1. Who We Are
Insightrix™ is a specialist AI consulting studio headquartered in Paris (France), with a partner office in London (United Kingdom). We help regulated companies in finance, real estate, and B2B SaaS design, build, and deploy AI systems on EU-resident infrastructure.
Registered address: 60 Rue François 1er, 75008 Paris, France
Data Protection Contact: aru.bhardwaj@insightrix.eu
For the purposes of applicable data protection legislation (including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, and the French Loi Informatique et Libertés), Insightrix is the data controller of personal data collected through this website and our services.
2. Data We Collect
We collect personal data in the following ways:
2.1 Data You Provide Directly
- Contact forms and enquiries: Name, email address, phone number, company name, job title, and any information you include in your message.
- Booking a call: Name, email, and scheduling preferences via our booking platform (Zcal).
- Newsletter popup: Name, email address, phone number, company name, and service interest.
- Client engagements: Business contact details, project-related information, and contractual documentation.
2.2 Data Collected Automatically
- Technical data: IP address, browser type and version, operating system, referral source, pages visited, time spent on pages, and click patterns.
- Cookies: We use essential cookies only. See Section 9 for details.
2.3 Data We Do Not Collect
We do not collect sensitive personal data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or sexual orientation). We do not process data of children under 16.
3. How We Use Your Data
We process your personal data for the following purposes:
- Responding to enquiries: To reply to your contact form submission, email, or call booking within 24 hours.
- Providing our services: To deliver AI consulting, development, and advisory services under our contractual obligations.
- Sending relevant communications: To share insights, articles, and updates that are relevant to your expressed interests. You can opt out at any time.
- Improving our website: To understand how visitors use our site and improve user experience.
- Legal compliance: To comply with applicable laws, regulations, and legal processes.
We do not sell, rent, or trade your personal data to third parties. We do not use your data for automated decision-making or profiling.
4. Legal Basis for Processing
Under the GDPR and UK GDPR, we rely on the following lawful bases:
- Consent (Article 6(1)(a)): When you submit a contact form or sign up for communications, you consent to us processing your data for that purpose. You can withdraw consent at any time.
- Contractual necessity (Article 6(1)(b)): When we process data to deliver services you have engaged us for.
- Legitimate interests (Article 6(1)(f)): When we process data to improve our website, respond to enquiries, or send relevant business communications. We balance our interests against your rights and freedoms.
- Legal obligation (Article 6(1)(c)): When we are required to process data to comply with legal or regulatory requirements.
5. Data Sharing
We share your data only with the following categories of recipients, and only to the extent necessary:
- Email service provider (Resend): To deliver enquiry notification emails. Resend processes data as a processor under our instructions.
- Hosting provider (Cloudflare): Our website is hosted on Cloudflare Pages. Cloudflare may process technical data (IP addresses, request logs) as part of their infrastructure services.
- Scheduling platform (Zcal): When you book a call, your scheduling data is processed by Zcal.
- Professional advisors: Legal, accounting, or regulatory advisors where necessary.
- Law enforcement: Where required by law, court order, or regulatory authority.
We do not share your data with marketing platforms, advertising networks, or data brokers.
6. International Data Transfers
As we operate across France, the United Kingdom, and India, your data may be transferred between these jurisdictions:
- France ↔ UK: Transfers between the EU and UK are covered by the EU adequacy decision for the UK (adopted June 2021).
- EU ↔ UK: Where data is transferred between our Paris HQ and London partner office, we rely on the UK adequacy decision and, where applicable, Standard Contractual Clauses (SCCs).
- Engineering contractors outside the EEA: If we engage an individual engineering contractor based outside the European Economic Area, we put SCCs (or equivalent UK IDTA) in place before any personal data is shared.
- Cloudflare: Operates a global network. EU data is processed within the EU under Cloudflare's Data Processing Addendum.
- Resend: Data is processed in the EU (eu-west-1 region) as configured for our account.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
- Enquiry data: 24 months from the date of enquiry, unless a business relationship is established.
- Client data: Duration of the engagement plus 6 years (for legal, tax, and accounting obligations).
- Website analytics: Aggregated and anonymised. No personal data is retained beyond the browsing session.
- Marketing communications: Until you unsubscribe or withdraw consent.
After the retention period, data is securely deleted or anonymised.
8. Your Rights
Under the GDPR and UK GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15): Request a copy of the personal data we hold about you.
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your data where there is no compelling reason for continued processing.
- Right to restrict processing (Article 18): Request that we limit how we use your data.
- Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format.
- Right to object (Article 21): Object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please email aru.bhardwaj@insightrix.eu. We will respond within 30 days.
Supervisory authorities: If you are unsatisfied with how we handle your data, you have the right to lodge a complaint with:
- France: Commission Nationale de l'Informatique et des Libertés (CNIL) — www.cnil.fr
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
9. Cookies
Our website uses only essential cookies required for basic functionality:
- Lead popup cooldown: A localStorage item (
insightrix_popup_shown) that stores a timestamp to prevent showing the popup repeatedly. This is not a tracking cookie and contains no personal data. - Cloudflare security cookies: Cloudflare may set cookies for security purposes (e.g., bot detection, DDoS protection). These are strictly necessary and exempt from consent requirements under ePrivacy rules.
We do not use analytics cookies, advertising cookies, or third-party tracking cookies. We do not use Google Analytics, Facebook Pixel, or any similar tracking technologies.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- HTTPS encryption for all website traffic (TLS 1.3)
- Cloudflare Web Application Firewall (WAF)
- API keys and credentials stored securely, never exposed client-side
- Access to personal data limited to authorised personnel only
- Regular review of data processing activities
11. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. Any material changes will be posted on this page with an updated "Last updated" date. We encourage you to review this policy periodically.
12. Contact Us
If you have any questions about this privacy policy or our data practices, please contact us:
- Email: aru.bhardwaj@insightrix.eu
- Address: 60 Rue François 1er, 75008 Paris, France
- Website: insightrix.eu | insightrix.co.uk
13. Trademarks
“Insightrix™”, “Insightrix.”, the “Insightrix” word mark, and the Insightrix logo (collectively, the “Insightrix Marks”) are trademarks of Aru Bhardwaj operating as Insightrix, with offices in Paris (France) and a partner office in London (United Kingdom).
All other trademarks, service marks, product names, brand names, and company names referenced on this website—including without limitation Mistral, Anthropic Claude, OpenAI, Hugging Face, Scaleway, OVHcloud, AWS, Google, Microsoft Azure, Pennylane, Sage, Xero, Stripe, HubSpot, Supabase, Cloudflare, and similar third-party marks—are the property of their respective owners and are used here solely for descriptive and identification purposes. Their inclusion does not imply endorsement, partnership, or affiliation unless explicitly stated.
You may not use the Insightrix Marks (including in domain names, social-media handles, marketing materials, or AI-generated content presented as official Insightrix output) without our prior written permission. For licensing or attribution enquiries, please contact aru.bhardwaj@insightrix.eu.