Privacy Policy
Last updated: [DATE]
A working draft, not legal advice. Replace every [bracketed] field and have a lawyer review it. You'll process personal data of individuals in the UK and EU, bringing UK GDPR and GDPR into scope alongside India's DPDP Act — and you'll be handling enterprise clients' customer lists, which is exactly where a template isn't enough.
Who we are
Upshiftz ([registered entity name]) is an independent consultancy registered in [jurisdiction], operating from [address]. For anything relating to this policy or your personal data, contact [privacy email].
What this policy covers
Two distinct groups: people who visit this website, and individuals whose details we process on behalf of a client while running a review programme. The rules differ, so they're treated separately below.
Website visitors
- What you submit — name, work email, company website, product category, and anything you write in an audit request.
- Technical data — IP address, browser type and pages visited, collected by our hosting provider and any analytics tooling.
We use this to reply to you and to understand which parts of the site are useful. We don't sell it and we don't share it with advertising networks.
Client programme data
When running a review programme we may process contact details of a client's customers — typically name, job title, employer and work email. In that context our client is the data controller and we act as processor, on their documented instructions, under a written agreement.
We don't use that data for our own purposes, don't contact anyone outside the scope agreed with the client, and return or delete it when the engagement ends.
Legal bases
Where UK or EU law applies we rely on legitimate interests for business-to-business communication, consent where you've opted in, and contractual necessity where processing is needed to deliver services you or your employer engaged us for.
Retention
Enquiry data is kept for [period] unless you ask us to delete it sooner. Client programme data is retained for the engagement plus [period], unless the client agreement says otherwise.
Sharing and sub-processors
We share personal data only with providers necessary to operate — currently [list: hosting, email, CRM, analytics]. Each is bound by contract. We never sell personal data.
International transfers
We operate from India and may process data relating to individuals in the UK, EU and elsewhere. Where required, transfers are made under Standard Contractual Clauses or another approved safeguard.
Your rights
Depending on where you live you may have the right to access, correct, delete or port your data, to object to or restrict processing, and to withdraw consent. Contact [privacy email] and we'll respond within 30 days. If we hold your data on behalf of a client, we'll pass your request to them and support their response.
Cookies
[Describe the cookies actually in use, or state that only essential cookies are set. If you add analytics you need a consent banner for UK and EU visitors — decide this before launch.]
Complaints
If you're unhappy with how we've handled your data, you can complain to your local supervisory authority — the ICO in the UK, your national authority in the EU, or the Data Protection Board of India.
Changes
Any material change will be posted here with an updated date.