Legal
Privacy Policy
- Last reviewed August 14, 2026
Template — have counsel review before going live. This document is a structural starting point covering the sections a policy of this kind normally needs. It is not legal advice and it has not been reviewed against the specific regimes Ailoitte Technologies Private Limited operates under.
Who we are
This policy sets out how we collect and use your personal data through your use of leverge.ai, through any enquiry you send us, and in the course of an engagement we deliver for you.
Leverge is a brand of Ailoitte Technologies Private Limited, a company registered in India, and work contracted in the United States is delivered through Ailoitte LLC. Together we are "we", "us" and "our" in this policy. The entity that is controller of your personal data is the one you contracted with; if you have only visited this website, it is the India entity.
Questions about this policy, and requests to exercise any of the rights described below, go to the address in contact details. That address is also the route for a grievance under the India Digital Personal Data Protection Act 2023.
Types and sources of personal data
Personal data means information about a person from which that person can be identified. It does not include data that has been aggregated or stripped of identifiers so that it no longer points at anyone.
These are the categories we hold. The purposes table below refers back to them by name.
- Identity Data. Your name, job title or role, and the company you work for.
- Contact Data. Work email address, phone number where you give one, and a postal address for client billing.
- Technical Data. IP address, browser type and version, operating system, referring URL and timestamps, recorded in server access logs.
- Usage Data. Which pages were requested and in what order, from those same logs. Aggregate, not tied to a person.
- Enquiry Content. What you actually write to us — the project description on a form, and the correspondence that follows. Usually the most substantive thing we hold about you.
- Transaction Data. For clients only: billing entity details, invoices raised, and payments received against them.
- Marketing Data. Whether you asked us to send you something, and whether you have since told us to stop.
Categories a policy of this kind normally lists, which we do not hold — stated so you do not have to infer it from their absence:
- Profile Data. There is no account to create on this site and no login, so there is no username, password or saved profile.
- Financial Data. We take no card or bank details through this website. Client payments are invoiced and settled through our bank, and the card networks are never in the path.
- Special Category Data. Health, biometric, racial, political, religious or sexual-orientation data. We do not ask for any of it, and enquiry forms should not be used to send it.
Information you give us
Most of what we hold, you typed. That means the enquiry form on /book-a-call, the form on our contact page, and email or calls that follow — including anything you attach. During an engagement it also includes the working material a client's team shares with us: architecture notes, sample records, and the credentials issued to us for their systems.
Information we collect automatically
Less than you would expect. Analytics is switched off on this site, so no analytics script runs and no identifier is created for you. What is recorded is the standard access log our hosting provider keeps for every request — Technical Data and Usage Data as defined above. This site sets no cookies of its own; the cookie policy covers the one page where a third party may set its own.
Information from other sources
Business contact details from public professional sources, used only to reply to something you started — for example confirming which company an enquiry came from. Information a client gives us about their own staff, so we can work with those people. And the enquiry itself as it reaches us through HubSpot, which hosts that form.
We do not buy contact lists, we do not enrich enquiries against data brokers, and we do not build profiles of visitors to this site.
Lawful bases for processing personal data
Where the GDPR, the UK GDPR, or the India Digital Personal Data Protection Act 2023 applies, we process personal data on one of four bases.
- Performance of a contract. Delivering an engagement under a signed statement of work, and taking steps you have asked for before one exists.
- Legitimate interests. Our own or a third party's interests, where they are not overridden by your rights. The specific interests are named in the next section, and we weigh the effect on you before relying on this.
- Consent. Where we ask for it. You can withdraw it at any time, and withdrawing it does not affect what was lawful before you did.
- Legal obligation. Tax, accounting, statutory record-keeping, and responding to a lawful request from an authority.
Purposes of processing personal data
Every purpose we hold personal data for, which categories it touches, the basis we rely on, and how long it stays.
| Purpose | Type of data | Lawful basis | Retention |
|---|---|---|---|
| Responding to an enquiry or a request for a call, and the conversation that follows | Identity Data, Contact Data, Enquiry Content | Legitimate interests, and steps taken at your request before a contract | 24 months from our last contact, then deleted |
| Scoping a piece of work and putting a proposal together | Identity Data, Contact Data, Enquiry Content | Legitimate interests, and steps taken at your request before a contract | 24 months, or the engagement term if it becomes one |
| Delivering an engagement under a signed statement of work | Identity Data, Contact Data, Enquiry Content | Performance of a contract | The engagement term, then as that agreement specifies |
| Invoicing, accounting, and meeting tax obligations in India and the United States | Identity Data, Contact Data, Transaction Data | Legal obligation | Eight years, the longer of the two statutory minimums |
| Keeping the site and our systems secure, and investigating abuse of them | Technical Data, Usage Data | Legitimate interests | Access logs are held short-term by our hosting provider |
| Understanding which services are being asked about, in aggregate | Usage Data | Legitimate interests | Aggregate counts only; no individual record is kept for this |
| Sending you something you specifically asked us to send | Identity Data, Contact Data, Marketing Data | Consent | Until you withdraw it, then a suppression record so we do not send again |
| Maintaining our own records of approvals, agreements and access decisions | Identity Data, Contact Data, Transaction Data | Legal obligation, and legitimate interests | As contract and professional obligations require |
If we ever need to use your data for a purpose that is not on this list, we will tell you and explain the basis before we do it.
Our legitimate interests
Where the table above says legitimate interests, these are the interests. In each case we have asked whether a business contact would reasonably expect it.
- Replying to enquiries, and keeping a record of them. Someone who writes to a company expects a reply and expects the thread to still exist next month.
- Understanding what is being asked about. In aggregate, so we describe our services accurately rather than guessing which ones matter.
- Securing the site and our systems. Detecting abuse, blocking it, and investigating it afterwards.
- Running the business. Knowing who approved what, which agreements are in force, and who has access to which client environment.
You can object to any of it — see your rights. We run no marketing sequences, so there is no list you can be added to without asking.
When we act as a processor rather than a controller
During an engagement we routinely handle data that belongs to the client, which can include personal data about their customers, patients or employees. In that role we are a processor: we act on the client's documented instructions, under the data processing agreement for that engagement, and we do not use the data for any purpose of our own.
Because it is the first question every AI engagement raises: we do not use client data to train, fine-tune or improve any model, for ourselves or anyone else. Where an engagement involves a third-party model provider, the architecture and its retention terms are agreed in writing, and our default is zero-retention with training disabled.
If you are an individual whose data we hold in this role, your rights are exercised against the client, who is the controller. Send the request to us and we will pass it to them.
Connected systems in an engagement
The agents we build read from and write to systems a client already runs. What follows describes that access, because it is the part of our work that touches the most personal data and the part a reader cannot see from the outside.
What we access
Only what the workflow being built requires, and only in the client's own tenant. Depending on the engagement that can include document and file storage, spreadsheets, a CRM, a ticketing system, an ERP, a data warehouse, or a mailbox. Access is granted by the client through their own administration console, scoped to the accounts and records the workflow needs, and it is read-only unless the workflow has to write — in which case the write path goes through a named human approver before anything is committed.
How we use it
To build, test and operate the workflow the client asked for, and to investigate a fault when they ask us to. Not to train models, not to develop our own products, not for any purpose outside that engagement, and never shared onward except to a sub-processor named in that engagement's agreement. Access is time-bound and revoked at the end of the engagement, and the client can revoke it themselves at any point without going through us.
Sharing of personal data
We share personal data with three kinds of recipient, and no others.
- Service providers acting on our instructions. HubSpot, which hosts the enquiry form on /book-a-call and stores what is submitted through it. Google, whose reCAPTCHA Enterprise service runs on that form to stop automated abuse, and which therefore receives your IP address and interaction signals for that page. Amazon Web Services, which hosts this site and serves it through the CloudFront content delivery network, and whose access logs are the ones described above. And our email provider. Each is contractually bound to process data only as we instruct and to keep it secure.
- Professional advisers and authorities. Accountants, auditors and lawyers under duties of confidence, and regulators, courts or law enforcement where we are legally required to disclose.
- An acquirer, if the business or part of it is sold or reorganised, on condition that the same protections continue to apply.
We would ask your express consent before sharing your personal data with any third party for that party's own marketing, and we have never had reason to ask. We do not sell personal data and we do not share it for cross-context behavioural advertising.
The sub-processors used in a specific engagement are listed for that client on request.
International data transfers
We operate from India and the United States, so data we hold may be processed in either, and the service providers named above — HubSpot, Google, AWS — process data in the United States. Some of those countries do not give personal data the protection that UK and EU law does.
Where a transfer out of the UK or EEA needs a legal mechanism we use the UK or EU standard contractual clauses, or an equivalent safeguard such as an adequacy decision or the applicable data bridge, together with whatever additional measures the transfer risk assessment calls for. Where an engagement carries a data residency requirement, we design the system to keep the data inside that jurisdiction rather than transfer it and rely on paperwork.
Data retention
We keep personal data only while there is a reason to, and the reasons and periods are in the purposes table above rather than described in general terms here. Enquiry correspondence goes 24 months after our last contact unless it became an engagement. Engagement records are kept for the period that contract and our tax and professional obligations require. Client data processed under an engagement is returned or deleted on termination as that agreement specifies. When a period ends we delete the data or irreversibly anonymise it.
Data security
Access is granted on a least-privilege basis and reviewed periodically. Data is encrypted in transit and at rest, administrative access is logged, and credentials a client issues to us are held in a secrets manager — never in code, a ticket or a chat message. Where a client prefers it, our engineers work inside the client's own environment so the data never crosses their perimeter.
No system is perfectly secure. Where a personal data breach is likely to affect you we will tell you and the relevant regulator within the deadline the applicable law sets.
Automated decision-making
We build automated decision systems for a living, which is why this section is worth reading rather than skipping: we do not point any of them at you. Nothing on this site scores, ranks or profiles visitors, and no decision about whether we reply to your enquiry, or on what terms, is made without a person. You are not subject to a decision based solely on automated processing that has a legal or similarly significant effect on you.
Inside an engagement, the agents we build do make automated decisions as part of the client's workflow, and may process personal data in doing so. What such a system is permitted to decide, and where a human approver sits in the chain, is defined by the client and written into that engagement. Where we advise on the design, an irreversible action always has a named approver.
Sensitive personal data
We do not ask for special category or sensitive personal data through this website, and enquiry forms should not be used to send it. Where an engagement necessarily involves such data — a clinical documentation system, for example — it is handled as client data under that engagement's agreement, with the additional controls that agreement sets.
Children's privacy
Our services are directed at businesses, not consumers, and never at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, write to us and we will delete it.
Your data protection rights
Depending on where you live, you have some or all of the following rights.
- Access. Ask what personal data we hold about you and get a copy of it, together with confirmation of why we hold it and who it has been shared with.
- Rectification. Have anything inaccurate corrected, and anything incomplete completed. If we have shared the inaccurate version with a service provider we will tell them too.
- Erasure. Have data deleted where we no longer have a reason to hold it. We may have to refuse in part — invoices and engagement records are held under tax and professional obligations — and we will say which parts and why rather than refuse the whole request.
- Objection. Object to any processing we base on legitimate interests, including the record-keeping described above. We stop unless we can show grounds that override yours, and we explain what those are. Where you object to direct marketing there is no balancing test: we stop.
- Restriction. Have us pause processing rather than delete — while an accuracy dispute is resolved, where processing was unlawful but you want the data kept, where you need it kept for a legal claim of your own, or while we consider an objection.
- Portability. Receive the data you gave us in a structured, machine-readable format, or have us send it directly to someone else. This applies to data you provided under consent or a contract, which in practice means your enquiry and correspondence.
- Withdrawing consent. Withdraw consent at any time where consent is what we relied on. That does not make the earlier processing unlawful, and it does not affect anything we hold on another basis.
- Nominating someone. Have another person exercise these rights for you, where the law that applies to you provides for it — including a nominee under the India Digital Personal Data Protection Act 2023.
To exercise any of them, write to the address in contact details. There is no fee. We may ask for specific information to confirm who you are before we act — usually by replying to an address we already hold — because handing personal data to the wrong person is the failure mode this check exists to prevent. If a request is clearly unfounded, repetitive or excessive we may charge a reasonable fee or decline it, and we will say which and why.
We aim to respond within one month, which is the GDPR deadline. If a request is complex, or you have made several, it may take longer — in which case we will tell you inside that month and keep you updated. Exercising a right never costs you a worse service from us.
Right to lodge a complaint
We would rather hear it first, and we would appreciate the chance to put it right before you go elsewhere. But you can complain to a regulator instead of or as well as to us: in the EEA, the data protection authority where you live or work; in the UK, the Information Commissioner's Office ; in India, the Data Protection Board of India; and in the United States, your state attorney general where your state's privacy law provides for it.
If you choose not to provide certain information
Everything an enquiry form asks for, apart from your phone number, is something we need in order to reply — we cannot answer a question about your systems without knowing what they are, or send the answer without somewhere to send it. You are free to withhold any of it, and free to email us directly instead of using a form. The only consequence is that we may not be able to respond usefully, and we will say so rather than guess.
Contact details
For any question about this policy, any request to exercise a right, or any grievance:
- Email: privacy@ailoitte.com
- Post, India (Ailoitte Technologies Private Limited): L-148, 5th Main Road, Sector 6, HSR Layout, Bengaluru, Karnataka 560102, India
- Post, United States (Ailoitte LLC): 8 The Green, STE R, Dover, DE 19901, United States
- Telephone: +91-72510-27270 (India), +1-302-608-0009 (United States)
Changes to this privacy policy
We keep this policy under review, and the date below changes when it changes. Where a change materially affects how we handle data we already hold, we tell affected clients directly rather than rely on anyone noticing a new date.
It also matters that what we hold about you stays accurate — if your email address or company changes during an engagement, tell us and we will update it.
Contact
Questions about this policy should go to privacy@ailoitte.com.
Last reviewed: