On This Page↕
1. Introduction
Nunmathi Technologies Pvt Ltd ("Nunmathi," "Company," "we," "our," or "us") is an industrial artificial intelligence company registered in India, with its principal place of business at NO.1A, Street-5, R K Nagar, Irugur, Coimbatore – 641103, Tamil Nadu, India.
We develop and deploy AI-powered software, web applications, mobile applications, APIs, SaaS products, enterprise automation systems, computer vision platforms, predictive analytics engines, and custom AI solutions for industrial and healthcare clients.
This Privacy Policy ("Policy") describes how we collect, use, store, protect, and share information about you when you access or use our website at nunmathi.com, interact with our products and services, or submit enquiries through our contact form.
We comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the EU General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the CPRA, and internationally recognised data protection principles.
We do not sell your personal data. We never have and we never will.
2. Definitions
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
| Term | Meaning |
|---|---|
| Personal Data | Any information that identifies or could identify a natural person, directly or indirectly. |
| Processing | Any operation performed on personal data including collection, storage, use, disclosure, transfer, or deletion. |
| Data Controller | The entity that determines the purposes and means of processing. For this website, Nunmathi Technologies Pvt Ltd is the Data Controller. |
| Data Processor | A third party that processes personal data on behalf of the Data Controller under a written agreement. |
| Data Subject / User | The natural person whose personal data is being processed — including website visitors, enquiry submitters, API users, and enterprise clients. |
| Consent | A freely given, specific, informed, and unambiguous agreement to the processing of personal data for a stated purpose. |
| GDPR | General Data Protection Regulation (EU) 2016/679, effective May 25, 2018. |
| CCPA/CPRA | California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020. |
| DPDP Act | India's Digital Personal Data Protection Act, 2023. |
| AI Interaction Data | Prompts, queries, uploaded documents, generated outputs, and feedback submitted through any Nunmathi AI product or API. |
| Enterprise Customer | A business or organisation that engages Nunmathi under a separate contractual agreement to deploy, integrate, or license AI systems. |
3. Information We Collect
3.1 Personal Information
- Full name
- Work email address
- Phone number
- Job title and department
- Billing name and address (for paid services)
- Digital signatures or electronic acknowledgements
3.2 Business Information
- Company or organisation name
- Industry sector and company size
- Business use case and operational requirements
- Enterprise contract details
- Details of the AI challenge described in enquiries
3.3 Technical Information
- IP address (may be anonymised or truncated)
- Browser type, version, and language settings
- Operating system and device type
- Referring URL and exit pages
- Pages visited and navigation path
- Timestamps and session duration
3.4 Device Information
- Device model and manufacturer
- Operating system version
- Unique device identifiers (where applicable)
- Network connection type and mobile carrier
3.5 Cookies and Tracking Technologies
We use cookies and similar technologies to operate our Site. See Section 12 for a detailed explanation of cookie categories and your choices.
3.6 Analytics Data
Aggregated or pseudonymised data about how visitors use our Site — page performance metrics, feature adoption rates, and user flow data — used to improve our website and services. This data is not used to identify individual users.
3.7 AI Interaction Data
When you use any Nunmathi AI product (AutoPour, AMFDS, AMFIS, Healthcare AI Platform) or interact with our APIs, we may process:
- Input prompts, queries, instructions, and commands submitted to AI systems
- Documents, images, sensor data, or files uploaded for AI analysis
- AI-generated outputs, predictions, and recommendations
- Feedback, ratings, or corrections provided on AI outputs
- API request metadata — endpoints, timestamps, and response codes
- System logs generated during AI model inference
Processing of AI Interaction Data for Enterprise Customers is governed by the applicable Data Processing Agreement (DPA), which takes precedence over this Policy where they conflict.
4. How We Collect Information
- Directly from you — when you submit our contact form, send an email, or enter into a contract.
- Automatically — through server logs, cookies, and analytics tools when you visit our Site.
- Through our products and APIs — when authorised users interact with Nunmathi AI systems.
- From third parties — where Enterprise Customers integrate our APIs and pass data under their own data handling obligations.
- From publicly available sources — where legitimately relevant to a business enquiry.
5. Legal Basis for Processing (GDPR)
For individuals in the EEA or UK, we process personal data under the following lawful bases under Article 6 of the GDPR:
| Legal Basis | Purpose |
|---|---|
| Consent (Art. 6(1)(a)) | Where you have given explicit consent, such as enabling non-essential cookies. |
| Contractual Necessity (Art. 6(1)(b)) | To perform a contract or take pre-contractual steps at your request. |
| Legal Obligation (Art. 6(1)(c)) | To comply with applicable law — tax records, regulatory reporting, or lawful authority requests. |
| Legitimate Interests (Art. 6(1)(f)) | Fraud prevention, IT security, and improving our services — where our interests are not overridden by your fundamental rights. |
6. How We Use Information
- To respond to enquiries and schedule technical discovery conversations
- To assess requirements and prepare tailored AI proposals
- To enter into and perform service agreements and contracts
- To operate, deliver, and support Nunmathi AI products
- To process billing and manage enterprise accounts
- To send transactional communications related to your use of our services
- To send marketing communications — only with your prior consent
- To monitor, maintain, and improve the performance of our systems
- To detect, investigate, and prevent security incidents, fraud, or misuse
- To comply with applicable law and respond to lawful authority requests
- To conduct internal analytics using aggregated or anonymised data
7. AI Data Processing and Model Usage
7.1 Client-Deployed AI Systems
In deployed systems (AutoPour, AMFDS, AMFIS, Healthcare AI Platform, or custom builds), the Enterprise Customer is typically the Data Controller and Nunmathi acts as a Data Processor. All data flows are defined in the applicable DPA.
7.2 What We Do With AI Interaction Data
- AI Interaction Data is used to generate outputs requested by the authorised user and to operate the AI system as contracted.
- We may use interaction data to monitor system performance and detect anomalies.
- We do not use Enterprise Customer data to train or fine-tune our core AI models without explicit written consent.
- Interaction data is not shared with other clients, advertisers, or data brokers.
- User-submitted prompts and documents are processed transiently; we do not retain raw inputs beyond the period necessary to generate a response and maintain required audit logs.
7.3 Uploaded Documents and Files
Files are processed solely to produce the requested AI output and stored only for the duration required for processing and applicable audit obligations. Files are not accessed by Nunmathi staff unless required for technical support and authorised by the Customer.
7.4 API Usage
API consumers are responsible for ensuring they have obtained appropriate permissions from their own end users before transmitting personal data to our systems.
7.5 No Sale of Data for AI Training
We do not sell, license, or transfer your personal data or AI interaction data to any third party for the purpose of training external AI models.
8. Data Storage and Security
We store personal data on secure servers located in India and, where required, in international cloud regions. Data at rest is protected using industry-standard encryption. Data in transit is encrypted using TLS 1.2 or higher. Access to personal data is restricted to authorised personnel on a need-to-know basis.
We maintain regular automated backups and test restoration procedures periodically to ensure data availability in the event of an incident.
9. Encryption and Security Measures
| Control Category | Measures Implemented |
|---|---|
| Encryption in Transit | TLS 1.2+ on all public-facing endpoints; HSTS headers enforced; automated certificate management. |
| Encryption at Rest | AES-256 for databases and object storage; encrypted backups; HSM key management where applicable. |
| Access Controls | Role-based access control (RBAC); principle of least privilege; MFA for all staff accounts; PAM for production systems. |
| Network Security | Firewalls, intrusion detection systems (IDS), and network segmentation between production, staging, and development. |
| Monitoring & Alerting | Continuous security monitoring; centralised log aggregation; automated anomaly detection; 24/7 alerting. |
| Vulnerability Management | Regular automated scanning; periodic penetration testing; dependency auditing and patch management. |
| Incident Response | Documented incident response plan; defined escalation procedures; notifications compliant with regulatory timelines (72 hours for GDPR; DPDP Act requirements). |
| Staff Training | Mandatory security awareness training; role-specific data protection training; annual policy attestation. |
Notwithstanding these measures, no method of data transmission or storage is 100% secure. If you believe your interaction with us has been compromised, contact us immediately at info@nunmathi.com.
10. Third-Party Services
We engage carefully selected third-party service providers who process data on our behalf as Data Processors, bound by contractual obligations (DPAs). We do not sell personal data to third parties, and we do not share it with advertisers or data brokers.
Categories of third-party processors we may engage:
- Cloud infrastructure providers (compute, storage, database hosting)
- Email delivery services (transactional and notification emails)
- CRM software providers
- Analytics platforms (privacy-safe, aggregated website analytics)
- Payment processors (enterprise billing — we do not store card data)
- Communication tools (internal team collaboration)
A list of current key sub-processors is available upon written request to info@nunmathi.com.
11. Cloud Infrastructure
Our services are hosted on and may utilise infrastructure from Amazon Web Services (AWS), Microsoft Azure, and/or Google Cloud Platform (GCP). These providers operate globally certified, enterprise-grade data centres with ISO 27001, SOC 2 Type II, and PCI-DSS certifications.
Data processed on behalf of Enterprise Customers may be hosted in specific cloud regions as agreed in the applicable service agreement. Where a Customer requires data to remain within India or another jurisdiction, we configure the deployment accordingly.
Cloud providers process data solely as infrastructure providers and do not have access to your data for their own purposes.
12. Cookies and Tracking Technologies
| Category | Purpose | Consent Required |
|---|---|---|
| Essential | Required for the Site to function — navigation, security, form submission. Cannot be disabled. | No |
| Functional | Remember your preferences and settings to improve your experience. | Yes |
| Analytics | Understand how visitors interact with the Site using aggregated, anonymised data. | Yes |
| Marketing | Track browsing activity to deliver relevant advertising. Nunmathi does not currently use marketing cookies. | Yes |
You can control and delete cookies through your browser settings. Disabling essential cookies will impair Site functionality. We do not use fingerprinting, pixel tracking for third-party advertising, or cross-site tracking scripts.
13. Data Retention
| Data Category | Retention Period |
|---|---|
| Contact form submissions | Up to 3 years from submission, or until the enquiry is fully resolved. |
| Enterprise contract records | Duration of contract plus 7 years (Indian accounting and tax law). |
| AI interaction logs | As specified in the applicable DPA; default 90 days unless extended. |
| Uploaded documents and files | Deleted within 30 days of processing unless a longer period is agreed. |
| Website analytics data | Up to 24 months in aggregated, anonymised form. |
| Security and access logs | 12–36 months depending on legal requirements. |
| Financial and billing records | 7 years as required by Indian tax regulations. |
When personal data is no longer required, we securely delete or anonymise it using industry-standard methods.
14. Your Rights
Your specific rights depend on your jurisdiction. The table below shows which rights apply under each framework:
| Right | GDPR | CCPA/CPRA | DPDP Act |
|---|---|---|---|
| Access / Know | ✓ | ✓ | ✓ |
| Correction | ✓ | ✓ (CPRA) | ✓ |
| Deletion / Erasure | ✓ | ✓ | ✓ |
| Data Portability | ✓ | ✓ (CPRA) | ✓ |
| Restrict Processing | ✓ | — | — |
| Object to Processing | ✓ | — | — |
| Withdraw Consent | ✓ | ✓ | ✓ |
| Non-Discrimination | ✓ | ✓ | ✓ |
| Automated Decision Info | ✓ | — | ✓ |
To exercise any right, see Section 22. We respond within 30 days (GDPR/DPDP Act) or 45 days (CCPA). If you are in the EEA or UK and believe we have not handled your data lawfully, you may lodge a complaint with your national data protection authority.
15. Children's Privacy
Our Site and services are designed for business professionals and are not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a child has submitted data to us, contact info@nunmathi.com and we will delete it promptly upon verification.
16. International Data Transfers
Nunmathi is headquartered in India. If you access our services from outside India, your data may be transferred to and processed in India or other countries where our cloud providers operate.
For transfers from the EEA, UK, or Switzerland to countries without adequate protection, we use appropriate safeguards including:
- European Commission Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreements (IDTAs)
- Binding Corporate Rules or other approved mechanisms where relevant
For cross-border transfers under the DPDP Act, we comply with restrictions and permitted grounds as notified by the Government of India.
17. Automated Decision-Making
Some of our AI products involve automated processing that produces outputs affecting operational decisions — for example, a quality inspection result triggering a production halt, or an alert classification routing a clinical notification.
Where automated processing produces decisions with legal or similarly significant effects:
- We provide information about the logic involved upon request.
- Enterprise Customers are responsible for ensuring human oversight mechanisms are in place as required by applicable law.
- We design our AI systems to support human decision-making, not to replace it in high-stakes contexts.
18. Business Transfers
If Nunmathi undergoes a merger, acquisition, restructuring, sale of assets, or insolvency, personal data may be among the assets transferred. In such cases:
- We will notify affected users by posting a notice on our Site or by email before any transfer.
- Any successor entity will be required to handle personal data in accordance with this Policy or equivalent protection.
- You will retain all rights described in Section 14.
19. Links to Other Websites
Our Site may contain links to third-party websites for your reference. These links do not constitute an endorsement. Nunmathi has no control over, and assumes no responsibility for, the privacy practices or content of external websites. We encourage you to review the privacy policy of any third-party site before submitting personal data.
20. Changes to This Privacy Policy
We may update this Policy periodically. When we make material changes, we will update the "Last Updated" date, post a notice on our Site, and where required by law, notify you directly by email.
Continued use of our Site after the effective date of a revised Policy constitutes acceptance of the updated terms. If you do not agree, please discontinue use and contact us to exercise applicable rights.
21. Contact Information
Nunmathi Technologies Pvt Ltd is the Data Controller for personal data collected through this Site. For all privacy-related questions, concerns, or requests:
Nunmathi Technologies Pvt Ltd
Address: NO.1A, Street-5, R K Nagar, Irugur,
Coimbatore – 641103, Tamil Nadu, India
Privacy Enquiries: info@nunmathi.com
Phone: +91 93633 72992
We aim to acknowledge all privacy enquiries within 3 business days and resolve them within the timeframes required by applicable law.
22. How to Submit a Privacy Request
To exercise any of the rights in Section 14, submit a written request via:
- Email: info@nunmathi.com — subject line: "Privacy Request – [Your Name]"
- Post: Our registered address above, marked for the attention of "Data Privacy"
Please include: your full name, contact email, a description of the right you wish to exercise, the relevant data or processing activity, and your country of residence. We may ask you to verify your identity before processing your request.
We will not charge a fee for reasonable requests. If a request is manifestly unfounded or excessive, we reserve the right to charge a reasonable administrative fee or decline, explaining our reasons in writing.
This Privacy Policy is effective as of July 20, 2026.
© 2026 Nunmathi Technologies Pvt Ltd. All rights reserved.