Legal
Privacy notice
Last updated 22 August 2026 · Version 1.0
This notice explains what personal data Kaul Innovation & Technology Group Private Limited (“we”, “us”, “the Company”) collects about you, why we collect it, how long we keep it, and the rights you have. It is written to meet our obligations under India’s Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
We have tried to write it in plain language. If anything here is unclear, please ask us — the contact details are in section 11.
On this page
1 · Who we are
For the purposes of the Digital Personal Data Protection Act, 2023, the Data Fiduciary — the entity that decides how and why your personal data is processed — is:
| Legal name | Kaul Innovation & Technology Group Private Limited |
| CIN | [CIN — fill this in] |
| Registered office | [Registered address — fill this in] |
| info@kaulinnovationandtechnologygroup.com |
An important distinction. When we build or operate software for a client, that client decides what data is collected from their own customers and why. In those cases the client is the Data Fiduciary and we act as a Data Processor on their instructions. This notice covers data we control ourselves — visitors to this website, people who contact us, and our own clients and suppliers. If you are a customer of one of our clients, their privacy notice applies to you, not this one.
2 · What we collect
2.1 When you contact us
- Your name, and the organisation you represent
- Your email address and, if you give it, your telephone number
- Whatever you choose to tell us in your message about your business or requirements
2.2 When you visit this website
- Technical information your browser sends automatically — IP address, browser type, device type, operating system, and the page you arrived from
- Which pages you viewed and for how long — only if you allow analytics cookies
- Your cookie preferences, stored in your own browser so we do not ask you repeatedly
2.3 When we work together
- Contact details for the people we deal with at your organisation
- Contractual and billing information, including GST details where applicable
- Correspondence, project documentation and meeting records
- Access credentials to systems you ask us to work on — held securely and returned or destroyed when the work ends
What we do not collect. We do not ask for or want your financial account passwords, card numbers, Aadhaar numbers or other government identifiers, and we do not knowingly collect sensitive personal data through this website. Please do not send such information to us by email.
3 · Why we use it
| Purpose | Data used | Basis |
|---|---|---|
| Replying to your enquiry | Name, contact details, message | Your consent, given by contacting us |
| Providing services you engaged us for | Contact, contractual and project data | Performance of our contract with you |
| Invoicing, accounting and tax | Billing details, transaction records | Legal obligation |
| Keeping this website secure and available | Technical and log data | Legitimate use — necessary to operate the service |
| Understanding how the site is used | Analytics data | Your consent only — off by default |
| Measuring whether a campaign reached you | Marketing cookie data | Your consent only — off by default |
We do not sell personal data. We do not share it with data brokers, we do not use it to build advertising profiles, and we do not use it to train artificial-intelligence models.
4 · Consent, and withdrawing it
Where we rely on your consent, that consent is free, specific, informed, unconditional and unambiguous, and given by a clear affirmative action. Nothing on this site is pre-ticked in our favour.
You can withdraw consent at any time, and it is exactly as easy as giving it.
- Cookies — use the Cookie preferences link, available in the footer of every page. Changes apply immediately.
- Marketing email — use the unsubscribe link in any message, or email us.
- Everything else — email us and we will action it.
Withdrawing consent does not make anything we did lawfully beforehand unlawful, and it does not affect data we must keep for a legal reason such as tax records.
5 · Who we share it with
We share personal data only where it is necessary, and only with organisations that are bound to protect it:
- Hosting and infrastructure providers that run this website and our systems
- Email and communication providers we use to correspond with you
- Analytics providers — only if you have allowed analytics cookies
- Professional advisers such as our accountants and lawyers, where genuinely required
- Government authorities, where the law obliges us to disclose
Each processor is engaged under a contract requiring them to process data only on our instructions and to protect it appropriately. We do not disclose our clients’ data to other clients, and where we operate multi-tenant systems, separation between customers is enforced technically and tested on every release.
6 · Where it is stored
We store personal data on infrastructure located in India wherever we control that choice. Some service providers may process limited data outside India; where they do, we satisfy ourselves that appropriate protections are in place and that the transfer is permitted under applicable Indian law, including any restrictions notified by the Central Government under the Digital Personal Data Protection Act, 2023.
7 · How long we keep it
| Category | Retention |
|---|---|
| Enquiries that do not become projects | 24 months from last contact, then deleted |
| Client records and correspondence | Duration of engagement, then 3 years |
| Invoices, tax and accounting records | 8 years, as required by Indian law |
| Website technical logs | 90 days |
| Analytics data (if allowed) | 14 months |
| Cookie preferences | 12 months, or until you change them |
When a retention period ends we delete the data or irreversibly anonymise it. You may ask us to erase your data sooner — see section 9.
8 · How we protect it
- Encryption in transit (HTTPS everywhere) and at rest on our systems
- Access limited to those who genuinely need it, protected by multi-factor authentication
- Row-level separation between customers on any multi-tenant system, verified on each release
- Append-only audit logging of access to sensitive records
- Regular backups, and tested restoration procedures
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person without delay, in the form and manner required by the Act and Rules, describing what happened, the likely consequences, and what we are doing about it. Our full security posture is described on our security page.
9 · Your rights
Under the Digital Personal Data Protection Act, 2023, as a Data Principal you have the right to:
| Right | What it means |
|---|---|
| Access | Obtain a summary of the personal data we hold about you, what we are doing with it, and who we have shared it with. |
| Correction | Have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated. |
| Erasure | Have your personal data deleted where we no longer need it for the purpose it was collected, unless the law requires us to keep it. |
| Grievance redressal | Have a readily available means of raising a complaint with us, and receive a response. |
| Nomination | Nominate another person to exercise these rights on your behalf in the event of your death or incapacity. |
How to exercise them. Email info@kaulinnovationandtechnologygroup.com with the subject line “Data request”, telling us which right you wish to exercise. We may need to verify your identity before acting. We will respond within 30 days. There is no charge.
You also have a duty under the Act not to make a false or frivolous request, and not to impersonate another person when making one.
10 · Children
This website and our services are intended for businesses and are not directed at children. We do not knowingly collect personal data of anyone under 18. Where we become aware that we hold a child’s personal data without verifiable consent from a parent or lawful guardian, we will delete it. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
11 · Contact and complaints
First, come to us. We would much rather fix a problem than have you escalate it.
| Grievance Officer | [Name of grievance officer — fill this in] |
| info@kaulinnovationandtechnologygroup.com | |
| Postal address | [Registered address — fill this in] |
| Response time | Acknowledged within 3 working days · resolved within 30 days |
If we do not resolve it. If you are not satisfied with our response, you may complain to the Data Protection Board of India established under the Digital Personal Data Protection Act, 2023, in the manner it prescribes.
12 · Changes to this notice
We update this notice when our practices change or the law requires it. The version number and date at the top always reflect the current version. Where a change materially affects how we use data you have already given us, we will tell you directly rather than relying on you noticing.