ZeroBridge Consultants
  • Home
  • About Us
  • Why ZeroBridge
  • Services
    • All Services

    • DPDP Assessment
    • Awareness Sessions
    • DPDP Webinars
    • DPO as a Service
    • Talks & Awareness Programs
    • Implementation Consulting
  • Industries
  • Platforms
    • DPDP GuideFree reference on the Act & Rules
    • DPDP CheckupFree 20-minute readiness check
    • DPDP AcademyFree training & certificate
  • Contact
Talk to a DPDP Expert
ZeroBridge Consultants
  • Home
  • About Us
  • Why ZeroBridge
  • Services
    • All Services
    • DPDP Assessment
    • Awareness Sessions
    • DPDP Webinars
    • DPO as a Service
    • Talks & Awareness Programs
    • Implementation Consulting
  • Industries
  • Platforms
    • DPDP Guide
    • DPDP Checkup
    • DPDP Academy
  • Contact

[email protected]
+91-8899010801

© ZeroBridge Consultants

Privacy Policy

How we handle personal data — written to the same standard we advise our clients to meet.

Privacy Policy

  • Home
  • Privacy Policy

On this page

  • Who we are
  • What this notice covers
  • Personal data we collect
  • Why we process it
  • Our basis for processing
  • Cookies and third-party services
  • Who we share personal data with
  • How long we keep it
  • How we protect it
  • If there is a personal data breach
  • Children and persons with a guardian
  • Your rights as a Data Principal
  • How to exercise your rights
  • Your duties under the Act
  • Complaining to the Data Protection Board
  • Transfers outside India
  • Contact us
  • Changes to this notice

Effective 28 August 2026

In short: this website sets no cookies of its own, runs no analytics, no advertising pixels, and no tracking. We collect personal data only when you choose to send it to us through the enquiry form or by contacting us directly, and we use it only to respond to you. We never sell personal data.

1. Who we are

ZeroBridge Consultants (“ZeroBridge”, “we”, “us”) is a consulting firm specialising in compliance with India’s Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) and the DPDP Rules, 2025. Our office is at 568-A, Gandhi Nagar, Jammu – 180004, Jammu and Kashmir, India.

In respect of the personal data described in this notice, ZeroBridge Consultants is the Data Fiduciary — we determine the purpose and means of processing, and we are accountable for it.

2. What this notice covers

This notice applies to personal data we process through this website, zerobridgeconsultants.com, and through direct contact with us by email or telephone.

It does not cover two other situations:

  • Client engagement data. When we deliver an assessment, implementation, DPO, or training engagement, we often process personal data that belongs to our client’s systems. In that work we normally act as a Data Processor on the client’s instructions, and the client remains the Data Fiduciary. That processing is governed by the engagement contract between us, not by this notice.
  • Our other platforms. DPDPGUIDE.IN, DPDPCHECKUP.COM, and DPDPACADEMY.IN are separate websites that we publish. Each carries its own privacy notice. Read the notice on the site you are actually using.

3. Personal data we collect

We collect only what you give us. There is no hidden collection, no profiling, and no data purchased from third parties.

a. When you submit the enquiry form on our contact page, you provide:

  • Full name (required)
  • Email address (required)
  • Your message (required)
  • Organization name (optional)
  • Designation (optional)
  • Telephone number (optional)
  • The service you are interested in (optional)

Alongside the submission, our server records the IP address the form was sent from and the date and time of submission. This is used to operate the anti-spam check and to keep a record of the enquiry, and for nothing else.

b. When you email or telephone us, we process whatever you choose to include — typically your name, contact details, organization, and the content of your message.

c. Server logs. Our hosting infrastructure keeps standard web server logs (IP address, request time, page requested, browser user-agent) as an ordinary part of running and securing a website.

Please do not send us sensitive personal information, or personal data about other people, through the enquiry form. If you need to share such material for an engagement, we will agree a secure route with you first.

4. Why we process it

We process the personal data above only for these specified purposes:

  • To read, understand, and respond to your enquiry.
  • To discuss and scope a possible engagement, and to send you a proposal if you ask for one.
  • To deliver a service you have engaged us for, and to administer that relationship.
  • To keep a record of enquiries and correspondence for our own accountability.
  • To protect the website against spam, abuse, and automated attacks.
  • To meet a legal or regulatory obligation where one applies to us.

We do not use your personal data for advertising, behavioural profiling, automated decision-making, or any purpose unconnected with your enquiry. We do not sell, rent, or trade personal data. We will not add you to a marketing list on the strength of an enquiry.

5. Our basis for processing

Where you submit the enquiry form or contact us, we process your personal data on the basis of the consent you give by choosing to send it, for the purposes set out in section 4 (s.6 of the Act).

Where you are an existing client, we process personal data for the certain legitimate uses recognised by s.7 of the Act — principally, where you have voluntarily provided the data for a specified purpose and have not indicated that you object to its use for that purpose — and to perform our contract with you.

Consent can be withdrawn at any time. See section 12.

6. Cookies and third-party services

This website sets no cookies of its own. There is no analytics package, no tag manager, no advertising or social media pixel, and no cross-site tracking. Our fonts, stylesheets, and scripts are served from our own domain rather than from third-party CDNs.

Two third-party services appear on the contact page only:

  • Cloudflare Turnstile — the anti-spam check on the enquiry form. To confirm the form is being submitted by a person rather than a bot, Turnstile receives your IP address and technical signals from your browser, and may place a token in your browser for this purpose. Cloudflare states that Turnstile is designed for privacy and is not used to build advertising profiles. It is governed by Cloudflare’s own privacy policy.
  • Google Maps — the embedded map showing our office. If your browser loads the map, Google receives your IP address and may set cookies in the map frame under Google’s own privacy policy. If you would rather not load it, our address is written out in plain text on the same page.

We have no control over, and take no responsibility for, the data practices of these third parties. Neither service is used by us to track you.

7. Who we share personal data with

We share personal data only where it is necessary, and only with:

  • Our own team members who need it to respond to you or deliver an engagement.
  • Service providers acting as Data Processors on our instructions — principally our website host and our email service provider. They may process personal data only for the purpose we specify, under contract, and may not use it for their own purposes.
  • Professional advisers such as our own legal or accounting advisers, where genuinely required.
  • A public authority, court, or regulator, where we are legally obliged to disclose.

We do not disclose enquiry details to any other party. We do not share personal data with our other platforms.

8. How long we keep it

Section 8(7) of the Act requires personal data to be erased once the purpose is no longer being served and retention is no longer necessary for a legal purpose. Our retention practice is:

  • Enquiries that do not lead to an engagement — retained for up to 24 months from our last communication with you, then erased. This allows us to pick up a conversation you may return to.
  • Enquiries and correspondence relating to an engagement — retained for the duration of the engagement and then for the period set out in the engagement contract, or as required for legal, tax, or accounting purposes.
  • Server logs — retained for a short operational period in the ordinary course and then overwritten.

If you ask us to erase your personal data sooner, we will do so unless we are required to keep it for a legal purpose. See section 12.

9. How we protect it

We take reasonable security safeguards to prevent a personal data breach, as required by s.8(5) of the Act. These include transport encryption (HTTPS) across the site, access limited to team members who need it, credentials held in server-side configuration rather than in page code, an anti-spam control on the enquiry form, and periodic review of who holds access to what.

No system can be guaranteed secure, and we do not claim otherwise. What we do commit to is handling your information with the same care we advise our clients to apply to theirs.

10. If there is a personal data breach

If a personal data breach affects your personal data, we will notify you and the Data Protection Board of India in the manner and within the timelines required by s.8(6) of the Act and the DPDP Rules, 2025. Our notification will describe the nature and extent of the breach, its likely consequences, the measures we have taken, and what you can do to protect yourself.

11. Children and persons with a guardian

Our services are directed at organizations, and this website is not intended for children. We do not knowingly collect the personal data of a child (a person under eighteen years of age) or of a person with a lawful guardian through this website.

Consistent with s.9 of the Act, we do not undertake tracking or behavioural monitoring of children, and we do not direct advertising at children. If you believe a child has provided us with personal data, contact us and we will erase it.

12. Your rights as a Data Principal

Chapter III of the Act gives you the following rights over your personal data, and we honour all of them:

  • Right to access information (s.11) — a summary of the personal data we hold about you, the processing we carry out, and the identities of any other Data Fiduciaries or Processors with whom it has been shared.
  • Right to correction and erasure (s.12) — to have inaccurate or misleading personal data corrected, incomplete data completed, data updated, and data erased where it is no longer needed for the purpose and we are not required to keep it.
  • Right of grievance redressal (s.13) — to raise a grievance with us about how we have handled your personal data or responded to your request, and to receive a response.
  • Right to nominate (s.14) — to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
  • Right to withdraw consent (s.6(4)–(6)) — to withdraw your consent at any time, as easily as you gave it. Withdrawal does not affect processing already carried out lawfully before you withdrew.

13. How to exercise your rights

You can exercise any of the rights above, including withdrawing consent, by emailing [email protected] with the words “DPDP request” in the subject line, or by writing to us at the postal address in section 16. You may also telephone us on +91-8899010801 and we will guide you through it.

Tell us what you would like us to do and give us enough detail to find your records — the email address you used, and roughly when you contacted us, is usually sufficient. Where we cannot identify you from what you provide, we may ask for further particulars; we will not ask for more personal data than we need to locate your records.

We will respond to any request or grievance within 30 days of receiving it. There is no fee. If we need longer because a request is complex, we will tell you why within that period.

You do not need to use a form or any particular wording. A plain email is enough.

14. Your duties under the Act

Section 15 of the Act also places duties on Data Principals. In summary, you must not impersonate another person when providing personal data, must not suppress material information or provide false particulars where required by law, must not register a false or frivolous grievance or complaint, and must furnish only authentic information when seeking correction or erasure.

15. Complaining to the Data Protection Board

If you are not satisfied with how we have handled your request or grievance, you may make a complaint to the Data Protection Board of India, established under Chapter V of the Act.

Under s.13(3) of the Act, you should first exhaust the grievance route with us before approaching the Board. Complaints to the Board may be made in the manner and form the Board prescribes; details are published by the Board and by the Ministry of Electronics and Information Technology. We will cooperate fully with any Board proceeding and will give you whatever information you need to make your complaint.

16. Transfers outside India

We are an India-based firm and our enquiry data is handled in India. Certain service providers we rely on — for example our email provider and the anti-spam service on the contact form — may process limited data on infrastructure outside India.

Section 16 of the Act permits transfer of personal data outside India except to territories restricted by the Central Government by notification. We do not transfer personal data to any restricted territory, and we will adjust our arrangements if the Central Government notifies restrictions that affect them.

17. Contact us

As required by s.8(9) of the Act, the business contact for questions about how we process personal data is:

Grievance Officer, ZeroBridge Consultants

Email: [email protected]

Telephone: +91-8899010801

Post: 568-A, Gandhi Nagar, Jammu – 180004, Jammu and Kashmir, India

We are not currently required to appoint a Data Protection Officer under s.10 of the Act, as we have not been notified as a Significant Data Fiduciary. The contact above is the person able to answer questions on our behalf about the processing of personal data.

18. Changes to this notice

We will update this notice when our practices change or when the DPDP Rules, 2025 and Data Protection Board guidance develop. The effective date below always reflects the current version. Where a change materially affects how we process personal data you have already given us, we will tell you directly rather than relying on you to notice an update here.

Effective 28 August 2026. This page replaces any earlier version.

ZeroBridge Consultants

Specialist consulting for compliance with India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.

Quick Links

  • Home
  • About Us
  • Why ZeroBridge
  • Industries
  • Contact
  • FAQs

Services

  • DPDP Assessment
  • Awareness Sessions
  • Webinars
  • DPO as a Service
  • Talks & Programs
  • Implementation Consulting

Our Platforms Free

  • DPDPGUIDE.IN
  • DPDPCHECKUP.COM
  • DPDPACADEMY.IN

Contact

[email protected]

+91-8899010801

568-A, Gandhi Nagar, Jammu – 180004

Copyright © ZeroBridge Consultants. All Rights Reserved.

Privacy Policy  ·  Terms of Use