Privacy Policy
Last updated: August 2, 2026
HawkLogic Systems Private Limited — a deep-tech company based in Bangalore, India — operates hawklogicsystems.com. This policy covers the site, the engineering tools, ENKI (our AI design assistant), and HawkLogic accounts. Our Terms of Service govern your use of those services.
Information we collect & why
- Account data (via AWS Cognito). Your email address (the verified identifier you sign in with), an optional and unverified phone number, and a password — stored hashed by Cognito, so we never see it. Used to authenticate you and provide account features.
- Spacebuilder profile (signed-in users). The display name, @handle, role, bio, organisation, location and links you choose to put on your account profile, plus the settings for your generated mission-patch avatar. All of it is optional, all of it is editable by you, and the @handle is reserved so it stays unique.
- ENKI conversations (signed-in users). If you are signed in, your ENKI design conversations — your messages, ENKI's replies, and the design state (mission parameters and every calculation artifact) — are saved to your account so you can resume them. You can delete any conversation from the history panel in the studio. If you are not signed in, your conversation is never stored on our servers between turns — it lives only in your browser tab for the session.
- Saved tool history (signed-in users). When you are signed in, the inputs to a calculator run and a short headline of its results are saved to your account so you can reopen and manage them. You can delete any saved run inside the tool.
- First-party usage analytics. We record product-usage events — for example, viewing a page (including the path you viewed), viewing a tool, running a calculation, or opening the explainer — together with the tool identifier where one applies and a short hash of the inputs. These are tied to your account when you are signed in, and otherwise to a salted, pseudonymous identifier derived from your network address. Pseudonymous, not anonymous: it is a one-way hash we cannot turn back into an address, but it stays the same for the same network, so we treat it as personal data rather than claiming it is anonymised. We do not store your raw IP address for this. It is used only to improve the product; it is not sold, and not shared with advertisers.
- Ad-click attribution. If you arrive from an advertisement, the click identifier and campaign labels carried in the link (for example gclid, utm_source) are kept in your browser's session storage for that browsing session and attached to the usage events above, so we can tell which campaigns bring people who actually use the tools. It stays in your browser tab and is cleared when you close it, it sets no cookie, it does not follow you to other sites, and it expires with those usage events after roughly 90 days. Where a click leads to a purchase, the identifier is also attached to that payment record as order metadata, so we can tell which campaigns lead to a sale. That copy is kept with the payment record and has no automatic expiry today — ask us and we delete it with the rest of your data, and we remove it even where the underlying transaction record itself has to be kept for tax or accounting purposes.
- Rate-limit & usage counters. To keep the AI features fairly available and bound their cost, we keep per-caller usage counters. For signed-in users these are keyed by your account; for anonymous visitors they are keyed by a one-way hash of your IP address — never the raw address. We also keep per-request AI usage records (tokens, latency, cost) keyed the same way.
- Contact & newsletter. If you use the contact form or subscribe to our newsletter, we store the name, email, and message you provide so we can reply or send updates. Contact and newsletter submissions also generate a notification email to our team.
- Feedback. If you send feedback (for example from the ENKI studio), we store the message, the page it came from, and — if you are signed in or provide one — your email address, and notify our team by email. If you register interest on one of our in-development feature pages (a "fake door" — no purchase or commitment involved), we also send you a one-time confirmation email at the address you provide.
- Registered interest in features we have not built. If you press Register interest on one of the coming-soon cards on your account page, we record which feature you asked for, when, and the account it came from (your email address, and your display name and @handle if you have set them). We notify our team by email, and we send you a one-time confirmation naming what you registered for. Nothing is charged and nothing else on your account changes. We use it to decide what to build next, and we will email you again when that feature opens; ask us and we delete the record.
- Technical / operational logs. Standard server and application logs — which can include IP address, user agent, forwarded-address headers, and timestamps — kept for security, abuse prevention, and reliability. Two specifics worth stating plainly: when our spam filter blocks a form submission, a truncated copy of what was submitted is written to the log so a wrongly-blocked message can be found and recovered; and a payment notification from our payment provider is logged with the address and user agent it arrived from, so we can tell a real notification from a forged one. These logs are not joined to your analytics profile.
- Legacy waitlist sign-ups: if you joined the waitlist for SkillSwap — an earlier product we no longer operate — we still hold the email address you gave us and the date you signed up. The form was removed in July 2026 and we do not send email to this list.
Where your data is stored
Primary region: AWS ap-south-1 (Mumbai, India). Everything described above is stored there — the database tables holding contact messages, newsletter subscriptions, feedback, saved tool runs, usage events, ENKI conversations and design state, rate-limit counters, profiles and payment entitlements; the AWS Cognito user pool holding your account; the functions that process your requests; and the service that sends our email.
The site is delivered by Amazon CloudFront, a global content-delivery network. Your request is received at a CloudFront edge location — which may be outside India — before it reaches our servers in Mumbai.
Who else processes it, and what leaves India
- Amazon Web Services (AWS). Hosts the site, stores the data, runs the code and sends our email. Storage and processing are in the ap-south-1 (Mumbai) region; delivery is via CloudFront's global network, as above.
- Anthropic (United States) — leaves India. When you use ENKI or the tool explainer, the content of that request — your messages, the design state, and the calculator inputs and outputs being explained — is sent to Anthropic, whose AI models generate the response. That content leaves our AWS environment and India for the duration of processing, and is handled by Anthropic under its own privacy policy. We do not send Anthropic your email address, password or any other account identifier — only the content needed to answer. ENKI can also call an orbital-mechanics tool we host in Mumbai; when it does, Anthropic's servers contact that tool directly and the tool's inputs travel the same route in reverse.
- Dodo Payments — merchant of record, leaves India. Only if you buy something. Dodo — not HawkLogic — is the seller of record for the transaction and runs the checkout page. We send Dodo your account email address and an order reference that contains your account identifier; Dodo sends back a customer reference, the email and name on the payment, a payment reference and the billing month, which we store against your account to grant your entitlement. If you arrived from an advertisement, the click identifier and campaign labels from that link also travel with the order as metadata and come back to us on the payment notification, so a sale can be matched to the campaign that produced it. Your card details always stay with Dodo and never reach our systems. For prepaid credit-pack purchases, Dodo's checkout page also collects your own billing country (plus, where a tax regime needs it, a postal code) and uses it to work out the currency and tax for your purchase. For plan purchases, currency and tax are currently computed against our registered business address in India rather than your own location — so a plan checkout is priced in INR wherever you buy from.
- Google Analytics 4 — leaves India. Google's gtag.js runs on our pages for aggregate page-view and product-interaction analytics (for example, which tool a button was clicked on — never form contents, emails, or anything you type). It sets analytics cookies only after you accept them; until then it runs with storage denied and cannot set them at all (see Cookies & local storage below). It is operated by Google and governed by Google's privacy policy — policies.google.com/privacy.
- Microsoft — inbound email. Mail sent to our addresses is delivered to mailboxes hosted by Microsoft. So a copy of anything you send us — a contact message, feedback, or a data request — also comes to rest in a Microsoft-hosted mailbox, in addition to the copy in our database in Mumbai.
Transfers out of the UK and the EU/EEA. If you are in the UK or the EU/EEA, everything above involves a transfer of your data outside your country — to India, where we store and process it, and to the United States, where our AI-model provider and our analytics provider operate. Those transfers rely on the Standard Contractual Clauses (for the UK, the UK International Data Transfer Addendum) built into our agreements with those providers, together with the technical and organisational measures described in this policy. Ask us through the data-request route below and we will tell you which mechanism covers a given recipient and share the relevant terms.
If you do not want particular information processed this way, don't include it in an ENKI conversation or an explained calculation.
How long we keep it
- Usage-analytics events: automatically expire after roughly 90 days.
- Unpinned, auto-saved tool runs: automatically expire after roughly 180 days. Pinned runs are kept until you delete them.
- ENKI conversations & design state: kept until you delete the conversation in the studio, or until we delete it at your request. There is no automatic expiry on this store today.
- Rate-limit counters & AI usage records: pseudonymous (hashed IP or account id); kept until deleted at your request. There is no automatic expiry on this store today.
- Account data & profile: kept while your account exists; deleted when you ask us to delete your account (below), which also releases your @handle.
- Billing & entitlement records: the record that you bought something — the payment reference, the plan or pack, the date, and the entitlement it granted — is kept as long as tax and accounting law requires us to keep it, and is not deleted on request while that obligation runs. We say so rather than promise a deletion we cannot make. Anything on those records that is not required for that purpose — the ad-click identifier and campaign labels — is removed on request.
- Contact messages & feedback: kept until you ask us to remove them.
- Newsletter data: kept until you unsubscribe or ask us to remove it.
- Operational logs: kept for a bounded period for security and reliability, then discarded.
- Legacy waitlist sign-ups: no automatic expiry. Ask us and we will delete your entry.
Cookies & local storage
Analytics cookies are off until you accept them. On your first visit we ask; until you choose, Google Analytics runs with storage denied and cannot set them. Choose Decline and it stays that way. We remember your answer in your browser's local storage so we don't ask again — clear your site data to be asked afresh.
Your sign-in tokens are stored in your browser's local storage, not in cookies; they are strictly necessary to keep you signed in and are not covered by the choice above. We use no advertising or cross-site tracking cookies, and Google's advertising storage and personalization signals stay denied at all times. When you create an account or complete a purchase, a cookieless Google Ads conversion signal is sent (the event name and, for purchases, the payment provider's transaction reference — never your identity), so we can count which ads lead to real sign-ups; it sets no ad cookie and cannot follow you across sites. We do record the ad-click identifier from the link you arrived on, as described above — it starts in your browser's session storage and is also attached to the usage events we store server-side, as noted there.
Do Not Track. Browsers can send a "Do Not Track" signal, and there is no agreed standard for what a site should do with it, so we do not respond to it. It changes nothing here either way: analytics storage stays denied until you accept it, and stays denied for good if you decline.
Your rights
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), and — for visitors in the EU, EEA, or UK — the General Data Protection Regulation (GDPR), you have the right to access, correct, and delete your personal data, to receive a copy of it, and to withdraw consent. Under the GDPR you also have the right to object to processing we carry out on the basis of our legitimate interests — which is the basis for our first-party analytics and rate limiting (see Legal bases below) — and the right to ask us to restrict processing while a dispute about it is resolved.
Canada (PIPEDA). If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) gives you the right to access the personal information we hold about you, to ask for corrections, and to challenge how we handle it. Use the same route below; the same 30-day response commitment applies. Note that your information is stored and processed outside Canada — in India, and in the United States by the providers named above — which means it is subject to the laws of those countries and may be accessible to their courts, law enforcement, and national-security authorities.
In-app: you can delete individual saved tool runs inside each tool, and delete ENKI conversations from the studio's history panel. Newsletter emails carry an unsubscribe path.
Everything else — including full account deletion — is handled on request. Email support@hawklogicsystems.com with the subject "DSAR" (Data Subject Access Request), from the email address registered with us, and tell us what you want — a copy of your data, a correction, or deletion. We verify identity by replying to your registered address, and we respond within 30 days. Account deletion removes your Cognito account and the records keyed to it — your profile and @handle, saved runs, ENKI conversations, and usage counters — with one stated exception: billing and entitlement records we are required to keep (see How long we keep it, above). We tell you in the reply if anything was kept and why.
Grievance redressal
As required by the DPDP Act, you can raise a grievance about how your data is handled with our grievance-redressal contact: Grievance Officer, HawkLogic Systems Private Limited, reachable at founders@hawklogicsystems.com (Bangalore, India). The holder of that role also acts as our person in charge of the protection of personal information for the purposes of Québec's Law 25, and is the contact for privacy complaints from Québec. We acknowledge grievances promptly and aim to resolve them within 30 days. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India — or, for GDPR matters, to your local supervisory authority, and in Canada to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
Legal bases
We provide account features on the basis of delivering the service you request; we run product analytics and rate limiting on the basis of our legitimate interest in improving and protecting the service; and anything else is done with your consent, which you can withdraw at any time.
Internal access
Authorised HawkLogic staff can access personal data only where needed for support, security, or legal compliance — for example, to fulfil a deletion request. We do not browse your saved work or conversations for curiosity or marketing.
Children
The site is not directed to children, and we do not knowingly collect data from anyone under the age set by applicable law — under 18 under India's DPDP Act, and 16 under GDPR.
Changes to this policy
We may update this policy from time to time. The "last updated" date above reflects the latest version.
Contact
Data requests: support@hawklogicsystems.com. Anything else: the contact section on the homepage, or founders@hawklogicsystems.com.