1. Data Controller Identification
Medhavat ("we", "us", or "our") operates the website https://medhavat.com and provides
digital transformation, bespoke software engineering, and artificial intelligence solutions. We act as the
Data Controller for personal data collected through this website and initial client
consultations.
Registered Office: Magarpatta, Hadapsar, Pune, Maharashtra 411028, India.
Contact Email: info@medhavat.com
Privacy & Compliance Desk: info@medhavat.com
2. Personal Data We Collect
We strictly limit data collection to what is necessary to evaluate business inquiries, deliver high-performance solutions, and maintain website stability:
- Inquiry & Consultation Data: Full name, corporate email address, phone number, company name, project budget, and project specifications provided voluntarily via our contact form or WhatsApp connection.
- Technical & Usage Metrics: IP address (anonymized/truncated), browser type and version, device category, screen resolution, referral URL, and interaction timestamps.
- Preference & Theme State: Local user preferences stored in your browser, including your chosen Theme HUD matrix configuration (`night-grey`, `night-colour`, `day-colour`, `day-grey`) and cookie consent flags.
3. Legal Basis for Processing (GDPR Art. 6 & DPDP Act)
We process your personal data under the following recognized legal grounds:
• Performance of a Contract / Pre-contractual Steps (Art. 6(1)(b)): Responding to quotation
requests, scoping architecture roadmaps, and executing service agreements.
• Consent (Art. 6(1)(a)): Utilizing non-essential functional, analytics, or marketing
cookies, which you may grant or withdraw at any time via our Cookie Preferences Modal.
• Legitimate Interests (Art. 6(1)(f)): Maintaining cybersecurity, preventing
denial-of-service disruptions, and ensuring server performance.
4. Cookies & Data Retention Schedule
In compliance with GDPR Article 5(1)(e) (Storage Limitation), personal data is retained strictly for the duration necessary for its intended purpose:
| Category | Purpose | Retention Duration |
|---|---|---|
| Strictly Necessary | Security, routing, anti-CSRF token defense | Session (cleared on browser close) |
| Functional (HUD Theme) | Persisting 2×2 Theme Matrix & UI state | 12 months (local storage) |
| Anonymized Analytics | Core Web Vitals & journey analysis | Max 12 months |
| Project Inquiries | Scoping, consultation records & proposals | 3 years post-last interaction |
| Tax & Contract Records | Statutory Indian & international audit compliance | 7 years from invoice date |
5. Your Rights Under GDPR & Indian DPDP
Depending on your jurisdiction, you possess the following actionable rights regarding your data:
- Right of Access (Art. 15): Request a structured copy of your personal data held by us.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete information.
- Right to Erasure / Right to be Forgotten (Art. 17): Request deletion of your data when retention is no longer justified.
- Right to Data Portability (Art. 20): Receive your data in a machine-readable JSON format.
- Right to Withdraw Consent: Revoke non-essential cookie permissions instantly using our Cookie Settings Modal.
6. Enterprise Data Security & AI Confidentiality
For all client builds and bespoke AI solutions (such as enterprise document RAG pipelines), Medhavat enforces strict architectural isolation: AES-256 encryption at rest, TLS 1.3 encryption in transit, private Virtual Private Clouds (VPC), zero data retention agreements with foundation model APIs, and strict role-based access control (RBAC). Client data is never utilized to train public artificial intelligence models.
7. Contact & Privacy Inquiries
To exercise your rights or submit a data protection inquiry, contact our Data Protection Desk at info@medhavat.com or write to Medhavat, Magarpatta, Hadapsar, Pune, Maharashtra 411028, India.