Legal & Compliance

Privacy Policy

At Chandak Infotech, your privacy is built into everything we do. This policy explains what data we collect, how we use it, and the rights you hold over your information.

Effective Date: 1 July 2025  ·  Last Updated: 22 July 2026
01 — Information We Collect

Information We Collect

We collect information you provide directly, data we generate when you use our services, and data from third-party sources. Categories of personal data we may collect include:

  • Full name and job title
  • Business email address
  • Phone and mobile number
  • Company name and website URL
  • Project requirements and budget range
  • IP address and approximate location
  • Browser type and OS version
  • Pages visited and session duration
  • Device and screen resolution data
  • Contact form submissions
  • Uploaded files or documents
  • Referral source (how you found us)

We collect this when you fill out contact forms, request a quote, subscribe to our newsletter, schedule a consultation, or interact with our website or customer support.

02 — How We Use Your Information

How We Use Your Information

Chandak Infotech uses the information we collect for the following legitimate business purposes:

  • Respond to inquiries and deliver services
  • Send project updates and progress reports
  • Process payments and generate invoices
  • Improve our website functionality and services
  • Send marketing communications (with your consent)
  • Analyse usage trends and website behaviour
  • Comply with applicable legal obligations
  • Prevent fraud, abuse, and security threats
  • Personalise your website experience
  • Conduct surveys and service research
  • Provide ongoing customer support
  • Meet our contractual obligations to clients
Legal Basis: Where required by applicable law (e.g. GDPR), our processing is based on your consent, performance of a contract, compliance with a legal obligation, or our legitimate business interests. We will never sell your personal information to third parties for their own marketing purposes.
03 — Information Sharing

Information Sharing & Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your data only in the following limited circumstances:

  • Trusted service providers (hosting, email, analytics) under strict data processing agreements
  • Payment processors for secure transaction handling
  • Law enforcement or government authorities when legally required
  • Business transfers during a merger or acquisition, with advance notice
  • Professional advisors (lawyers, auditors) bound by strict confidentiality
  • With your explicit written consent for any other purpose

All third-party service providers we engage are contractually required to handle your data securely and only for the specific purposes we define.

04 — Cookies & Tracking Technologies

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyse site traffic, and personalise content. Below is a summary of the types of cookies we use:

Cookie TypePurposeDuration
EssentialRequired for the website to function (form submissions, session management)Session
AnalyticsUnderstand how visitors interact with our site (Google Analytics, heatmaps)Up to 2 years
MarketingTrack ad performance and deliver relevant ads (Meta Pixel, Google Ads)Up to 90 days
FunctionalRemember your preferences (language, region, chat state)Up to 1 year
Meta Pixel Notice: We use the Meta (Facebook) Pixel to measure the effectiveness of our advertising campaigns. This tool may collect data about your activity on our website and share it with Meta Platforms, Inc. You can opt out via Meta Ad Preferences or your browser cookie settings.

You can control cookies through your browser settings. Disabling certain cookies may affect site functionality.

05 — Data Security

Data Security

Protecting your information is a top priority. We implement comprehensive technical and organisational security measures including:

  • SSL/TLS encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • Role-based access controls and strict permissions
  • Regular security audits and vulnerability scans
  • Secure development practices (OWASP guidelines)
  • Staff data protection training and awareness programs
  • Incident response and breach notification procedures
  • Two-factor authentication for all internal systems

While we implement robust security measures, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and report any suspected security issues to us immediately.

06 — Data Retention

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this policy, or as required by law. Our retention principles are:

  • Contact and inquiry data: 3 years from last interaction
  • Client project data: 7 years (legal and accounting requirements)
  • Marketing consent records: until withdrawal plus 1 year
  • Website analytics data: 26 months (Google Analytics default)
  • Cookie data: as specified per cookie type above
  • Support tickets: 2 years after resolution

When your data is no longer required, we securely delete or anonymise it so it can no longer be associated with you.

07 — Your Rights

Your Rights & Choices

Depending on your location, you may have the following rights regarding your personal data. We honour these rights promptly and without charge:

Access
Request a copy of the personal data we hold about you.
Rectification
Ask us to correct inaccurate or incomplete personal data.
Erasure
Request deletion of your personal data (right to be forgotten).
Object
Object to processing based on legitimate interests or direct marketing.
Portability
Receive your data in a structured, machine-readable format.
Restriction
Request that we limit the processing of your personal data.
Withdraw Consent
Withdraw consent at any time where processing is consent-based.
Complaint
File a complaint with your local data protection authority.

To exercise any of these rights, email us at hello@chandakinfotech.com. We will respond within 30 days.

09 — Children Privacy

Children's Privacy

Our services are intended for business professionals and are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16.

If we become aware that we have collected personal information from a child without verifiable parental consent, we will take steps to delete that information immediately. If you believe we may have collected data about a child, please contact us at hello@chandakinfotech.com.

10 — Changes to This Policy

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the Last Updated date at the top of this page
  • Post the revised policy on our website immediately
  • Notify you via email for material changes (where we hold your email address)
  • Display a notice banner on our website for 30 days post-update

Your continued use of our website or services after the effective date of the revised policy constitutes your acceptance of the changes.