PRIVACY NOTICE
This Privacy Policy ("Policy") describes how Capital Numbers Infotech Limited, a company incorporated under the laws of India and doing business as “Capital Numbers” ("Capital Numbers," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal information when you interact with us.
This Policy applies to personal information processed through our website at https://www.capitalnumbers.com and any other website, landing page, or digital property of ours that links to this Policy (collectively, the "Website"), as well as personal information we process in connection with our software development, digital engineering, and related professional services (the "Services"). It applies to:
- Website visitors who browse or interact with the Website;
- Prospects and business contacts who submit inquiries, request quotes, download resources, or book a consultation;
- Clients and client personnel in connection with the delivery of our Services;
- Job applicants who apply through our careers pages or recruitment channels; and
- Event and marketing contacts who engage with us at webinars, conferences, trade shows, or through marketing campaigns.
This Policy does not apply to personal information we process on behalf of our clients as a service provider/processor under a separate master services agreement or data processing agreement; that processing is governed by those agreements. It also does not apply to third-party websites, applications, or services that we do not control (see Third-Party Links).
Summary of Key Points
This summary is provided for convenience. Please read the full Policy for complete details.
| Topic | Key Point |
|---|---|
| What we collect | Contact and professional details you give us (forms, consultation bookings, applications, newsletters); device, usage, and log data collected automatically; and limited information from third parties such as publicly available sources, referrals, and analytics providers. See Section 1. |
| Sensitive data | We do not seek to collect sensitive personal information through the Website and ask that you not submit it. |
| How we use it | To respond to inquiries, schedule consultations, deliver and improve our Services, send marketing (with opt-out), secure our systems, and comply with law. See Section 2. |
| Legal bases | Consent, contract performance, legitimate interests, and legal obligations under GDPR/UK GDPR; notice and consent under India’s DPDP Act, 2023. See Sections 3 and 4. |
| Cookies | We use cookies and similar technologies as described in our Cookie Policy. You can manage preferences through our cookie banner and your browser. See Section 5. |
| Sharing | With vetted service providers and sub-processors under contract, our group companies, and as required by law or in a business transaction. We do not sell your personal information. See Section 6. |
| International transfers | Data may be processed in India, the United States, and Australia. We use EU Standard Contractual Clauses and the UK Addendum where required. See Section 7. |
| Retention | We keep data only as long as needed for the purpose collected, per the schedule in Section 8. |
| Security | Appropriate technical and organizational security measures aligned with our ISO 27001 certification and SOC 2 Type II attestation — but no method is 100% secure. See Section 9. |
| Your rights | Access, correction, deletion, portability, objection, opt-out of marketing/targeted advertising, and more — depending on your region (EEA/UK/Switzerland, US states, India, Canada, Australia). See Section 10. |
| AI transparency | We do not make solely automated decisions with legal or similarly significant effects. AI tools are used internally under strict governance. See Section 11. |
| Children | Our Website and Services are directed to adults (18+); we do not knowingly collect data from children. See Section 12. |
| Contact / complaints | DPO: Mukul Gupta, [email protected], +91-33-6799222. You may also complain to your supervisory authority or, in India, the Data Protection Board. See Section 16. |
1. Information We Collect
1.1 Information You Provide Directly
We collect personal information that you voluntarily provide when you interact with us, including:
- Contact and inquiry forms. When you complete a “Contact Us,” “Request a Quote,” or similar form, we collect your name, business email address, phone number, company name, job title, country, and the content of your message, including any project details you choose to share.
- Consultation booking. When you book a consultation or discovery call, we collect your name, email address, phone number, company, time-zone and scheduling preferences, and any notes you provide about your requirements.
- Careers and job applications. When you apply for a role, we collect your name, contact details, resume/CV, employment history, education and qualifications, professional links (e.g., LinkedIn or portfolio URLs), compensation expectations where voluntarily provided, and any other information included in your application or interviews.
- Newsletters and content downloads. When you subscribe to our newsletter, blog updates, or download gated resources (such as whitepapers or case studies), we collect your name, email address, company, and topic preferences.
- Client onboarding and service delivery. If you become a client, we collect billing and invoicing details, tax identifiers where required, contract signatory information, and the contact details of your project personnel.
- Events and surveys. When you register for webinars or events, or respond to surveys, we collect registration details and your responses.
- Communications. Records of correspondence when you contact us by email, phone, chat, or social media, including call notes and (where notified) call recordings.
Please do not submit sensitive personal information (such as government ID numbers, financial account credentials, health data, biometric data, or information revealing racial or ethnic origin, political opinions, religious beliefs, or union membership) through the Website. We do not intentionally collect such data through the Website; if you nonetheless provide it, we will handle it in accordance with applicable law and delete it where it is not required.
1.2 Information Collected Automatically
When you visit the Website, we and our service providers automatically collect certain technical and usage information, including:
- Device and browser data: IP address, device type, operating system, browser type and version, language settings, screen resolution, and device identifiers.
- Usage data: pages viewed, links clicked, time spent on pages, scroll depth, referring and exit URLs, search terms used on the Website, and date/time stamps.
- Log data: server logs recording requests, errors, and diagnostic information used for security and troubleshooting.
- Approximate location: inferred from IP address at country or city level (not precise geolocation).
- Cookies and similar technologies: identifiers placed via cookies, pixels, tags, and SDKs. Details — including the categories of cookies used and how to manage them — are set out in our Cookie Policy. See also Section 5.
1.3 Information from Third Parties
Our previous policy stated that we did not receive any information from third parties. To keep this Policy accurate and current, we now disclose the limited third-party sources from which we may receive personal information:
- Publicly available sources: professional and business information available on public platforms such as LinkedIn, company websites, business directories, and public registries, used for B2B outreach and to verify business contact details.
- Referrals: where a client, partner, or mutual business contact refers you to us, we may receive your name and business contact details from them.
- Analytics and advertising providers: aggregated or pseudonymous information from providers that operate analytics or advertising tools on the Website, subject to your cookie preferences (see the Cookie Policy).
- Recruitment channels: where you apply via a job board, recruitment agency, or professional network, we receive the application data you submit through that channel.
- Group companies: information shared within our corporate group, including companies that join the group through acquisition, for administrative and business-development purposes (see Section 6).
Where required by law, we treat this information in accordance with this Policy and honor your rights with respect to it.
2. How We Use Your Information
We use personal information for the following purposes:
- Responding to inquiries and scheduling consultations — to reply to your messages, provide quotes, arrange discovery calls, and manage the pre-sales process.
- Service delivery and client administration — to onboard clients, perform contracts, manage projects, communicate about deliverables, process invoices and payments, and provide support.
- Marketing and business development — to send newsletters, event invitations, service updates, and relevant B2B communications. Every marketing email includes an unsubscribe link, and you may opt out at any time by contacting us. Opting out does not affect service-related (non-marketing) communications.
- Recruitment — to evaluate applications, conduct interviews, verify qualifications and references (where permitted), and manage the hiring process.
- Website operation and improvement — to operate, maintain, troubleshoot, analyze, and improve the Website and its content and user experience.
- Security and fraud prevention — to protect the Website, our systems, our personnel, and our clients; to detect and prevent fraud, abuse, and security incidents; and to enforce our Terms and Conditions.
- Legal compliance — to comply with applicable laws, regulations, tax and accounting obligations, lawful requests from authorities, and to establish, exercise, or defend legal claims.
- Business transactions — to evaluate or carry out a merger, acquisition, reorganization, or sale of assets (see Section 6).
- AI and service improvement (limited basis) — we may use de-identified or aggregated information to improve our internal tools, accelerators, and AI-assisted delivery capabilities. We do not use identifiable personal information to train AI models, and we use client data for service-improvement purposes only where permitted by the applicable contract. See Section 11.
We will not use your personal information for purposes materially incompatible with those described above without notifying you and, where required, obtaining your consent.
3. Legal Bases for Processing (GDPR/UK GDPR)
Where the EU General Data Protection Regulation (“GDPR”) or the UK GDPR applies, we process personal data only where we have a valid legal basis under Article 6. Depending on the context, these are:
| Purpose | Legal basis (Art. 6 GDPR / UK GDPR) |
|---|---|
| Responding to inquiries; pre-contractual steps (quotes, consultations) | Art. 6(1)(b) — contract or steps prior to entering a contract |
| Delivering Services to client contacts; administering contracts | Art. 6(1)(b) — contract performance; Art. 6(1)(f) — legitimate interests |
| B2B marketing to existing and prospective business contacts | Art. 6(1)(f) — legitimate interests (balanced against your rights); Art. 6(1)(a) — consent where required (e.g., certain e-marketing under ePrivacy rules) |
| Non-essential cookies and similar technologies | Art. 6(1)(a) — consent (via our cookie banner); strictly necessary cookies: Art. 6(1)(f) |
| Website analytics, security, and improvement | Art. 6(1)(f) — legitimate interests in a secure, effective Website |
| Recruitment | Art. 6(1)(b) — pre-contractual steps; Art. 6(1)(f) — legitimate interests; Art. 6(1)(a) — consent (e.g., retaining your profile for future roles) |
| Compliance with law, tax, accounting, and legal claims | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interests |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your fundamental rights and freedoms; you may obtain details of this balancing assessment on request. Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. India: Digital Personal Data Protection Act, 2023
Capital Numbers is headquartered in India and acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules notified under it, as they are brought into force. This section applies to the processing of digital personal data within the scope of the DPDP Act.
4.1 Notice and Consent Standard
We process your personal data on the basis of your consent, following a clear notice describing the personal data sought, the purpose of processing, the manner in which you may exercise your rights, and the manner in which you may complain to the Data Protection Board of India. You may withdraw consent at any time with equivalent ease; withdrawal does not affect the lawfulness of processing already carried out, and upon withdrawal we will cease processing and erase your personal data within a reasonable time unless retention is required or permitted by law. We may also process personal data without consent for certain legitimate uses recognized by the DPDP Act — for example, where you voluntarily provide your data for a specified purpose without indicating that you do not consent (such as submitting an inquiry form), or for compliance with law or a court order.
4.2 Rights of Data Principals
Subject to the DPDP Act, you have the right to:
- Access — obtain a summary of your personal data being processed, the processing activities, identities of Data Fiduciaries/Processors with whom it has been shared, and other prescribed information;
- Correction, completion, updating, and erasure — correct inaccurate or misleading data, complete incomplete data, update it, and request erasure when it is no longer necessary for the specified purpose, unless retention is legally required;
- Grievance redressal — raise a grievance regarding our processing or our response to your rights requests, which we will resolve within the period we publish (and in any event as required by the DPDP Act and its rules); you must use this mechanism before approaching the Data Protection Board;
- Nominate — nominate an individual to exercise your rights in the event of your death or incapacity.
4.3 Grievance Officer
For any grievance under the DPDP Act, or to exercise your Data Principal rights, contact our designated Grievance Officer:
Mukul Gupta, Grievance Officer / Data Protection Officer Email: [email protected]; Phone: +91-33-6799222; Address: Capital Numbers Infotech Limited, Mani Casadona, Unit No 8E4, Action Area #2 F, New Town, Kolkata 700156, West Bengal, India.
4.4 Complaints to the Data Protection Board
If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India in the manner prescribed under the DPDP Act and its rules.
5. Cookies and Tracking Technologies
We use cookies, web beacons, pixels, tags, and similar technologies to operate the Website, remember your preferences, analyze traffic and usage, and — where you consent — support marketing and advertising measurement. Cookies fall into the following categories:
- Strictly necessary — required for core Website functionality and security; these cannot be switched off.
- Functional/preferences — remember choices such as language and region.
- Analytics/performance — help us understand how visitors use the Website so we can improve it.
- Marketing/advertising — used to measure campaign effectiveness and, where applicable, deliver relevant content; set only with your consent where required.
Full details — including the specific cookies used, their providers, purposes, and lifespans — are set out in our Cookie Policy, which forms part of this Policy. You can manage your preferences at any time through the cookie consent banner on the Website or via your browser settings. Rejecting non-essential cookies will not prevent you from using the Website, though some features may be limited.
6. How We Share and Disclose Information
We disclose personal information only in the following circumstances:
- Service providers and sub-processors. We engage carefully vetted third parties that process personal information on our behalf under written contracts imposing confidentiality, security, and data-protection obligations — for example, providers of cloud hosting, CRM and marketing automation, scheduling tools, email delivery, analytics, recruitment platforms, payment and invoicing support, and professional advisers (lawyers, accountants, auditors). These providers may process personal information only on our documented instructions and for the services they provide to us.
- Affiliates and group companies. We may share personal information within our corporate group — including companies that join our group through acquisition — for internal administration, service delivery coordination, and business development, in each case consistent with this Policy.
- Business transfers. If we are involved in a merger, acquisition, financing, reorganization, or sale of all or part of our assets or business, personal information may be transferred as part of that transaction, subject to standard confidentiality protections. We will notify you of any change in ownership or control where required by law.
- Legal requirements and protection of rights. We may disclose personal information where we believe in good faith that it is necessary to: comply with applicable law, regulation, legal process, or an enforceable governmental request; enforce our agreements and policies; protect the rights, property, or safety of Capital Numbers, our clients, our personnel, or others; and detect, prevent, or address fraud, security, or technical issues.
- With your consent or at your direction. We may share personal information with third parties when you ask us to or consent to the sharing.
We do not sell your personal information, and we do not share it with third parties for their own direct marketing purposes. We have not sold personal information in the preceding twelve (12) months. Where our use of cookies for analytics or advertising measurement could be characterized as a “sale” or “sharing” under certain US state laws, you may opt out as described in Section 10 and the Cookie Policy.
7. International Data Transfers
We are headquartered in India and serve clients globally. Personal information may be transferred to, stored, and processed in India, the United States, and Australia, and in other countries where our service providers operate. These countries may have data-protection laws that differ from those in your jurisdiction.
Where we transfer personal data originating in the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, including:
- the EU Standard Contractual Clauses adopted by the European Commission (with the UK International Data Transfer Addendum or UK IDTA where the UK GDPR applies), executed with the relevant importer; and
- supplementary technical and organizational measures where appropriate, aligned with our ISO 27001 certification and SOC 2 Type II attestation (see Section 9).
For transfers of personal data from India, we comply with the cross-border transfer provisions of the DPDP Act, which permits transfers to all jurisdictions except those specifically restricted or blacklisted by the Central Government by notification.
You may request a copy of the safeguards applicable to your personal data by contacting us (see Section 16); certain commercially sensitive or security-related terms may be redacted.
8. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, tax, accounting, and reporting requirements, and to establish or defend legal claims. Rather than applying a single blanket period, we apply the following purpose-based schedule:
| Category of personal information | Typical retention period |
|---|---|
| Website contact/inquiry submissions and consultation bookings (no engagement follows) | Up to 24 months from last interaction, then deleted or de-identified |
| Prospect/lead records in CRM (no engagement follows) | Up to 24 months from last meaningful interaction |
| Client contract, billing, and transaction records | Duration of the engagement plus 7 years, to meet Indian tax, accounting, and limitation-of-claims requirements |
| Client project communications and delivery records | Duration of the engagement plus up to 3 years, unless the contract requires otherwise |
| Newsletter and marketing subscriptions | Until you unsubscribe; we retain a minimal suppression record (email + opt-out flag) indefinitely to honor your opt-out |
| Job applications — unsuccessful candidates | 12 months after the recruitment process closes, unless you consent to longer retention (up to 24 months) for future opportunities |
| Job applications — hired candidates | For the duration of employment and thereafter as required by Indian employment and tax law |
| Server logs and security telemetry | Up to 12 months, unless needed longer to investigate an incident |
| Cookie identifiers | Per the lifespans stated in the Cookie Policy |
| Backups | Deleted on the normal backup-rotation cycle, generally within 90 days of deletion from production systems |
When retention periods expire, we securely delete the data or irreversibly de-identify it. We may retain de-identified or aggregated information that can no longer be associated with you for analytics and service-improvement purposes without time limit.
9. Data Security
We maintain a comprehensive information security program designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. We implement appropriate technical and organizational security measures aligned with our ISO/IEC 27001 certification and SOC 2 Type II attestation, taking into account the nature, scope, and purposes of the processing and the risks involved.
However, no method of transmission over the internet or method of electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities where required by applicable law.
10. Your Privacy Rights by Region
Depending on where you are located, you may have some or all of the rights below. To exercise any right, see Section 16. We will not discriminate or retaliate against you for exercising your rights.
10.1 European Economic Area, United Kingdom, and Switzerland
Under the GDPR, UK GDPR, and Swiss data protection law, you have the right to:
- Access your personal data and obtain a copy;
- Rectification of inaccurate or incomplete data;
- Erasure (“right to be forgotten”), subject to legal exceptions;
- Restriction of processing in certain circumstances;
- Data portability — receive your data in a structured, commonly used, machine-readable format and transmit it to another controller;
- Object to processing based on legitimate interests, including profiling, and to direct marketing at any time (we will stop upon objection);
- Withdraw consent at any time, where processing is based on consent, without affecting prior lawful processing;
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (see Section 11);
- Lodge a complaint with your local supervisory authority (in the EEA, your national data protection authority; in the UK, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner). We encourage you to contact us first so we can resolve your concern.
We respond to verified requests within one month, extendable by up to two further months for complex or numerous requests (we will tell you if an extension applies).
10.2 United States — State Privacy Laws
If you are a resident of California (CCPA as amended by the CPRA), Virginia, Colorado, Connecticut, Utah, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Rhode Island, Florida, Montana, Oregon, Texas, Kentucky, Indiana, or another US state with a comprehensive consumer privacy law in effect as of 2026, you may have some or all of the following rights, subject to each law’s scope, thresholds, and exceptions:
- Right to know/access — confirm whether we process your personal data and obtain access to it, including the categories and specific pieces collected;
- Right to correct inaccurate personal data;
- Right to delete personal data, subject to statutory exceptions;
- Right to data portability — obtain a copy in a portable, readily usable format;
- Right to opt out of (a) the sale of personal data, (b) targeted advertising, and (c) profiling in furtherance of decisions with legal or similarly significant effects;
- Right to limit the use and disclosure of sensitive personal information (California) — we do not use or disclose sensitive personal information for purposes requiring a right to limit;
- Right to non-discrimination for exercising your rights;
- Right to appeal our decision on a request — you may appeal by replying to our response email or contacting us with “Privacy Appeal” in the subject line; we will respond within the period required by your state’s law (e.g., 60 days under the Colorado Privacy Act).
Honoring your choices. We do not sell personal information. Where required by applicable law, we honor legally recognized opt-out preference signals (such as the Global Privacy Control (GPC)) as a valid request to opt out of sale/sharing/targeted advertising for the browser or device sending the signal (see Section 14). You may also manage advertising cookies via the Cookie Policy and our cookie banner.
Authorized agents. You may designate an authorized agent to submit a request on your behalf; we may require proof of authorization and verification of your identity.
California-specific disclosures. In the preceding 12 months we have collected the following categories of personal information: identifiers (e.g., name, email, IP address); personal records (e.g., phone number, employment and education history for applicants); commercial information (e.g., records of services purchased); internet or electronic network activity (e.g., Website usage data); professional or employment-related information; and inferences drawn from the foregoing for Website improvement. We collect these for the business and commercial purposes described in Section 2 and disclose them to the categories of third parties described in Section 6. We have not sold or shared (for cross-context behavioral advertising) personal information in the preceding 12 months, and we do not knowingly sell or share the personal information of consumers under 16.
10.3 India
See Section 4 for your rights as a Data Principal under the DPDP Act, including access, correction, erasure, grievance redressal, nomination, and the right to complain to the Data Protection Board of India.
10.4 Canada
Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws (including Quebec's Law 25), you have the right to request access to and correction of your personal information, to withdraw consent (subject to legal and contractual restrictions), and, in Quebec, to data portability and to information about automated processing. You may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial commissioner.
10.5 Australia
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to request access to and correction of the personal information we hold about you, and to complain to us about our handling of it. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).
11. Automated Decision-Making and AI Transparency
- No solely automated decisions with legal or significant effect. We do not use your personal information to make decisions based solely on automated processing — including profiling — that produce legal effects concerning you or similarly significantly affect you (within the meaning of Article 22 GDPR and equivalent provisions of other laws). If this changes, we will notify you and implement the safeguards required by law, including the right to human intervention and to contest the decision.
- Internal use of AI tools. We use artificial intelligence and machine-learning tools internally to support service delivery, code quality, documentation, analytics, and operational efficiency. Where such tools process personal information, they do so under the same contractual, security, and confidentiality controls described in this Policy, and our personnel remain responsible for reviewing and validating outputs.
- No training on your identifiable personal data. We do not use identifiable personal information collected through the Website to train AI models. Any use of data for improving AI-assisted capabilities is limited to de-identified or aggregated data, and, for client data, only where the governing contract permits it.
- EU AI Act commitment. Consistent with the transparency principles of the EU Artificial Intelligence Act, where you interact with an AI system operated by us (for example, a chatbot on the Website), we will disclose that you are interacting with an AI, and we will clearly label AI-generated content where required.
12. Children’s Privacy
The Website and Services are intended for businesses and adults. We do not knowingly collect, solicit, or process personal information from anyone under 18 years of age, and we do not knowingly market to children. By using the Website, you represent that you are at least 18. If we learn that we have collected personal information from a person under 18 without appropriate authorization, we will promptly delete it. If you believe a child has provided us personal information, please contact us at [email protected].
13. Third-Party Links
The Website may contain links to third-party websites, plug-ins, social media platforms, and applications (for example, LinkedIn, X/Twitter, or YouTube) that we do not own or control. Clicking those links or enabling those connections may allow third parties to collect or share data about you. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to read the privacy policy of every third-party site or service you visit or use.
14. Do-Not-Track and Global Privacy Control
“Do Not Track” (“DNT”) is a browser preference signal for which no uniform industry standard has been adopted; like most websites, the Website does not currently respond to DNT signals. However, where required by applicable law (for example, certain US state privacy laws), we honor legally recognized opt-out preference signals, such as the Global Privacy Control (GPC), as a valid request to opt out of the sale or sharing of personal information and of targeted advertising for the browser or device transmitting the signal. You can also control tracking through our cookie consent banner and your browser settings (see the Cookie Policy).
15. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational needs. The updated version will be indicated by the “Last Updated” date at the top of this page and will be effective when posted, unless a later effective date is stated. If we make material changes, we will provide a more prominent notice — for example, by posting a notice on the Website or, where appropriate, by emailing you at the address we have on file — before the change takes effect. We encourage you to review this Policy periodically.
16. Contact Us and How to Exercise Your Rights
If you have questions or concerns about this Policy or our privacy practices, or if you wish to exercise any of your rights, contact our Data Protection Officer (DPO) / Grievance Officer:
Mukul Gupta Data Protection Officer, Capital Numbers Infotech Limited Email: [email protected] Phone: +91-33-6799222.
Registered & Corporate Office:
Capital Numbers Infotech Limited Attn: Mukul Gupta Mani Casadona, Unit No 8E4, Action Area #2 F, New Town, Kolkata 700156, West Bengal, India.
How to submit a request. You may exercise your rights by emailing us at [email protected] with the subject line “Privacy Request” and describing the right you wish to exercise. To protect your information, we will take reasonable steps to verify your identity (and the authority of any authorized agent) before acting on a request, and we will use the information you provide in the request only for verification purposes.
Response timeline. We will acknowledge your request promptly and respond within one month of receipt, as required by the GDPR/UK GDPR. Where requests are complex or numerous, we may extend this period by up to two further months and will inform you of the extension and the reasons. For requests under US state laws, the DPDP Act, or other regimes, we will respond within the timeline required by the applicable law (for example, 45 days under the CCPA, extendable once by 45 days).
No fee; manifestly unfounded requests. Exercising your rights is generally free of charge. Where a request is manifestly unfounded or excessive (in particular because of its repetitive character), we may charge a reasonable fee or decline to act, as permitted by law, and we will explain our reasons.
Related Policies and Documents
This Policy should be read together with the following documents, each available on our Website:
- Cookie Policy — details of the cookies and tracking technologies we use and how to manage them;
- Terms and Conditions — the terms governing your use of the Website and our Services;
- Disclaimer — important limitations on the information provided on the Website;
- Refund Policy — our policy on cancellations and refunds for Services.
This Privacy Policy is provided for the website of Capital Numbers Infotech Limited and reflects our practices as of the “Last Updated” date above.