LEGAL • PRIVACY • DATA PROTECTION

Privacy Policy

Chaitanya Digital Solutions respects the privacy of individuals who visit our websites, contact us, or engage our services. This Privacy Policy explains what personal information we may collect, why we may process it, how it may be shared and retained, and the choices and rights available to individuals under applicable law.

This policy applies to information associated with our website, inquiries, communications, and relevant service relationships, including website development, SEO, cybersecurity-related services, automation, AI-assisted systems, CRM, digital strategy, branding, and related technology services.

Effective Date: 5 September 2026

DOCUMENT OVERVIEW

Our Approach to Personal Information

We aim to collect and use personal information in a manner that is relevant to the purpose for which it is obtained, proportionate to the business requirement, and subject to appropriate safeguards.

What This Policy Covers

This policy covers personal information that may be collected through the CDS website, contact and enquiry channels, project communications, customer relationships, and other interactions where this Privacy Policy applies.

What This Policy Does Not Cover

Third-party websites, applications, platforms, payment providers, communication services, hosting providers, and other external services operate under their own terms and privacy practices. Their processing is governed by the relevant provider’s policies where applicable.

INFORMATION COLLECTION

Information We May Collect

The information collected depends on how you interact with CDS and which services or features you use.

1. Information You Provide

Depending on the interaction, you may provide information such as your name, email address, telephone number, company or organisation name, project requirements, service preferences, billing details, correspondence, and other information you voluntarily choose to provide.

2. Technical Information

When you access a CDS website, technical information may be processed by the website or its infrastructure. This may include IP address, browser information, device type, operating system, referring information, pages accessed, timestamps, and technical or security logs, depending on the website configuration.

3. Communications

When you communicate with CDS through email, WhatsApp, telephone, contact forms, social or business communication channels, or other support channels, information contained in those communications may be retained where reasonably necessary for responding, providing services, maintaining continuity, resolving issues, or meeting applicable obligations.

4. Project & Service Information

Clients may provide information, documents, credentials, technical details, website data, business information, or other materials required for a particular engagement. The nature of such information depends on the agreed scope of work.

5. Information From Third Parties

We may receive information from third-party platforms, service providers, business directories, payment providers, or other sources where such information is relevant to a legitimate business interaction or service and is obtained in accordance with applicable requirements.

6. Information Provided on Behalf of Others

If you provide personal information relating to another individual, you should have an appropriate legal basis or authority to provide that information and should ensure that the relevant person is informed where required.

PURPOSE & USE

Why We May Use Information

Personal information may be processed for purposes connected with operating the business, responding to individuals, delivering agreed services, maintaining security, and meeting applicable obligations.

Service Delivery

To plan, provide, maintain, support, improve, and manage services requested by clients or users.

Enquiries & Communication

To respond to enquiries, consultation requests, support requests, project communications, and other legitimate business communications.

Contracts & Payments

To prepare proposals, manage contractual relationships, maintain project records, issue invoices, process payments, and maintain appropriate transaction records.

Security & Abuse Prevention

To protect websites, accounts, systems, communications, and infrastructure against unauthorized access, abuse, fraud, or other security risks.

Business Operations

To maintain internal records, manage relationships, administer operations, improve service processes, and support legitimate business activities.

Legal & Regulatory Requirements

To comply with applicable laws, regulations, lawful requests, contractual obligations, dispute-resolution requirements, and other legitimate legal responsibilities.

PROCESSING CONTEXT

Processing Depends on Purpose & Context

The legal basis or justification for processing personal information depends on the nature of the interaction and the applicable legal framework. Depending on the circumstances, processing may be connected with consent, requested services, contractual or pre-contractual activities, legitimate business purposes where permitted, security, legal obligations, or other grounds recognised under applicable law.

Consent

Where processing relies on consent, consent may be requested in the manner appropriate to the relevant activity and may be withdrawn subject to applicable law and legitimate retention requirements.

Service & Contract

Information may be required to respond to a request, establish or perform a service relationship, administer an engagement, or fulfil agreed contractual responsibilities.

Legal Obligations

Certain information may need to be retained or disclosed where required by applicable law, lawful process, taxation, accounting, dispute resolution, or other regulatory requirements.

Security & Legitimate Operations

Certain technical or operational information may be processed to protect systems, prevent abuse, maintain service integrity, or support legitimate business operations where permitted by applicable law.

COMMUNICATION CHANNELS

WhatsApp, Email, Phone & Forms

Communications may contain personal or business information. We process communication records according to the purpose of the interaction and the applicable retention and contractual requirements.

WhatsApp

If you contact CDS through WhatsApp, the communication may include your phone number, profile information made available through the service, message content, attachments, timestamps, and other information processed through WhatsApp. WhatsApp also operates under its own privacy practices and technical infrastructure.

Email

Emails sent to or received by CDS may be retained for responding to enquiries, project communication, service continuity, recordkeeping, dispute resolution, security, and other legitimate business purposes.

Telephone

Telephone interactions may result in business notes or related records where reasonably necessary for service delivery, follow-up, support, or recordkeeping. Call recording should not be assumed unless separately communicated or legally required.

Website Forms

Information submitted through website forms may be transmitted to CDS and/or relevant technical service providers supporting form delivery, hosting, security, or communications.

COOKIES & TECHNOLOGIES

Cookies Are Covered by a Separate Policy

CDS websites may use cookies and similar technologies for essential functionality, preferences, security, analytics, performance measurement, or other website functions where applicable.

Cookie Choices

Depending on the website configuration, visitors may be able to manage optional cookie technologies through website controls or browser settings. Restricting necessary technologies may affect website functionality.

Read the Cookie Policy

For further information about cookie categories, third-party technologies, and available controls, please refer to the CDS Cookie Policy.

INFORMATION SHARING

When Information May Be Shared

CDS does not sell personal information. Information may be disclosed where reasonably necessary for service delivery, business operations, legal compliance, security, or other purposes described in this Policy.

Service Providers

Information may be shared with providers supporting hosting, cloud infrastructure, domain services, email, analytics, payments, communications, security, software, or other services necessary for business operations.

Professional & Business Support

Where reasonably necessary, information may be shared with professional advisers, contractors, or business support providers subject to appropriate confidentiality and legal requirements.

Legal Requests

Information may be disclosed where required by applicable law, court order, lawful governmental request, regulatory requirement, or where necessary to establish, exercise, or defend legal rights.

Business Transactions

In connection with a restructuring, merger, acquisition, sale of assets, or similar business transaction, relevant information may be transferred subject to applicable confidentiality and legal requirements.

CLIENT DATA & SERVICE PROCESSING

Client Data May Be Processed Within an Agreed Scope

Some CDS engagements involve access to information belonging to or controlled by a client. Examples may include website data, customer records, business documents, CRM information, website credentials, analytics information, or technical configuration data.

Client-Controlled Information

Where information is supplied by or controlled by a client, the client’s rights, instructions, contractual arrangements, and applicable legal obligations may determine how that information can be accessed or processed.

Purpose-Limited Access

CDS seeks to use client-provided information in accordance with the agreed service scope and the instructions applicable to the engagement.

Third-Party Platforms

Client systems may depend on third-party hosting, cloud, analytics, CRM, payment, communication, or software platforms. Those providers may independently process information under their own terms and privacy practices.

Contractual Controls

Where a project requires specific data-processing obligations, confidentiality terms, security requirements, or processing instructions, these may be addressed through the applicable service agreement, statement of work, NDA, or separate data processing arrangement.

DATA SECURITY

Protecting Information With Reasonable Safeguards

CDS applies reasonable technical and organisational measures appropriate to the nature of the information and the relevant operational context.

Access Controls

Access to information and systems may be restricted according to operational requirements, permissions, roles, and the relevant service environment.

Secure Transmission

Appropriate secure transmission mechanisms may be used where supported by the relevant website, service, platform, or infrastructure.

Operational Safeguards

Security practices may include authentication controls, restricted access, secure hosting configurations, backups, software maintenance, logging, and other measures appropriate to the environment.

No Absolute Security Guarantee

No internet-connected system or method of electronic storage or transmission can be guaranteed to be completely secure. CDS does not represent that personal information is immune from every possible security risk.

RETENTION

How Long We May Keep Information

Retention depends on the nature of the information, the purpose for which it was collected, the service relationship, legal requirements, security considerations, and legitimate business needs.

Business Records

Transaction, invoice, contract, project, accounting, and related records may be retained for periods required by applicable law or reasonably necessary for legitimate business and dispute-resolution purposes.

Communication Records

Emails, messages, enquiries, and support records may be retained for as long as reasonably necessary for service continuity, security, recordkeeping, dispute resolution, or other legitimate purposes.

Technical & Security Logs

Technical and security information may be retained for periods appropriate to security monitoring, troubleshooting, fraud prevention, system integrity, or applicable operational requirements.

Deletion & Disposal

When information is no longer reasonably required and no legal, contractual, security, or legitimate retention requirement applies, it may be deleted, anonymised, or securely disposed of using appropriate methods.

PRIVACY RIGHTS

Your Privacy Rights Depend on Applicable Law

Depending on the applicable legal framework and the circumstances of processing, individuals may have rights relating to their personal information, including rights concerning access, correction, updating, erasure, consent, or other matters.

Access & Information

You may request information about personal data processed by CDS where such a right is available under applicable law.

Correction

You may request correction or updating of inaccurate personal information, subject to appropriate verification and applicable requirements.

Erasure

You may request deletion or erasure where available under applicable law, subject to legal, contractual, security, or other permitted retention requirements.

Consent Withdrawal

Where processing is based on consent, you may withdraw consent using an appropriate available mechanism, subject to the legal consequences and limitations applicable to that processing.

PRIVACY REQUESTS

How to Submit a Privacy Request

Privacy requests should contain enough information for CDS to understand the request and verify that it relates to the relevant individual or authorised representative.

1. Contact Us

Send your request using the official email, WhatsApp, or other contact details published in this Privacy Policy.

2. Describe the Request

Clearly identify whether you are requesting access, correction, deletion, withdrawal of consent, information about processing, or another privacy-related action.

3. Verification

We may request reasonable information to verify identity or authority before processing a request, particularly where disclosure could affect another person’s privacy or security.

4. Review & Response

Requests will be reviewed and handled within the timeframe and according to the procedures required by applicable law and the circumstances of the request.

CHILDREN & MINORS

Services Are Not Intentionally Directed at Children

CDS does not intentionally design its general business services to target children as a primary audience. Where information relating to a child or minor is provided to CDS in connection with a legitimate service or request, it should be provided only where the relevant parent, guardian, organisation, or other authorised party has the appropriate authority and where applicable requirements are followed.

THIRD-PARTY INFRASTRUCTURE

External Providers May Process Information

Digital services often rely on external infrastructure. Depending on the configuration of a particular service, information may be processed by providers located in India or other jurisdictions.

Hosting & Cloud

Websites, applications, databases, backups, or other systems may rely on hosting and cloud infrastructure operated by third-party providers.

Communication Platforms

Email, WhatsApp, messaging, support, and related communication services may process information according to their own systems and privacy practices.

Analytics & Software

Where enabled, analytics, software, security, CRM, automation, or AI services may process technical or business information required for the relevant functionality.

Payment Providers

Payment transactions may be processed by the relevant payment provider. CDS does not intend to store complete payment-card credentials where the transaction is handled directly by an external payment provider.

SECURITY INCIDENTS

Responding to Data Security Incidents

If CDS becomes aware of a security incident involving personal information under its control, we will assess the incident and take reasonable response measures appropriate to the circumstances, including steps required under applicable law.

Depending on the nature and legal requirements of an incident, this may include investigation, containment, remediation, preservation of relevant records, and notification to affected persons, authorities, or other parties where required.

POLICY UPDATES

Privacy Practices May Change Over Time

We may update this Privacy Policy when our services, technology, processing practices, contractual arrangements, or applicable legal requirements change.

Effective Date

The effective date displayed at the beginning of this policy identifies the version currently published on this page.

Material Changes

Where appropriate, material changes may be highlighted through updated policy information or other reasonable communication mechanisms.

CONTACT & PRIVACY

Privacy Inquiries

For privacy questions, personal-information requests, or concerns regarding the handling of information by CDS, contact us using the official channels below.

POLICY STATUS

Privacy Should Be Clear by Design

This Privacy Policy should be read together with the CDS Cookie Policy, Terms & Conditions, Acceptable Use Policy, Disclaimer, applicable service agreements, and other relevant legal or contractual documents.

Last Updated: 5 September 2026