Privacy Policy
Last updated: August 27, 2026
Effective Date: August 27, 2026
This Privacy Policy is published in compliance with and governed by the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) (“DPDP Rules”), and the Information Technology Act, 2000 along with applicable rules framed thereunder.
This policy describes how CREDDIO PLATFORMS (OPC) PRIVATE LIMITED (“Company”, “Creddio Tech”, “we”, “us”, or “our”), operating the website tech.creddio.in (the “Site”), acting in the capacity of a Data Fiduciary, collects, uses, stores, processes, protects, and discloses the digital personal data of visitors, clients, and users (“Data Principal”, “you”, or “your”).
1. Notice to Data Principals (Rule 3, DPDP Rules 2025)
In accordance with Section 6 of the DPDP Act and Rule 3 of the DPDP Rules, 2025, this Privacy Policy serves as an independent, clear, and comprehensive notice informing you of the categories of personal data collected, the specified purposes of processing, the means available to exercise your statutory rights, and the procedure to withdraw consent or submit grievances.
2. Itemised Description of Personal Data Collected
We only collect personal data that is necessary, adequate, and relevant for specified and lawful purposes.
A. Personal Data Provided Directly by You
- Identity & Contact Data: Full name, business or personal email address, phone/mobile number, and designation/company name provided when submitting inquiry forms, scheduling calls, or communicating with our team.
- Project & Requirement Data: Details of your software requirements, tech stack preferences, budget ranges, architectural needs, and RFP/brief documentation shared with us.
- Communication Records: Inquiries, feedback, emails, and correspondence exchanged between you and Creddio Tech.
B. Personal Data Collected Automatically
- Technical & Device Data: Internet Protocol (IP) address, operating system, browser type and version, device identifiers, time zone setting, and network connection parameters.
- Traffic & Access Logs: URLs accessed, page response times, interaction timestamps, referral sources, and navigational flow across the Site, collected for security, performance monitoring, and statutory audit purposes.
Note on Sensitive Personal Data: We do not collect, process, or store financial credentials, credit/debit card numbers, biometric identifiers, or government identity cards through this Site.
3. Specified Purposes of Processing Personal Data
Your digital personal data is processed strictly for the following specified, lawful purposes:
- Responding to Discovery & Project Inquiries: Evaluating client inquiries, discussing software architecture, preparing proposals, and communicating project feasibility.
- Service Delivery & Contractual Execution: Providing custom software development, lead generation platforms, web application development, UI/UX design, cloud hosting setup, and AI automation consulting.
- Platform Security & Fraud Prevention: Safeguarding our digital infrastructure against unauthorized access, cyber threats, automated abuse, spam, and denial-of-service attempts.
- Regulatory & Statutory Compliance: Complying with Indian laws, statutory audits, court orders, or lawful directions issued by the Data Protection Board of India (DPBI) or law enforcement authorities.
- Technical Log Retention: Maintaining mandatory security and processing logs for the duration prescribed under Rule 6(1)(e) and Rule 8(3) of the DPDP Rules, 2025.
4. Legal Grounds for Processing
We process personal data based on:
- Consent: Clear, affirmative, specific, and informed consent provided by you when submitting contact forms or initiating discovery discussions (Section 6, DPDP Act).
- Legitimate Uses: Processing necessary for fulfilling a specified purpose voluntarily provided by you (Section 7, DPDP Act), or for complying with any legal obligation or court order under Indian law.
5. Statutory Rights of the Data Principal (DPDP Act)
As a Data Principal under the DPDP Act, 2023 and DPDP Rules, 2025, you are entitled to exercise the following statutory rights:
1. Right to Access Information (Section 11)
You have the right to obtain from us a summary of personal data being processed, a description of processing activities, and the identities of all Data Processors or third parties with whom your personal data has been shared.
2. Right to Correction and Completion (Section 12)
You have the right to request correction of inaccurate or misleading personal data, completion of any incomplete personal data, and updating of your records.
3. Right to Erasure (Section 12 & Rule 8)
You have the right to request the erasure of your personal data when the specified purpose for which it was collected is no longer being served, or upon withdrawal of consent, subject to statutory retention requirements under Indian law.
4. Right of Grievance Redressal (Section 13 & Rule 14(3))
You have the right to readily available grievance redressal in respect of any act or omission by Creddio Tech regarding the performance of our obligations under the DPDP Act. We resolve all verified grievances within the statutory timeline (not exceeding 30 days).
5. Right to Nominate (Section 14 & Rule 14(4))
You have the right to nominate any individual who shall, in the event of your death or incapacity, exercise your rights as a Data Principal under the DPDP Act.
6. Withdrawal of Consent (Rule 3(c)(i), DPDP Rules 2025)
You may withdraw your consent at any time with the ease comparable to the manner in which consent was given. To withdraw consent:
- Send an email with the subject line
"Consent Withdrawal Request"to hello@tech.creddio.in. - Upon receiving verified consent withdrawal, we will cease processing your personal data within a reasonable timeframe, unless continued processing is required or authorized under applicable law.
7. Data Retention & Purpose Erasure (Rule 8 & Schedule VII)
- Active Inquiries & Client Records: We retain inquiry submissions and project communications only as long as necessary to address your request, conclude commercial agreements, or execute services.
- Statutory Log Retention: In compliance with Rule 6(1)(e) and Rule 8(3) of the DPDP Rules, 2025, technical traffic data, access logs, and security audit trails are retained for a minimum period of one (1) year from the date of processing to enable detection and investigation of unauthorized access, after which they are permanently deleted or irreversibly anonymized.
- Pre-Erasure Intimation (Rule 8(2)): Where personal data is slated for statutory erasure following the lapse of specified purpose, we ensure data is safely purged without unauthorized residual copies.
8. Reasonable Security Safeguards (Rule 6, DPDP Rules 2025)
In accordance with Rule 6 of the DPDP Rules, 2025, Creddio Tech has implemented robust techno-legal measures to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction:
- Encryption: Modern transport layer encryption (TLS 1.3 / HTTPS) for all data in transit, alongside encrypted cloud storage repositories.
- Access Controls: Strict role-based least-privilege access protocols and multi-factor authentication (MFA) restricting data access exclusively to authorized personnel.
- Continuous Monitoring: Real-time visibility through server access logs, anomaly detection, and periodic security evaluations.
- Resilience & Backups: High-availability data backups to prevent data loss or compromise.
- Data Processing Agreements (Rule 6(1)(f)): Enforceable contracts binding all third-party Data Processors (e.g., hosting and infrastructure providers) to observe equivalent security safeguards.
9. Personal Data Breach Intimation Protocol (Rule 7)
In the event of an identified personal data breach:
- Intimation to Affected Data Principals (Rule 7(1)): We will intimate affected Data Principals without delay, describing the nature and timing of the breach, likely consequences, mitigation steps taken, safety measures the user may adopt, and direct contact details of our response officer.
- Intimation to the Data Protection Board of India (Rule 7(2)): We will notify the Data Protection Board of India (DPBI) without delay, followed by a comprehensive incident report within seventy-two (72) hours in compliance with statutory requirements.
10. Protection of Children & Persons with Disabilities
- Age Restriction: Our Site and technology consulting services are intended strictly for adults (individuals who have attained the age of eighteen years) and business entities.
- No Tracking of Children: We do not knowingly process personal data belonging to children, nor do we engage in targeted advertising, profiling, or behavioral tracking of minors.
- If we become aware that personal data of a child has been submitted without verifiable parental consent under Rule 10, we will take immediate steps to delete such data from our records.
11. Cross-Border Transfer of Personal Data (Rule 15)
Personal data processed by Creddio Tech may be transferred, stored, or processed on secure cloud infrastructure located in India or outside India, strictly subject to the restrictions and compliance standards established under Section 16 of the DPDP Act and Rule 15 of the DPDP Rules, 2025. We do not transfer personal data to any country or territory restricted by the Central Government of India.
12. Sharing with Third-Party Data Processors
We do not sell, rent, or trade your personal data. We disclose personal data only to:
- Authorized Data Processors: Reliable cloud hosting providers (e.g., Vercel, Netlify), database infrastructure services (e.g., Supabase, PostgreSQL), and email routing platforms bound by strict confidentiality and data protection obligations.
- Legal & Law Enforcement Authorities: Only when mandated by applicable Indian laws, judicial orders, or formal directives issued by competent authorities under the DPDP Act.
13. Grievance Redressal & Contact Information
If you have any questions, wish to exercise your statutory rights as a Data Principal, or wish to submit a grievance regarding the processing of your personal data, please reach out to our designated Data Protection & Grievance Contact:
- Entity: CREDDIO PLATFORMS (OPC) PRIVATE LIMITED
- Attn: Data Protection & Grievance Redressal Officer
- Email: hello@tech.creddio.in
- Phone: +91 94468 60261
- Website: https://tech.creddio.in
- Location: India (Remote Worldwide)
Escalation to the Data Protection Board of India
If your grievance is not resolved to your satisfaction through our internal redressal mechanism within the statutory period, you have the right to file a complaint before the Data Protection Board of India (DPBI) in digital form pursuant to Section 27 of the DPDP Act and Rule 14(3) / Rule 20 of the DPDP Rules, 2025.
14. Updates to This Privacy Policy
We may periodically revise this Privacy Policy to reflect statutory updates, emerging regulatory guidance under the DPDP Rules, or improvements in our technological safeguards. The "Last updated" date at the top of this document indicates the most recent modification. Continued use of our Site following any posted update constitutes your acknowledgment of the revised terms.