Privacy Policy

Effective Date: 02nd March 2026

1. Introduction

Tudo Technologies Pvt. Ltd. (“Tudo”, “we”, “our”, “us”) processes personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (India) (“DPDPA”) and, in respect of individuals located in the European Union/European Economic Area, as a Controller under the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you visit our website at www.tudotechnologies.com (the “Website”), engage with our products and services, or otherwise interact with us. Rather than applying different standards to different users, this Policy applies the same protections to all users, adopting whichever of the DPDPA or GDPR standards is more protective where the two diverge. This Policy applies to personal data collected through the Website only; personal data Tudo processes on behalf of clients under a service engagement is governed by the applicable Master Services Agreement, Statement of Work, or Data Processing Agreement executed with that client, and not by this Policy.

2. Definitions

“Personal Data” means any data about an identified or identifiable individual, referred to in this Policy as a “Data Principal” (under the DPDPA) or “Data Subject” (under the GDPR), used interchangeably;
“Processing” means any operation performed on personal data, including collection, storage, use, sharing, and erasure;
“Control of Personal Data” is exercised by Tudo as “Data Fiduciary” (DPDPA) or “Controller” (GDPR);
“Processor” means an entity that processes personal data on Tudo’s behalf;
“Consent” means a free, specific, informed, unconditional, and unambiguous indication of the Data Principal’s or Data Subject’s wishes through a clear affirmative action;
“Special Category Data” means personal data revealing racial or ethnic origin, religious or philosophical beliefs, health, biometric or genetic data, or data concerning sex life or sexual orientation.

3. Scope and Territorial Application

This Policy applies to all visitors to and users of the Website, regardless of location, and is designed to meet the requirements of the DPDPA for Data Principals connected to India at all times. The GDPR-specific provisions of this Policy, including Clause 18 (EU Representative and Data Protection Officer), take effect from the point at which Tudo begins to offer services to, or monitor the online behaviour of, individuals located in the EU/EEA within the meaning of Article 3(2) GDPR, for example, on signing Tudo’s first engagement with an EU-based client. From that point, this Policy will be updated to reflect the appointments made under Clause 18. Where the DPDPA and GDPR impose differing obligations on any point and both apply, Tudo applies whichever standard affords the individual greater protection; the rights, security, and breach-notification standards in Clauses 6–15 of this Policy already apply to all visitors regardless of that trigger.

4. Personal Data We Collect

We collect personal data that you voluntarily provide through contact forms, enquiry forms, demo requests, career applications, newsletter subscriptions, or other direct communications with us, including your name, company name, designation, email address, phone number, resume/CV where applicable, and any other information you choose to share. We also automatically collect limited technical data through cookies and similar technologies, including your IP address, browser type, device information, and Website usage patterns, as described in Clause 7 (Cookies and Tracking Technologies) below. We do not intentionally collect Special Category Data through the Website. If you submit Special Category Data to us unsolicited (for example, in a career application), we will process it only with your explicit consent, or delete it, and will not use it beyond the purpose for which it was evidently provided.

5. Purpose and Legal Bases for Processing

We process personal data only for specified, lawful purposes, each supported by an appropriate legal basis: responding to enquiries and providing customer support (necessary to take steps at your request prior to, or in performance of, a contract); processing career applications (consent, or steps necessary prior to a contract of engagement); sending marketing or promotional communications (consent, which you may withdraw at any time); Website security, fraud prevention, and analytics (our legitimate interests in operating a secure and effective Website, balanced against your rights and freedoms); and compliance with legal obligations (necessary to comply with applicable law). Where the DPDPA governs the processing, we additionally rely on Consent as described in Clause 6, or on the specified legitimate uses recognised under the DPDPA, as applicable. We do not process personal data for any purpose beyond what has been disclosed, except where permitted or required by law.

6. Consent Management

Where we rely on Consent, it is obtained through a clear affirmative action — such as ticking a consent box, submitting a form, or accepting a cookie banner — and not through mere browsing of the Website. You may withdraw your Consent at any time, with the same ease with which it was given, by writing to us at the contact details in Clause 19 (or Clause 20). Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal, and we will cease processing (and, where applicable, direct our processors to cease processing) your personal data within a reasonable time following withdrawal, unless retention is otherwise required by law.

7. Cookies and Tracking Technologies

The Website uses cookies and similar technologies, categorised as:

  • (a) Strictly necessary cookies: required for the Website to function;
  • (b) Analytics cookies: (for example, Google Analytics 4) used to understand Website usage; and
  • (c) Marketing cookies: (for example, Google Analytics / Google Ads Remarketing) used to measure and improve marketing effectiveness.

Strictly necessary cookies are placed without consent, as permitted by law. Analytics and marketing cookies are placed only with your prior opt-in consent, given through the cookie consent banner presented on your first visit; you may withdraw or modify this consent at any time through the Website’s cookie preference settings or your browser settings. This opt-in approach applies to all visitors, regardless of location.

8. How We Share Your Information

We do not sell or rent personal data. We may disclose personal data to:

  • (a) Service providers and processors: engaged to operate the Website and deliver our services (for example, cloud hosting, email delivery, analytics, and CRM providers), acting under written instructions and confidentiality obligations;
  • (b) Professional advisors: where necessary for the provision of their services to us;
  • (c) Government or regulatory authorities: where required by law or a valid legal process; and
  • (d) A successor entity: in connection with a merger, acquisition, or sale of assets, subject to equivalent privacy protections.

We require all such recipients to implement appropriate security and confidentiality safeguards, and, where they act as processors, to do so under a written agreement consistent with applicable law.

9. Cross-Border Transfer of Personal Data

We may transfer personal data outside India, and, where applicable, outside the EEA, to service providers described in Clause 8, including providers located in The United States, The United Kingdom, Australia, New Zealand, The United Arab Emirates, and Canada. Where personal data originating in the EEA is transferred to a country not recognised by the European Commission as providing an adequate level of protection (which includes India), we rely on the European Commission’s Standard Contractual Clauses (SCCs) as the transfer mechanism, together with any supplementary measures necessary to ensure an essentially equivalent level of protection. A copy of the relevant SCCs is available on request from our Grievance Officer or EU Representative (Clause 18). For transfers governed solely by the DPDPA, such transfers are made in accordance with the Act, which permits transfer of personal data outside India except to countries restricted by the Central Government by notification.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law, whichever is longer, subject to the following indicative periods:

  • Website enquiry data: 36 months from last contact;
  • Career application data: 24 months from the date of application, unless a longer period is agreed with the applicant;
  • Marketing consent data: until consent is withdrawn.

On expiry of the applicable retention period, or upon withdrawal of Consent where no overriding legal basis for retention exists, we will erase or anonymise the relevant personal data within a reasonable time.

11. Data Security

We implement appropriate technical and organisational measures, including access controls, encryption in transit, and periodic security review, designed to protect personal data against unauthorised access, disclosure, alteration, or loss. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12. Data Protection Impact Assessments

Where a proposed processing activity is likely to result in a high risk to the rights and freedoms of individuals, we will, prior to commencing that processing, carry out a Data Protection Impact Assessment addressing the nature, scope, and risks of the processing and the measures taken to mitigate those risks, and will consult the relevant supervisory authority in advance where required by law.

13. Data Breach Notification

In the event of a personal data breach, we will notify the competent supervisory authority (the Data Protection Board of India and/or the relevant EU supervisory authority, as applicable) without undue delay and, in any event, within 72 hours of becoming aware of the breach where feasible, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. We will document all breaches, including their effects and the remedial action taken.

14. Your Rights

Subject to applicable law, you have the right to:

  • (a) Access: obtain confirmation of, and access to, the personal data we hold about you and the processing carried out;
  • (b) Rectification: request correction or completion of inaccurate or incomplete personal data;
  • (c) Erasure: request erasure of personal data no longer necessary for the purpose for which it was collected, subject to our legal retention obligations;
  • (d) Restriction: request restriction of processing in specified circumstances;
  • (e) Data Portability: receive personal data you have provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means;
  • (f) Objection: object to processing carried out on the basis of legitimate interests, including profiling, on grounds relating to your particular situation, and to object to processing for direct marketing at any time without needing to provide a reason;
  • (g) Withdraw Consent: withdraw Consent at any time, without affecting the lawfulness of processing before withdrawal;
  • (h) Automated Decision-Making: not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, except in limited circumstances and subject to the safeguards in Clause 15;
  • (i) Nomination: nominate another individual to exercise these rights on your behalf in the event of your death or incapacity; and
  • (j) Lodge Complaint: lodge a complaint with the Data Protection Board of India and/or your local EU data protection supervisory authority.

You may exercise these rights by contacting our Grievance Officer or EU Representative at the details in Clause 19.

15. Automated Decision-Making and Profiling

We do not currently make any decision about you based solely on automated processing, including profiling, that produces legal or similarly significant effects. If this changes, we will notify you of the logic involved and the significance and envisaged consequences of such processing, and will provide a mechanism for you to obtain human intervention, express your point of view, and contest the decision.

16. Children’s Data

The Website and our services are not directed at, and are not intended for use by, individuals under the age of 18, which exceeds the minimum age thresholds set under both the DPDPA and GDPR. We do not knowingly collect personal data from children. Where we become aware that we have inadvertently collected personal data from a child without verifiable parental or guardian consent, we will take steps to delete such data promptly. If you believe a child has provided us with personal data, please contact us using the details in Clause 19.

17. Third-Party Websites

The Website may contain links to third-party websites that operate independently of Tudo. We do not control and are not responsible for the privacy practices of such third parties, and encourage you to review their privacy policies before providing personal data to them.

18. EU Representative and Data Protection Officer

In accordance with Article 27 GDPR, Tudo will designate a representative in the European Union, and will appoint a Data Protection Officer, before commencing the offer of services to, or monitoring of, individuals located in the EU (see Clause 3). Once appointed, their contact details will be published in this Clause 18 and made available to supervisory authorities and Data Subjects on request.

19. Grievance Redressal, Supervisory Authorities, and Contact

Any Data Principal or Data Subject with a complaint or query regarding the processing of their personal data or this Policy may contact:

Grievance Officer (India): Arjun G N

Email: privacy@tudotechnologies.com

Address: No.251, 4th Main, KG Nagar, Bangalore-560019, Karnataka, India

EU Representative: To be appointed per Clause 18; until then, direct EU data protection enquiries to the Grievance Officer above.

We will endeavour to respond to and resolve grievances within 30 days of receipt. If you remain unsatisfied with our response, you may escalate your complaint to the Data Protection Board of India or to the EU data protection supervisory authority for your place of habitual residence, place of work, or the place of the alleged infringement.

20. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes affecting the purpose or scope of processing will be accompanied by a request for fresh Consent where required by law. The updated Policy will be published on this page with a revised effective date.