UNIQPIXLAI Labs
GLOBAL LEGAL & DATA PROTECTION GOVERNANCE

Privacy Policy

Effective Date: February 20, 2026 • UNIQPIXL AI LABS • Compliant with EU/UK GDPR, India DPDP Act 2023 & CCPA/CPRA

01. Scope & Identity of Data Fiduciary / Controller

UNIQPIXL AI LABS ("UNIQPIXL", "we", "our", or "us") operates as a productized systems engineering consultancy building custom Business Operating Systems, AI integration pipelines, and operational software for established businesses globally and in India.

For the purposes of applicable data protection laws—including the Regulation (EU) 2016/679 (EU General Data Protection Regulation / "GDPR"), the UK Data Protection Act 2018 ("UK GDPR"), the India Digital Personal Data Protection Act, 2023 ("DPDP Act 2023"), and the California Consumer Privacy Act ("CCPA/CPRA")—UNIQPIXL acts as the Data Controller (under GDPR) and Data Fiduciary (under the DPDP Act 2023).

02. Categories of Data We Collect

We collect personal and operational data necessary to respond to inquiries, conduct Discovery Calls, deliver AI & Systems Assessments, and execute Statements of Work ("SOW"):

  • Identity & Professional Contact Data: Full name, business email address, phone number, company name, job title, and country of operation.
  • Intake & Operational Telemetry: Self-reported business workflow descriptions, current software stack details (CRM, ERP, database, finance tools), operational bottlenecks, team size, and revenue range brackets submitted via our intake or scheduling flows.
  • Engagement Artifacts & Technical Credentials: Workflow charts, API keys, database schemas, and system access tokens voluntarily shared by clients under strict non-disclosure during paid assessment or Business OS engineering engagements.
  • Technical Telemetry & Cookies: Internet Protocol (IP) address, browser type, operating system, device identifiers, and anonymized page analytics captured during site visits.

03. Lawful Grounds for Processing (GDPR & DPDP Act 2023)

We process your personal data strictly under valid statutory grounds:

  • Contractual Necessity (GDPR Art. 6(1)(b) / DPDP Section 6): Processing required to schedule calls, deliver the AI & Systems Assessment report, or execute software SOW obligations.
  • Explicit Consent (DPDP Act Section 6(1) / GDPR Art. 6(1)(a)): Where you fill out our intake form, book sessions, or opt-in to technical communications. You have the right to withdraw consent at any time.
  • Legitimate Uses & Interests (GDPR Art. 6(1)(f) / DPDP Section 7): Preventing fraudulent access, enforcing system security, maintaining audit logs, and managing legal claims.

04. AI Data Confidentiality & Zero Public Training Commitment

CRITICAL AI PROTECTION GUARANTEE:

Client operational data, code repositories, internal workflows, data schemas, and API payloads processed during UNIQPIXL engagements are NEVER used to train, retrain, or fine-tune public foundation AI models. All AI integrations engineered by UNIQPIXL utilize enterprise zero-data-retention API endpoints operating under private data isolation boundaries.

05. Authorized Third-Party Service Providers & Infrastructure

We do not sell, lease, or monetize personal or business data under any circumstances. We share data only with trusted enterprise service providers bound by strict confidentiality and Data Processing Agreements (DPAs) strictly for operational fulfillment:

  • Customer Relationship Management (CRM) Infrastructure: For processing intake records, qualification notes, and client communication logs stored in secure, SOC2 Type II compliant environments.
  • Calendar & Scheduling Providers: For managing calendar availability and scheduling discovery sessions or findings walkthroughs.
  • Cloud Hosting & Edge Infrastructure: For web application hosting, content delivery network (CDN) distribution, and secure API execution.
  • PCI-DSS Compliant Payment Gateways: For processing authorized assessment transactions (UNIQPIXL never stores or processes raw credit card numbers).

06. International Cross-Border Data Transfers

As a global AI engineering firm, data may be transferred to or processed in servers located outside your jurisdiction (including the United States, EU, and India). All cross-border transfers comply with standard contractual clauses (EU SCCs) or statutory safeguards under the India DPDP Act 2023.

07. Your Statutory Data Rights (Data Subject / Data Principal)

Depending on your geographic location, you possess explicit rights regarding your personal data:

EU & UK GDPR Rights
  • Right of Access & Data Portability
  • Right to Rectification & Erasure ("Right to be Forgotten")
  • Right to Restrict or Object to Processing
  • Right to Lodge Complaint with DPA Supervisory Authority
India DPDP Act 2023 Rights
  • Right to Access Information about Personal Data
  • Right to Correction & Erasure of Data
  • Right of Grievance Redressal
  • Right to Nominate Representative in event of incapacity

08. Data Security & Retention Schedules

We enforce physical, technical, and organizational safeguards including SSL/TLS 1.3 encryption in transit, AES-256 encryption at rest, role-based access control (RBAC), and multi-factor authentication.

Lead intake telemetry is retained for up to 24 months unless earlier erasure is requested. Paid assessment and SOW project data are retained for the active contract duration plus statutory accounting/tax periods (up to 7 years).

09. Data Protection & Grievance Redressal Officer

To exercise any of your data rights, request erasure, or lodge a data protection grievance under the India DPDP Act 2023 or GDPR, please contact our Data Protection & Grievance Officer:

UNIQPIXL AI LABS • Legal & Data Protection Office
Grievance Officer: Data Governance Division
Response SLA: Statutory acknowledgment within 48 hours; resolution within statutory limit (30 days under GDPR / DPDP guidelines).