Legal
Privacy
This site is a static, informational property. We collect as little as possible, and we process your personal data only for the purposes described here — under the Digital Personal Data Protection Act, 2023 (and the DPDP Rules, 2025). This notice explains what we collect, why, and how you can exercise your rights.
1. What we collect
- Contact form: name, email, topic and message — sent only when you submit, transmitted by
email from the lab's own server over SMTP (no third-party form processor), and used solely to answer your enquiry.
Successful submissions are retained in a private server-side log (
data/contact.log); a separate server-only log (data/contact-error.log) records failed delivery attempts for operational debugging and is not accessible from the web. - Data rights and opt-out forms: name, email and optional details, emailed to our Compliance
Team and retained in
data/data-requests.loganddata/privacy-opt-out.logto action and audit your request. - Security checks: the contact and rights forms use Cloudflare Turnstile, which may process your
IP address for fraud and abuse prevention (see §4). For rate limiting we keep only a one-way hash of your IP
address in short-lived files under
.ratelimit/, refreshed daily and not containing your identity. - Server logs: standard access logs (IP, user-agent) retained by our hosting provider for security and abuse prevention. These are not used to profile you.
- Theme preference: a
dl-themesetting kept in your browser's localStorage to remember your appearance choice. This is stored on your device, not on our server.
2. Legal basis
- Processing for an enquiry or request (notice, not consent): when you contact us, we process your details to respond — as voluntarily provided and reasonably expected, under DPDP Act s.7(a).
- Marketing updates (consent): we only send promotional or update emails if you tick the "marketing updates" box (s.6). You can withdraw consent at any time with the same ease — email grievance@delrique.com or use the Data Rights form.
- Security & abuse prevention: visitor IP numbers are used transiently to rate-limit abusive
submissions and are stored only as a one-way hash in daily-refreshed files under
.ratelimit/.
3. What we don't do
- No advertising or third-party tracking cookies.
- No analytics that profile you across sites.
- No sale or sharing of personal data.
- No external CDNs for fonts or images — your browser doesn't contact third parties to render this site.
4. Processors
We host on MilesWeb and use our own secure SMTP mailbox (Zoho) for outbound email from
no-reply@alerts.delrique.com. The contact form's bot check is done by
Cloudflare Turnstile, which may process your IP address for fraud and abuse prevention (see
Cloudflare's
Turnstile page and Cloudflare's
Privacy Policy). That is the complete list; we do not add processors for a purpose without updating this notice.
5. Retention & security
- Contact logs are kept access-controlled on the same hosting account and reviewed for deletion on a rolling basis (successful submissions after 12 months unless needed to action a request). Data-rights and opt-out records are kept for up to 12 months to evidence compliance (DPDP Act s.8(7)).
- Communication with our SMTP server is encrypted in transit (TLS). Logs are stored outside the web root where
filesystem permissions allow, and the SMTP configuration never sits inside
public_html. - We do not knowingly collect the data of children (individuals under 18), consistent with the DPDP Act's provisions on children's personal data; nothing on this site targets minors. If you are a parent or guardian and believe a child has provided data through the contact form, contact our Compliance Team and we will erase it promptly.
6. Your rights
Under s.11 of the DPDP Act you may request access, correction, erasure, objection or withdrawal of consent through our Data Rights & Request Form. We respond to every request within 30 days (DPDP Rules 2025, Rule 14).
7. Personal Data Breach
If we experience a security incident affecting your personal data, we will assess the risk to you and, where required by the DPDP Act s.8(6)-(9), notify the Data Protection Board of India and affected individuals without undue delay, including the nature of the breach, the data likely affected, and steps you can take to protect yourself.
8. Grievance & complaints
Contact our Compliance Team — Grievance Officer: Beena T S — at grievance@delrique.com, or by post to: Compliance Team, DELRIQUE LABS, Chembur, Mumbai, Maharashtra 400089, India. We respond within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India (DPDP Act 2023, s.13(3)).
9. Cookies
This site sets no advertising, marketing or analytics cookies. The only cookies are strictly necessary ones issued by Cloudflare for bot/fraud protection (see Cloudflare's cookie list). The theme preference is saved in your browser's localStorage and never transmitted to us.
10. Contact
Questions about this policy: reach the lab, or contact the Delrique Compliance Team — Grievance Officer: Beena T S — at grievance@delrique.com.