Privacy Policy
Last updated
This site collects very little, and this page says exactly what. If you only read one thing: we run no analytics and no advertising, and the only personal data we hold is the message you chose to send us.
1. Who is responsible for your data
ILLUSIONART AI PRIVATE LIMITED (trading as illusionart) is the controller of the personal data described here under the EU and UK General Data Protection Regulation, and the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023.
Registered office
A-2304, Hill Crest, House of Hiranandani
Bommanahalli
Bengaluru, Karnataka 560068
India
Corporate Identity Number: U58200KA2025PTC210720
Contact for anything on this page: support@illusionart.ai
The same address handles data protection questions, requests to exercise your rights, and grievances under section 13 of the DPDP Act. A message to it reaches a person, not a queue.
2. What we collect
When you write to us
The enquiry form on this site asks for your name, your email address and your message, and records which topic you picked. When you send it, our server also records the IP address the request came from.
Two emails follow: one to us containing everything above, and a short acknowledgement to you. The acknowledgement deliberately contains none of what you wrote — it exists so you know the message arrived.
When you read this site
Loading a page means your browser asks our host — and, for images and video, our media provider — for files. Those requests carry your IP address, the page you asked for, and the headers your browser sends (its user-agent, language and referrer). Both keep short-lived server logs. We do not build profiles from them, and we do not combine them with anything else. The typefaces are served from this domain, so no third party learns anything from them.
What stays in your browser
Two values are stored on your device and are never transmitted to us: your reduced-motion preference, and your answer to the consent question. Both are described in the Cookie Policy.
What we do not collect
There is no analytics service, no advertising or tracking network, no session recording, no heatmap, no fingerprinting, no CRM pixel and no user accounts on this site. We do not buy personal data, and we do not sell or rent yours.
3. Why we process it, and on what basis
| Purpose | Data | GDPR basis | DPDP basis |
|---|---|---|---|
| Reading and replying to your enquiry | Name, email, message, topic | Art. 6(1)(b) — steps at your request before a contract | s. 7(a) — data you voluntarily provided for this purpose |
| Stopping abuse of the enquiry form | IP address, submission counts | Art. 6(1)(f) — our legitimate interest in not having our mail domain used to send spam | s. 7(a), read with our obligation to keep the service secure |
| Serving the pages, images and video you requested | IP address, request headers | Art. 6(1)(f) — delivering a site you asked to see, securely | s. 7(a) — necessary to provide what you requested |
Where we rely on legitimate interest we have weighed it against your interests and concluded it is narrow, expected, and not something a visitor would object to. You can object anyway — see section 7.
We do not use your data for automated decision-making or profiling within the meaning of Art. 22, because we do neither.
4. Who else sees it
We use the following processors, and no others. Each acts on our instructions under a data processing agreement, and none of them is permitted to use your data for their own purposes.
| Processor | What it receives | Where | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. (opens in a new tab) | IP address, request headers and page requested, in server logs | United States, with edge delivery worldwide | EU Standard Contractual Clauses and the EU–US Data Privacy Framework |
| Resend (Plus Five Five, Inc.) (opens in a new tab) | your name, email address, message and the IP address you sent it from | United States | EU Standard Contractual Clauses |
| Cloudinary Ltd. (opens in a new tab) | IP address and request headers when your browser fetches an image or video | United States and Israel | EU Standard Contractual Clauses and an EU adequacy decision for Israel |
Beyond these, we would disclose personal data only where a law or a binding order requires it, or to establish or defend a legal claim.
5. Transfers outside your country
We operate internationally, and the providers above are largely outside the EEA, the UK and India. Where personal data leaves the EEA or the UK it is transferred under the European Commission’s Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies), or under an adequacy decision, as listed in section 4. Under the DPDP Act, transfers are made to countries not restricted by the Central Government.
You can ask us for a copy of the relevant safeguards at support@illusionart.ai.
6. How long we keep it
- Enquiry correspondence — 24 months from your last message, so we can pick up a conversation where it left off. Then it is deleted.
- Abuse-prevention counters — one hour. They live in memory only and are gone when the server instance recycles.
- Provider server logs — for the retention period each provider operates, linked in section 4. We do not extend them.
- Your browser settings — on your device until you clear them; the consent record is re-asked after 12 months.
7. Your rights
Under the GDPR (Arts. 15–22) you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time without affecting what was lawful before.
Under the DPDP Act you have the right to access a summary of your data and of our processing, the right to correction, completion, updating and erasure, the right to grievance redressal, and the right to nominate someone to exercise these rights on your behalf if you die or become incapacitated.
To exercise any of them, write to support@illusionart.ai. We answer within one month, as the GDPR requires, and usually much sooner — this is a small site with a small amount of data. We may ask you to confirm the email address the data is attached to, and nothing more; we will not demand identity documents to answer a question about an email you sent us.
If we get it wrong you can complain to a supervisory authority. In the EU that is the authority where you live or work; in the UK it is the Information Commissioner’s Office (opens in a new tab); in India, the Data Protection Board of India — though under section 13 of the DPDP Act please raise it with us first, so we have the chance to fix it.
8. Children
This site is aimed at businesses, and is not directed at children. We do not knowingly process the personal data of anyone under 18. If you believe a child has sent us data, tell us and we will delete it.
9. Security
The site is served only over HTTPS. The enquiry endpoint validates and size-limits every submission, escapes everything it puts into an email, rate-limits by IP and by address, and will only send free-text to a fixed internal address — so it cannot be used to relay someone else’s words out of our domain. Access to the mailbox that receives enquiries is limited to the people who answer them.
If a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, tell you directly. Under the DPDP Act we will notify the Data Protection Board and every affected person.
10. Changes
If this policy changes we update the date at the top of the page. Where a change materially affects how we handle data you have already given us, we will say so prominently rather than rely on you re-reading this page.