Contact Us

Privacy Policy

Last updated: 26 July 2026

The short version

We collect what you type into our contact form and standard analytics about how this site is used. We use it to reply to you and to improve the site. We never sell it or rent it, and you can ask us to show or delete what we hold about you at any time by emailing info@redliolabs.com.

Who we are, and who controls your data

This site, redliolabs.com, is operated by Redlio Labs, an enterprise software development company based in Ahmedabad, India. Redlio Labs is the trading name of Mayursinh Jadeja, sole proprietor, who is the data controller for the information described in this policy. Our office is at Office no. 421, 4th Floor, Shivalik Shilp 2, Keshavbag Party Plot, Vastrapur, Ahmedabad, Gujarat 380015, India. Our GSTIN is 24ANTPJ0672M1ZJ, registered at Second Floor, 12, Krishna Complex, Janta Fatak, Jamnagar, Gujarat 361006.

For everything you send us through this website, Redlio Labs is the data controller. That means we decide what is collected and why, and we are the party you hold accountable for it. Data we handle inside client projects works differently, and the section on client project data below explains how.

You can reach us about any of this at info@redliolabs.com.

Our legal basis for using your information

Privacy laws in the EU, the UK, and a growing list of other places require us to name the legal ground we rely on. We rely on three.

  • Legitimate interest, for replying to an enquiry you sent us and for keeping the site secure. If you contact a software company about a project, answering you is the outcome you asked for.
  • Legitimate interest, for analytics, which runs by default so we can see how the site is used. You can turn it off at any time using the opt out described below, and doing so costs you no functionality.
  • Contract, once we are working together, for the information needed to deliver and invoice the work.

What we collect, and why

1. What you send us through the contact form

When you submit the form on our contact page we receive your name, email address, the service you are interested in, and your message. If you choose to fill them in, we also receive your company name, budget range, and how you found us.

We use this for one purpose: understanding and responding to your enquiry. Asking how you found us helps us understand which channels bring people here, whether search engines, AI assistants, or referrals.

2. Analytics

We use Google Analytics 4 to understand how visitors use the site: which pages are read, roughly where visitors come from, and what device and browser they use. This information is aggregated. We do not use it to identify you personally.

3. Server logs

Like almost every website, our server keeps standard technical logs: IP address, browser type, pages requested, and timestamps. We use them for security and to keep the site running, not to profile visitors.

4. Email

If you email us, we keep the correspondence for as long as we need it to handle your enquiry or project.

Client project data, and where this policy stops

This policy covers you as a visitor to redliolabs.com. It is not the policy that governs data inside the systems we build and run, and the distinction matters if you are evaluating us as a supplier.

When we build, migrate, or support a client system, our engineers can come into contact with personal data belonging to that client’s customers, staff, or patients. In that work we are a data processor and the client is the controller. We act on their documented instructions, not on our own judgement, and we do not use their data for any purpose of our own.

Those engagements are governed by the project agreement and, where the work involves personal data, a data processing agreement covering scope, security measures, sub-processors, breach notification, and what happens to the data when the engagement ends. We sign the client’s DPA where they have one. Ask us for our standard terms before you brief us, not after.

Access is limited to the engineers assigned to the work, granted for as long as the work requires it, and revoked when the engagement closes.

What we never do

We never sell, rent, or trade your personal information.

We never add you to a mailing list you did not ask to join. Submitting the contact form gets you a reply, not a newsletter.

We never share your enquiry with anyone outside Redlio Labs, except the service providers below or where the law requires it.

Cookies and analytics choices

This site sets one small cookie of its own, which stores your cookie choice for six months. Google Analytics cookies are set by default to measure site usage as described above, and are removed if you turn analytics off. We do not run advertising or social media tracking pixels.

You can turn analytics off in the cookie banner, change your choice at any time using Cookie preferences in the footer, block cookies in your browser settings, or install Google’s Analytics opt-out add-on. None of these choices costs you any functionality.

Who processes data on our behalf

We keep this list short on purpose, and we name names rather than saying "trusted partners".

  • Google, which processes analytics data as described above under its own terms as a processor.
  • Our cloud hosting provider, which serves the site and stores the server logs on infrastructure located in India.

Contact enquiries are delivered to a lead management system that we build and operate ourselves, on our own infrastructure. Your enquiry is not passed to a third party CRM, an outsourced sales agency, or an advertising platform.

If we add a provider that changes this picture, this page changes before the provider goes live.

Where your data lives, and international transfers

Redlio Labs operates from India, so information you send through this site is processed in India. Our providers may also store data in other countries, including the United States in the case of Google Analytics.

India has not received an adequacy decision from the European Commission. If you are contacting us from the EU or the UK, that means your enquiry is transferred outside your jurisdiction when you press send. We are telling you plainly rather than implying a protection we have not put in place: we do not currently rely on Standard Contractual Clauses for website enquiries, and we treat your submission as one you chose to send us for the explicit purpose of getting a reply.

For client engagements the position is different and stricter. Where a project involves personal data originating in the EU or the UK, the transfer mechanism is settled in the data processing agreement before work starts. Raise it during procurement and we will address it in writing.

Wherever your data is processed, the protections described in this policy travel with it.

How long we keep it

Contact enquiries: for as long as we are handling the enquiry and any project that follows. Where an enquiry does not become a project, we delete it within 24 months, and sooner on request. Legal, tax, and fraud prevention obligations are the only reasons we would hold anything longer, and only for as long as those require.

Analytics: retained per Google Analytics settings for 14 months, then aggregated or expired.

Server logs: rotated automatically on a short cycle.

Your rights

Whatever your jurisdiction, we honour the same set of requests. Email info@redliolabs.com and we will respond within a reasonable time, usually much faster than the 30 days most privacy laws allow. We do not charge for this and we do not ask why.

  • Access: ask what we hold about you and get a copy of it.
  • Correction: ask us to fix anything inaccurate.
  • Deletion: ask us to erase it, which we will do unless a law requires us to keep it.
  • Objection and restriction: ask us to stop or limit how we use it.
  • Portability: ask for it in a machine readable format you can take elsewhere.
  • Withdraw consent: turn off analytics whenever you like, with no loss of functionality.

If you are in the EU or the UK these correspond to your GDPR rights, and you also have the right to complain to your national data protection authority without contacting us first. In Ireland that is the Data Protection Commission, in the UK the Information Commissioner’s Office. We would rather you told us first so we can fix it, but the choice is yours.

If you are in California these correspond to your CCPA rights, including the right not to be discriminated against for exercising them. We do not sell personal information, so there is nothing to opt out of.

We do not make automated decisions about you and we do not profile you. No algorithm scores your enquiry.

Security

The site is served over HTTPS, access to submitted enquiries is limited to the people who need them to respond, and we keep our infrastructure patched. No method of transmission or storage is fully secure, but we treat your data with the same care we apply to our clients’ production systems.

Children

This site is a business services site and is not directed at children under 16. We do not knowingly collect their information. If you believe a child has sent us personal data, email us and we will delete it.

Links to other sites

Pages on this site link to external sites such as client review platforms, cited sources, and social profiles. Their privacy practices are their own. This policy covers redliolabs.com only.

Changes to this policy

When our practices change, this page changes, and the date at the top changes with it. Significant changes get a visible note here rather than a silent edit.

Contact

Questions about this policy, requests about your data, or a concern about how we have handled something: info@redliolabs.com, or write to Redlio Labs, Office no. 421, 4th Floor, Shivalik Shilp 2, Keshavbag Party Plot, Vastrapur, Ahmedabad, Gujarat 380015, India.

If you are a prospective client whose procurement or legal team needs our data processing terms, security posture, or a signed DPA, use the same address and say so in the subject line. Those requests go to the engineering team, not to a sales queue.