How we collect, use, share and protect personal data on iparable.co.in
This Privacy Policy (“Policy”) explains how iParable, having its office at H-96, OFC-2, Second Floor, Sector 63, Noida, Uttar Pradesh 201301, collects, uses, shares, stores, protects and erases personal data when you visit iparable.co.in (the “Website”), contact us, request a quote, apply for a job, subscribe to our updates, or engage us for our services.
This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”) (together, the “DPDP Law”), and the Information Technology Act, 2000 and the rules made under it, to the extent applicable.
At a glance
| Question | Short answer |
|---|---|
| Who is responsible for your data? | iParable, as Data Fiduciary, for data collected through the Website and our own business |
| What do we collect? | What you give us in forms, emails and calls; basic technical data; cookies (non-essential only with consent) |
| Do we sell your data? | No. Never. |
| Do we send marketing? | Only with your separate consent, and you can unsubscribe at any time |
| What about our clients' data? | We process it only on the client's instructions, as their Data Processor (Section 3) |
| How do you reach us? | Our Grievance Officer at info@iparable.co.in (Section 19) |
1. Key terms
| Term | Meaning |
|---|---|
| Personal data | Any data about an individual who is identifiable by or in relation to that data |
| Data Principal / you | The individual to whom the personal data relates. For a child, this includes the parent or lawful guardian; for a person with a disability, the lawful guardian acting on their behalf |
| Data Fiduciary | The person who decides the purpose and means of processing personal data |
| Data Processor | A person who processes personal data on behalf of a Data Fiduciary |
| Processing | Any wholly or partly automated operation on personal data, including collection, storage, use, sharing and erasure |
| Personal data breach | Any unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises its confidentiality, integrity or availability |
| Board | The Data Protection Board of India established under the DPDP Act |
2. Scope of this policy
This Policy covers personal data of website visitors, enquirers, prospective and existing client contacts, job applicants, newsletter subscribers and vendors that iParable processes for its own purposes.
It does not cover personal data that our clients collect from their own customers and that we process on their behalf through websites, applications, hosting, email marketing, ERP or other services we provide. That data is governed by the client's privacy policy. Our role for such data is explained in Section 3.
It does not cover third-party websites linked from our Website, including client websites shown in our portfolio and case studies, or software portals operated by third parties (Section 17).
3. Our role: data fiduciary and data processor
| Situation | Our role | Who you should contact |
|---|---|---|
| You browse our Website, fill our forms, call or email us, apply for a job, or subscribe to updates | Data Fiduciary | iParable (Section 19) |
| We manage our own client relationships, contracts, invoices and vendor records | Data Fiduciary | iParable (Section 19) |
| We build, host, maintain or run a website, app, ERP, email campaign, DPDP compliance tool or digital marketing campaign for a client, and that system holds personal data of the client's users or customers | Data Processor for the client | The client organisation, which is the Data Fiduciary. We will help them respond |
When we act as Data Processor, we process personal data only on the client's documented instructions. We do not use it for our own purposes, keep it confidential and secure, and assist the client in meeting its obligations under the DPDP Law. If you contact us about data we hold for a client, we will forward your request to that client promptly.
4. Personal data we collect
We collect only the personal data that is necessary for the purposes described in Section 5.
| Source | Personal data | Required? |
|---|---|---|
| Contact Us, Get Started and Request a Quote forms | Name, email, phone number, company, city, service of interest and your message | Name, email or phone, and message are required; the rest is optional |
| Calls, WhatsApp, email and meetings | Name, contact details, designation, company and the content of your communication | As you choose to share |
| Client engagement | Names, designations, email and phone numbers of client contacts; billing contact details; GSTIN and billing address of the business | Required to deliver services and invoice |
| Job applications | Name, contact details, CV, education, work history, current and expected compensation, notice period and references | As requested in the job posting |
| Newsletter and updates | Name and email address | Only if you opt in |
| Blog (iparable.co.in) | Name, email and comment, if you comment on a post | Only if you comment |
| Automatic technical data | IP address, browser and device type, operating system, pages visited, referring page, date and time of visit, and approximate location derived from IP | Collected automatically; analytics only with consent (Section 7) |
Please do not send us sensitive data such as Aadhaar numbers, bank or card details, passwords, health information or personal data of other people through our forms or email unless we specifically ask for it for a stated purpose. If you share login credentials for your systems as part of a project, share them through a secure channel we agree with you, not in a contact form.
5. Why we use personal data and our legal basis
| Purpose | Personal data used | Legal basis under the DPDP Act |
|---|---|---|
| Responding to your enquiry, preparing quotes and proposals, and following up on that enquiry | Form and communication data | Data voluntarily provided for that specified purpose (Section 7(a)) |
| Delivering services, managing projects, invoicing and collecting payment under a contract | Client contact and billing data | Data voluntarily provided for that specified purpose (Section 7(a)) |
| Evaluating job applications and communicating with candidates | Application data | Data voluntarily provided for that specified purpose (Section 7(a)) |
| Sending newsletters, offers, event invitations and service updates not related to an active request | Name and email | Consent (Section 6), given separately; optional |
| Measuring and improving Website performance through analytics cookies | Technical data and cookie identifiers | Consent (Section 6), through the cookie banner |
| Securing the Website, preventing spam, fraud and misuse, and investigating incidents | Technical data and logs | Reasonable security safeguards (Section 8(5); Rule 6) |
| Managing our employees and contractors | Personnel records | Employment purposes (Section 7(i)) |
| Complying with tax, accounting and other laws, court orders and lawful requests of authorities | Data relevant to the requirement | Compliance with law, judgment or order (Section 7(c) to 7(e)) |
We do not sell personal data, do not rent it, and do not use it for any purpose incompatible with those above. If we need to use your data for a new purpose, we will tell you first and, where required, obtain your consent.
6. Who we share data with
Personal data is disclosed only where necessary for the purposes in Section 5, and only to:
Authorised iParable personnel who need it for their work and are bound by confidentiality obligations.
Service providers acting as our Data Processors, including website hosting and cloud storage, email and communication tools, CRM and project management tools, and analytics providers (Section 7). They process data only on our instructions under written contracts and may not use it for their own purposes. A current list is available from our Grievance Officer on request.
Professional advisers such as chartered accountants, auditors and lawyers, under a duty of confidentiality.
Government, regulatory, law-enforcement or judicial authorities, where disclosure is required by law, or permitted by law to protect the rights, property or safety of iParable, our clients or others.
A successor entity in a merger, acquisition or transfer of our business, which must protect the data in line with this Policy and the DPDP Law.
When you interact with our pages on LinkedIn, Facebook, Instagram or X, those platforms process your data under their own privacy policies.
7. Cookies, analytics and embedded content
| Type | Purpose | Consent |
|---|---|---|
| Strictly necessary | Site security, form submission, spam protection and remembering your cookie choice | Not required; always on |
| Analytics | Google Analytics via Google Tag Manager, to count visits and understand which pages are useful. Google processes this data under its own terms | Only with your consent |
| Marketing | Advertising and remarketing pixels, if we use them for our own campaigns | Only with your consent |
| Embedded content | Google Maps and embedded videos may set cookies and receive your IP address when loaded | Loaded only after consent, or on click |
You can accept, reject or change your choices at any time through the Cookie Settings link in the Website footer, or by clearing cookies in your browser. Rejecting non-essential cookies does not affect your use of the Website.
8. Consent and its withdrawal
Where we rely on consent, we show a clear notice that lists the personal data and the specific purpose, and ask for an affirmative action. Consent for marketing is never bundled with an enquiry or quote request.
You may withdraw consent at any time, as easily as you gave it: through the unsubscribe link in any email, Cookie Settings for cookies, or by writing to our Grievance Officer. We will stop the processing concerned within a reasonable time and instruct our Data Processors to do the same, unless another legal basis applies.
Withdrawal does not affect processing carried out before it.
Where Consent Managers registered with the Board become available, you may also give, manage, review and withdraw consent through such a Consent Manager.
9. Where your data is stored
Personal data is stored on servers and cloud services located at various places. Some of our service providers, such as hosting, email, analytics and productivity tools, may process data outside India.
10. How we protect your data
We maintain reasonable security safeguards appropriate to the nature of the data, in line with Section 8(5) of the DPDP Act and Rule 6 of the DPDP Rules, including:
encryption of data in transit using HTTPS (TLS), and encryption of stored data and backups where supported;
role-based, need-to-know access, unique user accounts and two-factor authentication for administrative systems;
logging and monitoring of access to personal data so that unauthorised access can be detected, investigated and remedied;
confidentiality obligations for all personnel and contractual security obligations for our Data Processors; and
an information security management system aligned with ISO 27001
No internet-based system is completely secure. If you believe your interaction with us is no longer secure, please contact us immediately.
11. Personal data breaches
If a personal data breach affects data for which we are Data Fiduciary, we will inform affected individuals without delay, in plain language, of the nature and extent of the breach, when it occurred, its likely consequences, the measures taken and being taken, the steps you can take to protect yourself, and whom to contact.
We will inform the Data Protection Board without delay and submit a detailed report within 72 hours of becoming aware of the breach, or within any longer period the Board allows, as required by Rule 7 of the DPDP Rules.
If a breach affects data we process for a client, we will notify that client promptly, and in any event within the time agreed in our contract with them, so that the client can meet its own obligations.
12. How long we keep your data
| Category | Retention period |
|---|---|
| Enquiries and quote requests that do not lead to an engagement | Up to 24 months from your last interaction, then erased |
| Client contact, contract and project records | For the engagement and up to 3 years after it ends, for support, warranty and disputes |
| Invoices, payment and tax records | 5 years from the end of the financial year, as required by tax and company law |
| Job applications not selected | Up to 3 months, to consider you for future roles, unless you ask us to delete them earlier |
| Newsletter subscriptions | Until you unsubscribe or withdraw consent |
| Analytics data | As configured in the analytics tool |
| Security and access logs | At least 1 year, as required by Rule 6, and longer only to investigate an incident or meet a legal requirement |
| Grievance and rights request records | Up to 1 year after closure, to evidence how the matter was handled |
When data is no longer needed, we erase it or anonymise it so that it no longer identifies you, and we instruct our Data Processors to do the same.
13. Client data in our hosting and managed services
Where a client uses our hosting, email, ERP or other managed services, the following applies to the client's data held on our systems, subject to the client's contract with us:
The client owns its data. We will not access it except to provide, support or secure the service, or as the client instructs.
During an active subscription, the client can download a full backup of its data, for example through the control panel provided, or request one from us.
We send renewal reminders before a subscription expires. After expiry, we retain the client's data for 30 days so that the client can renew or request a backup.
A backup requested after expiry is provided on the terms set out in the client's contract or on terms agreed between both parties, including any applicable recovery charge.
At the end of the retention period, the data is securely and permanently deleted, including from backups at the end of their backup cycle, unless the client has asked us in writing to preserve it with applicable charges or the law requires us to retain it.
14. Your rights
Subject to the DPDP Law, you have the right to:
Access information (Section 11): a summary of your personal data and the processing activities undertaken with it, and the identities of all other Data Fiduciaries and Data Processors with whom it has been shared, with a description of the data shared;
Correction, completion, updating and erasure (Section 12): have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased when it is no longer necessary for its purpose, unless retention is required by law;
Withdraw consent (Section 6): as described in Section 8;
Grievance redressal (Section 13): have your grievance addressed by our Grievance Officer; and
Nomination (Section 14): nominate another individual to exercise your rights in the event of your death or incapacity.
How to make a request
Email our Grievance Officer (Section 19) from the email address or phone number you used with us, stating your name and the right you wish to exercise.
We may ask for reasonable information to verify your identity before acting, and will not ask for more than is needed.
We will acknowledge your request within 7 days and aim to resolve it within 30 days. In every case we will respond within the period prescribed under the DPDP Law, which for grievances does not exceed 90 days.
If we cannot fully act on a request, for example because tax law requires us to keep an invoice, we will explain why.
15. Your duties
Under Section 15 of the DPDP Act, you must not impersonate another person, suppress material information, provide false particulars, or file a false or frivolous grievance or complaint, and you must provide only verifiably authentic information when seeking correction or erasure. Please share personal data of other people, such as colleagues, only where you are authorised to do so.
16. Children and persons with disabilities
Our Website and services are meant for businesses and adults. We do not knowingly collect personal data of anyone under 18 years of age. If we learn that we have collected such data, we will delete it promptly. Where we build a website or app for a client that is directed at children, the client as Data Fiduciary is responsible for obtaining verifiable parental consent under Section 9 of the DPDP Act, and we will build the functionality the client instructs.
Where an individual is a person with a disability who has a lawful guardian, the guardian may exercise rights on that individual's behalf after reasonable verification of guardianship.
17. Third-party links and portals
Our Website links to third-party websites, including client websites shown in our portfolio and case studies, our social media pages, and software portals hosted on other domains. We are not responsible for the privacy practices of those websites, which are governed by their own policies. Please read their privacy policies before sharing personal data with them.
18. Changes to this policy and language
We may update this Policy to reflect changes in our services, practices or the law. The updated Policy will be posted on this page with a new “Last updated” date and version number.
For material changes, we will notify subscribers and active clients by email before the change takes effect, and seek fresh consent where the law requires it.
This Policy is available in English. On request to our Grievance Officer, we will provide it in Hindi or any other language specified in the Eighth Schedule to the Constitution of India.
19. Grievance officer and contact
For questions about this Policy, to exercise your rights, to withdraw consent, or to raise a grievance about the processing of your personal data, please contact:
| Privacy and grievance enquiries | iParable |
| Organisation | iParable |
| Address | H-96, OFC-2, Second Floor, Sector 63, Noida, Uttar Pradesh 201301 |
| info@iparable.co.in | |
| Phone | +91-9792-996-611 |
Please raise your grievance with our Grievance Officer first. If you are not satisfied with our response, or do not receive one within the prescribed period, you may file a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Law.
20. Governing law
This Policy is governed by the laws of India. Subject to the powers of the Data Protection Board of India and the Appellate Tribunal under the DPDP Act, the courts at Noida / Gautam Buddh Nagar shall have exclusive jurisdiction over any dispute arising out of this Policy. Where this Policy conflicts with a mandatory requirement of law, the law prevails.
© 2010–2026 iParable. All rights reserved.