Tudo Technologies Pvt. Ltd. (“Tudo”, “we”, “our”, “us”) processes personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (India) (“DPDPA”) and, in respect of individuals located in the European Union/European Economic Area, as a Controller under the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit our website at www.tudotechnologies.com (the “Website”), engage with our products and services, or otherwise interact with us. Rather than applying different standards to different users, this Policy applies the same protections to all users, adopting whichever of the DPDPA or GDPR standards is more protective where the two diverge. This Policy applies to personal data collected through the Website only; personal data Tudo processes on behalf of clients under a service engagement is governed by the applicable Master Services Agreement, Statement of Work, or Data Processing Agreement executed with that client, and not by this Policy.
“Personal Data” means any data about an identified or identifiable individual, referred to in this Policy as a “Data Principal” (under the DPDPA) or “Data Subject” (under the GDPR), used interchangeably;
“Processing” means any operation performed on personal data, including collection, storage, use, sharing, and erasure;
“Control of Personal Data” is exercised by Tudo as “Data Fiduciary” (DPDPA) or “Controller” (GDPR);
“Processor” means an entity that processes personal data on Tudo’s behalf;
“Consent” means a free, specific, informed, unconditional, and unambiguous indication of the Data Principal’s or Data Subject’s wishes through a clear affirmative action;
“Special Category Data” means personal data revealing racial or ethnic origin, religious or philosophical beliefs, health, biometric or genetic data, or data concerning sex life or sexual orientation.
This Policy applies to all visitors to and users of the Website, regardless of location, and is designed to meet the requirements of the DPDPA for Data Principals connected to India at all times. The GDPR-specific provisions of this Policy, including Clause 18 (EU Representative and Data Protection Officer), take effect from the point at which Tudo begins to offer services to, or monitor the online behaviour of, individuals located in the EU/EEA within the meaning of Article 3(2) GDPR, for example, on signing Tudo’s first engagement with an EU-based client. From that point, this Policy will be updated to reflect the appointments made under Clause 18. Where the DPDPA and GDPR impose differing obligations on any point and both apply, Tudo applies whichever standard affords the individual greater protection; the rights, security, and breach-notification standards in Clauses 6–15 of this Policy already apply to all visitors regardless of that trigger.
We collect personal data that you voluntarily provide through contact forms, enquiry forms, demo requests, career applications, newsletter subscriptions, or other direct communications with us, including your name, company name, designation, email address, phone number, resume/CV where applicable, and any other information you choose to share. We also automatically collect limited technical data through cookies and similar technologies, including your IP address, browser type, device information, and Website usage patterns, as described in Clause 7 (Cookies and Tracking Technologies) below. We do not intentionally collect Special Category Data through the Website. If you submit Special Category Data to us unsolicited (for example, in a career application), we will process it only with your explicit consent, or delete it, and will not use it beyond the purpose for which it was evidently provided.
We process personal data only for specified, lawful purposes, each supported by an appropriate legal basis: responding to enquiries and providing customer support (necessary to take steps at your request prior to, or in performance of, a contract); processing career applications (consent, or steps necessary prior to a contract of engagement); sending marketing or promotional communications (consent, which you may withdraw at any time); Website security, fraud prevention, and analytics (our legitimate interests in operating a secure and effective Website, balanced against your rights and freedoms); and compliance with legal obligations (necessary to comply with applicable law). Where the DPDPA governs the processing, we additionally rely on Consent as described in Clause 6, or on the specified legitimate uses recognised under the DPDPA, as applicable. We do not process personal data for any purpose beyond what has been disclosed, except where permitted or required by law.
Where we rely on Consent, it is obtained through a clear affirmative action — such as ticking a consent box, submitting a form, or accepting a cookie banner — and not through mere browsing of the Website. You may withdraw your Consent at any time, with the same ease with which it was given, by writing to us at the contact details in Clause 19 (or Clause 20). Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal, and we will cease processing (and, where applicable, direct our processors to cease processing) your personal data within a reasonable time following withdrawal, unless retention is otherwise required by law.
The Website uses cookies and similar technologies, categorised as:
Strictly necessary cookies are placed without consent, as permitted by law. Analytics and marketing cookies are placed only with your prior opt-in consent, given through the cookie consent banner presented on your first visit; you may withdraw or modify this consent at any time through the Website’s cookie preference settings or your browser settings. This opt-in approach applies to all visitors, regardless of location.
We do not sell or rent personal data. We may disclose personal data to:
We require all such recipients to implement appropriate security and confidentiality safeguards, and, where they act as processors, to do so under a written agreement consistent with applicable law.
We may transfer personal data outside India, and, where applicable, outside the EEA, to service providers described in Clause 8, including providers located in The United States, The United Kingdom, Australia, New Zealand, The United Arab Emirates, and Canada. Where personal data originating in the EEA is transferred to a country not recognised by the European Commission as providing an adequate level of protection (which includes India), we rely on the European Commission’s Standard Contractual Clauses (SCCs) as the transfer mechanism, together with any supplementary measures necessary to ensure an essentially equivalent level of protection. A copy of the relevant SCCs is available on request from our Grievance Officer or EU Representative (Clause 18). For transfers governed solely by the DPDPA, such transfers are made in accordance with the Act, which permits transfer of personal data outside India except to countries restricted by the Central Government by notification.
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law, whichever is longer, subject to the following indicative periods:
On expiry of the applicable retention period, or upon withdrawal of Consent where no overriding legal basis for retention exists, we will erase or anonymise the relevant personal data within a reasonable time.
We implement appropriate technical and organisational measures, including access controls, encryption in transit, and periodic security review, designed to protect personal data against unauthorised access, disclosure, alteration, or loss. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Where a proposed processing activity is likely to result in a high risk to the rights and freedoms of individuals, we will, prior to commencing that processing, carry out a Data Protection Impact Assessment addressing the nature, scope, and risks of the processing and the measures taken to mitigate those risks, and will consult the relevant supervisory authority in advance where required by law.
In the event of a personal data breach, we will notify the competent supervisory authority (the Data Protection Board of India and/or the relevant EU supervisory authority, as applicable) without undue delay and, in any event, within 72 hours of becoming aware of the breach where feasible, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. We will document all breaches, including their effects and the remedial action taken.
Subject to applicable law, you have the right to:
You may exercise these rights by contacting our Grievance Officer or EU Representative at the details in Clause 19.
We do not currently make any decision about you based solely on automated processing, including profiling, that produces legal or similarly significant effects. If this changes, we will notify you of the logic involved and the significance and envisaged consequences of such processing, and will provide a mechanism for you to obtain human intervention, express your point of view, and contest the decision.
The Website and our services are not directed at, and are not intended for use by, individuals under the age of 18, which exceeds the minimum age thresholds set under both the DPDPA and GDPR. We do not knowingly collect personal data from children. Where we become aware that we have inadvertently collected personal data from a child without verifiable parental or guardian consent, we will take steps to delete such data promptly. If you believe a child has provided us with personal data, please contact us using the details in Clause 19.
The Website may contain links to third-party websites that operate independently of Tudo. We do not control and are not responsible for the privacy practices of such third parties, and encourage you to review their privacy policies before providing personal data to them.
In accordance with Article 27 GDPR, Tudo will designate a representative in the European Union, and will appoint a Data Protection Officer, before commencing the offer of services to, or monitoring of, individuals located in the EU (see Clause 3). Once appointed, their contact details will be published in this Clause 18 and made available to supervisory authorities and Data Subjects on request.
Any Data Principal or Data Subject with a complaint or query regarding the processing of their personal data or this Policy may contact:
Grievance Officer (India): Arjun G N
Email: privacy@tudotechnologies.com
Address: No.251, 4th Main, KG Nagar, Bangalore-560019, Karnataka, India
EU Representative: To be appointed per Clause 18; until then, direct EU data protection enquiries to the Grievance Officer above.
We will endeavour to respond to and resolve grievances within 30 days of receipt. If you remain unsatisfied with our response, you may escalate your complaint to the Data Protection Board of India or to the EU data protection supervisory authority for your place of habitual residence, place of work, or the place of the alleged infringement.
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes affecting the purpose or scope of processing will be accompanied by a request for fresh Consent where required by law. The updated Policy will be published on this page with a revised effective date.