Privacy Policy

No cookies, no analytics, no tracking. Here is exactly what happens to anything you send us.

Privacy Policy

Who we are

This policy explains what Codespark Infotech Private Limited (“Codespark”, “we”, “us”) does with personal data collected through this website, code-spark.com. For that data we are the controller under the EU and UK General Data Protection Regulation, and the data fiduciary under India’s Digital Personal Data Protection Act, 2023.

Codespark Infotech Private Limited

sd@code-spark.com

CIN: U62013MH2023PTC407276

What we collect

Only two things: what you type into our contact form, and what our web server records automatically.

The contact form

When you ask for a quote we collect your name, work email address, which services you selected, your budget range, your WhatsApp number if you choose to give one, and the project brief you write. Name, email and brief are required; the rest is optional. Please do not put confidential details in the brief, a sentence or two is enough to get a useful reply, and we will sign an NDA before you share more.

Server logs

Our hosting provider records standard web server logs for every request: IP address, timestamp, the page requested, and your browser’s user-agent string. These exist to keep the site running and to spot abuse. We do not use them to build a profile of you.

What we do not collect

This site sets no cookies. It runs no analytics, no advertising pixels, no session recording and no third-party tracking of any kind. Fonts and scripts are served from our own domain rather than a CDN, so simply reading these pages does not report your visit to anyone else. There is no cookie banner because there is nothing to consent to.

Why we use it, and on what basis

We use your enquiry for exactly one purpose: to reply to it, scope your project and, if it goes ahead, to contract with you. Under GDPR our basis is Art. 6(1)(b), steps taken at your request before entering a contract, and Art. 6(1)(f), our legitimate interest in responding to business enquiries. Under the DPDP Act our basis is the consent you give by submitting the form. Server logs rest on our legitimate interest in operating a secure website.

We do not send marketing email. We will not add you to a newsletter, and we will never sell, rent or share your details with anyone for their own marketing.

Who else handles it

We keep the list of processors deliberately short:

  • ZeptoMail (Zoho Corporation) — delivers the contact form to our inbox. Data centre: India.
  • FormSubmit — a fallback that receives the form only if our own mail relay is unreachable, so that an enquiry is never silently lost.
  • Our hosting provider — stores the server logs described above.
  • Calendly — only if you click “Book a call” while online booking is enabled. Nothing from Calendly loads until you click, and you give your details to Calendly directly.

Beyond these we disclose personal data only where the law requires it.

International transfers

We are based in India and your enquiry is read and stored there. For visitors in the European Economic Area and the UK this is a transfer to a country without an adequacy decision, so we rely on the European Commission’s Standard Contractual Clauses. Where we process personal data on behalf of a client rather than our own, we sign a Data Processing Agreement with the SCCs annexed before any data moves.

How long we keep it

Enquiries that do not become projects are deleted within 24 months. Enquiries that do become projects are retained for the life of the engagement and then for as long as tax and contract law requires us to keep the records, currently eight years in India. Server logs are rotated by our host within 12 months.

Your rights

You can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict or object to how we use it, or send it to you in a portable format. Where we rely on consent you can withdraw it at any time. Exercising any of these costs nothing and we will respond within 30 days.

Email sd@code-spark.com and say what you want. We may ask one question to confirm you are who you say you are, and nothing more.

If you think we have handled your data badly, please tell us first, we would rather fix it. You also have the right to complain to your local supervisory authority: in the EEA your national data protection authority, in the UK the Information Commissioner’s Office, and in India the Data Protection Board.

Client project data

This policy covers our own website. When we build or maintain software for a client, any personal data inside that system belongs to the client and we act as their processor under a separate Data Processing Agreement, which sets out the security measures, sub-processors and deletion terms for that engagement. Our standard contracts also assign all intellectual property in the work to the client on payment.

Security

The site is served over HTTPS only. Form submissions are validated and length-capped server side, mail credentials are held outside the web root and never in our source repository, and access to enquiry email is limited to the engineers who answer it.

Changes

If we change this policy we will update the date below. Material changes will be summarised at the top of this page for a reasonable period.

Contact

Questions about this policy, or about anything above, go to sd@code-spark.com.