Privacy Policy
We take your privacy seriously. This policy explains exactly what personal data we collect when you visit networkz.in, why we collect it, how we protect it, and the rights available to you.
1. Introduction
Welcome to Networkz. This Privacy Policy explains how NETWORKZ ("Networkz", "we", "us", or "our"), a Sole Proprietorship established under the laws of India with MSME Udyam Registration Number UDYAM-MH-18-0561547, collects, uses, stores, and protects personal information when you visit networkz.in or communicate with us.
We are committed to handling personal data responsibly, lawfully, and transparently, in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, where applicable to international visitors, the principles of the General Data Protection Regulation (GDPR).
By using this website, you acknowledge that you have read and understood this policy. If you do not agree, please do not use the website.
2. Who We Are
| Business Name | NETWORKZ (trading as "Networkz") |
| Registration | MSME Udyam Registration No. UDYAM-MH-18-0561547 |
| Address | Malad West, Mumbai Suburban, Maharashtra 400095, India |
| hello@networkz.in | |
| Phone | +91 86555 46603 |
| Website | https://networkz.in |
For the purposes of data protection law, Networkz is the Data Fiduciary (as defined under the DPDP Act) and, where applicable, the Data Controller (as defined under the GDPR) in respect of personal data processed through this website.
3. Data We Collect
3.1 Data you provide directly
When you submit the contact form on networkz.in, you provide:
- Full name
- Business / company name (optional)
- Email address
- Phone number
- Service of interest (selected from a list)
- Budget range (optional)
- Timeline preference (optional)
- Project description (free text)
When you contact us via WhatsApp, you provide your phone number and the content of your messages. WhatsApp is operated by Meta Platforms Ireland Limited; messages sent via WhatsApp are subject to WhatsApp's own privacy policy in addition to ours.
When you contact us by email, you provide your email address and the content of your message.
3.2 Data collected automatically
When you visit networkz.in, our hosting and content-delivery infrastructure automatically records certain technical data, including:
- Your IP address (may be truncated or anonymised at the edge)
- Browser type and version
- Operating system
- Referring URL
- Pages visited and timestamps
- HTTP request and response data
This data is collected by our infrastructure providers (Vercel and Cloudflare) as a necessary part of delivering the website. We do not add any analytics or tracking scripts of our own.
3.3 Data we do not collect
We do not collect:
- Payment card details (we accept bank transfers and UPI only; no card data passes through our systems)
- Sensitive personal data (health, religion, political views, biometrics, etc.)
- Location data beyond what is inferred from an IP address
- Data from social media pixels (we do not use Meta Pixel, LinkedIn Insight Tag, or similar)
- Data from advertising networks
4. How We Collect Data
- Contact form: data is submitted directly to our server-side API and stored in a managed database (Prisma-managed PostgreSQL on a cloud host).
- Email: we receive your email address and message content when you email us directly.
- WhatsApp: we receive your phone number and message content through the WhatsApp Business platform.
- Automatically (server/edge logs): IP and request metadata are logged by Vercel and Cloudflare as standard infrastructure operation.
5. Why We Collect It — Purposes of Processing
| Purpose | Data Used |
|---|---|
| Respond to your enquiry or project request | Name, email, phone, service, message |
| Assess your project requirements and prepare a proposal | All contact form fields |
| Communicate about your project (if you become a client) | Contact details, project communications |
| Detect and prevent automated abuse (bot filtering, spam) | IP address, submission timing, honeypot field |
| Maintain the security and reliability of the website | IP address, request metadata, edge logs |
| Comply with legal obligations | As required by applicable law |
We do not use your data for marketing, advertising, profiling, or sale to third parties.
6. Legal Basis for Processing
Under the DPDP Act 2023, we process personal data on the basis of consent (provided when you submit the contact form) and legitimate use for the purposes described above.
For individuals in the EEA or UK, the legal bases under the GDPR are:
- Legitimate interests (Art. 6(1)(f)) — for responding to your enquiry, security monitoring, and fraud prevention. Our legitimate interests are outweighed in these cases by the reasonable expectations of a visitor making a business enquiry.
- Performance of a contract or pre-contractual steps (Art. 6(1)(b)) — when you request a proposal or enter into a client engagement.
- Legal obligation (Art. 6(1)(c)) — where required by applicable law.
7. Data Minimisation
We collect only the personal data that is necessary for the purposes described in this policy. Fields such as "Budget Range" and "Timeline" are optional on our contact form. We periodically review the data we hold and delete information that is no longer necessary.
8. Retention Schedule
| Category | Retention Period | Rationale |
|---|---|---|
| Contact form enquiries (no engagement) | 12 months from submission | To allow follow-up if the prospect re-engages |
| Contact form enquiries (engagement commenced) | Duration of project + 3 years | Commercial record-keeping |
| Project communications (email, WhatsApp) | Duration of project + 3 years | Dispute resolution and record-keeping |
| Vercel server/edge logs | Up to 30 days (Vercel platform default) | Security monitoring and debugging |
| Cloudflare edge logs | Up to 72 hours to 30 days (Cloudflare defaults) | DDoS protection and security |
| Upstash Redis (rate-limit counters) | Up to 60 seconds per counter (TTL-based) | Spam and abuse prevention |
On expiry of the applicable retention period, data is securely deleted or anonymised so that it can no longer be associated with an identifiable individual.
9. Third-Party Subprocessors
We use the following third-party services to operate this website. Each is bound by its own privacy policy and, where applicable, by a data processing agreement.
| Subprocessor | Role | Data Transferred | Location |
|---|---|---|---|
| Vercel Inc. | Website hosting & server-side API execution | All website traffic data, contact form data, server logs | USA (with edge nodes globally) |
| Cloudflare Inc. | CDN, DDoS protection, TLS termination, DNS | IP address, request metadata | USA / Global edge network |
| Resend Inc. | Transactional email delivery (we receive your enquiry by email) | Your name, email address, message content | USA |
| Upstash Inc. | Redis-based rate limiting on form submissions | Hashed IP address (rate-limit counter key only) | EU (where available) / USA |
We do not sell, rent, or share your personal data with any other third party except as required by law or with your explicit consent.
10. International Transfers
Our infrastructure providers (Vercel, Cloudflare, Resend) are headquartered in the United States. This means that your personal data may be transferred to and processed in the United States or other countries outside India.
For transfers of personal data from the European Economic Area (EEA) or the United Kingdom to the USA, these providers rely on Standard Contractual Clauses (SCCs) as approved by the European Commission, or equivalent UK transfer mechanisms, to provide appropriate safeguards.
We take reasonable steps to ensure that our subprocessors maintain adequate data protection standards. You may request information about the safeguards in place by contacting us at hello@networkz.in.
11. Automated Decision-Making and Profiling
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.
Our contact form uses automated signals (submission timing, a honeypot field, and IP-based rate limiting) to detect and filter bot submissions. These signals are supplementary checks only; no legitimate enquiry is rejected based solely on automated scoring without human review.
12. Cookies and Similar Technologies
We use a limited number of strictly necessary cookies to operate this website. We do not currently use any analytics, advertising, or tracking cookies. For full details, please read our Cookie Policy.
13. Data Security Measures
We implement the following technical and organisational security measures:
- Encryption in transit: All data transmitted to and from networkz.in is protected by HTTPS with TLS 1.3.
- Encryption at rest: Data stored in our managed database is encrypted at rest by the hosting provider.
- Access controls: Access to contact submissions and the admin panel is restricted by JWT-based authentication and role-based access controls.
- Rate limiting: All public form endpoints are protected by Redis-based rate limiting to prevent abuse.
- Dependency management: We regularly audit dependencies for known vulnerabilities.
- No payment data storage: We accept only bank transfer and UPI payments; no payment card data is processed or stored on our systems.
- Secrets management: Credentials and API keys are stored as environment variables; never in source code.
No method of transmission or storage is 100% secure. In the event of a data breach, we will take appropriate steps as described in Section 14.
14. Data Breach Notification
In the event we become aware of a personal data breach that is likely to affect your rights and interests, we will:
- Notify affected individuals without undue delay once the breach has been contained and its scope understood.
- Provide information about the nature of the breach, the data affected, the likely consequences, and the steps we are taking.
- Where required, notify the relevant data protection authority within the timeframes prescribed by applicable law (e.g., 72 hours under the GDPR for reportable breaches; as required under the DPDP Act).
Breach notifications will be sent to the email address you have provided, or via the most appropriate channel available.
15. Lawful Requests from Authorities
We may disclose personal data to law enforcement, courts, regulatory bodies, or other government authorities where we are legally required to do so, or where we have a good-faith belief that disclosure is necessary to:
- comply with a legal obligation;
- protect the rights, property, or safety of Networkz, our clients, or the public;
- prevent or investigate suspected fraud, illegal activity, or a threat to security.
Where permitted by law, we will attempt to notify you before complying with such a request so that you may seek appropriate legal relief.
16. Your Rights Under the DPDP Act 2023 (India)
Under India's Digital Personal Data Protection Act, 2023, you have the following rights in relation to your personal data:
| Right | What it means |
|---|---|
| Right of Access | You may request a summary of the personal data we hold about you and the purposes for which it is processed. |
| Right to Correction | You may request correction of inaccurate or incomplete personal data. |
| Right to Erasure | You may request deletion of your personal data where we no longer need it for the purposes for which it was collected, subject to legal retention obligations. |
| Right to Grievance Redressal | You may raise a grievance with us and we will respond within a reasonable period. |
| Right to Nominate | You may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity. |
17. Additional Rights for EEA and UK Individuals (GDPR)
If you are located in the European Economic Area or the United Kingdom, you have the following additional rights under the GDPR or UK GDPR:
- Right to restriction: You may ask us to restrict processing of your data in certain circumstances.
- Right to data portability: You may request a copy of your data in a structured, machine-readable format.
- Right to object: You may object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
- Right to lodge a complaint: You have the right to lodge a complaint with your national data protection supervisory authority (e.g., the Information Commissioner's Office in the UK, or the relevant EEA supervisory authority).
18. How to Exercise Your Rights
To exercise any of the rights described above, or to raise a data protection concern, please contact us at:
We will acknowledge your request within 5 business days and respond substantively within 30 days (or within the period required by applicable law). We may ask you to verify your identity before processing your request.
We do not charge a fee for reasonable requests. If a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline to act, with reasons.
19. Children's Privacy
Our services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have collected personal data from a minor, we will delete it promptly. If you believe we have inadvertently collected such data, please contact us immediately.
20. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Continued use of the website after a policy update constitutes acceptance of the revised policy. If you disagree with any changes, please stop using the website and contact us to request deletion of your data.
21. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, please contact: