Consider Done Consultants Limited
Privacy Policy
Effective Date: 1st June 2026 | Version: 1.0
Governed by the IT Act 2000, SPDI Rules 2011, and the Digital Personal Data Protection Act, 2023
Consider Done Consultants Limited is committed to handling all personal data with the highest standards of care, transparency, and accountability. This Policy reflects our obligations under Indian data protection law and our respect for every individual whose data we process.
1. Introduction and Purpose
Consider Done Consultants Limited (“we”, “us”, “our”, or “the Company”) is a company incorporated under the Companies Act, 2013, engaged in providing consultancy services. In the course of our operations, we necessarily collect, use, store, and process personal data of a variety of individuals including but not limited to our employees, prospective employees, clients, client personnel, vendors, contractors, and visitors to our premises or website.
We recognise that privacy is a fundamental right and that the trust placed in us by individuals who share their personal data is of paramount importance. This Privacy Policy (“Policy”) sets out, in a comprehensive and transparent manner, how we collect personal data, the purposes for which it is used, how it is stored and protected, with whom it may be shared, and the rights available to individuals in relation to their personal data.
This Policy has been drafted in compliance with the following legal framework:
- The Information Technology Act, 2000 (“IT Act”), as amended from time to time;
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) notified under Section 43A of the IT Act;
- The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and all rules, regulations, and guidelines issued or to be issued thereunder by the Central Government or the Data Protection Board of India;
- Any other applicable sector-specific laws, regulations, and guidelines issued by competent authorities in India.
Where any conflict exists between this Policy and the applicable law, the provisions of the applicable law shall prevail. This Policy is intended to supplement, and not replace, the requirements of the law.
This Policy applies with effect from 1st June 2026 and supersedes all prior privacy notices, policies, or statements issued by the Company. It will be reviewed and updated periodically to reflect changes in law, technology, or our business practices.
2. Scope and Applicability
2.1 Who This Policy Applies To
This Policy applies to all personal data processed by or on behalf of the Company, including personal data relating to:
- Current, past, and prospective employees, interns, apprentices, and trainees;
- Independent contractors, consultants, freelancers, and temporary workers engaged by the Company;
- Clients, client-side personnel, and counterparties to contracts;
- Vendors, suppliers, service providers, and their personnel;
- Shareholders, directors, and officers of the Company;
- Visitors to the Company’s offices or website;
- Any other individual who interacts with the Company and provides personal data.
2.2 Geographic Scope
This Policy applies to all processing of personal data carried out by Consider Done Consultants Limited, whether within India or involving the cross-border transfer of data from India to other countries. It governs all business units, offices, and locations of the Company.
2.3 What This Policy Does Not Cover
This Policy does not apply to:
- Anonymised or aggregated data that cannot reasonably be used to identify any individual;
- Personal data of individuals who are legal persons (e.g., company-level data, not individual employee data of a corporate client);
- Third-party websites, products, or services that may be linked to from our website — individuals should review the separate privacy policies of such third parties.
2.4 Internal Obligations
All employees, contractors, and agents of Consider Done Consultants Limited who access, handle, or process personal data on behalf of the Company are required to comply with this Policy and the Company’s associated internal data protection guidelines as a condition of their engagement. Failure to comply may result in disciplinary action, up to and including termination of employment or contract.
3. Key Definitions
For the purposes of this Policy, the following terms shall carry the meanings assigned below. Unless the context otherwise requires, these definitions are consistent with those used in the DPDP Act, 2023 and the SPDI Rules, 2011:
Consent: A free, specific, informed, unconditional, and unambiguous indication of the Data Principal’s agreement to the processing of their personal data for a specified purpose, expressed through a clear affirmative action.
Data Breach: Any unauthorised or accidental access, disclosure, acquisition, alteration, loss, or destruction of personal data that compromises its confidentiality, integrity, or availability.
Data Fiduciary: Consider Done Consultants Limited, which alone or jointly with others determines the purpose and means of processing personal data. As a Data Fiduciary, the Company bears primary accountability for compliance with data protection obligations.
Data Principal: The individual to whom personal data relates. In the context of a child, the term includes the parent or lawful guardian of such child.
Data Processor: Any person or entity that processes personal data on behalf of a Data Fiduciary pursuant to a written contract, and in accordance with the instructions of the Data Fiduciary.
Data Protection Board of India: The adjudicatory body to be constituted by the Central Government under Section 18 of the DPDP Act, 2023, responsible for determining non-compliance and imposing penalties.
DPDP Act: The Digital Personal Data Protection Act, 2023, enacted by the Parliament of India, which governs the processing of digital personal data in India.
Grievance Officer / Data Protection Officer: The designated officer of Consider Done Consultants Limited responsible for overseeing data protection compliance and addressing grievances relating to personal data processing.
IT Act: The Information Technology Act, 2000 (as amended), including all rules and regulations made thereunder.
Personal Data: Any data about an individual who is identifiable by or in relation to such data, whether directly or indirectly. This includes, but is not limited to, name, identification numbers, location data, online identifiers, or factors specific to physical, physiological, genetic, mental, economic, cultural, or social identity.
Processing: Any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
Sensitive Personal Data or Information (SPDI): Personal data that falls within specified sensitive categories under the SPDI Rules, 2011, including passwords; financial information (bank account, credit/debit card, other payment instrument details); physical, physiological, and mental health condition; sexual orientation; medical records and history; biometric information; caste or tribe; religious or political beliefs or affiliations.
Significant Data Fiduciary: A Data Fiduciary notified as such by the Central Government under the DPDP Act, having regard to the volume and sensitivity of personal data processed, risk to Data Principals, national security implications, and other relevant factors.
4. Categories of Personal Data We Collect
The personal data we collect varies depending on the nature of our relationship with the individual. We collect only such personal data as is necessary for the legitimate purposes described in this Policy. The following categories of personal data may be collected:
4.1 Identity and Contact Data
- Full legal name, date of birth, age, gender, and nationality;
- Residential and correspondence address, email address, and telephone/mobile number;
- Emergency contact details (name, relationship, and contact number);
- Signature (physical or digital).
4.2 Government-Issued Identification Data
- Permanent Account Number (PAN);
- Aadhaar number (only where legally mandated and with appropriate consent);
- Passport number, driving licence number, or Voter ID number;
- Company Identification Number (CIN), Director Identification Number (DIN), or GST Identification Number (GSTIN) where applicable.
4.3 Employment and Professional Data
- Educational qualifications, professional certifications, and academic transcripts;
- Curriculum vitae / resume, employment history, and professional references;
- Employee identification number, designation, department, and reporting structure;
- Performance appraisals, key result areas (KRAs), performance improvement plans;
- Training records, skill assessments, and learning & development data;
- Attendance, leave, and working hours records;
- Disciplinary records, grievance records, and investigation outcomes;
- Background verification reports (employment, education, criminal record checks conducted with consent).
4.4 Financial and Payroll Data
- Bank account name, account number, IFSC code, and branch details;
- Salary, compensation, benefits, bonuses, and deductions;
- Tax declarations, Form 12BB, investment proofs, and Form 16;
- Provident Fund (PF) and Employee State Insurance (ESI) registration numbers;
- Gratuity entitlement and actuarial data;
- Reimbursement claims and expense reports;
- Invoice, payment, and credit data (for clients and vendors).
4.5 Sensitive Personal Data or Information (SPDI)
- Physical, physiological, and mental health data (e.g., medical certificates, health insurance claims, disability status);
- Biometric data (e.g., fingerprint or facial recognition data used for attendance systems, where deployed);
- Financial passwords, PINs, and security credentials (encrypted);
- Caste, religious affiliation, or tribe (only where required under applicable reservation or welfare legislation);
- Sexual orientation (only where voluntarily disclosed in the context of workplace inclusion programmes).
SPDI will be collected only with explicit, freely-given, informed consent, and only where strictly necessary for a specified and lawful purpose. Collection of SPDI from third parties on behalf of an individual will be done only with the individual’s prior written consent.
4.6 Technical and Usage Data
- Internet Protocol (IP) address, browser type and version, operating system, and device identifiers;
- Website usage data including pages visited, time spent, referring URLs, and navigation paths;
- Cookies and similar tracking identifiers (refer to Section 15 for our Cookies Policy);
- Email metadata, communication logs, and call recordings (where applicable and disclosed);
- CCTV footage collected at Company premises for security purposes.
4.7 Third-Party and Public Source Data
- Data obtained from background verification agencies (with your consent);
- Publicly available professional information from platforms such as LinkedIn, MCA21, or government registries;
- References provided by former employers or professional contacts (with your consent);
- Court records, regulatory filings, or credit bureau data (where lawfully obtained for legitimate purposes).
5. How We Collect Personal Data
5.1 Data Collected Directly from You
We collect personal data directly from individuals through various channels, including:
- Employment application forms, onboarding documents, and HR portals;
- Client engagement letters, contracts, know-your-client (KYC) forms, and project briefs;
- Vendor registration forms and procurement documentation;
- In-person meetings, telephone conversations, and video conferences;
- Email correspondence and written communications;
- Physical forms submitted to our offices.
5.2 Data Collected Automatically
When you interact with our digital platforms, certain data may be collected automatically through:
- Cookies, web beacons, and similar tracking technologies embedded in our website;
- Server logs that record technical information such as IP address, browser type, and access times;
- Biometric attendance systems deployed at our offices (where applicable);
- CCTV and physical access control systems at our premises.
5.3 Data Collected from Third Parties
We may receive personal data from third parties in limited circumstances, including:
- Background verification and screening agencies engaged for pre-employment checks;
- Statutory authorities such as EPFO, ESIC, and income tax authorities;
- Credit bureaus and financial institutions (for vendor due diligence);
- Professional networking platforms and publicly available databases;
- Referees and former employers provided by a candidate or employee.
In all cases where data is obtained from third parties, we ensure that such collection is based on a lawful ground and that appropriate notices are given or consents obtained.
6. Purposes for Which Personal Data Is Processed
We process personal data only for specified, explicit, and legitimate purposes. Below is a comprehensive description of the purposes for which we use personal data:
| Purpose | Description |
| Recruitment and Selection | Evaluating job applications, conducting interviews, carrying out background verification checks, and making employment decisions. |
| Employee Onboarding | Processing joining documentation, setting up payroll, registering for PF/ESI/gratuity, and issuing employment credentials. |
| Payroll and Compensation | Calculating and disbursing salaries, processing reimbursements, managing deductions, and filing statutory returns. |
| Performance Management | Conducting appraisals, setting objectives, managing performance improvement plans, and administering promotions or increments. |
| Attendance and Leave Management | Recording and managing attendance, leave applications, and working hours in compliance with applicable labour laws. |
| Training and Development | Organising and tracking training programmes, certifications, and skill development activities. |
| Client Service Delivery | Managing client relationships, delivering consulting services, and maintaining project records. |
| Vendor and Supplier Management | Onboarding, evaluating, and managing relationships with vendors and service providers. |
| Legal and Regulatory Compliance | Meeting obligations under labour law, tax law, corporate law, and other applicable legislation. |
| Statutory Filings and Reporting | Filing returns with EPFO, ESIC, income tax department, MCA, and other statutory bodies. |
| Contract Management | Drafting, reviewing, and administering employment contracts, client agreements, and vendor contracts. |
| Fraud Prevention and Investigation | Detecting, preventing, and investigating fraudulent activities, misconduct, or policy violations. |
| IT Security and Access Control | Managing user access to Company systems, monitoring for security threats, and enforcing IT security policies. |
| Health and Safety | Managing medical emergencies, ensuring workplace safety, and complying with health and safety regulations. |
| Insurance and Benefits | Administering group health insurance, accident insurance, and other employee benefit schemes. |
| Business Continuity | Maintaining emergency contact records and business continuity planning. |
| Audit and Internal Controls | Conducting internal and external audits, financial controls, and risk assessments. |
| Grievance Redressal | Receiving, investigating, and resolving employee or stakeholder grievances, including PoSH complaints. |
| Communication and Marketing | Sending business communications, service updates, and information relevant to our professional relationship. |
| Website and Digital Services | Operating and improving our website, analysing usage patterns, and enhancing user experience. |
We will not use personal data for any purpose that is incompatible with the original purpose of collection without obtaining fresh consent or establishing another lawful ground for processing. Automated decision-making, including profiling, that produces legal or similarly significant effects on individuals will not be carried out without appropriate safeguards and disclosure.
7. Legal Basis for Processing Personal Data
Every instance of personal data processing by the Company is grounded in one or more of the following lawful bases. We identify the appropriate legal basis prior to commencing any processing activity and document the same in our internal records of processing activities.
7.1 Consent
We rely on consent where we are required by law to obtain it (particularly for SPDI and for purposes not strictly necessary for contractual or legal compliance), or where no other lawful basis is applicable. Consent will be:
- Freely given — not a condition of employment or service where unrelated to the processing;
- Specific — sought for a clearly identified purpose;
- Informed — accompanied by clear information about what data will be processed and why;
- Unambiguous — expressed through a clear affirmative action, not pre-ticked boxes or silence;
- Revocable — capable of being withdrawn at any time without adverse consequences unrelated to the processing purpose.
7.2 Contractual Necessity
Processing that is necessary for the performance of a contract to which the Data Principal is a party, or in order to take steps at the request of the Data Principal prior to entering into a contract (e.g., pre-employment screening, client onboarding, vendor engagement).
7.3 Legal and Statutory Obligation
Processing that is required to comply with a legal or statutory obligation to which the Company is subject, including obligations under the Income Tax Act, 1961; Employees’ Provident Funds and Miscellaneous Provisions Act, 1952; Employees’ State Insurance Act, 1948; Payment of Gratuity Act, 1972; the Companies Act, 2013; the Sexual Harassment of Women at Workplace (Prevention, Prohibition and Redressal) Act, 2013; and other applicable legislation.
7.4 Legitimate Interests
Processing that is necessary for the purposes of legitimate interests pursued by the Company or a third party, where such interests are not overridden by the interests or fundamental rights of the Data Principal. Legitimate interests relied upon by the Company include:
- Fraud prevention, security monitoring, and risk management;
- Network and information security;
- Improvement of business operations and services;
- Internal reporting, audit, and quality assurance;
- Business development and client relationship management.
In each case, we carry out a balancing test to ensure that the Data Principal’s interests do not override our legitimate interests.
7.5 Vital Interests
Processing that is necessary to protect the vital interests of a Data Principal or another natural person, such as in a medical emergency.
7.6 Public Interest
Processing that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company, to the extent applicable.
8. Consent: Collection, Management, and Withdrawal
8.1 How Consent is Obtained
Consent is sought through written consent forms, electronic consent mechanisms (e.g., checkboxes on digital platforms), or verbal confirmation documented in writing. We maintain records of all consents obtained, including the date, time, method, and scope of consent.
For SPDI, a separate and explicit written consent will be obtained from the Data Principal. This consent will specify the type of SPDI being collected, the purpose of collection, the names of persons or entities with whom it may be shared, and the right to withdraw consent.
8.2 Consent for Children
Where we process personal data of children (individuals below 18 years of age), whether in the context of employment of a minor in permitted circumstances, scholarship programmes, or other activities, we will obtain verifiable consent from the child’s parent or lawful guardian before processing. We will not undertake behavioural monitoring of children or serve targeted advertising to children.
8.3 Withdrawal of Consent
Any Data Principal who has provided consent may withdraw it at any time by submitting a written request to our Grievance Officer (see Section 17). The following shall apply upon withdrawal:
- We will cease processing personal data for the purpose covered by the withdrawn consent within a reasonable timeframe;
- Withdrawal of consent does not affect the lawfulness of any processing that was carried out on the basis of consent prior to its withdrawal;
- Where processing was also based on another lawful ground (e.g., legal obligation), we may continue to process personal data under that alternative ground;
- We will inform the Data Principal of the consequences of withdrawal, if any, before it takes effect.
8.4 Deemed Consent
Under the DPDP Act, 2023, certain processing is treated as having the deemed consent of the Data Principal, including processing for compliance with law, performance of a contract, medical emergencies, and employment-related purposes specifically enumerated in the legislation. Where we rely on deemed consent, we will maintain appropriate documentation of the applicable provision.
9. Disclosure and Sharing of Personal Data
We treat personal data as confidential and do not sell, rent, trade, or otherwise disclose it to third parties for commercial gain. Personal data may be disclosed in the following limited circumstances:
9.1 Data Processors
We engage third-party service providers who process personal data solely on our behalf and under our written instructions. These include:
- Payroll processing companies and HR management software providers;
- Cloud infrastructure and data storage providers;
- Background verification agencies;
- IT support, cybersecurity, and software maintenance providers;
- Legal, audit, and accounting firms engaged by the Company;
- Insurance companies and benefits administrators;
- Travel management and logistics service providers.
All Data Processors are engaged under written data processing agreements that impose obligations equivalent to those under this Policy and applicable law, including data security requirements, confidentiality obligations, restrictions on sub-processing, and obligations regarding data breach notification.
9.2 Statutory and Regulatory Authorities
We may disclose personal data to:
- Government departments and ministries (e.g., Ministry of Labour, Ministry of Finance);
- Regulatory bodies (e.g., SEBI, RBI, IRDAI, where applicable);
- Tax authorities (e.g., Income Tax Department, GST authorities);
- Labour authorities (e.g., EPFO, ESIC, Labour Commissioner);
- Law enforcement agencies, courts, tribunals, or arbitral bodies upon receipt of a lawful order or summons;
- Any statutory authority conducting an inspection, audit, or investigation.
Such disclosures are made only to the extent required by the applicable legal obligation and, where legally permissible, we will inform the affected Data Principal of any such disclosure.
9.3 Professional Advisors
We may share personal data with our solicitors, advocates, chartered accountants, auditors, and other professional advisors who are bound by duties of professional confidentiality and engaged in connection with the Company’s legal, financial, or compliance matters.
9.4 Group Companies and Business Partners
Where necessary for operational or business purposes, personal data may be shared within the Company’s group entities or with strategic business partners, subject to confidentiality obligations and data protection safeguards equivalent to those in this Policy.
9.5 Business Transfers
In the event of a merger, acquisition, demerger, restructuring, assignment of business, or sale of all or part of the Company’s assets, personal data held by the Company may be transferred to the acquirer or successor entity, subject to:
- The acquirer or successor being bound by data protection obligations equivalent to those under this Policy;
- Prior notice being given to affected Data Principals where legally permissible;
- The transfer being conducted in accordance with applicable law.
9.6 With Your Consent
In circumstances not covered above, personal data will be shared with third parties only with the prior, explicit consent of the Data Principal.
10. Cross-Border Transfer of Personal Data
The Company’s primary operations are based in India and personal data is generally stored and processed within India. However, in the course of providing services to international clients, using cloud-based platforms hosted abroad, or engaging with international vendors, personal data may occasionally need to be transferred to or accessed from countries outside India.
10.1 Legal Framework for International Transfers
Cross-border transfers of personal data will be carried out only in accordance with the DPDP Act, 2023 and any notifications or rules issued by the Central Government specifying permitted countries or territories for data transfer. Until such notifications are issued, transfers will be governed by the existing IT Act framework.
10.2 Safeguards for International Transfers
Prior to any cross-border transfer of personal data, the Company will ensure that:
- The recipient country has been notified by the Central Government as a permitted territory, or alternative safeguards are in place;
- Appropriate contractual safeguards (such as data transfer agreements or standard contractual clauses) are executed with the recipient;
- The recipient provides a level of data protection at least equivalent to that required under Indian law;
- Transfers of SPDI to a body corporate or person located outside India are permitted only if that entity ensures the same level of data protection as required under the SPDI Rules.
10.3 Employee and Client Awareness
Where personal data of an employee or client will be transferred internationally as part of a project engagement or service delivery arrangement, we will inform the relevant individual of such transfer in advance.
11. Data Retention and Disposal
11.1 Retention Principles
The Company retains personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law, whichever is the longer. We do not retain personal data beyond what is needed for the stated purpose, and we regularly review our data holdings to identify and delete data that is no longer required.
11.2 Retention Schedule
| Category of Personal Data | Retention Period |
| Employee personal records (including PF, ESI, tax) | 8 years from the date of cessation of employment, or as required under applicable labour and tax laws, whichever is longer |
| Payroll records and salary registers | 8 years, as required under the Minimum Wages Act, Payment of Wages Act, and Income Tax Act |
| Employment contracts and offer letters | Duration of employment + 8 years |
| Performance appraisal records | 5 years from date of appraisal |
| Disciplinary and investigation records | 7 years from closure of proceedings |
| Recruitment data — selected candidates | Duration of employment + 8 years |
| Recruitment data — unsuccessful candidates | 12 months from the date of application |
| Client contracts and engagement records | 10 years from contract termination or project closure |
| Financial and accounting records | 8 years as required under the Companies Act, 2013 and Income Tax Act, 1961 |
| Vendor contracts and procurement records | 8 years from contract termination |
| CCTV footage | 30 days, unless required for an ongoing investigation |
| Website usage data and cookies | 12 months, unless required for ongoing technical or legal purposes |
| Background verification reports | Duration of employment + 5 years |
| PoSH complaints and investigation records | Lifetime of the Company or as directed by a court/tribunal |
| Statutory filings (PF, ESI, TDS returns) | 8 years as required by applicable law |
11.3 Data Disposal
Upon expiry of the applicable retention period, personal data will be securely disposed of in accordance with the Company’s data disposal procedures, which include:
- Secure deletion of electronic records using data-erasure tools that overwrite data beyond recovery;
- Physical destruction (shredding) of paper-based documents containing personal data;
- Decommissioning of storage media in compliance with applicable security standards;
- Verification and documentation of disposal by the IT/HR department.
Data that has been anonymised beyond the possibility of re-identification is not subject to deletion requirements and may be retained for statistical, analytical, or historical research purposes.
12. Data Security
12.1 Security Obligations
Consider Done Consultants Limited is committed to implementing and maintaining reasonable security practices and procedures as mandated under Section 43A of the IT Act and the SPDI Rules, 2011. Our security framework is designed to protect personal data against unauthorised access, disclosure, alteration, accidental loss, or destruction.
12.2 Technical Security Measures
- Encryption of personal data — particularly SPDI — during transmission (using TLS/SSL protocols) and at rest (using AES-256 or equivalent encryption standards);
- Role-based access controls ensuring that employees can access only the personal data necessary for their role;
- Multi-factor authentication for access to systems containing personal data;
- Regular vulnerability assessments and penetration testing of IT systems;
- Firewalls, intrusion detection systems, and anti-malware tools;
- Secure backup and disaster recovery systems;
- Data loss prevention (DLP) tools to prevent unauthorised exfiltration of personal data.
12.3 Organisational Security Measures
- Mandatory data protection training for all employees handling personal data, conducted at onboarding and annually thereafter;
- Execution of non-disclosure and confidentiality agreements with all employees and contractors;
- A documented data protection policy accessible to all employees;
- Periodic internal audits of data protection practices;
- Designation of a Grievance Officer / Data Protection Officer responsible for compliance oversight;
- Background checks on personnel with access to sensitive personal data.
12.4 Physical Security Measures
- Restricted physical access to server rooms, filing areas, and premises storing personal data;
- CCTV surveillance of entry and exit points at Company offices;
- Secure storage of physical documents containing personal data (locked cabinets and secure archive rooms);
- Clear-desk and clear-screen policies for employees handling personal data.
12.5 Third-Party Security
All Data Processors and third parties with access to personal data are required to demonstrate adequate security practices as a pre-condition of engagement. Contracts with Data Processors include specific security requirements and audit rights for the Company.
12.6 Data Breach Management
In the event of a personal data breach, the Company will:
- Activate its incident response plan to contain, assess, and remediate the breach;
- Document the breach, including its nature, categories and approximate number of records affected, likely consequences, and remedial action taken;
- Notify affected Data Principals and the Data Protection Board of India in the manner and within the timeframe prescribed under the DPDP Act, 2023 and applicable rules, where the breach is likely to result in harm to Data Principals;
- Undertake a root-cause analysis and implement corrective measures to prevent recurrence.
13. Rights of Data Principals
Under the DPDP Act, 2023 and applicable law, Data Principals have the following rights in respect of their personal data processed by the Company. We are committed to facilitating the exercise of these rights in a timely, transparent, and non-discriminatory manner.
13.1 Right to Access Information
You have the right to obtain, upon request:
- Confirmation as to whether the Company processes your personal data;
- A summary of the personal data being processed and the processing activities undertaken with respect to such data;
- Identities of all Data Fiduciaries and Data Processors with whom your personal data has been shared, along with the purpose of sharing.
13.2 Right to Correction and Updation
You have the right to request that the Company:
- Correct inaccurate or misleading personal data;
- Complete personal data that is incomplete;
- Update personal data that has become outdated.
We will action correction requests within 30 days, or such shorter or longer period as may be prescribed. Where a correction is made, we will, where feasible, inform relevant Data Processors and third parties of the correction.
13.3 Right to Erasure
You have the right to request the erasure of your personal data where:
- The personal data is no longer necessary for the purpose for which it was collected or processed;
- You withdraw your consent and there is no other lawful basis for processing;
- The personal data has been unlawfully processed.
Please note that the right to erasure does not apply where processing is necessary for compliance with a legal obligation, the establishment or defence of legal claims, or other grounds specified under applicable law. We will inform you of any such applicable exception.
13.4 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw consent at any time. Withdrawal will not affect the lawfulness of processing carried out prior to withdrawal. Consequences of withdrawal, if any, will be communicated to you at the time of withdrawal.
13.5 Right to Grievance Redressal
You have the right to have any grievance relating to the processing of your personal data addressed by our Grievance Officer within a reasonable timeframe. If you are not satisfied with the response, you have the right to escalate the matter to the Data Protection Board of India once constituted.
13.6 Right to Nominate
You have the right to nominate another individual (a nominee) who may, in the event of your death or incapacity, exercise your rights under the DPDP Act on your behalf. Nomination may be submitted to the Grievance Officer in writing.
13.7 How to Exercise Your Rights
To exercise any of the above rights, please submit a signed written request to our Grievance Officer at the contact details set out in Section 17. Your request should include:
- Your full name, employee ID or client reference number (where applicable), and contact details;
- A clear description of the right you wish to exercise and the specific data to which it relates;
- Proof of identity (to verify your identity before actioning the request).
We will respond to your request within 30 days of receipt. Where the request is complex or we receive a large volume of requests, this period may be extended by a further 30 days with appropriate notice.
We will not charge a fee for actioning requests unless they are manifestly unfounded, repetitive, or excessive, in which case a reasonable administrative fee may be levied.
14. Employee and Candidate Data
14.1 Recruitment
Personal data collected during recruitment is used solely to assess a candidate’s suitability for the role applied for and to carry out pre-employment checks. Unsuccessful candidate data is retained for 12 months and then securely deleted, unless the candidate has consented to being considered for future opportunities.
14.2 During Employment
During the course of employment, we collect and use employee personal data for all employment-related purposes set out in this Policy. Employees are informed of our processing activities through this Policy, their employment contract, and the Company’s internal HR guidelines.
Employee monitoring (including IT systems monitoring, CCTV, email and internet usage monitoring) is carried out only to the extent necessary for legitimate security and compliance purposes, and employees are notified of such monitoring practices in advance.
14.3 Post-Employment
Upon cessation of employment, we retain employee personal data only for as long as required by law or legitimate business purposes (as specified in Section 11). Departing employees are provided with information about the retention and deletion of their data.
Reference requests from prospective employers will be responded to only with the former employee’s consent, or where limited to factual confirmation of dates of employment and role.
14.4 Health and Medical Data
Health and medical data of employees is processed strictly on a need-to-know basis. Such data is stored separately from general employment records and is accessible only to authorised HR and management personnel. It is used only for purposes of managing sick leave, health insurance claims, occupational health and safety, and statutory obligations.
15. Cookies and Online Tracking
15.1 What Are Cookies
Cookies are small text files that are placed on your device by websites you visit. They are widely used to make websites function more efficiently and to provide analytics information to website owners.
15.2 Types of Cookies We Use
| Cookie Type | Purpose |
| Strictly Necessary Cookies | Essential for the basic functioning of our website. These cannot be disabled as the website will not function without them. |
| Analytical / Performance Cookies | Collect anonymised information about how visitors use our website (e.g., pages most visited, error messages). Help us improve website performance. |
| Functionality Cookies | Remember choices you make (e.g., language, region) to provide a more personalised experience. |
| Security Cookies | Used to detect and prevent fraudulent access and ensure the integrity of our digital services. |
15.3 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to refuse cookies, delete cookies already placed on your device, or be notified when a website attempts to set or access a cookie. Please note that restricting certain cookies may impair the functionality of our website.
We do not use cookies to serve targeted advertising or to track your activity across third-party websites.
16. Third-Party Websites and Services
Our website or communications may contain hyperlinks to third-party websites, applications, or services that are not operated by or on behalf of the Company. This Policy applies only to personal data processed by the Company and does not extend to third-party platforms.
We encourage you to carefully review the privacy policies and terms of use of any third-party website you visit before providing any personal data. The Company is not responsible for the content, privacy practices, or data security of third-party websites.
Where we embed third-party tools or plugins on our website (e.g., social media buttons, analytics tools), those third parties may independently collect personal data in accordance with their own privacy policies, which we encourage you to review.
17. Grievance Officer and Data Protection Officer
17.1 Designation
In accordance with Section 5(9) of the IT Act, Rule 5(9) of the SPDI Rules, and the provisions of the DPDP Act, 2023, Consider Done Consultants Limited has designated a Grievance Officer to address grievances relating to the processing of personal data. The Grievance Officer is also responsible for overseeing the Company’s data protection compliance programme.
17.2 Contact Details
| Name: [To be designated by the Board] Designation: Grievance Officer / Data Protection Officer Organisation: Consider Done Consultants Limited Email Address: [grievance@considerdone.com — to be confirmed] Postal Address: [Registered Office Address — to be inserted] Contact Number: [To be updated] Response Time: Within 30 days of receipt of complaint or request |
17.3 Grievance Redressal Process
Any Data Principal who has a grievance relating to the processing of their personal data may submit a written complaint to the Grievance Officer. The grievance should include:
- The name and contact details of the complainant;
- A clear description of the nature of the grievance and the specific data or processing activity concerned;
- Copies of any relevant documents or correspondence;
- The remedy or action sought.
Upon receipt of a grievance, the Grievance Officer will:
- Acknowledge receipt of the grievance within 5 working days;
- Investigate the grievance in a fair, impartial, and timely manner;
- Provide a written response with findings and any remedial action taken or proposed, within 30 days of receipt;
- Where the grievance cannot be resolved within 30 days, inform the complainant of the extended timeline and reasons therefor.
17.4 Escalation
If a Data Principal is not satisfied with the resolution provided by the Grievance Officer, they may:
- Escalate the matter to the senior management of the Company;
- Lodge a complaint with the Data Protection Board of India once constituted under the DPDP Act, 2023;
- Seek redress before the appropriate court or tribunal.
18. Protection of Children’s Personal Data
The Company’s services are not directed at children below 18 years of age and we do not knowingly collect personal data from children without verifiable parental or guardian consent.
18.1 When Children’s Data May Be Collected
In limited circumstances, we may process personal data relating to children, including:
- Nomination of minor dependants of employees under insurance or gratuity schemes;
- Emergency contact records where a minor is listed as a dependent;
- Educational or scholarship programmes, if any, administered by the Company.
In all such cases, we obtain explicit consent from the child’s parent or lawful guardian before collecting or processing such data.
18.2 Obligations in Respect of Children’s Data
- We will not undertake targeted advertising directed at children;
- We will not monitor children’s online behaviour;
- We will implement appropriate technical and organisational measures to verify the age of users of our digital platforms where children’s data may be involved;
- Upon becoming aware that personal data of a child has been collected without appropriate parental consent, we will take immediate steps to delete such data.
19. Automated Decision-Making and Profiling
Automated decision-making refers to the use of algorithms, artificial intelligence, or automated processing to make decisions about individuals without meaningful human involvement. Profiling refers to automated processing of personal data to evaluate certain personal aspects of an individual.
The Company does not currently use automated decision-making that produces legal or similarly significant effects on individuals (such as automated hiring decisions or automated credit assessments). Where any such automated processing is introduced in the future, the Company will:
- Provide clear and transparent information to Data Principals about the existence of such processing;
- Implement appropriate safeguards, including the right to obtain human review of automated decisions;
- Ensure that automated decisions are not based solely on SPDI without explicit consent;
- Allow Data Principals to contest automated decisions and request human review.
20. Data Protection Training and Awareness
Consider Done Consultants Limited recognises that data protection compliance is a shared responsibility. All personnel who access or handle personal data are required to complete data protection training as follows:
- Induction training for all new employees covering this Policy, data handling obligations, and breach reporting procedures;
- Annual refresher training covering updates to applicable law, policy changes, and emerging data protection risks;
- Role-specific training for HR, Finance, IT, and senior management personnel who handle significant volumes of personal or sensitive data;
- Targeted training following any data breach or significant compliance issue.
Training records are maintained and available for review by auditors. Completion of mandatory data protection training is a condition of continued employment. Non-compliance may result in disciplinary action.
21. Records of Processing Activities
In accordance with data protection best practices and in anticipation of regulatory requirements under the DPDP Act, 2023, Consider Done Consultants Limited maintains a Register of Processing Activities (“ROPA”) documenting all data processing operations carried out by the Company. The ROPA records, for each processing activity:
- The name and contact details of the Data Fiduciary and Grievance Officer;
- The purposes of processing;
- Categories of Data Principals and personal data processed;
- Categories of recipients to whom personal data has been or will be disclosed;
- Cross-border transfers of personal data, including the destination countries and applicable safeguards;
- Retention schedules;
- Description of technical and organisational security measures.
The ROPA is reviewed and updated at least annually and whenever a significant change to processing activities occurs.
22. Changes to This Privacy Policy
The Company reserves the right to amend this Policy at any time to reflect changes in:
- Applicable laws and regulations (including amendments to the DPDP Act, 2023, IT Act, and associated rules);
- The Company’s business operations, services, or data processing activities;
- Technology or industry best practices.
The updated Policy will be published on the Company’s internal employee portal and website, with the revised effective date clearly indicated. For material changes that significantly affect the rights of Data Principals, the Company will provide prior notice through appropriate communication channels (such as email or intranet announcements) at least 15 days before the changes take effect.
We encourage all Data Principals and employees to review this Policy periodically. Continued engagement with the Company or use of its services after the effective date of any amendment constitutes acceptance of the revised Policy, to the extent permitted by law.
23. Governing Law and Jurisdiction
This Policy is governed by and construed in accordance with the laws of the Republic of India. Any dispute, controversy, or claim arising out of or in connection with this Policy, or the breach, termination, or validity thereof, shall be subject to the exclusive jurisdiction of the competent courts in India.
Individuals in India may also seek remedies through the Data Protection Board of India (once constituted) for breaches of the DPDP Act, 2023, and through the Adjudicating Officer appointed under the IT Act for breaches under that legislation.
24. Contact Information
For any questions, requests, or concerns relating to this Policy or the processing of your personal data, please contact us at:
| Company Name: Consider Done Consultants Limited Registered Office: H No. 754, Sec-42, Golf Course Road, Galleria DLF-IV, Gurugram – 122 009, Haryana CIN: [CIN — U74909HR2026PLC143666] Email (Privacy): Email (Grievance): Website: www.considerdone.in Phone: 9892545039 |
This Privacy Policy was approved by the Board of Directors of Consider Done Consultants Limited and is effective from 1st June 2026.
Document Reference: CDCL-PRIV-POL-001 | Version 1.0 | Review Due: 1st June 2027
This document is confidential and proprietary to Consider Done Consultants Limited. Unauthorised reproduction or distribution is prohibited.
