Privacy Notice

Last updated: 2026-09-29

This notice explains how personal data is handled when you use solutions4it.in, contact us, book a consultation or become a client. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, US state privacy laws (including the California Consumer Privacy Act as amended by the CPRA), the Australian Privacy Act 1988 and Australian Privacy Principles, the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

1. Who is responsible for your data

The data controller ("Data Fiduciary" under the DPDP Act) is Koustov Choudhury (Koustov Choudhury (sole proprietor)), 309/181 N.S Road, Sheoraphuli, Hooghly 712223, West Bengal, India. Contact: koustov.choudhury@solutions4it.in, +91 7602662320.

Grievance Officer (DPDP Act) / privacy contact: Koustov Choudhury — koustov.choudhury@solutions4it.in.

2. What we collect

  • Enquiry and booking details you provide: name, business email, company, website, country, role, company size, the service you are interested in, your description of the problem, timeline, optional budget range, preferred meeting time and time zone.
  • Consent records: what you consented to, when, and which version of this notice applied, together with a one-way keyed hash of your IP address (we do not store the IP address itself).
  • Client engagement data: communications, proposals, invoices and project records if you become a client. Where our work involves access to your systems, any personal data within them is processed on your instructions under a separate agreement.
  • Payment records: if you pay for a service, we keep the payment reference, amount, date, status and the name/email on the request. Card and account details are entered on the payment provider's own checkout (Stripe, PayPal or Razorpay) and never reach our systems; for bank transfers we see what appears on our own statement.
  • Website usage data: pages viewed, buttons clicked, referring website, campaign (UTM) parameters, language and — where provided by our infrastructure — country. This is collected without cookies or other device storage, without storing IP addresses, and is not used to identify you. It is not collected at all if your browser sends a Global Privacy Control or Do Not Track signal.

We do not intentionally collect sensitive or special-category data, and ask you not to include it in forms. Our services are for businesses; we do not knowingly collect data from children.

3. Why we use it and our legal basis

PurposeLegal basis (GDPR / UK GDPR)
Responding to your enquiry, scoping work, scheduling and confirming bookingsYour consent, and steps taken at your request before entering a contract (Art. 6(1)(a) and (b))
Taking payment and keeping payment/invoice recordsPerformance of a contract (Art. 6(1)(b)); legal obligations for tax and accounting records (Art. 6(1)(c))
Delivering services, invoicing and managing the client relationshipPerformance of a contract (Art. 6(1)(b)); legal obligations for tax and accounting records (Art. 6(1)(c))
Prioritising enquiries (a transparent points-based score from the information you submit; a person always reviews it)Legitimate interests in managing enquiries efficiently (Art. 6(1)(f)). No decision with legal or similarly significant effect is made solely by automated means.
Occasional emails with practical IT and security guidanceYour separate, optional consent (Art. 6(1)(a)); withdraw at any time
Website security, spam prevention and aggregate usage statisticsLegitimate interests in operating a secure, useful website (Art. 6(1)(f))

Under the DPDP Act, we process your personal data on the basis of the consent you give when submitting a form, for the specific purposes listed above, and for legitimate uses permitted by the Act. You may withdraw consent at any time, as easily as you gave it; withdrawal does not affect processing already carried out.

4. Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share it only with:

  • Service providers (processors) that host and operate this website and our systems — including Amazon Web Services for hosting (region: Mumbai, India (AWS ap-south-1)) and our email delivery provider — under contracts requiring them to protect it and use it only on our instructions.
  • Payment processors (Stripe, PayPal, Razorpay) when you choose to pay online. They act as independent controllers for the card and account data you give them and process it under their own privacy notices.
  • Team members or subcontractors engaged on your project, only where you have agreed to a team engagement and bound by confidentiality.
  • Professional advisers and authorities where required by law or to establish, exercise or defend legal claims.

5. International transfers

We are based in India, and your data is processed in India and in the locations where our service providers operate. When personal data from the EU/EEA or UK is transferred to countries without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, and you may request a copy of the relevant safeguards. For Australian residents, we take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles. Transfers from the UAE are made in accordance with the UAE PDPL.

6. How long we keep it

  • Enquiries and leads that do not become clients: 24 months after the last contact, then deleted or anonymised.
  • Booking records: 24 months after the booking date.
  • Client, invoicing and payment records: as long as required by applicable tax and accounting law (typically several years); on an erasure request the personal details are removed and only the financial record needed for that legal purpose remains.
  • Website usage events: 13 months.
  • Privacy-request records: 36 months, to demonstrate how requests were handled.
  • Consent records: for as long as we rely on the consent, plus the period needed to demonstrate it.

If you withdraw consent or ask us to delete your data, we erase it unless we are legally required to retain it.

7. Security

We use HTTPS encryption, access controls with strong authentication, least-privilege access, audit logging, hashed IP addresses and passwords, and regular encrypted backups. No system is perfectly secure; if a personal data breach occurs that is likely to affect you, we will notify you and the relevant authorities as required by law (including the Data Protection Board of India under the DPDP Act, and within 72 hours to the competent authority where GDPR/UK GDPR requires).

8. Your rights

Depending on where you live, you have some or all of the following rights, free of charge:

  • Access your personal data and receive a copy (including in a portable format)
  • Correct, complete or update inaccurate data
  • Erase your data
  • Restrict or object to processing, including processing based on legitimate interests
  • Withdraw consent at any time, including for marketing emails
  • Opt out of the "sale" or "sharing" of personal information (we do neither) and of targeted advertising
  • Not be discriminated against for exercising your rights
  • Nominate another individual to exercise your rights in the event of death or incapacity (DPDP Act)
  • Grievance redressal (DPDP Act) and to use an authorised agent (US state laws)

To exercise any right, use the privacy request form or email koustov.choudhury@solutions4it.in. We verify requests by confirming control of your email address and respond within the time required by applicable law (for example, one month under GDPR/UK GDPR, 45 days under the CCPA, and 30 days under the Australian Privacy Principles).

Complaints. Please contact us first so we can try to resolve your concern. You also have the right to complain to your local authority — for example, the Data Protection Board of India (after using our grievance process), your EU supervisory authority, the UK Information Commissioner's Office (ICO), the Office of the Australian Information Commissioner (OAIC), the UAE Data Office, or the California Privacy Protection Agency / your state Attorney General.

9. California and other US state residents

In the past 12 months we have collected the categories of personal information described in section 2 (identifiers, commercial/professional information, and internet activity) for the business purposes in section 3, from you directly and from your use of this website. We have not sold or shared personal information, do not use or disclose sensitive personal information, and do not have actual knowledge of processing data of consumers under 16. You can submit a request via the Do Not Sell or Share link.

10. Cookies

We use only strictly necessary cookies. See the Cookie Policy.

11. Changes

We will update this notice when our practices change. The version date is shown at the top; if changes are material, we will tell clients and ask for fresh consent where required.