The short version
We are a business-to-business software company. We do not sell personal data, we do not run advertising networks, and we do not build profiles of you for marketing. The website collects only what you type into the contact form, plus the minimum technical logs needed to keep it online and secure.
This policy explains the detail. It applies to codexlab.in and to the personal data we handle as a business — enquiries, clients, candidates and vendors. It does not cover our products; for Zanoo, see the Zanoo Privacy Policy.
Who is responsible for your data
For the data described in this policy, Codexlab Enterprise Pvt Ltd is the Data Fiduciary (the equivalent of a "data controller") under the Digital Personal Data Protection Act, 2023 ("DPDP Act").
Personal data we collect
a. When you use the contact form
The enquiry form on our homepage collects exactly three fields, all of which you type yourself:
b. When you browse the site
- Server and edge logs kept by our hosting provider: IP address, timestamp, requested URL, referrer, user-agent, response status and approximate region. These are generated automatically by the infrastructure and are used to keep the site online, diagnose faults and detect abuse.
- Local browser state used to render the site (for example, remembering that a mobile menu is open). This stays in your browser.
Cookies. codexlab.in does not set advertising, marketing or cross-site tracking cookies, and does not currently run a third-party analytics tag. If we add analytics in future, we will update this policy and, where the law requires it, ask for your consent before any non-essential cookie or tracker is set.
c. When you become a client
- Business contact details of your team — names, roles, work emails, phone numbers.
- Contractual and billing information — company name, registered address, GSTIN, PAN, purchase orders, invoices and payment records.
- Project communications — email, messaging, call notes, tickets, meeting recordings where you have agreed to them.
- Credentials and access you grant us for the duration of a project. We ask for least-privilege access and hand it back or ask you to revoke it at the end.
d. When you apply for a role or supply us
- Candidates: CV, contact details, work history, portfolio links, interview notes and, if we make an offer, the documents required for onboarding.
- Vendors and contractors: contact and bank details, tax registrations and invoices, as required to pay you and meet our statutory obligations.
We do not knowingly collect biometric data, health data, or financial account credentials through this website.
Why we use it, and on what basis
Under the DPDP Act we process personal data either with your consent, or for a legitimate use permitted by the Act (such as a purpose for which you voluntarily provided the data, or compliance with law).
Where processing is based on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out, and may mean we can no longer provide the related service.
Where your data is processed
We prefer India-region infrastructure, and our transactional email is sent through ZeptoMail’s India endpoint. Some of our providers operate globally, so personal data may be stored or processed outside India.
Where that happens, we transfer data only to countries not restricted by the Central Government under section 16 of the DPDP Act, and we require contractual safeguards obliging the provider to protect the data to a standard consistent with this policy.
How long we keep it
We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires — then we delete it or irreversibly anonymise it.
How we protect it
We apply reasonable security safeguards proportionate to the data we hold, including:
- HTTPS/TLS on every page and API request; secrets held in environment variables and never shipped to the browser.
- Least-privilege access, multi-factor authentication on business-critical accounts, and prompt revocation when someone leaves a project or the company.
- Input validation and length limits on public endpoints, and escaping of user-supplied content before it is rendered, to prevent injection.
- Dependency and vulnerability monitoring, with security patches applied on a defined cadence.
- Encrypted storage with our infrastructure providers, and confidentiality obligations on everyone with access.
No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and the affected individuals as required by the DPDP Act and the rules made under it.
Your rights
As a Data Principal under the DPDP Act, you have the right to:
- Access — obtain a summary of the personal data we process about you, what we do with it, and the other fiduciaries and processors it has been shared with.
- Correction and completion — have inaccurate or misleading data corrected, incomplete data completed, and outdated data updated.
- Erasure — have your data deleted where it is no longer needed for the purpose it was collected for and we are not required by law to keep it.
- Withdraw consent — as easily as you gave it, where processing rests on consent.
- Grievance redressal — raise a complaint with us first, and escalate to the Data Protection Board of India if you are not satisfied with our response.
- Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
You also have a duty under the Act not to file false or frivolous complaints and not to impersonate another person when exercising these rights.
How to exercise your rights
Email support@codexlab.in with the subject line "DPDP request" and tell us which right you want to exercise. We may ask for information to verify your identity — we will only ask for what is necessary, and we will not use it for anything else.
We acknowledge requests within 48 hours and respond substantively within 30 days. Exercising these rights is free; we may charge a reasonable fee or decline only where a request is manifestly unfounded or repetitive, and we will explain why.
If the data in question was given to us by one of our clients — that is, we hold it as a processor on their behalf — we will point you to that client, who is the Data Fiduciary for it, and support them in responding.
Data we handle on behalf of clients
When we build or operate a system for a client, we may process personal data belonging to that client’s users. In those cases the client is the Data Fiduciary and Codexlab is a Data Processor. We:
- Process such data only on the client’s documented instructions, for the purposes of the engagement.
- Do not use it for our own purposes, and never to train models or build products.
- Bind our sub-processors to equivalent obligations and remain responsible for their performance.
- Ask clients to use masked or synthetic data in development and test environments wherever production data is not strictly necessary.
- Assist the client with data principal requests, security reviews and breach notification, and delete or return the data at the end of the engagement.
If you are an end user of a system we built for someone else, your request should go to that organisation. We are happy to be copied so we can help them action it.
Children’s data
This website and our services are intended for business users and are not directed at children. We do not knowingly collect personal data of anyone under 18 through this website. If we become aware that we have, we will delete it promptly — write to support@codexlab.in.
Where a client engagement requires processing children’s data, we will do so only under a written agreement that provides for verifiable parental consent and the additional protections the DPDP Act requires, including no behavioural advertising or tracking directed at children.
Automated decisions and AI
We do not make decisions with legal or similarly significant effects about you by purely automated means, and we do not profile website visitors.
Where we use AI tooling internally to assist with engineering work, we do not feed client Confidential Information or personal data into third-party AI services unless the client has approved it in writing and the provider is contractually barred from training on that input.
Third-party links
Our site links to external destinations — our own product sites such as zanoo.in, client sites and third-party tools. Once you follow such a link, that destination’s own privacy policy applies. We are not responsible for the content or privacy practices of sites we do not operate.
Changes to this policy
We update this policy when our practices, our providers or the law change. The version in force is always the one on this page, marked with the effective date at the top. For material changes we will give notice on the website and, where we hold your email address for an ongoing relationship, by email — at least 14 days before the change takes effect where practicable.
Grievance officer
If you are unhappy with how we have handled your personal data or a privacy request, contact our Grievance Officer, appointed under the Information Technology Act, 2000 and designated to answer questions about processing under the DPDP Act:
If our response does not resolve the matter, you may escalate your complaint to the Data Protection Board of India under the DPDP Act.
This Privacy Policy forms part of our Terms & Conditions.
Codexlab Enterprise Pvt Ltd · Kandivali West, Mumbai, Maharashtra, India · support@codexlab.in