Learn more about DSCI Accredited Privacy Champions Program

Legal

Privacy Policy

Privacy Notice — Privacient · Effective date: 1 September 2025 · Last reviewed: 1 February 2026

Cookie preferences

Choose which cookie categories this browser may set. You can change your mind at any time.

Preference Center

View or withdraw the form consents attached to your email.

Manage preferences

Individual rights

Request access, correction, erasure or nomination, withdraw consent, or raise a grievance about your personal data.

Submit a rights request

This Privacy Notice is provided independently and in clear language before or when Privacient asks you to provide personal data or consent.

This Privacy Notice is provided independently and in clear language before or when Privacient asks you to provide personal data or consent. It explains what personal data we collect, why we collect it, how we use and share it, how long we retain it, and how you can exercise your rights.

1. Who we are

Data Fiduciary: Privacient Private Limited, trading as “Privacient”. Website: https://www.privacient.com. Privacy and grievance contact: Sanyogeeta Gaekwad. Email: contact@privacient.com. Telephone: +91 8007747096.

For Privacient.AI, learning services, DPDP Lens, training, assessments and related services, the same Data Fiduciary applies unless a separate notice identifies another entity.

2. Services covered

This Notice applies to www.privacient.com; Privacient.AI, DPDP Lens, including scan registration, OTP verification, scan results and report downloads; learning.privacient.ai and associated training services; contact, programme, assessment, resource and marketing forms; Calendly booking pages used by Privacient; emails, telephone calls and other communications with Privacient; and resources, PDFs and linked services that refer to this Notice.

Third-party websites such as Calendly, Microsoft Teams, LinkedIn, Instagram, YouTube and external learning or hosting services may have their own notices and cookies.

3. Personal data we collect and why

We collect only the personal data reasonably needed for the applicable purpose.

InteractionData and purpose
Website and resource browsingIP address; browser, operating-system and device details; viewed pages; timestamps; referring page; cookies; server-log information; security identifiers. Purpose: deliver pages, maintain security, prevent abuse, diagnose errors and, where separately permitted, understand website use.
Resource and programme formsFull name; work email; organisation; designation; requested programme or resource; consent and communication preferences; submission date, source page and technical metadata. Purpose: send the requested resource, respond, provide programme information, prepare a proposal and record communication choices.
Contact and call-request formFull name; work email; organisation; preferred time; message; communication records. Purpose: respond, schedule a call, understand requirements and provide requested services.
DPDP Lens website assessmentSubmitted website address; public pages, forms, notices, tags, trackers and consent signals; public DNS, TLS and robots.txt information; scan status, date, time and technical results. Purpose: run the requested outside-in assessment and produce the report.
DPDP Lens registration and reportName; work email; organisation; role; industry; website URL; OTP or email verification; authorisation confirmation; confidentiality choice; report-delivery and marketing choices; assessment report. Purpose: verify the requester, run the scan, send the report and manage preferences.
Privacient.AI demoFull name; email; organisation; designation; jurisdiction; comment; privacy-notice acknowledgement and optional communications choice. Purpose: respond to the demo request and send communications only where separately authorised.
Preference centreEmail address; communication preferences; consent status; consent receipt; withdrawal or unsubscribe information. Purpose: manage communication choices and maintain an accurate consent record.
Calendly and meetingsName; email; meeting date, time and time zone; guest details if added; preparation response; booking and cancellation information; technical and cookie information. Purpose: schedule and conduct the meeting.
Learning and trainingUsername or email; account and login information; course enrolment and progress; assessments; downloads; certificates; support communications; location or device information only where actually collected. Purpose: provide training, maintain completion records, issue certificates and provide support.
Direct communications and supportContact details; email, phone, chat or call content and records; information voluntarily provided. Purpose: respond, provide support, maintain business records and handle complaints.
Resources and PDFsTechnical download and server-log information. No direct form is required for ungated resources. Purpose: deliver the resource and protect the service.
Marketing communicationsEmail address; organisation; role; marketing choice; campaign interaction; unsubscribe or withdrawal status. Purpose: send marketing only where separately authorised.

4. Sources of personal data

  • Directly from you.
  • Automatically from your browser, device and interaction with our services.
  • From your organisation or an authorised representative.
  • From service providers used to schedule meetings, manage consent, operate learning services or deliver communications.
  • From publicly accessible website information when you request a DPDP Lens assessment.

5. Why we are permitted to process personal data

  • To provide a service or resource you request.
  • Based on your consent where consent is requested.
  • To send marketing only where you have separately opted in.
  • For security, fraud prevention, service integrity and technical operations.
  • To comply with applicable legal obligations.
  • To respond to rights requests and complaints.
  • For other purposes permitted as legitimate uses under applicable Indian law.

Where consent is the basis, we will record the purpose, notice version, time, source, choice and, where applicable, the consent withdrawal.

6. Consent and withdrawal

You may withdraw consent at any time by using the following channels:

The withdrawal method must be no more difficult than the method used to give consent. Withdrawal does not affect processing carried out lawfully before withdrawal. If you withdraw consent required to provide a particular optional service, we may no longer be able to provide that service or send the requested communication. We will stop the relevant processing and delete or anonymise the personal data unless continued retention or processing is required or permitted by law.

7. Your Data Principal rights

  1. Obtain a summary of the personal data we process about you.
  2. Obtain information about processing activities and the Data Fiduciaries or Processors with whom your data has been shared.
  3. Request correction, completion or updating of inaccurate, incomplete or outdated personal data.
  4. Request erasure where the data is no longer required for the specified purpose or where law permits.
  5. Withdraw consent.
  6. Raise a grievance with us.
  7. Nominate another person to exercise your rights in the event of your death or incapacity.
  8. Complain to the Data Protection Board after using our grievance mechanism.

Submit a Data Principal Rights/Access Request through: DPAR form: https://www.privacient.com/individual-rights. You may also email contact@privacient.com. We may verify your identity and authority before responding. Please provide accurate information and do not impersonate another person or submit a false or frivolous request.

8. Grievance redressal

Grievance officer or authorised contact: Sanyogeeta Gaekwad. Email: contact@privacient.com. Expected response period: 90 Days. If you are not satisfied after using our grievance process, you may complain to the Data Protection Board of India.

9. Recipients and service providers

  • Privacient employees and authorised contractors.
  • Website, cloud, hosting and email providers.
  • TrustArc for consent, preference and consent-receipt management.
  • Calendly for meeting scheduling.
  • Microsoft Teams for meetings.
  • The learning-platform, Moodle and related hosting providers.
  • Security, monitoring, backup and technical-support providers.
  • Content-delivery, font and infrastructure providers used on particular pages.
  • Certification partners where a certificate is requested.
  • Professional advisers, auditors and insurers.
  • Public authorities, courts or law-enforcement bodies where legally required.
  • A purchaser or successor in a merger, acquisition, restructuring or transfer of business.

We do not permit service providers to use personal data for their own unrelated purposes.

10. International processing

Some service providers may process personal data outside India, including in the United States or other countries where those providers operate. We will apply the safeguards, contractual requirements and transfer restrictions required by applicable law and will update the service-provider list when providers change.

11. Retention and deletion

We retain personal data only for as long as needed for the specified purpose, to provide the relevant service, to establish or defend legal claims, to comply with law, or to maintain evidence of consent and rights handling.

  • DPDP Lens report-registration information: 24 months from the last interaction, after which it is deleted or anonymised unless a longer period is legally required.
  • Consent, withdrawal and unsubscribe records: for the period reasonably necessary to demonstrate and administer choices and comply with law.
  • Contact, lead and marketing records: until the purpose ends, marketing is withdrawn or the approved retention period expires.
  • Learning, course and certification records: for the account, course, certificate and legal-retention period approved for that service.
  • Security and technical logs: for the security, incident-response and legal period applicable to the relevant system.

When personal data is no longer required, we will delete, anonymise or securely dispose of it and require relevant Processors to do the same where applicable.

12. Cookies and similar technologies

We use strictly necessary cookies, server logs and similar technologies for security, session management, authentication, preference management and service operation. Optional analytics, advertising, personalisation, replay or similar technologies will be disclosed in the Cookie Notice (https://www.privacient.com/privacy-policy#cookies) and activated only after the required choice or consent. Calendly, Privacient.AI, the learning platform and other third-party services may use their own cookies and technologies under their own notices.

13. Security and personal-data breaches

We use reasonable technical, organisational and administrative safeguards appropriate to the nature of the personal data and the risks of processing. These may include access controls, encryption or masking where appropriate, logging, monitoring, backups, incident response, vendor controls and secure deletion. If a personal-data breach occurs, we will notify affected Data Principals and the Data Protection Board in the form and within the time required by applicable law.

14. Children

Our public business websites and services are not directed to children under 18. We do not knowingly request personal data from children through ordinary business forms. If a service is intentionally offered to children, we will implement the required age and parental-verification controls and will not use children’s data for harmful processing, behavioural tracking or targeted advertising where prohibited by law. If you believe a child has provided personal data, contact us at contact@privacient.com.

15. Automated decision-making and profiling

We do not currently make automated decisions that produce legal or similarly significant effects about you. If this changes, we will update this Notice before introducing that processing and explain the relevant purpose and consequences.

16. Third-party links

Our website may link to third-party websites, social-media pages, booking services, learning services or video platforms. Their processing is governed by their own notices. We recommend reviewing those notices before submitting personal data.

17. Changes to this Notice

We may update this Notice when our services, data collection, recipients, technology or legal obligations change. We will publish the updated version with a new “Last reviewed” date and provide any additional communication required by law.

18. Language

This Notice is available in English and Hindi. You may select your preferred language using the language control on the website. The English and Hindi versions are intended to communicate the same information.