Privacy Policy
How Tarini Engineering Works handles personal data across the PandaLogix website and the cloud control plane. Written to be checked against the software rather than to cover every eventuality.
Effective 9 September 2026
Who is responsible
Tarini Engineering Works, Khasra No. 2915, Kataria Complex, Near Daulatabad Flyover, Gurugram, Haryana 122006, is the data fiduciary for everything described here. Reach us at business@tariniengg.in.
The website
Public pages record one page view each, and the implementation is deliberately narrow:
- No cookies are set for analytics. A session identifier lives in sessionStorage, dies with the tab, and exists only so one person reading three pages counts as one visit rather than three.
- Your IP address is never stored. It is used at the edge to derive a two-letter country code and then dropped.
- Your user agent is never stored. It is collapsed to mobile, tablet or desktop and discarded.
- The referrer is reduced to a hostname before it is written, because a full referring URL can carry the search terms someone typed.
- If your browser sends Do Not Track, nothing is recorded at all.
- What remains is the path, that country code, the device class, any utm_* tags on the URL, and the tab-scoped session id.
There is no third-party analytics, no advertising pixel, no session recorder and no social tracking script on this site. Nothing about a visitor is shared with anyone, because there is nothing worth sharing and no one to share it with.
The console — everything behind a sign-in — is not instrumented at all. Watching what a paying customer does inside their own dashboard is not what this was built for.
Enquiries and licence requests
When you submit a pricing enquiry, a Verdict enquiry or a licence request, we keep what you typed: your name, work email, company, phone if you gave one, and the message. We use it to reply, to quote, and to issue and support a licence. We do not sell it, rent it, or pass it to anyone for their marketing.
Console accounts
An account holds your email address and the organisation you belong to. Authentication is handled by Supabase, our processor; the session cookie it sets is strictly necessary for signing in and is not used to track you.
What a gateway sends us
This is the part worth reading closely, because it is the part about your plant rather than about you.
- Heartbeats — that a gateway is alive, its version, and the health of its connections.
- Tag metadata — the names and addresses of the tags a gateway is configured to poll, so the console can show its configuration.
- Log tails — only when an operator asks for one from the console. Up to 20 per gateway are retained.
- Commands you issue from the console, and their results.
Process values are not streamed to us as a matter of course. The gateway serves your data to your own systems over OPC-UA, Modbus, MQTT, SQL and REST; it does not route production data through our infrastructure to get there. Where the console shows live tag values, it is fetching them on demand, for you, while you are looking.
A log tail is a log tail: if your plant writes sensitive strings into gateway logs, they will be in the tail you asked us to collect. Deployments that cannot accept that should not request log capture.
How long anything is kept
- Heartbeats and gateway logs: 7 days by default, then deleted automatically.
- Log tails: the most recent 20 per gateway, whatever their age.
- Page views: pruned on a rolling window; they contain no identifier for a person.
- Enquiries, invoices and licence records: kept for as long as the licence is live and then as long as Indian tax and company law requires.
Who processes data on our behalf
- Supabase — database, authentication and storage for the control plane.
- Netlify — hosting and edge delivery for this site and the console.
- Razorpay — payment processing. Card and bank details are entered on their systems and are never seen by, sent to, or stored by us. We receive the fact of a payment, its reference, and the amount.
- Email delivery — for transactional mail: sign-in links, licence keys and support replies.
Each is used for that purpose and no other. None of them is given data for their own marketing.
Security
Traffic is served over TLS. Gateways authenticate with signed tokens that can be revoked from the console, per gateway, without touching the rest of a fleet. Database access is constrained by row-level security so one organisation cannot read another's rows. No arrangement is perfect and we do not claim otherwise; if we ever find a breach that affects you, we will tell you what happened and what we did about it.
Your rights
You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or withdraw consent to marketing contact — which we do not send by default anyway. Email business@tariniengg.in and we will respond within one working day and act within 30 days. Deleting an account removes its personal data; records we are legally required to retain, such as issued GST invoices, stay for their statutory period.
Children
This is industrial software sold to businesses. It is not directed at children and we do not knowingly collect their data.
Changes
Material changes are published here with a new effective date. If a change alters what we collect from an existing customer, we email them rather than relying on this page being reread.
Contact and grievances
Privacy questions, requests and complaints go to business@tariniengg.in, or by post to the address on our contact page.