Privacy Policy

1.) Introduction

Blutrain Private Limited ("Blutrain", "we", "us", or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website theblutrain.com, engage our services, or interact with us in any capacity.

By accessing our website or using our services — including AI solutions, data analytics, machine learning, natural language processing, computer vision, and related technology services — you acknowledge that you have read, understood, and agree to this Privacy Policy.

Important: If you do not agree with the terms of this Privacy Policy, please discontinue use of our website and services and contact us to discuss your concerns.

2.) Who We Are

Blutrain Private Limited is an Artificial Intelligence and technology solutions company registered under the Companies Act, 2013, providing services including:

  • Data Analytics and Business Intelligence
  • Machine Learning and Deep Learning Solutions
  • Natural Language Processing (NLP)
  • Computer Vision and Image Recognition
  • Predictive Maintenance and Risk Management
  • Personalized Recommendation Systems
  • Supply Chain Optimization
  • Customer Insights and Behaviour Analytics
  • AI-Powered Web, Mobile, and Software Development

Data Controller

Blutrain Private Limited acts as the Data Controller for personal data collected through our website and during client engagements. For data processed on behalf of our clients as part of project delivery, we act as a Data Processor.

Registered Address: SCF 08, 2nd Floor, The Eminence Plaza, Ambala–Chandigarh Expy, Zirakpur, Punjab 140603, India

3.) Information We Collect

We collect several categories of information depending on how you interact with us:

3.1 Information You Provide Directly

  • Contact Information: Name, email address, phone number, company name
  • Query & Project Details: Service requirements, budget range, project timeline, uploaded documents (RFPs, briefs)
  • Billing & Financial Information: GST number, billing address, payment details (processed via secure payment gateways — we do not store card data)
  • Account Credentials: Username, password (hashed), and profile information for client portal access
  • Communication Records: Emails, support tickets, chat logs, and meeting notes
  • Feedback & Reviews: Testimonials, satisfaction ratings, survey responses

3.2 Information Collected Automatically

  • Log Data: IP address, browser type, operating system, referring URL, pages visited, time and duration of visit
  • Device Information: Device ID, screen resolution, language settings
  • Usage Data: Features accessed, clicks, scroll depth, and navigation patterns on our website
  • Cookies & Tracking Pixels: Session identifiers, preference cookies, analytics data (see Section 7)

3.3 Information from Third Parties

  • Referral information from partners, affiliates, or third-party platforms
  • Social media profile data if you connect your account or interact with our social pages
  • Business information from public directories or professional networks (e.g., LinkedIn) for B2B outreach
  • Payment verification data from financial institutions and payment processors

3.4 Project & Client Data

As part of delivering AI solutions and technology services, we may process data that you share with us, including datasets for model training, business process data, customer records, or operational data. This is governed by your service agreement and treated with the highest confidentiality.

4.) How We Use Your Information

Purpose Data Used Basis
Responding to enquiries and queries Contact info, query details Legitimate interest / Contract
Generating proforma invoices and proposals Contact, company, service details Contract performance
Creating and managing customer accounts All contact & billing data Contract performance
Delivering AI & technology services Project data, credentials Contract performance
Processing payments and issuing invoices Billing & financial data Contract / Legal obligation
Sending project updates and milestone notifications Contact info, project data Contract / Legitimate interest
Providing technical support and resolving tickets Contact info, support history Contract / Legitimate interest
Marketing communications (with consent) Email, company info Consent
Website analytics and improvement Log data, cookies, usage data Legitimate interest
Legal compliance and dispute resolution All relevant data Legal obligation
Security and fraud prevention Log data, IP, account activity Legitimate interest / Legal obligation

We do not sell your personal data. We do not trade, sell, rent, or share your personal information with third parties for their marketing purposes without your explicit consent.

5.) Legal Basis for Processing

Our processing of personal data is governed by the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) and applicable Indian law.

  • Consent: Where you have expressly provided consent for specific uses such as marketing communications or cookie placement
  • Contract Performance: Where processing is necessary to deliver services you have engaged us for, including project execution, billing, and client portal access
  • Legal Obligation: Where we are required to process data under applicable Indian laws, tax regulations, or court orders
  • Legitimate Interests: Where processing serves our legitimate business interests such as improving our services, website analytics, security monitoring, and relationship management — where these do not override your fundamental rights

6.) Data Sharing & Disclosure

We may share your personal data with the following categories of recipients, strictly for the purposes stated in this policy:

6.1 Service Providers & Technology Partners

  • Cloud Infrastructure: AWS, Google Cloud, or Microsoft Azure for hosting and data storage
  • Payment Processors: Razorpay, PayU, or equivalent for secure payment processing
  • Communication Tools: Email delivery services (SendGrid, Mailchimp), WhatsApp Business API
  • Analytics: Google Analytics, Hotjar, or equivalent for website behaviour analysis
  • CRM & Project Tools: Internal project management and CRM systems
  • AI & ML Platforms: OpenAI, Hugging Face, or equivalent used in project delivery

6.2 Legal & Regulatory Disclosure

We may disclose your information where required by law, court order, regulatory authority, or to protect the rights, property, or safety of Blutrain, our clients, or the public.

6.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred as part of that transaction. We will notify affected parties as required by law.

6.4 With Your Consent

We may share your data with other parties where you have provided explicit prior consent to do so.

All third-party service providers are contractually bound to handle your data confidentially and in compliance with applicable privacy laws. We conduct due diligence before engaging any data processor.

7.) Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our website. You can control cookie preferences through your browser settings.

Cookie Type Purpose Duration
Essential / Functional Enable core website functionality, session management, login state Session
Analytics Track visitor behaviour, page performance, and usage patterns (Google Analytics) Up to 2 years
Preference Remember your settings such as language, region, or display preferences Up to 1 year
Marketing Deliver relevant advertisements and measure ad campaign performance Up to 90 days

You may disable non-essential cookies at any time through your browser settings or our cookie preference centre. Note that disabling essential cookies may impair website functionality.

8.) AI & Automated Processing

As an AI-focused company, some of our services involve automated data processing, including machine learning model training, predictive analytics, and AI-driven decision support. We are committed to responsible AI use.

  • Client data used for AI model training is strictly governed by your service agreement and processed only with explicit authorization
  • We do not use client data shared in a confidential project context for training our own general-purpose AI models without written consent
  • Automated decisions with significant impact on individuals are subject to human oversight and review
  • We maintain audit logs of AI processing activities as part of our data governance framework
  • Our AI systems are designed to minimize bias and we conduct periodic fairness and accuracy evaluations

Website AI Features: If we use AI-powered chatbots, recommendation engines, or lead scoring on our website, these are disclosed at the point of use and you retain the right to opt out of automated profiling.

9.) Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements.

Data Category Retention Period Reason
Client contact & account data Duration of relationship + 5 years Contract & legal obligations
Financial records & invoices 7 years Income Tax Act & GST compliance
Project & delivery data 5 years post-project Warranty, disputes, and reference
Support tickets & communications 3 years Dispute resolution & quality review
Website analytics data 26 months Google Analytics default
Marketing consent records Until consent withdrawn + 2 years Compliance evidence
Prospective client queries 2 years from last contact Business development

Upon expiry of the retention period, data is securely deleted or anonymized. You may request earlier deletion subject to legal obligations (see Section 11).

10.) Data Security

Blutrain Private Limited implements comprehensive technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

Technical Measures

  • SSL/TLS encryption for all data in transit (HTTPS enforced site-wide)
  • AES-256 encryption for sensitive data at rest
  • Role-based access controls (RBAC) limiting data access to authorized personnel only
  • Multi-factor authentication (MFA) for all internal systems and client portals
  • Regular security audits, vulnerability assessments, and penetration testing
  • Automated intrusion detection and real-time monitoring systems
  • Secure, isolated development and production environments

Organizational Measures

  • Data privacy training for all team members with access to personal data
  • Strict non-disclosure agreements (NDAs) with all employees and contractors
  • Data breach response plan with defined notification timelines
  • Periodic data protection impact assessments (DPIAs) for high-risk processing activities

While we employ best-in-class security practices, no method of electronic transmission or storage is 100% secure. In the unlikely event of a data breach, we will notify affected parties as required by applicable law.

11.) Your Privacy Rights

Subject to applicable Indian law and our legal obligations, you have the following rights regarding your personal data:

👁
Right to Access
Request a copy of personal data we hold about you
✏️
Right to Rectification
Correct inaccurate or incomplete personal data
🗑️
Right to Erasure
Request deletion of data where no longer necessary
⏸️
Right to Restriction
Restrict processing in certain circumstances
📦
Right to Portability
Receive your data in a structured, machine-readable format
🚫
Right to Object
Object to processing for direct marketing or profiling
🔄
Right to Withdraw Consent
Withdraw consent at any time for consent-based processing
📋
Right to Complain
Lodge a complaint with our Grievance Officer or relevant authority

To exercise any of these rights, please contact us at support@theblutrain.com. We will respond within 30 days. We may require identity verification before processing your request.

12.) Third-Party Links & Integrations

Our website and services may contain links to third-party websites, tools, and integrations. These include but are not limited to payment gateways, cloud platforms, social media pages, and partner websites.

We are not responsible for the privacy practices of third-party platforms. We encourage you to review the privacy policies of any third-party services you access through our platform. Our policy applies only to information collected directly by Blutrain Private Limited.

13.) Children's Privacy

Our services are directed exclusively to businesses and individuals aged 18 years and above. We do not knowingly collect or process personal data of individuals under the age of 18.

If we become aware that we have inadvertently collected personal data from a minor, we will take immediate steps to delete such data. If you believe we may have collected data from a minor, please contact us at support@theblutrain.com immediately.

14.) International Data Transfers

Our primary operations and data storage are located in India. However, as an AI and technology company, we may use cloud infrastructure, AI platforms, or service providers based in other countries (such as the United States, EU member states, or Singapore).

Where personal data is transferred internationally, we ensure that:

  • The receiving country provides an adequate level of data protection, or
  • Appropriate safeguards are in place such as standard contractual clauses (SCCs), data processing agreements (DPAs), or equivalent protections
  • The transfer is necessary for the performance of your service contract with us

15.) Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or business practices. We will notify you of material changes by:

  • Posting the updated policy on this page with a revised "Last Updated" date
  • Sending an email notification to registered clients
  • Displaying a prominent notice on our website for 30 days following significant changes

Your continued use of our website or services following notification of changes constitutes your acceptance of the revised Privacy Policy.

16.) Contact Us & Grievance Officer

As required under the Information Technology Act, 2000 and SPDI Rules, 2011, we have appointed a Grievance Officer to address your data privacy concerns.

Blutrain Private Limited

Email:- support@theblutrain.com
Website:- www.theblutrain.com
Address:- SCF 08, 2nd Floor, The Eminence Plaza, Ambala–Chandigarh Expressway, Zirakpur, Punjab 140603, India