1. Who we are
Enricx Private Limited (CIN: U62011KA2026PTC218527), Bengaluru, India, is the data fiduciary responsible for the personal data described in this policy. For any privacy matter, write to privacy@enricx.com.
2. Scope
This policy covers the public website at enricx.com and its sub-domains, including the “Get in touch” contact form. It does not cover our products (Penricx, Swymly, Phitrix) or any client engagement, which are governed by their own agreements and notices.
3. Personal data we collect
3.1 Information you give us (contact form)
- Name — required.
- Business email address — required. Consumer and disposable email domains are not accepted.
- Product or service interest — required (the option you select).
- Country — required; tells us which privacy law applies to you.
- Your consent — the checkbox you tick, recorded with the time and the version of this policy you agreed to.
- Company website and phone number — optional.
3.2 Information collected automatically
- Submission timestamp, stored with your enquiry.
- Bot-protection signals. The contact form is protected by Cloudflare Turnstile, which processes your IP address and browser characteristics to distinguish people from automated traffic. This processing is performed by Cloudflare, Inc. under Cloudflare’s privacy policy.
- Request logs. When you submit the form we record your IP address, the time of the request and whether it succeeded, for security and abuse prevention. These logs are kept for up to 90 days. Your IP address is not stored with your enquiry.
3.3 Cookies, analytics and tracking
We do not use advertising or cross-site tracking cookies, and our analytics (described below) sets no cookies at all. Cloudflare Turnstile may set strictly necessary cookies or use local storage solely to complete its bot check. Web fonts are served from our own domain; no request is made to a third-party font service.
First-party usage analytics (no cookies). To understand which parts of our website are useful, we collect usage events — pages and sections viewed, time spent, clicks, the site you came from and any campaign tags in the link you followed — directly on our own infrastructure in AWS ap-south-1 (Mumbai, India). No analytics data is shared with, or collected by, any third-party analytics or advertising service; it is processed and stored only on our AWS infrastructure in India (section 6). We store no lasting identifier on your device: a random session reference lives only in your browser tab’s short-term memory (sessionStorage) and is deleted when the tab closes.
What we derive from your IP address. When an event reaches our server, we use your IP address in memory only to (a) derive your country and the name of the network it belongs to — for example a company network or an internet provider — using a copy of the IPinfo Lite database held on our own servers (IP address data powered by IPinfo; no data about you is sent to IPinfo), and (b) compute a one-way code that changes every day, used to count unique visitors. Your IP address is not stored with analytics data, and requests to our analytics endpoint are not kept in logs that contain your IP address — your IP address is used only momentarily in memory, as described above. The analytics records we keep are engineered so that we cannot tell who you are from them, and we do not combine them with anything that identifies you unless you submit the contact form (below).
If you prefer not to be counted at all, we honour your browser’s Global Privacy Control signal; when it is active, no usage events are sent from your browser.
If you submit the contact form, your enquiry is stored together with a summary of the pages you viewed on this website during that visit, so we can understand what you were interested in. That summary becomes part of the enquiry data in section 3.1 and is processed on the basis of the consent you give when you submit the form.
4. Why we process your data and on what basis
We process contact-form data, and limited website usage data, for the following purposes:
- to respond to your enquiry and schedule a consultation;
- to share information about the product or service you expressed interest in;
- to prevent spam, abuse and automated misuse of the form;
- to keep a record of enquiries for business administration;
- to understand, in aggregate, how our website is used — including which countries and organisations’ networks visits come from — and to improve the site and our outreach (via the cookie-less analytics described in section 3.3).
Our legal basis under the DPDP Act is your consent, which you give when you submit the form after reading this notice. You may withdraw consent at any time (see section 8). Security logging relies on the legitimate use of preventing and detecting unauthorised access.
We do not sell personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.
5. Where your data is stored
Your enquiry is stored in India. Contact-form submissions are stored in an AWS-managed database in AWS ap-south-1 (Mumbai, India), encrypted at rest with a key that we control and in transit with TLS 1.2+. Access is limited to named roles that require multi-factor authentication, and every access is logged.
If you are outside India, submitting the form means your details are sent to and stored in India. We apply the same safeguards to everyone. The internal notification we receive when you submit the form contains no personal data — only your country, the product you are interested in, your company's website domain and a reference number.
6. Third parties who process your data
| Processor | Service | Purpose | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Managed cloud hosting, compute, database, encryption, email delivery and logging services | Receiving, validating, storing and notifying us of submissions; security logs and audit trail; usage-analytics events (section 3.3) | India (ap-south-1, Mumbai) |
| Microsoft Corporation | Microsoft 365 (Exchange Online) | Receives the internal notification email (contains no personal data) | Per our Microsoft 365 tenant region |
| Cloudflare, Inc. | Turnstile | Bot protection on the contact form | Global edge network |
We may also disclose personal data where required by law, a court order or a lawful request from a government authority, or to protect our rights, safety or property.
7. How long we keep your data
- Contact-form submissions are retained for 36 months from the date of submission and are then deleted automatically (automated expiry; deletion completes within a few days of expiry), unless a longer period is required by law or you have become a client, in which case the client agreement governs.
- Deleted records may persist in encrypted point-in-time-recovery backups for up to 35 days before they are purged.
- Notification emails contain no personal data and are kept under our normal mailbox rules.
- Request logs are retained for up to 90 days.
- Usage analytics events (which are not linked to your identity) are retained for up to 13 months, then deleted automatically.
You can ask us to delete your data earlier at any time (section 8).
8. Your rights under the DPDP Act
As a data principal you have the right to:
- access a summary of the personal data we hold about you and the processing activities it is used for;
- correct, complete or update inaccurate data;
- erase your data once it is no longer needed for the purpose it was collected for;
- withdraw consent at any time, with prospective effect;
- nominate another person to exercise these rights on your behalf in case of death or incapacity;
- grievance redressal (section 9).
To exercise any right, email privacy@enricx.com from the address you used on the form (or provide enough information for us to verify your identity). We respond within 30 days. Deletion requests are honoured by removing the record from our systems (located by a one-way hash of your email address) and from any system we have shared it with, and confirming to you by email. We keep a log of the request itself — date, type and a one-way hash of the address — as evidence that it was fulfilled; that log contains no personal data.
9. Grievance redressal
If you have a concern about how we handle your personal data, contact our Grievance Officer, Sivaramakrishna Kasimahanthi, at privacy@enricx.com, Enricx Private Limited, Bengaluru, India. We acknowledge grievances within 7 days and aim to resolve them within 30 days. If you are not satisfied with our response, you may approach the Data Protection Board of India in accordance with the DPDP Act.
10. Security
We apply technical and organisational measures appropriate to the data we hold, including TLS-only transport, strict browser security headers, server-side input validation, bot protection, encrypted storage and least-privilege access. Details and our responsible disclosure policy are on the Security page.
11. Additional information for visitors in the EU, EEA, UK and Switzerland
If you are in one of these territories, the GDPR or UK GDPR may apply to your enquiry. Enricx Private Limited is the controller. Our lawful basis is your consent (Article 6(1)(a)), which you may withdraw at any time by emailing privacy@enricx.com. In addition to the rights in section 8 you have the rights to restrict processing, to data portability, and to lodge a complaint with your local supervisory authority. Your data is stored in India (section 5); you provide it to us directly, and we apply the safeguards described in this policy to it. Our usage analytics (section 3.3) sets no cookies and stores no lasting identifier on your device; the only thing written to your browser is a per-tab session reference that is deleted when the tab closes, and you can object to the measurement altogether as described in section 3.3. The momentary use of your IP address to derive a country and network name relies on our legitimate interests in understanding and improving our website (Article 6(1)(f)); you have the right to object (Article 21). The analytics records we retain are engineered so that they cannot be linked back to you. Our usage analytics measures how the site is used without identifying or profiling individual visitors, and we do not otherwise monitor people in these territories. We have not appointed an EU or UK representative; we will do so if our processing changes in a way that requires one.
12. Children
Our website and services are directed at businesses and are not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. The “last updated” date at the top reflects the current version. Material changes will be highlighted on this page.
14. Contact
Enricx Private Limited · CIN: U62011KA2026PTC218527
Bengaluru, India
Privacy: privacy@enricx.com
Security: security@enricx.com