1. Who we are

This website is operated by GREYSCRIPT TECHNOLOGIES PRIVATE LIMITED, trading as GreyScript AI, an initiative of GreyScript Technologies ("we", "us", "our"). We are the controller (under GDPR and UK GDPR) and the data fiduciary (under India's Digital Personal Data Protection Act, 2023) for the personal information described in this policy.

2. What this policy covers

This policy covers personal information we handle through this website and when you contact us. It does not cover data we process on behalf of clients during an engagement; that is governed by our contract and, where required, a data processing agreement with the client.

3. What we collect

Information you give us

Information collected automatically

What we do not collect

4. How we use it, and our legal bases

We do not send marketing emails unless you ask for them. We do not sell personal information, use it for targeted advertising, or make decisions about you based solely on automated processing that have legal or similarly significant effects. Where Indian law applies, we process personal data you provide on the basis of your consent given when you submit it, for the purpose stated at the time, and you may withdraw that consent at any time.

5. Who we share it with

We share personal information only with service providers that help us run the website and communicate with you, under contracts that restrict their use of it:

We may also disclose information to professional advisers, to authorities when the law requires it, to protect our rights or others' safety, or to a successor if our business is reorganized or sold, in which case this policy continues to apply.

6. International transfers

Our service providers may process personal information outside your country, including in the United States. Where data protection law requires it, we rely on appropriate safeguards for these transfers, such as adequacy decisions (including the EU-US Data Privacy Framework and its UK extension, where the provider participates) or standard contractual clauses approved by the European Commission and the UK authorities.

7. How long we keep it

8. How we protect it

The website is served only over HTTPS. Contact form submissions are validated and passed straight to our inbox; the website itself does not keep a database of them. Access to our inbox and hosting accounts is limited to people who need it. No method of transmission or storage is completely secure, but we take reasonable measures appropriate to the information we hold.

9. Your rights

Wherever you are, you can ask us what personal information we hold about you, ask us to correct it or delete it, and ask questions about how we use it. Depending on where you live, you have additional rights:

European Economic Area, United Kingdom and Switzerland

You have the right to access, rectify and erase your personal data, to restrict or object to its processing (including processing based on legitimate interests), to data portability, and to withdraw consent at any time where we rely on it. You also have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office), although we would appreciate the chance to address your concern first.

California and other US states

Where US state privacy laws such as the California Consumer Privacy Act (as amended by the CPRA) apply to us, you have the right to know what personal information we collect, use and disclose, to access and obtain a copy of it, to correct it, and to delete it. In the last 12 months we have collected the following categories: identifiers (name, email address, IP address), professional information (company) and internet activity (server log data), from you and your device, for the purposes described in section 4. We do not sell or share personal information for cross-context behavioral advertising, and we do not collect sensitive personal information. We will not discriminate against you for exercising your rights. You may use an authorized agent, and we may need to verify your identity before acting on a request.

India

Under the Digital Personal Data Protection Act, 2023, you have the right to obtain information about the personal data we process, to request its correction, completion, updating and erasure, to withdraw consent, to have your grievances addressed, and to nominate another person to exercise your rights in the event of death or incapacity. Contact our grievance officer at greyscripttech@gmail.com. If your grievance is not resolved, you may approach the Data Protection Board of India.

Other countries

If you live elsewhere, for example in Brazil, Canada, Australia or Singapore, you may have similar rights under local law. We will honor them as the law requires.

How to make a request

Email greyscripttech@gmail.com with the subject "Privacy request", or use the contact form and choose "Privacy or data request". We will respond within the time the applicable law requires (for example, one month under GDPR, or 45 days under the CCPA), and we may ask for information to verify your identity.

10. Children

This website is intended for businesses and is not directed at anyone under 18. We do not knowingly collect personal information from children. If you believe a child has sent us personal information, contact us and we will delete it.

11. Links to other websites

This website links to other sites, such as greyscripttech.com and LinkedIn. Their own privacy policies apply when you visit them.

12. Changes to this policy

We will update this policy when our practices change, and revise the effective date above. If a change materially affects how we use personal information you have already given us, we will tell you where we reasonably can.

13. Contact

Questions about this policy or your personal information: greyscripttech@gmail.com, or write to GREYSCRIPT TECHNOLOGIES PRIVATE LIMITED, 3rd Floor, Vihang Garden, Thane-400606, Maharashtra, India.