Privacy policy
What we collect through this website, why we collect it, who else sees it, and how to get a copy or have it deleted. Written to be read rather than survived.
We collect what a business enquiry needs: your name, a way to reply, and whatever you type. Advertising tags stay off until you accept them. We do not sell personal data and we do not pass your enquiry to other agencies. An enquiry that went nowhere is deleted after 24 months. Ask for a copy or a deletion and our Grievance Officer replies inside 30 days.
Who we are
Knit Infotech Pvt. Ltd. is a web design, web development and digital marketing company registered in India. Our head office is in Noida, Uttar Pradesh, and we also work out of Corpus Christi in Texas and Grey Lynn in Auckland. Our CIN and GSTIN are shown on our invoices.
This policy covers personal data we collect through knitinfotech.com. We work with clients in India, the United States, Australia, New Zealand and Kuwait, so it is written to hold up in all of those places. Indian law governs it.
We hold two different roles, and the difference decides who you complain to:
- For this website we are the data fiduciary. We decide what gets collected and why. That is the term the Digital Personal Data Protection Act, 2023 uses. Under the GDPR the same role is called the controller.
- For a client's own systems we are a processor. When we run a CRM, an ad account, an analytics property or a database we built, we act on that client's written instructions and nothing else. Their privacy notice covers their customers. This page does not.
What we collect and why
We collect what an enquiry or a project actually needs, and we stop there.
Things you type or send us
- Enquiry and quote forms: your name, work email, phone number, the services you ticked and the message you wrote.
- Job applications: your name, email, phone, the role, and the portfolio, GitHub or LinkedIn link you choose to share.
- Email, WhatsApp and phone calls: what you send us, and the address or number it came from.
- Newsletter sign-up, if you ask for it: your email address and nothing else.
Things your browser tells us
- IP address, browser and operating system, screen size, the page you arrived from, the pages you read and how long you stayed.
- Analytics identifiers, described in full in our Cookie Policy.
- Server logs: the URL requested, a timestamp, the response code and the user agent. We keep these to spot attacks and to fix errors.
Things we deliberately do not collect
- Card numbers. Invoices are settled by bank transfer or through a payment provider that handles the card on its own systems under RBI tokenisation rules. There is no checkout on this site, so no payment gateway script and no payment cookie ever loads here.
- Sensitive personal data as Rule 3 of the SPDI Rules, 2011 defines it: passwords, financial account details, health or medical records, biometrics and sexual orientation. We have no use for any of it.
- Caste, religion, date of birth, marital status or a photograph on a job application. Please do not send them.
- Data about anyone we know to be a child.
The lawful basis for each use
Every use below has a purpose and a lawful basis sitting behind it. This table is the whole list, not a sample.
We do not sell personal data. We do not share it for cross-context behavioural advertising. There is no quiet second purpose hiding behind a phrase like "to improve our services".
| What we do | Why | Lawful basis |
|---|---|---|
| Reply to your enquiry and write a proposal | You asked us to | DPDP: your consent. GDPR: steps before a contract, Art. 6(1)(b) |
| Deliver the work you signed for | To do the job | DPDP: performance of the contract. GDPR: Art. 6(1)(b) |
| Raise invoices and keep tax records | Indian company and tax law | DPDP: compliance with law. GDPR: legal obligation, Art. 6(1)(c) |
| Measure how the website performs | To fix what is broken | Notice and a standing opt-out. GDPR: Art. 6(1)(a) where consent applies |
| Show ads and count what they produced | To know if a campaign paid for itself | Your consent, given in the banner. Off until you say yes |
| Email existing clients about related work | To keep a live business relationship going | DPDP: a legitimate use. GDPR: legitimate interests, Art. 6(1)(f). Opt out in one click |
| Assess a job application | To hire people | Steps before a contract, plus our interest in filling the role |
| Block spam, abuse and fraud | To keep the site and your data safe | DPDP: a legitimate use. GDPR: legitimate interests, Art. 6(1)(f) |
Under the DPDP Act our basis is your consent or one of the "certain legitimate uses" in section 7. Under the CCPA and CPRA these are the only business purposes for which we handle your data. Until the DPDP consent provisions commence, the SPDI Rules, 2011 govern consent for sensitive personal data, and we do not collect any.
Cookies, analytics and advertising
This site loads Google Tag Manager, and Google Analytics 4 through it. We run Google Consent Mode v2, and we would rather describe what it does than sell you a slogan.
- Advertising storage starts denied.
ad_storage,ad_user_dataandad_personalizationare all set to denied before the container loads. Nothing for Google Ads runs until you press Accept. - Analytics storage starts granted. GA4 measures the visit on a notice basis, which is the pattern Google recommends for visitors in India, the United States, Australia and New Zealand. The banner lets you switch it off, and we remember that you did.
- Nothing is sold on. Google Signals is off, IP addresses are truncated and event data expires after 14 months.
If you would rather no analytics ran at all, press Manage consent in the footer and turn it off, or block cookies for this site in your browser. We would rather tell you the real sequence than claim a blanket opt-in we do not operate.
Every tag and every storage key is named in the Cookie Policy.
Who we share it with
The supplier list is deliberately short. Each one is bound by a written agreement, and none of them may use your data for their own purposes.
- Google for Analytics 4, Tag Manager, Google Ads and our email.
- Our hosting and email providers, so this site loads and your enquiry reaches an inbox.
- Our accountants, and lawyers if we ever needed them, under a duty of confidence.
- A buyer or successor, if the business is ever sold, on the same terms you have today.
We will disclose data where an Indian court, a tax authority or a law enforcement agency lawfully requires it. Rule 6 of the SPDI Rules, 2011 allows that without your consent, and we hold suppliers to the same line: a lawful written demand, not an informal ask.
We do not sell or rent your enquiry to other agencies, lead brokers or partner networks. If someone calls you claiming to be a Knit Infotech partner, they are not. Tell us and we will look into it.
Where your data goes
Our team and our servers are in India. If you write to us from the UK, the EEA, Australia, New Zealand or Kuwait, your data is transferred to India, and to the United States where Google's infrastructure sits.
India does not currently restrict outbound transfers to any country. Section 16 of the DPDP Act lets the government name restricted countries, and no list has been published, so this section is really about the rules that protect you at the other end.
- UK and EEA: we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, plus encryption in transit and at rest and access limited to named staff. Where a supplier is certified under the EU to US Data Privacy Framework, we rely on that as well.
- New Zealand: Information Privacy Principle 12 of the Privacy Act 2020 requires comparable safeguards before we send data offshore, and the contracts above provide them.
- Australia: Australian Privacy Principle 8 makes us accountable for what an overseas recipient does with your data. We accept that.
Ask us and we will tell you which mechanism covers your data.
How long we keep it
- Enquiries that did not become projects: 24 months, then deleted. Long enough to pick up the conversation, short enough not to become a liability.
- Client contracts and invoices: 8 financial years, because Indian company and tax law says so.
- Job applications: 12 months from the decision, so we can come back to you. Ask us to delete it sooner and we will.
- Newsletter subscribers: until you unsubscribe, plus 30 days to process it.
- Google Analytics 4 event data: 14 months, the shortest setting Google offers.
- Server and security logs: 90 days. Access logs for systems holding personal data are kept for one year, which is what Rule 6 of the DPDP Rules, 2025 will require.
When a period ends the record is deleted or anonymised beyond recovery. Backups age out on their own cycle, never more than 90 days after the live copy goes.
How we protect it
Enquiry data travels over TLS and sits on access-controlled systems. Only the people who need it can reach it, in practice the founder and the account lead on your project. Accounts carry two-factor authentication. Client data does not live on personal laptops or unmanaged phones. Every engagement runs under an NDA and an IP assignment as standard.
That set of controls is what Rule 8 of the SPDI Rules, 2011 calls reasonable security practices, and it lines up with the safeguards Rule 6 of the DPDP Rules, 2025 sets out: encryption, access control, logging, a written incident procedure and back-to-back terms with anyone who processes data for us.
No system is perfect and we will not pretend otherwise. What we can promise is that we do not collect data we have no use for, which is the only security control that never fails.
If there is a data breach
If personal data is lost or exposed and it could put you at risk, we will tell you without delay, in plain words: what happened, what data was involved, what it could mean for you and what we are doing about it.
We will also notify the regulator. Under the DPDP framework that means telling the Data Protection Board of India as soon as we know, with the fuller particulars inside 72 hours. Under the GDPR and UK GDPR it means the relevant supervisory authority within 72 hours. Australia's Notifiable Data Breaches scheme and New Zealand's Privacy Act 2020 both require notice for a breach likely to cause serious harm, and we will meet those too.
We will not wait for a lawyer to finish drafting before we warn the people affected.
Which Indian law applies right now
This is worth stating precisely, because a lot of policies get it wrong.
The Digital Personal Data Protection Act, 2023 is law, but it is being switched on in stages. The DPDP Rules, 2025 were notified on 13 November 2025. From that date the definitions and the Data Protection Board provisions came into force. Consent Manager registration follows from 13 November 2026. The operating duties, notice, consent, security safeguards, breach intimation, children's data, data principal rights and grievance redressal, are set to commence on 13 May 2027.
So as of the date at the top of this page, the binding Indian rules for a company like ours are still section 43A of the Information Technology Act, 2000 and the SPDI Rules, 2011. Section 72A of the same Act makes disclosure in breach of a lawful contract a criminal offence.
We are not waiting for 2027. This policy already reads as a DPDP notice, we already name a Grievance Officer, and we already run the safeguards the DPDP Rules describe. If any of it changes when the remaining provisions commence, we will update this page and tell you what moved.
Your rights in India
If you are a Data Principal in India, the DPDP Act gives you the right to:
- Get a summary of the personal data we process about you and who we have shared it with;
- Correct, complete, update or erase that data;
- Withdraw consent as easily as you gave it, with no effect on what we did lawfully before you withdrew it;
- Nominate someone to exercise these rights if you die or are unable to act;
- Raise a grievance with our Grievance Officer, named at the bottom of this page.
The SPDI Rules, 2011 already give you the right to review what we hold, to have anything inaccurate corrected, and to withdraw consent for sensitive personal data. Those rights apply today, not from 2027.
Start with our Grievance Officer. We answer inside 30 days. If our answer does not satisfy you, you may take the complaint to the Data Protection Board of India once it is receiving complaints.
The Act gives you duties too. The main two: do not file a false or frivolous grievance, and do not impersonate someone else when you make a request.
Your rights in the UK and the EEA
This is secondary to the Indian position above, but it stands on its own where it applies.
If the UK GDPR or the EU GDPR covers you, you can ask us for a copy of your data, for corrections, for deletion, for a pause on processing while a dispute runs, for a portable export, or to stop processing based on legitimate interests. Marketing stops the moment you ask, without argument. You can withdraw consent at any time.
We answer within one month and we do not charge. If our answer disappoints you, complain to the ICO in the UK or to your national authority in the EEA. You can also bring it to us first, and most people find that faster.
Your rights in California
If you live in California, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to get a copy, to correct it, to delete it and to limit the use of sensitive personal information.
There is nothing here to limit. We do not collect sensitive personal information through this site, we do not sell personal information, and we do not share it for cross-context behavioural advertising. That is why there is no "Do Not Sell or Share" link in our footer. Adding one would be theatre.
Email us with "CCPA request" in the subject line. We verify you by replying to the address we already hold, and we answer within 45 days. Asking costs you nothing and changes nothing about how we treat you.
Australia and New Zealand
Also secondary, and also real.
If you are in Australia, the Australian Privacy Principles under the Privacy Act 1988 apply to how we handle your data, including our accountability for overseas recipients under APP 8. If you are in New Zealand, the Privacy Act 2020 applies, including IPP 12 on offshore disclosure.
In both countries you can ask for access and correction. Write to our Grievance Officer, who handles these requests as well. If you are not satisfied you can go to the OAIC in Australia or the Office of the Privacy Commissioner in New Zealand.
Children
This is a business website. We do not knowingly collect data from children, we do not advertise to them, and we do not track, monitor or profile them, which the DPDP Act prohibits outright.
We do not run any service aimed at anyone under 18, and we do not ask for age. If you believe a child has sent us personal data, tell us and we will delete it.
Automated decisions and AI
We do not make decisions about you by automated means where the decision has a legal or similarly significant effect, and we do not profile you.
We do use AI tools in our own work: drafting, code review, research notes. Where a client engagement involves putting their data into an AI system, that is agreed in writing in the contract before it happens. We use business-tier tools whose terms exclude training on customer content. We never paste an enquiry or a job application into a public chatbot.
Governing law: India
This policy is governed by the laws of India. Any dispute about it goes to the courts at Gautam Buddha Nagar, Uttar Pradesh, and both sides agree to that.
That holds even where a foreign privacy law gives you rights under this policy. You keep those rights. The forum for arguing about them is India.
Changes to this policy
When we change this policy we move the date at the top, and for anything that affects you we say what changed. If a change needs your consent, we ask for it before it takes effect. Silence is not agreement.
Grievance Officer
Our Grievance Officer is Sam K, Founder. He handles every request under this policy: access, correction, deletion, consent withdrawal, and complaints about how we have handled your data.
Write to him and say what you want in the subject line. We acknowledge inside one working day and we resolve inside 30 days of receiving the grievance, which is the window Rule 5(9) of the SPDI Rules, 2011 sets and the standard the DPDP Rules carry forward. If the answer needs longer we tell you why before the 30 days are up, rather than after.
If our answer does not satisfy you, you can escalate to the Data Protection Board of India, or to your own regulator if you are outside India.
- Grievance Officer
- Email: [email protected]
- Phone: +91 98719 12805
- Postal address: Knit Infotech Pvt. Ltd., 932, 9th Floor, I-Thum Tower B, A-40, Sector 62, Noida, Uttar Pradesh 201309, IN

