Skip to main content

Privacy Policy

Vantedge Professional Services Private Limited

Last updated: 12 July 2026 Effective date: 12 July 2026

Vantedge Professional Services Private Limited ("Company", "Vantedge", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and the rights available to you.

This policy is designed to meet our obligations under:

  • India — the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025, together with the Information Technology Act, 2000 and rules made under it;
  • European Union / United Kingdom — the EU General Data Protection Regulation (EU) 2016/679 and the UK GDPR ("GDPR"), where applicable; and
  • California, USA — the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), where applicable.

If you are in a region not listed above, we still apply the core protections in this policy to your personal data.

1. Who we are and our role

Vantedge Professional Services Private Limited is the entity responsible for deciding how and why your personal data is processed. Under the DPDP Act we act as a Data Fiduciary; under the GDPR we act as a data controller; under the CCPA/CPRA we act as a business. Where we process personal data on behalf of a client under a contract, we act as a Data Processor / processor / service provider for that data, and the client's own privacy policy governs it.

Our contact details are in Section 14 (Grievance Officer and contact).

2. The personal data we collect

We collect the following categories of personal data:

  • Identity and contact data — name, email address, phone number, job title, and company details.
  • Technical and usage data — IP address, browser type and version, device information, access logs, and pages viewed on our website.
  • Communications data — the content of enquiries, emails, and other messages you send us.
  • Project data — business documents, requirements, or other information you share with us so we can scope or deliver work. This may occasionally contain personal data about your own staff or customers; where it does, you are responsible for having a lawful basis to share it with us.

We do not intentionally collect special-category or sensitive personal data (such as health, biometric, or financial-account data) through our website. Please do not send us such data unless we specifically ask for it.

3. How and why we use your data (and our legal basis)

We use your personal data to:

  • respond to your enquiries and communicate with you;
  • provide, scope, and deliver our services and products;
  • meet our contractual and legal obligations;
  • operate, secure, and improve our website; and
  • send you information you have asked for or, where permitted, relevant business updates.

Legal bases (GDPR). Where the GDPR applies, we rely on one or more of the following: your consent; performance of a contract with you; compliance with a legal obligation; and our legitimate interests in running and growing our business (balanced against your rights).

Grounds for processing (DPDP Act). Where the DPDP Act applies, we process your personal data on the basis of your consent, or for certain legitimate uses permitted by the Act. Our consent notices tell you what data we collect and the purpose for each use.

We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects about you. [Confirm this remains accurate if you introduce AI-based automated decision-making; if you do, this section must be updated.]

4. Consent and how to withdraw it

Where we rely on your consent, it is sought through a clear, affirmative action and is free, specific, informed, and unambiguous.

You can withdraw your consent at any time. Withdrawing consent is as easy as giving it. To withdraw, contact us using the details in Section 14. Withdrawal does not affect processing already carried out, and some processing may continue where we have another lawful basis or legal obligation.

Once the Consent Manager framework under the DPDP Act is operational, you will also be able to manage or withdraw consent through a registered Consent Manager.

5. Cookies and tracking

We use cookies and similar technologies to run our website and, where enabled, to measure how it is used. [State whether you use only strictly necessary cookies, or also analytics/advertising cookies. If you use analytics or advertising cookies, you must (a) obtain prior consent via a cookie banner for EU/UK visitors, and (b) treat certain uses as "sharing" under the CCPA — see Section 10.]

You can control or disable cookies through your browser settings and, where provided, through our cookie banner.

6. How we share your data

We may share your personal data with:

  • Service providers / processors who help us operate (for example, hosting, email, and analytics providers), under contracts that require them to protect your data and use it only on our instructions;
  • Professional advisers such as lawyers, auditors, and insurers; and
  • Legal and regulatory authorities, where required by law or to protect our legal rights.

We do not sell your personal data. For how "sale" and "sharing" are treated under California law, see Section 10.

7. International data transfers

We are based in India, and your data may be processed in India or in other countries where we or our service providers operate.

  • From the EU/UK: where we transfer personal data outside the EEA or UK, we use an approved safeguard such as the European Commission's / UK's Standard Contractual Clauses, or another lawful transfer mechanism.
  • Under the DPDP Act: we may transfer personal data outside India, except to any country restricted by notification of the Government of India.

[Insert the countries or regions where your main service providers store data, if you wish to be specific.]

8. Data retention and erasure

We keep your personal data only for as long as necessary for the purposes described in this policy, or as required by law. When it is no longer needed, we erase or anonymise it.

Indicative retention periods:

  • Enquiry and contact data: [insert period, e.g., 24 months after last contact]
  • Client and project data: [insert period, e.g., duration of the engagement plus X years for legal/tax reasons]
  • Website technical logs: [insert period]

You can ask us to erase your data (see Section 9), subject to legal or contractual limits.

9. Your rights

Everyone covered by this policy has the right to ask us to access, correct, or erase their personal data, and to withdraw consent. Depending on where you are, you may have the additional rights below. To exercise any right, contact us using the details in Section 14. We will verify your identity and respond within the time limits set by the applicable law.

9.1 If you are in India (DPDP Act)

You have the right to:

  • access a summary of the personal data we process about you and how we process it;
  • correct, complete, or update your personal data;
  • erase your personal data where it is no longer needed;
  • grievance redressal — raise a complaint with our Grievance Officer, who will respond within 90 days; and
  • nominate another person to exercise your rights in the event of your death or incapacity.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

9.2 If you are in the EU or UK (GDPR)

You have the right to: access; rectification; erasure ("right to be forgotten"); restriction of processing; data portability; to object to processing (including direct marketing); and not to be subject to solely automated decision-making that has legal or similarly significant effects.

You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO); in the EU, your local Data Protection Authority.

[If you have no establishment in the EU/UK but offer goods or services to, or monitor, people there, you may be required to appoint an Article 27 EU/UK Representative. Insert their details here, or confirm with counsel that an exemption applies.]

9.3 If you are in California (CCPA/CPRA)

You have the right to: know what personal information we collect and how we use and disclose it; delete personal information; correct inaccurate personal information; opt out of the "sale" or "sharing" of personal information; limit the use of sensitive personal information; and not be discriminated against for exercising your rights.

To exercise these rights, contact us using the details in Section 14. You may use an authorised agent to submit a request on your behalf.

The categories of personal information we have collected in the last 12 months are described in Section 2. [Confirm whether, under California's broad definitions, any disclosure to analytics or advertising partners counts as "selling" or "sharing." If it does, add a clearly labelled "Do Not Sell or Share My Personal Information" link and a "Limit the Use of My Sensitive Personal Information" link on your website, and update the statement below.]

We do not sell or share personal information as those terms are defined under the CCPA/CPRA. [Amend if the point above applies.]

10. Data security

We use appropriate technical and organisational measures to protect your personal data, including access controls, secure storage, and confidentiality obligations on our team. No method of transmission or storage is completely secure, but we work to protect your data and to limit access to those who need it.

If a personal data breach occurs, we will notify the relevant authority and affected individuals as required by the applicable law, including the Data Protection Board of India under the DPDP Act.

11. Children's data

Our website and services are directed at businesses and are not intended for children.

  • India (DPDP Act): we do not knowingly process the personal data of anyone under 18 without verifiable consent from a parent or lawful guardian, and we do not track, monitor behaviour, or direct targeted advertising at children.
  • EU/UK (GDPR): we do not knowingly process the data of children below the applicable age of digital consent (16, or lower where a member state has set it) without parental consent.
  • California: we do not knowingly sell or share the personal information of consumers under 16.

If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Third-party links

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. Please review their privacy policies before providing them with personal data.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where required by law, take additional steps to notify you or obtain fresh consent. Please review this page periodically.

14. Grievance Officer and contact

For any questions, requests, or complaints about this policy or your personal data, contact our Grievance Officer (appointed in compliance with the Information Technology Act, 2000 and the DPDP Act, 2023):

  • Name: Vantedge Grievance Officer
  • Email: privacy@vantedge.in
  • Phone: +91 98454 98427
  • Address: Ebony B-1601, Salarpuria Greenage, Bengaluru 560068, INDIA

We will acknowledge and respond to your request within the timelines required by the applicable law, and within 90 days for grievances under the DPDP Act.