Legal & Compliance

Privacy Policy

At Skyrn Studio, we design premium digital experiences and bespoke AI automation infrastructure. We treat your privacy and personal data with the highest standard of care, transparency, and technical security. This policy outlines our data practices in full compliance with the Indian Information Technology Act, 2000 (Section 43A), the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 (DPDPA), and the General Data Protection Regulation (GDPR) for international visitors.

Last UpdatedSeptember 2026
JurisdictionIndia (Global Coverage)
Tracking CookiesNone / Zero Ad Trackers
Grievance OfficerAbhinav Rai

01.Information We Collect

Skyrn Studio operates on a privacy-first ethos. We deliberately minimize the volume of data we collect, gathering solely the information essential to deliver our design and AI automation consulting services, respond to inbound inquiries, and ensure digital infrastructure stability.

A. Contact Form Data (via /api/contact)

When you initiate a dialogue or request a consultation via our contact form, we collect:

  • Full Name
  • Work or Personal Email Address
  • Company / Organization Name (if provided)
  • Inquiry Message and Project Context
  • Submission timestamp and server origin reference

B. Funnel Form Data (via /api/leads)

When you navigate our project onboarding or lead funnel, we collect:

  • Full Name
  • Email Address
  • Phone / WhatsApp Contact Number
  • Project Need, Target Goals, and Functional Requirements
  • Project timeline and scoping notes

C. Analytics Events & Diagnostics (via /api/analytics/collect)

Our landing funnel utilizes lightweight, privacy-preserving behavioral beacons:

  • Aggregated Event Names: Page views (page_view), scroll depth markers (25%, 50%, 75%), funnel progression views (funnel_step_view), and form error telemetry.
  • Page Context: URL path (e.g. /, /about) and sanitized referring URL.
  • Session Identifiers: Ephemeral, randomized session IDs for single-visit flow attribution.

Important Notice: Our custom analytics mechanism does not store persistent tracking cookies, does not construct cross-site behavioural profiles, and does not sell or share event telemetry with ad brokers.

D. UTM Attribution & Anti-Spam Telemetry

We capture inbound campaign parameters (utm_source, utm_medium, utm_campaign) to measure advertising channel effectiveness. Additionally, incoming IP addresses are inspected temporarily for automated bot protection (honeypots, rate-limiting windows) and are not combined with personal profiling databases.

E. Typography Assets (Google Fonts)

Our site loads Google Fonts to deliver our editorial visual identity. When downloading font files, your browser establishes a connection with Google LLC servers, transmitting standard HTTP request headers (such as IP address and User-Agent) governed by Google's privacy policy.

02.How We Use Your Information

We process your personal information strictly for legitimate commercial and engineering purposes:

  • Inquiry Response & Communication: Answering questions, coordinating discovery calls, providing quotes, and discussing AI automation opportunities.
  • Proposal Architecture: Scoping custom software, designing web architectures, and drafting Master Services Agreements (MSAs) or Statements of Work (SOWs).
  • Client Project Execution: Delivering premium web builds, custom AI agents, API integrations, and workflow orchestrations.
  • System Security & Fraud Prevention: Operating honeypots, rate limiters, and threat filtering to protect our endpoints against spam bots, brute force, and abuse.
  • Legal & Tax Compliance: Maintaining statutory business records, accounting invoices, and tax filings in accordance with applicable Indian laws.

04.Data Sharing & Third Parties

Zero Commercial Sale Guarantee: Skyrn Studio does not sell, rent, lease, trade, or monetize your personal information to third parties, advertising networks, or data aggregators under any circumstances.

To deliver a robust web experience, we engage reputable third-party infrastructure providers who act as data processors bound by strict confidentiality and security covenants:

  • Vercel Inc. (Hosting & Edge Infrastructure): Our website and serverless API routes are hosted on Vercel. Vercel processes network requests and may deploy essential security and operational headers/cookies for edge routing, performance, and server telemetry.
  • Skyrn OS CRM (Internal System of Record): Validated lead funnel and analytics events are forwarded to our private, authenticated operational CRM (Skyrn OS) to centralize client onboarding and communication pipelines.
  • Workflow Automations (n8n Webhooks): Where configured, inbound contact requests may be securely transmitted through isolated n8n workflow bridges for internal instant notification (e.g. email or Slack alerts).
  • Google Fonts (Google LLC): Static font styling assets are served via Google's global Content Delivery Network.

Statutory Disclosures: We may disclose personal data if required to do so by applicable Indian or international law, court summons, or regulatory compliance directives issued by competent law enforcement agencies.

05.Data Security (Reasonable Security Practices)

In compliance with Section 43A of the Indian Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), Skyrn Studio has implemented a comprehensive information security framework tailored to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

1. Cryptographic ProtectionAll data in transit across our domain and API routes is enforced through Transport Layer Security (TLS 1.3 / HTTPS) with modern cipher suites.
2. Input Sanitization & DefenseServer-side validation strips all HTML tags and control characters to neutralize Cross-Site Scripting (XSS) and injection vulnerabilities.
3. Bot Detection & Rate LimitingMulti-tiered defenses including hidden honeypots, interaction timing tripwires, and in-memory IP rate limiting actively neutralize spam operations.
4. Environment IsolationAPI credentials, webhook secrets, and database tokens exist exclusively in secured server-side environment variables with strict least-privilege access.

06.Data Retention

We adhere to the principle of storage limitation. We retain personal data only for as long as necessary to fulfill the explicit purposes for which it was collected, or to comply with statutory legal mandates:

  • Inbound Inquiries & Lead Submissions: Retained for the duration of our active communication and up to twenty-four (24) months thereafter, after which data is purged or anonymized, unless converted into an active client contract.
  • Client Commercial & Invoicing Records: Retained for up to eight (8) years following project closure in compliance with Indian corporate, taxation (Income Tax Act, 1961), and audit statutory requirements.
  • Diagnostic & Analytics Logs: Telemetry logs in our OS CRM are held in aggregated or pseudonymous form for a maximum of twelve (12) months.

Under Section 8(7) of the DPDPA 2023, upon the withdrawal of consent or when the purpose for processing is no longer served, we systematically erase personal data unless retention is mandatory under Indian law.

07.Your Rights (DPDPA & GDPR)

Regardless of your geographical location, Skyrn Studio honors comprehensive data rights. We recognize the statutory rights guaranteed under the Indian Digital Personal Data Protection Act, 2023 (DPDPA) as well as the General Data Protection Regulation (GDPR).

IndiaRights under the DPDPA 2023

1. Right to Access Information (§ 11):Obtain a summary of your personal data being processed, the processing activities carried out, and the identities of third-party processors.
2. Right to Correction & Erasure (§ 12):Request correction of inaccurate or misleading data, complete incomplete records, or seek erasure of data no longer necessary for the purpose.
3. Right of Grievance Redressal (§ 13):Readily accessible grievance resolution directly with our designated Grievance Officer, with response within 30 days.
4. Right to Nominate (§ 14):Designate another individual to exercise your data principal rights in the event of death or incapacity.
5. Right to Withdraw Consent (§ 6(4)):Withdraw consent for marketing communications or inquiry processing at any point, with the same ease as granting consent.

EEA / UKRights under GDPR (International Visitors)

Right of Access (Art. 15):Request confirmation and a copy of personal data processed.
Right to Rectification (Art. 16):Rectify inaccurate or outdated personal details.
Right to Erasure (Art. 17):"Right to be forgotten" when processing is no longer required or consent is withdrawn.
Right to Data Portability (Art. 20):Receive your personal data in a structured, commonly used, machine-readable format.
Right to Restrict Processing (Art. 18):Limit how your data is processed during disputes or verification.
Right to Object (Art. 21):Object to processing carried out under legitimate interest or direct communications.

How to Exercise Your Rights

To exercise any of the rights listed above, please email our Grievance Officer at skyrn.studio@gmail.com with the subject line "Data Rights Request". We verify identity before fulfilling requests and respond within statutory timelines (within 30 days), free of charge.

08.International Data Transfers

Skyrn Studio is based and headquartered in India. However, because we utilize world-class distributed cloud infrastructure provided by Vercel Inc. and global technology providers, your information may be transferred to, processed, and stored on servers located outside of India, including in the United States and the European Union.

Where cross-border data transfers occur, we implement recognized transfer mechanisms—including standard contractual safeguards, data processing agreements, and compliance with rules notified under the Indian Digital Personal Data Protection Act, 2023—to guarantee that your personal data receives an equivalent standard of protection regardless of territorial processing.

09.Children's Privacy

Our services, consulting solutions, and digital offerings are exclusively intended for commercial enterprises, entrepreneurs, and individuals aged eighteen (18) years or older.

We do not knowingly collect, request, or retain personal information from minors under the age of 18 (as defined under the Indian Majority Act, 1875 and DPDPA 2023). If we become aware that personal information of a minor has been collected without verified parental or legal guardian consent, we take immediate corrective steps to expunge such data permanently from our systems. Parents or guardians who suspect such collection may contact us immediately at skyrn.studio@gmail.com.

10.Changes to This Policy

We may periodically revise this Privacy Policy to reflect modifications in our software architecture, consulting services, legal precedents, or guidelines issued by the Data Protection Board of India (DPBI).

Whenever changes are implemented, we will update the "Last Updated" date at the top of this document. We encourage you to review this page periodically. Continued engagement with our website or services following the publication of an updated Privacy Policy constitutes your acknowledgment of the revisions.

11.Grievance Officer

In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and Section 13 of the Digital Personal Data Protection Act, 2023 (DPDPA), the contact details of the designated Grievance Officer for Skyrn Studio are set forth below:

Designated Grievance Officer

Abhinav Rai

Founder & Data Protection Officer · Skyrn Studio

Statutory SLA: 30 Days
JurisdictionIndia
Postal Address[YOUR ADDRESS], India
Grievance Redressal Timeline: All submitted grievances, queries, or notices regarding data handling practices will be formally acknowledged within 48 hours and thoroughly addressed and resolved within thirty (30) calendar days in accordance with statutory guidelines.

12.Contact Information

For general inquiries, project discussions, or questions regarding this Privacy Policy, please reach out through any of our official channels:

Direct Inquiriesskyrn.studio@gmail.comExpect a response within 24 business hours
Physical Location[YOUR ADDRESS]India
Online Presenceskyrn-studio.vercel.appOfficial Website & Portal
Professional Networks