Data Privacy Policy

  • Home
  • /
  • Data Privacy Policy

Last updated: June 2026

This Data Privacy Policy ("Policy") describes the detailed data processing practices of Corposol Research India Pvt Ltd ("Corposol", "Data Fiduciary", "we", "our", or "us") in compliance with India's Digital Personal Data Protection (DPDP) Act, 2023 and other applicable data protection frameworks. This Policy applies to all personal data we process in connection with our software development and IT services.

1. Definitions

  • Personal Data: Any data about an individual who is identifiable by or in relation to such data.
  • Data Principal: The individual to whom the personal data relates (i.e., you, our client or website visitor).
  • Data Fiduciary: Corposol Research India Pvt Ltd, which determines the purpose and means of processing personal data.
  • Processing: Collection, storage, use, sharing, disclosure, or deletion of personal data.
  • Consent: A free, specific, informed, and unambiguous indication of the Data Principal's wishes.

2. Categories of Personal Data Processed

We process the following categories of personal data in the course of our business:

  • Identity Data: Full name, designation, and organisation name of contacts.
  • Contact Data: Email address, phone number, postal address.
  • Business Requirement Data: Project briefs, technical specifications, business process details shared during engagements.
  • Financial Data: Billing information, invoices, and payment records (processed via secure channels).
  • Technical Data: IP address, browser information, device identifiers, access logs from website visits.
  • Communication Records: Emails, call records, meeting notes, WhatsApp messages related to project delivery.

3. Legal Basis for Processing

We process personal data on the following legal bases:

  • Consent: When you submit forms, subscribe to our newsletter, or initiate contact with us, you consent to our processing of the data you provide.
  • Contract Performance: Processing is necessary to enter into or perform a contract for software/app development services you have engaged us for.
  • Legal Obligation: Processing required to comply with Indian tax laws, accounting regulations, or orders of competent authorities.
  • Legitimate Interests: Processing for purposes of business development, security, fraud prevention, and improving our services, where this does not override your rights.

4. Purpose Limitation

Personal data collected for a specific purpose will not be used for any other purpose without obtaining fresh consent or unless required by law. We do not use project-related client data for marketing purposes.

5. Data Minimisation

We collect only the personal data that is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. We do not collect sensitive personal data (such as biometric data, financial account details, health records) unless strictly required for a specific project engagement and with explicit consent.

6. Rights of Data Principals

Under applicable law, you have the following rights with respect to your personal data:

  • Right to Access: Obtain a summary of the personal data we hold about you and the purposes for which it is being processed.
  • Right to Correction: Request correction of inaccurate or outdated personal data.
  • Right to Erasure: Request deletion of personal data that is no longer necessary or where consent has been withdrawn (subject to legal retention requirements).
  • Right to Grievance Redressal: Register a complaint with our Data Protection Officer if you believe your rights have been violated.
  • Right to Nominate: Nominate an individual to exercise your rights in the event of your incapacity or death.

To exercise any of these rights, please submit a written request to enquiries@gocorposol.com. We will respond within 30 days.

7. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Our general retention schedule is:

  • Contact enquiry data: Up to 12 months from last interaction if no engagement is initiated.
  • Active project data: Duration of the project plus 3 years post-completion.
  • Financial and billing records: 7 years as required by Indian accounting and tax laws.
  • Newsletter subscriber data: Until unsubscription or withdrawal of consent.

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.

8. Data Security Measures

We implement the following safeguards to protect personal data:

  • Access controls and role-based permissions for internal systems.
  • Encrypted transmission of data over the internet (HTTPS/TLS).
  • Regular security assessments of our systems and applications.
  • Confidentiality obligations imposed on all employees and contractors who handle personal data.
  • Incident response procedures to detect, report, and remediate personal data breaches.

In the event of a personal data breach that is likely to result in high risk to your rights, we will notify you without undue delay.

9. Cross-Border Data Transfers

We primarily process personal data within India. Where client engagements require data to be shared with internationally located sub-contractors or cloud service providers, we ensure appropriate safeguards are in place, including contractual clauses or reliance on jurisdiction-specific adequacy decisions.

10. Data Processing in Software Development Services

When we develop software solutions that involve personal data of your end-users, Corposol acts as a Data Processor on behalf of our client (the Data Controller/Fiduciary). In such cases:

  • We process data only on documented instructions from the client.
  • We maintain confidentiality of the data and ensure our staff are bound by appropriate obligations.
  • We assist the client in responding to data subject requests.
  • We delete or return all personal data upon completion of services, as instructed.
  • Data processing terms are documented in our service agreements.

11. Grievance Redressal

If you have any concerns about how we handle your personal data, you may contact our Data Protection Point of Contact:

Data Protection Contact

Corposol Research India Pvt Ltd

Email: enquiries@gocorposol.com

Phone: +91 8105199399

We aim to resolve all grievances within 30 days of receipt.

If your concern is not resolved to your satisfaction, you may escalate to the relevant data protection authority.

12. Updates to This Policy

This Policy will be reviewed and updated periodically, especially when there are changes in applicable law or our data processing activities. Material changes will be communicated via our website. Continued use of our services after such updates constitutes acceptance of the revised Policy.