This policy explains what personal data Inventh collects through inventh.com and in the course of our work, why we use it, who we share it with, how long we keep it, and the rights you have.
Privacy Policy
At a glance
- We never sell your personal data. We do not sell it, rent it or share it for targeted advertising.
- We collect what you send us. Enquiries, white paper requests, job applications, payments, and basic website usage data.
- We use it for the reason you gave it. To reply, deliver services, send what you asked for, and keep the site secure and working.
- We share it only with providers who run our services. Hosting, email, payments and analytics, or authorities when the law requires.
- You stay in control. Ask to see, correct or delete your data at mail@inventh.com. We reply within one month.
01Who we are
Inventh is the trading name of Great Inventh Private Limited, a company registered in India, and its group companies (together, Inventh, we or us). We have offices in Farmers Branch, Texas, United States; Northampton, United Kingdom; and Kochi, Kerala, India.
For the personal data described in this policy, Inventh is the controller (a data fiduciary under India’s Digital Personal Data Protection Act, 2023). This policy covers inventh.com and our own business activities. Big Accountants, our subsidiary, publishes its own privacy policy for its accounting, bookkeeping and tax services.
02What we collect
Information you give us. When you send an enquiry, request a white paper, apply for a job, sign up for updates, become a client or make a payment, you may give us your name, work email, phone number, company, job title, billing address, and anything you choose to write in a message or attach, such as a CV.
Information collected automatically. When you use the site we collect technical data: IP address, browser and device type, operating system, pages visited, time on page, referring and exit pages, and approximate location at city or country level.
Information from others. When your organization engages us, it may give us the names and work contact details of the people we will work with.
Payment card details are entered directly with our payment provider, Razorpay. We never see or store your full card number.
03How we use it, and for how long
We only use personal data for the purposes below. For visitors in the EEA and the UK, the table also shows the legal basis we rely on.
| Data | Why we use it | Legal basis (EEA and UK) | How long we keep it |
|---|---|---|---|
| Enquiry form: name, work email, company, phone, service and project details | To reply and discuss your project | Steps before a contract, or legitimate interests | 24 months after our last contact |
| White paper requests: first name, work email, company, job title | To send the paper and follow up on its topic | Consent, or legitimate interests | 24 months, or until you opt out |
| Job applications: name, contact details, CV, cover letter, anything you add | To assess your application | Steps before a contract | 12 months after the role closes, unless you agree to longer |
| Clients and suppliers: contact names, work emails, billing details, contracts, invoices | To deliver, bill and account for services | Contract, and legal obligation | As long as tax and company law requires |
| Online payments: name, email, amount, payment reference | To take and reconcile payments | Contract, and legal obligation | As long as tax and company law requires |
| Updates and newsletters: name, email | To send updates you signed up for | Consent | Until you unsubscribe |
| Website usage: IP address, device, browser, pages visited, referring page | To measure and improve the site and keep it secure | Consent for analytics; legitimate interests for security | Up to 14 months in analytics; security logs up to 90 days |
When a retention period ends, we delete the data or make it anonymous. We keep it longer only when the law requires it or to deal with a legal claim.
04Cookies and similar technologies
Cookies are small files a website stores in your browser. We use three kinds:
- Essential cookies keep the site working and secure, for example page caching and form protection. These do not need consent.
- Analytics cookies from Google Analytics tell us how the site is used, so we can improve it.
- Functional cookies remember choices such as your cookie preferences.
We do not use advertising or remarketing cookies. Where the law requires consent for non-essential cookies, including in the EEA and the UK, we ask for it through our cookie banner before setting them, and you can change your choice at any time. You can also block or delete cookies in your browser settings; the site will still work, although some features may not.
05Who we share it with
We share personal data only when we need to, and only with:
- Service providers that run our business for us, under contract and only on our instructions: Hostinger (website hosting), Google (Workspace email and Google Analytics) and Razorpay (payments).
- Our own teams in the United States, the United Kingdom and India, where they need the data to do their work.
- WhatsApp, operated by Meta, if you choose to contact us through the WhatsApp button. Meta’s own privacy policy applies to that conversation.
- Professional advisers, such as lawyers, auditors and accountants, under a duty of confidentiality.
- Authorities, when the law requires it or to protect our rights and the safety of others.
- A buyer or successor, if all or part of our business is sold or reorganized. This policy will continue to apply to your data.
We do not sell personal data, and we do not share it for cross context behavioral advertising.
06International transfers
Our teams and service providers work in several countries, so your data may be processed outside the country where you live, including in India and the United States. When we transfer personal data out of the EEA or the UK, we use a legal safeguard recognized there, such as an adequacy decision, the European Commission’s standard contractual clauses or the UK International Data Transfer Addendum.
07How we protect it
We use technical and organizational measures suited to the data we hold, including encryption in transit (HTTPS), access limited to the people who need it, confidentiality agreements for staff, secured backups and monitoring for threats. No system is completely secure. If a breach affects your data and the law requires us to tell you, we will.
08Your rights
Everyone. You can ask us what personal data we hold about you, ask us to correct or delete it, and opt out of marketing email at any time using the unsubscribe link or by writing to us.
EEA and UK (GDPR and UK GDPR). You also have the right to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting earlier processing. You can complain to your local data protection authority; in the UK that is the Information Commissioner’s Office (ico.org.uk).
India (Digital Personal Data Protection Act, 2023). You have the right to information about how your data is processed; to correction, completion, updating and erasure; to grievance redressal; and to nominate another person to exercise your rights. If our response does not resolve your grievance, you may complain to the Data Protection Board of India.
United States. Depending on your state, you may have the right to know, access, correct and delete personal data, and to opt out of its sale, sharing or use for targeted advertising. We do not sell or share personal data in those ways. We will not treat you differently for using your rights.
How to use your rights. Email mail@inventh.com (or hello@inventh.com in India). We may ask you to confirm your identity. We reply within one month, and tell you if we need longer where the law allows it.
09Marketing email
We send business updates and insights only to people who have asked for them or who are existing business contacts, where the law allows. Every email includes an unsubscribe link, and unsubscribing does not affect any service you receive from us.
10Data we process for our clients
When we build or run software for a client, we may process personal data inside that client’s systems on the client’s behalf. In that work, the client decides how the data is used, and our contract with the client, including any data processing agreement, governs it. This policy does not cover that data. Please contact the client organization directly about it.
11Children
Our site and services are for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, contact us and we will delete it.
12Other websites
Our site links to websites we do not operate, such as social networks and our subsidiary’s website. Their own privacy policies apply when you visit them.
13Changes to this policy
We update this policy when our practices or the law change. The date at the top shows the latest version. If a change is significant, we will say so on this page and, where appropriate, tell you directly. This version was last updated on 28 September 2026.
Contact us about privacy
Questions, requests and complaints about personal data go to our privacy contact. In India, our Grievance Officer handles requests under the Digital Personal Data Protection Act, 2023.
Privacy contact
Inventh, Dallas area office
14455 Webb Chapel Road, Suite 201
Farmers Branch, TX 75234, United States
Grievance Officer, India
Great Inventh Private Limited
L-3, Changampuzha Nagar, Kalamassery
Kochi, Kerala 682033, India
