Privacy policy
What we do with personal data on this website, and what we do with it when we build and run software for a client.
Last updated October 2026
1. Who we are
Sodiarc JR is the engineering arm of Sodiarc and operates as a division of Sodiarc Education Private Limited ("Sodiarc JR", "we", "us"), registered in India at Collaboratory, 307/2/2, Nyanapahalli Main Road, Devarachikkana Halli, Bengaluru, Karnataka 560076.
This policy covers sodiarcjr.ai. For data processed on behalf of a client under a software engagement, see section 6 — our role there is different, and so are our obligations.
Questions, or any request under this policy: hello@sodiarc.ai.
2. What we collect on this website
Information you give us
- Your name, email address and phone number
- Your company, your role, and the website of your business
- What your business does, and the problem you describe to us, when you submit an enquiry or apply to an event
- Anything else you choose to put in a message to us
Information collected automatically
- Page views and referring pages, through privacy-focused analytics that do not use cookies and do not build a profile of you
- Standard server logs, including IP address, kept for security and troubleshooting
We do not use advertising cookies and we do not sell data to anyone, in any circumstances.
3. Why we use it, and on what basis
- To answer you. If you send an enquiry we use your details to reply and to discuss the work. Under the DPDP Act this is processing for the purpose you gave the data for; under the UK and EU GDPR the basis is steps taken at your request prior to a contract.
- To run an event you applied to. To assess the application, confirm a place and send joining details.
- To keep records. Contracts, invoices and tax records, which we are required to retain.
- To keep the site working and secure. Server logs and aggregate analytics, on the basis of our legitimate interest in operating the site.
We do not send marketing email to people who have only made an enquiry. If we ever start, it will be something you opt into and can leave in one click.
4. Who else sees it
We keep the number of parties small on purpose. Personal data from this site may be handled by:
- Our hosting and email providers, in order to serve the site and deliver mail
- Our analytics provider, which receives page-level data without cookies or personal identifiers
- Our accountants and professional advisers, where a record is relevant to them
- A public authority, where we are legally required to disclose
We do not pass your details to another company so that they can market to you. A current list of the providers we use is available on request from hello@sodiarc.ai.
5. How long we keep it
- Enquiries that do not become work: up to 24 months, then deleted.
- Event applications: up to 12 months after the event.
- Client records: for the engagement and then as long as tax and company law requires.
- Server logs: a rolling short period for security purposes.
Ask us to delete your enquiry sooner and we will, unless we are required to keep a record of it.
6. Client engagements: we are usually the processor, not the controller
When we build or operate software for a client, personal data inside that system belongs to the client's world, not ours. The client decides what is collected and why. In the language of the law, the client is the Data Fiduciary under the DPDP Act, or the controller under the UK and EU GDPR, and we are the Data Processor.
What that means in practice:
- We process that data only on the client's documented instructions, under a written agreement. We can provide a data processing agreement meeting Article 28 of the UK and EU GDPR, and equivalent terms for DPDP engagements.
- We do not use client data to improve our own products, and we do not use it to train models.
- We tell the client before adding a sub-processor, and we work on client-owned infrastructure wherever the engagement requires it, so the data never leaves their own accounts.
- We notify the client without undue delay if we become aware of a personal data breach affecting their data, so that they can meet their own notification deadlines.
- At the end of an engagement we return or delete the data, at the client's choice.
If you are a customer, patient or user of a system we built for somebody else, your request should go to that organisation, because they decide what happens to your data. If you contact us we will pass it to them promptly and tell you we have done so.
7. Where your data is held
Data from this website is held in India. On client engagements, the location is a decision we make with the client before anything is built rather than afterwards, because data residency is not a setting that can be changed later. Where a client requires data to stay in a particular country, we design for that from the first day.
8. Your rights
Under India's Digital Personal Data Protection Act 2023, and under the UK and EU GDPR where it applies to you, you can ask us to:
- Tell you what personal data of yours we hold and what we do with it
- Correct it if it is wrong or incomplete
- Delete it, where we are not required to keep it
- Stop using it for a particular purpose, or withdraw a consent you gave
- Provide it in a portable form, or restrict or object to our use of it, where the GDPR applies
Write to hello@sodiarc.ai and we will respond within 30 days. There is no charge. If you are not satisfied with our response you may complain to the Data Protection Board of India, or to your supervisory authority where the GDPR applies to you — in the UK, the Information Commissioner's Office.
9. Security
We use access control at the data layer rather than only in the interface, encryption in transit, least-privilege access for our own team, and audit logging on systems that hold personal data. Production access on client systems is read-only by default and every change is explicitly approved before it runs. No system is perfectly secure, and we will not claim otherwise.
10. Children
This website is intended for people acting in a business capacity and is not directed at children. We do not knowingly collect data from children through it. Where a client's system processes children's data — as one of ours does — that is handled under the client's instructions and the applicable rules on verifiable parental consent.
11. Changes to this policy
If we change this policy we will update the date at the top. Where a change is significant and affects people we hold data about, we will tell them directly rather than rely on them noticing.
12. Contact
Sodiarc JR, a division of Sodiarc Education Private Limited
Collaboratory, 307/2/2, Nyanapahalli Main Road, Devarachikkana Halli, Bengaluru, Karnataka 560076, India
hello@sodiarc.ai · +91 91875 18671