AI product (AutoPour, AMFDS, AMFIS, Healthcare AI Platform) or interact with our APIs, we may process:

  • Input prompts, queries, instructions, and commands submitted to AI systems
  • Documents, images, sensor data, or files uploaded for AI analysis
  • AI-generated outputs, predictions, and recommendations
  • Feedback, ratings, or corrections provided on AI outputs
  • API request metadata — endpoints, timestamps, and response codes
  • System logs generated during AI model inference

Processing of AI Interaction Data for Enterprise Customers is governed by the applicable Data Processing Agreement (DPA), which takes precedence over this Policy where they conflict.

4. How We Collect Information

  • Directly from you — when you submit our contact form, send an email, or enter into a contract.
  • Automatically — through server logs, cookies, and analytics tools when you visit our Site.
  • Through our products and APIs — when authorised users interact with Nunmathi AI systems.
  • From third parties — where Enterprise Customers integrate our APIs and pass data under their own data handling obligations.
  • From publicly available sources — where legitimately relevant to a business enquiry.

5. Legal Basis for Processing (GDPR)

For individuals in the EEA or UK, we process personal data under the following lawful bases under Article 6 of the GDPR:

Legal BasisPurpose
Consent (Art. 6(1)(a))Where you have given explicit consent, such as enabling non-essential cookies.
Contractual Necessity (Art. 6(1)(b))To perform a contract or take pre-contractual steps at your request.
Legal Obligation (Art. 6(1)(c))To comply with applicable law — tax records, regulatory reporting, or lawful authority requests.
Legitimate Interests (Art. 6(1)(f))Fraud prevention, IT security, and improving our services — where our interests are not overridden by your fundamental rights.

6. How We Use Information

  • To respond to enquiries and schedule technical discovery conversations
  • To assess requirements and prepare tailored AI proposals
  • To enter into and perform service agreements and contracts
  • To operate, deliver, and support Nunmathi AI products
  • To process billing and manage enterprise accounts
  • To send transactional communications related to your use of our services
  • To send marketing communications — only with your prior consent
  • To monitor, maintain, and improve the performance of our systems
  • To detect, investigate, and prevent security incidents, fraud, or misuse
  • To comply with applicable law and respond to lawful authority requests
  • To conduct internal analytics using aggregated or anonymised data

7. AI Data Processing and Model Usage

7.1 Client-Deployed AI Systems

In deployed systems (AutoPour, AMFDS, AMFIS, Healthcare AI Platform, or custom builds), the Enterprise Customer is typically the Data Controller and Nunmathi acts as a Data Processor. All data flows are defined in the applicable DPA.

7.2 What We Do With AI Interaction Data

  • AI Interaction Data is used to generate outputs requested by the authorised user and to operate the AI system as contracted.
  • We may use interaction data to monitor system performance and detect anomalies.
  • We do not use Enterprise Customer data to train or fine-tune our core AI models without explicit written consent.
  • Interaction data is not shared with other clients, advertisers, or data brokers.
  • User-submitted prompts and documents are processed transiently; we do not retain raw inputs beyond the period necessary to generate a response and maintain required audit logs.

7.3 Uploaded Documents and Files

Files are processed solely to produce the requested AI output and stored only for the duration required for processing and applicable audit obligations. Files are not accessed by Nunmathi staff unless required for technical support and authorised by the Customer.

7.4 API Usage

API consumers are responsible for ensuring they have obtained appropriate permissions from their own end users before transmitting personal data to our systems.

7.5 No Sale of Data for AI Training

We do not sell, license, or transfer your personal data or AI interaction data to any third party for the purpose of training external AI models.

8. Data Storage and Security

We store personal data on secure servers located in India and, where required, in international cloud regions. Data at rest is protected using industry-standard encryption. Data in transit is encrypted using TLS 1.2 or higher. Access to personal data is restricted to authorised personnel on a need-to-know basis.

We maintain regular automated backups and test restoration procedures periodically to ensure data availability in the event of an incident.

9. Encryption and Security Measures

Control CategoryMeasures Implemented
Encryption in TransitTLS 1.2+ on all public-facing endpoints; HSTS headers enforced; automated certificate management.
Encryption at RestAES-256 for databases and object storage; encrypted backups; HSM key management where applicable.
Access ControlsRole-based access control (RBAC); principle of least privilege; MFA for all staff accounts; PAM for production systems.
Network SecurityFirewalls, intrusion detection systems (IDS), and network segmentation between production, staging, and development.
Monitoring & AlertingContinuous security monitoring; centralised log aggregation; automated anomaly detection; 24/7 alerting.
Vulnerability ManagementRegular automated scanning; periodic penetration testing; dependency auditing and patch management.
Incident ResponseDocumented incident response plan; defined escalation procedures; notifications compliant with regulatory timelines (72 hours for GDPR; DPDP Act requirements).
Staff TrainingMandatory security awareness training; role-specific data protection training; annual policy attestation.

Notwithstanding these measures, no method of data transmission or storage is 100% secure. If you believe your interaction with us has been compromised, contact us immediately at info@nunmathi.com.

10. Third-Party Services

We engage carefully selected third-party service providers who process data on our behalf as Data Processors, bound by contractual obligations (DPAs). We do not sell personal data to third parties, and we do not share it with advertisers or data brokers.

Categories of third-party processors we may engage:

  • Cloud infrastructure providers (compute, storage, database hosting)
  • Email delivery services (transactional and notification emails)
  • CRM software providers
  • Analytics platforms (privacy-safe, aggregated website analytics)
  • Payment processors (enterprise billing — we do not store card data)
  • Communication tools (internal team collaboration)

A list of current key sub-processors is available upon written request to info@nunmathi.com.

11. Cloud Infrastructure

Our services are hosted on and may utilise infrastructure from Amazon Web Services (AWS), Microsoft Azure, and/or Google Cloud Platform (GCP). These providers operate globally certified, enterprise-grade data centres with ISO 27001, SOC 2 Type II, and PCI-DSS certifications.

Data processed on behalf of Enterprise Customers may be hosted in specific cloud regions as agreed in the applicable service agreement. Where a Customer requires data to remain within India or another jurisdiction, we configure the deployment accordingly.

Cloud providers process data solely as infrastructure providers and do not have access to your data for their own purposes.

12. Cookies and Tracking Technologies

CategoryPurposeConsent Required
EssentialRequired for the Site to function — navigation, security, form submission. Cannot be disabled.No
FunctionalRemember your preferences and settings to improve your experience.Yes
AnalyticsUnderstand how visitors interact with the Site using aggregated, anonymised data.Yes
MarketingTrack browsing activity to deliver relevant advertising. Nunmathi does not currently use marketing cookies.Yes

You can control and delete cookies through your browser settings. Disabling essential cookies will impair Site functionality. We do not use fingerprinting, pixel tracking for third-party advertising, or cross-site tracking scripts.

13. Data Retention

Data CategoryRetention Period
Contact form submissionsUp to 3 years from submission, or until the enquiry is fully resolved.
Enterprise contract recordsDuration of contract plus 7 years (Indian accounting and tax law).
AI interaction logsAs specified in the applicable DPA; default 90 days unless extended.
Uploaded documents and filesDeleted within 30 days of processing unless a longer period is agreed.
Website analytics dataUp to 24 months in aggregated, anonymised form.
Security and access logs12–36 months depending on legal requirements.
Financial and billing records7 years as required by Indian tax regulations.

When personal data is no longer required, we securely delete or anonymise it using industry-standard methods.

14. Your Rights

Your specific rights depend on your jurisdiction. The table below shows which rights apply under each framework:

RightGDPRCCPA/CPRADPDP Act
Access / Know
Correction✓ (CPRA)
Deletion / Erasure
Data Portability✓ (CPRA)
Restrict Processing
Object to Processing
Withdraw Consent
Non-Discrimination
Automated Decision Info

To exercise any right, see Section 22. We respond within 30 days (GDPR/DPDP Act) or 45 days (CCPA). If you are in the EEA or UK and believe we have not handled your data lawfully, you may lodge a complaint with your national data protection authority.

15. Children's Privacy

Our Site and services are designed for business professionals and are not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a child has submitted data to us, contact info@nunmathi.com and we will delete it promptly upon verification.

16. International Data Transfers

Nunmathi is headquartered in India. If you access our services from outside India, your data may be transferred to and processed in India or other countries where our cloud providers operate.

For transfers from the EEA, UK, or Switzerland to countries without adequate protection, we use appropriate safeguards including:

  • European Commission Standard Contractual Clauses (SCCs)
  • UK International Data Transfer Agreements (IDTAs)
  • Binding Corporate Rules or other approved mechanisms where relevant

For cross-border transfers under the DPDP Act, we comply with restrictions and permitted grounds as notified by the Government of India.

17. Automated Decision-Making

Some of our AI products involve automated processing that produces outputs affecting operational decisions — for example, a quality inspection result triggering a production halt, or an alert classification routing a clinical notification.

Where automated processing produces decisions with legal or similarly significant effects:

  • We provide information about the logic involved upon request.
  • Enterprise Customers are responsible for ensuring human oversight mechanisms are in place as required by applicable law.
  • We design our AI systems to support human decision-making, not to replace it in high-stakes contexts.

18. Business Transfers

If Nunmathi undergoes a merger, acquisition, restructuring, sale of assets, or insolvency, personal data may be among the assets transferred. In such cases:

  • We will notify affected users by posting a notice on our Site or by email before any transfer.
  • Any successor entity will be required to handle personal data in accordance with this Policy or equivalent protection.
  • You will retain all rights described in Section 14.

19. Links to Other Websites

Our Site may contain links to third-party websites for your reference. These links do not constitute an endorsement. Nunmathi has no control over, and assumes no responsibility for, the privacy practices or content of external websites. We encourage you to review the privacy policy of any third-party site before submitting personal data.

20. Changes to This Privacy Policy

We may update this Policy periodically. When we make material changes, we will update the "Last Updated" date, post a notice on our Site, and where required by law, notify you directly by email.

Continued use of our Site after the effective date of a revised Policy constitutes acceptance of the updated terms. If you do not agree, please discontinue use and contact us to exercise applicable rights.

21. Contact Information

Nunmathi Technologies Pvt Ltd is the Data Controller for personal data collected through this Site. For all privacy-related questions, concerns, or requests:

Nunmathi Technologies Pvt Ltd

Address: NO.1A, Street-5, R K Nagar, Irugur,
Coimbatore – 641103, Tamil Nadu, India

Privacy Enquiries: info@nunmathi.com

Phone: +91 93633 72992

We aim to acknowledge all privacy enquiries within 3 business days and resolve them within the timeframes required by applicable law.

22. How to Submit a Privacy Request

To exercise any of the rights in Section 14, submit a written request via:

  • Email: info@nunmathi.com — subject line: "Privacy Request – [Your Name]"
  • Post: Our registered address above, marked for the attention of "Data Privacy"

Please include: your full name, contact email, a description of the right you wish to exercise, the relevant data or processing activity, and your country of residence. We may ask you to verify your identity before processing your request.

We will not charge a fee for reasonable requests. If a request is manifestly unfounded or excessive, we reserve the right to charge a reasonable administrative fee or decline, explaining our reasons in writing.

This Privacy Policy is effective as of July 20, 2026.
© 2026 Nunmathi Technologies Pvt Ltd. All rights reserved.