Privacy Policy

Legal & Compliance

Privacy Policy

How AI Tool Clinic collects, uses, protects, and respects your personal information โ€” in plain language, fully compliant with Indian and international privacy law.

Effective: 1 March 2026 Last Updated: 27 March 2026 Version 1.0

๐ŸขWho We Are

AI Tool Clinic (“AITC”, “we”, “us”, “our”) is an independent digital publication operated by Dr. Keerthi Vardhan, based in India. We publish reviews, comparisons, and educational guides about artificial intelligence tools and software at aitoolclinic.com.

This Privacy Policy explains how we handle personal data when you visit our website, subscribe to our newsletter, contact us, or interact with our content. By using our website, you agree to the practices described herein.

Governing Law: This policy is governed by the Information Technology Act, 2000 (India), the Digital Personal Data Protection Act, 2023 (India), and aligns with the EU GDPR, UK GDPR, CCPA (California), and ACL (Australia) for visitors from those regions.

๐Ÿ“‹Information We Collect

2.1 Information You Provide Directly

  • Contact & Enquiries: Name, email address, and message content when you use our contact form or email us.
  • Newsletter Subscription: Email address (and optionally your name) when you subscribe to our mailing list.
  • Comments: Name, email address, and website URL if you leave comments on our articles (subject to our comment moderation policy).

2.2 Information Collected Automatically

When you visit our website, our servers and third-party analytics tools may automatically collect:

  • Usage Data: Pages viewed, time on page, referring URL, search terms used to find our site, and navigation paths.
  • Device & Technical Data: Browser type and version, operating system, screen resolution, device type (desktop/mobile/tablet), and IP address (anonymised where possible).
  • Location Data: Approximate geographic location derived from your IP address (country/city level only โ€” no precise GPS data).
  • Cookies & Similar Technologies: See Section 5 for full details.

2.3 Information from Third Parties

  • Analytics Providers: Google Analytics may provide aggregated demographic and interest data about our audience.
  • Affiliate Networks: Amazon Associates, Impact, ShareASale, and similar platforms may share anonymised click and conversion data to help us understand which content performs well.
  • Search Consoles: Google Search Console provides aggregate data on search queries and site performance โ€” no personal data is shared.
Note: We do not knowingly collect sensitive personal data such as financial details, health records, government ID numbers, biometrics, caste, religion, or political opinions. If you share such information with us voluntarily, we will treat it with the highest level of confidentiality.

โš™๏ธHow We Use Your Information

Purpose Data Used Legal Basis (GDPR/DPDP)
Operating the website โ€” serving pages, ensuring security, preventing fraud IP address, device/browser data, cookies Legitimate interest / Consent
Analytics & improvement โ€” understanding how visitors use our content so we can improve it Usage data, anonymised IP Legitimate interest / Consent
Newsletter โ€” sending educational content, new article notifications, product roundups you opted in to receive Email address, name (optional) Consent (freely given, specific, opt-in)
Responding to enquiries โ€” replying to messages you send us Name, email, message content Performance of contract / Consent
Affiliate tracking โ€” confirming clicks/conversions for our partner programmes (we receive commission, not your personal data) Anonymised click identifiers Legitimate interest
Legal compliance โ€” meeting obligations under Indian law, GDPR, or other applicable regulations As required by law Legal obligation

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

๐ŸคHow We Share Information

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share data only in the following limited circumstances:

4.1 Service Providers (Data Processors)

We use trusted third-party services to operate our website. These providers act as data processors and may only use your data on our instructions:

  • Hosting: Our website is hosted on servers that may process visitor IP addresses and request logs for security purposes.
  • Email Marketing: Newsletter emails are sent via a third-party email service provider (e.g., Mailchimp, ConvertKit, or similar) that stores subscriber email addresses securely.
  • Analytics: Google Analytics (with IP anonymisation enabled) processes usage data on our behalf.
  • Caching & Security: LiteSpeed Cache and any CDN or security plugins process request metadata to protect the site.

4.2 Affiliate & Advertising Partners

When you click affiliate links on our site, you are redirected to third-party websites (e.g., Amazon, software vendors). Those sites have their own privacy policies and we are not responsible for their data practices. We only receive anonymised sales/commission data โ€” not your personal information.

4.3 Legal Requirements

We may disclose your information if required to do so by law, court order, or government authority under the IT Act 2000, DPDP Act 2023, or equivalent legislation in your jurisdiction.

4.4 Business Transfers

If AI Tool Clinic is acquired, merged, or its assets transferred, your data may form part of the transferred assets. We will notify you via a prominent notice on our website if this occurs.

No Data Sales: We will never sell your personal data to data brokers, advertisers, or any third party for commercial gain.

๐ŸชCookies & Tracking Technologies

Our website uses cookies โ€” small text files stored on your device โ€” and similar technologies including web beacons and pixel tags. Here is how we use them:

Category Examples Purpose Can You Opt Out?
Strictly Necessary WordPress session cookie, security tokens Core website functionality; cannot be disabled without breaking the site No (required)
Analytics _ga, _gid (Google Analytics) Understanding visitor behaviour; helping us improve content Yes โ€” via cookie banner or browser settings
Affiliate Tracking Amazon affiliate tag, network pixels Crediting us with commissions when you make a purchase via our links Yes โ€” disable third-party cookies in browser
Performance LiteSpeed Cache identifiers Serving cached pages faster to improve your experience No (performance only)

Managing Cookies

You can control and delete cookies through your browser settings. Useful links:

  • Google Chrome: Settings โ†’ Privacy & Security โ†’ Cookies
  • Mozilla Firefox: Options โ†’ Privacy & Security โ†’ Cookies and Site Data
  • Safari: Preferences โ†’ Privacy โ†’ Manage Website Data
  • Microsoft Edge: Settings โ†’ Cookies and Site Permissions

You may also opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on available at tools.google.com/dlpage/gaoptout.

EU/UK Visitors: In compliance with the ePrivacy Directive and UK PECR, non-essential cookies are set only after you provide consent via our cookie consent mechanism. You may withdraw consent at any time.

๐Ÿ—“๏ธData Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law:

  • Newsletter subscribers: Until you unsubscribe. Unsubscribed records are deleted within 30 days.
  • Contact form submissions: Up to 24 months from the date of the enquiry, or until resolved.
  • Website analytics data: Google Analytics data is retained for 14 months (our configured retention period), after which it is automatically deleted.
  • Server/access logs: Typically 90 days, retained for security and fraud prevention purposes.
  • Comments: Retained for the lifetime of the article unless you request deletion.
  • Legal/compliance records: As required by applicable law (e.g., 7 years for financial records under Indian tax law).

When data is no longer required, we securely delete or anonymise it.

โš–๏ธYour Privacy Rights

Depending on your location, you may have the following rights regarding your personal data. We honour these rights regardless of where you are located:

๐Ÿ‘๏ธ
Right to Access Request a copy of personal data we hold about you.
โœ๏ธ
Right to Correction Request correction of inaccurate or incomplete data.
๐Ÿ—‘๏ธ
Right to Erasure Request deletion of your personal data (“right to be forgotten”).
๐Ÿ”’
Right to Restrict Request that we limit how we process your data in certain circumstances.
๐Ÿ“ฆ
Right to Portability Request your data in a structured, machine-readable format.
๐Ÿšซ
Right to Object Object to processing based on legitimate interests or for direct marketing.
๐Ÿ”™
Right to Withdraw Consent Withdraw consent at any time for consent-based processing (e.g., newsletter).
๐Ÿ“ฃ
Right to Complain Lodge a complaint with the relevant data protection authority in your country.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days (GDPR standard) or within the timeframe required by applicable law in your jurisdiction. We may need to verify your identity before processing your request.

Unsubscribing from Newsletter

Every newsletter email contains a one-click unsubscribe link at the bottom. You may also email us directly to be removed from our mailing list. Removal is processed within 5 business days.

๐Ÿ‡ฎ๐Ÿ‡ณIndia-Specific Provisions

8.1 Digital Personal Data Protection Act, 2023 (DPDP Act)

AI Tool Clinic complies with the DPDP Act, 2023 to the extent it applies to our operations. Under this Act, you have the right to:

  • Obtain a summary of personal data being processed and the processing activities undertaken by us;
  • Correct inaccurate or misleading personal data;
  • Erase personal data that is no longer necessary for the purpose it was collected;
  • Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity;
  • Grieve before us or the Data Protection Board of India if your rights are violated.

As a Data Fiduciary under the DPDP Act, we process your personal data only for lawful purposes, with your consent where required, and take reasonable security measures to protect it.

8.2 Information Technology Act, 2000 & IT Rules 2021

This Privacy Policy constitutes a “Privacy Policy” as required under Rule 3 of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. We collect, use, store, and transfer your sensitive personal data or information (SPDI) in compliance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

We maintain a Grievance Officer as required under the IT Rules. Contact details are in Section 13 below.

8.3 Consumer Protection Act, 2019

Our data practices comply with consumer protection obligations under the Consumer Protection Act, 2019, including transparency in our practices and the availability of a grievance redressal mechanism.

Cross-Border Transfers: Our hosting and service providers may be located outside India. We ensure such transfers are protected by appropriate contractual safeguards as required by applicable Indian law and the DPDP Act.

๐ŸŒInternational Visitors

European Union & United Kingdom (GDPR / UK GDPR)

For visitors from the EU and UK, we process your data under the following lawful bases: consent (for analytics and marketing), legitimate interests (for site security and fraud prevention), and legal obligation (when required by law). You have the right to lodge a complaint with your national supervisory authority (e.g., ICO in the UK, or your country’s DPA in the EU).

As our operations are based in India, data transfers to India are protected by standard contractual clauses or equivalent safeguards where required by GDPR.

United States โ€” California (CCPA / CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA. We do not sell or share personal information as defined by the CCPA. You have the right to know, delete, correct, and opt-out of sale/sharing of your personal information. To exercise your CCPA rights, contact us at [email protected].

Australia (Privacy Act 1988 / APPs)

For Australian visitors, we comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988. You may request access to or correction of your personal information by contacting us. Complaints may be made to the Office of the Australian Information Commissioner (OAIC).

Canada (PIPEDA / CASL)

For Canadian visitors, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). Our email newsletter complies with Canada’s Anti-Spam Legislation (CASL) โ€” we send marketing emails only with your express consent and every email includes an unsubscribe mechanism.

๐Ÿ”Security

We take the security of your personal data seriously and implement reasonable technical and organisational measures, including:

  • HTTPS/TLS encryption on all pages of our website;
  • Access controls โ€” only authorised personnel can access personal data;
  • Regular security updates applied to our WordPress installation, themes, and plugins;
  • Firewall and malware scanning via reputable security tools;
  • Minimal data collection โ€” we collect only what is necessary (data minimisation principle).
Important: While we take all reasonable precautions, no data transmission over the internet is completely secure. We cannot guarantee the absolute security of information you send to us electronically. Transmission is at your own risk. Once we receive your information, we use reasonable physical, electronic and procedural safeguards to protect it.

If you believe your data has been compromised or you discover a security vulnerability on our site, please report it immediately to [email protected]. We will acknowledge and investigate within 72 hours.

๐Ÿ‘ถChildren’s Privacy

AI Tool Clinic is designed for adults and professionals interested in AI tools. Our content is not directed at children under the age of 18 (or the relevant age of digital consent in your jurisdiction).

We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at [email protected] and we will delete such data promptly.

Under the DPDP Act 2023 (India), we do not process personal data of children under 18 without verifiable parental consent. We do not undertake behavioural monitoring of children.

๐Ÿ“Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the “Last Updated” date at the top of this page;
  • Where feasible and for significant changes, notify newsletter subscribers via email;
  • For EU/UK users, re-obtain consent where required by GDPR/UK GDPR.

We encourage you to review this page periodically to stay informed about how we protect your information. Continued use of our website after any changes constitutes your acceptance of the updated policy.

Previous versions of this policy can be requested by emailing [email protected].

Contact & Grievance Officer

For any privacy-related enquiries, data access/deletion requests, or to lodge a complaint, please reach out to us:

General Privacy
Grievance Officer (India)
Dr. Keerthi Vardhan
[email protected]
Organisation
AI Tool Clinic
India
Response Time
Within 30 days (GDPR)
Within 30 days (DPDP Act)

Under Rule 5(9) of the IT Rules 2011 and the DPDP Act 2023, you may contact the Grievance Officer for any complaint or concern relating to the processing of your personal data. Complaints are acknowledged within 48 hours and resolved within 30 days.


Data Protection Board of India (once operational) ยท ICO (UK): ico.org.uk ยท EU DPAs: edpb.europa.eu/about-edpb/about-edpb/members ยท OAIC (Australia): oaic.gov.au ยท OPC (Canada): priv.gc.ca