On this page
Effective 28 August 2026
In short: this website sets no cookies of its own, runs no analytics, no advertising pixels, and no tracking. We collect personal data only when you choose to send it to us through the enquiry form or by contacting us directly, and we use it only to respond to you. We never sell personal data.
ZeroBridge Consultants (“ZeroBridge”, “we”, “us”) is a consulting firm specialising in compliance with India’s Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) and the DPDP Rules, 2025. Our office is at 568-A, Gandhi Nagar, Jammu – 180004, Jammu and Kashmir, India.
In respect of the personal data described in this notice, ZeroBridge Consultants is the Data Fiduciary — we determine the purpose and means of processing, and we are accountable for it.
This notice applies to personal data we process through this website, zerobridgeconsultants.com, and through direct contact with us by email or telephone.
It does not cover two other situations:
We collect only what you give us. There is no hidden collection, no profiling, and no data purchased from third parties.
a. When you submit the enquiry form on our contact page, you provide:
Alongside the submission, our server records the IP address the form was sent from and the date and time of submission. This is used to operate the anti-spam check and to keep a record of the enquiry, and for nothing else.
b. When you email or telephone us, we process whatever you choose to include — typically your name, contact details, organization, and the content of your message.
c. Server logs. Our hosting infrastructure keeps standard web server logs (IP address, request time, page requested, browser user-agent) as an ordinary part of running and securing a website.
Please do not send us sensitive personal information, or personal data about other people, through the enquiry form. If you need to share such material for an engagement, we will agree a secure route with you first.
We process the personal data above only for these specified purposes:
We do not use your personal data for advertising, behavioural profiling, automated decision-making, or any purpose unconnected with your enquiry. We do not sell, rent, or trade personal data. We will not add you to a marketing list on the strength of an enquiry.
Where you submit the enquiry form or contact us, we process your personal data on the basis of the consent you give by choosing to send it, for the purposes set out in section 4 (s.6 of the Act).
Where you are an existing client, we process personal data for the certain legitimate uses recognised by s.7 of the Act — principally, where you have voluntarily provided the data for a specified purpose and have not indicated that you object to its use for that purpose — and to perform our contract with you.
Consent can be withdrawn at any time. See section 12.
This website sets no cookies of its own. There is no analytics package, no tag manager, no advertising or social media pixel, and no cross-site tracking. Our fonts, stylesheets, and scripts are served from our own domain rather than from third-party CDNs.
Two third-party services appear on the contact page only:
We have no control over, and take no responsibility for, the data practices of these third parties. Neither service is used by us to track you.
We share personal data only where it is necessary, and only with:
We do not disclose enquiry details to any other party. We do not share personal data with our other platforms.
Section 8(7) of the Act requires personal data to be erased once the purpose is no longer being served and retention is no longer necessary for a legal purpose. Our retention practice is:
If you ask us to erase your personal data sooner, we will do so unless we are required to keep it for a legal purpose. See section 12.
We take reasonable security safeguards to prevent a personal data breach, as required by s.8(5) of the Act. These include transport encryption (HTTPS) across the site, access limited to team members who need it, credentials held in server-side configuration rather than in page code, an anti-spam control on the enquiry form, and periodic review of who holds access to what.
No system can be guaranteed secure, and we do not claim otherwise. What we do commit to is handling your information with the same care we advise our clients to apply to theirs.
If a personal data breach affects your personal data, we will notify you and the Data Protection Board of India in the manner and within the timelines required by s.8(6) of the Act and the DPDP Rules, 2025. Our notification will describe the nature and extent of the breach, its likely consequences, the measures we have taken, and what you can do to protect yourself.
Our services are directed at organizations, and this website is not intended for children. We do not knowingly collect the personal data of a child (a person under eighteen years of age) or of a person with a lawful guardian through this website.
Consistent with s.9 of the Act, we do not undertake tracking or behavioural monitoring of children, and we do not direct advertising at children. If you believe a child has provided us with personal data, contact us and we will erase it.
Chapter III of the Act gives you the following rights over your personal data, and we honour all of them:
You can exercise any of the rights above, including withdrawing consent, by emailing [email protected] with the words “DPDP request” in the subject line, or by writing to us at the postal address in section 16. You may also telephone us on +91-8899010801 and we will guide you through it.
Tell us what you would like us to do and give us enough detail to find your records — the email address you used, and roughly when you contacted us, is usually sufficient. Where we cannot identify you from what you provide, we may ask for further particulars; we will not ask for more personal data than we need to locate your records.
We will respond to any request or grievance within 30 days of receiving it. There is no fee. If we need longer because a request is complex, we will tell you why within that period.
You do not need to use a form or any particular wording. A plain email is enough.
Section 15 of the Act also places duties on Data Principals. In summary, you must not impersonate another person when providing personal data, must not suppress material information or provide false particulars where required by law, must not register a false or frivolous grievance or complaint, and must furnish only authentic information when seeking correction or erasure.
If you are not satisfied with how we have handled your request or grievance, you may make a complaint to the Data Protection Board of India, established under Chapter V of the Act.
Under s.13(3) of the Act, you should first exhaust the grievance route with us before approaching the Board. Complaints to the Board may be made in the manner and form the Board prescribes; details are published by the Board and by the Ministry of Electronics and Information Technology. We will cooperate fully with any Board proceeding and will give you whatever information you need to make your complaint.
We are an India-based firm and our enquiry data is handled in India. Certain service providers we rely on — for example our email provider and the anti-spam service on the contact form — may process limited data on infrastructure outside India.
Section 16 of the Act permits transfer of personal data outside India except to territories restricted by the Central Government by notification. We do not transfer personal data to any restricted territory, and we will adjust our arrangements if the Central Government notifies restrictions that affect them.
As required by s.8(9) of the Act, the business contact for questions about how we process personal data is:
Grievance Officer, ZeroBridge Consultants
Email: [email protected]
Telephone: +91-8899010801
Post: 568-A, Gandhi Nagar, Jammu – 180004, Jammu and Kashmir, India
We are not currently required to appoint a Data Protection Officer under s.10 of the Act, as we have not been notified as a Significant Data Fiduciary. The contact above is the person able to answer questions on our behalf about the processing of personal data.
We will update this notice when our practices change or when the DPDP Rules, 2025 and Data Protection Board guidance develop. The effective date below always reflects the current version. Where a change materially affects how we process personal data you have already given us, we will tell you directly rather than relying on you to notice an update here.
Effective 28 August 2026. This page replaces any earlier version.
Copyright © ZeroBridge Consultants. All Rights Reserved.