Legal

Privacy Policy

Effective date: 11 August 2026  ·  Last updated: 11 August 2026 (analytics disclosure added)

← Back to gennexa.ai

This Privacy Policy explains how Gennexa.ai (“Gennexa”, “we”, “us” or “our”) collects, uses, discloses, retains and protects personal information. It applies to the website gennexa.ai and to the artificial intelligence, business process outsourcing (BPO), intelligent automation, analytics, and software development and cloud services we provide to our clients.

Summary

  • We collect the business contact details you submit through our contact, demo booking, ROI calculator and newsletter forms — typically your name, work email, phone number, company, job title and your message.
  • We use that information to respond to your enquiry, provide and improve our services, and — where permitted — send you relevant business communications.
  • We use Google Analytics and Microsoft Clarity to measure how the website is used and where visitors run into difficulty. These set cookies. We do not use advertising cookies, and neither tool runs on the internal pages where client and enquirer records are displayed.
  • We do not sell personal information, and we do not share it for cross-context behavioural advertising.
  • When we deliver services to a client, we generally act as a processor handling data on that client's documented instructions, not as the controller.
  • You can ask us to access, correct, delete or stop using your information at any time by writing to info@gennexa.ai.

This summary is for convenience only. The full policy below governs.

1. Who we are

Gennexa.ai is a technology and operations services provider delivering AI solutions, BPO services, intelligent automation, analytics and business intelligence, software development, and cloud and infrastructure services to enterprise clients. We operate from offices in Bengaluru, India and Dubai, United Arab Emirates.

For personal information we collect through this website and in the course of our own business activities, Gennexa.ai is the data controller. Our contact details are set out in section 18.

2. Scope of this policy

This policy applies to personal information we process about:

It does not govern personal information we process on behalf of our clients in the delivery of our services — see section 3.

3. Our role: controller and processor

Our responsibilities differ depending on why we hold the information. This distinction matters because it determines who you should contact to exercise your rights.

Situation Our role What it means
You contact us through this website, or we market our services to you Controller We decide why and how the information is used. This policy applies in full, and you can exercise your rights directly with us.
We process data belonging to a client — for example, handling customer records, claims, documents or support interactions as part of a BPO, automation or software engagement Processor We act only on that client's documented instructions under a written services agreement and data processing agreement. The client is the controller and its own privacy notice applies. If you are that client's customer or employee, please direct your request to them; if you contact us, we will refer you to the relevant client.

4. Information we collect

4.1 Information you give us

When you complete a form on our website, we collect the information you choose to submit:

FormInformation collected
Contact / enquiry form Name, email address, phone number (optional), company (optional), subject (optional), your message, and how you heard about us (optional)
Demo booking Name, email address, phone number, company, job title, industry, and any notes about your requirements, together with your preferred meeting time
ROI calculator Company size, industry, budget range and the process and volume inputs you enter, plus your contact details if you request the resulting report
Newsletter subscription Email address

We also record the source of the enquiry (for example, which page or campaign it came from, including any UTM campaign parameters present in the link you followed) so that we can understand which of our activities are useful.

If you email, telephone or message us directly, we collect the contact details and content of that correspondence.

4.2 Information collected automatically

Our web servers keep standard technical logs of requests made to the site. These include your IP address, the date and time of the request, the page or resource requested, the HTTP status returned, the referring page and your browser's user-agent string. We use these logs to operate and secure the site, diagnose faults, and detect abuse such as automated scraping or attempted intrusion.

4.3 Analytics and usage measurement

We use two third-party tools to understand how our website is used and to improve it:

ToolWhat it does
Google Analytics 4
(Google Ireland Limited / Google LLC)
Measures page views, traffic sources and aggregate usage patterns. Sets cookies on your device and processes your IP address.
Microsoft Clarity
(Microsoft Corporation)
Records how pages are used — clicks, scrolling and mouse movement — to produce heatmaps and session replays that help us find and fix usability problems.

Neither tool is loaded on our internal administration pages, so the client and enquirer records held there are never captured by them. We do not use these tools for advertising, we do not use them to build marketing profiles about individual visitors, and we do not attempt to identify you from the data they produce. Section 7 explains how to opt out.

4.4 Information we do not collect through this website

We do not use advertising cookies or cross-site advertising pixels. We do not collect special category data (such as health, biometric, religious or political information) through this website. Please do not include sensitive personal information in a website form or an unencrypted email.

4.5 Recruitment

If you apply for a role with us, we collect the information in your application, CV and any supporting documents, together with interview notes and, where lawful and relevant to the role, the results of background or reference checks.

5. How and why we use information

We use personal information to:

Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:

Legal basisWhen we rely on it
ConsentSending newsletters and marketing emails to individuals who have subscribed. You may withdraw consent at any time.
Performance of a contractDelivering services to a client, and taking steps at your request before entering into a contract.
Legitimate interestsResponding to business enquiries, promoting our services to business contacts, securing our systems, and running and improving our business — balanced against your rights and freedoms.
Legal obligationMeeting statutory record-keeping, tax, accounting and regulatory requirements, and responding to lawful requests from authorities.

7. Cookies and similar technologies

Our website uses cookies and similar technologies for two purposes only:

We do not set advertising cookies, and we do not sell information collected through cookies.

How to opt out.

If we introduce advertising technologies in future, we will update this policy and, where required, request your consent before those technologies are used.

8. When we share information

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose personal information only in the circumstances below.

8.1 Service providers

We use a small number of vetted providers to run our business. They act on our instructions under contract, may use the information only to provide their service to us, and are bound by confidentiality and security obligations.

CategoryPurpose
Cloud hosting and infrastructureHosting the website, application and database
Customer relationship managementRecording and following up on business enquiries
Transactional and marketing emailDelivering the emails, reports and newsletters you request
Meeting schedulingBooking and managing demonstration calls
Internal collaboration and alertingNotifying our sales team of a new enquiry
Website analyticsMeasuring how the website is used — Google Analytics and Microsoft Clarity, as described in section 4.3

8.2 Other recipients

9. International transfers

We operate internationally, and personal information may be transferred to, stored in or accessed from countries other than the one in which you are located, including countries whose data protection laws differ from those of your home country.

Where we transfer personal information out of the European Economic Area or the United Kingdom, we put in place an appropriate safeguard recognised under applicable law — most commonly the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant) — together with any additional technical and organisational measures the transfer requires. You may request a copy of the safeguards we rely on by writing to info@gennexa.ai.

10. How long we keep information

We keep personal information only for as long as we need it for the purposes described in this policy, and then delete or anonymise it.

InformationRetention period
Enquiries and demo bookings that do not become client relationshipsUp to 24 months from your last interaction with us
Client contact and relationship recordsFor the duration of the relationship, and then as required for legal, tax and audit purposes
Newsletter subscriptionsUntil you unsubscribe, and then a suppression record to honour your opt-out
Website server logsTypically up to 12 months
Unsuccessful job applicationsUp to 12 months, unless you ask us to keep your details on file
Data processed on behalf of a clientAs instructed by that client under our agreement, and returned or deleted at the end of the engagement

Where a longer period is required by law, or information is needed to establish, exercise or defend a legal claim, we retain it for that period.

11. How we protect information

We maintain technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration and loss. These include encryption of data in transit, authentication and access controls on administrative systems, least-privilege access for personnel, network and firewall controls, logging and monitoring, secure development practices, vendor due diligence, and staff confidentiality obligations and training.

Details of our wider security and compliance programme are available on our Trust Center. Client engagements are governed by the specific security and compliance commitments set out in the applicable contract.

No method of transmission or storage is completely secure. If we become aware of a personal data breach affecting your information, we will notify you and the relevant supervisory authority where required by law.

12. Artificial intelligence and automated decisions

We build and operate AI systems for our clients. We consider the following commitments an essential part of how we handle personal information:

If you believe an automated process has affected you unfairly, contact us using the details in section 18 and we will review it.

13. Your privacy rights

Depending on where you live, you may have some or all of the following rights in relation to your personal information:

California residents. We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act, as amended. You may exercise your rights to know, delete, correct and opt out, and may use an authorised agent to do so.

India. Where the Digital Personal Data Protection Act, 2023 applies, you may access, correct, complete, update and erase your personal data, nominate another person to exercise your rights, and raise a grievance with us using the contact details below.

How to exercise your rights. Write to info@gennexa.ai. We will acknowledge your request and respond within the period required by applicable law — generally within 30 days, and we will tell you if we need longer. We may need to verify your identity before acting, and will only use the information you provide for that purpose. Exercising your rights is free of charge unless your request is manifestly unfounded or excessive.

If your request concerns data we process on behalf of a client, we will forward it to that client and support their response, as described in section 3.

14. Marketing communications

We send newsletters and business communications only where you have subscribed or where we are otherwise permitted to contact you about services relevant to your professional role. Every marketing email includes an unsubscribe link, and you can also opt out at any time by writing to info@gennexa.ai. We will still send you necessary service and transactional messages relating to an active enquiry or engagement.

15. Children's privacy

Our website and services are intended for businesses and their representatives. They are not directed at children, and we do not knowingly collect personal information from anyone under the age of 18. If you believe a child has provided us with personal information, contact us and we will delete it.

16. Third-party links and services

Our website links to third-party websites and services that we do not control, including social media platforms. This policy does not apply to them. We encourage you to read the privacy notice of any third-party site you visit.

17. Changes to this policy

We may update this policy to reflect changes in our practices, technology, or legal and regulatory requirements. The effective date at the top of this page shows when it was last revised. Where a change materially affects how we use your personal information, we will provide prominent notice and, where required, obtain your consent.

18. How to contact us

For any question about this policy, to exercise your privacy rights, or to raise a grievance, contact us at:

Gennexa.ai — Privacy

Email: info@gennexa.ai

India
1877/4, 80 Feet Rd, HBR Layout 2nd Block, 1st Stage, HBR Layout, Bengaluru, Karnataka 560084, India

United Arab Emirates
105, Fronds, Al Garhoud, Dubai, United Arab Emirates

If you are in the European Economic Area or the United Kingdom and are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. If you are in India, you may escalate an unresolved grievance to the Data Protection Board of India.