Last Updated: 29 July 2026
1. Introduction & Scope
This Privacy Policy ("Policy") is published by Infble (OPC) Private Limited (hereinafter referred to as "Infble," "we," "us," or "our"), a company incorporated under the laws of India, in its capacity as Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules").
This Policy explains how we collect, use, store, share, and protect the personal data of individuals ("Data Principals") who:
- Visit or interact with our website at infble.com ("Website");
- Submit enquiries, contact forms, or project requirement details through the Website;
- Engage with us for business discussions, proposals, or consultations.
Important - Client Project Data: Personal data processed in the course of delivering specific client engagements (custom software development, IT staffing, SaaS hosting, etc.) is governed by the separately signed Master Service Agreement (MSA) and/or Data Processing Agreement (DPA) for that engagement - not by this public Privacy Policy. This Policy covers Website visitors and general business interactions only.
2. Identity & Contact Details of the Data Fiduciary
| Detail |
Information |
| Legal Entity Name |
Infble (OPC) Private Limited |
| Registered Address |
ANO 24, PURVA NANKARI, IIT KANPUR, Kalyanpur, Kanpur Nagar- 208016, Uttar Pradesh, India |
| CIN |
U62099UP2026OPC250506 |
| Email |
support@infble.com |
| Website |
https://infble.com |
3. Categories of Personal Data Collected
We collect personal data limited to what is necessary for the specific purposes described in Section 4 below. The categories are:
3.1 Contact & Enquiry Data
When you submit a contact form, book a call, or communicate with us via email or WhatsApp, we may collect:
- Full name
- Work email address
- Company/organisation name
- Phone number or WhatsApp number (if provided voluntarily)
- Project description and requirements details
- Approximate budget range
3.2 Business & Engagement Data
When a business relationship is established, we may additionally collect:
- Business entity details (company name, registration number, billing address)
- Authorised signatory and contact person details
- Banking or payment details for invoicing purposes
- Contract and correspondence records
3.3 Candidate & Personnel Data (Staffing/Outsourcing)
When we provide IT staffing, outsourcing, or team augmentation services, we may process:
- Candidate resumes, CVs, and professional profiles
- Educational qualifications and professional certifications
- Employment history and references
- Background verification information (where required by the client engagement agreement)
- Skills assessments and interview records
This data is processed solely for the purpose of fulfilling the staffing engagement and is retained only for the duration specified in the applicable staffing agreement plus any statutory retention period.
3.4 Technical & Usage Data
When you visit the Website, our hosting infrastructure may automatically collect:
- IP address
- Browser type and version
- Operating system
- Referring URL and pages visited
- Date, time, and duration of access
- Device identifiers
This data is collected through standard web server logs and is used for security monitoring, performance optimisation, and aggregate analytics. It is not used to individually identify or profile Website visitors.
4. Purpose of Collection
We collect and process personal data only for specific, clearly defined purposes. We do not process personal data for any purpose beyond what is stated here without obtaining fresh consent.
- Responding to enquiries: To review your project requirements, provide technical feedback, and schedule consultation calls.
- Delivering services: To execute contracted engagements including custom software development, SaaS product deployment, tech consulting, and IT staffing/outsourcing.
- Contract management: To prepare proposals, statements of work, invoices, and related commercial documentation.
- Staffing fulfilment: To source, screen, and place qualified IT professionals for client engagements.
- Communication: To send project updates, invoices, service notifications, and respond to your communications.
- Legal compliance: To comply with applicable laws, regulations, court orders, or lawful requests from government authorities, including tax (GST, TDS) and employment law obligations.
- Security & fraud prevention: To monitor and protect the Website and our infrastructure against unauthorised access, abuse, or malicious activity.
- Website improvement: To analyse aggregate usage patterns and improve the Website's performance, content, and user experience.
5. Consent Mechanism
Under the DPDP Act, we process your personal data based on your consent or for certain legitimate uses as defined under Section 7 of the Act.
5.1 How Consent Is Captured
- Contact/enquiry forms: Every form on the Website that collects personal data carries an unticked consent checkbox. The form cannot be submitted until you tick it, and we record the wording you agreed to along with the date and time of that agreement.
- Client project portal: Each requirement update you submit through the project portal is confirmed with the same consent checkbox before it is stored against your project record.
- AI assistant (site chatbot): The assistant asks for your consent as an explicit question before any details you have shared with it are stored or sent to us. If you decline, nothing from that conversation is submitted.
- Call scheduling: Booking a slot through our scheduling provider is your affirmative action; the details you enter are shared with us and with that provider solely to confirm and run the call, as stated next to the scheduler.
- Email/WhatsApp communication: By initiating communication with us via email or WhatsApp, you consent to us processing the information you share for the purpose of that communication.
- Contractual engagement: When you enter into a service agreement with us, consent for processing data necessary to perform that contract is captured through the signed agreement.
5.2 Withdrawal of Consent
You may withdraw your consent at any time by contacting us at support@infble.com. Upon receiving a valid withdrawal request:
- We will cease processing your personal data for the purposes to which consent was withdrawn, within a reasonable timeframe.
- Withdrawal of consent will not affect the lawfulness of processing carried out prior to the withdrawal.
- If your data is being processed under a contractual obligation or a legitimate use under the DPDP Act, withdrawal may not apply to that specific processing.
- We will inform you of any consequences of withdrawal (e.g., inability to continue providing a requested service).
6. Cookies & Tracking Technologies
As of the date of this Policy, the Infble Website does not deploy any third-party analytics, advertising, or tracking cookies. We do not use Google Analytics, Meta Pixel, Hotjar, or similar tracking services.
| Cookie Type |
Status |
Purpose |
| Essential / Technical |
May be set by hosting provider |
Basic website functionality, security (e.g., CSRF protection, load balancing) |
| Analytics / Performance |
Not in use |
- |
| Advertising / Marketing |
Not in use |
- |
| Third-party / Social |
Not in use |
- |
If we introduce analytics or tracking technologies in the future, this Policy will be updated accordingly, and where required under the DPDP Act, appropriate consent will be obtained before activation.
7. Data Sharing & Disclosure
We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and only to the extent necessary for the stated purposes:
- Cloud hosting & infrastructure providers: For hosting the Website and supporting service delivery infrastructure.
- Communication tools: Email service providers and scheduling platforms used for business communication.
- Professional advisors: Legal counsel, accountants, and auditors where required for compliance or dispute resolution.
- Sub-contractors & partner developers: When we engage vetted sub-contractors to deliver portions of a client project, limited personal data may be shared as necessary, subject to confidentiality obligations.
- Government & regulatory authorities: Where required by applicable law, court order, or regulatory directive.
We do not sell, rent, trade, or otherwise commercially transfer your personal data to any third party.
8. Cross-Border Data Transfer
As an IT services firm serving both Indian and international clients, your personal data may be processed on servers or by personnel located outside India in the following circumstances:
- Our cloud hosting infrastructure may utilise data centres located outside India.
- When delivering services to international clients, project-related communications and data may transit through systems in the client's jurisdiction.
- Sub-contractors engaged for specific project components may operate from jurisdictions outside India.
Such transfers are permitted under Section 16 of the DPDP Act, subject to any restrictions notified by the Central Government on transfers to specific countries. We do not transfer personal data to any country that the Government of India has specifically restricted under the Act.
For international client engagements, data processing may additionally be subject to the data protection laws of the client's jurisdiction (such as the EU General Data Protection Regulation or the California Consumer Privacy Act). In such cases, the applicable Data Processing Agreement (DPA) signed for that engagement will govern the specific cross-border transfer obligations and safeguards.
9. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, after which it is securely deleted or anonymised. Specific retention periods are:
| Data Category |
Retention Period |
| Contact/enquiry form data |
24 months from the date of last interaction, or until consent is withdrawn - whichever is earlier. |
| Business & engagement records |
Duration of the contractual relationship plus 8 years (to satisfy tax, audit, and Companies Act obligations). |
| Candidate/personnel data (staffing) |
Duration of the staffing engagement plus 12 months, unless a longer period is required by the client agreement or applicable employment law. |
| Technical/usage data (server logs) |
90 days, unless retention is extended for an ongoing security investigation. |
| Invoice & financial records |
8 years from the end of the relevant financial year (GST and Income Tax Act requirements). |
10. Security Safeguards
We implement reasonable security safeguards - technical, administrative, and organisational - to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include, but are not limited to:
- Encryption of data in transit using industry-standard TLS/SSL protocols.
- Access controls restricting personal data access to authorised personnel on a need-to-know basis.
- Secure hosting infrastructure with regular security patching and monitoring.
- Confidentiality obligations for all team members and sub-contractors handling personal data.
- Periodic review of security practices and incident response procedures.
While we take all reasonable steps to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incident in accordance with applicable law.
11. Rights of Data Principals
Under the DPDP Act, you (as a Data Principal) have the following rights with respect to your personal data:
- Right to Access: You may request confirmation of whether we process your personal data and obtain a summary of such data and the processing activities.
- Right to Correction: You may request correction of inaccurate or incomplete personal data, and we will update it or have the relevant Data Processor update it.
- Right to Erasure: You may request erasure of your personal data that is no longer necessary for the purpose for which it was collected. This right is subject to our legal obligations to retain certain records (e.g., tax, audit).
- Right to Grievance Redressal: You have the right to register a grievance with us regarding our processing of your personal data. See Section 14 below for the grievance process.
- Right to Nominate: You may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity, in accordance with the DPDP Act.
How to Exercise Your Rights
To exercise any of the above rights, submit a written request to our Grievance Officer at the contact details provided in Section 14. We will verify your identity before processing the request and respond within 30 days of receiving a valid, verifiable request.
12. Personal Data Breach Notification
In the event of a personal data breach, Infble is committed to:
- Notifying the Data Protection Board of India in the manner and within the timeframe prescribed under the DPDP Rules, 2025.
- Notifying each affected Data Principal whose personal data has been breached, providing details of the nature of the breach and recommended protective actions.
- Taking immediate remedial measures to contain and mitigate the impact of the breach.
- Maintaining an internal record of all data breaches, including their nature, impact, and remedial actions taken.
13. Children's Data
Infble's services are directed at businesses and professionals. We do not knowingly collect or process personal data of individuals under the age of 18 years.
If we become aware that we have inadvertently collected personal data from a child (an individual below 18 years of age as defined under the DPDP Act), we will take prompt steps to delete such data and, where applicable, notify the Data Protection Board.
If you are a parent or guardian and believe that a child has provided personal data to us, please contact us immediately at support@infble.com.
14. Grievance Officer
In accordance with the DPDP Act and DPDP Rules, we have appointed a Grievance Officer to address your concerns regarding the processing of your personal data:
| Detail |
Information |
| Name |
Uma Pal |
| Designation |
Grievance Officer - Data Protection |
| Email |
dpo@infle.com |
| Response Commitment |
We will acknowledge receipt of your grievance within 48 hours and provide a substantive response within 30 days. |
If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India established under the DPDP Act.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes:
- The updated Policy will be published on this page with a revised "Last Updated" date.
- For material changes that affect the way we process your personal data, we will make reasonable efforts to notify you (e.g., via a notice on the Website or by email, where your email address is available to us).
- Where required under the DPDP Act, we will obtain fresh consent before processing your data under materially revised terms.
We encourage you to review this Policy periodically to stay informed about how we protect your data.
16. Governing Law & Jurisdiction
This Privacy Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023, and the rules made thereunder.
Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Kanpur, India.