Skip to main content

    Privacy Policy

    Last Updated: September 2026

    CirroCraft Solutions LLP ("CirroCraft", "we", "us", "our") builds and manages business systems for clients around the world. This policy explains what personal data we handle, why, on what legal basis, how long we keep it, where it goes, and the rights you have over it.

    It applies to everyone, wherever you are. Section 11 sets out the additional rights that apply in specific regions, including the European Economic Area, the United Kingdom, Canada, India, and US states with comprehensive privacy laws. Where a local law gives you stronger rights than this policy describes, that local law applies.

    Reading this page does not itself constitute consent to anything. Where we need consent, we ask for it separately and you are free to refuse. Where we rely on another legal basis, we say so below.

    1. Two Roles: Controller and Processor

    We handle personal data in two distinct capacities, and the difference determines who is accountable for what.

    • As a controller. For our own website visitors, enquiries, marketing and client-relationship records, we decide why and how the data is used. This policy governs that data.
    • As a processor. When we implement, migrate or operate a system on behalf of a client, any personal data inside that system belongs to the client, who remains the controller. We act only on their documented instructions under a data processing agreement. Our client's own privacy notice, not this one, governs that data, and requests about it should be directed to them.

    We do not use client or end-customer data for our own purposes, and we do not access it beyond what a specific engagement requires.

    2. Information We Collect

    • Details you give us: name, email address, phone number, company, role, country, and whatever you choose to tell us in a form, email, chat or call.
    • Approximate location: the city and country derived from your IP address at our edge network, used to route enquiries and understand which regions we are reaching. This is coarse, city-level information. We never request precise device location, and the site actively blocks the browser geolocation permission so it cannot be asked for.
    • Technical data: IP address, browser and device type, referring page, and pages viewed.
    • Chat and booking data: the content of a live chat conversation or a booking request, if you start one.
    • Business relationship records: correspondence, contracts, project notes and billing information for clients and suppliers.

    We do not knowingly collect special category data, and we ask that you do not send it to us through the website.

    3. Why We Use It, and Our Legal Basis

    Where a legal basis is required (for example under the GDPR), we rely on the following:

    • Responding to your enquiry, booking, or chat — steps taken at your request prior to a contract, or our legitimate interest in answering people who contact us.
    • Delivering services and support to clients — performance of a contract.
    • Routing enquiries and regional reporting (including city and country from IP) — our legitimate interest in operating a business across multiple markets.
    • Website analytics — your consent, given through our cookie banner and withdrawable at any time.
    • Newsletters and marketing email — your consent, or our legitimate interest in contacting existing clients about related services. Every message contains an unsubscribe link.
    • Security, fraud prevention and service integrity — our legitimate interest in keeping our systems safe.
    • Accounting, tax and legal obligations — compliance with a legal obligation.

    Where we rely on legitimate interest, we have weighed it against your rights and interests, and you may object at any time (see Section 10).

    4. Cookies, Analytics and Website Tools

    We keep this deliberately simple. There is one optional thing, and everything else loads only when you ask for it.

    Optional, and only with your consent:

    • Google Analytics 4 (Google LLC) — measures visits, pages and referral sources so we can improve the site. IP anonymisation is enabled. Data is retained for 14 months. Nothing is loaded and no analytics cookie is set unless you accept.

    Loaded only when you open them, not on page load:

    • Zoho SalesIQ — live chat. Loads only when you click the chat button.
    • Zoho Forms — our contact, trial, partner and newsletter forms. Each loads only when you open that form.
    • Zoho Bookings — the consultation calendar. Loads only when you choose to book.

    These are services you have explicitly requested by clicking to open them, so they are not part of the analytics choice. The practical consequence is important: declining analytics costs you no functionality whatsoever. You can still contact us, chat with us, subscribe and book a call.

    Some cookies are strictly necessary to make the site work and cannot be switched off. We store your cookie choice in your browser's local storage so we do not have to ask again.

    You can change your mind at any time using , also linked in the footer of every page. Withdrawing consent stops analytics immediately and clears the cookies it set. We ask again after 12 months so a choice you made long ago does not stand forever.

    5. Sharing and Service Providers

    We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not trade it in any form.

    We share data only with:

    • Zoho Corporation — our CRM, forms, live chat, bookings and business email. Zoho processes enquiry, chat and client relationship data on our behalf under a data processing agreement.
    • Google LLC — website analytics, where you have consented.
    • Netlify — website hosting and content delivery, which processes request data including IP addresses in order to serve the site.
    • Professional advisers, auditors and payment or accounting providers — where necessary to run the business, under confidentiality obligations.
    • Integration partners — only where required to deliver a specific client solution, and only with that client's knowledge and instruction.
    • Legal and regulatory authorities — where we are legally required to disclose, or to establish or defend legal claims.

    We may also transfer data as part of a merger, acquisition or sale of assets, in which case we will notify affected individuals and this policy will continue to apply until it is replaced.

    6. Where Your Data Is Processed

    CirroCraft is established in India, and our core business systems run in Zoho's India data centre. If you contact us from the European Economic Area, the United Kingdom, Canada, the United States or elsewhere, your data will be transferred to and processed in India, and in the case of analytics, in the United States.

    We state this plainly because it matters: for most of our clients, India is a third country, and these are cross-border transfers. We rely on the following safeguards:

    • Standard Contractual Clauses approved by the European Commission, and the UK International Data Transfer Addendum, incorporated into our agreements with vendors and clients.
    • Data processing agreements with each provider, including Zoho and Google, imposing confidentiality, security and onward-transfer restrictions.
    • Transfer impact assessment and supplementary technical measures, including encryption in transit and at rest, where required.

    If your organisation requires data residency in a specific region, tell us before an engagement begins. Many of our platforms can be provisioned in an EU, UK, Canadian, Australian or US data centre, and we will confirm the arrangement in writing.

    You may request a copy of the relevant transfer safeguards by contacting us at the address in Section 15.

    7. How Long We Keep It

    We keep personal data only as long as it serves the purpose it was collected for, then delete or anonymise it.

    • Website analytics — 14 months.
    • Live chat transcripts — 24 months from the conversation.
    • Enquiries and leads that do not become clients — 24 months from last contact.
    • Newsletter subscriptions — until you unsubscribe.
    • Client records, contracts and invoices — 7 years after the engagement ends, to meet tax, accounting and contractual limitation requirements.
    • Cookie choice — 12 months, after which we ask again.

    Where a legal obligation requires a longer period, we keep the data for that period and no longer.

    8. Security

    We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls on a least-privilege basis, multi-factor authentication on business systems, a content security policy and strict permissions policy on this website, vendor due diligence, and confidentiality obligations for everyone who works with us. No system is perfectly secure, but if a breach occurs that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected individuals as required by applicable law.

    9. Automated Decisions and Children

    We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not profile visitors for that purpose. Our website and services are directed at businesses, not children. We do not knowingly collect data from anyone under 16, and will delete it if we learn we have.

    10. Your Rights

    Subject to your local law, you may ask us to:

    • Confirm what personal data we hold about you, and give you a copy
    • Correct data that is inaccurate or incomplete
    • Delete data we no longer have grounds to keep
    • Restrict how we use it, or object to processing based on legitimate interest
    • Provide your data in a portable, machine-readable format
    • Withdraw consent at any time, without affecting anything done before you withdrew it
    • Stop sending you marketing, which you can do instantly via any unsubscribe link

    Write to info@cirrocraft.com and we will respond within one month, or sooner where the law requires it. If we need more time for a complex request, we will tell you why. We do not charge for these requests and we will never treat you differently for making one. We may ask for enough information to confirm your identity before we act.

    If your request concerns data held inside a client's system where we act as a processor, please contact that organisation directly. If you contact us instead, we will pass it on and tell you we have done so.

    11. Regional Information

    European Economic Area and United Kingdom

    We process personal data in line with the GDPR and UK GDPR. You have the rights in Section 10, and the right to lodge a complaint with your national data protection authority or, in the UK, the Information Commissioner's Office. We would appreciate the chance to address your concern first. Transfers out of the EEA and UK rely on the safeguards described in Section 6.

    Canada

    We handle personal information in line with PIPEDA and applicable provincial legislation, including Quebec's Law 25. Because we process data outside Canada, your information may be accessible to foreign courts and authorities under the laws of those countries. You may direct questions or complaints to us, and ultimately to the Office of the Privacy Commissioner of Canada or your provincial regulator.

    India

    We process personal data in line with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 together with the rules made under them. You may access, correct, complete, update or erase your data, nominate another individual to exercise your rights, and raise a grievance with us using the contact details in Section 15. If a grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India.

    United States

    Residents of California and other states with comprehensive privacy laws have the right to know what personal information is collected and disclosed, to request deletion or correction, to obtain a portable copy, and to opt out of sale or sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to exercise. We do not use sensitive personal information for inferring characteristics, and we will not discriminate against you for exercising any right.

    Everywhere else

    If you are in a jurisdiction not named above, the rights in Section 10 are available to you as a matter of our own policy, whether or not your local law requires them.

    12. Marketing Communication

    We send newsletters and occasional updates about our services. You can unsubscribe from any message using the link it contains, or by writing to us, and we will action it promptly. Unsubscribing from marketing does not stop necessary service or contractual messages relating to work we are doing for you.

    13. Third-Party Links

    Our website links to external sites, including Zoho product documentation. We are not responsible for their content or privacy practices, and we encourage you to read their policies before providing data to them.

    14. Changes to This Policy

    We update this policy when our practices change. The date at the top always reflects the current version. If a change materially affects how we use your personal data, we will give prominent notice on this site and, where required, ask for fresh consent or notify you directly. We will not rely on your continued use of the site as agreement to a material change.

    15. Contact and Complaints

    For any privacy question, request or grievance, including data subject requests and requests for transfer safeguards:

    CirroCraft Solutions LLP

    Mumbai, India

    Email: info@cirrocraft.com

    We aim to resolve every concern directly. If we cannot, you retain the right to complain to the supervisory authority for your region, as described in Section 11.