Legal
Privacy Policy
Effective Date: March 2026 · Last Reviewed: August 2026
This policy states what personal data CivicLayer Technologies collects from visitors to consentos.in and users of the ConsentOS platform, why we collect it, how long we keep it, and what rights you hold over it under the Digital Personal Data Protection Act 2023.
CivicLayer Technologies Private Limited ("CivicLayer Technologies", "we", "our", "us")
Incorporated in India under the Companies Act 2013
CIN: U62011HR2026PTC146035
GSTIN: 06AANCC8790K1ZX
Registered Address: H40/8A, Upper Ground Floor, DLF Phase 1, DLF QE, Gurgaon 122002, Haryana, India
Effective Date: March 2026
1. Who This Policy Applies To
This policy applies to:
- Visitors to consentos.in
- Businesses and individuals who register for or use a ConsentOS account
- Contacts who submit inquiries through our website or by email
2. Data We Collect
Website visitors
When you visit consentos.in, we collect log data including your IP address, browser type, pages visited, and timestamps. This data is used to monitor site performance. It is not used to build individual profiles or for advertising purposes.
This website sets no cookies of its own. The ConsentOS platform sets a session cookie once you sign in. Section 8 states the full position.
Account registration
When you create a ConsentOS account, we collect your name, business email address, company name, and job role. This information is necessary to create and maintain your account.
Platform usage
While you use the ConsentOS platform, we collect usage data including feature access logs, API call records, and error reports. This data is used to maintain platform reliability and diagnose technical issues.
Inquiries and communications
If you contact us by email or through a website form, we retain the content of that communication along with your contact details, for as long as the inquiry remains open and for 12 months after it is resolved.
3. How We Use Your Data
We use the data described above for the following purposes:
- Creating and maintaining your ConsentOS account
- Delivering the platform and its features
- Sending transactional communications, including account confirmations, product updates, and billing notifications
- Complying with our obligations under the DPDP Act 2023 and other applicable Indian law
- Diagnosing and resolving technical issues
- Improving platform reliability and performance
We do not sell personal data. We do not use personal data for advertising targeting on third-party platforms.
4. Third-Party Processors (Sub-processors)
To operate ConsentOS, we share certain personal data with the following third-party processors. Each processor is engaged under contractual terms that require it to handle your data in accordance with applicable law. Infrastructure providers in India hold platform data at rest; the United States providers receive only the categories listed against them.
| Processor | Country | Purpose | Data Transferred |
|---|---|---|---|
| HubSpot Inc. | United States | Contact management and CRM | Name, email address, company name, inquiry content |
| Resend Inc. | United States | Transactional email delivery | Name, email address |
| Razorpay Software Private Limited | India | Subscription and implementation fee payments | Name, email address, phone number, payment instrument details. Card and UPI data are collected by Razorpay directly; ConsentOS receives payment references only |
| Cloudflare Inc. | United States | Website hosting, edge security, and inbound email routing for @consentos.in mailboxes | Log data, platform data (encrypted in transit) |
| Oracle Cloud Infrastructure | India (Asia Pacific Mumbai) | Virtual machine hosting the ConsentOS platform database | Platform data at rest, including customer tenant records |
| Amazon Web Services | India (Asia Pacific Mumbai) | Encrypted offsite copies of the platform database, retained for 35 days under a deletion lock | Database backups, encrypted with a customer-managed key |
| Better Stack | Data location as published by the provider | Uptime monitoring and application log ingestion | Operational log lines and monitor results. No personal data by design |
Data transfers to processors outside India are made under appropriate contractual safeguards in accordance with the DPDP Act 2023.
5. Your Rights
Under the DPDP Act 2023, you have the following rights over your personal data:
Right to access. You may request a summary of the personal data we hold about you.
Right to correction. You may request that we correct inaccurate or incomplete data.
Right to erasure. You may request that we delete your personal data. We will do so within 30 days of receiving a verified request, except where retention is required by law.
Right to withdraw consent. Where processing is based on your consent, you may withdraw it at any time. Withdrawal takes effect from the date of your request and does not affect the legality of processing carried out before that date.
Right to nominate. You may nominate another individual to exercise these rights on your behalf.
Right to grievance redressal. If you are not satisfied with how we have handled your data or your rights request, you may raise a complaint with our Grievance Officer (Section 9) or with the Data Protection Board of India.
To exercise any of these rights, contact our Grievance Officer using the details in Section 9.
6. Data Retention
We keep personal data for as long as your account remains active.
When you close your account:
- Account data is deleted within 90 days
- Billing records are retained for 7 years for tax compliance
- Log and usage data is retained for 12 months, then deleted
If you contact us without creating an account, we retain your inquiry data for 12 months from the date of last contact.
7. Data Security
ConsentOS platform data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Access to personal data is restricted to personnel who require it for operational purposes, and all access is logged and reviewed.
We maintain incident response procedures for security events. On any personal data breach affecting your personal data, we intimate affected individuals without delay, and we intimate the Data Protection Board of India in the manner and within the timelines the DPDP Rules 2025 prescribe under Rule 7, including the detailed report due within 72 hours of becoming aware of the breach. No risk threshold applies: Rule 7 attaches to every personal data breach, not only to those we judge severe. Rule 7 becomes enforceable on 13 May 2027, and we operate to it now. Where an incident is also a reportable cyber security incident, we report to CERT-In within the six-hour window already in force under the CERT-In Directions 2022.
No transmission over the internet is entirely secure. We maintain these controls to reduce risk to a responsible minimum, and we will continue to review and improve them as the platform grows.
8. Cookies
consentos.in sets no cookies of its own. The marketing pages are prerendered. Our edge provider, Cloudflare, may set a short-lived security cookie only if it serves a bot challenge to your browser. The site runs no analytics script, no tag manager, and no advertising or cross-site tracking tag, so there is nothing to opt out of and no cookie preferences panel is presented. Two interactive tools keep your own entries in your browser's own storage so your progress survives a reload: the compliance checklist uses local storage, and the gap assessment uses session storage, which your browser discards when you close the tab. Neither is a cookie. That data stays on your device until you submit the assessment form.
Essential cookies on the platform. The ConsentOS platform at app.consentos.in sets session cookies once you sign in. They carry your authentication session and nothing else. They are required for the platform to function and cannot be disabled while you are signed in. Signing out ends the session.
Traffic measurement without cookies. We understand site traffic from the aggregated request logs our hosting provider generates at the edge (Section 4). That measurement sets no cookie, runs no script in your browser, and is not used to build individual profiles.
9. Grievance Officer
In accordance with the DPDP Act 2023, CivicLayer Technologies has appointed a Grievance Officer to receive and address inquiries and complaints related to personal data handling.
Name: Swati Jain
Designation: Grievance Officer, CivicLayer Technologies Private Limited
Email: privacy@consentos.in
Address: H40/8A, Upper Ground Floor, DLF Phase 1, DLF QE, Gurgaon 122002, Haryana, India
We will acknowledge your inquiry within 48 hours. We will provide a substantive response within 30 days of receiving your complaint.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.
10. Changes to This Policy
We may update this policy when our data practices change or when required by law. If we make material changes, we will notify active account holders by email at least 14 days before the changes take effect.
The current version of this policy is always available at consentos.in/privacy. The effective date at the top of this page reflects when the current version came into force.
11. Contact
For questions about this policy that are not a rights request:
Email: hello@consentos.in
For rights requests and complaints, contact the Grievance Officer at privacy@consentos.in.