01
Who we are
The Reciprocal Solutions is a software and artificial intelligence consultancy registered in India and operating from N302, Third Floor, Socrates Block, SNS College of Engineering, Saravanampatti, Coimbatore, Tamil Nadu 641107. We design, build and run AI agents, automations and custom language-model systems for clients in India and abroad.
In the language of India's Digital Personal Data Protection Act, 2023, we act as a Data Fiduciary for the personal data we collect about our own enquirers, visitors and contacts. We act as a Data Processor for personal data a client asks us to process inside a project we deliver for them. This notice covers the first case in full, and describes our handling commitments for the second.
Where a signed client agreement says something different from this notice, the agreement governs.
02
What we collect
We keep the list short on purpose. If a field is not needed to answer you or to run a project, we do not ask for it.
- Enquiry form. Your name, work email, company, role, and optionally a phone number, together with the service, budget band, timeline and message you choose to send us.
- Correspondence. Emails, calls and messages exchanged with us, including meeting notes taken during a call.
- Website analytics. Aggregate page views, referring site, approximate country, browser and device class. This is measured without cookies and is not linked back to a named person.
- Server logs. IP address, timestamp, requested path and user agent, recorded automatically so we can spot abuse and diagnose faults.
- Client project data. Whatever a client's system contains and the engagement requires us to process. That may include personal data belonging to their customers, staff or suppliers.
We do not buy contact lists, we do not run advertising trackers on this site, and we do not attempt to identify visitors who have not written to us.
03
Lawful basis and consent
When you submit the enquiry form you are giving us consent to use those details to reply to you, prepare for a call and follow up on the specific enquiry. The purpose is stated on the form itself, and nothing you send is used for anything else without asking you first.
We also process a small amount of data under the legitimate uses the DPDP Act recognises: keeping the site secure, meeting our accounting and tax obligations, and performing a contract you have entered into with us.
You can withdraw consent at any time by writing to info@thereciprocalsolutions.com. Withdrawal is as easy as giving consent. It does not undo processing already carried out lawfully, and it does not remove records we are legally required to keep, such as invoices.
For personal data we handle inside a client project, the lawful basis is the client's. They decide the purpose, they give us documented instructions, and we act only on those instructions.
04
How client project data is handled
Client data is segregated by default. Each engagement gets its own repository, its own cloud project or account, its own credentials store and its own access list. We do not pool data across clients, and we do not use one client's material to build or demonstrate anything for another.
- Access is granted per engagement, to the named engineers working on it, and reviewed when someone joins or leaves the team.
- Wherever the work allows it, we build inside your environment rather than copying production data into ours.
- Where an extract is unavoidable, we take the smallest sample that proves the point and mask or synthesise direct identifiers first.
- Production credentials are held in a managed secrets store, never in source control, chat or a spreadsheet.
- Laptops used on client work are encrypted, patched and remotely wipeable.
- At the end of an engagement we return or delete client data within thirty days, and confirm the deletion in writing on request.
05
AI systems and model data
This is the part most clients want in writing, so it is set out precisely.
- No training on client data. Client content is never used to train, fine-tune or evaluate any model that is shared with another client or handed back to a vendor.
- Zero-retention API configuration. Where a commercial model provider offers a zero data retention or no-training setting, we enable it and record which account it applies to in the engagement's data schedule.
- Fine-tuning only on request. If an engagement requires a fine-tuned model, it is trained only on data the client has explicitly authorised, and the resulting weights belong to that engagement alone.
- Self-hosted where policy demands it. For workloads that cannot leave a network, we run open-weight models inside the client's own cloud account or on their hardware, so no prompt or document reaches a third party.
- Logs stay with the client. Prompts, retrieved context and outputs are logged for evaluation, debugging and audit inside the client's environment, under their retention policy, not ours.
- Redaction before the model. Where a workflow does not need an identifier to do its job, we strip it before the request is made rather than trusting a downstream setting.
- Human review by design. Systems that touch money, customers or clinical, legal and safety decisions are built with an approval step, and that step is part of the deliverable rather than an optional extra.
Model output is probabilistic. We test it against an evaluation set the client owns, we report the error rate we measure, and we design the surrounding workflow on the assumption that some output will be wrong.
06
Sub-processors and cloud regions
We rely on a small set of infrastructure and tooling vendors to run our own business and to host client systems. They fall into these categories:
- Cloud infrastructure — compute, storage, databases and managed services.
- Model providers — hosted large language, vision and speech models, configured for zero retention.
- Email delivery and business email, used to receive and answer enquiries.
- Source control, build and deployment pipelines.
- Error monitoring and uptime alerting.
- Cookieless website analytics.
- Accounting and invoicing software, which holds billing contacts and payment records.
The named vendors for a given engagement are listed in that engagement's data-processing schedule. We tell clients in writing before adding a new sub-processor that would touch their data, and a client may object.
The default hosting region for Indian clients is India, typically a Mumbai region. Clients elsewhere are deployed into the region their own policy requires. Where a client instructs us that data must not leave a named region, we write that into the engagement and architect to it, including the choice of model endpoint.
07
How long we keep things
Retention is capped by default rather than left open. These are our standard periods; a client contract may set a shorter one, and we will follow it.
| What | How long |
|---|---|
| Enquiry form submissions and related correspondence | 24 months from last contact |
| Client project data held in our environments | Duration of the engagement, then deleted within 30 days |
| Prompt, context and output logs | As set by the client's own retention policy, inside their environment |
| Contracts, invoices and tax records | 8 years, as Indian company and tax law requires |
| Server and application logs | 90 days |
| Aggregate website analytics | 26 months |
| Encrypted backups | Rolling 35 days, then overwritten |
08
Security measures
No control set is a guarantee, so we treat security as a set of habits rather than a certificate on a wall. These are the ones we hold ourselves to.
- Encryption in transit with TLS 1.2 or better, and encryption at rest for stored data and backups.
- Single sign-on with multi-factor authentication on every business system that supports it.
- Least-privilege access, granted per engagement and reviewed at least twice a year.
- Secrets held in a managed vault, rotated when a team member leaves an engagement.
- Peer review on every code change, with automated dependency and secret scanning in the pipeline.
- Separate development, staging and production environments, with production data kept out of the first two.
- Logging and alerting on administrative actions in client environments.
- An incident response procedure. If a breach affects your data we tell you without undue delay, describe what happened and what we are doing, and make the reports the DPDP Act requires to the Data Protection Board of India.
09
Your rights under the DPDP Act 2023
If we hold personal data about you as a Data Fiduciary, you have the following rights. They are free to exercise, and using them will not affect how we deal with you.
- Access. Ask for a summary of the personal data we hold about you, what we are doing with it, and who we have shared it with.
- Correction and completion. Ask us to correct data that is wrong, complete data that is partial, and update data that has gone stale.
- Erasure. Ask us to delete data we no longer need for the purpose it was collected for, or where you withdraw consent.
- Withdrawal of consent. Tell us to stop, at any time, for any processing that runs on consent.
- Nomination. Nominate another person to exercise these rights on your behalf if you die or become incapable of doing so.
- Grievance redressal. Raise a complaint with us and get a response, before going to the regulator.
To use any of them, email info@thereciprocalsolutions.com with the subject line "Data request" and enough detail for us to find your records. We may ask one question to confirm you are who you say you are. We respond within thirty days.
If your data reached us through a client's system, we will pass your request to that client, who is the fiduciary for it, and tell you we have done so.
10
Grievance contact
Complaints about how we have handled your personal data go to our grievance officer. Write to info@thereciprocalsolutions.com with "Grievance — Data Protection" in the subject line, or post to N302, Third Floor, Socrates Block, SNS College of Engineering, Saravanampatti, Coimbatore, Tamil Nadu 641107.
We acknowledge within three working days and give a substantive response within thirty days. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
11
Cookies and tracking
This site sets no advertising cookies and carries no cross-site tracking pixels. Our analytics is cookieless: it counts page views without storing an identifier on your device or building a profile of you across other websites.
First-party storage is used only where a feature needs it, for example to remember that you have dismissed a notice. Your browser settings remain the final word, and blocking storage will not stop the site working.
12
International transfers
We are based in India and process in India by default. Some of our sub-processors, particularly model providers and developer tooling, operate outside India, so data may be processed abroad.
Where that happens, the transfer is covered by contract terms that hold the vendor to the standards described in this notice, and we observe any restriction the Central Government places on transfers to a particular country under the DPDP Act. Clients who need a guarantee that their data stays in a named region can have it written into the engagement, and we will select regions, endpoints and vendors accordingly.
13
Children's data
This website is aimed at businesses, and we do not knowingly collect personal data about anyone under eighteen through it. If you believe a child has sent us data, write to us and we will delete it.
Where a client engagement necessarily processes children's data, verifiable parental consent is the client's responsibility to obtain, and we build the system without behavioural tracking or targeted advertising, as the DPDP Act requires.
14
Changes to this notice
We revise this notice when our practice changes. The revision date at the top of the page is always current. Where a change materially affects how we handle client data, we tell affected clients in writing before it takes effect.
15
Contact us
Email info@thereciprocalsolutions.com, call +91 97915 97993, or write to N302, Third Floor, Socrates Block, SNS College of Engineering, Saravanampatti, Coimbatore, Tamil Nadu 641107.