Privacy Notice
How Regulens Technologies Private Limited collects, uses, shares and protects personal data across our website, platform and business operations, under the Digital Personal Data Protection Act, 2023.
Last updated
This notice explains how Regulens Technologies Private Limited ("Regulens", "we") handles personal data, in line with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000. It covers our website, our platform, and our dealings with prospective and existing customers. It is written to be read, not to be survived.
Who we are
Regulens Technologies Private Limited is the Data Fiduciary for personal data described in this notice, incorporated in India (CIN U72900KA2021PTC148802), with its registered office at Prestige Trade Tower, 8th Floor, 46 Palace Road, Vasanth Nagar, Bengaluru 560001, Karnataka.
For personal data that our customers upload into the platform, our customer is the Data Fiduciary and Regulens acts as Data Processor. That relationship is governed by our Data Processing Addendum rather than by this notice.
What we collect
Information you give us. Name, work email, organisation, job title and anything you write in a form or email. If you subscribe to the Monday Briefing we hold your email and preferences.
Information from your use of the website. Pages visited, referring page, approximate location derived from IP address, browser and device type. We keep this in aggregate for understanding what is useful and do not use it to build individual profiles.
Platform account data. For users of the platform: identity, authentication events, entitlements, and a record of actions taken, retained as an audit trail because our customers are required to have one, and because several of the statutes we help track require it of them.
Information from third parties. Where a colleague refers you, or where we obtain business contact details from a professional source, we tell you where we got them the first time we contact you.
Why we use it, and your consent
We process personal data on the basis of your consent, or where processing is necessary for a legitimate use permitted under the DPDP Act — such as responding to a request you have made, or for our own legitimate business purposes where your interests are not overridden.
| Purpose | Basis |
|---|---|
| Responding to your enquiry | Legitimate use — steps taken at your request |
| Providing and supporting the platform | Performance of contract with your organisation |
| Sending the Monday Briefing | Consent, withdrawable in one click |
| Security, fraud prevention and audit logging | Legitimate use and legal obligation |
| Improving the website and product | Legitimate use |
| Meeting our own legal and regulatory obligations | Legal obligation |
Where we rely on consent, the request is specific, itemised and as easy to withdraw as it was to give.
What we do not do
We do not sell personal data. We do not share it with advertising networks. We do not use customer content to train shared or third-party AI models. We do not run cross-site tracking or advertising cookies on this website. We do not treat any category of personal data as inherently exempt from care — the DPDP Act does not create a special category, and neither do we.
Cookies
We use strictly necessary cookies for session management and security, and a first-party analytics cookie that records page views without cross-site identifiers. You can decline the analytics cookie without losing any functionality. See the Cookie Notice for the full list.
Who we share it with
Service providers who process data on our behalf under contract — hosting, email delivery, customer relationship management, support tooling and AI inference providers. The current list is published in our sub-processor register.
Professional advisers where necessary, such as auditors and legal counsel.
Authorities where we are legally required to disclose, including the Data Protection Board of India or CERT-In where a request is validly made. We will notify you unless legally prohibited from doing so.
Where your data is processed
Our primary infrastructure is in India — Mumbai and Hyderabad regions. Where a transfer outside India is required for a specific service (for example, a globally operated sub-processor), we ensure it is to a country not restricted by the Central Government under the DPDP Act, and that appropriate contractual safeguards are in place.
Platform customers can select data residency within India as standard, with single-tenant and customer-hosted options for Enterprise agreements.
How long we keep it
- Enquiries that do not become customers: 24 months from last contact
- Newsletter subscriptions: until you unsubscribe, plus 12 months of suppression data so we do not re-add you
- Customer contract records: the contract term plus 8 years
- Platform audit logs: per the customer's configured retention, up to 15 years
- Website analytics: 14 months in aggregate
Your rights
Under the DPDP Act you have the right to obtain a summary of the personal data we hold about you and the processing activities relating to it, to correction and completion of your data, to erasure (unless retention is required by law), to grievance redressal, and to nominate another individual to exercise your rights on your behalf in the event of death or incapacity.
Where we rely on consent, you may withdraw it at any time, with the same ease with which it was given.
To exercise any of these, email privacy@regulens.in. We respond within thirty days. We will not charge you or make it difficult.
If you are unhappy with how we have handled your data and our response, you can file a complaint with the Data Protection Board of India.
Changes
We will update this notice when our practices change and record the date below. Where a change is material we will notify affected individuals directly rather than relying on you noticing.