S8N Intelligence Hub

Intelligence Hub

Legal Documentation

Platform Privacy Policy

SECURITY PROTOCOL S8N-PRV-2026-R3 · LAST AUDITED: June 29, 2026

1. Scope & Applicable Law. This Policy is issued in accordance with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Sensitive Personal Data) Rules, 2011 (“SPDI Rules”), the IT (Intermediary Guidelines) Rules, 2021, and aligns with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) ahead of its full enforcement on 13 May 2027. We use DPDP terms (“Data Principal,” “Data Fiduciary,” “Data Processor”) below for clarity and forward-compatibility. This Policy applies to s8n.in, consultancy.s8n.in, academy.s8n.in, our Client Portal, newsletter, and scheduling tools (together, the “Platform”), operated by SHRIRAJ NILESH NAIK, trading as “S8N” (“S8N”, “we”, “our”, “us”).

2. Information We Collect. To deliver premium AI architectural engineering and consultancy solutions, S8N processes data across three primary dimensions: Active Disclosures (name, work email, phone, job title, company name, industry, and project details, including PAN/GST and portfolios for S8N Consultancy consultants); Automated Technical Logs (masked IP addresses, User Agent profiles, device configuration traits, cookie identifiers, and path sequence telemetry); and Sensitive Personal Data (we do not intentionally collect sensitive personal data as defined under the SPDI Rules; any such processing on behalf of a client is governed separately by a DPA).

A. Active Disclosures

When you submit contact inquiries, scheduling details, waitlist requests, or gated content requests, we collect your Full Name, Corporate Email, Corporate Phone, Job Title, Industry Sector, and specific operational challenges. For S8N Consultancy, we also collect PAN, GST details (where applicable), credentials, and portfolio information from Consultants.

B. Automated Technical Logs

When navigating S8N, our systems automatically log connection parameters, including masked IP addresses, User Agent profiles, device configuration traits, cookie identifiers, and path sequence telemetry.

3. Legal Basis & How We Use Data. We process personal data on the following bases under the DPDP Act: Consent, for marketing communications, optional cookies, and newsletter subscriptions (withdrawable at any time by emailing privacy@s8n.in); Performance of a Contract, to deliver services, verify credentials, and manage bookings; Legitimate Use, where you voluntarily provide data for a specific purpose and have not indicated otherwise; and Legal Obligation, tax, accounting, and regulatory compliance. We use personal data to: process and qualify leads; confirm and manage bookings; deliver requested brochures, reports, and newsletters; operate the Client Portal, S8N Consultancy, and S8N Academy; process payments and issue invoices (GST-compliant once registration is complete); secure the Platform; and comply with legal and regulatory obligations.

4. Third-Party Disclosures & Sub-Processors. We do not sell, rent, or trade your personal data. We share data under strict confidentiality terms with trusted service infrastructure partners: Supabase (database, auth); Vercel Inc. (hosting, edge network security, and performance telemetry); Resend (transactional email notifications); Razorpay (payment processing and split-settlement via Razorpay Route); Google LLC (optional analytics, with consent); Large Language Model Providers (OpenAI, Anthropic, Google, or others depending on the engagement); and n8n (workflow execution infrastructure). We may also disclose information where required by law, to respond to a valid legal process, or to protect the rights, property, or safety of S8N, our users, or the public.

5. Data We Process on Behalf of Clients. Where you are an S8N client and we build or operate an AI agent or RAG system that processes personal data of your customers or employees (“Client Data”), S8N acts as a Data Processor, and you act as the Data Fiduciary, under the DPDP Act. We process such Client Data strictly on your documented instructions, do not use it to train or fine-tune models, and will delete/return it within 30 days of contract termination.

6. Cookie Controls. We use strictly necessary cookies under legitimate interest. Analytics and marketing cookies are switched off by default and require your affirmative consent. You can review or change your cookie preferences through your browser settings or platform settings.

7. Security, Breach Notification & Storage. We implement reasonable security safeguards consistent with the SPDI Rules and the DPDP Act, including database encryption, RLS policies, TLS 1.3, and role-based access controls. In the event of a confirmed breach, we will notify affected individuals and regulators as soon as possible and, in any event, within 72 hours.

8. Data Retention. We retain personal data only as long as necessary for the purpose collected or as required by law. Lead data is kept for up to 24 months of inactivity. Account data is kept for the life of the account plus 90 days. Payment and invoicing records are retained for 8 years under Income Tax Act requirements.

9. AI & Automated Processing. We use automated tools to triage leads and power AI-driven automations. Publicly published AI-generated content is clearly labeled as AI-assisted. Lead-scoring does not result in final decisions carrying legal consequences without human review.

10. Children's Data. The Platform is not directed at, and we do not knowingly collect personal data from, individuals under 18. If we inadvertently collect data from a minor without verifiable parental consent, we will delete it promptly.

11. Your Rights as a Data Principal. Under the DPDP Act, you have the right to: access a summary of your personal data processed; request correction or completion of inaccurate data; request erasure of data no longer required; withdraw consent at any time; lodge grievances with our Grievance Officer; and nominate a representative in the event of death or incapacity. Email privacy@s8n.in with your request; we will respond within 30 days.

12. International Visitors (GDPR/CCPA). Visitors located in the EEA, UK, or California may exercise their GDPR or CCPA rights (such as data portability, access, deletion, and right to object to marketing) by reaching out to privacy@s8n.in.

13. Cross-Border Transfers. Data collected may be transferred to and processed in countries where our infrastructure or sub-processors operate. We rely on standard contractual clauses for transfers outside the EEA. No restricted-country transfers are performed under Section 16 of the DPDP Act.

14. Grievance Officer & Contact. Please direct privacy questions, data rights requests, or complaints to:

Grievance Officer: SHRIRAJ NILESH NAIK
S8N — Legal & Compliance
G. D. Ambekar Road, Mumbai, Maharashtra 400012, India

We acknowledge privacy complaints within 24 hours and aim to resolve them within 15 days. If unsatisfied, you may appeal to the Data Protection Board of India.