Legal
Privacy Policy
How Bodhrik Technologies Private Limited collects, uses, and protects your personal data — aligned with India's Digital Personal Data Protection Act, 2023.
Introduction
Effective date: May 1, 2026
This Privacy Policy explains how Bodhrik Technologies Private Limited ("Bodhrik," "we," "us") collects, uses, discloses, and protects personal data in connection with our products, services, consulting engagements, and website. This policy applies to clients, prospective clients, website visitors, job applicants, and any other individuals whose personal data we process.
What personal data we collect
We may collect the following categories of personal data, depending on how you interact with us:
- Contact and identity information — name, email address, phone number, job title, company name.
- Account and engagement information — information provided when you engage us for products, services, or consulting, including business context necessary to deliver that engagement.
- Website usage information — information collected through cookies and similar technologies (see our Cookie Notice for detail).
- Job application information — resume, work history, and related information, if you apply for a role with us.
- Data processed on behalf of clients — where we act as a data processor for a client (for example, operating a client's platform or product), we process personal data strictly according to that client's instructions and our contractual agreement with them.
Why we collect and use personal data
We collect and use personal data for the following purposes:
- To deliver the products, services, consulting engagements, or talent placements you have engaged us for.
- To respond to inquiries and communicate with prospective and existing clients.
- To evaluate and process job applications.
- To meet legal, regulatory, and contractual obligations.
- To improve our products and services, and to maintain the security of our systems.
We do not use personal data for purposes incompatible with the purpose for which it was originally collected, consistent with the DPDP Act's purpose-limitation principle.
Our lawful basis for processing
Where required, we obtain your consent before collecting or processing your personal data, and you have the right to withdraw that consent at any time. Where we process personal data on behalf of a client, we do so under that client's instructions and their own lawful basis for that processing.
How we use AI in connection with your data
Your personal data is not used to train, fine-tune, or otherwise improve Bodhrik's own AI systems, or any third-party AI system we use, unless you have separately and explicitly consented to that as part of a specific engagement. Where our team uses AI tools internally — for example, to accelerate drafting or analysis work on your engagement — that use stays within our own delivery process and does not mean your data is used to train a third party's underlying model beyond the ordinary terms of that tool's own data-handling policy. If this ever changes for a specific product or service, we will disclose it clearly and seek your consent before it applies to you.
Data sharing and sub-processors
We may share personal data with the following categories of third parties:
- Sub-processors and service providers who help us deliver our products and services (see current list below).
- Regulators, law enforcement, or other authorities, where required by law.
- A successor entity, in the event of a merger, acquisition, or sale of assets.
We do not sell personal data to third parties.
Current sub-processor list:
| Category | Vendor | Data touched |
|---|---|---|
| Website hosting | Microsoft Azure (Static Web Apps) | Website traffic, form submissions |
| Analytics | Google Analytics | Visitor behaviour, no personal identifiers unless login-gated |
| Email / contact form | Bodhrik's own internal API (self-hosted) | Name, email, message content |
| Engagement tracking | Google Workspace (Sheets, Drive, Apps Script) | Client documents, GAP assessments — internal delivery tooling |
All sub-processors are bound by written data protection and confidentiality terms. We commit to updating this page whenever the list changes materially.
Data retention
We retain personal data collected through this website and in the course of client engagements for as long as necessary to fulfil the purpose for which it was collected, and thereafter for a period of 3 years from the completion or termination of the engagement, to meet legal, accounting, audit, or dispute-resolution requirements — unless a longer retention period is required by applicable law. Data is securely deleted or anonymised thereafter.
Your rights under the DPDP Act
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Request correction or completion of inaccurate or incomplete personal data.
- Request erasure of your personal data, where applicable.
- Withdraw consent for processing, where consent is the basis for that processing.
- Nominate another individual to exercise your rights on your behalf, in the event of your death or incapacity.
- Lodge a grievance regarding the handling of your personal data.
To exercise any of these rights, contact our Grievance Officer at swati.bande@bodhrik.com or +91 88550 44332.
Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023, Bodhrik Technologies Pvt Ltd has appointed a Grievance Officer to address any queries, concerns, or grievances relating to the processing of your personal data.
We will acknowledge grievances within 2 business days and aim to resolve them within 30 days of receipt. If you are not satisfied with our response, you may approach the Data Protection Board of India.
Data security
We maintain reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, or destruction. See our Trust & Security page for more detail on our security practices.
Data breach notification
In the event of a personal data breach that is likely to affect you, we will notify you and, where applicable, the Data Protection Board of India, within 72 hours of confirming the breach, describing its nature, likely consequences, and the measures taken or proposed to mitigate its effects.
Cross-border data transfers
Where personal data is transferred outside India, we take steps to ensure that data receives an equivalent level of protection, consistent with DPDP Act requirements and any applicable government restrictions on cross-border transfer.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised effective date.
Contact us
Questions about this Privacy Policy can be directed to: legal@bodhrik.com
Registered address:
3E4, 4022, SOBHA WINDSOR, PH-2, VIJAYANAGARA,
Whitefield, Bangalore South, Bangalore – 560066, Karnataka.
Related policies