CodeAro Technologies · LEGAL & COMPLIANCE

DPDP Policy - India

Our compliance commitments under the Digital Personal Data Protection Act, 2023, for clients and visitors based in India.

Effective: 28 September 2026
Udyam: UDYAM-UP-50-0304037
Governing law: India

What the DPDP Act means for you

India's Digital Personal Data Protection Act, 2023 (DPDP Act) gives every individual - a data principal - control over their personal data and sets obligations on the organisation that processes it, a data fiduciary.

In plain terms: we use your data only for the project you asked for, we tell you plainly what we hold, you can see it, correct it or have it deleted, we do not sell it, and if anything goes wrong we tell you quickly. This policy is issued by CodeAro Technologies, a proprietorship enterprise, Udyam Registration UDYAM-UP-50-0304037.

EnterpriseCodeAro Technologies
Udyam RegistrationUDYAM-UP-50-0304037
Effective date28 September 2026

01 Scope and Applicability

This policy applies to CodeAro Technologies, a proprietorship enterprise registered under Udyam Registration UDYAM-UP-50-0304037, in its capacity as a Data Fiduciary for the personal data of data principals who are in India. It covers our website, our quote form, our email and messaging channels, and the personal data we process while delivering projects for Indian clients.

Where we process personal data purely on a client's instructions - for example maintaining the customer records of an e-commerce store we built - the client is the Data Fiduciary and we act as a Data Processor. Section 10 explains what that changes.

02 Key Terms Used Here

  • Digital Personal Data - information in digital form that identifies or can reasonably be linked to an individual, including name, phone number, email address, address, payment identifiers, device identifiers and online identifiers.
  • Data Principal - the individual to whom the personal data relates.
  • Data Fiduciary - the entity that determines the purpose and means of processing personal data.
  • Data Processor - an entity that processes personal data on the Data Fiduciary's behalf and instructions.
  • Consent - a free, specific, informed, unconditional and unambiguous indication of the data principal's wish, given through a clear affirmative action.
  • Personal Data Breach - any unauthorised access to, or unauthorised disclosure, alteration or destruction of personal data.

03 What Personal Data We Process, and the Lawful Basis

We rely on consent and on performance of a contract or pre-contractual steps, as applicable. We do not rely on legitimate interest as a default.

Data we processWhyLawful basis
Name, business name, phone, email, cityResponding to your enquiry and preparing a quotationConsent, and steps prior to entering a contract
Project requirements, budget, timelineScoping, pricing and delivering the projectPerformance of a contract
Project files, content, credentialsBuilding and supporting your projectPerformance of a contract
Invoices, payment and tax recordsBilling, accounting and statutory complianceCompliance with a legal obligation
IP address, timestamp, request logsSecurity, abuse prevention and troubleshootingConsent, and legal obligation for security logs
Correspondence with youAnswering questions and managing the engagementConsent and performance of a contract

You may withdraw consent at any time, but a withdrawal made before we have performed a contract with you may mean we can no longer deliver the project. We will tell you if that is the case.

04 Notice to Data Principals

Every time you give us personal data, we give you this notice:

  • Who we are - CodeAro Technologies, a proprietorship enterprise, Udyam UDYAM-UP-50-0304037, reachable at [email protected].
  • What we collect - the details listed in section 03, plus anything you choose to put in the requirements box.
  • Why we collect it - to reply to you, quote accurately, build and support your project, invoice you, and keep our systems secure.
  • How long we keep it - as set out in section 08.
  • Who else sees it - our hosting, email, messaging and payment providers, and the third parties your project integrates with (section 06).
  • Your rights - the rights in section 05.
  • How to complain - email us first, or approach the Data Protection Board of India as described in section 11.

05 Rights of Data Principals

Under the DPDP Act you may ask us to:

  • Obtain a copy of the personal data we hold about you, in a readable form.
  • Correct or complete incomplete or inaccurate personal data.
  • Erase personal data where its purpose is met, where you withdraw consent, or where we are legally required to erase it.
  • Withdraw consent at any time.
  • Nominate someone to exercise your rights on your behalf if you are unable to do so yourself.
  • Know how your personal data was used and where it was stored.
  • Object to, and stop, any use of your personal data for direct marketing.
  • Withdraw your personal data from any use in artificial-intelligence or machine-learning models you train, where such use has been notified to you.
  • Raise a grievance with us and receive a response.

To exercise any of these rights, email [email protected] with the subject line "DPDP Request" or call +91 97628 13988. We respond within two business days and complete most requests within 30 days. We may verify your identity first. We do not charge for a legitimate request, and we will never penalise you for making one.

06 Sharing and Cross-Border Transfer

We share personal data only with service providers strictly necessary to deliver your project and meet our legal obligations - hosting, backup and security providers, our email and business-messaging providers, our payment gateway, our accountant, and the third-party platforms your project integrates with. Each is bound by contract to process data only as we instruct and to keep it confidential.

Where personal data is transferred outside India, we apply an appropriate safeguard recognised under Indian law - a standard contractual clause or an equivalent written obligation - and limit the transfer to the minimum data needed. We do not sell or rent personal data to anyone.

07 Security Measures

  • Encryption of data in transit (HTTPS with valid TLS) on every page and form.
  • Regular backups, with copies held away from the primary server, and automated monitoring for availability and infrastructure faults.
  • Access controls: only team members working on your project can reach your files and accounts, and credentials are shared securely rather than by open email.
  • No storage of payment card data, CVV, bank details, UPI PINs or OTPs - we never ask for them, so we can never leak them.
  • Staff briefed on confidentiality obligations.

08 Retention

  • Enquiries that do not become projects - deleted within 12 months.
  • Project and contractual records - retained for the life of the project plus 8 years for accounting, tax and legal record-keeping.
  • Security and server logs - 90 days, extended where an investigation is under way.
  • Backups - deleted as they age out of the rotation cycle.

09 Personal Data Breach

If we discover a personal data breach that may harm a data principal, we will:

  1. Contain and remediate the breach as quickly as possible.
  2. Notify every affected data principal, without undue delay, describing what happened, what data was involved and what you should do.
  3. Notify the Data Protection Board of India and any other competent authority within the time required by law, with details of the breach and the remedial steps taken.

Where a breach affects an active project, we also notify you directly as our client, because you are usually the Data Fiduciary for any personal data held inside that project.

10 Our Role as Data Processor

Where we process personal data only on a client's documented instructions, we act as a Data Processor. The client is the Data Fiduciary and is responsible for the lawfulness of the processing. We will:

  • Process personal data only on the client's documented instructions, including instructions to transfer data to another country.
  • Ensure that people authorised to process the data are bound by confidentiality obligations.
  • Implement the security measures described in section 07.
  • Assist the client in responding to a data principal's request, in so far as we are able.
  • Notify the client without undue delay if we become aware of a breach affecting their data.
  • Delete or return the personal data at the end of the engagement, subject to our records-retention obligations.

11 Grievance Redressal and Contact

If you have a concern, email [email protected] with the subject line "DPDP Grievance", or call +91 97628 13988 between 10:00 and 19:00 IST, Monday to Saturday. We acknowledge within two business days and aim to resolve within 30 days, telling you clearly if a matter needs longer.

If you are not satisfied with our response, you may approach the Data Protection Board of India, the authority established under the DPDP Act, 2023. We would genuinely rather hear from you first and put it right.

12 Children and Verifiable Consent

Our services are for businesses. We do not knowingly process the personal data of children under 18, and we do not knowingly target children. Where a project is, by its nature, likely to be used by children, we ask the client to put an appropriate age-assurance and parental-consent mechanism in place, and we support the client in implementing it. If you believe a child has given us personal data, tell us and we will erase it.

13 Changes to This Policy

We update this policy when our practices, our processors or the law changes. The "last updated" date always reflects the current version. For material changes we notify active clients by email before the change takes effect.

Data principal requests and grievances

Email with the subject line “DPDP Request” or “DPDP Grievance”. We acknowledge within two business days and aim to resolve within 30.

Call / WhatsApp +91 97628 13988
Udyam Registration

UDYAM-UP-50-0304037

Business hours

Mon - Sat, 10:00 - 19:00 IST