Privacy Policy
Effective 28 July 2026
Friedbot Studio Private Limited ("Friedbot Studio", "we", "us") operates friedbotstudio.com. This policy explains what we collect when you visit the site or get in touch, who processes it on our behalf, and what you can ask us to do about it.
1.Defined terms
In this document, the following words carry the meanings given here. Where a word is defined in the Act, that meaning applies.
- the Act
- : the Digital Personal Data Protection Act, 2023, and the rules made under it.
- the Company, we, us, our
- : Friedbot Studio Private Limited, Corporate Identity Number U62010UP2025PTC222020, registered office O-1275 Gaur City Center, Greater Noida West, Uttar Pradesh 201318, India.
- the Site
- : the website published at friedbotstudio.com.
- personal data
- : data about you from which you can be identified, whether on its own or together with other data we hold.
- Data Fiduciary
- : the party that decides why and how personal data is processed. For the Site, that is us.
- Data Principal
- : the person the personal data is about. That is you.
- processor
- : a third-party service that handles personal data on our behalf and on our instructions. Every one we use is named in clause 8.
2.Who we are, and who to contact
2.1Friedbot Studio Private Limited is a company registered in India. Corporate Identity Number U62010UP2025PTC222020. Registered office: O-1275 Gaur City Center, Greater Noida West, Uttar Pradesh 201318, India.
2.2For any question about how we handle your personal data, and for any grievance, the person who will answer is Tushar Srivastava, reachable at [email protected]. Please mark your message for the attention of the Grievance Officer so it is routed correctly.
2.3Under India's data protection framework we are a Data Fiduciary in respect of the personal data described below, and you are a Data Principal.
3.Where this policy and the law differ
3.1This policy describes our practice. It does not, and cannot, reduce the rights you have under the Digital Personal Data Protection Act, 2023 and the rules made under it.
3.2If anything here is inconsistent with that Act or those rules, the Act and the rules govern and this policy is to be read accordingly. If we have described something less generously than the law requires, you get what the law requires. If we have promised something the law does not permit us to do, we will tell you rather than quietly do neither.
4.What this policy covers
4.1This policy covers friedbotstudio.com only.
4.2Our product sites are operated separately and have their own terms: the Baseline documentation at baseline.friedbotstudio.com, and PhantomFlow at phantomflow.dev. Work we do under a signed client contract is governed by that contract, not by this policy.
5.What you give us directly
5.1The contact form asks for your name, email address, subject, and message. A company name is optional. The waitlist forms ask only for an email address.
5.2We use this to reply to you and, where relevant, to keep a record of the conversation. We do not sell it, and we do not add you to a mailing list you did not ask for.
6.What we collect automatically
6.1When you visit the site, some information is collected without you entering it:
- (a)Usage analytics: pages viewed, links clicked, approximate location derived from your network, device and browser type.
- (b)Error and performance data: when something breaks, a technical report is generated so we can fix it.
- (c)Session recordings. The next section explains this one on its own.
7.Session recording
7.1We use Sentry Session Replay on a sample of visits, and on visits where an error occurs. It reconstructs what happened in the browser so we can reproduce faults.
7.2It is configured to redact content before anything leaves your browser: all text and images are masked, and keystrokes are replaced with asterisks. What you type into the contact form is not transmitted. We have also disabled the setting that would attach your IP address and request headers.
7.3What is recorded: page structure and how it changed, which elements were interacted with, console messages, network request metadata, and your browser and operating system.
7.4We spell this out because a visitor would not assume a session recorder is running.
8.Who processes data on our behalf
8.1We use third-party services to run the site. Each receives only what it needs:
- (a)Google (Google Analytics 4, via Google Tag Manager): usage analytics.
- (b)Sentry: error monitoring and session replay. Data is held in Sentry's United States region.
- (c)Cloudflare: content delivery, DNS, and protection against abuse. It sees requests to the site.
- (d)DigitalOcean (Droplet, Bengaluru region, India): the server running the site.
- (e)Google (Sheets): storage of contact form submissions.
- (f)Slack: notification when a form is submitted, so we see it promptly.
- (g)Sanity: the content management system holding our blog posts. It does not receive visitor data.
9.How we protect it
9.1The measures we take include: serving the whole site over HTTPS with strict transport security; restricting access to the systems that hold personal data; masking session recordings before transmission; keeping logs that let us detect and investigate unauthorised access; and keeping backups so data is not lost.
9.2We are also required to place security obligations on the services listed above by contract. Where a provider offers standard data protection terms, we are working through accepting them, and we will say so here when that is complete rather than implying it is already done.
9.3No set of measures makes a breach impossible. The next section says what happens if one occurs.
10.If something goes wrong
10.1If personal data we hold is breached, we will tell you without delay, using the contact details we have for you. We will describe what happened, what it is likely to mean for you, what we have done to limit the damage, what you can do to protect yourself, and who to contact with questions.
10.2We will also report the breach to the Data Protection Board of India: an initial description without delay, then a fuller account within seventy-two hours of becoming aware of it.
11.Cookies and similar technologies
11.1On your first visit you are asked whether analytics and session recording may run. Both stay switched off unless you accept. Declining is one click, and it costs you nothing on this site.
11.2Error reporting is the one thing that runs either way, because a site that cannot report its own faults cannot be fixed. It is described in the section on why we are allowed to process your data.
11.3Google Analytics sets cookies to tell visits apart, and only once you have accepted. We run no advertising, retargeting, or social media pixels at all, and advertising storage stays switched off whatever you choose.
11.4You can change your mind at any time. The Analytics choice link in the footer of every page revokes your agreement straight away and asks again.
11.5You can also block cookies in your browser. The site works without them.
12.Why we are allowed to process it
12.1Two different grounds apply, and they are worth separating.
12.2When you fill in the contact form or join a waitlist, you are giving us your details for a purpose you chose: getting a reply. Indian law treats that as a legitimate use in its own right, so we do not ask for separate consent to answer you. If you tell us you no longer want to hear from us about it, we stop processing your details for that purpose.
12.3Analytics and session recording are different. You did not hand that data over for a purpose; it is collected because you visited. So we ask first, and you can decline without losing access to anything on this site.
12.4Error reports sit between the two. They are only produced when something breaks, and they run without a separate question, because we cannot keep the site working without knowing what failed. We have switched off the setting that would attach your IP address to them, and nothing you type is included.
13.How long we keep it
13.1We erase personal data when you withdraw your consent, or when it is reasonable to assume the purpose it was collected for has been served, unless retention is necessary to comply with a law in force.
13.2That last clause is not boilerplate. Indian law requires certain personal data, traffic data, and processing logs to be retained for a minimum period, and where that applies we cannot delete on request inside that window. If you ask us to erase something and a retention requirement prevents it, we will tell you which data is affected and when it can be erased, rather than going quiet.
13.3Where no retention requirement applies, ask Tushar Srivastava at [email protected] and we will erase it.
14.Your rights, and how to use them
14.1You can ask us to:
- (a)Give you a summary of the personal data we hold about you and what we do with it.
- (b)Tell you which other organisations we have shared it with, and what we shared.
- (c)Correct, complete, or update anything that is wrong or out of date.
- (d)Erase what we hold, subject to the retention position described above.
- (e)Withdraw consent you previously gave, as easily as you gave it.
- (f)Tell us you no longer need what you contacted us about, and we will stop processing your details for that purpose.
- (g)Ask for this notice in any language listed in the Eighth Schedule to the Constitution.
- (h)Nominate someone to exercise these rights for you if you die or become unable to.
15.Making a request
15.1Email [email protected], marked for the attention of the Grievance Officer, and say which of the above you want. There is no form to fill in.
15.2So that we give your data to you and nobody else, please write from the email address you originally contacted us from, and tell us roughly when you got in touch. If you cannot use that address, say so and we will agree another way to confirm who you are.
15.3We do not charge for this.
16.If you are unhappy with how we handled it
16.1Tell Tushar Srivastava at [email protected], marked for the Grievance Officer. We will respond within 90 days, which is the maximum the rules allow.
16.2If you are still not satisfied, you may complain to the Data Protection Board of India. The Board asks that you raise the matter with us first and give us the chance to resolve it, so please start here. Details of how to reach the Board are published by the Ministry of Electronics and Information Technology at meity.gov.in.
17.Data leaving India
17.1The server running this site is in India, in DigitalOcean's Bengaluru region. The site itself does not move your data abroad.
17.2Several of the services listed above do. Google Analytics, Google Sheets, Sentry, Slack, and Cloudflare are operated from outside India, and data sent to them is processed and stored there: Sentry in the United States, the others across their global infrastructure. We rely on the contractual protections those providers offer, including the standard clauses and transfer frameworks they publish.
18.Children
18.1This site is aimed at businesses and working professionals. We do not knowingly collect data from children. If you believe a child has sent us information, tell us and we will remove it.
19.Changes to this policy
19.1When we change this policy we will update the effective date at the top. Material changes will be called out on the page rather than made quietly.