××××
Legal Dossier

Privacy Policy

How Codence Studio collects, processes, stores, and protects personal data under global legal frameworks.

××××

Last updated: March 24, 2026

At Codence Studio ("we," "us," or "our"), we respect your privacy and are committed to protecting your personal data in accordance with applicable legal frameworks. This Privacy Policy outlines how we collect, process, store, disclose, and secure personal data when you interact with our website located at https://codencestudio.com (the "Site") or utilize our software development, design, and consulting services.

This Privacy Policy is formulated in strict compliance with the Digital Personal Data Protection Act (DPDPA), 2023 (India), the Information Technology Act, 2000 (India) including the Information Technology Rules, 2011, and, where globally applicable, the General Data Protection Regulation (GDPR) (EU) and the California Consumer Privacy Act (CCPA).

01 // Scope & Legal Capacity

Fiduciary vs. Processor Roles

It is vital to distinguish our legal roles depending on our relationship with you:

  • As a Data Fiduciary: We act as a Data Fiduciary regarding the personal information of visitors to our Site, prospective business clients, and partners. We determine the purposes and means of processing this data.
  • As a Data Processor: When providing custom software development, backend integrations, or maintenance services to our Clients, we process end-user personal data solely on behalf of, and under the strict directions of, the Client (who acts as the Data Fiduciary).

02 // Information Collection

Categories of Collected Data

We collect personal information that you voluntarily provide to us when you fill out contact forms, book a consultation call, subscribe to our newsletter, or communicate with us. This information includes:

  • Identity Data: First name, last name, and professional titles.
  • Contact Data: Email address, phone number, and company details.
  • Transaction Data: Details about services you have purchased from us.
  • Usage & Technical Data: IP address, browser type, referral sources, campaign parameters, pages visited, and interaction signals collected via first-party analytics cookies.

03 // Legal Framework

Bases for Processing Data

  • Consent: Where you have given explicit consent (e.g. newsletter opt-in or analytics cookies).
  • Contractual Necessity: Where processing is necessary to perform a contract with you or take pre-contractual scoping steps.
  • Legal Obligation: Where required to comply with statutory laws or regulatory requirements.
  • Legitimate Interests: To improve our Site experience, maintain network security, prevent fraud, and run analytics systems.

04 // Tracking Technologies

Cookies & Local Storage

Our Site utilizes a limited number of first-party cookies and local storage tokens. Necessary storage is used to store your cookie preferences and maintain state. Opt-in analytics cookies help us measure Site usage, referral sources, and traffic campaigns. We do not engage in cross-site behavioral advertising.

05 // Third Parties

Data Sharing & Transfers

We do not sell, rent, or trade your personal data. We may share information with trusted third-party service providers (such as cloud hosting, email delivery, and consented analytics systems) that process data under strict confidentiality agreements. Where personal data is transferred outside the European Economic Area (EEA) or India, we implement Standard Contractual Clauses (SCCs).

06 // Retention & Security

Security Protocols

We employ robust administrative, technical, and physical security measures to safeguard your personal data. Personal data is retained only as long as necessary for the purpose it was collected, to deliver our services, resolve disputes, maintain compliance audits, and satisfy legal record-keeping requirements.

07 // Statutory Rights

Rights of the Data Principal (GDPR & DPDPA)

Depending on your location, you possess statutory rights including Access, Rectification, Erasure ("Right to be Forgotten"), Restriction/Objection, Data Portability, and CCPA Opt-Out. To exercise any of these rights, contact legal@codencestudio.com.

08 // Governance & Contact

Grievance Redressal Mechanism & Officer

In accordance with the IT Rules 2011 and the DPDP Act 2023, Codence Studio has designated a Grievance Officer. Complaints are acknowledged within 48 hours and resolved within thirty (30) days.

××××

Grievance Officer

Codence Studio Administration

Maharashtra, India

Email: legal@codencestudio.com

09 // Updates

Policy Amendments

We reserve the right to modify this Privacy Policy to align with technical modifications, service changes, or amendments in statutory laws. Updates will be published on this page.