Privacy notice

How HMR Infotech collects, uses and protects personal data on this website.

Version 1.0 · Last reviewed 2026-09-27

This notice explains what personal data HMR Infotech collects through this website, why, who else handles it, how long we keep it and what you can ask us to do with it. It applies to hmrinfotech.com only. When we work on a client project, the contract for that project sets out how client data is handled.

Who we are

HMR Infotech Private Limited (CIN U62099UP2024PTC207412), registered office B 501, Flora Heritage, Bisrakh, Gautam Buddha Nagar 201306, Uttar Pradesh, India, is the Data Fiduciary (under India's Digital Personal Data Protection Act, 2023) and the controller (under the EU and UK GDPR) for the data described here. In this notice "HMR", "we" and "us" mean HMR Infotech Private Limited.

For any question about this notice or your data, write to privacy@hmrinfotech.com or by post to our Grievance Officer at the address above. You can also call +91-7906749546.

What we collect and why

We collect only what you type into a form, plus a small amount of technical data needed to deliver it safely.

Form What we ask for Why we use it
Readiness audit Name, work email, company, job title, role, company size, industry, country, focus areas, timeline, optional notes To assess your request, prepare for the audit and contact you about it
Contact Name, work email, company, topic, message To answer your message
Specialist talent request Name, work email, company, skills, seniority, headcount, start date, location, duration To respond with suitable engineers
HMReach demo Work email, monthly message volume To arrange a product demo
Security pack Name, work email, company, reason for the request To decide whether to share our security documentation with you, and to send it
Newsletter and downloads Email address, and which asset you asked for To send what you asked for, and the newsletter if you opted in

With each form we also record the page you sent it from, the referring page and any campaign tags in the link (such as utm_source), the version of the consent text you saw, and the time. Cloudflare Turnstile checks that a person, not a bot, sent the form; to do this it processes your IP address and browser signals.

We do not ask for sensitive data such as health, financial or identity-document details, and we ask you not to include them in free-text fields.

Our legal basis

  • India (DPDP Act 2023): we process your data on the basis of the consent you give when you submit a form (section 6), and for the purpose you gave it for. Security checks against bots and abuse rely on legitimate uses under section 7 where the Act allows.
  • EU and UK (GDPR): we rely on steps you ask us to take before a possible contract (Article 6(1)(b)) for audit, contact, talent and demo requests; on your consent (Article 6(1)(a)) for the newsletter and analytics; and on our legitimate interest in keeping the site secure (Article 6(1)(f)) for bot checks and security logs.

You can withdraw consent at any time, as easily as you gave it. Withdrawal does not affect processing that already happened.

Where your data goes

When you submit a form, our website service (running on Cloudflare) checks it and writes it to a Google Sheet in HMR's own Google Workspace account. Only HMR staff who handle enquiries can open that sheet. We use these service providers, each under its own data processing terms:

Provider What it does for us Where it may process data
Cloudflare, Inc. Hosting, security, bot checks (Turnstile), cookieless web analytics, temporary form storage Global network, including the US and India
Google LLC (Google Workspace) Stores enquiries in a Google Sheet; our email US, EU, India and other Google regions
Resend, Inc. Sends confirmation and notification emails United States
Cal.com, Inc. Booking calendar when you pick a meeting time United States and EU

We do not sell personal data and we do not share it with advertisers.

Transfers outside India

Some providers above process data outside India. We transfer data only to countries not restricted by the Government of India under section 16 of the DPDP Act. For visitors in the EU or UK, transfers to the US rely on the provider's certification under the EU-US Data Privacy Framework (and UK extension) where it holds one, or on the European Commission's Standard Contractual Clauses.

How long we keep it

  • Website copy: our website service keeps a copy of each form only until the Google Sheet confirms it has the entry, and then for 7 days as a safety net. After that the personal fields are deleted automatically.
  • Enquiries in the Google Sheet: 24 months from our last contact with you, then deleted, unless the enquiry became a contract, in which case the contract's retention terms apply.
  • Newsletter: until you unsubscribe. Every newsletter has an unsubscribe link.
  • Security pack requests: 24 months, as a record of who received the documentation.
  • Security logs: up to 90 days.

Your rights

Under the DPDP Act you can ask us for a summary of the personal data we hold about you and how we use it, ask us to correct, complete, update or erase it, withdraw consent, nominate someone to exercise your rights if you die or become unable to, and have a grievance addressed. Under the GDPR you also have the rights to restrict or object to processing and to data portability.

Write to privacy@hmrinfotech.com and tell us what you would like. We may ask you to confirm your identity. We reply within 30 days, and sooner where we can.

If you are not satisfied with our answer, you can complain to the Data Protection Board of India once you have used our grievance process. In the EU or UK you can complain to your local data protection authority.

Children

This website is for businesses and professionals. It is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a child has sent us data, write to us and we will delete it.

Security

Data travels only over encrypted connections. Access to enquiries is limited to named HMR staff with multi-factor sign-in. You can read more on our Security and compliance page.

Changes to this notice

When we change this notice we update the version and date below it. If a change affects how we use data you have already given us, we will tell you before it applies.