Legal
Privacy policy
This policy explains what personal data Perspec Technologies Private Limited collects through this website, why we collect it, who we share it with and what rights you have over it. It covers this website only. Data we process for a client under a services agreement is governed by that agreement.
Who we are
Perspec Technologies Private Limited is a company incorporated in India, with its place of business in Bangalore, India. In this policy we refer to ourselves as Perspec, we or us.
For the purposes of the Indian Digital Personal Data Protection Act 2023 we are the Data Fiduciary for the personal data described here. For the purposes of the UK and EU General Data Protection Regulation we are the Controller. Where our clients instruct us to process data on their behalf under a services agreement, we act as a Data Processor for that data and this policy does not apply to it.
You can reach us about anything in this policy at getperspec@gmail.com.
What we collect
We collect three kinds of personal data through this website, and nothing else.
Contact form. When you send us an enquiry we collect your name, your company name, your email address, your team size, any message you write, and whether you ticked the mailing list box. All of these except the message and the tick box are required in order to submit the form. We keep a record of each enquiry on our own server so that we can retrieve and review past enquiries.
Newsletter. When you sign up for updates we collect your email address.
Analytics. When you visit any page we collect, through Google Analytics, your approximate location derived from your IP address, your device type, browser and operating system, the pages you view, how you arrived at the site and how long you stay. Google Analytics truncates IP addresses before storing them and we never see your full IP address in Analytics.
We also process your IP address transiently on our own server. Every form submission is rate limited by IP address for twenty seconds to blunt automated abuse. That address is held in memory only, is never written to a database and is discarded within twenty seconds. Our hosting provider records standard server logs which include IP addresses.
We do not collect special category or sensitive personal data, we do not ask for financial information, and we do not build profiles or make automated decisions that produce legal or similarly significant effects.
Why we use it, and on what basis
Enquiries. We use your contact form submission to answer you and to have the conversation you asked for. Under the GDPR our basis is the steps taken at your request prior to entering a contract, and our legitimate interest in responding to business enquiries. Under the DPDP Act our basis is your consent, given when you submit the form.
Marketing email. The contact form carries a tick box asking whether you want to join our mailing list. It is never ticked for you, and we add you only if you tick it. Our basis under both the GDPR and the DPDP Act is your consent, which you can withdraw at any time. Every marketing email carries a one-click unsubscribe link, and unsubscribing removes you from all marketing while leaving your enquiry correspondence intact.
Newsletter. We use your address to send you updates about our work. Our basis is your consent, which you give by submitting the form and can withdraw at any time using the unsubscribe link.
Analytics. We use analytics to understand which pages are read and how people move through the site, so we can improve it. Our basis is your consent under the ePrivacy rules in the EU and UK, and legitimate interest in understanding our own audience where consent is not required.
Abuse prevention. We use the transient IP rate limit to protect the site from automated submissions. Our basis is legitimate interest in the security and availability of our own service.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we have never done either.
Cookies and analytics
This website sets no cookies of its own and stores nothing in your browser.
Google Analytics sets cookies named _ga and _ga_ followed by a measurement identifier. They distinguish one visitor from another and record whether a visit is a continuation of an earlier one. They expire two years after they are set, and Google Analytics is the only reason any cookie is set on this site.
Our fonts are served from our own domain rather than from a content delivery network, so loading a page does not disclose your IP address to a font provider.
You can block analytics entirely with a browser content blocker, by using your browser private mode, or by installing the Google Analytics opt out add on. Nothing on this site stops working if you do.
Who we share it with
We use three service providers, and no others touch your data.
Resend, operated by Resend Inc in the United States, sends the email that carries your enquiry to us, stores our contact list and sends our marketing email. It receives your name and email address, and the content of your enquiry.
Google, operated by Google LLC and Google Ireland Limited, provides Google Analytics. It receives the analytics data described above.
Railway, operated by Railway Corporation in the United States, hosts this website. It processes the data in server logs incidental to serving pages to you.
We disclose personal data outside this list only where we are legally required to, for example in response to a valid order from a court or a regulator, or where it is necessary to establish or defend a legal claim. We will tell you if that happens unless we are prohibited from doing so.
Where your data goes
We are based in India and our service providers are based in the United States. Your personal data is therefore transferred outside India, and outside the European Economic Area and the United Kingdom.
For transfers from the EEA and the UK we rely on the European Commission Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer originates in the United Kingdom. Copies are available on request.
Under the DPDP Act, transfers out of India are permitted except to territories the Government of India has restricted. None of our providers are in a restricted territory at the date of this policy.
How long we keep it
Enquiries. We keep your enquiry and our correspondence for three years from our last contact with you, so that we have a record of what was discussed. If the enquiry becomes an engagement, the record is kept for the duration of that engagement and for eight years afterwards to meet Indian accounting and tax record keeping requirements.
Mailing list. We keep your address until you unsubscribe, and for a further two years afterwards so that we have a record of the fact you unsubscribed and do not add you again by mistake.
Analytics. Google Analytics retains user level and event level data for fourteen months from your last visit, after which it is deleted automatically. Aggregate reporting is retained indefinitely and cannot identify you.
Rate limiting. Discarded within twenty seconds. Hosting logs are retained by our host for a rolling period of no more than thirty days.
Your rights
Wherever you are, you can ask us for a copy of the personal data we hold about you, ask us to correct it if it is wrong or incomplete, ask us to delete it, and ask us to stop sending you marketing. We will not treat you differently for exercising any of these.
If you are in India, the DPDP Act gives you the right to access a summary of your personal data and our processing of it, the right to correction, completion, updating and erasure, the right to nominate another person to exercise your rights in the event of your death or incapacity, and the right to an accessible grievance redressal mechanism, which is set out below.
If you are in the EEA or the UK, the GDPR gives you in addition the right to restrict our processing, the right to receive your data in a portable machine readable format, the right to object to processing carried out on the basis of legitimate interest including profiling, and the right to withdraw consent at any time without affecting the lawfulness of processing before you withdrew it.
If you are in California, you have the right to know what we collect and why, the right to delete, the right to correct, the right to opt out of sale or sharing, and the right not to be discriminated against for exercising them. We do not sell or share your personal information as those terms are defined by the CCPA as amended.
To exercise any right, write to getperspec@gmail.com. We will respond within thirty days. We may ask you for information to confirm your identity, and we will only use what you send for that purpose.
Grievance redressal
If you are dissatisfied with how we have handled your personal data or a request about it, contact our Grievance Officer at getperspec@gmail.com, marking your message for the attention of the Grievance Officer. We will acknowledge within seventy two hours and resolve within thirty days.
If we do not resolve your grievance, you may complain to the Data Protection Board of India under the DPDP Act.
If you are in the EEA or the UK you may also complain to your local supervisory authority. In the United Kingdom that is the Information Commissioner Office at ico.org.uk. You do not have to come to us first, although we would prefer the chance to put it right.
Children
This website is intended for professional audiences and is not directed at children. Under the DPDP Act a child is anyone under eighteen years of age. We do not knowingly collect personal data from children, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children.
If you believe a child has given us personal data, write to us and we will delete it.
How we protect it
This site is served only over an encrypted connection. Access to our email, our contact list and our hosting is restricted to the two founders of the company and protected by multi factor authentication. Credentials for our service providers are held as environment variables on the host and are never committed to our source code.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and every affected person as required by the DPDP Act, and where the GDPR applies we will notify the competent supervisory authority within seventy two hours of becoming aware of it.
Changes to this policy
If we change how we handle personal data we will update this page and change the date at the top of it. If a change materially affects your rights we will tell the people on our mailing list by email before it takes effect.