1. Who we are
For the purposes of data-protection law, the data controller is Codescapeai LLP — a Limited Liability Partnership registered in India, operating a product studio at Tajpur, Samastipur, Bihar, India, reachable by email at contact@codescapeai.com and by phone at +919064959128. We have been operating continuously since 2012.
We do not currently maintain a physical establishment in the European Union or the United Kingdom, so we are not required to appoint a formal GDPR representative. We do, however, commit to cooperating in good faith with any supervisory authority that contacts us about a complaint from one of their residents.
2. Scope of this policy
This policy applies to:
- Visits to codescapeai.com and any subdomain we operate.
- Information you submit through our contact form, project brief, or newsletter signup.
- Comments or testimonials you submit to our blog.
- Any client services we host or operate on your behalf under a written contract.
Client engagements are also governed by the master services agreement (or equivalent) signed with the client. Where this policy and that contract conflict, the contract wins for the data it covers.
3. Information we collect
Information you give us
When you contact us, subscribe to the newsletter, or comment on the blog, you may give us your name, email, phone number, company, and a free-text project brief. We collect only what we need to reply to you.
Information collected automatically
Like most websites, our servers log the request: your IP address, user-agent string, referrer, the page requested, and the time. We derive an approximate country from the IP address for analytics; we do not store precise geolocation.
Cookies and similar technologies
See our Cookie Policy for a full inventory of the cookies and local-storage items we set.
Information from third parties
Our content (blog posts, portfolio entries, testimonials) is hosted by Sanity, our headless CMS. When you read content served from Sanity, the request passes through their infrastructure; their privacy notices apply to that data path.
4. Why we use your data (legal bases)
Under the EU/UK General Data Protection Regulation we must tell you the legal basis for each processing activity. The relevant bases (GDPR Article 6) for our processing are:
- Contract necessity— to deliver the services you have commissioned us to build.
- Legitimate interests— to respond to your enquiries, secure the site, and measure aggregate traffic patterns. We balance these interests against yours and never use this basis in a way that overrides your fundamental rights.
- Consent— for the newsletter, for any non-essential cookies, and for any marketing that isn’t covered by the bases above. You can withdraw consent at any time without affecting prior processing.
- Legal obligation— to keep tax, accounting, and statutory records for the periods required by Indian law.
5. How long we keep your data
We retain personal data only as long as we have a reason to keep it:
- Enquiry emails: 24 months from last contact.
- Project files and deliverables: per the duration of the client contract, plus the statutory records period.
- Newsletter subscription: until you unsubscribe, plus 30 days for processing the unsubscribe.
- Web server access logs: 30 days.
- Encrypted backups: 90 days rolling.
After the retention period ends, data is either deleted or anonymised so it can no longer be associated with you.
7. International transfers
Some of our sub-processors are located outside India, including in the United States and the European Union. When we transfer your data across borders we rely on appropriate safeguards — the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, or equivalent legal mechanisms — and we verify that the receiving country offers adequate protection where required.
8. Your rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data (subject to our statutory retention obligations).
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint — with your local data-protection authority.
To exercise any of these rights, email contact@codescapeai.com with the subject line “Privacy request”. We respond within 30 days. We may need to verify your identity before acting on the request to prevent fraud.
9. Children’s data
Our site is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at contact@codescapeai.com and we will delete it.
10. Security
We protect personal data with industry-standard safeguards: TLS in transit, encryption at rest where the underlying service supports it, role-based access controls, hardware-security-key multi-factor authentication on production systems, and regular staff training. No system is 100% secure; if a breach affects your data we will notify you and the relevant supervisory authorities as required by law.
11. Changes to this policy
Material changes will be announced with a banner on the site and via a notice at the top of this page. Non-material changes are reflected in the “Last updated” date above. We encourage you to review this policy periodically.
12. Contact us
The fastest way to reach the team responsible for privacy is contact@codescapeai.com. Postal correspondence can be sent to Tajpur, Samastipur, Bihar, India.
