← Privacy Settings

PRIVACY POLICY

Selective AI Pvt. Ltd. | Mindgraph AI

Version 1.0 | Effective Date: September 24, 2026 | Last Updated: September 24, 2026

Your privacy matters to us. This Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have. It applies to our clients, contractors, employees, website visitors, and job applicants. If you have questions, contact our Grievance Officer at the details in Section 14.

1. WHO WE ARE

Selective AI Pvt. Ltd., operating under the brand Mindgraph AI, is a technology and artificial intelligence services company registered in India. We provide software development, AI/ML, and related services to businesses. For the purposes of data protection law, we are the Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 (“DPDPA”).

Legal EntitySelective AI Pvt. Ltd.
Brand NameMindgraph AI — www.mgraph.dev
CINU62011WB2025PTC276107
Registered AddressBL-A, 3rd Floor, FL-C-303 2, Mahatma Gandhi Road, Joka, Amgachi, South 24 Parganas, West Bengal, India.
Grievance Officer Emailhello@mgraph.dev

2. WHO THIS POLICY APPLIES TO

This Privacy Policy applies to all individuals whose personal data we process, including:

  • Current and prospective clients and their authorised representatives
  • Employees, whether full-time, part-time, or on probation
  • Freelancers, contractors, subcontractors, and agency personnel engaged by us
  • Job applicants and candidates
  • Visitors to our website (www.mgraph.dev)
  • Any other person who contacts us or whose data we receive in connection with our business

This Policy applies to personal data we collect and process in both digital and physical formats.

3. WHAT PERSONAL DATA WE COLLECT & HOW WE USE IT

The table below sets out the categories of personal data we collect, the purposes for which we use it, and how long we keep it. We collect only what is necessary for the stated purpose.

CategoryTypes of Data CollectedPurpose(s)Retention
Clients & Their RepresentativesName, job title, email, phone, company name, address, PAN, GSTIN, payment records, project briefs, correspondenceService delivery; invoicing and payment; GST and tax compliance; contract management; business communication7 years from end of engagement (IT Act & GST Act requirements)
EmployeesName, address, DOB, PAN, Aadhaar (where required by law), bank details, salary, leave records, performance data, emergency contact, employment historyHR administration; payroll; statutory compliance (PF, PT, TDS); performance management; legal obligations as employerDuration of employment + 7 years (statutory obligation)
Contractors & FreelancersName, address, PAN, GSTIN, bank details, work product, invoices, correspondenceEngagement management; payment; TDS compliance; IP and contract administration7 years from end of engagement
Job ApplicantsName, email, phone, resume/CV, work history, skills, educational background, referencesRecruitment and candidate evaluation; communication about the application process6 months from date of application if unsuccessful; on hiring, transferred to employee records
Website VisitorsApproximate region (Country), coarse browser and device type, pages visited, interaction events (e.g. clicks, scroll depth), time on site, referring domain, and contact form submissions (name, email, message). We do not collect or store raw IP addresses or device fingerprints.Website analytics and improvement; responding to enquiries; security and fraud preventionAnalytics event data: 90 days. Aggregated analytics statistics: 24 months. Contact form data: 12 months unless a business relationship develops

4. HOW WE COLLECT YOUR DATA

We collect personal data in the following ways:

  • Directly from you: When you contact us, fill in a form on our website, sign a contract, apply for a job, or correspond with us by email, phone, or messaging platforms.
  • In the course of providing services: When you give us access to systems, share project materials, or provide instructions relating to an engagement.
  • Automatically via our website: Through our first-party, self-hosted analytics system that collects privacy-preserving usage data when you browse www.mgraph.dev. See Section 12 on Cookies & Analytics.
  • From third parties: References from prior employers or clients (for job applicants or contractors), publicly available business information (e.g., company registration data, LinkedIn profiles for business development).

5. LEGAL BASIS FOR PROCESSING

Under the DPDPA 2023, we process personal data on one or more of the following lawful bases:

  • Consent: Where you have given us clear consent to process your data for a specific purpose, such as receiving marketing communications or having your data used for analytics. You may withdraw consent at any time (see Section 10).
  • Contract: Where processing is necessary to perform a contract you are party to, or to take steps at your request before entering a contract (e.g., processing client or contractor data to deliver services or make payment).
  • Legal obligation: Where we are required to process data to comply with applicable law, including the Income Tax Act, GST Act, Companies Act, and any directions from government authorities or courts.
  • Employer’s legitimate use: For employee data, as permitted under Section 7 of the DPDPA for lawful employment-related processing.
  • Legitimate interests: For certain processing activities (such as fraud prevention, network security, and business analytics) where our interests are balanced against and do not override your rights.

6. WHO WE SHARE YOUR DATA WITH

We do not sell your personal data. We share it only where necessary, with the following categories of recipients:

  • Subcontractors and freelancers: Personnel engaged to deliver services on our behalf. They are bound by confidentiality and data protection obligations equivalent to those in this Policy.
  • Cloud and technology service providers: Hosting, storage, project management, and communication tools (e.g., AWS, Google Workspace, GitHub). These providers process data only on our instructions.
  • Professional advisors: Lawyers, accountants, and auditors who assist us in running the business, subject to professional confidentiality obligations.
  • Tax and regulatory authorities: The Income Tax Department, GST authorities, Registrar of Companies, and other government bodies where required by law.
  • Courts and law enforcement: Where we are legally required to disclose data pursuant to a court order, summons, or regulatory direction.
  • Business transferees: If we merge with, are acquired by, or transfer assets to another entity, personal data may be transferred as part of that transaction, subject to equivalent protections.

We require all third parties to treat your data with appropriate security and to use it only for the purpose for which it was disclosed.

7. CROSS-BORDER DATA TRANSFERS

Our operations are primarily based in India. Where we use cloud service providers or tools with servers located outside India, your data may be transferred to and processed in other countries. We take steps to ensure that such transfers are made in accordance with applicable Indian data protection law, including relying on standard contractual protections or the recipient country’s adequacy status as notified by the Government of India under the DPDPA.

If you would like information about the specific countries to which your data may be transferred, please contact our Grievance Officer.

8. DATA SECURITY

We implement reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, disclosure, or destruction. These include:

  • Access controls and role-based permissions on all internal systems
  • Encrypted communication channels (HTTPS, TLS) for data in transit
  • Secure password management and multi-factor authentication on key systems
  • Confidentiality obligations for all employees and contractors with access to personal data
  • Regular review of access rights when roles change or engagements end

No method of electronic storage or transmission is completely secure. If you become aware of a security concern relating to your data, please notify us immediately at hello@mgraph.dev.

9. DATA RETENTION

We retain personal data only for as long as is necessary for the purposes set out in Section 3, or as required by applicable law. The retention periods in the table in Section 3 are our standard periods. Where a legal dispute arises, we may retain relevant data for longer, until the dispute is resolved. When data is no longer needed, we securely delete or anonymise it.

10. YOUR RIGHTS UNDER DPDPA 2023

As a Data Principal under the DPDPA, you have the following rights with respect to your personal data that we process:

Your RightWhat This Means
Right to AccessYou can ask us what personal data we hold about you and receive a summary of how it is being processed.
Right to CorrectionYou can ask us to correct any inaccurate or incomplete personal data we hold about you.
Right to ErasureYou can ask us to delete your personal data where it is no longer necessary for the purpose for which it was collected, or where you withdraw consent and no other legal basis applies. Statutory retention obligations may prevent full deletion.
Right to Withdraw ConsentWhere we process your data based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
Right to Grievance RedressalYou have the right to have your grievances addressed by our Grievance Officer (see Section 14), and to escalate unresolved complaints to the Data Protection Board of India.
Right to NominateYou may nominate another person to exercise your rights on your behalf in the event of your death or incapacity, as provided under the DPDPA.

To exercise any of these rights, please contact our Grievance Officer (see Section 14). We will respond within 30 days of receiving your request. We may need to verify your identity before acting on a request.

11. CHILDREN’S DATA

Our services are directed at businesses and professionals and are not intended for children under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly. If you believe a child’s data has been submitted to us, please contact our Grievance Officer immediately.

12. COOKIES & WEBSITE ANALYTICS

Our website (www.mgraph.dev) uses cookies and similar technologies to understand how visitors use the site and to improve the experience. Cookies are small text files placed on your device.

  • Essential technologies: Necessary for the website to function (e.g., theme preferences). Cannot be disabled.
  • Analytics identifiers: We use a first-party, self-hosted analytics system to understand how visitors interact with the website (e.g., pages visited, time spent). We use a randomly generated identifier (`mg_vid`, rotated roughly every 90 days, and `mg_sid`) stored in local and session storage. This data is not shared with third parties or advertising networks. Raw IP addresses are used momentarily to determine a coarse country region and then immediately discarded.
  • All visitors, everywhere: No analytics identifier and no analytics event is created until you explicitly opt in via the privacy banner or the Privacy Settings page. Some regions (for example, the UK's statistical-purpose exception, or opt-out-based US state rules) would technically permit analytics to run by default with a right to object afterward. We do not currently rely on those exceptions, because our website is statically generated and does not reliably determine a visitor's region before the page loads — rather than guess, we apply the same opt-in requirement to every visitor regardless of location. If we later add reliable region detection, this Policy will be updated before any region-specific default is introduced.
  • We also honor Global Privacy Control (GPC) signals: if your browser sends GPC, analytics defaults to off automatically, on top of the opt-in requirement above.

You can manage your analytics preferences or withdraw consent at any time by visiting our Privacy Settings page or through your browser settings.

13. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. We will update the “Last Updated” date at the top of this document. For material changes, we will notify affected individuals by email or by a prominent notice on our website. We encourage you to review this Policy periodically.

14. GRIEVANCE OFFICER & HOW TO CONTACT US

In accordance with the DPDPA 2023, we have appointed a Grievance Officer to address any complaints or concerns regarding the processing of your personal data.

Grievance OfficerSwapravo Sinha Roy
DesignationDirector
Emailhello@mgraph.dev
Response TimeWithin 30 days of receipt of complaint
EscalationIf unresolved within 30 days, you may approach the Data Protection Board of India at www.dpboard.gov.in

15. GOVERNING LAW

This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 (as amended), and all rules and regulations made thereunder. Any disputes relating to this Policy shall be subject to the jurisdiction of the Courts of Kolkata, West Bengal.