what we collect, why we have it, who else sees it, and how you get it back or get it deleted.
a summary, not the agreement. the numbered clauses below are what binds.
Alchemist inc. is a next-gen creative technologist group and marketing agency, with its office in Bangalore, India. in this policy we, us and our mean alchemist inc.; you means anyone whose personal data we hold — a visitor to this site, someone who writes to us, or a client.
for anything in this policy — a question, a request to see or delete your data, or a complaint — write to:
that address reaches a named person who can answer questions about how we handle your data. we are not required to appoint a data protection officer and we have not appointed one; the address above is the contact for these purposes.
this policy covers this website and the documents we serve from it — proposals, agreements and invoices at their private links. it also covers emails you send us and the enquiries we handle.
it does not cover the material inside a client project. when we work on a campaign we often process data that belongs to the client — their customer lists, their research, their footage. in that work the client decides what happens to the data and we act on their instructions, under the contract we have signed with them. if your data was given to us by a company we work for, ask them first; we will help them answer you.
it also does not cover other people's sites. our links to instagram, linkedin and our booking calendar take you to services run by meta, microsoft and google, each with its own policy and none of them ours.
everything the site can hold about you, in one table. nothing is collected that isn't listed here.
| when | what we get | where it goes |
|---|---|---|
| you ask to be told when we launch | your email address, and the date you asked. | a private table in our database. a copy is also kept in your own browser so the form remembers you — that copy is yours and clearing your browser data removes it. |
| you use the contact form | your name, email and message. | nowhere on our systems. the form composes a message in your own email program and you send it yourself — so it reaches us as an ordinary email, and we hold it the way we hold any email. |
| you talk to the showroom | whatever you type, and a random session number that ties one conversation together. the session number is not linked to you and disappears when you close the tab. | a conversation log in our database, and the ai suppliers in clause 06 who generate the reply. please don't type anything confidential into it. |
| you sign an agreement we sent you | your organisation's legal name, entity type and registered address; the email for notices; the signatory's name and designation; the signature itself, typed or drawn; and — recorded automatically — the ip address you signed from, your browser's user-agent string, the exact wording you agreed to, the time, and a fingerprint of the document. | the agreement record in our database. see clause 04 for why the last part is there. |
| we invoice you | your billing name and postal address, gstin and pan, email and phone, and the description of the work. | the invoice record in our database. |
| you open an agreement or invoice link | the date and time you first opened it. | the same record. it tells us a document arrived, which is otherwise guesswork. |
| any page load | your ip address, browser and operating system, the page you asked for and the page you came from — the ordinary server log every website keeps. | our hosting and database suppliers' logs, held for their own operational and security periods. |
| you write for us | your name, biography, photograph and social handles. | published on the article, because a byline is the point of a byline. |
| what | why | the basis we rely on |
|---|---|---|
| launch list email | to send you one message when the site opens. | your consent, asked for at the point you type it in. you can withdraw it at any time and we will delete the address. |
| enquiry emails | to reply to you and, if it goes somewhere, to quote for the work. | you gave it to us voluntarily for that purpose. we do not add enquirers to any mailing list — that would need a separate, explicit yes. |
| showroom conversations | to answer you, to stop one person flooding the service, and to see what people actually ask us so the thing gets better. | your consent, given by typing into it after reading the notice on the panel; and our legitimate interest in keeping the service standing up. |
| agreement and invoice records | to perform the contract, to bill for it, and to meet indian tax law. | performance of a contract, and our legal obligations under tax and accounting law. |
| ip address, browser and timestamp on a signature | to prove who signed, from where, when, and to what exact wording — the evidence that makes an electronic signature worth as much as an ink one. | our legitimate interest in agreements that are actually enforceable, and yours in the same. we tell you before you sign, and we do not use this data for anything else. |
| server logs | to keep the site up, and to investigate abuse. | our legitimate interest in a working, un-attacked website. |
we do not sell personal data, we do not trade it, and we do not share it for anyone else's marketing. the only outside parties that touch it are the suppliers who run parts of the service for us:
| supplier | what they do | what reaches them |
|---|---|---|
| supabase, through lovable | our database, file storage and login system. | everything in clause 03 that we store. they hold it for us and may not use it for their own purposes. |
| lovable | hosts and builds the site, and routes the showroom's ai requests. | site traffic, and showroom conversation text. |
| openai | generates the showroom's replies. | the text of your showroom conversation. nothing else — no name, no email, no ip address. |
| cloudflare | delivers the site and screens out attacks. | your ip address and request details, as part of serving every page. |
| serves the three typefaces the site is set in, from its font service. | your ip address and browser, on every page load, because your browser fetches the fonts directly from google. | |
| open-meteo | supplies the weather reading on the pre-launch page. | your ip address and browser, when that page loads. no location of yours is sent — the coordinates are ours. |
beyond that, we will hand over personal data only where the law requires it — a court order, a tax authority, a regulator with the power to ask — or where we need to establish or defend a legal claim. if we are ever sold or merged, whoever takes over the business takes over these obligations with it.
our database and file storage are run by supabase on cloud infrastructure, and the suppliers in clause 06 operate globally. so your data is stored and processed outside india, and if you are in the eu or the uk, outside those too.
indian law permits this: transfers abroad are allowed except to countries the central government specifically restricts, and no country is currently restricted. where we transfer personal data out of the eu or uk, we rely on the european commission's standard contractual clauses and the uk addendum, through the terms our suppliers publish. ask us and we will point you to them.
| what | kept for |
|---|---|
| launch list email | until we have sent the launch announcement, then deleted within 30 days — unless you have separately asked to stay on a mailing list. withdraw sooner and we delete it on request. |
| enquiry emails | 24 months from our last exchange, so we can pick up a conversation that restarts. longer if it turned into a project, in which case it belongs to the project file. |
| showroom conversations | 12 months, then deleted. |
| agreements | for as long as the confidentiality obligations run, and then for as long afterwards as a claim could still be brought on them. |
| invoices and billing records | eight years from the end of the financial year they belong to. indian tax and accounting law requires this and we cannot shorten it on request. |
| server logs | as long as our hosting suppliers hold them, which is a matter of months, not years. |
you can ask us to:
write to hello@alchemistgroup.in. we will reply within 30 days. there is no charge. we may ask you to confirm who you are first — not to obstruct you, but because handing your data to someone impersonating you would be the worse failure.
this site and our services are aimed at businesses and the people who work in them. we do not knowingly collect personal data from anyone under 18, and we do not direct advertising at children or track them. if you believe a child has given us their data, tell us at hello@alchemistgroup.in and we will delete it.
no system is perfectly secure, and we won't pretend otherwise. if a breach ever affects your personal data we will tell you and the relevant authority, promptly and with what we actually know rather than a holding statement.
if you are unhappy with how we have handled your data or your request, write to hello@alchemistgroup.in with grievance in the subject line. we will acknowledge it and give you an answer within 30 days.
if that doesn't resolve it, you can complain to a regulator. in india that is the data protection board of india, once it is receiving complaints. in the eu or the uk it is the supervisory authority where you live or work — in the uk, the information commissioner's office. you do not have to come to us first, though we would rather you did.
when we change what we collect or what we do with it, we change this page and move the date at the top. if a change materially affects you and we hold your email address, we will tell you directly rather than relying on you to notice. we won't apply a new purpose to data we already hold without asking you first, where asking is what the law requires.