Skip to content
Legal

Privacy Policy

This policy explains what information we collect through this website and through the enquiries and client work that follow from it, why we collect it, who else sees it, and what you can ask us to do about it.

Effective
August 4, 2026
Last updated
August 4, 2026
Operated by
Ayush Malik

Who operates this website

North is a business and trading name used by Ayush Malik for his independent consulting activities in India. References to North, we, us, or our mean Ayush Malik carrying on business under the name North, unless a signed agreement expressly states otherwise.

North is an AI-Native Growth Office. We diagnose business constraints and build growth systems across strategy, AI, technology, revenue, automation, websites, sales systems, CRM, go-to-market, and personal branding. This policy covers this website, the enquiry and booking forms on it, and the business relationships that follow.

Information we may collect

We only ask for what we need to answer you properly and, if we go on to work together, to do the work. Most of what we hold is information you chose to send us.

  • Contact and business details

    Your name, email address, company name, job title or role, company website, telephone number if you send one, and your LinkedIn profile if you share it.

  • Enquiry content

    What you tell us about the business: the industry, company size, timeline, where growth is stuck, what has already been tried, and anything else written into a form or an email.

  • Meeting information

    Details connected to arranging or attending a meeting with us, including the time chosen and any notes added when booking.

  • Technical data

    IP address, browser type, device type, operating system, referring source, pages requested, and the dates and times of those requests. This is collected through ordinary server and hosting logs.

  • Interaction data

    How pages on the site are used, at an aggregate level, where any measurement is in place. Our Cookie Policy states exactly what is active today.

  • Communications

    Emails, messages, and the notes we take during calls and meetings with you.

  • Client materials

    Documents, data, systems access and business information that a prospective or existing client chooses to share with us during an engagement.

We do not ask for sensitive personal information through this website. Please do not send financial account details, government identifiers, health information, passwords or other sensitive data through the enquiry form. If you need to share something sensitive during an engagement, we will agree a suitable method with you first.

How we collect it

  • The enquiry and Growth Audit forms on this website
  • Email and direct messages you send us
  • Calls, meetings and the notes taken during them
  • The scheduling calendar embedded on our booking page
  • Server, hosting and security logs generated automatically when a page is requested
  • Cookies and similar technologies, where they are in use
  • Onboarding and delivery during a client engagement
  • Business systems we use to run North, such as email and calendars

We do not buy contact lists, and we do not scrape personal data to build one.

Why we process it

  • Responding to your enquiry
  • Assessing whether an engagement is a sensible fit for both sides
  • Arranging and holding meetings
  • Preparing proposals, diagnoses and scopes of work
  • Onboarding a client and delivering contracted work
  • Providing consulting, implementation and support services
  • Operating, maintaining and securing this website
  • Understanding how the site is used so it can be improved
  • Keeping ordinary business, accounting and project records
  • Preventing abuse of our forms, including spam and automated submissions
  • Meeting obligations that apply to us under law
  • Sending service-related messages about work in progress
  • Sending occasional business updates, only where that is lawful and appropriate, and only until you tell us to stop
In plain English

We use what you send us to answer you and to do the work. We do not sell your information, and we do not share it with anyone for their own marketing.

The basis for processing

We process information where you have given it to us for a clear purpose, where processing is necessary to respond to your request or to perform an agreement with you, where we have a legitimate business interest such as running and securing this website and keeping proper records, and where the law requires it.

Where consent is the right basis, for example optional business updates by email, we ask for it separately and you can withdraw it at any time. Withdrawing consent does not affect anything already done on the basis of it.

Indian data protection law continues to develop. We will keep this policy under review and update it as obligations become applicable to a business of this size and type.

Service providers we rely on

We use established third-party services to run the website and the business. Each one operates under its own terms and privacy practices, and each name below links to that provider's privacy information.

In use today:

  • Vercel (opens in a new tab)

    Hosting, delivery and infrastructure for this website. Information involved: IP address, browser and device type, pages requested, server and security logs.

  • Zoho (opens in a new tab)

    Business email on the joinnorth.in domain. Information involved: name, email address, message content, attachments you choose to send.

  • GoDaddy (opens in a new tab)

    Domain registration and DNS for joinnorth.in. Information involved: domain registration records.

  • Calendly (opens in a new tab)

    Self-serve meeting scheduling. The booking page embeds Calendly's scheduler, so it loads on that page and nowhere else on this site. Information involved: name, email address, chosen time slot, booking notes.

  • Resend (opens in a new tab)

    Delivers enquiries submitted through the form on this website to our inbox. Information involved: name, email address, message content.

Not in use today, and listed here so this page stays honest about what may change. We will update this policy before any of these begins handling your information through this website:

We may also share information with professional advisers, or where we are required to do so by law or to establish or defend a legal claim.

Processing outside India

Some of the providers above operate infrastructure and support functions outside India. Where that happens, information may be processed in another country under that provider's own terms and safeguards.

We choose established providers and rely on the protections set out in their agreements. Where we cannot verify where a particular provider processes information, we do not state a location rather than guess at one.

How long we keep it

We keep information only for as long as there is a reasonable need for it. That need usually comes from one of the following:

  • Answering and following up on an enquiry
  • Performing an agreement and supporting the work afterwards
  • Keeping ordinary business and financial records
  • Security, including investigating misuse of our forms
  • Obligations that apply to us under law
  • Resolving a dispute or defending a claim

We have not set a single fixed retention period for every category, because different records serve different purposes and a stated period we did not follow would be worse than none. Where you ask us to delete something and there is no ongoing business or legal reason to keep it, we will delete it.

How we protect it

We take reasonable technical and organisational measures to protect information, in proportion to the size of the business and the sensitivity of what we hold. In practice that includes:

  • The whole website served over HTTPS
  • Access limited to the people who need it for the work
  • Authentication on the business accounts and tools we use
  • Established service providers rather than self-managed infrastructure
  • Email authentication on our domain, where configured
  • Backups and monitoring where the platforms we use provide them
  • Rate limiting and anti-spam controls on the website forms

No website or business can promise perfect security. We do not claim that information sent over the internet is completely secure, and we cannot guarantee that our measures will prevent every possible incident. If something material happens to information we hold about you, we will tell you what we know and what we are doing about it.

Your choices and requests

Depending on the circumstances and on the law that applies, you can ask us to:

  • Tell you what information we hold about you
  • Correct or update anything that is wrong or out of date
  • Delete information where there is no ongoing reason for us to keep it
  • Stop sending you business updates
  • Withdraw consent you previously gave
  • Explain how a particular piece of information reached us
  • Deal with a complaint about how we have handled your information

Where Indian data protection law grants further rights, including the ability to nominate another person to exercise your rights in the event of death or incapacity, we will honour them as those provisions come into force.

  1. Write to business@joinnorth.in and tell us what you are asking for.
  2. Give us enough detail to find the right records, such as the email address you used.
  3. We may ask you to confirm your identity before we act, so that we do not disclose information to the wrong person.
  4. We will respond within a reasonable period and explain what we have done, or why we cannot do it.

Business updates and marketing

Replying to your enquiry, arranging a meeting and communicating about work in progress are service messages, not marketing, and we will send them whether or not you have opted into anything else.

We do not add you to a mailing list simply because you contacted us, and we do not use pre-ticked consent boxes. If we ever offer an email list, joining it will be a separate and deliberate choice, and every message will carry a way to stop receiving them.

Cookies and similar technologies

Our Cookie Policy sets out exactly what this website does and does not use, and how to control it from your browser. It is kept separate so it can be updated the moment anything changes.

  • Cookie Policy

    What this website currently sets, and what it does not.

Children

This website and our services are intended for businesses and for adults acting in a business capacity. They are not directed at children, and we do not knowingly collect information from children. If you believe a child has sent us information, write to us and we will remove it.

AI and automated decisions

We use AI-assisted tools internally, for example to summarise research or draft material that a person then reviews. We do not rely solely on automated processing to decide whether to accept or decline a prospective client. A person reads every enquiry.

If an engagement ever involves automated decision-making that materially affects someone, we will say so as part of that engagement.

Changes to this policy

We will update this policy when our practices, our tools or the applicable law change. The effective date and last updated date at the top of this page always reflect the current version. Where a change is significant, we will make that clear rather than relying on you to notice it.

Contact and grievances

Privacy questions, requests and grievances all go to the same place, and are handled by Ayush Malik, who operates the business under the name North.

If you are not satisfied with how we have handled a request, tell us and we will look at it again. You may also have the right to complain to the relevant authority under applicable law.