RecursX Innovations·India's Leading AI Company·We Build Our Own Systems·Custom LLMs · AI Models · IoT·From Idea to Deployment·Agentic AI · GenAI · Automation·Student-Founded · India-Built·Intelligence Inside Every Product·We Ship Fast. We Ship Smart.·RecursX Innovations·India's Leading AI Company·We Build Our Own Systems·Custom LLMs · AI Models · IoT·From Idea to Deployment·Agentic AI · GenAI · Automation·Student-Founded · India-Built·Intelligence Inside Every Product·We Ship Fast. We Ship Smart.·

Legal

Privacy Policy

This policy explains what personal data RecursX Innovations collects when you use recursx.com, why we collect it, who we share it with, how long we keep it, and the choices and rights you have over it. We wrote it to be read, not skimmed past.

Effective date: 10 August 2026Last updated: 10 August 2026Applies to: https://recursx.com

1. Who we are

RecursX Innovations (“RecursX”, “we”, “us”, “our”) is an India-based artificial-intelligence company. We design and ship custom large language models, agentic AI systems, generative-AI applications, IoT-connected products and production SaaS platforms, and we operate our own products including Goraahi, Transmeet, DailySamvaad, KhetSahayak, NeetraX and SwatchhX.

For the personal data described in this policy, RecursX Innovationsis the data fiduciary (under India’s Digital Personal Data Protection Act, 2023) and the data controller (under the EU/UK General Data Protection Regulation, where it applies). You can reach us at any time at contact@recursx.com.

2. Privacy governance and accountability

Privacy at RecursX is somebody’s named job, not a shared assumption. We maintain a standing internal privacy function — supported by external legal counsel on Indian and EU data-protection matters — that is responsible for our compliance with applicable privacy law and with industry-standard privacy practice.

Who is accountable

  • Data Protection Officer (privacy contact) — reachable at contact@recursx.com. This mailbox is monitored on business days and is the single front door for privacy questions, data-subject rights requests, breach reports and regulator correspondence.
  • Akshat Sharma, Co-Founder — accountable owner for data protection (akshat@recursx.com). Signs off this policy and our vendor data-processing terms, owns the record of processing activities, and is the escalation point if the DPO mailbox has not resolved your request.
  • Aditya, Co-Founder — accountable owner for security and engineering controls (aditya@recursx.com). Owns access control, encryption, retention and deletion mechanics across our website, chat backend and product infrastructure, and leads incident response.

What that function actually does

  • Reviews every new feature, integration and vendor before launch for the personal data it touches, and reshapes or rejects anything that collects more than it needs.
  • Maintains our record of processing activities, our retention schedule and our list of sub-processors, and keeps this policy in step with them.
  • Receives, verifies and answers data-subject rights requests within the statutory deadlines, and logs each request and how it was resolved.
  • Runs and documents data-protection impact assessments for higher-risk processing, including AI and model-training workloads.
  • Owns the incident-response and breach-notification procedure, including notifying the Data Protection Board of India, EU/UK supervisory authorities and affected individuals within the applicable timeframes.
  • Trains the team on handling personal data, confidentiality and secure development, and reviews this programme at least once a year.

3. Scope of this policy

This policy covers the RecursX marketing website at recursx.com — including the contact form, the on-site AI assistant, and the media and content served from it.

It does not cover:

  • Our individual products and their apps, each of which carries its own privacy notice governing the data collected inside that product.
  • Data we process on behalf of a client under a services agreement — see “Client and project data” below.
  • Third-party websites you reach by following a link from ours.

4. Information we collect

a. Information you give us directly

  • Contact form. When you submit the enquiry form on our home page we collect the name, email address and message you type into it. All three fields are required to send the form; if you would rather not use it, email us instead.
  • Email and direct outreach. If you email a member of our team (our founders’ addresses are published on the site), we receive whatever you choose to include — your name, email address, company, role, and the contents of your message and attachments.
  • AI assistant chat. The messages you type into the chat widget are sent to our backend so it can generate an answer. Please do not enter sensitive personal information, credentials, financial details or confidential material into the chat.

b. Information collected automatically

  • Technical and log data. Our hosting provider and our chat backend automatically record standard server logs when your browser requests a page or calls our API: IP address, timestamp, requested URL, HTTP status, referring URL, user-agent string, and approximate location derived from the IP address.
  • Device and browser data. Screen size, device type, operating system, browser and language preference, used to render the site correctly and to fix layout and performance problems.
  • Usage data. Pages viewed, time on page, scroll depth, whether the brand film was played, and which interface elements were used — in aggregate, to understand what people find useful.

c. What we do not collect

  • We do not ask for, and the site never requests, payment-card numbers, bank details, government identifiers, passwords or API keys. Never send these to us through the website.
  • We do not collect special-category data (health, biometrics, religion, political opinions, sexual orientation) through this website.
  • We do not buy personal data from data brokers or list vendors.
  • We do not run advertising trackers, retargeting pixels or ad-network cookies on this site.

5. How we use your information

  • To reply to your enquiry, answer questions about our products and services, and follow up on a conversation you started.
  • To prepare proposals, scopes of work, quotes and contracts when you ask us to.
  • To operate the AI assistant and return an answer to the question you asked.
  • To run, maintain, debug and secure the website and the chat backend — including detecting abuse, spam, scraping and denial-of-service attempts.
  • To measure and improve the site: which pages are read, where people drop off, what loads too slowly.
  • To review anonymised chat questions so we can improve the assistant’s answers and our product documentation.
  • To meet legal, tax, accounting and regulatory obligations, and to establish, exercise or defend legal claims.

We do not sell your personal data, we do not rent or trade it, and we do not use the contact details you give us to add you to a marketing list without your consent. If we ever want to send you a newsletter, we will ask first, and every such email will carry an unsubscribe link.

We do not use your personal data to make decisions about you by automated means alone that produce legal or similarly significant effects.

7. The RecursX AI assistant

The chat widget in the corner of the site is a product-guidance assistant. It works in two layers: a local guide that runs entirely in your browser and matches your question against our product catalogue, and a backend service that generates a written answer.

  • The text of your message is sent over an encrypted HTTPS connection to our chat backend at recursx-backend.recursx.com, which is operated by RecursX.
  • If the backend is unreachable, the widget silently falls back to the in-browser guide and your message is not transmitted anywhere.
  • Your conversation is held in your browser’s memory for the duration of the page visit and is cleared when you close or reload the tab. We do not attach it to a profile of you.
  • Backend request logs may include your message text, IP address and timestamp. We use them to keep the service running and to improve answer quality, and we retain them as described under “How long we keep data”.
  • The assistant produces informational responses about our products and can be wrong. Nothing it says is a binding quote, a commitment, or professional advice.
  • Please do not enter personal data about other people, confidential business information, credentials or financial details into the chat.

8. Cookies and similar technologies

RecursX does not set advertising or cross-site tracking cookies on this website. The site is a static export and needs no login, so it sets no authentication cookies either.

Technologies that may be used are limited to:

  • Strictly necessary storage — browser memory and local storage used to keep the interface working during your visit, such as holding the current chat conversation.
  • Analytics — where enabled, privacy-respecting analytics that measure aggregate traffic. We configure analytics to minimise personal data and we do not use it to build advertising profiles.
  • Third-party fonts and media — the site loads web fonts and may embed images served by third parties (see below). Those requests reveal your IP address and user-agent to the provider.

You can block or delete cookies and site storage in your browser settings at any time. Blocking storage may cause parts of the chat widget to behave unexpectedly, but the rest of the site will work normally. We honour Global Privacy Control and Do-Not-Track signals where our infrastructure receives them.

9. How we share information

We share personal data only in these situations:

  • Service providers. Vendors who host our site, deliver our email, store our form submissions and run our backend, acting on our instructions under contract and only for the purposes we set.
  • Our team. The RecursX people who need the information to reply to you — kept to the smallest number practical.
  • Professional advisers. Lawyers, accountants and auditors, bound by confidentiality, where genuinely needed.
  • Legal and safety. Where we are required by law, court order or a valid request from a public authority, or where disclosure is necessary to protect our rights, our users, or the security and integrity of our systems.
  • Business transfers. If RecursX is involved in a merger, acquisition, financing or sale of assets, personal data may transfer as part of that transaction. We will notify you and this policy will continue to apply until it is replaced.

We never sell your personal data or share it for cross-context behavioural advertising.

10. Third-party services we rely on

These are the external services involved in running this website. Each processes a limited slice of data, and each has its own privacy policy that governs what it does with it.

  • Google (Apps Script & Sheets) — receives contact-form submissions (name, email, message) and records them so we can respond.
  • Google Fonts — serves the typefaces used on the site; font requests expose your IP address and user-agent to Google.
  • Google user-content hosting — some profile images shown on the site are served from Google’s image CDN (lh3.googleusercontent.com), which likewise sees the request metadata.
  • RecursX chat backend — our own service at recursx-backend.recursx.com, which receives AI-assistant messages and returns answers.
  • Website hosting and CDN — serves the static site and keeps standard access logs.
  • Business email — our mail provider stores correspondence sent to our @recursx.com addresses.

11. International data transfers

RecursX operates from India. Some of the providers above store or process data on servers outside India, including in the United States and the European Union. When personal data protected by the GDPR moves outside the EEA or the UK, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, an adequacy decision, or the provider’s certification under an approved transfer framework.

You may request details of the safeguards applied to a specific transfer by writing to contact@recursx.com.

12. How long we keep data

  • Contact-form submissions and email correspondence: kept for up to 24 months after our last exchange, so we can pick up the thread if you come back, then deleted or anonymised.
  • Records tied to a signed contract, invoice or tax obligation: kept for as long as the applicable statutory retention period requires, typically up to 8 years.
  • Chat-assistant conversations: held only in your browser for the visit; backend request logs are retained for up to 90 days for security and quality purposes.
  • Server and access logs: retained for up to 12 months, then deleted or aggregated into non-identifying statistics.
  • Aggregated, de-identified analytics that cannot be linked back to you: retained indefinitely.

When a retention period ends we delete the data or irreversibly anonymise it. Backups are cycled out on their own schedule, so a deleted record may persist in an encrypted backup for a short additional period before it is overwritten.

13. How we protect your data

  • All traffic to recursx.com and to our chat backend is encrypted in transit with TLS/HTTPS.
  • Access to form submissions, email and backend systems is restricted to the team members who need it, protected by strong authentication and multi-factor authentication where available.
  • We collect the minimum data needed and avoid storing anything sensitive on this website at all.
  • We patch dependencies, review code changes, and monitor our services for abuse and unusual activity.

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. If a personal-data breach occurs that is likely to cause you harm, we will notify the appropriate supervisory authority and affected individuals as required by applicable law, and tell you what happened and what to do about it.

14. Your rights and choices

Subject to the law that applies to you, you have the right to:

  • Access — obtain confirmation of whether we process your personal data and receive a copy of it.
  • Correction — have inaccurate or incomplete data about you corrected or completed.
  • Erasure — ask us to delete your personal data where we no longer have a valid reason to keep it.
  • Restriction — ask us to pause processing while a dispute about accuracy or legitimacy is resolved.
  • Objection — object to processing based on our legitimate interests, and object at any time to direct marketing.
  • Portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
  • Withdraw consent — at any time, where our processing rests on consent.
  • Nominate — under the DPDP Act, nominate another individual to exercise your rights in the event of your death or incapacity.
  • Complain — lodge a complaint with your data-protection authority, or with the Data Protection Board of India.

To exercise any of these, email contact@recursx.com with “Privacy request” in the subject line and tell us what you want us to do. We will respond within 30 days. We may ask for enough information to verify your identity before acting — that check exists to stop someone else obtaining or deleting your data. Exercising your rights is free; we will only charge for a request that is manifestly unfounded or excessive, and we will tell you before we do.

15. Data obtained via platform APIs

Some RecursX products and integrations obtain personal data from third-party platforms through their official APIs — including the LinkedIn Member Data Portability API — and always with the explicit, informed authorisation of the member whose data it is. We treat that data as belonging to the member, not to us.

a. How we obtain and use it

  • We receive data only after the member completes the platform’s own consent flow and grants us access. We never scrape, buy, or otherwise acquire platform data outside the sanctioned API.
  • We request the narrowest scopes needed for the feature the member asked for, and nothing beyond them.
  • We use the data solely to deliver that feature to that member. We do not sell it, share it for advertising, or repurpose it for unrelated products.
  • We do not use member data obtained via these APIs to train general-purpose or third-party AI models unless the member has separately and explicitly opted in.
  • We honour the originating platform’s API terms, developer agreement and data-handling requirements, and we delete data when our access is revoked or the platform requires it.

b. Data subject rights over data obtained via these APIs

RecursX has the technical and operational capability to comply with all relevant data subject rights for data obtained through the LinkedIn Member Data Portability API and any comparable platform API. Our systems are built so that every record can be traced back to the member it belongs to, exported, corrected or destroyed on request. A member may ask us to:

  • Access — confirm what data we hold about them, where it came from, what we use it for and who it has been shared with.
  • Port / export — receive a copy in a structured, commonly used, machine-readable format (JSON or CSV).
  • Correct — rectify data that is inaccurate, outdated or incomplete.
  • Erase — delete their data from our production systems, with deletion propagating to backups on the next backup cycle, and to any sub-processor that received it.
  • Restrict or object — pause a particular use of their data, or object to it.
  • Withdraw authorisation— revoke our API access at any time, either through the platform’s own settings or by telling us. On revocation we stop retrieving new data and delete what we hold, unless a specific legal obligation requires us to keep a record.

Send any such request to our Data Protection Officer at contact@recursx.com, or escalate to akshat@recursx.com or aditya@recursx.com. We acknowledge requests within 5 business days and complete them within 30 days, free of charge. We verify that the requester controls the account in question before acting, and we confirm in writing once the request has been carried out.

16. Children's privacy

This website is aimed at businesses and professionals and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data through this site, write to contact@recursx.com and we will delete it promptly.

17. Client and project data

When we build and operate AI systems for a client, any personal data inside that client’s systems, datasets or workloads is processed by us as a data processor on the client’s instructions, under the terms of the services agreement and data-processing agreement signed with that client — not under this policy.

  • We do not use client data to train general-purpose models for other customers unless the client has explicitly agreed in writing.
  • We hold client data under confidentiality obligations and access it only to deliver the agreed services and support.
  • We return or delete client data at the end of an engagement in line with the contract.
  • If you are an individual whose data sits inside a client’s system, please direct your rights request to that organisation; we will support them in answering it.

19. Changes to this policy

We may update this policy as our services, our vendors, or the law change. The version in force is always the one published at https://recursx.com/privacy-policy, and the effective date at the top tells you when it took effect. If we make a change that materially affects how we handle your personal data, we will make that clear on this page and, where the law requires it, ask for your consent again. Continuing to use the site after an update means you accept the revised policy.

20. Contact us

Questions, requests or complaints about privacy at RecursX go to our privacy contact:

RecursX Innovations

Data Protection Officer contact@recursx.com

Akshat Sharma, Co-Founder — accountable owner for data protection — akshat@recursx.com

Aditya, Co-Founder — accountable owner for security and engineering controls — aditya@recursx.com

Website: https://recursx.com

Country of operation: India

We aim to reply to every privacy enquiry within 30 days. If you are in the EEA or the UK and you are not satisfied with our response, you may complain to your local supervisory authority. In India, you may escalate to the Data Protection Board of India after raising the matter with us first.