Who We Are
RoboInfocom Private Limited ("RoboInfocom", "we", "us" or "our") is an enterprise AI and digital transformation company headquartered in Pune, India, with offices in Bengaluru (India), Dublin (Ireland), London (United Kingdom), and Austin (United States of America).
We are the data controller for personal data processed in connection with our website, marketing activities, client engagements, recruitment, and internal operations. For data processed on behalf of clients as part of contracted services, we act as a data processor.
This Privacy Policy applies to all websites operated by RoboInfocom (including roboinfocom.com and associated subdomains), our client-facing platforms, our recruitment portal, and any other interaction where we collect personal data.
Data We Collect
We collect personal data only where necessary and proportionate to our legitimate purposes. The categories of data we collect depend on your relationship with us:
2.1 Website Visitors
- IP address and approximate geographic location (country/city level)
- Browser type, version, and operating system
- Pages visited, referral source, and time spent on pages
- Cookie identifiers (see Section 7 for full details)
- Contact form submissions — name, email address, company, and message content
2.2 Clients & Prospective Clients
- Business contact details: name, job title, work email, phone number, company name
- Contract and commercial information: proposal details, signed agreements, invoicing data
- Communications: emails, meeting notes, call recordings (where consented)
- Technical data shared for delivery purposes: system access credentials, environment details
2.3 Job Applicants & Employees
- Identity data: full name, date of birth, national ID (where required by law)
- Contact details: home address, personal email, phone number
- Professional data: CV/résumé, work history, education, certifications, references
- Compensation and benefits information (employees only)
- Background check results (where legally permitted and consented)
2.4 Data We Do Not Collect
How We Use Your Data
We use personal data for the following purposes:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Responding to enquiries and contact form submissions | Name, email, message content | Legitimate interest / Pre-contractual |
| Delivering contracted services to clients | Business contact, technical, commercial data | Contract performance |
| Sending marketing communications | Email, name, company, preferences | Consent / Legitimate interest |
| Processing job applications and recruitment | CV, contact, professional data | Pre-contractual / Consent |
| Improving website experience and analytics | IP address, cookies, usage data | Consent / Legitimate interest |
| Compliance with legal obligations | Identity, financial, contractual data | Legal obligation |
| Fraud prevention and security monitoring | IP address, login data, usage patterns | Legitimate interest |
| Employee HR management and payroll | Identity, compensation, attendance data | Contract performance / Legal obligation |
We will never sell your personal data to third parties. We will never use your data for automated decision-making or profiling that produces significant legal effects without your explicit consent.
Legal Basis for Processing
Under GDPR (Article 6) and India's Digital Personal Data Protection Act 2023, we rely on the following lawful bases:
- Contract Performance — Processing is necessary to perform a contract with you or to take pre-contractual steps at your request (e.g., delivering services, processing employment agreements).
- Legal Obligation — Processing is required to comply with a legal obligation (e.g., tax reporting, regulatory requirements, employment law).
- Legitimate Interest — Processing is necessary for our legitimate business interests, provided these are not overridden by your rights and freedoms. We conduct a Legitimate Interests Assessment (LIA) before relying on this basis.
- Consent — Where we rely on consent, you have the right to withdraw it at any time by contacting us at privacy@roboinfocom.com. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Vital Interests — In rare emergencies where processing is necessary to protect someone's life.
Data Sharing & Disclosure
We do not sell, rent or trade your personal data. We share data only in the circumstances below, and only with appropriate contractual protections in place:
5.1 Service Providers & Sub-processors
We engage trusted third-party processors to support our operations. All sub-processors are bound by Data Processing Agreements (DPAs) requiring GDPR-equivalent protections:
5.2 Business Partners
Where delivery of services requires collaboration with Microsoft, ServiceNow, UiPath, or Murex (our certified technology partners), we may share relevant contact information necessary for licence management, certification, or support escalation. We will inform you where this is the case.
5.3 Legal & Regulatory Disclosure
We may disclose personal data to law enforcement, regulatory authorities, or courts where required by applicable law, or where necessary to protect the rights, property, or safety of RoboInfocom, our clients, or others.
5.4 Corporate Transactions
In the event of a merger, acquisition, restructuring or sale of assets, personal data may be transferred to a successor entity, subject to equivalent privacy protections. We will provide notice before any such transfer where required by law.
International Data Transfers
RoboInfocom operates globally with offices in India, Ireland (EU), the UK, and the USA. As a result, personal data may be transferred between these jurisdictions in the course of our operations.
Transfers from the European Economic Area (EEA)
For transfers of personal data from the EEA to countries without an EU adequacy decision (including India and the USA), we rely on:
- Standard Contractual Clauses (SCCs) — EU Commission-approved SCCs are incorporated into our contracts with data importers
- UK International Data Transfer Agreements (IDTAs) — for transfers from the United Kingdom
- Binding Corporate Rules (BCRs) — under development for intra-group transfers
Transfers from India
For transfers of personal data outside India, we comply with the cross-border transfer provisions of the Digital Personal Data Protection Act 2023 and any Rules or Government notifications issued thereunder.
Cookies & Tracking Technologies
Our website uses cookies and similar technologies to provide functionality, understand usage patterns, and deliver relevant content. You can manage your cookie preferences at any time through our Cookie Preference Centre.
| Category | Purpose | Basis | Retention |
|---|---|---|---|
| Strictly Necessary | Core website functionality, security, session management. Cannot be disabled. | Legitimate interest | Session / 1 year |
| Performance & Analytics | Anonymised usage statistics (Google Analytics, Azure Application Insights). Helps us improve the site. | Consent | Up to 2 years |
| Functional | Remembering your preferences, language settings, and form data. | Consent | Up to 1 year |
| Marketing | LinkedIn Insight Tag, Microsoft Advertising, retargeting. Used to measure ad effectiveness. | Consent | Up to 90 days |
Managing Your Cookie Preferences
You can withdraw or adjust cookie consent at any time by:
- Clicking "Cookie Settings" in the footer of any page on our website
- Using your browser settings to block or delete cookies
- Using the opt-out mechanisms provided by Google (Google Analytics Opt-out) and LinkedIn
Disabling non-essential cookies will not affect your ability to use our website, but may reduce personalisation features.
Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. Our retention schedule:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Website enquiry / contact form | 3 years from last contact | Legitimate interest in business development |
| Client contract data | 7 years from contract end | Legal obligation (tax, audit, regulatory) |
| Marketing email subscribers | Until unsubscription + 90 days | Consent-based — deleted upon withdrawal |
| Job applications (unsuccessful) | 12 months from decision | Legitimate interest in future recruitment |
| Employee records | 7 years post-employment | Legal obligation (employment law, tax) |
| Website analytics (cookies) | Up to 26 months | Industry standard analytics retention |
| Security logs | 12 months | ISO 27001 security monitoring requirements |
When data reaches the end of its retention period, it is securely deleted or anonymised in accordance with our Data Destruction Policy (ISO 27001, Annex A.8).
Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data. We will respond to all verified requests within 30 days (GDPR) or within the timescales specified under applicable law.
| Right | What It Means | GDPR | DPDPA |
|---|---|---|---|
| Access (Right to Know) | Request a copy of personal data we hold about you and information on how it is used | ✓ Art. 15 | ✓ Sec. 11 |
| Rectification | Request correction of inaccurate or incomplete data | ✓ Art. 16 | ✓ Sec. 12 |
| Erasure (Right to be Forgotten) | Request deletion of your personal data (subject to legal retention obligations) | ✓ Art. 17 | ✓ Sec. 12 |
| Restriction of Processing | Request that we limit processing of your data in certain circumstances | ✓ Art. 18 | — |
| Data Portability | Receive your data in a structured, machine-readable format | ✓ Art. 20 | — |
| Objection | Object to processing based on legitimate interests or for direct marketing | ✓ Art. 21 | — |
| Withdraw Consent | Withdraw previously given consent at any time without affecting past processing | ✓ Art. 7(3) | ✓ Sec. 6 |
| Nominate a Data Nominee | Nominate another person to exercise rights on your behalf in case of death or incapacity | — | ✓ Sec. 14 |
| Grievance Redressal | Lodge a complaint with our Data Protection Officer | ✓ | ✓ Sec. 13 |
How to Exercise Your Rights
Submit a Data Subject Request (DSR) by emailing privacy@roboinfocom.com with the subject line "Data Subject Request" and your full name, the nature of your request, and proof of identity. We may need to verify your identity before processing your request.
Right to Complain
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:
- EU/EEA: Your local Data Protection Authority (DPA), e.g., the Irish Data Protection Commission (DPC) for Ireland-based processing.
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- India: Data Protection Board of India (once operational under DPDPA 2023)
Security Measures
RoboInfocom is ISO 27001 certified and maintains a comprehensive Information Security Management System (ISMS). Our technical and organisational security measures include:
- Encryption at rest and in transit — AES-256 encryption for stored data; TLS 1.3 for all data in transit
- Access controls — Role-based access control (RBAC), multi-factor authentication (MFA), and least-privilege principles
- Network security — Firewalls, intrusion detection/prevention systems, and Cloudflare DDoS protection
- Vulnerability management — Regular penetration testing, vulnerability scanning, and security patch management
- Incident response — Documented breach response procedures; notification to supervisory authorities within 72 hours as required by GDPR
- Staff training — All employees receive mandatory information security and data protection training annually
- Vendor security — Due diligence assessments and contractual security requirements for all sub-processors
Children's Privacy
Our website and services are directed exclusively at business professionals and are not intended for, and should not be used by, persons under the age of 18 (or the applicable age of digital consent in your jurisdiction).
We do not knowingly collect or process personal data from children. If we become aware that a child has provided us with personal data without verifiable parental consent, we will delete that data immediately. If you believe we have inadvertently collected data from a child, please contact privacy@roboinfocom.com.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
- Update the "Last updated" date at the top of this policy
- Notify registered subscribers via email (where we have your address)
- Display a prominent notice on our website for 30 days following material changes
We encourage you to review this policy periodically. Your continued use of our services after any changes constitutes acceptance of the updated policy, subject to applicable law.
Previous versions of this Privacy Policy are available on request by emailing privacy@roboinfocom.com.
Contact Our Data Protection Team
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact our Data Protection Officer: