01Who we are
adeve.ai is a performance-marketing and marketing-analytics service operated by Insane Labs (“adeve”, “we”, “us”, “our”), registered in India at [registered business address — to be filled in].
We build advertising and attribution systems for healthcare and service businesses — connecting ad spend to real business outcomes such as booked appointments and walk-ins. This policy explains what personal data we collect through this website and our advertising, how we use it, and the choices you have.
This policy is written to meet the requirements of India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and — where a visitor is located in the European Economic Area or the United Kingdom — the GDPR and UK GDPR.
02Data we collect
We keep collection deliberately narrow. We do not ask for and do not want medical, diagnostic or health-condition information about any individual.
| Category | What it includes | How we get it |
|---|---|---|
| Contact data | Name, business email address, phone number, company or clinic name, role. | You give it — by emailing us, filling in an enquiry form, or booking a call. |
| Enquiry content | Whatever you choose to write to us: your objectives, budget range, current challenges. | You give it. |
| Usage & device data | IP address, browser and device type, operating system, pages viewed, time on page, referring URL, and the ad or campaign that brought you here. | Collected automatically via cookies and similar technologies. |
| Advertising identifiers | Cookie IDs, click identifiers (such as fbclid and gclid), and event data indicating actions like a page view or an enquiry. | Collected automatically when you arrive from or interact with an ad. |
| Calculator inputs | The numbers you type into any on-page estimator or diagnostic tool (for example spend, enquiries, patients). | Processed in your browser only. These figures are not transmitted to or stored on our servers unless you separately choose to send them to us. |
We do not knowingly collect sensitive personal data — such as health records, financial account details, biometric data, caste, religion or sexual orientation — through this website. Please do not include such information in messages to us.
03Why we use it
- To respond to you. Answering enquiries, sending a proposal, scheduling a call.
- To provide our services. Setting up, running, measuring and reporting on advertising campaigns for our clients.
- To measure and improve advertising. Understanding which ads, keywords and pages lead to genuine enquiries, so budget is not wasted — this is the core of what we do.
- To improve the website. Aggregate analytics on which pages are read, where people drop off, and whether the site works on a given device.
- To send business communications you have asked for. Every marketing email carries a one-click unsubscribe link.
- To meet legal, tax and accounting obligations and to establish, exercise or defend legal claims.
- To keep the service secure — detecting fraudulent clicks, bot traffic, spam and abuse.
We do not sell personal data. We do not use your enquiry details to train third-party AI models, and we do not share your contact details with other advertisers.
04Legal basis for processing
Where the DPDP Act applies, we process personal data on the basis of the consent you give when you submit a form or accept cookies, and for legitimate uses permitted under the Act — such as responding to a request you have voluntarily made.
Where the GDPR or UK GDPR applies, our legal bases are: consent (non-essential cookies and marketing email), contract (delivering services you have engaged us for), legitimate interests (running and securing our website, measuring our own advertising, B2B outreach to relevant businesses), and legal obligation (tax and statutory records).
06Advertising platforms (Meta and Google)
We advertise on Meta (Facebook and Instagram) and Google, and we operate advertising accounts on behalf of our clients. To measure whether an ad produced a real enquiry, we use the standard measurement tools those platforms provide:
Meta Pixel and Conversions API
Our pages may load the Meta Pixel, and we may send equivalent event data server-side through the Meta Conversions API. These record actions such as a page view, a content view or a submitted enquiry, together with technical identifiers such as your IP address, browser user agent and the Meta click ID (fbclid).
Where an event includes contact details for matching, those details are hashed (SHA-256) before transmission in line with Meta’s requirements — Meta receives an irreversible hash, not your plain email address or phone number. We use this data for conversion measurement, campaign optimisation and building audiences of people who have already shown interest.
Meta processes this data as an independent controller under its own terms. See the Meta Privacy Policy, and manage your own choices in Meta’s Ad Preferences and Off-Facebook Activity settings.
Google Ads and Google Analytics
We use Google Ads conversion tracking and Google Analytics to attribute enquiries to campaigns and to measure site usage. This may involve cookies and the Google click ID (gclid). See the Google Privacy Policy. You can opt out of Google Analytics using Google’s browser opt-out add-on, and adjust ad personalisation at My Ad Center.
We do not run advertising that targets individuals on the basis of health conditions, and we do not upload health-related audience data to any advertising platform.
08Data we process on behalf of clients
When we deliver services, we handle enquiry and appointment records belonging to our client — the clinic or business that engaged us. In that context the client is the Data Fiduciary / controller and adeve.ai is a Data Processor acting on their written instructions.
Our practice is to work with the minimum viable data: we track outcomes and stages — enquiry, appointment booked, walk-in — rather than clinical detail. Case studies and reports we publish use aggregate figures, and the identity of individual patients is never disclosed. If you are an individual whose data sits in a client’s system, please direct access or deletion requests to that business; we will assist them promptly in fulfilling your request.
09How long we keep it
- Enquiries that do not become clients — up to 24 months from last contact, then deleted.
- Client records and campaign data — for the duration of the engagement and up to 7 years afterwards, where required for tax, accounting and contractual records.
- Website analytics — typically 14 to 26 months, per the retention setting of the analytics platform.
- Advertising event data — retained by Meta and Google under their own retention schedules, which we do not control.
When a retention period ends, we delete the data or irreversibly anonymise it.
10Your rights
Subject to the law that applies to you, you have the right to:
- Access a summary of the personal data we hold about you and how it is processed.
- Correct or complete data that is inaccurate, misleading or out of date.
- Erase your data where it is no longer needed for the purpose it was collected for.
- Withdraw consent at any time, as easily as it was given — this does not affect processing already carried out.
- Object to or restrict processing, and to data portability, where the GDPR or UK GDPR applies.
- Nominate another person to exercise your rights in the event of death or incapacity, under the DPDP Act.
- Complain — to the Data Protection Board of India, or to your local supervisory authority in the EEA/UK.
To exercise any of these, email access@insanelabs.in with “Privacy request” in the subject line. We respond within 30 days and may ask for proof of identity before acting, so that we do not disclose your data to someone else. Exercising your rights is free; we may charge a reasonable fee only for requests that are manifestly excessive or repetitive.
11Security
We apply reasonable security practices proportionate to the data we hold: encryption in transit (HTTPS/TLS), access restricted to the people who need it, credential rotation, and vendors selected for their own security posture. Personal identifiers are hashed before they are sent to advertising platforms.
No method of transmission or storage is perfectly secure. If a personal data breach occurs that is likely to affect you, we will notify the Data Protection Board of India and affected individuals as required by law and without undue delay.
12International transfers
We are based in India. Some of our providers — including Meta, Google, and our hosting and email vendors — process data on servers outside India, including in the United States and the European Union. Where such transfers involve personal data protected by the GDPR or UK GDPR, they are made under an adequacy decision or Standard Contractual Clauses, together with appropriate technical safeguards.
13Children
Our website and services are intended for businesses and for adults. We do not knowingly collect personal data from children under 18, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children, as required by the DPDP Act. If you believe a child has provided us with personal data, contact us and we will delete it.
14Changes to this policy
We may update this policy as our services, tools or the law change. The “Last updated” date at the top always reflects the current version. Where a change materially affects how we use your personal data, we will take reasonable steps to notify you — for example by email or a notice on this site — before it takes effect.
15Contact and grievance redressal
Data protection / grievance contact
Email: access@insanelabs.in
Entity: Insane Labs (operator of adeve.ai)
Address: [registered business address — to be filled in]
Grievance Officer: [name of grievance officer — to be filled in]
We acknowledge every privacy request or grievance within 72 hours and aim to resolve it within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India, or to your local data protection authority if you are in the EEA or the UK.