Legal / Privacy

Your data.
Plainly handled.

This policy explains what information the NuvaKit website and services collect, why it is used, and the choices available to you.

01 / Scope & responsibility

This policy describes personal information handled in connection with the NuvaKit marketing website, product access gateway, business enquiries and service administration. NuvaKit is the name used for the software business founded by Archit Bhatti. Contact details appear below.

This notice also covers enquiries sent through the Campus and Developers pages. It does not replace a customer deployment's own privacy notice or a separate recruitment, student-engagement or employment notice.

For a product deployed under a customer's brand, the customer normally determines the purposes of processing its users' information. Where NuvaKit handles that information on the customer's instructions, the applicable service agreement and data-processing terms govern that processing. Contact the operator of that product about its users' data; we can help route a request if you contact us.

02 / Information involved

  • Enquiries: the quote form collects your name, email address, product selection and message. Email enquiries may also contain an organisation, project requirements, portfolio, CV or other information you choose to include.
  • Product access: an access request collects your name, email, company and requirements, together with the product requested. Access administration records the product, grant and session expiry, redemption and revocation status, and authorised review actions. Tokens and session credentials are stored as cryptographic digests rather than plaintext credentials.
  • Customer administration: contact, order, invoice, payment-status and support correspondence supplied in the course of an agreed engagement. This website has no payment-card entry form.
  • Website requests: hosting infrastructure receives technical details needed to serve a page, including an IP address, requested resource and browser request information. Server or infrastructure logs may retain request times, response status and diagnostic information.

Submitting a quote or access-request form saves the entered details in NuvaKit's restricted enquiry store for later review. It does not send an email receipt, promise a response time or subscribe you to marketing. Email links remain available and open your own email application. Please do not include passwords, payment-card details or sensitive personal information in an initial enquiry.

CDA improvement work & assessment

For the optional CDA improvement service, the agreed input is customer-approved, redacted SQL queries and definitions. We do not use customer rows, result sets or raw data extracts for that improvement work. SQL can itself contain personal or confidential information in literal values, comments or identifiers; it must be reviewed and redacted before sharing. This is a service boundary, not a claim that every SQL statement is anonymous or that the deployed product never processes customer data.

Customer-run exploratory data analysis and answer checks remain in the customer's environment. Only approved metadata and non-sensitive findings are shared for scoping. Before any model processing or retraining, the service order and data-processing terms identify the method, permitted inputs, provider, access and retention. If a task cannot be completed within that boundary, a different authorised method must be agreed first.

03 / Browser storage & external requests

The current marketing pages do not use browser storage for navigation or visitor profiling. An earlier version stored a temporary page-switching value in session storage; the current switcher does not read or write that value. Any value remaining from the earlier version is normally cleared when its browser tab closes.

The quote form uses server-side validation, a hidden spam-trap field and temporary request limits, without a third-party CAPTCHA. These measures may use request information to limit abuse; they do not create a marketing profile. The marketing-site code does not set cookies or include an analytics tracker or advertising pixel. On product access pages, essential host-specific cookies maintain an authorised session and protect form submissions. The access-session cookie has a four-hour lifetime; the server rejects access earlier if the grant expires or access is revoked. The request-security cookie is a browser-session cookie. Logout clears the access-session cookie. These cookies are not used for advertising. The product application itself may have additional storage needed for its functions, which must be disclosed in its own notice. You can clear or restrict browser storage in your browser settings.

Pages load fonts from Google Fonts at fonts.googleapis.com and fonts.gstatic.com. Your browser connects to Google to request them, sending your IP address and request information. Google's handling of those requests is described in its privacy policy. The founder photograph is served from this website.

NuvaKit product access pages are covered by this notice. Customer-operated deployments and external sites, including LinkedIn, have their own operators and privacy notices. If we add analytics or other tracking, we will update this notice and implement any legally required choice mechanism before using it.

04 / Purposes & recipients

Information provided in an enquiry is used to review and respond to the request, discuss the requested work and manage the resulting relationship. Customer records are used to deliver agreed services, handle support and billing, maintain security, resolve disputes and meet applicable record-keeping obligations. Campus and developer enquiries are used to discuss the opportunity you contacted us about.

Website hosting uses Google Cloud Run, and quote submissions, access requests and access-administration records are stored in Google Cloud Firestore. Access is limited through cloud identity and access controls to authorised operators. Separate email correspondence passes through the providers involved in sending and receiving that message. For an agreed service, information may need to be shared with infrastructure suppliers, payment providers or professional advisers involved in that engagement, limited to the relevant purpose. Providers involved in a customer deployment are addressed in the service and data-processing arrangements for that deployment.

Information may be disclosed where legally required or necessary to address unlawful activity or protect legal rights. An enquiry is not permission to publish your name, testimonial or project details. It also does not by itself subscribe you to promotional email.

05 / Location & security

The website backend and its dedicated enquiry and access database are configured in Google Cloud's us-central1 region in the United States. Font and email providers may process information in other countries. Customer deployments are subject to the transfer restrictions and safeguards required by applicable law and their data-processing agreements.

No internet transmission or storage method can be guaranteed completely secure. Do not send production credentials or customer datasets through a general enquiry form or email; agree an appropriate transfer method and access arrangements first. Report suspected exposure of information to the contact below.

06 / Retention & deletion

Quote submissions and access requests are assigned an expiry 180 days after they are saved. Access sessions expire within four hours, with their stored records scheduled for deletion at expiry. Grant metadata is scheduled for deletion 90 days after its access expiry, and administrative audit events 90 days after the event. Revocation prevents further authorised access without waiting for record deletion. Firestore's time-to-live process deletes expired records asynchronously, so deletion is not necessarily immediate at the expiry time. The backend does not write enquiry contents to its application logs. For abuse prevention, it derives a keyed identifier from the request IP address and stores shared request counters with an expiry of no more than 20 minutes; it does not store the source IP address in the quote record. Hosting infrastructure may separately retain request metadata under its logging configuration.

Other personal information is retained for as long as reasonably necessary for its purpose: administering or delivering an agreed service, maintaining security, meeting a legal record-keeping obligation or resolving a dispute. Where a legal obligation or dispute requires longer retention, we limit further use to that purpose. We do not retain information indefinitely merely because it might be useful.

When information is no longer needed, we delete it or anonymise it. Copies in backups are removed through the applicable backup lifecycle and remain subject to these retention limits; they are not used for unrelated purposes. If a backup is restored, applicable deletion requests must be reapplied.

Customer-data export, return and deletion follow the applicable data-processing agreement and law, including copies held by service providers. Email us to ask about a particular record or to request deletion; we will explain any retention requirement that prevents us from fulfilling the request in full.

07 / Requests & complaints

You can email archit@kateindustries.com to request access to, correction of or deletion of information about you, raise a privacy complaint, or ask about its use. Where processing relies on consent, you can ask to withdraw that consent; this does not undo processing already lawfully performed and may affect a service that needs that information.

Describe the relationship or enquiry concerned and the outcome you seek. We may ask for proportionate information to verify your identity or authority, but do not send identity documents unless requested through an appropriate channel.

Legal rights, exceptions, response deadlines and any right to approach a regulator depend on the law applicable to you and the provisions in force at the time. Nothing here restricts those rights. For data handled on a customer's instructions, we may refer the request to that customer.

08 / Students & children

Campus is directed at undergraduates, who may include people under 18. If you are under 18, ask a parent or guardian to contact us before sending an application or personal documents. We will establish the age, consent and engagement requirements applicable to a minor before proceeding with their application or enrolment.

A parent or guardian concerned about information already sent can contact Archit Bhatti to request review or deletion, subject to applicable law. This notice does not treat a child's use of the website as parental consent.

09 / Contact & updates

Contact Archit Bhatti at archit@kateindustries.com.

NuvaKit
Kate Vasti Rd, Mithila Nagari, Pimple Saudagar, Pimpri-Chinchwad, Pune, Maharashtra 411027, India

NuvaKit is the business name used for the software business founded by Archit Bhatti. Use the contact above for questions about this website's information handling or to raise a privacy complaint.

This policy takes effect on 22 September 2026. We will show an updated effective date when it changes and communicate material changes as required by applicable law. A change to this notice does not replace consent or another legal basis where one is required.