Version 1.0Effective 25 January 2026

Privacy Policy

This Privacy Policy explains how KSM Cognitive Works Private Limited, operating as Noisiv Consulting (“Company,” “we,” “us,” “our”), collects, uses, discloses, and protects personal data in connection with noisivconsulting.com and in the course of providing our software development, digital marketing, and design services.

Legal framework. This Policy is framed primarily under India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Where you are located in, or we process personal data connected to, the EU (including Germany), the UK, the United States, or Japan, the additional protections in Section 8 apply.
01

Scope

This Policy applies to personal data we collect through the Site (e.g., contact forms, newsletter sign-ups, career applications) and, where relevant, personal data processed in the course of a client engagement, to the extent not separately governed by a Data Processing Agreement executed as part of that engagement.
02

Personal Data We Collect

CategoryExamplesSource
Contact and identity dataName, email address, phone number, job title, company nameProvided directly by you (contact forms, RFPs, meetings)
CommunicationsContent of emails, messages, or call notes exchanged with usProvided directly by you
Usage and device dataIP address, browser type, pages visited, referring URL, approximate locationCollected automatically via cookies and analytics tools (see our Cookie Policy)
Career applicant dataCV/resume, work history, portfolio linksProvided directly by you, if you apply for a role
Client project dataAny personal data your organisation shares with us in the course of an engagement (e.g., your customer/lead data for a marketing campaign)Provided by you or your organisation, governed additionally by the applicable Service Agreement/DPA

The Site currently uses Google Analytics to collect usage and device data. We may also deploy advertising pixels (such as Meta Pixel or LinkedIn Insight Tag) from time to time; where we do so, our Cookie Policy will be updated to reflect the specific tools in use and the controls available to you. We do not currently use any CRM, email marketing, or marketing automation platform in connection with the Site.

03

How and Why We Use Personal Data

We process personal data for the following purposes:

  • To respond to enquiries and provide requested information about our services
  • To deliver, manage, and communicate about a client engagement
  • To send newsletters or marketing communications, where you have opted in (or, for existing business contacts, where permitted under applicable law, with an opt-out in every communication)
  • To operate, secure, and improve the Site
  • To evaluate job applications
  • To comply with our legal and regulatory obligations

Under the DPDP Act, our basis for processing is primarily your consent (for marketing communications and non-essential cookies) or legitimate/certain specified uses, such as responding to a request you have voluntarily made.

04

Sharing and Disclosure of Personal Data

We do not sell personal data. We may share personal data with:

  • Service providers/sub-processors who support our website, communications, or service delivery (e.g., hosting, analytics, email, CRM, and productivity tools) — bound by contractual confidentiality and data protection obligations
  • Professional advisors (legal, accounting) where necessary
  • Regulators, courts, or government authorities, where required by law
  • A successor entity, in the event of a merger, acquisition, or sale of business assets, subject to equivalent protections

Current website-level sub-processors:

Sub-processorPurposeData Location
Google LLC (Google Analytics)Website analytics and usage reportingUSA (Google Cloud infrastructure)
Advertising pixel providers (e.g., Meta Platforms, LinkedIn)Conversion tracking and retargeting, when deployedUSA / EU infrastructure of respective provider

This list reflects tools active on the Site as of the effective date of this Policy. We will update this section, or publish a standalone sub-processor notice, when additional tools are onboarded.

05

Cookies

The Site uses cookies and similar tracking technologies. Full details — including categories of cookies used, their purposes, and how to manage your preferences — are set out in our separate Cookie Policy, incorporated into this Policy by reference.
06

Data Retention

We retain personal data only as long as necessary for the purposes described in Section 3, or as required by applicable law. Specifically:

Contact form / enquiry data (not converted to a client relationship)
24 months from the date of last contact
Client engagement data
Duration of the engagement plus any period required under the applicable Service Agreement, statutory record-keeping obligations (e.g., Companies Act 2013, applicable tax law), or as needed to defend legal claims
Career applicant data
12 months from the date of application, after which it is securely deleted or anonymised unless you have consented to longer retention for future opportunities
07

Data Security

We implement appropriate technical and organisational measures — including access controls, encryption in transit, and restricted internal access — to protect personal data against unauthorised access, loss, or misuse, consistent with the “reasonable security safeguards” standard under the DPDP Act and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
08

International Users: Additional Jurisdiction-Specific Commitments

Because Noisiv Consulting serves clients based in the European Union (including Germany), the United Kingdom, the United States, and Japan, we structure our data handling to align with the following frameworks where they apply to you:

  • GDPR (EU) and UK GDPR — including recognition of data subject rights such as access, rectification, erasure, restriction, portability, and objection
  • Applicable US state privacy laws (e.g., CCPA/CPRA and comparable state statutes) — including rights to know, delete, correct, and opt out of sale/sharing of personal information
  • Japan's Act on the Protection of Personal Information (APPI) — including rights to disclosure, correction, and suspension of use

Rather than reproduce each framework's full text here, we confirm our commitment to compliance with each, and will provide the specific supporting documentation relevant to your jurisdiction — such as a Data Processing Agreement, EU Standard Contractual Clauses, a UK International Data Transfer Addendum, or a jurisdiction-specific rider — as part of your Service Agreement, upon request.

09

Cross-Border Data Transfers

Noisiv Consulting is based in India, and personal data we collect or process may be transferred to, stored in, or accessed from locations outside your home country, including India and countries where our service providers operate their infrastructure.

Transfers from India
Under Section 16 of the DPDP Act, 2023, the Company may transfer personal data outside India except to countries or territories specifically restricted by notification of the Central Government. As of the effective date of this Policy, no such restriction affects our processing activities.
Transfers of EU/UK personal data to India
Where we process personal data originating in the EU or UK, and India does not benefit from an applicable adequacy decision, we rely on appropriate safeguards — including the EU Standard Contractual Clauses (and, where applicable, the UK International Data Transfer Addendum) executed with the relevant client or data exporter — supplemented by contractual, technical, and organisational measures.
Transfers involving our sub-processors
Where our service providers process personal data in a country other than India, we take reasonable steps to ensure a comparable level of protection through contractual commitments with those providers.
Your engagement-specific transfer terms
Where your Service Agreement includes its own data transfer or localisation terms, those terms govern in addition to this clause.
10

Your Rights

Subject to applicable law, you may have the right to:

  • Obtain confirmation of, and access to, personal data we hold about you
  • Request correction or completion of inaccurate or incomplete personal data
  • Request erasure of personal data that is no longer necessary for the purpose it was collected
  • Withdraw consent at any time, where processing is based on consent (without affecting the lawfulness of processing before withdrawal)
  • Nominate another individual to exercise your rights in the event of death or incapacity (a right specific to the DPDP Act)
  • Register a grievance regarding the handling of your personal data
  • Where applicable under GDPR/UK GDPR/CCPA/APPI, exercise the additional rights described in Section 8

To exercise any of these rights, contact us using the details in Section 13.

11

Children's Privacy

The Site and our services are not directed at, and we do not knowingly collect personal data from, individuals under the age of 18. If you believe a minor has provided us personal data, please contact us so we can take appropriate action.
12

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be indicated by an updated “Effective” date at the top of this page.
13

Grievance Officer and Contact

In accordance with the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, our Grievance Officer is:

Name
Subhadeep Datta
Designation
Chief Technology Officer
Response timeline
Acknowledgement within 24 hours; resolution within 15 days as required under applicable law.

General enquiries:

KSM Cognitive Works Private Limited

Operating as Noisiv Consulting

CIN
U72502DL2021PTC376732
Registered Office
403-B, Building 656, Lane 4, West End Marg, Saket (South Delhi Region), New Delhi 110030

Please also see our Terms of Use and Cookie Policy.

Noisiv Consulting is a registered brand of KSM Cognitive Works Private Limited, incorporated in India.

This Privacy Policy was last updated on 25 January 2026 (Version 1.0).