Skip to content
In2Gravity

Privacy Policy

Effective 1 September 2026

1. Who we are

In short: we're a Dhaka consultancy, and we're the controller for this site.

In2Gravity, a partnership firm under the laws of Bangladesh, Building 443 (5th Floor), Road 7, DOHS Baridhara, Dhaka 1206, Bangladesh — contact@in2gravity.com. We are the data controller for www.in2gravity.com.

This policy explains what personal data we collect through this website, why we collect it, who processes it on our behalf, and the rights you have. It does not cover data processed under a signed client engagement, which is governed by that engagement's own terms.

2. Data we collect

In short: only what you send us — plus cookieless analytics.

We collect the following, and no more:

  • Consultation bookings — when you book through our embedded scheduler (Cal.com): your name, email address, chosen time slot, and any notes you add. Cal.com processes this as our processor.
  • Contact-form submissions — the name, work email, company, service interest, budget range, and message you enter. Our form is handled by Web3Forms, which relays it to our inbox.
  • Technical and security data — Cloudflare Web Analytics, which is cookieless and records no cross-site tracking or user profiles, and Cloudflare Turnstile, which checks that form submissions are human.
  • Email correspondence — anything you send to contact@in2gravity.com, hosted on Zoho Mail.

3. Purposes & legal basis

In short: to reply to you, deliver work, and improve the site.

We use the data above to respond to your inquiries and schedule consultations, to operate and secure the website, and to improve our services. Under the Personal Data Protection Act, 2026, our basis for processing is your consent together with the steps taken at your request prior to entering a contract. Where we rely on consent, you may withdraw it at any time.

4. Processors & international transfers

In short: a few named tools process data for us; some are abroad.

We rely on a small set of reputable processors: Cal.com (scheduling), Web3Forms (contact form), Cloudflare (analytics and bot protection), and Zoho (email). Some of these providers operate servers outside Bangladesh.

Where personal data is transferred across borders, we rely on providers that offer an appropriate level of protection and contractual safeguards, consistent with the cross-border transfer rules under the Personal Data Protection Act, 2026.

5. Retention

In short: we keep data only as long as the purpose needs.

We keep inquiry and booking information for as long as needed to handle your request and any resulting business relationship. If no engagement follows, we delete it once it is no longer needed. You can ask us to delete your data at any time — see your rights below.

6. Your rights under the PDPA 2026

In short: access, correction, erasure, and complaint are yours.

Under the Personal Data Protection Act, 2026, you may:

  • Access the personal data we hold about you
  • Ask us to correct data that is inaccurate or incomplete
  • Ask us to erase your data
  • Withdraw consent you previously gave
  • Lodge a complaint with the national data protection authority once it is operational

7. EU/EEA visitors (GDPR)

In short: GDPR applies to you; here's your extra protection.

If you are in the European Union or European Economic Area, the General Data Protection Regulation applies to your personal data. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your local supervisory authority. Use the same contact channel — contact@in2gravity.com — to exercise them.

8. Cookies

In short: we avoid them; analytics are cookieless.

We do not use marketing or tracking cookies, and our analytics are cookieless. The only client-side storage comes from strictly necessary embedded services — the Cal.com scheduler and Cloudflare Turnstile — which need it to function. Because we set no non-essential cookies, we do not show a cookie consent banner.

9. Children

In short: this site isn't directed at children.

This website and our services are directed at organizations and professionals, not children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

10. Security

In short: least access, encryption in transit, and named responsibility.

We apply proportionate technical and organizational measures to protect personal data, including encryption in transit (TLS), least-access practices, and the use of reputable providers. No system is perfectly secure, but we take reasonable steps to keep your data safe and to respond promptly if something goes wrong.

11. Changes & effective date

In short: we date every version and flag material changes here.

We may update this policy from time to time. The effective date above reflects the current version, and we will note material changes on this page. This policy is a draft under review and does not yet constitute final legal advice.

Tell us what you're trying to build or fix.

We reply within one business day.

Book a consultation