Codexlab Enterprise
Pvt Ltd
  • Services
  • Products
  • Work
  • Contact
start_project()
PRIVACY
Codexlab Enterprise Pvt Ltd
Legal

Privacy Policy

What personal data we collect on codexlab.in and through our services, why we collect it, who it reaches, how long we keep it, and the rights you hold over it under the Digital Personal Data Protection Act, 2023.

Effective 28 August 2026 Last updated 28 August 2026 Version 1.0
Terms & Conditions Privacy Policy Refunds & Cancellation Looking for Zanoo? →

The short version

We are a business-to-business software company. We do not sell personal data, we do not run advertising networks, and we do not build profiles of you for marketing. The website collects only what you type into the contact form, plus the minimum technical logs needed to keep it online and secure.

This policy explains the detail. It applies to codexlab.in and to the personal data we handle as a business — enquiries, clients, candidates and vendors. It does not cover our products; for Zanoo, see the Zanoo Privacy Policy.

Who is responsible for your data

For the data described in this policy, Codexlab Enterprise Pvt Ltd is the Data Fiduciary (the equivalent of a "data controller") under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Data FiduciaryCodexlab Enterprise Pvt Ltd
CIN[CIN — to be filled]
Registered office[building, street], Kandivali West, Mumbai [PIN], Maharashtra, India
Privacy contactsupport@codexlab.in
Phone+91 73048 05318 · Mon–Sat, 10:00–19:00 IST

Personal data we collect

a. When you use the contact form

The enquiry form on our homepage collects exactly three fields, all of which you type yourself:

NameSo we know who we are replying to
Work emailThe address we reply to, and the address that receives your confirmation email
Your messageWhat you are trying to build. Please do not paste passwords, API keys, card numbers, government identifiers or other people’s personal data into this box.

b. When you browse the site

  • Server and edge logs kept by our hosting provider: IP address, timestamp, requested URL, referrer, user-agent, response status and approximate region. These are generated automatically by the infrastructure and are used to keep the site online, diagnose faults and detect abuse.
  • Local browser state used to render the site (for example, remembering that a mobile menu is open). This stays in your browser.

Cookies. codexlab.in does not set advertising, marketing or cross-site tracking cookies, and does not currently run a third-party analytics tag. If we add analytics in future, we will update this policy and, where the law requires it, ask for your consent before any non-essential cookie or tracker is set.

c. When you become a client

  • Business contact details of your team — names, roles, work emails, phone numbers.
  • Contractual and billing information — company name, registered address, GSTIN, PAN, purchase orders, invoices and payment records.
  • Project communications — email, messaging, call notes, tickets, meeting recordings where you have agreed to them.
  • Credentials and access you grant us for the duration of a project. We ask for least-privilege access and hand it back or ask you to revoke it at the end.

d. When you apply for a role or supply us

  • Candidates: CV, contact details, work history, portfolio links, interview notes and, if we make an offer, the documents required for onboarding.
  • Vendors and contractors: contact and bank details, tax registrations and invoices, as required to pay you and meet our statutory obligations.

We do not knowingly collect biometric data, health data, or financial account credentials through this website.

Why we use it, and on what basis

Under the DPDP Act we process personal data either with your consent, or for a legitimate use permitted by the Act (such as a purpose for which you voluntarily provided the data, or compliance with law).

Answering enquiriesTo read, reply to and follow up on what you send through the contact form — the purpose for which you voluntarily gave us the data.
Delivering projectsTo perform our contract with you: scoping, building, deploying, supporting and invoicing.
Running the websiteTo keep the site available, fast and secure, and to investigate errors and abuse.
Security & fraudTo detect and prevent spam, scraping, intrusion attempts and misuse of our forms and infrastructure.
Legal & accountingTo meet obligations under company, tax, GST and employment law, and to establish or defend legal claims.
RecruitmentTo assess applications and manage hiring.
MarketingOnly with your consent, and only ever to business contacts. Every marketing email carries a working unsubscribe link.

Where processing is based on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out, and may mean we can no longer provide the related service.

Who we share it with

We do not sell personal data, rent it, or share it with data brokers or advertisers. We share it only with the service providers (Data Processors) that run parts of our operation, and only to the extent they need it:

VercelWebsite and serverless hosting, edge delivery and request logs.
ZeptoMail (Zoho)Transactional email. Contact-form submissions are delivered to support@codexlab.in and a confirmation is sent back to you through this provider.
Cloud & collaboration toolsEmail, document storage, project tracking and code hosting used to run projects. [list your specific providers here]
Payment & accountingOur bank, payment processors and accountants, for invoicing, collection and statutory filings.
Professional advisersLawyers, auditors and insurers, where genuinely required.
AuthoritiesCourts, regulators and law-enforcement agencies where we are legally obliged to disclose, or to protect our rights, safety or property.
Business transferAn acquirer or successor, if we merge or sell the business — subject to this policy continuing to apply.

Every processor is bound by contract to process the data only on our instructions, keep it confidential and apply appropriate security safeguards.

Where your data is processed

We prefer India-region infrastructure, and our transactional email is sent through ZeptoMail’s India endpoint. Some of our providers operate globally, so personal data may be stored or processed outside India.

Where that happens, we transfer data only to countries not restricted by the Central Government under section 16 of the DPDP Act, and we require contractual safeguards obliging the provider to protect the data to a standard consistent with this policy.

How long we keep it

We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires — then we delete it or irreversibly anonymise it.

Contact enquiries24 months from the last exchange, unless the enquiry becomes a project
Client recordsFor the duration of the engagement, then up to 8 years for contracts, invoices and tax records as required under Indian accounting and tax law
Project data & credentialsDeleted or returned within 30 days of project closure, unless a support agreement requires otherwise
Server & edge logsTypically 30 days, longer only where an active security investigation requires it
Candidate records12 months after the hiring decision, unless you ask us to keep them longer for future roles
Marketing consent recordsUntil you unsubscribe, plus a suppression record so we do not contact you again

How we protect it

We apply reasonable security safeguards proportionate to the data we hold, including:

  • HTTPS/TLS on every page and API request; secrets held in environment variables and never shipped to the browser.
  • Least-privilege access, multi-factor authentication on business-critical accounts, and prompt revocation when someone leaves a project or the company.
  • Input validation and length limits on public endpoints, and escaping of user-supplied content before it is rendered, to prevent injection.
  • Dependency and vulnerability monitoring, with security patches applied on a defined cadence.
  • Encrypted storage with our infrastructure providers, and confidentiality obligations on everyone with access.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and the affected individuals as required by the DPDP Act and the rules made under it.

Your rights

As a Data Principal under the DPDP Act, you have the right to:

  • Access — obtain a summary of the personal data we process about you, what we do with it, and the other fiduciaries and processors it has been shared with.
  • Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated.
  • Erasure — have your data deleted where it is no longer needed for the purpose it was collected for and we are not required by law to keep it.
  • Withdraw consent — as easily as you gave it, where processing rests on consent.
  • Grievance redressal — raise a complaint with us first, and escalate to the Data Protection Board of India if you are not satisfied with our response.
  • Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.

You also have a duty under the Act not to file false or frivolous complaints and not to impersonate another person when exercising these rights.

How to exercise your rights

Email support@codexlab.in with the subject line "DPDP request" and tell us which right you want to exercise. We may ask for information to verify your identity — we will only ask for what is necessary, and we will not use it for anything else.

We acknowledge requests within 48 hours and respond substantively within 30 days. Exercising these rights is free; we may charge a reasonable fee or decline only where a request is manifestly unfounded or repetitive, and we will explain why.

If the data in question was given to us by one of our clients — that is, we hold it as a processor on their behalf — we will point you to that client, who is the Data Fiduciary for it, and support them in responding.

Data we handle on behalf of clients

When we build or operate a system for a client, we may process personal data belonging to that client’s users. In those cases the client is the Data Fiduciary and Codexlab is a Data Processor. We:

  • Process such data only on the client’s documented instructions, for the purposes of the engagement.
  • Do not use it for our own purposes, and never to train models or build products.
  • Bind our sub-processors to equivalent obligations and remain responsible for their performance.
  • Ask clients to use masked or synthetic data in development and test environments wherever production data is not strictly necessary.
  • Assist the client with data principal requests, security reviews and breach notification, and delete or return the data at the end of the engagement.

If you are an end user of a system we built for someone else, your request should go to that organisation. We are happy to be copied so we can help them action it.

Children’s data

This website and our services are intended for business users and are not directed at children. We do not knowingly collect personal data of anyone under 18 through this website. If we become aware that we have, we will delete it promptly — write to support@codexlab.in.

Where a client engagement requires processing children’s data, we will do so only under a written agreement that provides for verifiable parental consent and the additional protections the DPDP Act requires, including no behavioural advertising or tracking directed at children.

Automated decisions and AI

We do not make decisions with legal or similarly significant effects about you by purely automated means, and we do not profile website visitors.

Where we use AI tooling internally to assist with engineering work, we do not feed client Confidential Information or personal data into third-party AI services unless the client has approved it in writing and the provider is contractually barred from training on that input.

Third-party links

Our site links to external destinations — our own product sites such as zanoo.in, client sites and third-party tools. Once you follow such a link, that destination’s own privacy policy applies. We are not responsible for the content or privacy practices of sites we do not operate.

Changes to this policy

We update this policy when our practices, our providers or the law change. The version in force is always the one on this page, marked with the effective date at the top. For material changes we will give notice on the website and, where we hold your email address for an ongoing relationship, by email — at least 14 days before the change takes effect where practicable.

Grievance officer

If you are unhappy with how we have handled your personal data or a privacy request, contact our Grievance Officer, appointed under the Information Technology Act, 2000 and designated to answer questions about processing under the DPDP Act:

Grievance Officer[name of officer]
Emailsupport@codexlab.in
Phone+91 73048 05318
AddressCodexlab Enterprise Pvt Ltd, [building, street], Kandivali West, Mumbai [PIN], Maharashtra, India
Response timeAcknowledged within 48 hours; resolved within 30 days of receipt

If our response does not resolve the matter, you may escalate your complaint to the Data Protection Board of India under the DPDP Act.

This Privacy Policy forms part of our Terms & Conditions.
Codexlab Enterprise Pvt Ltd · Kandivali West, Mumbai, Maharashtra, India · support@codexlab.in

Codexlab
  • Services
  • Products
  • Work
  • Careers
  • Codexlab
  • Terms & Conditions
  • Privacy Policy
  • Refunds & Cancellation
  • Zanoo
  • Terms & Conditions
  • Privacy Policy
  • Refunds & Cancellation
© 2026 Codexlab Enterprise Pvt Ltd · Mumbai, India code. test. ship. repeat.