Skip to content
Independent creative digital agencySurat, IN · 2026
NULL LAB000
NULL LAB
  • WorkWork
    • Brand Identity & Strategy
    • Website Design & Development
    • AI Automation
    • Growth Marketing
  • BlogBlog
  • ContactContact
Start a Project

Privacy

Privacy Policy

Last updated 4 September 2026

This policy explains what NULL LAB (“we”, “us”, “the studio”) collects when you use nulllab.in and its project subdomains, why we collect it, which companies process it on our behalf, how long it is kept, where it goes, and what you can require us to do about it. We do not sell personal data, we do not buy it, and we do not use it to make automated decisions about you.

NULL LAB is an independent creative digital agency based in Surat, Gujarat, India, working remotely. For the purposes of India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) we are the Data Fiduciary. For the UK and EU General Data Protection Regulation we are the Controller. Where this policy says “personal data” it means both “personal data” under the GDPR and “personal data” as defined in section 2(t) of the DPDP Act.

1. Scope

This policy covers nulllab.in and the NULL LAB Originals published at ananta.nulllab.in, musee.nulllab.in, vara.nulllab.in, health.nulllab.in and habitloop.nulllab.in. It does not cover any third-party site you reach from a link here; those sites have their own policies and we have no control over them.

It does not cover data you send us by email or on a call outside the enquiry form. That correspondence is handled under the same retention and rights sections below, but it does not pass through the systems described in section 4.

2. What we collect

2.1 When you send an enquiry. The form asks for three things and offers four more:

  • Required — your full name, your business name, your email address.
  • Required choices — which services you are asking about, and a budget band.
  • Optional — a description of what you want to change, build or fix.
  • Collected automatically with the submission— the date and time; the two-letter country your request came from (read from Cloudflare’s network header, not from your device’s location services); your browser’s user-agent string, truncated to 400 characters; the page that referred you; and any utm_* campaign tags present in the URL you arrived on.

The form previously asked for a phone number, a website and a start date. Those fields were removed. If you send them to us anyway in the free-text field, they are stored as part of that field.

The form also contains one hidden field that is never shown to you and must stay empty. It exists to catch automated submissions. If it is filled, the submission is discarded and nothing is stored.

2.2 If you allow analytics and recordings. PostHog and Microsoft Clarity collect: pages viewed and the order you viewed them in; links, buttons and elements you clicked; scroll depth; approximate city-level location derived from your IP address; device type, screen size, browser and operating system; and a reconstruction of your pointer movement, scrolling and clicks that can be replayed as a session recording.

Text you type is masked before it leaves your browser. We never record the contents of form fields, and PostHog is configured with maskAllInputs and person_profiles: identified_only, which means no persistent profile is built for an anonymous visitor.

2.3 If you allow advertising. Google Tag Manager loads Google Analytics 4 and Google Ads tags, which set identifiers allowing Google to attribute a visit to an ad campaign and to include you in remarketing audiences — that is, to show you our advertising on other sites and platforms in Google’s network.

2.4 Always, before any choice. Cloudflare serves this site and processes your IP address, request headers and TLS metadata to deliver pages, cache them and block abusive traffic. This is necessary for the site to exist and cannot be switched off. Cloudflare retains this at the network level under its own policy; we do not receive or store server logs.

2.5 What we never collect. We do not ask for or store payment details, government identifiers, health data, or any other special-category data. We do not use fingerprinting. We do not track you across other websites except through the Google advertising tags described in 2.3, and only if you allow them.

3. Why, and on what legal basis

  • To answer your enquiry and prepare a proposal. GDPR Art. 6(1)(b) — steps taken at your request before entering a contract. DPDP Act s.4 — the certain legitimate use of responding to information you voluntarily provided for that purpose.
  • To understand how the site is used, and to advertise. GDPR Art. 6(1)(a) and DPDP Act s.6 — your consent, given through the banner, freely, specifically and by an unambiguous affirmative action. Refusing costs you nothing and the site works identically.
  • To serve and secure the site. GDPR Art. 6(1)(f) — our legitimate interest in the site working and not being attacked, balanced against the minimal data involved.
  • To keep records we are legally required to keep. GDPR Art. 6(1)(c) — a legal obligation, where an engagement produces invoices or tax records.

4. Who processes it for us

Each of these is a processor acting on our instructions under a data processing agreement. None of them is permitted to use your data for their own purposes.

  • Cloudflare, Inc. — hosting, CDN, DNS, WAF/bot protection, and the D1 database your enquiry is stored in. Receives: IP address, request headers, and the full enquiry record. Always active.
  • Resend (Plus Five Five, Inc.) — transactional email. Sends the new-enquiry alert to our inbox and the confirmation to yours. Receives: your name, business name, email address and the contents of your enquiry.
  • PostHog, Inc. (EU Cloud, hosted in Frankfurt) — product analytics and session replay. Receives: the events in 2.2. Analytics consent only.
  • Microsoft Corporation (Clarity) — heatmaps and session recordings. Receives: the events in 2.2. Analytics consent only.
  • Google LLC / Google Ireland Ltd (Tag Manager, Analytics 4, Google Ads) — campaign measurement and remarketing. Receives: the identifiers in 2.3. Advertising consent only.

We will also disclose personal data where we are legally compelled to — a court order, a lawful request from a public authority, or to establish or defend a legal claim. If NULL LAB is ever sold or merged, records may transfer to the acquirer under the same terms, and we will say so on this page before it happens. We share personal data with nobody else.

5. Cookies and similar technologies

Nothing that is not strictly necessary loads until you make a choice. The banner offers three categories:

  • Strictly necessary. One entry in your browser’s local storage, nulllab:consent, recording your choice and the date you made it. No tracking cookie is set. This cannot be switched off, because switching it off would mean forgetting that you refused.
  • Analytics & recordings. PostHog sets ph_* identifiers in local storage and a first-party cookie. Microsoft Clarity sets _clck (about one year) and _clsk (one day), and may set CLID on its own domain.
  • Advertising. Google Analytics 4 sets _ga (about two years) and _ga_*. Google Ads sets _gcl_* conversion linkers, and IDE or test_cookie may be set on doubleclick.net.

Durations are set by those vendors and can change; the list above is accurate as at the date of this policy.

How refusal is enforced. Google Consent Mode is primed to denied for advertising storage, ad user data, ad personalisation and analytics storage before Google’s container is ever requested, so no Google tag can fire on a default. If you switch a category off after having allowed it, we stop each vendor through its own API, send the revoking consent signals, delete the cookies those vendors set where your browser permits it, and reload the page — because a script already loaded cannot be removed from a page, and a reload is the only way to guarantee nothing in memory keeps sending.

You can reopen your choice at any time using Cookie settings at the foot of every page. We also honour your browser’s Do Not Track and Global Privacy Control signals where the vendor supports them. If we add or change a category, the stored record is invalidated and you are asked again rather than carried over on an answer you gave to a different question.

6. How long we keep it

  • Enquiries that do not become work — 24 months from your last contact with us, then deleted.
  • Enquiries that become work — for the duration of the engagement and then for as long as Indian tax and accounting law requires records of the transaction to be kept, currently eight years from the end of the relevant financial year.
  • Analytics events and session recordings — held by PostHog and Microsoft under their own retention schedules. Clarity recordings expire after 30 days by default. We do not keep a separate copy.
  • Advertising identifiers — per the cookie durations in section 5.
  • Your consent record — kept in your browser until you change it, clear your site data, or we invalidate it by changing the categories.

7. International transfers

Personal data leaves India. Cloudflare and Resend process data in the United States and at edge locations worldwide. PostHog is configured to its EU region. Microsoft and Google process data in the United States and in other countries where they operate.

Transfers rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum where they apply, on the EU–US and UK–US Data Privacy Framework where the recipient is certified, and, under the DPDP Act, on the absence of any restriction by the Central Government on transfer to the countries concerned. Copies of the relevant clauses are available on request.

8. Your rights

Whatever law applies to you, you can ask us to:

  • Confirm and access — tell you whether we hold personal data about you, what it is, why we have it, and who we have shared it with.
  • Correct or complete — fix anything inaccurate, misleading or incomplete.
  • Erase — delete it, unless we are legally required to keep it.
  • Withdraw consent — at any time, as easily as you gave it, without giving a reason. Withdrawing does not affect processing that already happened.
  • Nominate — appoint someone to exercise these rights on your behalf if you die or become incapacitated (DPDP Act s.14).

If the GDPR applies to you, you may additionally object to processing based on legitimate interests, ask for processing to be restricted while a dispute is resolved, and receive the data you gave us in a structured, machine-readable form or have it sent to another controller.

How to ask. Email [email protected] with the subject line Privacy request and tell us what you want. We do not charge for this. We reply within 30 days; if a request is unusually complex we will tell you why and when to expect an answer. We may ask for enough information to be sure it is you asking — usually just that you write from the address you used to contact us.

9. Complaints and the Grievance Officer

Complaints about this policy or how your data is handled go to the Grievance Officer at [email protected], marked Grievance. We acknowledge within 7 days and respond substantively within 30.

If you are not satisfied you may complain to the Data Protection Board of India. If you are in the UK or the EU, you may complain to the Information Commissioner’s Office or to the supervisory authority in your country of residence. You do not have to come to us first.

10. Security

The site is served only over HTTPS with HSTS, a strict Content Security Policy, framing denied, and MIME-sniffing disabled. Enquiries are written to the database using parameterised statements, every submitted value is length-capped and validated against an allow-list on the server, and control characters are stripped before storage. The enquiry endpoint is same-origin only and rate-limited. Access to stored enquiries is limited to the studio.

No system is perfectly secure. If a breach is likely to result in risk to you, we will notify you and the relevant authority without undue delay and within the timeframes the DPDP Act and the GDPR require.

11. Children

This site is for businesses and we do not direct it at children. We do not knowingly collect personal data from anyone under 18, and we do not undertake tracking or targeted advertising of children. If you believe a child has sent us information, email us and we will delete it.

12. Changes to this policy

If we change what we collect, why, or who processes it, we update this page and the date at the top. A change to the tracking categories invalidates your stored consent record and the banner asks you again. We do not apply a material change retroactively to data already collected under an earlier version.

13. Contact

NULL LAB, Surat, Gujarat, India. [email protected]. Contact the studio.

Ready to discussyour next project?

Start a project

Hello

Copy Email

Surat, Gujarat
IN — working remotely

Social

  • InstagramInstagram
  • LinkedInLinkedIn
  • BehanceBehance
  • GitHubGitHub
  • XX

Studio hours

Monday to Friday
10am – 7pm IST

We reply within one working day.

Legal

  • Privacy policyPrivacy policy
© 2026 NULL LAB®Creative digital agency
NULL LAB