DeepNotch · Legal

Privacy Policy

How DeepNotch collects, uses, and protects personal data when you visit deepnotch.ai — written to comply with the EU and UK GDPR, Saudi PDPL, India's DPDP Act, California's CCPA/CPRA, and other applicable privacy laws.

Version
1
Effective date
21 July 2026
Last updated
21 July 2026
Contact
info@deepnotch.ai

DeepNotch ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect when you visit www.deepnotch.ai (the "Website"), how we use it, who we share it with, and the rights you have over it — wherever in the world you are located.

This policy is intended to comply with applicable privacy and data protection laws in the jurisdictions where DeepNotch operates and where visitors access the Website, including (without limitation) the EU General Data Protection Regulation (GDPR), the UK GDPR, the Saudi Arabian Personal Data Protection Law (PDPL), the Indian Digital Personal Data Protection Act 2023 (DPDP Act), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and other applicable privacy laws such as Brazil's LGPD, Canada's PIPEDA, Singapore's PDPA, and Australia's Privacy Act.

By using the Website, you acknowledge that you have read and understood this Privacy Policy.

01Who we are — Data controller

DeepNotch is an internationally operating AI Governance, Risk, Compliance (GRC) and Security advisory practice. For the purposes of applicable data protection laws, DeepNotch is the "data controller" (or "data fiduciary" under the DPDP Act) of the personal data described in this policy.

Primary contact for all privacy matters: info@deepnotch.ai

Details of DeepNotch's registered business entity are available upon legitimate request via the contact email above. Where required by applicable law, DeepNotch will appoint local representatives in relevant jurisdictions (including an EU or UK representative under Article 27 GDPR / UK GDPR, if and when required).

DeepNotch has not appointed a Data Protection Officer, as one is not currently required by applicable law given the limited nature and scale of our processing. All privacy enquiries should be directed to info@deepnotch.ai.

02Personal data we collect

We practice data minimization: we collect only the personal data reasonably necessary for the stated purposes below and avoid collecting unnecessary information.

a. Information you provide directly

  • Email address — when you subscribe to receive updates through the subscription form on the Website.
  • Name, email address, and message contents — if you contact us directly at info@deepnotch.ai or connect with us via LinkedIn.
  • Any other information you voluntarily choose to share in your communications.

b. Information collected automatically

  • Technical and usage data — the Website is hosted on GitHub Pages (operated by GitHub, Inc.) and delivered through Cloudflare's content delivery and security network. Like most hosting and CDN providers, GitHub and Cloudflare may automatically process standard technical information such as IP address, browser type, operating system, referring pages, and timestamps for security, performance, and operational purposes. We do not access or use this data for tracking or profiling.
  • Anti-spam and security protections — Cloudflare's security services may process limited technical data to distinguish legitimate visitors from automated or malicious traffic and to protect the Website against abuse.

c. Cookies and similar technologies

We do not currently set marketing, advertising, or analytics cookies, and we do not use browser local storage or session storage to track visitors. Where legally required, we will obtain your consent before placing any non-essential cookies or similar technologies in the future, and this policy will be updated accordingly.

d. Information we do not collect

We do not knowingly collect sensitive or special categories of personal data (such as health information, biometric data, religious beliefs, precise geolocation, or government identifiers). We do not collect or use "sensitive personal information" for purposes requiring limitation under the CPRA. Please do not submit such information through the Website.

03How we use your personal data and our lawful bases

We process personal data only where a lawful basis exists under applicable law — including your consent, the performance of or steps toward a contract, compliance with legal obligations, or our legitimate interests where these are not overridden by your rights.

PurposeData usedPrimary lawful basis
Sending updates, announcements, and content about DeepNotch's servicesEmail addressYour consent, which you may withdraw at any time
Responding to enquiries and correspondenceName, email, message contentsOur legitimate interests in responding to you, or pre-contractual steps taken at your request
Operating, securing, and maintaining the WebsiteTechnical / log dataOur legitimate interests in Website security and integrity
Complying with legal obligationsAny of the above, as requiredLegal obligation

Marketing communications: we send updates only to individuals who have subscribed. Every marketing email includes a functioning unsubscribe link. You may also withdraw consent at any time by emailing info@deepnotch.ai. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

We do not sell or rent your personal data, and we do not share it for cross-context behavioral advertising.

04Artificial intelligence and automated decision-making

Although DeepNotch advises on AI governance and security, we want to be explicit about our own practices:

  • We do not use personal data submitted through the Website, subscription form, or email correspondence to train AI models — ours or anyone else's.
  • We do not use artificial intelligence or automated decision-making to make decisions that produce legal or similarly significant effects about individuals.
  • We do not carry out profiling of Website visitors.

05Data protection principles

We are committed to the core principles of responsible data handling: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy (we take reasonable steps to keep personal data accurate and up to date, and you may request corrections at any time); storage limitation; integrity and confidentiality; and accountability. DeepNotch maintains internal privacy governance practices and periodically reviews its compliance with applicable privacy laws.

06Who we share your data with

We share personal data only with the service providers ("processors") necessary to operate the Website:

  • Cloudflare, Inc. — provides content delivery, DNS, and security services for the Website. As traffic to the Website passes through Cloudflare's network, Cloudflare may process technical data such as IP addresses and request metadata to deliver the Website and protect it against malicious traffic.
  • Google — used to receive and manage email communications and subscription requests.
  • GitHub, Inc. (GitHub Pages) — hosts the Website and may process technical log data as described above.
  • LinkedIn — if you interact with our LinkedIn company page, LinkedIn processes your data under its own privacy policy.

We work only with providers that maintain appropriate data protection and security standards, and we rely on contractual terms requiring confidentiality, security, and compliance with applicable privacy laws. Our service providers may change over time as our operations evolve; a current list is available on request at info@deepnotch.ai.

We may also disclose personal data where required by law, regulation, court order, or lawful request by a public authority, or to establish, exercise, or defend legal claims.

Business transfers: if DeepNotch is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction. We will require the receiving party to honor commitments materially consistent with this Privacy Policy, and we will notify you of any material change in control or use of your personal data where required by law.

07International data transfers

DeepNotch operates internationally, and the service providers above may store or process personal data in countries other than your own, including the United States.

Where personal data is transferred across borders from jurisdictions that restrict such transfers, we rely on transfer mechanisms recognized under applicable law, including: adequacy decisions; Standard Contractual Clauses (SCCs); the UK International Data Transfer Agreement or UK Addendum; the EU–U.S. Data Privacy Framework (where the recipient is certified); Binding Corporate Rules; or other lawful safeguards, including your explicit consent where applicable.

08How long we keep your data

We retain personal data only as long as necessary for the purposes described in this policy. Our general retention criteria:

Data categoryRetention period
Subscriber email addressesUntil you unsubscribe or request deletion; removed from active mailing records within 30 days thereafter
General enquiries and correspondenceUp to 24 months after the last interaction, unless a longer period is needed for an ongoing relationship
Records required for legal, tax, or regulatory purposesFor the period required by applicable law
Technical / server log dataRetained by our hosting provider according to its own retention schedules; we do not maintain separate copies

When personal data is no longer needed, it is deleted or anonymized.

09How we protect your data

We apply technical and organizational measures appropriate to the nature and scale of the data we process, including:

  • Serving the Website exclusively over HTTPS (TLS encryption in transit);
  • Collecting only the minimum data necessary;
  • Restricting access to personal data to authorized persons on a least-privilege basis;
  • Multi-factor authentication and access controls on the accounts and systems used to receive and store personal data;
  • Using reputable service providers with established, independently operated security programs;
  • Periodic review of our data handling practices.

Incident response and breach notification: we maintain procedures for identifying, investigating, documenting, and responding to security incidents involving personal data. Where required under applicable law, we will notify affected individuals and the relevant supervisory or regulatory authorities within the legally prescribed timelines.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10Your privacy rights

Subject to applicable law, you have rights over your personal data. We extend the following core rights to all visitors, regardless of location: the right to access your data, to correct it, to have it deleted, and to withdraw consent at any time.

Depending on your jurisdiction, you may have additional rights:

EEA / UK — GDPR / UK GDPR

Access; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interests; withdrawal of consent; and the right to lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority or the UK Information Commissioner's Office).

Kingdom of Saudi Arabia — PDPL

The rights to be informed; to access and obtain a copy of your data; to request correction, completion, or updating; to request destruction of data no longer needed; to withdraw consent; and to lodge a complaint with the competent authority (SDAIA).

India — DPDP Act 2023

The rights to access a summary of your personal data and processing activities; to correction and erasure; to grievance redressal; to nominate another individual to exercise your rights in the event of death or incapacity; and to withdraw consent.

California — CCPA / CPRA

The rights to know, delete, and correct; to opt out of the sale or sharing of personal information (we do not sell or share personal information as defined by the CCPA/CPRA); to limit the use of sensitive personal information (we do not collect it for purposes requiring limitation); and to non-discrimination for exercising your rights.

Other jurisdictions

E.g., Brazil, Canada, Singapore, Australia, UAE, Qatar, South Africa — you may exercise the rights available under your local law by contacting us; we will honor them as required.

Do Not Track: at this time, the Website does not respond to browser "Do Not Track" signals, as no uniform standard has been adopted. We do not track visitors across third-party websites in any case.

How to exercise your rights

  1. Submit your request by email to info@deepnotch.ai, describing the right you wish to exercise.
  2. Verification: we may request reasonable additional information to verify your identity before fulfilling a request, to protect your data from unauthorized access.
  3. Response: we will respond within the timeframe required by applicable law — generally within 30 days. If we need more time for complex requests, we will tell you why and when to expect a response.
  4. Appeal: if you are dissatisfied with our response, you may reply to ask us to reconsider, and we will escalate your request for internal review.
  5. Complaint: you always retain the right to lodge a complaint with the data protection authority in your jurisdiction.

11Children's privacy

The Website is intended for professionals and business audiences and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18 (or the higher minimum age required under applicable law). If you believe a child has provided us with personal data, contact us at info@deepnotch.ai and we will delete it promptly.

12Third-party links

The Website may contain links to third-party sites and platforms (such as LinkedIn). We are not responsible for the privacy practices or content of those third parties, and we encourage you to review their privacy policies before providing them with personal data.

13Language

This Privacy Policy is provided in English. Where required under applicable law, translated versions may be provided upon request.

14Changes to this privacy policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The version number and "Last Updated" date at the top of this page indicate the current revision. Material changes will be highlighted on the Website. Your continued use of the Website after changes take effect constitutes acceptance of the revised policy.

v2.1 — 21 July 2026 — Updated service providers to reflect Cloudflare-delivered infrastructure.
v2.0 — 21 July 2026 — Expanded lawful basis, transfers, security, retention, rights process, and AI disclosures.
v1.0 — 20 July 2026 — Initial publication.

15Contact us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data: