Privacy notice · v3.1 · effective 20 August 2026

A privacy notice you can
actually read.

We sell consent infrastructure, so this page is held to our own standard: plain language, specific purposes, real retention periods, and rights you can exercise with one email.

The short version

This website sets no tracking cookies, uses no third-party analytics, and loads no third parties — the fonts, and our own self-hosted, opt-in analytics, are all served from our own domain. The only browser storage is strictly necessary regardless of that choice (see the cookie & storage policy). The only personal data this website collects from you is what you choose to give on the demo form, and only with your consent — but we hold personal data for other purposes too, and section 2 now lists all of them.

1 · Who we are (Data Fiduciary / Controller)

Consent Tree operates this website and decides why and how your personal data is processed. Under the Digital Personal Data Protection Act, 2023 (India) we are the Data Fiduciary; under the EU/UK GDPR we are the Data Controller. You can reach our Data Protection point of contact / Grievance Officer at cdpo@consentree.in.

2 · What we collect, why, and on what basis

If you submit the demo request form, we collect your name, work email, company, role, and anything you write in the message box. Purpose: to respond to your enquiry and schedule the demo you asked for; and, only if you separately opt in, to send occasional product updates. Legal basis: your consent (DPDP §6; GDPR Art 6(1)(a)), captured itemised and per-purpose on the form itself. No marketing lists, no enrichment, no resale, no automated decision-making or profiling.

That is what this website collects. We also hold personal data for four other purposes, listed here because a notice that mentions only the form would be describing part of what we do:

  • Prospect research. Organisation details and published role-based addresses for businesses we research. Basis: under review — whether business contact details compiled from public registers fall within this Act is a question we are taking advice on, and we would rather say so than state a basis we are unsure of. We use published role addresses rather than personal ones, we record where every record came from, we never probe mailboxes to test whether they exist, and if you ask us to stop we suppress you permanently.
  • Our own staff and administrator accounts. Name and work email, to operate the platform and to record who did what. Basis: DPDP §7(i), employment. Kept 365 days after the role ends.
  • Our data-protection contact record. Name, work email and phone for the person able to answer questions about personal data, so you and our Board can reach them. Deliberately not titled "Data Protection Officer": §2(l) defines that term as an appointee of a Significant Data Fiduciary, and we are not one — §8(9) and Rule 9 both say "a Data Protection Officer, if applicable, or a person who is able to answer", and we are the second. Basis: DPDP §7(i), employment. Kept 365 days after the role ends.
  • Consent records. The consent itself, including the IP address and browser it was given from. Basis: your consent; the record is kept because the Act places the burden of proving consent on us (§6(10)).

What we do not collect. For our own purposes we hold no health, financial, biometric or genetic data, no government identifiers such as Aadhaar or PAN, and no children's data. We verified this by scanning every database in our estate on 19 August 2026 — 14 databases, every one registered and scanned. We publish the limit of that check too: 112 of 502 candidate columns were examined, and the rest are recorded as could not assess rather than as clean.

What this notice does not cover. Personal data our customers process through the Consent Tree platform. For that the customer is the Data Fiduciary, we act on their instructions, and their notice governs it — not this one.

3 · Cookies & storage

No advertising or analytics cookies, no pixels, no fingerprinting, no third-party trackers. We use only strictly-necessary browser storage — remembering your cookie choice and theme, and the consent you give on our forms. If you separately grant the Analytics category on the banner, we load our own self-hosted analytics (Umami) — it sets no cookies or storage of its own. The readiness quiz runs entirely in your browser. Full detail, including each item and its lifetime, is in the cookie & storage policy. You can verify there are no third-party calls from your browser’s network inspector — we encourage it.

4 · How long we keep it

Demo-request details are kept while we’re in an active conversation and deleted no later than 12 months after our last contact. If you opt in to product updates, we keep your email for that purpose for up to 24 months or until you withdraw — whichever is earlier. Earlier on request, always.

5 · Your rights

Under the DPDP Act you may access, correct, update or erase your personal data, withdraw consent at any time (as easily as you gave it — via the withdrawal page), nominate another person to exercise your rights (§14), and raise a grievance. EU/UK visitors additionally have the rights to restriction, portability, and objection under the GDPR. One email starts any of these: cdpo@consentree.in. Erasure runs through our own DSR pipeline and returns a tamper-evident receipt.

We honour all of these today, and we are ahead of the law in doing so. The Act commences in tranches: under G.S.R. 843(E) of 13 November 2025, sections 3 to 17 — which include notice, consent and every right listed above — come into force on 13 May 2027. We would rather say so plainly than describe a duty that has not started. Ask us for any of these now and we will do it.

6 · Complaints & where your data goes

If we don’t resolve your concern, you may complain to the Data Protection Board of India; EU/UK residents may complain to their local supervisory authority. Your data is hosted on infrastructure in India; if any processing or transfer occurs outside your region, it is done under safeguards permitted by applicable law. We do not sell your data or share it with advertisers.

7 · How we protect it

We apply reasonable security safeguards (DPDP §8): access controls, encryption of sensitive identifiers, tenant isolation, and an append-only, cryptographically-chained audit trail for every consent and erasure. We collect the minimum needed and never store your form data in your browser.

8 · Changes to this notice

If this notice materially changes, the version and effective date at the top change with it — the same versioned-notice discipline our consent engine enforces for customers.