01. Data Fiduciary & Publisher Identity
This Privacy Policy applies to the digital properties and web applications operated by Codenosys ("we", "us", or "our"), an engineering and digital agency operating from Ajmer, Rajasthan, India, under the leadership of Founder and Lead Architect Aditya Lodha (Aditya Jain).
For the purposes of India's Digital Personal Data Protection Act, 2023 (DPDPA 2023) and the European Union's General Data Protection Regulation (GDPR), Codenosys acts as the Data Fiduciary (or Data Controller) regarding personal data collected directly through codenosys.in, associated discovery funnels, diagnostic audit tools, and service consultation channels.
02. Statutory Scope & Applicable Jurisdictions
Codenosys engineers high-performance web systems, custom SaaS applications, PWAs, and automated marketing architectures for clients domestically across India and globally across the United States, United Kingdom, European Union, Australia, and the Middle East. Accordingly, this policy adheres to:
- Indian Law: The Digital Personal Data Protection Act, 2023 (DPDPA 2023), Information Technology Act, 2000 (IT Act), and Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Consumer Protection (E-Commerce) Rules, 2020.
- European Union & United Kingdom: Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018 (UK GDPR).
- United States: California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA), and applicable state-level privacy statutes.
- ePrivacy Directive (Directive 2002/58/EC) & PECR: Mandating informed, prior consent for analytical cookies and local storage trackers.
03. Information Collection
We adhere to the statutory principle of data minimization, collecting only personal information strictly necessary to fulfill technical, commercial, and customer service requirements:
- Directly Provided Personal Data: Full Name, professional email address, telephone/WhatsApp number, company name, geographical location, and project specifications submitted via our "Initialize Protocol" multi-step onboarding funnel, "Request an Audit" diagnostic tool, career portal, or direct contact forms.
- Technical & Telemetry Data: Internet Protocol (IP) address, browser user-agent string, operating system, screen dimensions, referring URL, time spent per page, and navigation paths captured via analytical tools.
- Transaction & Invoicing Records: Formal project billing records, milestone approvals, and transaction IDs. Important: Codenosys does not store, capture, or process raw credit/debit card numbers or bank credentials on its servers. All payments are processed through PCI-DSS certified gateway partners (e.g., Stripe, Razorpay).
04. Lawful Basis for Processing
Under Article 6 of the GDPR and Section 6 of the DPDPA 2023, Codenosys processes your personal information only when backed by an authorized statutory lawful basis:
- Consent (Art. 6(1)(a) GDPR; Sec. 6 DPDPA): Where you have provided voluntary, specific, informed, and unambiguous consent, such as subscribing to the "Insider Circle" newsletter or authorizing analytics cookies via our System Protocol banner.
- Contractual Performance (Art. 6(1)(b) GDPR): Where processing is necessary to execute a Scope of Work (SOW), generate detailed architecture estimates, conduct technical onboarding, and deliver customized software solutions.
- Legitimate Interests (Art. 6(1)(f) GDPR): For maintaining infrastructure security, preventing distributed denial-of-service (DDoS) attacks, validating bot-check honeypots, and monitoring server health.
- Legal & Statutory Obligation (Art. 6(1)(c) GDPR): Complying with statutory accounting, Goods & Services Tax (GST) invoicing, and legal defense requirements.
05. Purpose of Data Processing
Your personal data is strictly processed for specified, lawful business functions:
- To architect, develop, test, and deploy customized software and growth solutions agreed in writing.
- To formulate comprehensive commercial project estimates and schedule architectural discovery calls.
- To transmit project milestones, sprint updates, security bulletins, and operational notifications.
- To audit website performance, server latency, and Core Web Vitals to maintain sub-second loading standards.
- To prevent fraudulent inquiries, spam submissions, and security vulnerabilities.
08. Cross-Border Data Transfers
Given the international scope of our clientele, data submitted to Codenosys may be processed on secure servers located in India, the European Union, and the United States. Whenever personal data originating from the European Economic Area (EEA) or UK is transferred to India or third countries, we enforce Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring equivalent statutory protection regardless of physical geography.
09. Security & Reasonable Security Practices (RSPP)
In adherence to Section 43A of the Information Technology Act, 2000 and SPDI Rules 2011, Codenosys maintains comprehensive technical and organizational safeguards:
- End-to-end 256-bit Transport Layer Security (TLS/SSL) encryption for all browser-server transmissions.
- Automated honeypot bot screening and rate limiting to prevent brute-force attacks and script injection.
- Role-based access control (RBAC), restricting client deliverables and project specifications to authorized developers.
- Zero plaintext storage of sensitive financial credentials or payment card numbers.
10. Data Retention Schedule
Personal data is retained only for the duration necessary to satisfy the statutory purpose for which it was gathered:
- General Inquiries & Discovery Submissions: Retained for twelve (12) months from the last communication, after which records are permanently expunged unless a commercial contract was executed.
- Active Project Deliverables & Code Repositories: Maintained for the duration of the engagement plus a standard thirty (30) day post-launch warranty window.
- Tax, Invoicing & Contract Records: Retained for seven (7) years in compliance with statutory Indian Goods and Services Tax (GST) regulations and corporate audit obligations.
11. Indian Data Principal Rights (DPDPA 2023)
If you are an Indian citizen or your data is processed within India, the Digital Personal Data Protection Act, 2023 provides you with enforceable statutory rights:
- Right to Access Information: Request a summary of personal data being processed, identity of fiduciaries, and processing categories.
- Right to Correction & Erasure: Request the correction of inaccurate or misleading data and the erasure of personal data no longer necessary for the specified purpose.
- Right of Grievance Redressal: The statutory right to register grievances with our designated Grievance Officer and receive formal resolution within thirty (30) days.
- Right to Nominate: The right to nominate an individual who, in the event of death or incapacity, shall exercise your rights as Data Principal.
12. EU & UK Data Subject Rights (GDPR)
Clients and website visitors residing within the European Economic Area (EEA) and United Kingdom hold comprehensive rights under Chapter III of the GDPR:
- Right of Access (Art. 15): Obtain confirmation as to whether personal data is processed, and obtain a copy thereof.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal records.
- Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of data where statutory retention grounds no longer apply.
- Right to Restriction of Processing (Art. 18): Restrict processing under contested circumstances.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing.
- Right to Lodge a Complaint: Lodge a complaint with your local EU Data Protection Supervisory Authority or the UK Information Commissioner's Office (ICO).
13. California Consumer Privacy Statement (CCPA / CPRA)
This section applies exclusively to California residents under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Notice at Collection: We collect identifiers (Name, Email, IP Address), commercial project requirements, and internet telemetry strictly for custom development and audit purposes.
- Explicit No-Sale & No-Share Declaration: Codenosys does not sell personal information, nor do we share personal information for cross-context behavioral advertising. We have not sold or shared any consumer personal data in the preceding twelve (12) months.
- Consumer Rights: You hold the Right to Know, Right to Delete, Right to Correct, and the Right to Non-Discrimination for exercising your CCPA statutory rights.
14. Minors & Children's Data
Our services and platforms are strictly directed to commercial businesses, founders, and enterprises. We do not knowingly solicit, collect, or process personal information from individuals under the age of eighteen (18) years. If you believe a minor has submitted personal data through our website, contact our Grievance Officer immediately for expedited erasure.
15. Designated Statutory Grievance Redressal Officer
In compliance with Section 13(1) of the Digital Personal Data Protection Act, 2023 and the Consumer Protection (E-Commerce) Rules, 2020, Codenosys has appointed a designated Grievance Officer to address data inquiries, privacy disputes, and statutory access requests:
Name: Aditya Lodha (Aditya Jain)
Designation: Data Protection & Grievance Redressal Officer
Operating Entity: Codenosys
Registered Postal Address: 38A Ganpati Nagar, BK Kaul Nagar, Ajmer, Rajasthan 305004, India
Dedicated Grievance Email: hello@codenosys.in (cc: contact@codenosys.in)
Official Telephone: +91 78789 88174
Statutory Resolution Timeline: Maximum thirty (30) days from formal electronic receipt of the grievance.
16. Contact Coordinates & Legal Inquiries
For general contract inquiries, technical privacy clarifications, or policy documentation copies, contact the Codenosys legal desk:
Primary Communication Desk: hello@codenosys.in
Official Agency Portal: https://codenosys.in
Postal Headquarters: 38A Ganpati Nagar, BK Kaul Nagar, Ajmer, Rajasthan 305004, India