1.Scope of this policy
This Privacy Policy applies to personal data we handle as a Data Fiduciary: information collected through consenpro.com, our marketing and event activity, sales enquiries, support interactions, and the administration of ConsenPro accounts.
It does not govern personal data that our customers upload to, or process through, the ConsenPro platform. For that data our customer is the Data Fiduciary and we act as a Data Processor on their instructions — see section 14.
2.Who we are
ConsenPro is a data privacy and consent management platform operated by Think360 Solutions Private Limited (“ConsenPro”, “we”, “us”). We are the Data Fiduciary for the personal data described in this policy and are responsible for determining how and why it is processed.
Questions about this policy, or about how we handle your data, can be raised through our contact form.
3.Personal data we collect
We collect only what we need, and we tell you why:
| Category | Examples | Why we collect it |
|---|---|---|
| Identity and contact details | Name, work email, phone number, organisation, designation | Responding to demo requests and business queries; account administration |
| Communication content | Messages you send us, support tickets, meeting notes | Answering your query and keeping a record of the exchange |
| Account and usage data | Login records, actions taken in the platform, audit logs | Providing and securing the service; troubleshooting |
| Technical data | IP address, browser and device type, pages visited | Site security, performance, and aggregate analytics |
| Consent records | Purposes accepted or declined, timestamp, notice version | Evidence of consent, as required under the DPDP Act |
We do not knowingly collect sensitive financial information, government identifiers, or health data through this website. Please do not include such information in free-text fields.
4.How we use your personal data
- To respond to demo requests, business queries and support messages you send us.
- To provide, administer and secure ConsenPro accounts, and to communicate about service changes.
- To send product updates, event invitations and marketing communications where you have consented to receive them.
- To understand how our website is used, so we can improve its content and performance.
- To meet legal, regulatory, audit and record-keeping obligations, including maintaining consent records.
We do not sell personal data, and we do not use the information you give us for automated decision-making that produces legal effects.
5.Consent and its withdrawal
Where we rely on consent, we ask for it through a notice that describes the personal data involved and the purpose it will be used for, before the data is recorded. Consent is given purpose by purpose, and declining an optional purpose does not prevent us from answering your enquiry.
You may withdraw consent at any time, with the same ease with which it was given, by contacting us through our contact form. Withdrawal applies going forward: it does not affect processing already carried out, and we may continue to retain records where the law requires it.
8.Storage and international transfers
Personal data collected through this website is stored on servers located in India. Where a service provider processes data outside India, we transfer it only to countries not restricted by the Central Government under the DPDP Act, and only under contractual safeguards requiring an equivalent standard of protection.
9.How long we keep data
We keep personal data only as long as the purpose it was collected for remains valid, and then erase it. Enquiry and marketing records are retained for up to 24 months from your last interaction with us unless you withdraw consent earlier. Account and transaction records are retained for the duration of the contract and for as long afterwards as tax, audit or other legal obligations require. Consent records are retained as evidence of compliance for as long as the law requires.
10.Security
We apply reasonable security safeguards to prevent personal data breaches, including encryption in transit, access controls on a need-to-know basis, logging and monitoring, and periodic review of our processors. If a personal data breach occurs, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act.
No system is perfectly secure. Please tell us immediately through our contact form if you believe your data has been compromised.
11.Your rights as a Data Principal
Under the DPDP Act, 2023 you have the right to:
- Access a summary of the personal data we hold about you and how it is being processed.
- Correct, complete, update or erase your personal data.
- Withdraw consent at any time.
- Nominate another individual to exercise your rights in the event of your death or incapacity.
- Grievance redressal — a readily available means of raising a complaint with us.
To exercise any of these, submit a request through our contact form, using the contact details associated with your data. We may ask for information to verify your identity, and will respond within the timelines prescribed under the Act.
The Act also places duties on Data Principals, including providing authentic information and not raising false or frivolous complaints.
12.Grievance redressal
We acknowledge grievances promptly and aim to resolve them within the period prescribed under the DPDP Act. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.
13.Children and persons with disability
Our website and platform are intended for business use and are not directed at children. We do not knowingly process the personal data of anyone under 18 without verifiable consent from a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. The same protections apply to persons with disability who have a lawful guardian.
If you believe a child's data has been shared with us, tell us through our contact form and we will erase it.
14.Data processed on behalf of customers
When an organisation uses ConsenPro to manage notices, consent records, data discovery or grievance workflows, that organisation decides what personal data enters the platform and why. It is the Data Fiduciary; we process the data as its Data Processor, under a written agreement, and only on its documented instructions.
If you want to exercise your rights over data held in a customer's ConsenPro workspace, please contact that organisation directly. If you approach us, we will refer your request to them.
15.Changes to this policy
We update this policy when our practices, our processors or the law change. The date at the top of this page shows when it was last revised. Where a change materially affects how we use personal data collected with your consent, we will notify you and, where required, seek fresh consent.
16.Contact us
Think360 Solutions Private Limited (ConsenPro)
Email: info@consenpro.com
For any privacy request, question or grievance, email us at the address above or use the contact form below and mark your message for the privacy team.
