How we collect, use, protect, and handle your personal data — aligned with India's Digital Personal Data Protection Act, 2023.
This Privacy Policy ("Policy") is published by Infble (OPC) Private Limited (hereinafter referred to as "Infble," "we," "us," or "our"), a company incorporated under the laws of India, in its capacity as Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules").
This Policy explains how we collect, use, store, share, and protect the personal data of individuals ("Data Principals") who:
| Detail | Information |
|---|---|
| Legal Entity Name | Infble (OPC) Private Limited |
| Registered Address | ANO 24, PURVA NANKARI, IIT KANPUR, Kalyanpur, Kanpur Nagar- 208016, Uttar Pradesh, India |
| CIN | U62099UP2026OPC250506 |
| support@infble.com | |
| Website | https://infble.com |
We collect personal data limited to what is necessary for the specific purposes described in Section 4 below. The categories are:
When you submit a contact form, book a call, or communicate with us via email or WhatsApp, we may collect:
When a business relationship is established, we may additionally collect:
When we provide IT staffing, outsourcing, or team augmentation services, we may process:
This data is processed solely for the purpose of fulfilling the staffing engagement and is retained only for the duration specified in the applicable staffing agreement plus any statutory retention period.
When you visit the Website, our hosting infrastructure may automatically collect:
This data is collected through standard web server logs and is used for security monitoring, performance optimisation, and aggregate analytics. It is not used to individually identify or profile Website visitors.
We collect and process personal data only for specific, clearly defined purposes. We do not process personal data for any purpose beyond what is stated here without obtaining fresh consent.
Under the DPDP Act, we process your personal data based on your consent or for certain legitimate uses as defined under Section 7 of the Act.
You may withdraw your consent at any time by contacting us at support@infble.com. Upon receiving a valid withdrawal request:
As of the date of this Policy, the Infble Website does not deploy any third-party analytics, advertising, or tracking cookies. We do not use Google Analytics, Meta Pixel, Hotjar, or similar tracking services.
| Cookie Type | Status | Purpose |
|---|---|---|
| Essential / Technical | May be set by hosting provider | Basic website functionality, security (e.g., CSRF protection, load balancing) |
| Analytics / Performance | Not in use | — |
| Advertising / Marketing | Not in use | — |
| Third-party / Social | Not in use | — |
If we introduce analytics or tracking technologies in the future, this Policy will be updated accordingly, and where required under the DPDP Act, appropriate consent will be obtained before activation.
We may share your personal data with the following categories of recipients, strictly on a need-to-know basis and only to the extent necessary for the stated purposes:
We do not sell, rent, trade, or otherwise commercially transfer your personal data to any third party.
As an IT services firm serving both Indian and international clients, your personal data may be processed on servers or by personnel located outside India in the following circumstances:
Such transfers are permitted under Section 16 of the DPDP Act, subject to any restrictions notified by the Central Government on transfers to specific countries. We do not transfer personal data to any country that the Government of India has specifically restricted under the Act.
For international client engagements, data processing may additionally be subject to the data protection laws of the client's jurisdiction (such as the EU General Data Protection Regulation or the California Consumer Privacy Act). In such cases, the applicable Data Processing Agreement (DPA) signed for that engagement will govern the specific cross-border transfer obligations and safeguards.
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, after which it is securely deleted or anonymised. Specific retention periods are:
| Data Category | Retention Period |
|---|---|
| Contact/enquiry form data | 24 months from the date of last interaction, or until consent is withdrawn — whichever is earlier. |
| Business & engagement records | Duration of the contractual relationship plus 8 years (to satisfy tax, audit, and Companies Act obligations). |
| Candidate/personnel data (staffing) | Duration of the staffing engagement plus 12 months, unless a longer period is required by the client agreement or applicable employment law. |
| Technical/usage data (server logs) | 90 days, unless retention is extended for an ongoing security investigation. |
| Invoice & financial records | 8 years from the end of the relevant financial year (GST and Income Tax Act requirements). |
We implement reasonable security safeguards — technical, administrative, and organisational — to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include, but are not limited to:
While we take all reasonable steps to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incident in accordance with applicable law.
Under the DPDP Act, you (as a Data Principal) have the following rights with respect to your personal data:
To exercise any of the above rights, submit a written request to our Grievance Officer at the contact details provided in Section 14. We will verify your identity before processing the request and respond within 30 days of receiving a valid, verifiable request.
In the event of a personal data breach, Infble is committed to:
Infble's services are directed at businesses and professionals. We do not knowingly collect or process personal data of individuals under the age of 18 years.
If we become aware that we have inadvertently collected personal data from a child (an individual below 18 years of age as defined under the DPDP Act), we will take prompt steps to delete such data and, where applicable, notify the Data Protection Board.
If you are a parent or guardian and believe that a child has provided personal data to us, please contact us immediately at support@infble.com.
In accordance with the DPDP Act and DPDP Rules, we have appointed a Grievance Officer to address your concerns regarding the processing of your personal data:
| Detail | Information |
|---|---|
| Name | Uma Pal |
| Designation | Grievance Officer — Data Protection |
| dpo@infle.com | |
| Response Commitment | We will acknowledge receipt of your grievance within 48 hours and provide a substantive response within 30 days. |
If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India established under the DPDP Act.
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or business operations. When we make material changes:
We encourage you to review this Policy periodically to stay informed about how we protect your data.
This Privacy Policy is governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023, and the rules made thereunder.
Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Kanpur, India.