CodeAro Technologies · LEGAL & COMPLIANCE

GDPR Policy - EU / EEA

Our compliance commitments under the EU General Data Protection Regulation, for visitors and clients in the European Economic Area.

Effective: 28 September 2026
Udyam: UDYAM-UP-50-0304037
Governing law: India

What the GDPR means for you

The GDPR treats you as the owner of your personal data. It gives you the right to know what we hold, to get a copy, to correct it, to have it deleted, to move it to another provider, and to object to how we use it.

It also obliges us to be specific about why we use each piece of data, to keep it only as long as we need it, to tell you within 72 hours if a breach puts your data at risk, and to transfer it outside the EEA only under a lawful safeguard. This page is issued by CodeAro Technologies, a proprietorship enterprise, Udyam Registration UDYAM-UP-50-0304037, established in India.

EnterpriseCodeAro Technologies
Udyam RegistrationUDYAM-UP-50-0304037
Effective date28 September 2026

01 Controller Identity

CodeAro Technologies, a proprietorship enterprise registered in India under Udyam Registration UDYAM-UP-50-0304037, is the controller of the personal data described in this policy. Our privacy contacts are [email protected] and +91 97628 13988, at 548 Gha / 107, Tezi Khera, Manaknagar, Lucknow, Uttar Pradesh - 226011, India.

CodeAro Technologies is a small business and has not appointed a dedicated Data Protection Officer. Our privacy lead operates under the contact details above. Where a project requires a named DPO or EU representative under the GDPR, we will identify and appoint one as part of that project's scope.

02 Scope

This policy applies to personal data we process in relation to you as a website visitor, an enquiry contact or a client where you are established in, or resident in, the European Economic Area. If you are in India, the DPDP Policy applies instead.

03 Lawful Bases for Processing

Under Article 6 GDPR we rely on the following bases:

PurposeDataLawful basis
Replying to your enquiry and preparing a quotationName, business, contact details, project and budget informationConsent (Art. 6(1)(a)) and steps prior to contract (Art. 6(1)(b))
Delivering and supporting your projectContact details, project files, credentials, correspondencePerformance of a contract (Art. 6(1)(b))
Billing, accounting and taxContact details, invoices, transaction recordsLegal obligation (Art. 6(1)(c))
Website security and abuse preventionIP address, timestamp, request dataLegitimate interests in securing our systems (Art. 6(1)(f))
Legal claims and record keepingCorrespondence, project recordsLegitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that the processing is necessary for our security and our legal position, and that it does not override your rights. You can object at any time - see section 08.

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

04 Special Category and Criminal-Offence Data

We do not intentionally collect special category data (health, biometrics, political opinions, religious or philosophical beliefs, trade-union membership, sex life or orientation, or genetic data) or criminal-offence data. If a project we build for you requires us to process such data on your behalf, we will document the condition relied on under Article 9 in a data processing agreement before any processing starts.

05 Recipients and Processors

We share personal data with a small number of processors, each limited to what it needs and bound by a written data processing agreement:

  • Our web hosting provider - servers, backups and security monitoring.
  • Our email and business-messaging provider - to reply to you.
  • Our payment gateway - to take payment for invoices.
  • Our accountant - to meet bookkeeping and tax obligations.
  • The third-party platforms your project integrates with (payment gateways, shipping providers, app stores, APIs) - data you have instructed us to send them.

A current list is available on request. We do not disclose personal data to advertisers, data brokers or anyone else for their own purposes.

06 International Transfers

CodeAro Technologies is established in India, so processing takes place in India. India has an adequacy decision from the European Commission, and we additionally rely on the European Commission's Standard Contractual Clauses where a transfer to a third country is required. We conduct a transfer impact assessment where a transfer presents a materially higher risk, and we apply supplementary measures - encryption in transit and at rest, access restriction, and minimum-necessary transfer - where needed. You may request a copy of the safeguards we rely on.

07 Retention Periods

  • Enquiries that do not become projects - 12 months from last contact.
  • Client project and contractual records - the duration of the project plus 8 years.
  • Security and server logs - 90 days.
  • Backups - deleted as they age out of the rotation cycle.

08 Your Rights Under the GDPR

You have the right to:

  • Be informed - this page, plus a clear notice at the point we collect your data.
  • Access (Art. 15) - confirmation that we process your data, plus a copy of it.
  • Rectify (Art. 16) - correct inaccurate data and complete incomplete data.
  • Erase (Art. 17) - "right to be forgotten", where one of the Article 17 grounds applies.
  • Restrict processing (Art. 18) - while a concern about accuracy or lawfulness is resolved.
  • Receive your data in a portable format (Art. 20) - machine-readable, so you can move it to another provider.
  • Object (Art. 21) - to processing based on legitimate interests, including any use for direct marketing. We do not use your data for direct marketing.
  • Withdraw consent (Art. 7(3)) - at any time, without affecting lawfulness of processing already carried out.
  • Not be subject to automated decision-making - we do not do this.
  • Complain to a supervisory authority (Art. 77) in your country of residence, work or the place of an alleged infringement. We would rather you raised it with us first.

To exercise a right, email [email protected] with the subject line "GDPR Request". We respond within two business days and complete requests within one month, as required by Article 12(3). We may verify your identity first, and we never charge for a request. If we refuse a request, we explain why and tell you how to complain.

09 Cookies and Similar Technologies

This website sets no advertising or analytics cookies and runs no cross-site tracking. We rely only on storage that is strictly necessary to operate the site and the quotation form. Because we do not use non-essential cookies, there is no consent banner to accept and nothing to refuse. If we ever introduce analytics, we will implement a proper consent mechanism in line with the ePrivacy Directive before setting any non-essential cookie.

10 Security of Processing

Taking into account the state of the art, implementation costs and the nature and scope of processing, we have implemented security measures appropriate to the risk, including encryption in transit, regular backups held away from the primary server, availability and infrastructure monitoring, access restriction to project-relevant team members, and a strict policy of never requesting or storing payment card, banking or authentication secrets.

Personal data breaches are reported to the relevant supervisory authority within 72 hours of becoming aware, and affected data subjects are notified without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

11 Children's Data

Our services are business services and are not directed at children. We do not knowingly collect personal data from anyone under 16. Where a project is likely to be used by children, we implement appropriate age-assurance and parental-consent flows at the client's request.

12 Changes to This Policy

We review this policy at least annually and whenever our processing changes materially. The "last updated" date reflects the current version. Where a change affects data you have given us, we will notify you by email before it takes effect.

GDPR rights requests

Email with the subject line “GDPR Request”. We acknowledge within two business days and complete requests within one month.

Call / WhatsApp +91 97628 13988
Udyam Registration

UDYAM-UP-50-0304037

Business hours

Mon - Sat, 10:00 - 19:00 IST