Legal
Privacy Policy
What personal data we collect, why, who we share it with, how long we keep it, and the rights you have under India’s DPDP Act and United States state privacy laws.
Effective 19 August 2026 · CodeNest Studio
Draft — not yet in force
Company details, registered address and grievance officer are still placeholders, and this document has not been reviewed by a lawyer. Fill in src/content/legal.ts and have counsel read it before relying on it.
1. Two roles, and why the difference matters
We handle personal data in two distinct capacities, and your rights differ depending on which applies.
- As a controller (a "Data Fiduciary" under India’s Digital Personal Data Protection Act, 2023): for our own website visitors, enquiries, quiz respondents and client account holders. We decide why and how that data is used, and this policy governs it.
- As a processor (a "Data Processor"): for the leads and contacts inside a client’s sub-account. That data belongs to our client. We process it on their instructions, and their own privacy notice governs it. If you were contacted by a business using our platform and want your data deleted, contact that business — or write to us and we will route your request to them.
2. What we collect
We collect only what the service needs to work.
- Account data: name, email address, password (stored hashed, never in plain text), company name and role.
- Enquiry and quiz data: name, email, phone number where you give it, industry, and the revenue range you enter to generate a growth score.
- Billing data: plan, invoice history and payment references. Card details are handled by our payment processor and never reach our servers.
- Usage data: pages visited, features used, IP address, browser and device type, and timestamps — used for security, debugging and understanding what the product needs.
- Client integration credentials: API keys and tokens you connect for your own Meta, WhatsApp or voice accounts. These are encrypted at rest with AES-256-GCM and no database policy exposes them for reading — not even to the account that owns them.
- Communications: messages exchanged in the portal, and where automated calling is enabled for a client, call metadata and transcripts.
- We do not knowingly collect data from children under 18. We do not sell personal data, and we do not share it for cross-context behavioural advertising.
3. Why we use it, and on what basis
Under the DPDP Act we rely on your consent, given when you submit a form or create an account, or on legitimate uses the Act recognises. In the United States and elsewhere we rely on the contract with you, our legitimate interests in operating and securing the service, and your consent for marketing communications.
- To provide the service you asked for, including generating your quote and running your campaigns.
- To bill you and keep the tax and accounting records the law requires.
- To secure the platform, investigate abuse and keep an audit trail of administrative actions.
- To contact you about your account. Marketing email is separate, requires opt-in, and every message carries a working unsubscribe.
4. Who we share it with
We share personal data only with the processors that make the service run, each under a contract limiting them to our instructions.
- Supabase (database, authentication and storage) and our hosting provider.
- Anthropic, for the AI features that generate scripts, captions and message drafts.
- Meta and Google, where you run advertising, and WhatsApp Business where messaging is enabled.
- Stripe or an equivalent processor for payments; Cal.com for scheduling; ElevenLabs where voice calling is enabled.
- Professional advisers, and authorities where we are legally required to disclose. We will tell you unless the law forbids it.
5. International transfers
We are based in India and our customers are largely in the United States, so personal data crosses borders in normal operation and may be processed in either country or in the European Union depending on where a provider hosts.
Transfers out of India are made in accordance with the DPDP Act and any restrictions the Central Government notifies. Transfers involving data about people in the United States are made under our contracts with each processor. Where an EU or UK transfer arises, we rely on Standard Contractual Clauses.
6. How long we keep it
We keep personal data only as long as it is needed, then delete or anonymise it.
- Account and client data: for the life of the account, then 90 days, to allow recovery of an account closed in error.
- Invoices and tax records: eight years, as Indian tax law requires.
- Enquiry and quiz submissions that do not become accounts: 24 months.
- Security and audit logs: 12 months.
- Call transcripts and message threads: for the term of the client engagement, then deleted with the sub-account unless the client exports them first.
7. Your rights in India
If you are a Data Principal under the Digital Personal Data Protection Act, 2023, you have the right to access a summary of your personal data and how it is processed; to correct or complete inaccurate data; to erasure; to nominate another person to exercise your rights if you die or become incapacitated; and to a grievance redressal process.
Exercise any of these by writing to privacy@studiocodenest.com. If you are not satisfied with our response, our Grievance Officer is [GRIEVANCE OFFICER NAME] — placeholder, reachable at grievance@studiocodenest.com or at [REGISTERED ADDRESS, CITY, STATE, PIN] — placeholder. We respond within the period the Act prescribes, and in any case without undue delay. You may afterwards complain to the Data Protection Board of India.
The Information Technology Act, 2000 and the SPDI Rules, 2011 continue to apply to sensitive personal data, and we maintain reasonable security practices as those rules require.
8. Your rights in the United States
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas or another state with a comprehensive privacy law, you have the right to know what personal information we have collected and why; to access and obtain a copy of it; to correct inaccuracies; to delete it; and not to be discriminated against for exercising these rights.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no "Do Not Sell or Share My Personal Information" mechanism to operate — but you may still ask us to confirm that.
Submit a request at privacy@studiocodenest.com. We verify identity before acting, respond within 45 days, and may extend once by a further 45 days where the request is complex. You may use an authorised agent. If we deny a request you may appeal by replying to our decision; California residents may also complain to the California Privacy Protection Agency or the Attorney General.
9. Cookies
We use cookies that are strictly necessary — the session cookie that keeps you signed in, and a cookie recording that an agency user is viewing a client sub-account. These cannot be switched off without breaking sign-in.
We do not run third-party advertising or cross-site tracking cookies on this website. If that changes we will publish a cookie notice and ask for consent before setting them.
10. Security, and what happens if it fails
Data is encrypted in transit. Access is enforced at the database level by row-level security, so a client account cannot read another client’s data even if an application bug were to ask for it. Administrative access to a client sub-account is recorded with the actor, time, IP address and browser. Stored third-party credentials are encrypted with AES-256-GCM and tamper-detected.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and affected Data Principals as the DPDP Act requires, and affected individuals and regulators in the United States as state breach-notification laws require.
11. Changes and contact
We will post changes here with a new effective date, and notify account holders by email where the change is material.
Privacy questions and rights requests: privacy@studiocodenest.com. Postal address: [REGISTERED ENTITY NAME] — placeholder, replace before launch, [REGISTERED ADDRESS, CITY, STATE, PIN] — placeholder.