Skip to content

Privacy Policy

What data is collected, where it goes, and how to get it removed.

Written to be read rather than to be survived. If you are evaluating this business as a vendor, the section on client data and sub-processors is the one your security reviewer will want.

Effective: 25 July 2026Entity: SoloZ AI — an OpenEng Labs ventureContact: hello@soloz.ai

This policy explains how SoloZ AI — an OpenEng Labs venture (“SoloZ AI”, “we”, “I”) handles personal data in two distinct situations: when you visit this website or make an enquiry, and when you become a client and business data passes through systems built for you. Those are treated very differently and are described separately below.

1. Data collected through this website

Only two things are collected from visitors.

Enquiry details you submit. When you complete the contact form, the following is stored: your name, email address, company name, team size, the service you indicated interest in, your message, the page you submitted from, the referring URL, any UTM campaign parameters in the link you arrived on, and your browser user-agent string. This is used to reply to you and to understand which channels produce enquiries. It is not added to a marketing list, not used for automated outbound sequences, and not sold or shared with any third party for their own purposes.

Anonymous usage analytics. This site uses Google Analytics 4, provided through Firebase, to count page views and understand which pages are read. It is configured for measurement only. No advertising features, remarketing audiences or cross-site advertising identifiers are enabled.

There is no live chat widget, no session recording, no heat-mapping, no advertising pixel and no third-party tracking script on this site.

For enquiries: you provided the information voluntarily in order to be contacted, and replying to you is our legitimate interest and the performance of steps taken at your request before entering a contract. For analytics: our legitimate interest in understanding whether the site works, using measurement configured to be as limited as the tool permits.

Under India’s Digital Personal Data Protection Act, 2023, submitting the form constitutes consent for the stated purpose of responding to your enquiry. You can withdraw that consent at any time by emailing hello@soloz.ai, and the record will be deleted.

3. Client data, and the sub-processors involved

This is the section that matters if you are evaluating us as a supplier. During an engagement, we design and build systems that process your business data. The governing principle is that the systems run in infrastructure you own: your cloud account, your automation platform, your vector database and your model API keys.

Consequently:

  • You are the data controller for the business data those systems process. We act as a processor, and only to the extent required to build, test and support what you commissioned.
  • Your data is not copied into our infrastructure. We work inside your environment under delegated administrative access, which you can revoke at any moment.
  • Sample data used during a build — for example the twenty historical records requested in the access checklist — is held only for as long as it is needed to build and test, is stored in your environment wherever technically possible, and is deleted at handover.
  • Model providers are your sub-processors, not ours. Because the API keys and accounts are yours, data sent to a language-model provider is sent under your agreement with that provider, not ours.

Before any build begins you receive a written one-page data summary listing every sub-processor the design involves, exactly what is sent to each, where it is processed and stored, how long it is retained, and how it is deleted. Where a provider offers a setting to exclude your data from model training, that setting is enabled by default and its status is stated in that document.

4. Sub-processors we use for our own operations

For running this business — as opposed to running your systems — we rely on a small number of established providers:

  • Google Firebase (Firestore, Hosting, Analytics) — hosts this website and stores contact-form submissions. Enquiry data is stored in a database located in Mumbai, India (asia-south1).
  • Google Workspace — email correspondence and documents.
  • Scheduling and payment providers — used to book calls and collect fees. These providers receive only what is necessary to perform that function, and each operates under its own privacy policy.

5. Where data is stored

Enquiry data submitted through this website is stored in Google Cloud’s Mumbai region (asia-south1), in India. Email correspondence is held in Google Workspace and may be processed in other regions in accordance with Google’s own terms.

If you are in the United Kingdom or the European Economic Area, personal data you send us is transferred to India. That transfer takes place on the basis of appropriate safeguards, including the European Commission’s standard contractual clauses where they apply, and is limited to the minimum necessary to respond to you and perform a contract with you.

6. How long it is kept

  • Enquiries that do not become clients: deleted within 24 months, or immediately on request.
  • Client records: retained for the duration of the engagement and for as long as required afterwards to meet Indian tax, GST and statutory record-keeping obligations.
  • Client business or sample data: deleted at handover, as described above.
  • Analytics: retained according to the retention setting configured in Google Analytics, currently the shortest period the tool allows.

7. Security

Credentials are held in a secret manager and never embedded in workflow definitions, documents or source code. Access to client systems is via scoped service accounts rather than shared personal logins, is requested at the minimum privilege the work requires, and is surrendered at the end of an engagement. Devices used for delivery are encrypted at rest and protected by multi-factor authentication.

No arrangement is perfectly secure. If a personal-data breach occurs that is likely to affect you, you will be notified without undue delay, along with what happened, what data was involved and what is being done about it.

8. Your rights

Whichever jurisdiction you are in, you may ask us to:

  • confirm what personal data about you we hold, and receive a copy of it;
  • correct anything inaccurate or incomplete;
  • delete it, where we are not required to retain it by law;
  • restrict or object to how it is used;
  • withdraw consent previously given, without affecting past lawful processing;
  • nominate another person to exercise these rights on your behalf in the event of death or incapacity, as provided under the DPDP Act.

Email hello@soloz.ai and the request will be answered within thirty days. There is no charge.

If you are unhappy with the outcome, you may complain to the Data Protection Board of India or, if you are in the UK or EEA, to your local supervisory authority.

9. Grievance contact

Questions, complaints and data-rights requests all go to the same place, and are handled by the person who runs the business rather than a ticket queue:

Email: hello@soloz.ai
Postal: Bangalore, Karnataka, India

10. Children

This is a business-to-business service. It is not directed at children and we do not knowingly collect personal data from anyone under 18. If you believe a child has submitted information through this site, email us and it will be deleted.

11. Changes to this policy

If this policy changes materially, the effective date at the top of this page is updated and, where the change affects an active engagement, clients are notified by email. Previous versions are available on request.

A note on these terms. This document is written to be accurate and enforceable for the way this business actually operates, and it is reviewed as the business changes. It is not legal advice, and it does not replace the signed master services agreement and statement of work that govern any specific engagement. Where this page and a signed agreement differ, the signed agreement controls.