Bodhrik

Legal

Privacy Policy

How Bodhrik Technologies Private Limited collects, uses, and protects your personal data — aligned with India's Digital Personal Data Protection Act, 2023.

Effective: May 1, 2026·Last updated: August 7, 2026
1.

Introduction

Effective date: May 1, 2026

This Privacy Policy explains how Bodhrik Technologies Private Limited ("Bodhrik," "we," "us") collects, uses, discloses, and protects personal data in connection with our products, services, consulting engagements, and website. This policy applies to clients, prospective clients, website visitors, job applicants, and any other individuals whose personal data we process.

2.

What personal data we collect

We may collect the following categories of personal data, depending on how you interact with us:

  • Contact and identity informationname, email address, phone number, job title, company name.
  • Account and engagement informationinformation provided when you engage us for products, services, or consulting, including business context necessary to deliver that engagement.
  • Website usage informationinformation collected through cookies and similar technologies (see our Cookie Notice for detail).
  • Job application informationresume, work history, and related information, if you apply for a role with us.
  • Data processed on behalf of clientswhere we act as a data processor for a client (for example, operating a client's platform or product), we process personal data strictly according to that client's instructions and our contractual agreement with them.
3.

Why we collect and use personal data

We collect and use personal data for the following purposes:

  • To deliver the products, services, consulting engagements, or talent placements you have engaged us for.
  • To respond to inquiries and communicate with prospective and existing clients.
  • To evaluate and process job applications.
  • To meet legal, regulatory, and contractual obligations.
  • To improve our products and services, and to maintain the security of our systems.

We do not use personal data for purposes incompatible with the purpose for which it was originally collected, consistent with the DPDP Act's purpose-limitation principle.

4.

Our lawful basis for processing

Where required, we obtain your consent before collecting or processing your personal data, and you have the right to withdraw that consent at any time. Where we process personal data on behalf of a client, we do so under that client's instructions and their own lawful basis for that processing.

5.

How we use AI in connection with your data

Your personal data is not used to train, fine-tune, or otherwise improve Bodhrik's own AI systems, or any third-party AI system we use, unless you have separately and explicitly consented to that as part of a specific engagement. Where our team uses AI tools internally — for example, to accelerate drafting or analysis work on your engagement — that use stays within our own delivery process and does not mean your data is used to train a third party's underlying model beyond the ordinary terms of that tool's own data-handling policy. If this ever changes for a specific product or service, we will disclose it clearly and seek your consent before it applies to you.

6.

Data sharing and sub-processors

We may share personal data with the following categories of third parties:

  • Sub-processors and service providers who help us deliver our products and services (see current list below).
  • Regulators, law enforcement, or other authorities, where required by law.
  • A successor entity, in the event of a merger, acquisition, or sale of assets.

We do not sell personal data to third parties.

Current sub-processor list:

CategoryVendorData touched
Website hostingMicrosoft Azure (Static Web Apps)Website traffic, form submissions
AnalyticsGoogle AnalyticsVisitor behaviour, no personal identifiers unless login-gated
Email / contact formBodhrik's own internal API (self-hosted)Name, email, message content
Engagement trackingGoogle Workspace (Sheets, Drive, Apps Script)Client documents, GAP assessments — internal delivery tooling

All sub-processors are bound by written data protection and confidentiality terms. We commit to updating this page whenever the list changes materially.

7.

Data retention

We retain personal data collected through this website and in the course of client engagements for as long as necessary to fulfil the purpose for which it was collected, and thereafter for a period of 3 years from the completion or termination of the engagement, to meet legal, accounting, audit, or dispute-resolution requirements — unless a longer retention period is required by applicable law. Data is securely deleted or anonymised thereafter.

8.

Your rights under the DPDP Act

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Request correction or completion of inaccurate or incomplete personal data.
  • Request erasure of your personal data, where applicable.
  • Withdraw consent for processing, where consent is the basis for that processing.
  • Nominate another individual to exercise your rights on your behalf, in the event of your death or incapacity.
  • Lodge a grievance regarding the handling of your personal data.

To exercise any of these rights, contact our Grievance Officer at swati.bande@bodhrik.com or +91 88550 44332.

9.

Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023, Bodhrik Technologies Pvt Ltd has appointed a Grievance Officer to address any queries, concerns, or grievances relating to the processing of your personal data.

Grievance Officer
Swati Bande

Email: swati.bande@bodhrik.com

Phone: +91 88550 44332

We will acknowledge grievances within 2 business days and aim to resolve them within 30 days of receipt. If you are not satisfied with our response, you may approach the Data Protection Board of India.

10.

Data security

We maintain reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or destruction. See our Trust & Security page for more detail on our security practices.

11.

Data breach notification

In the event of a personal data breach that is likely to affect you, we will notify you and, where applicable, the Data Protection Board of India, within 72 hours of confirming the breach, describing its nature, likely consequences, and the measures taken or proposed to mitigate its effects.

12.

Cross-border data transfers

Where personal data is transferred outside India, we take steps to ensure that data receives an equivalent level of protection, consistent with DPDP Act requirements and any applicable government restrictions on cross-border transfer.

13.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised effective date.

14.

Contact us

Questions about this Privacy Policy can be directed to: legal@bodhrik.com

Registered address:
3E4, 4022, SOBHA WINDSOR, PH-2, VIJAYANAGARA,
Whitefield, Bangalore South, Bangalore – 560066, Karnataka.

Related policies