Privacy Policy
1. Introduction
This Privacy Policy describes how Grids and Guides Technologies Private Limited ("Grids and Guides," "we," "us," or "our") collects, uses, discloses, and protects personal data in the course of operating our website at gridsandguides.com, engaging with prospective clients, delivering professional services, and hiring talent.
We treat personal data as material we hold in trust. This document sets out the specifics of that responsibility. It is written to satisfy the requirements of the Digital Personal Data Protection Act, 2023 of India ("DPDP Act"), the General Data Protection Regulation of the European Union (Regulation (EU) 2016/679) ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection laws in jurisdictions where we operate.
If any provision of this Privacy Policy conflicts with an executed data processing agreement, master services agreement, or statement of work between you and Grids and Guides, the terms of that agreement will prevail with respect to the subject matter it covers.
2. Who we are
Grids and Guides Technologies Private Limited is a company incorporated in India under the Companies Act, 2013.
- Corporate Identification Number (CIN): U62013TN2023PTC161693
- Registered office: 143/6C, 2B, 2nd Floor, Durga Enclave, Easwaran St, Karapakkam (OMR), Chennai, Tamil Nadu 600097, India
- Contact email: [email protected]
For the purposes of the GDPR, Grids and Guides acts as a Data Controller with respect to personal data collected through our website, marketing activities, hiring processes, and business development. For personal data processed on behalf of a client under a services engagement, we act as a Data Processor and the client remains the Data Controller.
For the purposes of the DPDP Act, Grids and Guides acts as a Data Fiduciary with respect to the personal data referenced above, and as a Data Processor when acting under written instruction from a Data Fiduciary client.
3. Categories of personal data we collect
The categories of personal data we collect depend on how you interact with us.
3.1 Website visitors. When you visit gridsandguides.com, we collect your IP address, browser type, operating system, referring URL, pages viewed, time of visit, and clickstream data. We also collect information stored in cookies and similar technologies. See our Cookie Policy for details.
3.2 Prospective clients and business contacts. When you submit an inquiry, subscribe to our Insights, request a diagnostic, or otherwise reach out to us, we collect your name, business email address, organisation name, role, country, and the content of your communication.
3.3 Client engagement personnel. When we deliver services under an engagement, we may collect the name, business contact details, and professional information of your personnel who interact with our team.
3.4 Job candidates. When you apply for a role, we collect your name, contact details, curriculum vitae, work history, professional references, right-to-work information, interview notes, and assessment results.
3.5 Vendors and partners. When we contract with a vendor, sub-processor, or partner, we collect the name, business contact details, and payment information of the individuals we transact with.
3.6 Personal data we do not intentionally collect. We do not intentionally collect special categories of personal data (as defined under GDPR Article 9) or sensitive personal data (as defined under the DPDP Act) through our website. If you volunteer such information in an unsolicited communication, we will handle it in accordance with the strictest applicable protection and delete it when it is no longer needed for the purpose you shared it.
4. How we collect personal data
We collect personal data directly from you when you provide it, automatically through your interaction with our website, and from limited third-party sources such as professional networking platforms (for business development), background verification providers (for candidates, with consent), and publicly available business registers.
5. Purposes and legal bases for processing
The table below sets out each purpose for which we process personal data and the corresponding legal basis under the GDPR. Under the DPDP Act, we process personal data on the basis of consent for lawful uses, and on the basis of legitimate uses where permitted by the Act (for example, employment purposes and compliance with law).
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to your inquiry | Article 6(1)(b) contract preparation, or 6(1)(f) legitimate interest |
| Sending Insights and other content you subscribed to | Article 6(1)(a) consent |
| Delivering contracted services | Article 6(1)(b) contract performance |
| Recruitment and hiring | Article 6(1)(b) pre-contract steps, and 6(1)(f) legitimate interest in assessment |
| Website analytics and improvement | Article 6(1)(f) legitimate interest, subject to your cookie preferences |
| Security monitoring and fraud prevention | Article 6(1)(f) legitimate interest |
| Regulatory and legal compliance | Article 6(1)(c) legal obligation |
| Corporate transactions (e.g., due diligence) | Article 6(1)(f) legitimate interest |
Where we rely on consent, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
6. Automated decision-making and profiling
We do not use personal data collected through our website to make automated decisions producing legal or similarly significant effects on you.
Our professional services include the design and deployment of AI systems, some of which may perform automated decision-making. Where we build such systems on behalf of a client, the client remains the Data Controller and is responsible for the disclosures, consent flows, and rights mechanisms required under applicable law. Our engagement contracts require alignment with the EU AI Act, the DPDP Act, and other applicable regulations governing automated decisions.
8. International data transfers
Grids and Guides is headquartered in India, and our sub-processors are located in multiple jurisdictions including the European Economic Area, the United Kingdom, the United States, and Singapore. Personal data may therefore be transferred internationally.
When we transfer personal data from the EEA, the UK, or Switzerland to countries not subject to an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Module 1, 2, 3, or 4 as applicable), the UK International Data Transfer Addendum, and, where warranted, supplementary technical and organisational measures.
When we transfer personal data outside India, we do so in accordance with the DPDP Act and any restrictions the Central Government may notify from time to time.
9. Data retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, to comply with legal, regulatory, or contractual obligations, or to establish, exercise, or defend legal claims.
Indicative retention periods:
- Website analytics data: 26 months from collection
- Business inquiry correspondence: 24 months after last contact
- Insights subscriber records: until you unsubscribe, plus 12 months for suppression
- Job application records for unsuccessful candidates: 12 months from the decision, unless you consent to a longer period
- Client engagement records: for the duration of the engagement, plus 7 years to satisfy statutory retention requirements under Indian law
- Vendor and payment records: 8 years, in line with statutory tax and audit requirements
At the end of the applicable retention period, personal data is either deleted, anonymised, or archived under restricted access.
10. Your rights
Subject to the conditions and exceptions set out in applicable law, you have the following rights.
10.1 Under the GDPR (EEA, UK, Switzerland).
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object to processing (Article 21)
- Right not to be subject to solely automated decision-making (Article 22)
- Right to withdraw consent
- Right to lodge a complaint with your supervisory authority
10.2 Under the DPDP Act (India).
- Right to access information about personal data
- Right to correction and erasure
- Right of grievance redressal
- Right to nominate another individual to exercise your rights in the event of your death or incapacity
10.3 Under the CCPA/CPRA (California residents).
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information
- Right to correct inaccurate personal information
- Right to opt out of sale or sharing of personal information (we do not sell or share personal information as those terms are defined under CCPA)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your rights
To exercise any of these rights, please contact our Grievance Officer using the details in Section 14. We will respond within the timeframes required by the applicable law.
11. Security
We maintain administrative, technical, and physical safeguards designed to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, and destruction. Our information security programme is aligned to ISO/IEC 27001 and SOC 2 Trust Services Criteria. It includes access control, encryption in transit and at rest for sensitive data, network segmentation, secure software development lifecycle practices, security monitoring, incident response planning, and periodic third-party assessment.
No system is impenetrable. If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, the affected individuals in accordance with applicable law.
13. Children's privacy
Our services and website are directed to businesses and to individuals over the age of 18. We do not knowingly collect personal data from children under 18. If you become aware that a child has provided us with personal data, please contact us and we will take reasonable steps to delete such information.
Under the DPDP Act, we do not process personal data of children (individuals under 18) or persons with disabilities in a manner that is likely to cause any detrimental effect. We do not track, target advertising to, or profile children.
14. How to contact us
Grievance Officer (Digital Personal Data Protection Act, 2023, India)
Jaswant K Email: [email protected] Address: Grids and Guides Technologies Private Limited, 143/6C, 2B, 2nd Floor, Durga Enclave, Easwaran St, Karapakkam (OMR), Chennai, Tamil Nadu 600097, India
The Grievance Officer is designated to receive and address grievances relating to personal data processing under the DPDP Act, and also serves as our primary contact for data subject requests under the GDPR and CCPA/CPRA. We will acknowledge receipt of your grievance within 72 hours and resolve it within the timeframe prescribed under the applicable Act.
General privacy inquiries: [email protected]
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will update the "Last updated" date at the top of this policy and, where appropriate, notify you by email or through a notice on our website. Please review this policy periodically.
16. Governing law
This Privacy Policy is governed by the laws of India, without prejudice to any additional protections available to you under the data protection laws of your jurisdiction of residence.

