Legal & Compliance
Privacy Policy.
This Privacy Policy sets out how JM Design Studio Private Limited (“JMDS”, “we”, “our”, or “us”) collects, processes, stores, and protects personal information through our websites (https://joshmachines.in and joshmachines.com), services, and customer interactions.
1. Our Details & Legal Identity
JM Design Studio Private Limited(referred to as “JMDS”, “we”, “our”, or “us”) is an enterprise technology solutions provider headquartered in India. We design, engineer, integrate, and manage business-critical applications, intelligent workflow platforms, and technology infrastructure for complex, operations-intensive organizations.
Our registered and principal office address is:
JM Design Studio Private Limited
#4, FF, Pocket 5, Block B, Sector 18, Rohini
New Delhi – 110089, India
Official Websites: https://joshmachines.in | https://www.joshmachines.com
Primary Contact Email: studio@joshmachines.com
Telephone: +91 74982 20248
Operating Hours:Monday – Friday, 9:30 AM – 6:30 PM IST
Depending on your relationship with us and applicable data protection legislation, JMDS acts as a Data Fiduciary(under India's Digital Personal Data Protection Act, 2023) or a Data Controller (under the EU/UK General Data Protection Regulation) for information collected directly through our website, contact channels, and client onboarding. When we process operational or customer data on behalf of our enterprise clients within custom systems or cloud environments, we act as a Data Processor in accordance with our client agreements.
2. Policy Summary & Core Principles
We adhere to internationally recognized privacy principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
Data Fiduciary / Controller: JM Design Studio Private Limited
What Information We Collect: Contact details (name, business email, phone, company name, role), communication history, technical connection data (IP addresses, device metadata, browser information), and functional session cookies.
Why We Collect It: To evaluate and respond to enterprise inquiries, provide architectural consultations, deliver contracted technology services, maintain website integrity and cybersecurity, and fulfill regulatory obligations.
Do We Sell or Share Personal Data: No. We do not sell your personal data, nor do we share or disclose personal information to third parties for cross-context behavioral advertising.
Your Control: You have the right to access, rectify, erase, or export your personal data, withdraw consent, and submit grievances at any time.
3. Applicable Legal Frameworks & Lawful Grounds
We process your personal information strictly in compliance with applicable data protection laws, including:
- India – Digital Personal Data Protection Act, 2023 (DPDPA) & IT Act, 2000: Processing is conducted based on valid, informed, and unconditional consent provided by the Data Principal, or under recognized “certain legitimate uses” such as voluntary provision of data for specific service inquiries, contract fulfillment, or statutory compliance.
- European Union & United Kingdom – GDPR / UK GDPR: Processing is based on lawful grounds under Article 6:
- Consent (Art. 6(1)(a)): Where you explicitly consent to receiving newsletters, updates, or specific marketing communications.
- Contractual Necessity (Art. 6(1)(b)): Where processing is necessary to prepare, negotiate, or perform an agreement or RFP response with your organization.
- Legal Obligation (Art. 6(1)(c)): Where compliance with applicable statutory, tax, financial, or cyber-incident reporting laws is mandated.
- Legitimate Interests (Art. 6(1)(f)): For safeguarding network security, preventing fraud, operating corporate infrastructure, and managing business-to-business relationships, where not overridden by your fundamental rights.
- United States – State Consumer Privacy Laws (CCPA / CPRA, VCDPA, etc.): We provide required notices at collection, honor consumer access, correction, and deletion requests, and verify that no sale or cross-context behavioral sharing occurs.
4. Information We Collect
We collect personal information through direct interactions, automated technologies, and legitimate commercial touchpoints:
A. Information You Provide Voluntarily
- Contact & Inquiry Data: When submitting an inquiry through our contact form, scheduling a consultation, or emailing us, we collect your full name, work email address, telephone number, organization name, job title, and project or operational requirements.
- Business Relationship Information: Information exchanged during contract negotiations, master services agreements (MSAs), billing documentation, and tax registration details (such as GSTIN or corporate identification).
- Communications: Any feedback, technical requirements, or correspondence exchanged via email, video conference, or messaging channels.
B. Information Collected Automatically
- Server Logs & Network Identifiers: When accessing our website, our infrastructure automatically records your IP address, browser type and version, operating system, referring URL, pages viewed, time stamps, and request response statuses.
- Security & Performance Telemetry: Anonymized metrics, load timings, and error logs to ensure server stability, prevent denial-of-service attempts, and protect system availability.
C. Information from Third Parties
We may receive verified professional contact data through commercial enterprise directories, industry platforms (such as LinkedIn), or joint business partners strictly where you have made your professional details publicly available or consented to such referral.
5. How We Use Your Information
We use collected information solely for genuine business operations and service delivery:
- Responding to Inquiries: Reviewing and answering your messages, preparing tailored enterprise solutions, and scheduling discovery calls.
- Delivering Services & Systems: Engineering, deploying, and supporting enterprise applications, intelligent workflows, and managed technology under signed contracts.
- Security & Fraud Prevention: Protecting our web services, network perimeter, intellectual property, and client data against cyber threats, unauthorized access, and malicious activity.
- Legal & Regulatory Compliance: Complying with accounting rules, tax authorities, legal audit mandates, and regulatory authorities (such as CERT-In directives).
- B2B Communications: Sharing necessary administrative alerts, service notices, and updates directly relevant to active commercial relationships.
6. Artificial Intelligence, Analytics & Automated Decision-Making
JMDS designs and implements intelligent workflow platforms and applied AI solutions for enterprises. Regarding our own website and data practices:
- No Public Model Training: We never use client confidential information, proprietary workflow data, or personal information submitted through our website to train public foundation models (such as commercial LLMs) without explicit written agreement.
- Governed Enterprise AI Workflows: Any AI-driven components deployed within our client solutions adhere to strict data boundaries, zero-data-retention APIs where applicable, and private on-premise or sovereign cloud deployments.
- No Significant Automated Decision-Making: We do not subject website visitors or individual users to automated decision-making or profiling that produces legal or similarly significant effects concerning them.
8. Disclosure to Service Providers & Third Parties
We do not sell, rent, or trade your personal information. Disclosures are limited to trusted partners under strict confidentiality and data protection obligations:
- Infrastructure & Cloud Hosts: High-security cloud hosting providers, content delivery networks (CDNs), and enterprise email platforms that maintain SOC 2, ISO 27001, and GDPR compliance certifications.
- Professional Advisors: Chartered accountants, legal counsel, auditors, and compliance consultants bound by statutory obligations of professional secrecy.
- Payment Processors: For commercial invoices, payments are processed via licensed banking partners and PCI-DSS compliant payment gateways. We do not store full payment card numbers on our web servers.
- Statutory & Law Enforcement Authorities: Where mandated by law, court orders, or official governmental directives (such as Indian cybersecurity incident reporting regulations).
9. Cross-Border Data Transfers
Because we work with enterprise clients globally, personal data may be stored or processed in India, where our primary operations are situated, or in regional cloud data centers.
When transferring data across international borders:
- We verify that transfers comply with applicable data transfer regulations, including the EU/UK Standard Contractual Clauses (SCCs) and Indian DPDPA cross-border guidelines.
- We implement robust supplementary technical safeguards, including end-to-end TLS encryption in transit and AES-256 encryption at rest.
- For enterprise client engagements requiring local data sovereignty, we support dedicated in-country data residency configurations.
10. Data Retention & Secure Disposal
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, tax, or reporting requirements:
- General Inquiries & RFP Communications: Retained for the duration of the inquiry and active dialogue, plus up to 24 months thereafter to facilitate follow-up discussions and maintain business audit trails.
- Client Contractual & Billing Records: Retained for a minimum of 8 years following the conclusion of the contract, in compliance with Indian corporate and taxation statutes (e.g., Companies Act, 2013 and Income Tax Act, 1961) and relevant international laws.
- Web Server & Security Logs: Retained for up to 180 days for security analysis, threat investigation, and IT compliance, after which they are systematically deleted or aggregated.
Upon the expiration of the applicable retention schedule, data is permanently erased or sanitized using secure cryptographic disposal standards.
11. Information Security & Technical Safeguards
We deploy industry-standard technical, operational, and organizational security controls to protect personal information from unauthorized access, alteration, disclosure, or destruction:
- Transport Layer Security: All data transmitted to and from our website is encrypted using modern TLS 1.3 / HTTPS protocols.
- Encryption at Rest: Sensitive data stored within our databases and backups is protected with AES-256 bit encryption.
- Access Controls: Access to systems is strictly restricted under the Principle of Least Privilege (PoLP), governed by Role-Based Access Controls (RBAC), and protected by mandatory Multi-Factor Authentication (MFA).
- Network Defenses: Web Application Firewalls (WAF), automated rate limiting, continuous intrusion detection systems, and periodic vulnerability assessments.
- Incident Response: Documented security incident response procedures, including timely notifications to regulatory bodies (such as CERT-In within required timeframes) and affected parties in the unlikely event of a reportable data breach.
12. Your Data Protection Rights
Depending on your location and the laws applicable to your jurisdiction (such as India's DPDPA, the GDPR, or US State Privacy Laws), you may exercise the following rights regarding your personal data:
- Right to Access & Summary: Request confirmation of whether your data is being processed, obtain a summary of personal data held, and learn about the processing activities.
- Right to Rectification & Correction: Request prompt correction of inaccurate, incomplete, or outdated personal information.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data where it is no longer necessary for the original purpose or where you withdraw consent, subject to statutory retention obligations.
- Right to Restrict Processing: Request a pause or restriction on data processing during disputes regarding data accuracy or lawfulness.
- Right to Data Portability: Obtain a structured, machine-readable copy of the personal data you supplied to us.
- Right to Withdraw Consent: Where processing is predicated on consent, withdraw your consent at any time without retroactive impact on prior lawful processing.
- Right of Nomination (under DPDPA): Under the Indian DPDPA, you have the right to nominate an individual who shall exercise your data principal rights in the event of death or incapacity.
- Right to Non-Discrimination: We will not discriminate against you in pricing, service level, or responsiveness for exercising any of your legal privacy rights.
To exercise any of these rights, please email us directly at studio@joshmachines.com or submit an inquiry through our contact page. We review and fulfill verified requests within 30 calendar days or the timeline mandated by your jurisdiction's laws.
13. Grievance Redressal & Data Protection Officer
In compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, JMDS has designated a Grievance Redressal Officer to address any data protection concerns, complaints, or rights inquiries:
Designation:Grievance Redressal & Data Protection Officer
Organization: JM Design Studio Private Limited
Address:#4, FF, Pocket 5, Block B, Sector 18, Rohini, New Delhi – 110089, India
Email: studio@joshmachines.com(Subject line: “Privacy & Grievance Redressal”)
Direct Telephone: +91 74982 20248
Working Hours:Monday – Friday, 9:30 AM – 6:30 PM IST
Our Grievance Officer will acknowledge your complaint within 48 hours and endeavor to resolve your concern within the statutory period (not exceeding 30 days). If your grievance under the DPDPA is not resolved satisfactorily, you may escalate your complaint to the Data Protection Board of India (DPBI). Residents of the EU/UK also hold the right to lodge a complaint with their national Data Protection Authority (DPA).
14. Children's Privacy
Our website and technology solutions are designed exclusively for commercial, enterprise, and professional use. We do not knowingly solicit, collect, or process personal data from individuals under 18 years of age.
In alignment with Section 9 of India's DPDPA and international standards, we do not engage in behavioral monitoring, tracking, or targeted advertising directed at minors. If you believe that an individual under 18 has provided us with personal information without verifiable parental or guardian consent, please contact our Grievance Officer at studio@joshmachines.com, and we will take immediate steps to delete such information securely.
15. Updates to This Privacy Policy
We may periodically update this Privacy Policy to reflect advancements in technology, emerging legal precedents, operational changes, or revised statutory requirements (including regulatory rules promulgated under the DPDPA).
When modifications occur, the updated policy will be published on this page with an amended “Last Revised” date. In the event of material alterations that significantly impact your rights or how we handle your personal data, we will provide prominent notice on our website or directly communicate via email where practicable.
16. Contact Information & Assistance
If you have questions, feedback, or need clarification regarding this Privacy Policy or our security practices, please connect with us through any of our direct channels:
- Online Contact Form: Submit a request via our Contact Page
- Email: studio@joshmachines.com
- Phone: +91 74982 20248
- Postal Mail: JM Design Studio Private Limited, #4, FF, Pocket 5, Block B, Sector 18, Rohini, New Delhi 110089, India
