Privacy Policy
Last updated: 30 July 2026 · Version 2.0
The short version
- We collect personal data in exactly two places: the contact form and the booking calendar. Both are voluntary, and both only happen because you chose to get in touch.
- No analytics, no advertising pixels, no tracking cookies, no profiling, no data-broker sharing. We have never sold personal data and will not.
- Fonts are served from our own servers, so no third party sees your IP address just because you opened a page.
- You can ask us to show, correct, or delete what we hold at any time by emailing contact@contensu.com. It is free, and we answer within 30 days.
On this page
- Who we are
- Which laws apply
- What we collect
- Why, and on what legal basis
- Consent and withdrawal
- Who else processes it
- International transfers
- Retention and erasure
- Your rights (India)
- Your rights (EEA / UK)
- How to exercise them
- Children’s data
- How we protect it
- Data breaches
- No profiling or ad tracking
- Data we handle for clients
- Changes to this notice
- Questions
1. Who we are
Contensu (“we”, “us”, “our”) is a custom software development agency established in India. We build CRM systems, business websites, internal tools, learning platforms, and custom web applications for clients worldwide.
For the personal data described in this notice we are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the data controller under the EU and UK General Data Protection Regulation (“GDPR”). That means we decide what is collected and why, and we are accountable for it.
Contacting us about your data
- Email — contact@contensu.com (put “Data rights request” or “Privacy” in the subject line and it reaches the right person)
- Postal address — we are a small remote team and do not publish a street address. We will provide it in writing on request, including to a supervisory authority or the Data Protection Board of India.
The same address serves as our published contact for data-protection questions and grievances under section 8(9) of the DPDP Act. We are not a Significant Data Fiduciary and are not required to appoint a Data Protection Officer under GDPR Article 37; the contact above is a real person who can answer questions about how we handle your data.
We are established outside the EEA and our processing of EEA and UK data is occasional, limited to business contact details, involves no special-category data and is unlikely to result in a risk to anyone’s rights. On that basis we rely on the exemption in GDPR Article 27(2) and have not appointed an EU or UK representative. If our processing ever goes beyond that, we will appoint one and name them here.
2. Which laws this notice covers
We wrote one notice that satisfies the strictest requirements that apply to us, rather than a different policy per region. Whichever of these applies to you, the whole notice applies to you.
- India — the DPDP Act, 2023 and the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025, with the substantive obligations phasing in by 13 May 2027). We already operate to these requirements. Sections 3 to 5, 9 and 10 below are the itemised notice required by section 5 of the Act and Rule 3 of the Rules.
- EEA — the GDPR (Regulation 2016/679), which applies to us under Article 3(2) because we offer services to businesses in the EEA.
- United Kingdom — the UK GDPR and the Data Protection Act 2018.
- ePrivacy / cookie rules — see our Cookie Policy. We set no cookies that require consent, which is why you see no cookie banner.
- Elsewhere — Switzerland (revised FADP), and US state privacy laws such as the CCPA/CPRA. We do not sell or share personal data for cross-context behavioural advertising, and we honour access and deletion requests from anyone, wherever they live.
3. What personal data we collect
An itemised list of everything we collect, where it comes from, and why we need that specific item:
| Data | Source | Why that item |
|---|---|---|
| Name | Contact form (required) | To address you properly in our reply |
| Email address | Contact form (required) | The only way we can answer you |
| Project details / message | Contact form (required) | To understand the requirement and judge whether we can help |
| Company or organisation | Contact form (optional) | Business context; helps us prepare a relevant response |
| Country | Contact form (optional) | Time zone for scheduling, and how invoicing and tax are handled if we work together |
| Service interest, budget range, timeline | Contact form (optional) | To scope a realistic proposal instead of guessing |
| How you heard about us | Contact form (optional) | Tells us which channels are worth our effort. Never used to profile you |
| Consent record — the exact consent wording, the language it was shown in, its version, and the date and time | Generated when you submit the form | Proof that consent was given and what you were told, as the DPDP Act and GDPR Article 7(1) require |
| Booking details — name, email, time zone, chosen slot and any answers you type | The calendar on the booking page, only after you click to load it | To hold the call. Processed in Cal.com’s EU instance |
| Anything in your emails to us | You, by writing to us | To carry on the conversation |
| Technical data — IP address, user agent, and request metadata, plus a Turnstile verification token | Automatically, at our infrastructure layer (Cloudflare), on every request | Delivering the page over TLS, blocking bots and spam, and rate-limiting the contact form to five submissions a minute per IP address |
What we deliberately do not collect
- No analytics or statistics tool of any kind, first-party or third-party.
- No advertising pixels, conversion tags, remarketing lists or ad IDs.
- No tracking cookies and no fingerprinting.
- No special-category or sensitive data (health, biometrics, political or religious views, and so on). Please do not send us any.
- No third-party fonts, scripts or embeds that load before you ask for them — the only exception is Cloudflare Turnstile on the contact form, which is there to keep spam out.
Giving us any of this is entirely voluntary. There is no statutory or contractual obligation to provide it. The only consequence of not providing it is that we cannot reply to you.
4. Why we process it, and our legal basis
| Purpose | Basis under the GDPR / UK GDPR | Basis under the DPDP Act |
|---|---|---|
| Reading your enquiry, replying, and preparing a proposal | Article 6(1)(b) — steps at your request prior to a contract; and Article 6(1)(f) — our legitimate interest in answering a business enquiry you initiated | Your consent under section 6, given by ticking the box on the form |
| Scheduling and holding a discovery call | Article 6(1)(b) — pre-contractual steps at your request | Your consent, given by loading the calendar and booking a slot |
| Keeping the site available and free of spam and abuse — TLS, bot filtering, rate limiting, security logs | Article 6(1)(f) — legitimate interest in the security and integrity of our own service, which is also recognised in Recital 49 | Section 7 — legitimate uses, including preventing fraud and abuse, together with the security safeguards required by section 8(5) |
| Delivering a project we have agreed, and supporting it afterwards | Article 6(1)(b) — performance of our contract with you | Section 7 — performance of the service you asked for |
| Invoices, tax and accounting records | Article 6(1)(c) — compliance with a legal obligation | Section 7 — compliance with Indian law |
| Naming or showing your project in our portfolio or a case study | Article 6(1)(a) — your consent, asked for separately and in writing | Your separate consent under section 6 |
| Staying in touch about our work, if you ask us to | Article 6(1)(a) — your consent, which you can withdraw at any time | Your consent under section 6 |
We do not repurpose your data. If we ever want to use it for something not listed above, we will ask you first.
5. Consent, and how to withdraw it
When you submit the contact form you tick a box confirming you have read this notice and consent to us using those details to reply. That box is never pre-ticked, is not bundled with anything else, and the form will not submit without it. We store the exact sentence you agreed to, the language it was shown in, its version, and the timestamp alongside your enquiry so that both of us have a record of what was agreed.
Withdrawing is as easy as giving it. Email contact@contensu.com with “Withdraw consent” in the subject line — one sentence is enough, and you do not need to give a reason. We stop processing on receipt and erase your data unless we are legally required to keep a specific record, such as an invoice. Withdrawal does not undo processing that already, lawfully, happened.
Withdrawing consent may mean we can no longer help you — for instance, we cannot answer an enquiry after we have deleted it. That is the only consequence.
6. Who else processes your data
We keep the list of third parties as short as we can. Each one below acts as our processor under a written data processing agreement, may only use the data to provide its service to us, and may not use it for its own purposes.
| Processor | What it does for us | Where |
|---|---|---|
| Cloudflare, Inc. | Website hosting, TLS, bot filtering (Turnstile) and rate limiting | United States / global edge network |
| Resend (Plus Five Five, Inc.) | Delivers the contact-form email to our inbox | United States |
| Cal.com, Inc. — EU instance (cal.eu) | Booking calendar, loaded only after you click to load it | European Union |
| Google (Gmail) | Hosts the contact@contensu.com mailbox — the only place enquiries are stored. We run no database of enquiries | United States / global Google data centres |
Beyond that list: we may disclose data to our accountants or legal advisers where we have to, and to a public authority where a valid, binding legal request compels us. We will tell you if that happens unless we are prohibited from doing so.
We do not sell personal data, do not rent or trade it, do not share it with data brokers, advertising networks or social platforms, and do not use it to train machine-learning models.
7. International transfers
We are based in India, so if you write to us from the EEA or the UK your data is transferred to India, and to the processors listed above in the EU and the United States. India, like the United States, has no adequacy decision from the European Commission covering our activity.
Where a transfer of EEA or UK data is involved we rely on the European Commission’s Standard Contractual Clauses under GDPR Article 46(2)(c) — and, for UK data, the UK International Data Transfer Addendum — which form part of our agreements with each processor, or on the EU–US Data Privacy Framework where the recipient is certified under it. We supplement them with practical measures: encryption in transit, no unnecessary copies, data minimisation, and access limited to the people who actually need it.
Under section 16 of the DPDP Act, transfers out of India are permitted except to countries the Central Government restricts by notification. None of the transfers described here involve a restricted country. If that changes, we will change our arrangements rather than continue the transfer.
You can ask us for a copy of the relevant transfer safeguards by emailing contact@contensu.com.
8. How long we keep it, and when we erase it
| What | How long |
|---|---|
| Enquiry that does not lead to a project | Erased within 6 months of our last exchange |
| Enquiry that becomes a project | For the engagement and up to 24 months after it ends, so we can support what we built and handle any warranty claim |
| Consent record | As long as we hold the data it relates to, plus a short period afterwards as evidence that processing was lawful |
| Invoices, contracts and tax records | For the period Indian tax and accounting law requires, which is longer than the periods above and overrides a deletion request for those specific documents |
| Security and processing logs | Retained at our infrastructure layer for at least one year, as the DPDP Rules, 2025 require for detecting and investigating incidents, then discarded |
| Anything, after you withdraw consent or ask for erasure | Erased without undue delay, except records we are legally obliged to keep |
When a retention period ends we erase the data rather than archive it. There is no CRM, no leads database and no spreadsheet copy — an enquiry exists only as an email in our mailbox. Erasure therefore means the message and any attachments are deleted, including from Trash, so nothing lingers in a backup of a system we do not run.
9. Your rights if you are in India
As a Data Principal under the DPDP Act you have the right to:
- Access a summary (section 11) — what personal data of yours we process, what we do with it, and which other Data Fiduciaries or processors we have shared it with, along with what they hold.
- Correction, completion, updating and erasure (section 12) — have inaccurate data corrected, incomplete data completed, and data erased where we no longer need it for the purpose you gave it for.
- Grievance redressal (section 13) — complain to us directly about anything in this notice. We aim to resolve grievances within 30 days and in no case later than 90 days, the outer limit set by the DPDP Rules, 2025. Using our grievance route first is a step you take before approaching the Board.
- Nominate someone (section 14) — nominate a person to exercise these rights on your behalf if you die or become incapacitated. Email us the nominee’s name and contact details and we will record it.
- Withdraw consent (section 6) — at any time, as easily as you gave it. See section 5 above.
If we do not resolve your grievance, you may complain to the Data Protection Board of India through its online mechanism. Complaints are subject to the time limits set out in the Act and Rules, so do not sit on one.
The Act also places duties on Data Principals (section 15): please do not impersonate anyone, suppress material information, or file a frivolous or false complaint — penalties can apply to you as well as to us.
10. Your rights if you are in the EEA, the UK or Switzerland
Under the GDPR and UK GDPR you have the right to:
- Access (Article 15) — a copy of the personal data we hold about you, and the information in this notice as it applies to you specifically.
- Rectification (Article 16) — have inaccurate data corrected or incomplete data completed.
- Erasure (Article 17) — the “right to be forgotten”, where we no longer have a lawful reason to keep the data.
- Restriction (Article 18) — have us pause processing while a dispute about accuracy or lawfulness is sorted out.
- Data portability (Article 20) — receive the data you gave us in a structured, commonly used, machine-readable format, or have us send it to someone else.
- Object (Article 21) — object to processing we base on legitimate interest. If you object, we stop unless we can show compelling grounds that override your rights.
- Withdraw consent (Article 7(3)) — at any time, without affecting the lawfulness of what happened before.
- Not be subject to automated decision-making (Article 22) — which is straightforward here, because we do not do any. See section 15.
You also have the right to lodge a complaint with a supervisory authority — normally the one in the EEA country where you live or work. In the UK that is the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner. You do not have to come to us first, though we would rather you did — it is usually faster.
11. How to exercise any of these rights
Email contact@contensu.com with “Data rights request” in the subject line. Tell us what you want and, if you can, which email address you used to contact us — it helps us find the right records.
- Cost — free. We will only charge for a request that is manifestly excessive or repetitive, and we will tell you before we do.
- Timing — we respond within 30 days. Under the GDPR we may extend by up to two further months for a complex request, and we will explain why within the first month. Grievances under the DPDP Act are resolved within 90 days at the very latest.
- Verification — if we genuinely cannot tell that a request comes from you, we will ask for enough information to confirm it. We will not demand ID documents where the reply address is already the one you contacted us from.
- Refusals — if we cannot do what you asked, we will say so, explain the legal reason, and tell you how to challenge it.
12. Children’s data
This is a business-to-business site and is not directed at children. We do not knowingly collect data from anyone under 18 (the threshold under the DPDP Act) or under 16 (the threshold used in several EEA states), and we have no way to process a child’s data with verifiable parental consent as section 9 of the DPDP Act would require.
We never track children, never serve them behavioural advertising — we serve nobody behavioural advertising — and we do nothing that could be detrimental to a child’s wellbeing. If we learn that someone under those ages has sent us personal data, we erase it. If you believe that has happened, email contact@contensu.com and we will deal with it promptly.
13. How we protect your data
Section 8(5) of the DPDP Act and Article 32 of the GDPR both require reasonable security safeguards. In our case those are:
- Encryption in transit — the whole site is HTTPS-only. Plain HTTP requests are redirected, and we send HTTP Strict Transport Security so browsers refuse to downgrade.
- Collect less, store less — there is no leads database and no customer portal to breach. Contact-form submissions are delivered to our mailbox and live only there.
- Hardened browser policy — a strict Content Security Policy, no third-party scripts beyond the anti-spam widget, framing of our pages blocked, and camera, microphone and payment APIs switched off.
- Abuse controls — Cloudflare Turnstile on the form and a server-side rate limit of five submissions a minute per IP address. Submissions are validated and escaped on the server before they reach anyone’s inbox.
- No third-party tracking surface — self-hosted fonts, no analytics, and third-party embeds that stay dormant until you click to load them.
- Access control — only the people who need to read enquiries can, using strong unique credentials on accounts protected by multi-factor authentication where the provider supports it.
- Vulnerability reports — see security.txt. We would rather hear about a problem than not.
No system is perfectly secure, and we will not pretend otherwise. What we can say is that we hold as little as possible, for as short a time as possible.
14. If there is a data breach
If personal data we hold is breached, we will act on it rather than sit on it. Under section 8(6) of the DPDP Act and the DPDP Rules, 2025 we will inform every affected Data Principal without delay, describing the nature of the breach, its likely consequences, what we have done about it and what you can do to protect yourself, and we will file a detailed report with the Data Protection Board of India within 72 hours of becoming aware.
Where the GDPR applies, we will notify the competent supervisory authority within 72 hours under Article 33 and tell affected individuals directly under Article 34 where the breach is likely to result in a high risk to their rights and freedoms.
15. No automated decisions, no profiling, no ad tracking
We make no decisions about you by automated means, and we do not profile you. A human reads every enquiry and decides whether we can help. There is no scoring, no segmentation, no lead-enrichment service looking you up, no cross-site tracking, and no advertising audience built from your data.
We also do not feed your enquiries or project data into machine-learning training. If we use an AI tool as part of delivering a project, we agree that with the client in the contract first.
16. Data we handle on behalf of clients
This notice covers data you give us. When we build or maintain a system for a client and that involves personal data of the client’s own customers, employees or users, the client is the Data Fiduciary or controller and we act as their processor.
In that role we act only on the client’s documented instructions, sign a data processing agreement — including the Standard Contractual Clauses or the UK Addendum where the client needs them — disclose and get approval for any sub-processor, keep the data confidential, help with data subject requests and breach notifications, and return or delete the data when the engagement ends. The commercial side of this sits in our Terms of Service, and we are happy to sign a client’s own DPA instead of ours.
If you are an individual whose data a client of ours holds, please contact that client — they control it, and we cannot lawfully act on their data without their instruction. Tell us anyway if you cannot reach them and we will pass it on.
17. Changes to this notice
We update this notice when what we do changes — not to quietly widen what we are allowed to do. The version and date at the top always reflect the current text. If a change materially affects how we use data you have already given us, we will contact you about it directly rather than rely on you re-reading this page.
This version replaces the version dated 1 April 2025. It adds the DPDP Act notice, the legal-basis and retention tables, the processor list, and corrects an earlier statement that no data was collected automatically — technical data is, and always was, processed at our infrastructure layer to serve and secure the site. Ask us for a copy of a previous version at any time.
Questions
Anything at all about this notice, or about data we hold — email contact@contensu.com. A person answers.