This policy explains what personal data Everligntek collects, why we collect it, who we share it with, and the choices you have. It covers our website, our marketing activity, and the data we handle while delivering AI, data and cloud consulting services.
Everligntek (referred to here as Everligntek, we, us or our) is a boutique technology consulting firm delivering enterprise AI, data engineering, analytics and cloud platform services. This policy applies to the everligntek.com website and to the personal data we handle in the course of running our business.
Depending on where you are located and how you engage with us, the controller of your personal data is one of the following group companies.
2049 Madrillon Rd, Vienna, VA 22182, United States
Vascon Eco Tower, 5Th Floor, Unit No. 501, Baner - Pashan Link Rd, Haveli, Pune, Maharashtra,
411045 - India.
You can reach either entity at info@everlign.com. Where both entities take part in the same engagement they act as joint controllers, and the entity closest to you is your first point of contact.
This policy applies to personal data relating to:
It does not cover personal data that we process on behalf of a client inside a delivery engagement. In those cases the client is the controller, we act as a processor, and the client privacy notice governs. Section 12 explains how that works.
We do not ask for special category data such as health, biometric, racial, religious or political information through this website, and we have no need for it. Please do not enter that kind of detail into free text fields.
We use personal data only for the purposes set out below. Where the EU GDPR, the UK GDPR or a comparable law applies, the legal basis we rely on is shown beside each purpose.
| Purpose | What this involves | Legal basis |
|---|---|---|
| Responding to enquiries | Replying to form submissions, emails and calls, and preparing proposals | Steps taken at your request before a contract; legitimate interests |
| Delivering services | Running engagements, project communication, invoicing and support | Performance of a contract |
| Marketing | Sending insights, newsletters, event invitations and service updates | Consent, or legitimate interests for existing business contacts |
| Website analytics | Understanding how the site is used so we can improve it | Consent for non essential cookies; legitimate interests for aggregate measurement |
| Recruitment | Assessing applications, arranging interviews and maintaining a talent pool | Steps taken before a contract; consent for the talent pool |
| Security | Monitoring for abuse, protecting our systems and preserving evidence | Legitimate interests; legal obligation |
| Compliance | Meeting tax, accounting, export control and regulatory reporting duties | Legal obligation |
Where we rely on legitimate interests we have assessed that our interest in running and growing a business does not override your rights and freedoms. You can ask us for a summary of that assessment at any time.
We do not sell personal data, and we do not use it to make decisions that produce legal or similarly significant effects about you without human involvement.
We operate across the United States, India, the Gulf and Europe, so personal data may be transferred outside the country where it was collected.
Where personal data leaves the EEA, the UK or another region with transfer restrictions, we rely on one of the following safeguards:
For each route we run a transfer risk assessment and apply supplementary measures: encryption in transit and at rest, strict access control, and pseudonymisation where it is practical. Write to info@everlign.com for a copy of the safeguards that apply to your data.
We keep personal data only as long as we need it for the purpose it was collected for, plus any period required by law.
| Data type | Retention period |
|---|---|
| Website enquiries and form submissions | 24 months from the last contact |
| Marketing contacts and consent records | Until you unsubscribe, plus 24 months to evidence consent |
| Client engagement records | Term of the contract, plus 7 years for legal, tax and audit purposes |
| Unsuccessful job applications | 12 months, or longer if you consent to join our talent pool |
| Cookie and analytics data | As set out in the Cookie Policy, and never more than 26 months |
| Security and access logs | 12 months |
When a retention period ends we delete the data or irreversibly anonymise it. Backup copies are overwritten on a rolling cycle and are not used to restore deleted records.
We apply organisational and technical controls proportionate to the sensitivity of the data we hold.
If a personal data breach is likely to create a risk to your rights we will notify the relevant supervisory authority within the statutory deadline, and we will notify you directly where the risk to you is high.
No method of transmission over the internet is completely secure. Please do not send contracts, credentials or other sensitive material to us by unencrypted email. Ask us for a secure upload link instead.
Subject to the law that applies to you, you have the following rights over your personal data.
Email info@everlign.com with the subject line Privacy Request, and tell us which right you want to exercise. We will verify your identity before we act, which usually means confirming the request from the email address we hold on file.
We respond within 30 days, or sooner where the law requires it. If a request is complex we may extend that period once and will tell you why. Requests are free unless they are manifestly unfounded or repetitive.
The following notices apply in addition to everything above, depending on where you are.
Under the EU GDPR and the UK GDPR the controller is the entity named in section 1. Our processing does not meet the thresholds in Article 37 for a statutory Data Protection Officer, so privacy matters are handled by a named privacy lead reachable at info@everlign.com. You may lodge a complaint with the supervisory authority where you live, where you work, or where the alleged infringement took place. In the United Kingdom that is the Information Commissioner's Office.
In the preceding 12 months we collected the categories of personal information described in section 3: identifiers, commercial information, internet or network activity, professional and employment information, and inferences drawn from them. We disclose these categories to service providers for business purposes only.
We do not sell or share personal information as those terms are defined in the CCPA as amended by the CPRA, and we do not knowingly collect the personal information of anyone under 16. California residents may request to know, delete and correct their information, and may limit the use of sensitive personal information. We will not discriminate against you for exercising any of these rights. An authorised agent may submit a request with written proof of authorisation.
For Data Principals in India, processing is carried out under the Digital Personal Data Protection Act 2023. You may withdraw consent as easily as you gave it, request correction or erasure, nominate another person to exercise your rights in the event of death or incapacity, and raise a grievance.
Grievance Officer: [Name and designation], [India entity legal name], reachable at info@everlign.com. We acknowledge every grievance within 7 days and aim to resolve it within 30 days. If you remain unsatisfied you may escalate to the Data Protection Board of India.
Where Federal Decree Law No. 45 of 2021 on the Protection of Personal Data applies, you have rights of access, correction, erasure, restriction, portability and objection, and you may complain to the UAE Data Office. Transfers of personal data out of the UAE are made only to jurisdictions offering an adequate level of protection, or under contractual safeguards that provide equivalent protection.
Inside a delivery engagement our client decides why and how personal data is processed. We act only on documented instructions, we do not use client data for our own purposes, and we return or delete it at the end of the engagement. Sub processors are disclosed in advance and are bound by equivalent terms. Our data processing agreement and current sub processor list are available on request.
Our website and services are aimed at businesses and the people who work in them, not at individuals under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it promptly.
This site links to third party websites, including partner sites and social platforms. We are not responsible for their content or their privacy practices. Read their policies before you share anything with them.
We review this policy at least once a year, and whenever we make a material change to how we handle personal data. The effective date at the top of this page always reflects the version currently in force.
Where a change materially affects your rights we will give notice by email, or through a prominent notice on this site, before it takes effect. Earlier versions are available on request.
For any question about this policy, to exercise a right, or to raise a concern about how we handle personal data, contact us using the details below.
Use the subject line Privacy Request so it reaches the right team quickly.
2049 Madrillon Rd, Vienna, VA 22182, United States.
Send us a note and a real person will answer. If you are evaluating us as a vendor, ask for our data processing agreement and current sub processor list.