What this website collects, where it goes, and how long it stays.
Caretech AI Pvt. Ltd. publishes this notice for the caretechai.com website. Three things on it touch personal data: the contact form, email sent to Caretech AI, and the request logs the hosting infrastructure keeps. Everything else you do here is read-only and unrecorded.
Effective 12 August 2026.
What this notice covers
This notice covers this website: the pages you are reading and the contact form on them. It describes what a visitor to caretechai.com hands over, deliberately or otherwise, and what happens to it afterwards.
It does not govern data inside a Caretech AI product or platform. Where an organization's data is processed under an engagement, that engagement governs it — including which party is the controller or fiduciary, which is the processor, and what each is obliged to do. Those are contract questions and they are answered in the contract, not on a web page.
What is collected, and when
Reading this site collects nothing from you beyond the request logs described at the end of this section. Personal data reaches Caretech AI in one of three ways.
The contact form
When you submit the form, it sends what you typed over HTTPS to an Amazon API Gateway endpoint, which passes it to an AWS Lambda function, which stores it in an Amazon DynamoDB table. A notification email containing the enquiry is then sent to Caretech AI through Amazon SNS.
What is stored per enquiry:
- Your name
- Your business email address
- Your organization
- Your country
- The area of interest you selected
- Your message, as written
- The IP address the submission came from
- The time it arrived
The last two are not asked for on the form, which is why they are listed here. Everything above them is what you chose to type.
Anti-abuse checks on the form
The form carries a hidden honeypot field that a person never sees or fills, and a timing check on how fast the form was completed. Both exist to separate a person from a script. It also applies a rate limit of five submissions per hour from one IP address, implemented as a counter keyed to that address which expires by itself after roughly two hours.
Mail to hello@caretechai.com and security@caretechai.com is received through Amazon SES. Messages are stored in an Amazon S3 bucket and notified onward to Caretech AI. Whatever you put in an email — including anything in a signature or a quoted thread below it — is what gets stored.
Infrastructure logs
The site is served from Amazon S3 through Amazon CloudFront, with AWS WAF in front of it. CloudFront and WAF process request metadata, including the IP address a request came from, in order to deliver pages and to identify and block abuse. That happens for every request to every page, whether or not you ever use the form.
Why it is collected
There are three purposes, and no fourth.
- To answer you. An enquiry is stored so that the team that owns your area of interest can read it, reply to it, and have the thread in front of them when they do.
- To prevent abuse. The honeypot, the timing check and the per-IP rate limit exist to keep automated submissions out of an inbox that a small team reads by hand.
- To keep the site available and secure. CloudFront and WAF use request metadata to serve pages and to stop traffic that is attacking rather than reading.
Nothing collected here is used to build a profile of you, to score you, to measure your behaviour across pages, or to train a model. No enquiry is used for a purpose other than the one it was sent for.
The basis for processing
For visitors in the EEA and the UK
Where the GDPR or the UK GDPR applies to this website, the processing described above rests on legitimate interests: replying to a business enquiry that you initiated, and keeping the service running and defended against abuse. Both are ordinary expectations of anyone who fills in a vendor's contact form.
Sending an enquiry is voluntary. Reading this site requires nothing from you, no page is gated, and you decide what goes in the message box. If you would rather not use the form, email is on the contact page and reaches the same people.
Caretech AI makes no claim of compliance with the GDPR anywhere on this site, and does not make one here. What is stated is the basis on which this specific, small piece of processing is carried out.
For visitors in India
Caretech AI makes no claim of compliance with the Digital Personal Data Protection Act, 2023. Where the Act applies, whether Caretech AI is a data fiduciary or a data processor in a given arrangement follows from who decides the purpose and means of processing, and that belongs in an agreement rather than on a website. For an enquiry submitted through this form, you supply the data yourself, for the stated purpose of a reply, and you can withdraw it at any time by the route in the retention section below.
Cookies and tracking
This site sets no cookies. It writes nothing to localStorage or sessionStorage. It loads no third-party scripts, no third-party fonts, no analytics, no advertising and no tracking pixels — the fonts are served from this domain, and the one script that runs is the site's own navigation. There is no consent banner because there is nothing to consent to: no cookie to accept or refuse, no vendor list, no preference to remember. That is a design decision rather than an omission, and the Content-Security-Policy this site is served with holds the third-party half of it in place: an outside script, font or pixel could not load even if one were added by mistake.
The practical effect is that closing this tab leaves nothing behind in your browser, and that reading a page about health data does not send your address to anybody's analytics.
Who else sees it
Caretech AI does not sell personal data, does not share it with advertisers or data brokers, and runs no advertising on this site. An enquiry goes to the people who can answer it and no further.
The website and the enquiry pipeline run on Amazon Web Services. The API endpoint, the function, the table, the mail service, the storage bucket, the content delivery network and the web application firewall named in this notice are all AWS services, and AWS processes what passes through them as Caretech AI's infrastructure provider, acting on Caretech AI's instructions. It is named here because a processor that handles your enquiry ought to be named, not as a partnership or an integration.
The data leaves your country
The infrastructure described in this notice runs in the AWS us-east-1 region, in the United States. An enquiry sent from India, from the European Economic Area, from the United Kingdom or from anywhere else is transmitted to and stored in the United States, and the notification email is delivered from there.
No India data residency and no EU data residency is claimed, here or anywhere else on this site. This paragraph exists so that you know it before you press send rather than afterwards.
How long it is kept
An enquiry is kept while the conversation it started is open, and for a reasonable period afterwards so that a later follow-up has its context. No fixed number of months is published here, because none has been set; if one is set, it will appear on this page.
The anti-abuse counter keyed to your IP address is the one thing with a definite life: it expires by itself roughly two hours after the submission that created it, without anybody deleting it.
You can have an enquiry removed before any of that runs its course. Write to compliance@caretechai.com and the enquiry record will be deleted.
Access, correction, deletion, objection
You may ask what is held about you, ask for it to be corrected, ask for it to be deleted, or object to the processing altogether. All four go to one address: compliance@caretechai.com.
The answer is usually short, because the holding is small: the enquiry as you wrote it, the IP address it came from, and the time it arrived. Say which enquiry you mean — the address you used and roughly when you sent it is enough to find it.
The Digital Personal Data Protection Act, 2023 requires a data fiduciary to publish the contact details of a designated Grievance Officer. That designation is pending. Privacy and data-protection correspondence reaches Caretech AI at compliance@caretechai.com; that address is not a grievance route under the Act and is not offered as one.
Two things this form must not carry
Patient data
Please do not include patient health information or other sensitive medical information in the contact form, or in any email to Caretech AI. That includes anonymized-looking case examples: re-identification from a small clinical detail plus an organization name is easier than most people expect, and ordinary email travels through mail servers neither party controls. Describe the workflow, the setting and the constraint instead. If a conversation genuinely requires real data, it needs an agreement first.
The rule in full, on the Terms of Use page
A child's information
This is a business website addressed to organizations. It is not directed at children, and Caretech AI does not knowingly collect a child's personal data through it. Do not submit a child's details in the form or by email. If a child's data reaches Caretech AI through this site, write to compliance@caretechai.com and the record will be deleted.
Changes to this notice
This notice describes the website as it is built today. If what the site collects changes — a new field on the form, a new service in the path an enquiry takes, anything stored in your browser — this page changes with it and the effective date moves.
Effective 12 August 2026. Questions about this notice, or about a change to it, go to compliance@caretechai.com. Suspected vulnerabilities go to security@caretechai.com.
Ask before you send, not after.
If anything here matters to your organization's own assessment — where the data sits, how long it stays, who processes it — ask. The answer will be the same one written above, and you can have it in writing.