Skip to content
RegulensR

Privacy Notice

How Regulens Technologies Private Limited collects, uses, shares and protects personal data across our website, platform and business operations, under the Digital Personal Data Protection Act, 2023.

Last updated

This notice explains how Regulens Technologies Private Limited ("Regulens", "we") handles personal data, in line with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000. It covers our website, our platform, and our dealings with prospective and existing customers. It is written to be read, not to be survived.

Who we are

Regulens Technologies Private Limited is the Data Fiduciary for personal data described in this notice, incorporated in India (CIN U72900KA2021PTC148802), with its registered office at Prestige Trade Tower, 8th Floor, 46 Palace Road, Vasanth Nagar, Bengaluru 560001, Karnataka.

For personal data that our customers upload into the platform, our customer is the Data Fiduciary and Regulens acts as Data Processor. That relationship is governed by our Data Processing Addendum rather than by this notice.

What we collect

Information you give us. Name, work email, organisation, job title and anything you write in a form or email. If you subscribe to the Monday Briefing we hold your email and preferences.

Information from your use of the website. Pages visited, referring page, approximate location derived from IP address, browser and device type. We keep this in aggregate for understanding what is useful and do not use it to build individual profiles.

Platform account data. For users of the platform: identity, authentication events, entitlements, and a record of actions taken, retained as an audit trail because our customers are required to have one, and because several of the statutes we help track require it of them.

Information from third parties. Where a colleague refers you, or where we obtain business contact details from a professional source, we tell you where we got them the first time we contact you.

We process personal data on the basis of your consent, or where processing is necessary for a legitimate use permitted under the DPDP Act — such as responding to a request you have made, or for our own legitimate business purposes where your interests are not overridden.

PurposeBasis
Responding to your enquiryLegitimate use — steps taken at your request
Providing and supporting the platformPerformance of contract with your organisation
Sending the Monday BriefingConsent, withdrawable in one click
Security, fraud prevention and audit loggingLegitimate use and legal obligation
Improving the website and productLegitimate use
Meeting our own legal and regulatory obligationsLegal obligation

Where we rely on consent, the request is specific, itemised and as easy to withdraw as it was to give.

What we do not do

We do not sell personal data. We do not share it with advertising networks. We do not use customer content to train shared or third-party AI models. We do not run cross-site tracking or advertising cookies on this website. We do not treat any category of personal data as inherently exempt from care — the DPDP Act does not create a special category, and neither do we.

Cookies

We use strictly necessary cookies for session management and security, and a first-party analytics cookie that records page views without cross-site identifiers. You can decline the analytics cookie without losing any functionality. See the Cookie Notice for the full list.

Who we share it with

Service providers who process data on our behalf under contract — hosting, email delivery, customer relationship management, support tooling and AI inference providers. The current list is published in our sub-processor register.

Professional advisers where necessary, such as auditors and legal counsel.

Authorities where we are legally required to disclose, including the Data Protection Board of India or CERT-In where a request is validly made. We will notify you unless legally prohibited from doing so.

Where your data is processed

Our primary infrastructure is in India — Mumbai and Hyderabad regions. Where a transfer outside India is required for a specific service (for example, a globally operated sub-processor), we ensure it is to a country not restricted by the Central Government under the DPDP Act, and that appropriate contractual safeguards are in place.

Platform customers can select data residency within India as standard, with single-tenant and customer-hosted options for Enterprise agreements.

How long we keep it

  • Enquiries that do not become customers: 24 months from last contact
  • Newsletter subscriptions: until you unsubscribe, plus 12 months of suppression data so we do not re-add you
  • Customer contract records: the contract term plus 8 years
  • Platform audit logs: per the customer's configured retention, up to 15 years
  • Website analytics: 14 months in aggregate

Your rights

Under the DPDP Act you have the right to obtain a summary of the personal data we hold about you and the processing activities relating to it, to correction and completion of your data, to erasure (unless retention is required by law), to grievance redressal, and to nominate another individual to exercise your rights on your behalf in the event of death or incapacity.

Where we rely on consent, you may withdraw it at any time, with the same ease with which it was given.

To exercise any of these, email privacy@regulens.in. We respond within thirty days. We will not charge you or make it difficult.

If you are unhappy with how we have handled your data and our response, you can file a complaint with the Data Protection Board of India.

Changes

We will update this notice when our practices change and record the date below. Where a change is material we will notify affected individuals directly rather than relying on you noticing.