Contensu (“we”, “us”, “our”) is a custom software development agency established in India. We build CRM systems, business websites, internal tools, learning platforms, and custom web applications for clients worldwide.

For the personal data described in this notice we are the Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the data controller under the EU and UK General Data Protection Regulation (“GDPR”). That means we decide what is collected and why, and we are accountable for it.

The same address serves as our published contact for data-protection questions and grievances under section 8(9) of the DPDP Act. We are not a Significant Data Fiduciary and are not required to appoint a Data Protection Officer under GDPR Article 37; the contact above is a real person who can answer questions about how we handle your data.

We are established outside the EEA and our processing of EEA and UK data is occasional, limited to business contact details, involves no special-category data and is unlikely to result in a risk to anyone’s rights. On that basis we rely on the exemption in GDPR Article 27(2) and have not appointed an EU or UK representative. If our processing ever goes beyond that, we will appoint one and name them here.

We wrote one notice that satisfies the strictest requirements that apply to us, rather than a different policy per region. Whichever of these applies to you, the whole notice applies to you.

An itemised list of everything we collect, where it comes from, and why we need that specific item:

Giving us any of this is entirely voluntary. There is no statutory or contractual obligation to provide it. The only consequence of not providing it is that we cannot reply to you.

We do not repurpose your data. If we ever want to use it for something not listed above, we will ask you first.

We keep the list of third parties as short as we can. Each one below acts as our processor under a written data processing agreement, may only use the data to provide its service to us, and may not use it for its own purposes.

Beyond that list: we may disclose data to our accountants or legal advisers where we have to, and to a public authority where a valid, binding legal request compels us. We will tell you if that happens unless we are prohibited from doing so.

We do not sell personal data, do not rent or trade it, do not share it with data brokers, advertising networks or social platforms, and do not use it to train machine-learning models.

We are based in India, so if you write to us from the EEA or the UK your data is transferred to India, and to the processors listed above in the EU and the United States. India, like the United States, has no adequacy decision from the European Commission covering our activity.

Where a transfer of EEA or UK data is involved we rely on the European Commission’s Standard Contractual Clauses under GDPR Article 46(2)(c) — and, for UK data, the UK International Data Transfer Addendum — which form part of our agreements with each processor, or on the EU–US Data Privacy Framework where the recipient is certified under it. We supplement them with practical measures: encryption in transit, no unnecessary copies, data minimisation, and access limited to the people who actually need it.

Under section 16 of the DPDP Act, transfers out of India are permitted except to countries the Central Government restricts by notification. None of the transfers described here involve a restricted country. If that changes, we will change our arrangements rather than continue the transfer.

You can ask us for a copy of the relevant transfer safeguards by emailing contact@contensu.com.

When a retention period ends we erase the data rather than archive it. There is no CRM, no leads database and no spreadsheet copy — an enquiry exists only as an email in our mailbox. Erasure therefore means the message and any attachments are deleted, including from Trash, so nothing lingers in a backup of a system we do not run.

As a Data Principal under the DPDP Act you have the right to:

If we do not resolve your grievance, you may complain to the Data Protection Board of India through its online mechanism. Complaints are subject to the time limits set out in the Act and Rules, so do not sit on one.

The Act also places duties on Data Principals (section 15): please do not impersonate anyone, suppress material information, or file a frivolous or false complaint — penalties can apply to you as well as to us.

Under the GDPR and UK GDPR you have the right to:

You also have the right to lodge a complaint with a supervisory authority — normally the one in the EEA country where you live or work. In the UK that is the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner. You do not have to come to us first, though we would rather you did — it is usually faster.

Email contact@contensu.com with “Data rights request” in the subject line. Tell us what you want and, if you can, which email address you used to contact us — it helps us find the right records.

This is a business-to-business site and is not directed at children. We do not knowingly collect data from anyone under 18 (the threshold under the DPDP Act) or under 16 (the threshold used in several EEA states), and we have no way to process a child’s data with verifiable parental consent as section 9 of the DPDP Act would require.

We never track children, never serve them behavioural advertising — we serve nobody behavioural advertising — and we do nothing that could be detrimental to a child’s wellbeing. If we learn that someone under those ages has sent us personal data, we erase it. If you believe that has happened, email contact@contensu.com and we will deal with it promptly.

Section 8(5) of the DPDP Act and Article 32 of the GDPR both require reasonable security safeguards. In our case those are:

No system is perfectly secure, and we will not pretend otherwise. What we can say is that we hold as little as possible, for as short a time as possible.

If personal data we hold is breached, we will act on it rather than sit on it. Under section 8(6) of the DPDP Act and the DPDP Rules, 2025 we will inform every affected Data Principal without delay, describing the nature of the breach, its likely consequences, what we have done about it and what you can do to protect yourself, and we will file a detailed report with the Data Protection Board of India within 72 hours of becoming aware.

Where the GDPR applies, we will notify the competent supervisory authority within 72 hours under Article 33 and tell affected individuals directly under Article 34 where the breach is likely to result in a high risk to their rights and freedoms.

We make no decisions about you by automated means, and we do not profile you. A human reads every enquiry and decides whether we can help. There is no scoring, no segmentation, no lead-enrichment service looking you up, no cross-site tracking, and no advertising audience built from your data.

We also do not feed your enquiries or project data into machine-learning training. If we use an AI tool as part of delivering a project, we agree that with the client in the contract first.

This notice covers data you give us. When we build or maintain a system for a client and that involves personal data of the client’s own customers, employees or users, the client is the Data Fiduciary or controller and we act as their processor.

In that role we act only on the client’s documented instructions, sign a data processing agreement — including the Standard Contractual Clauses or the UK Addendum where the client needs them — disclose and get approval for any sub-processor, keep the data confidential, help with data subject requests and breach notifications, and return or delete the data when the engagement ends. The commercial side of this sits in our Terms of Service, and we are happy to sign a client’s own DPA instead of ours.

If you are an individual whose data a client of ours holds, please contact that client — they control it, and we cannot lawfully act on their data without their instruction. Tell us anyway if you cannot reach them and we will pass it on.

We update this notice when what we do changes — not to quietly widen what we are allowed to do. The version and date at the top always reflect the current text. If a change materially affects how we use data you have already given us, we will contact you about it directly rather than rely on you re-reading this page.

This version replaces the version dated 1 April 2025. It adds the DPDP Act notice, the legal-basis and retention tables, the processor list, and corrects an earlier statement that no data was collected automatically — technical data is, and always was, processed at our infrastructure layer to serve and secure the site. Ask us for a copy of a previous version at any time.

Anything at all about this notice, or about data we hold — email contact@contensu.com. A person answers.