Legal
Privacy & data handling.
How Windsor Harlow handles personal data on this website and inside client engagements — under India's Digital Personal Data Protection Act, 2023 and, where EU or UK personal data is involved, the GDPR and UK GDPR.
- Controller
- Windsor Harlow, India
- Contact
- business@windsorharlow.com
- Last updated
- On publication
Before publishing: insert your registered entity name, CIN, registered office address, and the named grievance officer required under section 13 of the DPDP Act. Have a lawyer in your jurisdiction review this page — it is a well-structured starting point, not legal advice.
1. Who we are
Windsor Harlow is a technology consultancy registered in India, delivering services to clients in the United States and the European Union. For website enquiries we act as the data fiduciary (controller). Inside client engagements we normally act as a data processor on our client's instructions, governed by the data processing terms in the engagement agreement.
2. What we collect on this website
- Enquiry form data — name, work email, company, selected practice, engagement model, timeline and the description you write.
- Server logs — IP address, user agent, requested URL and timestamp, retained for security and abuse prevention.
- No advertising or cross-site tracking cookies. We do not run advertising pixels or sell data to anyone.
3. Why we process it
- To reply to your enquiry and scope potential work — on the basis of your consent, and our legitimate interest in responding to business contact.
- To keep the site secure and available — legitimate interest.
- To meet accounting, tax and contractual record-keeping obligations — legal obligation.
4. How long we keep it
Enquiries that do not become engagements are deleted within 24 months. Engagement records are retained for the period required by Indian tax and contract law, and by the terms of the relevant agreement. Server logs are retained for 90 days.
5. International transfers
We are based in India and process data there. Where we process personal data on behalf of an EU or UK client, transfers are covered by Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the technical and organisational measures set out in the engagement agreement.
6. Client data inside engagements
Where an engagement requires access to systems containing personal data, we work to the following defaults, tightened where a client's own policy is stricter:
- Least-privilege, time-boxed access, granted through the client's own identity provider wherever possible.
- No production personal data copied to engineer workstations. Anonymised or synthetic data for development and testing.
- Secrets held in a managed secret store — never in code, tickets or chat.
- Access revoked at engagement close, with confirmation provided in writing.
- NDA signed before scoping, on request.
7. Your rights
Under the DPDP Act you may request access to, correction of, or erasure of your personal data, nominate another person to exercise your rights, and raise a grievance with us. Under the GDPR and UK GDPR, where applicable, you additionally have rights to restriction, portability and objection, and the right to lodge a complaint with your supervisory authority.
To exercise any of these, email business@windsorharlow.com. We respond within 30 days.
8. Subprocessors
This site is served from a commercial hosting provider, and enquiry emails are delivered through a transactional email provider. A current list of subprocessors, with their locations, is available on request — and is provided as a matter of course in any engagement involving personal data.
9. Changes
Material changes to this notice are published on this page with a revised date. Where a change affects processing you have consented to, we will seek fresh consent.